Source: OJ L, 2024/436, 2.2.2024Consolidated text

Current language: EN

Article 16 Auditing compliance with Article 37 of Regulation (EU) 2022/2065 on independent audit


Summary What does Article 16 of the Performance of independent audits say?

This article deals with the temporal and organisational scope of compliance assessments concerning the auditing obligations themselves.

It establishes that when auditors assess whether an audited provider has met its auditing-related obligations, they look back at the prior yearly audit period rather than the current one.

There is, however, a carve-out for one specific obligation — relating to the provider's cooperation duties in the current audit — which is assessed in real time.

The article also addresses a conflict of interest concern, requiring transparency from auditing organisations that share continuity with a previous audit.

Important points:

  • Compliance with auditing obligations is assessed against the yearly period preceding the current audit, not the current audit period itself.
  • Assess your cooperation obligations under Article 37(2) of Regulation (EU) 2022/2065 in relation to the current audit, as this runs in parallel to the lookback assessment.
  • Where there is organisational continuity between the current and previous auditing organisation, the auditing organisation is required to explain in the audit report the steps taken to ensure objectivity.

Springlex's summary of the article is a reading aid, not a substitute for the legal text.

    1. Compliance with the obligations laid down in Article 37 of Regulation (EU) 2022/2065 and in this Regulation shall be assessed in relation to the audit or audits performed for the yearly period preceding that of the current audit.

    1. In addition to paragraph 1, the audit shall include an assessment of the audited provider’s compliance with Article 37(2) of Regulation (EU) 2022/2065 with respect to the current audit.

    1. Where the previous audit or audits referred to in paragraph 1 were performed by the same auditing organisation as the current audit, or where the auditing organisation carrying out the current audit comprises at least one legal entity which participated in the previous audit, the audit report shall include an explanation of the steps put in place by the auditing organisation to ensure the objectivity of the assessment.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod