Source: OJ L, 2024/436, 2.2.2024Consolidated text

Current language: EN

Article 4 Selection of the auditing organisation


Summary What does Article 4 of the Performance of independent audits say?

This article establishes the due diligence obligations that fall on the audited provider before selecting an auditing organisation.

It directly builds on Article 37(3) of Regulation (EU) 2022/2065, which sets out the eligibility requirements that an auditing organisation must meet.

Article 4 makes clear that verifying compliance with those requirements is the audited provider's responsibility, and that this check must happen before any selection is made.

The article also addresses the more complex scenario where the auditing organisation is made up of multiple legal persons or uses sub-contractors, specifying how the eligibility requirements apply in that context.

Important points:

  • Audited providers must verify that any auditing organisation they intend to select meets the eligibility requirements set out in Article 37(3) of Regulation (EU) 2022/2065 before making a selection.
  • Where the auditing organisation involves multiple legal persons or sub-contractors, each entity must individually meet certain requirements, while others can be satisfied collectively across the group.
  • The obligation to carry out these checks rests solely with the audited provider, not with any supervising authority.

Springlex's summary of the article is a reading aid, not a substitute for the legal text.

    1. Prior to selecting an auditing organisation with a view to performing the audit, the audited provider shall check whether the organisation to be selected fulfils the requirements laid down in Article 37(3) of Regulation (EU) 2022/2065.

    1. Where the auditing organisation to be selected consists of more than one legal person or intends to have recourse to one or several sub-contractors, the audited provider shall check whether all those legal persons or subcontractors:

      1. individually fulfil the requirements laid down in Article 37(3), points (a) and (c), of Regulation (EU) 2022/2065;

      2. jointly fulfil the requirement laid down in Article 37(3), point (b), of Regulation (EU) 2022/2065.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod