Source: OJ L, 2024/436, 2.2.2024

Current language: SV

Artikel 4 Val av revisionsföretag


Summary What does Article 4 of the Performance of independent audits say?

This article establishes the due diligence obligations that fall on the audited provider before selecting an auditing organisation.

It directly builds on Article 37(3) of Regulation (EU) 2022/2065, which sets out the eligibility requirements that an auditing organisation must meet.

Article 4 makes clear that verifying compliance with those requirements is the audited provider's responsibility, and that this check must happen before any selection is made.

The article also addresses the more complex scenario where the auditing organisation is made up of multiple legal persons or uses sub-contractors, specifying how the eligibility requirements apply in that context.

Important points:

  • Audited providers must verify that any auditing organisation they intend to select meets the eligibility requirements set out in Article 37(3) of Regulation (EU) 2022/2065 before making a selection.
  • Where the auditing organisation involves multiple legal persons or sub-contractors, each entity must individually meet certain requirements, while others can be satisfied collectively across the group.
  • The obligation to carry out these checks rests solely with the audited provider, not with any supervising authority.

Springlex's summary of the article is a reading aid, not a substitute for the legal text.

    1. Innan den leverantör som är föremål för revision utser ett revisionsföretag som ska utföra revisionen ska leverantören kontrollera huruvida det revisionsföretag som ska väljas ut uppfyller kraven i artikel 37.3 i förordning (EU) 2022/2065.

    1. Om det revisionsföretag som ska väljas ut består av fler än en juridisk person eller avser att anlita en eller flera underleverantörer ska den leverantör som är föremål för revision kontrollera huruvida samtliga av dessa juridiska personer eller underleverantörer

      1. individuellt uppfyller kraven i artikel 37.3 a och c i förordning (EU) 2022/2065, samt huruvida de

      2. tillsammans uppfyller kravet i artikel 37.3 b i förordning (EU) 2022/2065.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod