Source: OJ L, 2024/436, 2.2.2024 · Consolidated textCurrent language: EN
- Digital services act
Delegated acts
- Performance of independent audits
Article 7 Procedures for the preparations for the audit
Summary What does Article 7 of the Performance of independent audits say?
This article establishes the formal contractual foundation for the audit relationship between the audited provider and the auditing organisation.
Before any audit work begins, both parties must enter into a written agreement that governs the scope, responsibilities, logistics and dispute resolution of the audit.
The article also connects directly to the audit report itself, as required under Article 6, by mandating that this agreement — and any other related agreements or engagement letters — be annexed to it, ensuring full transparency of the audit's governing terms.
Important points:
- Audited providers and auditing organisations must conclude a written agreement before the audit covering scope, responsibilities, data access procedures, timeframes, and a dispute resolution procedure.
- All agreements and engagement letters between both parties related to the audit must be annexed to the final audit report.
- Any changes made to the written agreement during the audit must be explicitly disclosed in the audit report.
Springlex's summary of the article is a reading aid, not a substitute for the legal text.
The audited provider and the auditing organisation shall conclude a written agreement setting out:
the exhaustive list of audited obligations and commitments;
the responsibilities of the audit organisation, including, where applicable, detailed for each legal person constituting the auditing organisation, and the parties empowered to sign the audit report;
the procedures and contact points made available by the audited provider for the auditing organisation to request access to data referred to in Article 5(2);
the timeframe for the audit, including the start and end date of the audit procedures and the completion of the audit report;
a procedure on how disputes between the audited provider and the auditing organisation arising from the performance of the audit shall be resolved.
The agreement referred to in paragraph 1, as well as any other agreements or engagements letters between the auditing organisation and the audited provider related to the performance of the audit, shall be annexed to the audit report.
Where changes are made to the agreement referred to in paragraph 1 during the performance of the audit, they shall be made explicit in the audit report.
Springlex and this text is meant purely as a documentation tool and has no legal effect. No liability is assumed for its content. The authentic version of this act is the one published in the Official Journal of the European Union.
Definition
control risk
Definition
recipient of the service
Definition
audit evidence
Definition
audit risk
Definition
audit procedure
Definition
auditing organisation
Definition
information society service
Definition
audited provider
Definition
detection risk
Definition
misstatement
Definition
intermediary service
- a ‘mere conduit’ service, consisting of the transmission in a communication network of information provided by a recipient of the service, or the provision of access to a communication network;
- a ‘caching’ service, consisting of the transmission in a communication network of information provided by a recipient of the service, involving the automatic, intermediate and temporary storage of that information, performed for the sole purpose of making more efficient the information's onward transmission to other recipients upon their request;
- a ‘hosting’ service, consisting of the storage of information provided by, and at the request of, a recipient of the service;
Definition
audited obligation or commitment
Definition
inherent risk
Definition
substantive analytical procedure
Definition
online platform
Definition
online search engine
Definition
internal control
Definition
audited service
Definition
test