Source: OJ L, 2024/436, 2.2.2024Consolidated text

Current language: EN

Article 3 Scope of the audit and reasonable level of assurance


Summary What does Article 3 of the Performance of independent audits say?

This article establishes the temporal scope and duration requirements for audits carried out under this regulation.

It sets out when an audit period begins and ends, ensuring that audits are conducted in a way that allows the auditing organisation to reach conclusions with a reasonable level of assurance.

The article connects directly to Article 37 of Regulation (EU) 2022/2065, anchoring the audit timeframes to the obligations set out there.

It also addresses the specific situation where no previous audit has taken place, providing a defined starting point tied to the designation notification process under Article 33(6) of that Regulation.

Important points:

  • Audits must be conducted in a manner and for a duration that enables the auditing organisation to assess compliance with all audited obligations and commitments with a reasonable level of assurance.
  • The audit period runs immediately from the end of the previous audit's covered period, ensuring continuity of oversight with no gaps.
  • Where no previous audit exists, the audited period starts four months after the Article 33(6) notification, and the audit report must be completed within one year from that starting point.

Springlex's summary of the article is a reading aid, not a substitute for the legal text.

    1. The audit shall be performed in a manner and for a duration that allows the auditing organisation to assess the audited provider’s compliance with all audited obligations and commitments with a reasonable level of assurance.

    1. The audit shall cover the period starting immediately after the period covered by the previous audit and ending on a date that allows the auditing organisation to perform the audit within the time frame required by Article 37(1) of Regulation (EU) 2022/2065, including by asserting its assessment pursuant to paragraph 1 based on the evidence collected and audit procedures conducted during that period, and by completing and submitting the audit report pursuant to Article 37(4) of that Regulation to the audited provider.

    1. Where no previous audit was performed, the audit shall cover the period starting four months after the notification referred to in Article 33(6), first subparagraph, of Regulation (EU) 2022/2065, and the duration of the audit shall allow for the audit report pursuant to Article 6(1) to be completed at the latest within a year as from the start of the audited period.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod