Source: OJ L, 2024/436, 2.2.2024Current language: FR
- Digital services act
Delegated acts
- Performance of independent audits
Article 3 Champ de l’audit et niveau d’assurance raisonnable
Summary What does Article 3 of the Performance of independent audits say?
This article establishes the temporal scope and duration requirements for audits carried out under this regulation.
It sets out when an audit period begins and ends, ensuring that audits are conducted in a way that allows the auditing organisation to reach conclusions with a reasonable level of assurance.
The article connects directly to Article 37 of Regulation (EU) 2022/2065, anchoring the audit timeframes to the obligations set out there.
It also addresses the specific situation where no previous audit has taken place, providing a defined starting point tied to the designation notification process under Article 33(6) of that Regulation.
Important points:
- Audits must be conducted in a manner and for a duration that enables the auditing organisation to assess compliance with all audited obligations and commitments with a reasonable level of assurance.
- The audit period runs immediately from the end of the previous audit's covered period, ensuring continuity of oversight with no gaps.
- Where no previous audit exists, the audited period starts four months after the Article 33(6) notification, and the audit report must be completed within one year from that starting point.
Springlex's summary of the article is a reading aid, not a substitute for the legal text.
L’audit est effectué d’une manière et pour une durée qui permettent à l’organisme d’audit d’évaluer, avec un niveau d’assurance raisonnable, si le fournisseur audité respecte l’ensemble des obligations et engagements audités.
L’audit couvre la période commençant immédiatement après la période couverte par l’audit précédent et se terminant à une date qui permet à l’organisme d’audit de réaliser l’audit dans les délais prévus à l’article 37, paragraphe 1, du règlement (UE) 2022/2065, y compris en étayant l’évaluation qu’il a réalisée en application du paragraphe 1 par les éléments probants recueillis et les procédures d’audit menées au cours de cette période, et en complétant et en soumettant le rapport d’audit au fournisseur audité conformément à l’article 37, paragraphe 4, dudit règlement.
Lorsque aucun audit précédent n’a été réalisé, l’audit couvre la période commençant quatre mois après la notification prévue à l’article 33, paragraphe 6, premier alinéa, du règlement (UE) 2022/2065, et la durée de l’audit permet d’achever le rapport d’audit prévu à l’article 6, paragraphe 1, au plus tard dans un délai d’un an à compter du début de la période auditée.
Springlex and this text is meant purely as a documentation tool and has no legal effect. No liability is assumed for its content. The authentic version of this act is the one published in the Official Journal of the European Union.
Definition
procédure analytique de corroboration
(En. substantive analytical procedure)
Definition
inexactitude
(En. misstatement)
Definition
organisme d’audit
(En. auditing organisation)
Definition
procédure d’audit
(En. audit procedure)
Definition
test
Definition
service de la société de l’information
(En. information society service)
Definition
fournisseur audité
(En. audited provider)
Definition
plateforme en ligne
(En. online platform)
Definition
contrôle interne
(En. internal control)
Definition
risque de non-contrôle
(En. control risk)
Definition
service audité
(En. audited service)
Definition
niveau d’assurance raisonnable
(En. reasonable level of assurance)
Definition
risque d’audit
(En. audit risk)
Definition
risque inhérent
(En. inherent risk)
Definition
risque de non-détection
(En. detection risk)
Definition
destinataire du service
(En. recipient of the service)
Definition
moteur de recherche en ligne
(En. online search engine)
Definition
service intermédiaire
(En. intermediary service)
- un service de «simple transport», consistant à transmettre, sur un réseau de communication, des informations fournies par un destinataire du service ou à fournir l’accès à un réseau de communication;
- un service de «mise en cache», consistant à transmettre, sur un réseau de communication, des informations fournies par un destinataire du service, impliquant le stockage automatique, intermédiaire et temporaire de ces informations, effectué dans le seul but de rendre plus efficace la transmission ultérieure de ces informations à d’autres destinataires à leur demande;
- un service d’«hébergement», consistant à stocker des informations fournies par un destinataire du service à sa demande;
Definition
éléments probants
(En. audit evidence)