Source: OJ L, 2024/436, 2.2.2024

Current language: FR

Article 4 Sélection de l’organisme d’audit


Summary What does Article 4 of the Performance of independent audits say?

This article establishes the due diligence obligations that fall on the audited provider before selecting an auditing organisation.

It directly builds on Article 37(3) of Regulation (EU) 2022/2065, which sets out the eligibility requirements that an auditing organisation must meet.

Article 4 makes clear that verifying compliance with those requirements is the audited provider's responsibility, and that this check must happen before any selection is made.

The article also addresses the more complex scenario where the auditing organisation is made up of multiple legal persons or uses sub-contractors, specifying how the eligibility requirements apply in that context.

Important points:

  • Audited providers must verify that any auditing organisation they intend to select meets the eligibility requirements set out in Article 37(3) of Regulation (EU) 2022/2065 before making a selection.
  • Where the auditing organisation involves multiple legal persons or sub-contractors, each entity must individually meet certain requirements, while others can be satisfied collectively across the group.
  • The obligation to carry out these checks rests solely with the audited provider, not with any supervising authority.

Springlex's summary of the article is a reading aid, not a substitute for the legal text.

    1. Avant de sélectionner un organisme d’audit en vue de réaliser l’audit, le fournisseur audité vérifie si cet organisme remplit les exigences énoncées à l’article 37, paragraphe 3, du règlement (UE) 2022/2065.

    1. Lorsque l’organisme d’audit à sélectionner est composé de plus d’une personne morale ou a l’intention de recourir à un ou plusieurs sous-traitants, le fournisseur audité vérifie si toutes ces personnes morales ou sous-traitants:

      1. remplissent individuellement les exigences énoncées à l’article 37, paragraphe 3, points a) et c), du règlement (UE) 2022/2065;

      2. remplissent conjointement l’exigence énoncée à l’article 37, paragraphe 3, point b), du règlement (UE) 2022/2065.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod