lagen.nu
(EU) 2024/436

Supplementing Regulation (EU) 2022/2065 of the European Parliament and of the Council, by laying down rules on the performance of audits for very large online platforms and very large online search engines

Titel
Commission Delegated Regulation (EU) 2024/436 of 20 October 2023 supplementing Regulation (EU) 2022/2065 of the European Parliament and of the Council, by laying down rules on the performance of audits for very large online platforms and very large online search engines
CELEX
32024R0436
Datum
2023-10-20
Konsoliderad t.o.m.
2024-02-02
Källa
eur-lex.europa.eu

EUROPEISKA KOMMISSIONEN HAR ANTAGIT DENNA FÖRORDNING

med beaktande av fördraget om Europeiska unionens funktionssätt,

med beaktande av Europaparlamentets och rådets förordning (EU) 2022/2065 av den 19 oktober 2022 om en inre marknad för digitala tjänster och om ändring av direktiv 2000/31/EG (förordningen om digitala tjänster), särskilt artikel 37.7, och

(1) Oberoende revisioner är ett viktigt verktyg för att övervaka uppfyllandet av skyldigheterna för leverantörer av mycket stora onlineplattformar och av mycket stora onlinesökmotorer enligt förordning (EU) 2022/2065. Den förordningen innehåller även andra verktyg för att säkerställa ansvarsskyldighet, inte minst genom förbättrad offentlig granskning av transparensrapporter och andra upplysningskrav, men oberoende revisionsföretag spelar en särskild roll när det gäller att tidigt bedöma sådana leverantörers efterlevnad av den förordningen. Slutsatserna och resultaten av dessa oberoende revisioner, och de åtföljande rekommendationerna, kan ha en meningsfull inverkan på den rättsliga tillsynen. Samtidigt utgör oberoende revisioner en av flera källor till information och analys som tillsynsmyndigheter kan använda för att fullgöra sina övervaknings- och verkställighetsuppgifter.

(2) För att säkerställa att de oberoende revisionerna utförs på ett ändamålsenligt, effektivt, snabbt och jämförbart sätt från och med den dag då förordning (EU) 2022/2065 börjar tillämpas, enligt vad som anges i artiklarna 92 och 93 i den förordningen, bör kommissionen fastställa regler för utförandet av revisioner, i synnerhet när det gäller de rättsliga skyldigheterna för de leverantörer som är föremål för revision och förfarandestegen för att säkerställa att de företag som utför revisionerna uppfyller de villkor för oberoende, avsaknad av intressekonflikter samt sakkunskap och yrkesetik som fastställs i artikel 37.3 i förordning (EU) 2022/2065.

(3) För att underlätta lämpligt utförande av revisioner med en hög nivå av sakkunskap och föregripa oförutsedda konsekvenser på marknaden för revisionstjänster bör det förtydligas att revisioner som utförs i enlighet med artikel 37 i förordning (EU) 2022/2065 får utföras av flera revisorer. När så krävs, till exempel på grund av ett behov av särskild sakkunskap vid revision av vissa skyldigheter eller åtaganden, såsom de som rör algoritmiska systems utformning och funktion, eller en förståelse för riskerna för grundläggande rättigheter eller spridning av olagligt innehåll, får den leverantör som revisionen avser anlita olika revisionsföretag, eller ett konsortium av företag, för utförandet av revisionen. Revisionsföretag får även anlita underleverantörer som tillhandahåller den sakkunskap som krävs, förutsatt att både revisionsföretaget och underleverantören uppfyller de nödvändiga villkoren avseende oberoende, avsaknad av intressekonflikter, styrkt objektivitet och yrkesetik, och att de tillsammans uppfyller villkoren om teknisk sakkunskap. I sådana fall bör den leverantör som revisionen avser fortfarande säkerställa att dess uppfyllande av alla de skyldigheter och åtaganden som avses i artikel 37.1 i förordning (EU) 2022/2065 granskas minst en gång om året.

(4) De revisionsuttalanden som avses i artikel 37.4 g i förordning (EU) 2022/2065 bör utfärdas av revisionsföretag med rimlig tillförlitlighetsnivå. För att uppnå en rimlig tillförlitlighetsnivå bör revisionsföretaget ha en hög, men inte absolut, konfidensgrad om att det inte förekommer några felaktigheter, såsom utelämnanden, missvisande uppgifter eller fel, som inte upptäcktes vid revisionen. För att säkerställa den tillförlitlighetsnivån bör revisionsföretaget bland annat hämta in tillräcklig bevisning och använda lämpliga revisionsmetoder vid bedömningen.

(5) Enligt artikel 37.1 i förordning (EU) 2022/2065 bör oberoende revisioner utföras åtminstone årligen, i samband med den årliga omgång riskbedömningar som avses i artikel 34 i den förordningen. Det kan dock i vissa fall vara nödvändigt att utföra revisioner oftare. Revisionerna bör ske så att det säkerställs en fortlöpande övervakning av att de leverantörer som revisionen avser efterlever förordning (EU) 2022/2065 och relevanta uppförandekoder och krisprotokoll. Den leverantör som är föremål för revision bör säkerställa att den tidsperiod för vilken revisionen bedömer uppfyllandet av de skyldigheter och åtaganden som revisionen avser kompletterar den tidsperiod som omfattas av den föregående revisionen av leverantörens uppfyllande av dessa skyldigheter och åtaganden, och att den inleds senast då den tidsperiod som omfattas av den föregående revisionen avslutas. I och med att en slutförd revision omfattar både den bedömning som gjorts av revisionsföretaget och upprättandet av en revisionsrapport, bör de leverantörer som är föremål för revision säkerställa att tidsåtgången för revisionen gör att revisioner kan slutföras minst en gång per år och att revisionsrapporterna utan onödigt dröjsmål lämnas in till kommissionen och samordnaren för digitala tjänster, i enlighet med artikel 42.4 i förordning (EU) 2022/2065.

(6) Leverantörer som är föremål för revision bör under inga omständigheter lägga sig i utförandet av revisionen och dess slutsatser, utan de ska uppfylla sina skyldigheter enligt artikel 37 i förordning (EU) 2022/2065 bland annat genom att enas om avtalsvillkor med revisionsföretaget och, före valet av revisionsföretag, kontrollera att företaget uppfyller de villkor som avses i artikel 37.3 i förordning (EU) 2022/2065.

(7) Den leverantör som är föremål för revision bör till exempel bedöma de avtal som tidigare har tecknats med revisionsföretaget eller avtal som tecknats mellan revisionsföretaget och juridiska personer som har anknytning till den leverantör som är föremål för revision. Den leverantör som är föremål för revision bör även lägga till klausuler i avtal med revisionsföretag för att säkerställa att de villkoren i artikel 37.3 i förordning (EU) 2022/2065 uppfylls. Om revisionsföretaget består av flera enheter bör den leverantör som är föremål för revision kontrollera att alla dessa enheter uppfyller dessa villkor, inbegripet, i förekommande fall, eventuella underleverantörer som revisionsföretaget har anlitat i syfte att på något sätt bistå vid revisionen. Var och en av de enheter som utför revisionen ska individuellt uppfylla kraven på oberoende och avsaknad av intressekonflikter, men kraven på kompetens, sakkunskap och tekniska resurser ska uppfyllas tillsammans av dessa enheter, vilket innebär att olika enheter kan utföra olika delar av revisionen och bidra med den kapacitet, kompetens och sakkunskap som behövs för utförandet av revisionen. Revisionsrapporten ska innehålla uppgifter om varje enhets ansvarsområde för respektive del av revisionen.

(8) I enlighet med artikel 37.3 a i i förordning (EU) 2022/2065 ska den leverantör som är föremål för revision särskilt bemöda sig om att undvika att revisionsföretaget tillhandahåller andra tjänster än revision till den leverantör som revisionen avser vid kontrollen av huruvida ett revisionsföretag uppfyller kraven på oberoende och avsaknad av intressekonflikter. Den leverantör som är föremål för revision bör till exempel bedöma huruvida några tjänster har tillhandahållits, såsom tjänster som rör något system, någon programvara eller någon process som har anknytning till ärenden som är relevanta för den skyldighet eller det åtagande som revisionen avser, till exempel konsulttjänster för bedömning av prestanda, styrning eller programvara, utbildningstjänster, utveckling eller underhåll av system eller underleverans av innehållsmoderering. Dessa tjänster inbegriper även tjänster som tillhandahållits den leverantör som är föremål för revision i form av rådgivning om eller utveckling av interna kontroller, eller intern bedömning av leverantörens efterlevnad av förordning (EU) 2022/2065 eller uppförandekoder och krisprotokoll, även när detta är begränsat till punktvisa tester, till exempel tredjepartstester av prestanda hos system för innehållsmoderering. Detta bör inte utesluta revisionsföretag som har utfört lagstadgad revision.

(9) Med tanke på komplexiteten och särarten hos granskningar av efterlevnaden av förordning (EU) 2022/2065 är det avgörande att revisionsföretaget har sakkunskap inom ämnet, för att revisionerna ska kunna utföras med rimlig tillförlitlighetsnivå och för att revisionsföretaget ska kunna använda det yrkesmässiga omdöme och den professionella skepsis som krävs för att veta, till exempel, vilka uppgifter som behövs för att kunna utföra revisionsförfarandet eller ifrågasätta motsägelsefulla uppgifter. Den leverantör som är föremål för revision bör därför kontrollera att revisionsföretaget innehar denna sakkunskap, inbegripet inom riskhantering, när det gäller både revisionsrisker och innehållet i förordning (EU) 2022/2065 och i synnerhet de systemrisker för samhället som avses i artikel 34 i den förordningen. Den leverantör som är föremål för revision bör även kontrollera revisionsföretagets tekniska kompetens och kapacitet med avseende på den specifika tjänst som revisionen avser, inbegripet sakkunskap om dess innehåll, till exempel när det gäller funktion och effekter hos algoritmiska system såsom rekommendationssystem och andra sociotekniska system som drivs av leverantören. Revisionsföretaget bör ha möjlighet att anlita underleverantörer eller på annat vis erhålla och tillämpa den sakkunskap och kapacitet som krävs, och den leverantör som revisionen avser bör kontrollera och säkerställa att revisionsföretaget kan erhålla denna sakkunskap och kapacitet i tid för att kunna utföra revisionen.

(10) Vid kontrollen av om revisionsföretaget uppfyller villkoren i artikel 37.3 i förordning (EU) 2022/2065 bör den leverantör som revisionen avser bedöma alla relevanta bevis, inbegripet, i tillämpliga fall, intyg, redovisningar och revisionsrapporter som utfärdats av revisionsföretaget. Lämplig sakkunskap kan styrkas exempelvis genom praktisk erfarenhet av riskbedömning och riskhantering samt genom akademiska studier, vetenskapliga publikationer och erfarenhet av relevanta revisioner. Revisionsrapporterna ska innehålla alla relevanta styrkande handlingar som visar att revisionsföretaget uppfyller de nödvändiga villkoren.

(11) Enligt artikel 37.2 i förordning (EU) 2022/2065 ska den leverantör som är föremål för revision tillhandahålla revisionsföretaget det samarbete och bistånd som krävs för att revisionerna ska kunna utföras på ett ändamålsenligt, effektivt och snabbt sätt samt undvika att på något vis lägga sig i revisionsföretagets oberoende beslut. Den leverantör som revisionen avser bör till exempel inte tvinga, vägleda eller på annat sätt påverka revisionsföretaget med någon form av avtalsmässiga eller andra begränsningar eller incitament vad gäller dess val och utförande av revisionsförfaranden eller metoder, insamling och behandling av uppgifter och revisionsbevis, analys, tester, revisionsuttalande eller utarbetande av revisionsslutsatser.

(12) För att säkerställa det samarbete och bistånd som krävs under revisionen bör den leverantör som revisionen avser se till att revisionsföretaget har tillgång till alla uppgifter som krävs för utförandet av revisionen. Den leverantör som revisionen avser bör så tidigt som möjligt, och i vart fall innan revisionsföretaget påbörjar revisionsförfarandena, översända alla handlingar och intyg som krävs. Enligt artikel 41.3 d och e i förordning (EU) 2022/2065, till exempel, ska funktionen för regelefterlevnad hos den leverantör som är föremål för revision övervaka efterlevnaden av alla de skyldigheter och åtaganden som omfattas av revisionen, vilket bör utmynna i inrättandet av interna kontroller. Revisionsföretaget bör därför ges tillgång till all information som rör sådana kontroller och all annan information som beskriver strategin för att säkerställa regelefterlevnad hos den leverantör som revisionen avser. Den leverantör som revisionen avser bör i synnerhet tillhandahålla revisionsföretaget de riktmärken som leverantören använder för att säkerställa efterlevnaden av förordning (EU) 2022/2065, så att revisionsföretaget kan basera revisionskriterierna på denna information.. Revisionsföretaget bör också ges tillgång till eventuella analyser som leverantören som revisionen avser har gjort av inneboende risker och kontrollrisker. Den berörda leverantören bör tillhandahålla revisionsföretaget information som underlättar förståelsen av den granskade tjänsten, dess styrelseformer, olika arbetsgruppers respektive ansvarsområden samt beslutsstrukturer, inbegripet dess funktion för regelefterlevnad, liksom presentationer av dess it-system, data- och registerstrukturer och samspelet mellan olika algoritmiska system av betydelse för revisionen.

(13) Revisionsföretaget ska när som helst under utförandet av revisionen kunna begära eventuella ytterligare uppgifter som krävs. Tillgång till dessa uppgifter ska ges utan onödigt dröjsmål på ett sätt som inte på något vis hindrar utförandet av revisionen. Detta bör innefatta tillgång till uppgifter, inklusive personuppgifter, som samlats in från olika källor, såsom dokument, algoritmiska system, databaser eller intervjuer, enligt vad som är tillämpligt. Den leverantör som är föremål för revision bör även ge revisionsföretaget tillgång till förfaranden och processer samt it-system, såsom algoritmiska system och informationssystem, inbegripet testmiljöer. För att revisionsföretaget ska kunna granska dessa system på ett meningsfullt sätt bör den leverantör som revisionen avser tillhandahålla alla tillgängliga resurser som krävs för att hjälpa revisionsföretaget att komma åt och bedöma systemen, till exempel genom att ställa leverantörens behöriga personal till förfogande för att svara på frågor eller köra testmiljöer och förklara deras funktion, eller underlätta övrig tillgång som behövs till personal och lokaler, till exempel byggnader. Tillgång till förfaranden och processer kan till exempel innebära tillgång till beskrivningar eller handlingar som rör den interna beslutsprocessen för den leverantör som revisionen avser. Tillgång till relevanta uppgifter kan även kräva andra åtgärder från den leverantör som revisionen avser för att den ska uppfylla sin skyldighet till samarbete och bistånd. Intervjuer med personalen kan till exempel kräva att den leverantör som revisionen avser tillhandahåller säkra lokaler. När det är nödvändigt för utförandet av revisionen bör de leverantörer som är föremål för revision uppfylla sin samarbets- och biståndsskyldighet gentemot revisionsföretaget genom att bland annat underlätta tillgången till relevanta data om deras verksamhet som innehas av deras utomstående underleverantörer. Detta kan vara fallet exempelvis när det gäller resultatet av åtgärder för innehållsmoderering, utbildningsmaterial eller riktlinjer som används av utomstående underleverantörer som modererar innehåll, eller försäljare och tjänsteleverantörer för it-lösningar, inbegripet exempelvis algoritmer och tillämpningar som används i rekommendationssystem eller system för annonsering som används av den leverantör som revisionen avser.

(14) För att underlätta meningsfull insyn i resultaten av revisionen och möjliggöra ett heltäckande och jämförbart format för de revisionsrapporter som avses i artikel 37.4 i förordning (EU) 2022/2065 och de rapporter om genomförandet av revisionen som avses i artikel 37.6 i den förordningen bör det i denna förordning fastställas mallar för dessa rapporter och ett krav på ett antal bilagor till var och en av rapporterna. De mallar som fastställs i denna förordning kräver omfattande rapportering, men de bör inte påverka de krav på offentliggörande av rapporter som fastställs i artikel 42.4 och 42.5 i förordning (EU) 2022/2065.

(15) För att säkerställa att revisionsföretaget erhåller det bistånd som krävs av den leverantör som revisionen avser, utan inblandning i revisionen, och att revisionsföretaget uppfyller alla villkor för utarbetandet av revisionen och levererar revisionsrapporten i tid och med den kvalitet som krävs för att uppnå en rimlig tillförlitlighetsnivå bör vissa regler fastställas för att ange förfarandena för utarbetandet av revisionen. De skyldigheter och ansvar som åligger den leverantör som revisionen avser och revisionsföretaget, inbegripet alla underleverantörer eller partnerorganisationer och den personal som ansvarar för utförandet av revisionen, bör fastställas i ett skriftligt avtal, däribland genom avtalsvillkor. Det skriftliga avtalet bör även innehålla uppgifter om de skyldigheter och åtaganden som revisionen avser, fördelningen av resurser samt reglerna för interaktion och kontaktpunkter mellan revisionsföretaget och den leverantör som revisionen avser. Alla styrkande handlingar och avtal bör bifogas revisionsrapporten, även om handlingarna är i form av en skrivelse om åtagande av revision eller andra avtalsvillkor.

(16) För att möjliggöra en heltäckande översikt och underlätta ansvarsskyldigheten för de leverantörer som är föremål för revision bör revisionsrapporten innehålla en slutsats avseende revisionsföretagets bedömning av om den leverantör som är föremål för revision har uppfyllt de skyldigheter eller åtaganden som revisionen avser. Varje revisionsslutsats ska bygga på en rimlig tillförlitlighetsnivå och vara antingen ”positiv”, ”positiv med anmärkningar” eller ”negativ” för att kunna ligga till grund för revisionsuttalandet. Slutsatsen ”positivt med anmärkningar” bör inte avse bedömningen av själva efterlevnaden. Sådana anmärkningar kan till exempel avse leverantörens tillhandahållande av uppgifter på revisionsföretagets begäran eller förbättringar av det underhåll eller de kontroller som utförs av den leverantör som revisionen avser, eller avse ytterligare begränsningsplaner och förbättringar som den berörda leverantören avser att göra. Om revisionsföretaget finner att den leverantör som revisionen avser uppfyller en skyldighet eller ett åtagande som granskats, i enlighet med de riktmärken som rapporterats av den leverantör som revisionen avser, men anser det nödvändigt att ta med anmärkningar som rör dessa riktmärken, bör revisionsslutsatsen vara ”positiv med anmärkningar”, eftersom sådana anmärkningar kan vara till nytta för att informera leverantören om eventuella ändringar av dessa riktmärken, baserat på revisionsföretagets kunnande och sakkunskaper samt information från externa källor. Exempelvis skulle anmärkningarna kunna beakta vägledning från kommissionen, inbegripet genom kommissionens riktlinjer enligt artikel 35.3 i förordning (EU) 2022/2065 och eventuella andra relevanta riktlinjer som utfärdats av kommissionen med avseende på tillämpningen av den förordningen, rapporter från den europeiska nämnd för digitala tjänster som avses i artikel 35.2 i den förordningen, verkställighetsåtgärder, beslut som kommissionen fattat i enlighet med den förordningen, relevant rättspraxis – i synnerhet från Europeiska unionens domstol, offentliga samråd eller andra relevanta officiella källor.

(17) Om en revisionsslutsats är negativ men endast gäller under en begränsad tidsperiod och revisionsföretaget anser att den leverantör som revisionen avser har uppfyllt skyldigheten eller åtagandet för återstoden av den tidsperiod som revisionen omfattar bör detta återspeglas i revisionsrapporten för varje relevant skyldighet eller åtagande, för att möjliggöra offentlig granskning och rättslig tillsyn. Rapporten bör innefatta revisionsföretagets iakttagelser om all information om befintliga eller planerade begränsningsplaner för att åtgärda bristfällig efterlevnad som den leverantör som revisionen avser har gjort tillgänglig för det.

(18) Mot bakgrund av den olikartade karaktären hos de rättsliga skyldigheter som fastställs i kapitel III i förordning (EU) 2022/2065, och de frivilliga åtaganden som gjorts inom ramen för de uppförandekoder och krisprotokoll som avses i artiklarna 45, 46 och 48 i den förordningen, bör revisionsföretaget utfärda revisionsuttalanden om efterlevnaden av det kapitlet och av varje kod och protokoll.

(19) För att revisionen ska kunna utföras med rimlig tillförlitlighetsnivå, och lämpliga revisionsförfaranden ska kunna utarbetas enligt metoder som i högsta möjliga grad minimerar revisionsrisken, bör en viktig del av metoden för utförandet av revisionen vara bedömningen av revisionsrisken, dvs. risken för att revisionsföretaget utfärdar ett olämpligt revisionsuttalande eller en olämplig revisionsslutsats. Därför bör revisionsföretaget bedöma revisionsrisken alldeles i början av revisionen, innan en exakt metod tas fram och revisionsförfarandena utförs. Analysen av revisionsrisker behövs för att revisionsföretaget ska kunna välja de exakta metoderna för revisionen och fastställa hur omfattande revisionsförfarandena måste vara för att uppnå en rimlig tillförlitlighetsnivå i revisionsuttalandet. Revisionsföretaget bör utföra en analys av revisionsrisker inför bedömningen av varje skyldighet eller åtagande som revisionen avser, med beaktande av inneboende risker, kontrollrisker och upptäcktsrisker.

(20) För att kunna utvärdera revisionsriskerna korrekt bör analysen av revisionsrisker ta hänsyn till den granskade tjänstens särdrag, i synnerhet dess riskprofil, samt revisionens omfattning och komplexitet. Det är till exempel sannolikt att onlineplattformar som tillåter att distansavtal ingås mellan kunder har andra inneboende risker än videodelningsplattformar eller sökmotorer. Dessutom bör det sociala och ekonomiska sammanhang där tjänsten i fråga tillhandahålls beaktas, till exempel i fråga om typiska användargrupper, såsom minderåriga, eller vanligt beteende, såsom en hög förekomst av icke-autentisk användning och samordnade beteenden vid desinformationskampanjer. Det sociala och ekonomiska sammanhanget som beaktas bör även omfatta sannolikheten och, oberoende av detta, allvarlighetsgraden vad gäller exponering för krissituationer och oförutsedda händelser, enligt vad som avses i förordning (EU) 2022/2065.

(21) För att säkerställa att analysen av revisionsrisker motsvarar utvecklingen av de risker som tjänsten omfattas av, bör analysen av revisionsrisker även bygga på uppgifter från tidigare revisioner som leverantören har varit föremål för, i tillämpliga fall, och på uppgifter från sådana källor som revisionsrapporter som avser andra leverantörer med liknande riskprofil. För att säkerställa att analysen av revisionsrisker helt och hållet bygger på de senaste beläggen för risker i sammanhang som liknar de där den leverantör som revisionen avser verkar, och som enligt officiella källor har direkt relevans för tillämpningen av förordning (EU) 2022/2065, bör analysen även bygga på uppgifter från rapporter som utfärdats av den europeiska nämnden för digitala tjänster eller riktlinjer från kommissionen, i tillämpliga fall. Andra uppgifter kan även inbegripa uppgifter från revisionsrapporter som offentliggjorts i enlighet med artikel 42.4 i förordning (EU) 2022/2065 av andra leverantörer av mycket stora onlineplattformar eller mycket stora onlinesökmotorer.

(22) Revisionsföretaget bör, utan påverkan från den leverantör som revisionen avser, ta fram de revisionsmetoder som ska användas för att bedöma uppfyllandet av de skyldigheter och åtaganden som revisionen avser. Revisionskriterierna bör baseras på uppgifter som lämnats in av den leverantör som revisionen avser vad gäller riktmärken som denna leverantör använder för att övervaka efterlevnaden. Metoden får även ta hänsyn till annan information som tillhandahålls av den leverantör som revisionen avser, exempelvis analysen av inneboende risker, om denna leverantör har gjort en sådan analys, till exempel genom åtgärder som tagits fram av den regelefterlevnadsansvariga eller ledningsorganet, i enlighet med artikel 41 i förordning (EU) 2022/2065, eller andra åtgärder som ingår i funktionen för den tjänst för bedömningar av systemrisker som avses i artikel 34 i den förordningen.

(23) För att säkerställa att revisionsmetoderna är ändamålsenliga för att uppnå en rimlig tillförlitlighetsnivå för revisionsuttalandena bör valet av metod för revisionsförfarandena göras med hänsyn till särdragen hos den skyldighet eller det åtagande som revisionen avser, och metoderna bör exempelvis anpassas efter skyldighetens art som en skyldighet avseende medel eller en skyldighet avseende resultat som leverantören måste uppnå för att uppfylla skyldigheten. Till exempel skulle revisionsförfarandena för att bedöma uppfyllandet av transparensrapporteringsskyldigheten enligt artikel 15 i förordning (EU) 2022/2065 kunna ge revisionsföretaget möjligheten att fastställa huruvida rapporterna offentliggjordes i enlighet med de tidsgränser och format som föreskrivs i den förordningen, samt huruvida de var fullständiga och rapporterade data var korrekta, representativa och uppdelade på lämpligt sätt, exempelvis per kategori olagligt innehåll som lett till åtgärder.

(24) Valet av metod bör även bero på om bedömningen av uppfyllande kräver att revisionsföretaget tolkar kontextuell information. Valet av metoder bör även anpassas efter de inneboende risker som är kopplade till de aktiviteter som utförs vid tillhandahållandet av tjänsten och det sammanhang i vilket tjänsten tillhandahålls, till exempel om tjänsten innebär försäljning av varor som kan vara olagliga eller om tjänsten främst används av minderåriga. Metoder för att bedöma uppfyllandet av skyldigheten att införa lämpliga och proportionella åtgärder för att säkerställa en hög nivå av integritet, säkerhet och trygghet för minderåriga enligt artikel 28.1 i förordning (EU) 2022/2065 bör till exempel ge revisionsföretaget möjligheten att erhålla en tillräcklig förståelse för hur den tjänst som revisionen avser används av minderåriga, för de risker för deras integritet, säkerhet och trygghet som den kan innebära, samt för innebörden av en lämplig och proportionell åtgärd i det specifika sammanhanget för den tjänst som revisionen avser och minderårigas användning av den. Därför bör revisionsföretagen dela in bedömningen i lämpliga steg. De bör bedöma revisionsriskerna i enlighet med riskprofilen för den leverantör som revisionen avser, i synnerhet huruvida denna leverantör är tillgänglig för eller huvudsakligen används av minderåriga. De bör exempelvis bedöma om leverantören har infört verktyg för ålderssäkring, om dessa är effektiva och hur den leverantör som revisionen avser bedömer och övervakar verktygens effektivitet. De bör bedöma om den leverantör som revisionen avser har infört lämpliga åtgärder för att upptäcka fientlig användning av deras tjänst och beteendemönster som syftar till att skada eller sannolikt kommer att skada minderåriga.

(25) Valet av metod bör även anpassas efter de kontrollrisker som är kopplade till de efterlevnadsåtgärder som införts av den leverantör som revisionen avser, samt efter upptäcktsrisken, det vill säga risken för att inte upptäcka felaktigheter i de uppgifter som leverantören tillhandahåller revisionsföretaget. Till exempel, om en skyldighet som är föremål för revision kan innebära granskning av ett algoritmiskt system som bygger på personlig anpassning efter enskilda användare av den tjänst som revisionen avser och på återkommande uppdateringar av det algoritmiska systemet, såsom rapporteringsskyldigheten avseende rekommendationssystem enligt artikel 27 i förordning (EU) 2022/2065, bör valet av metod göra det möjligt för revisionsföretaget att utforma lämpliga tester för att minimera upptäcktsriskerna. På samma sätt gäller att om revisionsföretaget strävar efter att bedöma om alla relevanta risker begränsats vid utformningen, funktionen och användningen av tillämpningar baserade på storskaliga språkmodeller, såsom chattfunktioner eller rekommendationssystem som införts av den leverantör som revisionen avser, bör revisionsföretaget först bedöma hur ändamålsenliga de kontroller som leverantören infört är. Valet av tester bör göras med beaktande av hur robusta dessa interna kontroller är. I synnerhet, men inte enbart, i de fall där de interna kontrollerna är svaga, ofullständiga eller otillräckliga för att bedöma huruvida reglerna har uppfyllts med beaktande av användarna av den tjänst som revisionen avser bör revisionsförfarandena bygga på en kombination av metoder. Metoderna skulle till exempel kunna omfatta materiella analytiska förfaranden, såsom analys av interaktionerna mellan alla algoritmiska system som är relevanta för rekommendationssystemen och tillhörande regler för beslutsfattande och processer för att fastställa de huvudsakliga parametrarna för dessa rekommendationssystem, samt observationer av digitala arkiv och loggar. Metoderna skulle även kunna inbegripa tester av systemet, till exempel tester i simulerade miljöer.

(26) För att säkerställa att metoden är relevant och anpassas efter nya uppgifter som framkommer under utförandet av revisionen bör valet av metoder vägledas av revisionsföretagets yrkesmässiga bedömning och vid behov justeras efter nya resultat, i synnerhet om revisionsföretaget hyser rimliga tvivel beträffande de uppgifter som lämnats av den leverantör som är föremål för revision. Revisionsföretagets professionella skepsis bör bygga på dess sakkunskap och på andra informationskällor som har särskild relevans för tillämpningen av förordning (EU) 2022/2065, till exempel rapporter från den europeiska nämnden för digitala tjänster, vägledning från kommissionen, revisionsrapporter som utfärdats enligt de uppförandekoder eller krisprotokoll som avses i artiklarna 45, 46 och 48 i den förordningen eller uppgifter som framkommer under utförandet av revisionen, även när det gäller händelser, i synnerhet krissituationer, som kräver ytterligare åtgärder av den leverantör som revisionen avser för att säkerställa uppfyllandet av vissa skyldigheter eller åtaganden som är föremål för revision.

(27) För att säkerställa att tillräckliga revisionsbevis samlas in under revisionen bör revisionsföretag bedöma både de interna kontroller som införts av den leverantör som revisionen avser och utföra substansgranskningsåtgärder för att bedöma leverantörens efterlevnad. I vissa fall bör revisionsföretaget även utföra tester.

(28) Med tanke på komplexiteten hos de algoritmiska system som används av leverantörer av onlineplattformar, och deras viktiga roll när det gäller att uppfylla flera av de skyldigheter som fastställs i förordning (EU) 2022/2065, bör särskild uppmärksamhet ägnas valet av nödvändiga och lämpliga metoder för revision av algoritmiska system. Detta gäller både när de algoritmiska systemen är en del av de kontroller som införts av den leverantör som är föremål för revision och när dessa system i sig är föremål för de skyldigheter eller åtaganden som revisionen avser, såsom när det gäller rekommendationssystem, exempelvis i enlighet med artiklarna 27, 34, 35 och 38 i förordning (EU) 2022/2065, system för annonsering, exempelvis i enlighet med artiklarna 26, 28, 34, 35 och 39 i den förordningen, system för innehållsmoderering, exempelvis i enlighet med artiklarna 14, 15, 34 och 35 i den förordningen, eller något annat algoritmiskt system som bidrar till de risker som avses i artikel 34 i den förordningen.

(29) En kombination av materiella analytiska förfaranden bör även användas, som bygger på bland annat observationer av leverantörens processer och aktiviteter när det gäller utformning, utveckling, drift, testning och övervakning av algoritmiska system, eller observationer av digitala arkiv och loggar som producerats av systemen, enligt vad som är lämpligt. Metoderna bör anpassas efter de särskilda egenskaperna hos algoritmiska system, bland annat styrningen av dem, interaktionen mellan olika algoritmiska system och tillhörande datahanteringssystem, samt tekniken bakom dessa algoritmiska system, såsom generativa modeller eller andra klassificerare eller urvals- eller sökalgoritmer.

(30) Revisionsmetoderna för algoritmiska system bör även omfatta tester, till exempel för att samla in uppgifter som den leverantör som revisionen avser inte tidigare har dokumenterat eller för att oberoende återskapa och bedöma resultatet av exempelvis noggrannhetsindikatorer, tester i sandlådor eller simulerade miljöer eller tester i produktionssystem, bland annat genom dataskrapning eller kontradiktorisk testning.

(31) Eftersom revisionsbevis av hög kvalitet är en förutsättning för att ett revisionsföretag ska kunna formulera ett revisionsuttalande med rimlig tillförlitlighetsnivå bör de uppgifter som revisionsföretaget beslutar att använda som revisionsbevis vara lämpliga och tillräckliga för att minska revisionsriskerna. Revisionsbevisen bör även vara tillförlitliga enligt revisionsföretagets yrkesmässiga bedömning och skepsis och, när så är lämpligt, mot bakgrund av alternativa informationskällor. Yrkesmässig bedömning och skepsis bör inbegripa en kritisk bedömning av revisionsbevis och möjliga felaktigheter. Dessa kvalitetsnormer bör tillämpas på alla revisionsbevis oavsett om de lämnats in av den leverantör som revisionen avser eller samlats in från andra källor.

(32) En mängd informationskällor bör beaktas av revisionsföretaget, såsom bland annat intervjuer med leverantörens personal eller underentreprenörer, inbegripet regelefterlevnadsansvariga, ingenjörer, dataanalytiker, programvaruarkitekter eller medlemmar i arbetsgrupper för internrevision. Det kan även handla om teknisk dokumentation om utformningen, implementeringen, testningen och övervakningen av ett relevant system, bland annat när det gäller datakvalitet och dataförvaltning samt uppdateringar och versioner av systemet, och andra dokument om leverantörens styrnings- och beslutsprocesser, bland annat när det gäller prioriteringar, resurser, fördelning av uppgifter och ansvarsområden eller den relevanta personalens sakkunskap.

(33) För att säkerställa effektivitet och proportionalitet vid utförandet av revisionen bör revisionsföretaget tillåtas att ta stickprov på ett urval av data och uppgifter, med vederbörlig hänsyn till att ett representativt urval bör uppnås, för att revisionsföretaget ska kunna utarbeta ett revisionsuttalande med rimlig tillförlitlighetsnivå. För att säkerställa transparens och reproducerbarhet för revisionsförfarandena bör revisionsföretaget i revisionsrapporten motivera valet av urvalsstorlek och metod för att samla in urvalet. Exempelvis bör urvalsstorleken och metoden väljas med hänsyn till vad som krävs för att uppnå syftet med revisionen beträffande just den skyldighet eller det åtagande som revisionen avser och för att minimera risken för att slutsatsen av revisionen av det specifika urvalet skiljer sig från vad slutsatsen skulle vara om revisionsförfarandet omfattade det fullständiga underlaget. Storleken på och metoden för urvalet bör väljas med hänsyn till revisionens fullständiga omfattning samt till interna eller externa ändringar av den tjänst som revisionen avser under tidsperioden. De särskilda egenskaperna hos de algoritmiska systemen bör också beaktas, bland annat när det gäller personlig anpassning genom profilering. Som en del av detta bör revisionsföretaget exempelvis ta stickprov från de olika grupper eller avgränsningar som kan uppstå till följd av tekniker för personlig anpassning eller identifiera felmarginalen och motivera varför den är på en godtagbar nivå.

(34) I och med att vissa bestämmelser i förordning (EU) 2022/2065 är av ny art är det nödvändigt att fastställa metodologiska principer, bland annat revisionsfrågor och ytterligare riktlinjer för valet av revisionsmetoder och revisionsbevis för bedömningen av efterlevnad av dessa bestämmelser, närmare bestämt för bedömning av efterlevnaden av artiklarna 34, 35 och 36 i förordning (EU) 2022/2065 om utförandet av riskbedömningar och antagandet av riskbegränsningsåtgärder av leverantörer som är föremål för revision, samt om tillämpningen av skyldigheter avseende krisrespons.

(35) Med tanke på att revisionsföretag även bör bedöma leverantörers efterlevnad av artikel 37 i förordning (EU) 2022/2065 bör revisionen dessutom preciseras ytterligare med avseende på vilken bestämmelse som efterlevnadsbedömningen avser, i synnerhet för att undvika eventuella intressekonflikter för revisionsföretaget.

(36) Eftersom uppförandekoderna och krisprotokollen är frivilliga behöver särskilda regler fastställas för bedömning av efterlevnaden av artiklarna 45, 46 och 48 i förordning (EU) 2022/2065, i synnerhet för att säkerställa att revisionsföretagen har tillgång till alla uppgifter som krävs för att utföra revisioner av de specifika skyldigheterna för varje uppförandekod och krisprotokoll.

HÄRIGENOM FÖRESKRIVS FÖLJANDE.

Section I General provisions

Article1Subject matter

This Regulation lays down rules on the performance of audits pursuant to Article 37 of Regulation (EU) 2022/2065, as regards:

a) the procedural steps for ensuring that the auditing organisation to be selected fulfils the conditions laid down in Article 37(3) of Regulation (EU) 2022/2065;

b) the procedural steps for cooperation and assistance by the audited provider in the performance of audits, including accessing relevant information with a view to obtaining audit evidence;

c) the definition and selection of auditing methodologies;

d) the templates for the audit report and the audit implementation report.

Article2Definitions

For the purpose of this Regulation, the following definitions shall apply:

1. ‘auditing organisation’ means an individual organisation, a consortium or other combination of organisations, including any sub-contractors, that the audited provider has contracted to perform an independent audit in accordance with Article 37 of Regulation (EU) 2022/2065;

2. ‘audited service’ means a very large online platform or a very large online search engine designated in accordance with Article 33 of Regulation (EU) 2022/2065;

3. ‘audited provider’ means the provider of an audited service which is subject to independent audits pursuant to Article 37(1) of that Regulation;

4. ‘audited obligation or commitment’ means an obligation or commitment referred to in Article 37(1) of Regulation (EU) 2022/2065 which forms the subject matter of the audit;

5. ‘audit criteria’ means the criteria against which the auditing organisation assesses compliance with each audited obligation or commitment;

6. ‘audit evidence’ means any information used by an auditing organisation to support the audit findings and conclusions and to issue an audit opinion, including data collected from documents, databases or IT systems, interviews or testing performed;

7. ‘misstatement’ means an intentional or unintentional omission, misrepresentation or error in the declarations or data reported or provided by the audited provider to the auditing organisation, or in the testing environment made available by the audited provider to the auditing organisation;

8. ‘audit risk’ means the risk that the auditing organisation issues an incorrect audit opinion or reaches an incorrect conclusion concerning the audited provider’s compliance with an audited obligation or commitment, considering detection risks, inherent risks and control risks with respect to that audited obligation or commitment;

9. ‘detection risk’ means the risk that the auditing organisation does not detect a misstatement that is relevant for the assessment of the audited provider’s compliance with an audited obligation or commitment;

10. ‘inherent risk’ means the risk of non-compliance intrinsically related to the nature, the design, the activity and the use of the audited service, as well as the context in which it is operated, and the risk of non-compliance related to the nature of the audited obligation or commitment;

11. ‘control risk’ means the risk that a misstatement is not prevented, detected and corrected in a timely manner by means of the audited provider’s internal controls;

12. ‘materiality threshold’ means the threshold beyond which deviations or misstatements by the audited provider, individually or aggregated, would reasonably affect the audit findings, conclusions and opinions;

13. ‘reasonable level of assurance’ means a high but not absolute level of assurance, which allows the auditing organisation to assert in its audit opinion and audit conclusions whether the audited provider complies with the audited obligations or commitments, based on sufficient and appropriate evidence;

14. ‘internal control’ means any measures, including processes and tests, that are designed, implemented and maintained by the audited provider, including its compliance officers and management body, to monitor and ensure the audited provider’s compliance with the audited obligation or commitment;

15. ‘vetted researcher’ means a researcher vetted in accordance with Article 40(8) of Regulation (EU) 2022/2065;

16. ‘audit procedure’ means any technique applied by the auditing organisation in the performance of the audit, including data collection, the choice and application of methodologies, such as tests and substantive analytical procedures, and any other action taken to collect and analyse information to collect audit evidence and formulate audit conclusions, not including the issuing of an audit opinion or of the audit report;

17. ‘test’ means an audit methodology consisting in measurements, experiments or other checks, including checks of algorithmic systems, through which the auditing organisation assesses the audited provider’s compliance with the audited obligation or commitment;

18. ‘substantive analytical procedure’ means an audit methodology used by the auditing organisation to assess information to infer audit risks or compliance with the audited obligation or commitment.

Article3Scope of the audit and reasonable level of assurance

1. The audit shall be performed in a manner and for a duration that allows the auditing organisation to assess the audited provider’s compliance with all audited obligations and commitments with a reasonable level of assurance.

2. The audit shall cover the period starting immediately after the period covered by the previous audit and ending on a date that allows the auditing organisation to perform the audit within the time frame required by Article 37(1) of Regulation (EU) 2022/2065, including by asserting its assessment pursuant to paragraph 1 based on the evidence collected and audit procedures conducted during that period, and by completing and submitting the audit report pursuant to Article 37(4) of that Regulation to the audited provider.

3. Where no previous audit was performed, the audit shall cover the period starting four months after the notification referred to in Article 33(6), first subparagraph, of Regulation (EU) 2022/2065, and the duration of the audit shall allow for the audit report pursuant to Article 6(1) to be completed at the latest within a year as from the start of the audited period.

Section II Conditions for the performance of the audit

Article4Selection of the auditing organisation

1. Prior to selecting an auditing organisation with a view to performing the audit, the audited provider shall check whether the organisation to be selected fulfils the requirements laid down in Article 37(3) of Regulation (EU) 2022/2065.

2. Where the auditing organisation to be selected consists of more than one legal person or intends to have recourse to one or several sub-contractors, the audited provider shall check whether all those legal persons or subcontractors:

a) individually fulfil the requirements laid down in Article 37(3), points (a) and (c), of Regulation (EU) 2022/2065;

b) jointly fulfil the requirement laid down in Article 37(3), point (b), of Regulation (EU) 2022/2065.

Article5Cooperation and assistance between the audited provider and the auditing organisation

1. At a time agreed with the auditing organisation, and in any event prior to the performance of any audit procedure, the audited provider shall transmit to the selected auditing organisation at least the following information:

a) a description of the internal controls put in place with respect to each audited obligation and commitment, including related indicators and all present and historical measurements, and benchmarks used by the audited provider to assert or monitor compliance with the audited obligations and commitments, as well as any supporting documentation;

b) its preliminary analysis of inherent and control risks, where the audited provider has performed such an analysis, and any supporting documentation;

c) information about any relevant decision-making structures, competences of departments of the provider, including the compliance function pursuant to Article 41 of Regulation (EU) 2022/2065, relevant IT systems, data sources, processing and storage, as well as explanations of relevant algorithmic systems and their interactions.

2. The audited provider shall grant the auditing organisation, without undue delay, access to all data necessary for the performance of the audit, including personal data, documentation, information on procedures and processes, and to the information technology systems, testing environments, personnel and premises of that provider, and any relevant sub-contractors.

3. The audited provider shall make all necessary resources available and provide the auditing organisation with the assistance and explanations necessary for the auditing organisation to analyse the relevant information and to carry out tests, including where the information requested by the auditing organisation in accordance with Article 37(3) of Regulation (EU) 2022/2065 is held by a third-party contracted by the audited provider.

Section III Performance of audits

Article6Audit report and audit implementation report

1. The audit report referred to in Article 37(4) of Regulation (EU) 2022/2065 shall be established by the auditing organisation, without interference from the audited provider. That audit report shall be drawn up in accordance with the template in Annex I, and shall contain detailed and substantiated conclusions in relation to all elements of the template.

2. Where applicable, the audit implementation report referred to in Article 37(6) of Regulation (EU) 2022/2065 shall be drawn up in accordance with the template in Annex II.

Article7Procedures for the preparations for the audit

1. The audited provider and the auditing organisation shall conclude a written agreement setting out:

a) the exhaustive list of audited obligations and commitments;

b) the responsibilities of the audit organisation, including, where applicable, detailed for each legal person constituting the auditing organisation, and the parties empowered to sign the audit report;

c) the procedures and contact points made available by the audited provider for the auditing organisation to request access to data referred to in Article 5(2);

d) the timeframe for the audit, including the start and end date of the audit procedures and the completion of the audit report;

e) a procedure on how disputes between the audited provider and the auditing organisation arising from the performance of the audit shall be resolved.

2. The agreement referred to in paragraph 1, as well as any other agreements or engagements letters between the auditing organisation and the audited provider related to the performance of the audit, shall be annexed to the audit report.

3. Where changes are made to the agreement referred to in paragraph 1 during the performance of the audit, they shall be made explicit in the audit report.

Article8Audit opinion, audit conclusions and recommendations

1. The audit report shall include the audit conclusions that the auditing organisation has reached on the audited provider’s compliance with each of the audited obligations and commitments. The audit conclusions shall be either:

a) ‘positive’, where the auditing organisation concludes with a reasonable level of assurance that the audited provider has complied with an audited obligation or commitment;

b) ‘positive with comments’, where the auditing organisation concludes with a reasonable level of assurance that the audited provider has complied with an audited obligation or commitment, but:

i) the auditing organisation includes remarks on the benchmarks provided by the audited provider pursuant to Article 5(1), point (a); or

ii) the auditing organisation recommends improvements that do not have a substantive effect on its conclusion;

c) ‘negative’, where the auditing organisation concludes with a reasonable level of assurance that the audited provider has not complied with an audited obligation or commitment.

2. Where an audit report includes operational recommendations pursuant to Article 37(4), point (h) of Regulation (EU) 2022/2065, those recommendations and their recommended timeframe shall be specific to each audited obligation or commitment for which the audit conclusion pursuant to paragraph 1 is ‘positive with comments’ or ‘negative’.

3. Where the operational recommendations referred to in paragraph 2 include specific measures to achieve compliance, they shall be formulated in a way that explains the auditing organisation’s assessment of how such measures would affect the materiality threshold by comparison with the audit conclusion for the respective audited obligation or commitment.

4. On the basis of the audit conclusions, the audit report shall include an audit opinion on the audited provider’s compliance with all audited obligations referred to in Article 37(1), point (a), of Regulation (EU) 2022/2065.

5. On the basis of the conclusions of all audited commitments, the audit report shall include an audit opinion or opinions, as applicable, on the audited provider’s compliance with all audited commitments made by the audited provider under each code of conduct and crisis protocol referred to in Article 37(1), point (b), of Regulation (EU) 2022/2065.

6. Audit opinions pursuant to paragraphs 4 and 5 shall be either:

a) ‘positive’ if the auditing organisation has reached a ‘positive’ audit conclusion for all of the audited obligations or commitments;

b) ‘positive with comments’ if the auditing organisation has reached at least one audit conclusion that is ‘positive with comments’ for an audited obligation or commitment and has not reached a ‘negative’ audit conclusion for any of the audited obligations or commitments;

c) ‘negative’ if the auditing organisation reached a ‘negative’ audit conclusion for at least one audited obligation or commitment.

7. Where the auditing organisation assesses that, for a limited period during the period referred to in Article 3(2), the provider has not complied with an audited obligation or commitment, the audit report shall duly document that assessment.

8. Where the auditing organisation cannot issue with a reasonable level of assurance an audit conclusion pursuant to paragraph 1 or an audit opinion pursuant to paragraphs 4 and 5, the audit report shall include an explanation of the circumstances and the reasons why such a level of assurance could not be achieved.

Section IV Audit methodologies

Article9Audit risks analysis

1. The audit report shall include a substantiated audit risk analysis performed by the auditing organisation for the assessment of the audited provider’s compliance with each audited obligation or commitment.

2. The audit risk analysis shall be carried out prior to the performance of audit procedures and shall be updated during the performance of the audit, in the light of any new audit evidence which, according to the professional judgement of the auditing organisation, materially modifies the assessment of the audit risk.

3. The audit risk analysis shall consider:

a) inherent risks;

b) control risks;

c) detection risks.

4. The audit risk analysis shall be conducted taking into account:

a) the nature of the audited service and the societal and economic context in which the audited service is operated, including probability and severity of exposure to crisis situations and unexpected events;

b) the nature of the obligations and commitments;

c) other appropriate information, including:

i) where applicable, information from previous audits to which the audited service was subjected;

ii) where applicable, information from reports issued by the European Board for Digital Services or guidance from the Commission, including guidelines issued pursuant to Article 35(2) and (3) of Regulation (EU) 2022/2065, and any other relevant guidance issued by the Commission with respect to the application of Regulation (EU) 2022/2065;

iii) where applicable, information from audit reports published pursuant to Article 42(4) of Regulation (EU) 2022/2065 by other providers of very large online platforms or of very large online search engines operating in similar conditions or providing similar services to the audited service.

Article10Appropriate audit methodologies

1. Without prejudice to the specific audit methodologies set out in Articles 13, 14, and 15, audits shall be performed by using appropriate auditing methodologies to reduce the assessed audit risks to a level that enables the auditing organisation to reach audit conclusions at a reasonable level of assurance.

2. The audit report shall include a description of the audit methodologies designed by the auditing organisation prior to performing any audit procedures, including at least:

a) the audit criteria, for assessing compliance with each audited obligation or commitment, defined on the basis of information pursuant to Article 5(1), point (a), and the materiality threshold tolerated and expressed in qualitative or quantitative terms, as appropriate;

b) all tests and substantive analytical procedures and audit evidence that the auditing organisation intends to use to assess compliance for each audited obligation or commitment.

The audit report shall include a description of any changes to the methodologies used during the performance of the audit compared to the methodologies designed prior to performing audit procedures.

3. Where an auditing organisation has reasonable doubts concerning the information assessed in the performance of the audit, in particular as regards information that has been presented by the audited provider, the choice and application of the methodology shall be adapted to afford that organisation the necessary audit evidence in accordance with Article 11.

4. Reasonable doubts referred to in paragraph 3 shall be deemed to arise, in particular, in the presence of any of the following elements:

a) professional judgment and scepticism in assessing information, including concerning internal controls of the audited provider, that leads the auditing organisation to formulate reasonable doubts;

b) external indications pointing to audit risks, in particular reports from the European Board for Digital Services referred to in Article 35(2) of Regulation (EU) 2022/2065, guidance from the Commission including through guidelines referred to in Article 35(3) of that Regulation, and any other relevant guidance issued by the Commission with respect to the application of Regulation (EU) 2022/2065, and audit reports issued pursuant to codes of conduct or crisis protocols referred to in Articles 45, 46 and 48 of that Regulation;

c) information related to events occurring during the performance of the audit, including crisis situations, that require additional actions from the audited provider to ensure compliance with certain audited obligations or commitments.

5. Audit procedures shall include at least:

a) the performance of tests and substantive analytical procedures for the internal controls the audited provider has put in place for each of the audited obligations or commitments;

b) the performance of substantive analytical procedures to assess compliance with each audited obligation and commitment, including as regards algorithmic systems;

c) the performance of tests, including with respect to algorithmic systems, concerning the audited obligations and commitments in relation to which the auditing organisation has reasonable doubts, as referred to in paragraph 4, and concerning audited obligations and commitments where the auditing organisation deems necessary to perform tests in its choice of methodology pursuant to paragraph 1.

6. Where obligations or commitments referred to in Article 37(1) of Regulation (EU) 2022/2065 require the audited provider to report certain information publicly, the auditing methodologies shall include an assessment of whether the reported information is free from material error or omission which might otherwise render them misleading.

Article11Quality of audit evidence

The audit conclusions and audit opinions shall be based on audit evidence which fulfils both of the following requirements:

a) it is relevant and sufficient to reduce audit risks identified in accordance with Article 9, and to enable the auditing organisation to provide audit conclusions and opinions in accordance with Article 8;

b) it is reliable, according to the auditing organisation’s professional judgment and scepticism.

Article12Sampling methods

1. Where audit evidence is based, partially or entirely, on a sample of data or information, the sample size and methodology for sampling shall be selected with a view to minimising the detection risk and without interference by the audited provider.

2. The sample size and methodology for sampling shall be selected in a way that ensures representativeness of the data or information and, as appropriate, in consideration of all of the following:

a) the representativeness of the sample for the period referred to in Article 3(2) and (3);

b) relevant changes to the audited service during that period;

c) relevant changes to the context in which the audited service is provided during that period;

d) relevant features of algorithmic systems, where applicable, including personalisation based on profiling or other criteria;

e) other relevant characteristics or partitions of the data, information and evidence under consideration;

f) the representation and appropriate analysis of concerns related to particular groups as appropriate, such as minors or vulnerable groups and minorities, in relation to the audited obligation or commitment.

3. The audit report shall include a justification of the choice of the sample size and of the methodology for sampling.

Article13Specific methodologies for auditing compliance with Article 34 of Regulation (EU) 2022/2065 on risk assessment

1. The assessment of the audited provider’s compliance with Article 34 of Regulation (EU) 2022/2065 shall include, but not be limited to, an analysis of all of the following:

a) whether the audited provider has diligently identified, analysed, and assessed the systemic risks in the Union referred to in Article 34(1), first subparagraph, of Regulation (EU) 2022/2065, including by assessing:

i) how the audited provider identified the risks that are linked to its service, taking into account regional and linguistic aspects of the use made of its service, including when specific to a Member State, and whether the risks are appropriately identified;

ii) how the audited provider analysed and assessed each risk, including how it considered the probability and severity of the risks, and whether the assessment was appropriate;

iii) how the audited provider identified, analysed and assessed the factors referred to in Article 34(2), first subparagraph, of Regulation (EU) 2022/2065, whether they were appropriately identified, and to what extent such factors influence the risks identified in paragraph 1 of that Article;

iv) what sources of information the audited provider used, how it collected the information, including whether and how it relied on scientific and technical insights;

v) whether and how the audited provider tested assumptions on risks with groups most impacted by the specific risks;

b) whether the risk assessment was performed within the timeframes set out in Article 34(1), second subparagraph, of Regulation (EU) 2022/2065 and, where applicable, within the timeframes set for activities established as risk mitigation measures for the detection of systemic risks pursuant to Article 35(1), point (f) of that Regulation;

c) how the audited provider identified functionalities that are likely to have a critical impact on the risks for which risk assessments shall be conducted prior to their deployment, pursuant to Article 34(1), second subparagraph, of Regulation (EU) 2022/2065, whether those functionalities were correctly identified, and whether the risk assessment was appropriately conducted;

d) whether the audited provider correctly identified the supporting documentation that should be preserved with respect to the risk assessment and whether it has put in place the necessary means to ensure the preservation of that documentation for at least three years, pursuant to Article 34(3) of Regulation (EU) 2022/2065, and whether the documentation was preserved accordingly.

2. Without prejudice to any other analysis necessary for reaching a reasonable level of assurance, methodologies for auditing compliance with Article 34 of Regulation (EU) 2022/2065 shall include at least an assessment by the auditing organisation of the following elements:

a) the internal controls that the audited provider has put in place to monitor the performance of risk assessments regarding each factor referred to in Article 34(2), first subparagraph, of Regulation (EU) 2022/2065; such assessment shall:

i) be based on substantive analytical procedures, for those internal controls;

ii) be based on tests of whether those internal controls are reliable and diligently conceived, executed and monitored;

iii) evaluate how the compliance officer or officers performed their tasks with respect to Article 41(3), points (b), (d), (e) and, where applicable, (f), of Regulation (EU) 2022/2065 and how the management body of the audited provider was involved in the decisions related to risk management pursuant to Article 41(6) and (7) of that Regulation;

b) the actions, means and processes put in place by the audited provider to ensure compliance with Article 34 of Regulation (EU) 2022/2065 and the results thereof; such assessment shall be based on:

i) substantive analytical procedures;

ii) tests, including of algorithmic systems, where the auditing organisation has reasonable doubts, following the results of the substantive analytical procedures and the assessment of internal controls, or where the auditing organisation deems necessary to perform tests in its choice of methodology pursuant to article 10(1).

3. Information analysed by the auditing organisation in support of the assessment carried out pursuant to this Article shall consist of, but not be limited to:

a) the risk assessment report for the relevant audited period, which has been drawn up by the audited including, where necessary, confidential information that is not part of the information published pursuant to Article 42(2) of that Regulation, and all supporting documents;

b) where relevant, other risk assessments reports of the audited provider and their supporting documents;

c) information submitted by the audited provider pursuant to Article 5;

d) all relevant transparency reports of the audited provider referred to in Article 15(1) of Regulation (EU) 2022/2065;

e) any other test results, documentation, evidence, statements made in response to written or oral questions addressed by the auditing organisation to the personnel of the audited provider, and observations made on premises, where applicable;

f) other relevant evidence, including based on information made available by the audited provider;

g) where available, reports referred to in Article 35(2) of Regulation (EU) 2022/2065 and guidance from the Commission, including guidelines issued pursuant to Article 35(3) of that Regulation and any other relevant guidance issued by the Commission with respect to the application of Regulation (EU) 2022/2065.

4. Information analysed by the auditing organisation may comprise, as appropriate, information referred to in Article 42(4) of Regulation (EU) 2022/2065, including from audit, risk assessment and risk mitigation reports, concerning other very large online platforms or very large online search engines, or data and research made publicly available by vetted researchers pursuant to Article 40(8), point (g), of the Regulation.

Article14Specific methodologies for auditing compliance with Article 35 of Regulation (EU) 2022/2065 on mitigation of risks

Ändrad genom rättelse till förordning (EU) 2024/436.

1. The assessment of the audited provider’s compliance with Article 35 of Regulation (EU) 2022/2065 shall include, but not be limited to, an analysis of all of the following:

a) how the audited provider identified risk mitigation measures for each of the systemic risks referred to in Article 34(1) of Regulation (EU) 2022/2065, and whether the identification of such risk mitigation measures was carried out in a diligent manner;

b) how the audited provider assessed whether the risk mitigation measures in Article 35(1), points (a) to (k), of Regulation (EU) 2022/2065 were applicable to the audited service and whether the conclusion of that assessment was appropriate, including as regards those measures which were not applied by the audited provider;

c) whether the mitigation measures put in place by the audited provider are reasonable, proportionate and effective for mitigating the respective risks, including by:

i) assessing whether they respond collectively to all the risks, with particular consideration of the risks concerning the exercise of fundamental rights;

ii) assessing comparatively how the risks were addressed before and after the specific risk mitigation measures were put in place;

iii) assessing whether the risk mitigation measures were appropriately designed and executed.

2. Without prejudice to any other analysis necessary for reaching a reasonable level of assurance, methodologies for auditing compliance with Article 35 of Regulation (EU) 2022/2065 shall include at least an assessment by the auditing organisation of the following elements:

a) the internal controls the audited provider has put in place to monitor the application of risk mitigation measures referred to in Article 35(1) of Regulation (EU) 2022/2065 and whether they are reasonable, proportionate and effective; such assessment shall:

i) be based on substantive analytical procedures for those internal controls;

ii) be based on tests, of whether those internal controls are reliable and diligently conceived, executed and monitored;

iii) evaluate how the compliance officer or officers performed their tasks with respect to Article 41(3), points (b), (d), (e) and, where applicable, (f), of Regulation (EU) 2022/2065, and how the management body of the provider was involved pursuant to Article 41(6) and (7) of that Regulation;

b) mitigation measures put in place by audited providers; such assessment shall be based on:

i) substantive analytical procedures;

ii) tests, including of algorithmic systems, where the auditing organisation has reasonable doubts, following the results of the substantive analytical procedures and the assessment of internal controls, or where the auditing organisation deems necessary to perform tests in its choice of methodology pursuant to Article 10(1).

3. Information analysed by the auditing organisation in support of the assessment carried out pursuant to this Article shall consist of, but not be limited to:

a) the reports on risk assessment and risk mitigation for the relevant audited period, which have been drawn up by the audited provider including, where necessary, confidential information that is not part of the information published pursuant to Article 42(2) of Regulation (EU) 2022/2065, and all supporting documents;

b) where relevant, other reports on risk assessment and risk mitigation of the audited provider and their supporting documents;

c) information submitted by the audited provider pursuant to Article 5;

d) all relevant transparency reports of the audited provider referred to in Article 15(1) of Regulation (EU) 2022/2065;

e) where relevant, past reports on risk mitigation and their supporting documents, which concern periods not covered by the audited period, including, where necessary, confidential information that is not part of the information published pursuant to Article 42(2) of Regulation (EU) 2022/2065;

f) any other test results, documentation, evidence, statements made in response to written and or oral questions addressed by the auditing organisation to the personnel of the audited provider, and observations made on premises, where applicable;

g) other relevant evidence, including based on information made available by the audited provider;

h) where available, reports referred to in Article 35(2) of Regulation (EU) 2022/2065 and guidance from the Commission, including guidelines issued pursuant to Article 35(3) of that Regulation and any other relevant guidance issued by the Commission with respect to the application of Regulation (EU) 2022/2065.

4. Information analysed by the auditing organisation may comprise, as appropriate, information referred to in Article 42(4) of Regulation (EU) 2022/2065, including from audit, risk assessment and risk mitigation reports, concerning other very large online platforms or very large online search engines, or data and research made publicly available by vetted researchers pursuant to Article 40(8), point (g), of Regulation (EU) 2022/2065.

Article15Specific methodologies for auditing compliance with Article 36 of Regulation (EU) 2022/2065 on crisis response mechanism

1. The assessment of the audited provider’s compliance with Article 36(1), first subparagraph, point (a) of Regulation (EU) 2022/2065 shall include, but not be limited to, an analysis of whether and how the audited provider performed the required actions, in particular:

a) whether and how the audited provider identified the relevant systems involved in the functioning and use of their service that significantly contribute to the serious threat and whether those systems were appropriately identified;

b) whether and how the audited provider defined and monitored the significant contribution to the serious threat and whether its assessment was appropriate;

c) any other requirement specified in the Commission’s decision referred to in Article 36(1) or (7), second subparagraph, of Regulation (EU) 2022/2065, as appropriate.

2. The assessment of the audited provider’s compliance with Article 36(1), first subparagraph, point (b), of Regulation (EU) 2022/2065 shall include, but not be limited to, an analysis of whether and how the audited provider performed the required actions, in particular:

a) whether and how the audited provider identified measures to prevent, eliminate or limit any contribution to the serious threat;

b) whether and how the measures taken by the audited provider addressed the gravity of the serious threat, the urgency, and whether the measures were appropriate in this respect;

c) whether and how the audited provider identified the parties concerned by the measures and their legitimate interests, and how the audited provider assessed the actual or potential impact of the measures on those parties’ rights, including fundamental rights, and legitimate interests;

d) whether the measures taken by the audited provided were effective and proportionate;

e) any other requirement specified in the Commission’s decision referred to in Article 36(1) or (7), second subparagraph, of Regulation (EU) 2022/2065, as appropriate.

3. The assessment of the audited provider’s compliance with Article 36(1), first subparagraph, point (c) of Regulation (EU) 2022/2065, shall include, but not be limited to, an analysis of how the audited provider performed the required action, in particular whether the audited provider provided to the Commission the information required in the Commission’s decision referred to in Article 36(1) or (7), second subparagraph, of Regulation (EU) 2022/2065, and whether those reports were accurate.

Article16Auditing compliance with Article 37 of Regulation (EU) 2022/2065 on independent audit

1. Compliance with the obligations laid down in Article 37 of Regulation (EU) 2022/2065 and in this Regulation shall be assessed in relation to the audit or audits performed for the yearly period preceding that of the current audit.

2. In addition to paragraph 1, the audit shall include an assessment of the audited provider’s compliance with Article 37(2) of Regulation (EU) 2022/2065 with respect to the current audit.

3. Where the previous audit or audits referred to in paragraph 1 were performed by the same auditing organisation as the current audit, or where the auditing organisation carrying out the current audit comprises at least one legal entity which participated in the previous audit, the audit report shall include an explanation of the steps put in place by the auditing organisation to ensure the objectivity of the assessment.

Article17Auditing compliance with codes of conduct and crisis protocols

1. The audited provider shall make available to the auditing organisation:

a) a list and the text of all codes of conduct referred to in Articles 45 and 46 of Regulation (EU) 2022/2065 and crisis protocols referred to in Article 48 of that Regulation, to which the audited provider is a signatory;

b) a detailed list of commitments within those codes of conduct and crisis protocols that the audited provider has taken;

c) where applicable, the key performance indicators agreed under each code of conduct and crisis protocol;

d) where applicable, any available measurements, data and documentation, and any reports prepared by the audited provider with respect to the compliance of the audited provider with the commitments taken, including access to all relevant information and data related to the functioning of the services offered by the audited provider relevant to the implementation of the code of conduct or the crisis protocol;

e) where applicable, other measurements, data and documentation prepared by signatories of the code of conduct or the crisis protocol, and the assessments by the Commission or the Board referred to in Article 45(4) of Regulation (EU) 2022/2065.

2. The assessment of the audited provider’s compliance with codes of conduct referred to in Article 45 of Regulation (EU) 2022/2065 shall include, but not be limited to, the measurement of key performance indicators agreed in the code of conduct pursuant to Article 45(3) of that Regulation, specifying the materiality threshold of the audit conclusions, and whether the reported data is accurate.

Section V Final provisions

Article18Entry into force

This Regulation shall enter into force on the twentieth day following that of its publication in the Official Journal of the European Union.

ANNEX I

Table of contents

SECTION B: Auditing organisation(s)
To complete the section below, insert as many lines as necessary per point.
1. Name(s) of organisation(s) constituting the auditing organisation: …
2. Information about the auditing team of the auditing organisation: For each member of the auditing team, provide: 1. their personal name; 2. the individual organisation, part of the auditing organisation, they are affiliated with; 3. their professional email address; 4. descriptions of their responsibilities and the work they undertook during the audit. …
3. Auditors’ qualifications: … a. Overview of the professional qualifications of the individuals who performed the audit, including domains of expertise, certifications, as applicable: … b. Documents attesting that the auditing organisation fulfils the requirements laid down in Article 37(3), point (b) of Regulation (EU) 2022/2065 have been attached as an annex to this report: …
4. Auditors’ independence: a. Declaration of interests: … b. References to any standards relevant for the auditing team’s independence that the auditing organisation(s) adheres to: … c. List of documents attesting that the auditing organisation complies with the obligations laid down in Article 37(3), points (a) and (c) of Regulation (EU) 2022/2065 attached as annexes to this report: …
5. References to any auditing standards applied in the audit, as applicable: …
6. References to any quality management standards the auditing organisation adheres to, as applicable: …
SECTION F.1: Third-parties consulted
Repeat this section per third-party consulted, incrementing the name of the section by one (for example, F.1, F.2, and so forth).
1. Name of third party consulted: …
2. Representative and contact information of consulted third party: …
3. Date(s) of consultation: …
4. Input provided by third-party: …
SECTION G: Any other information the auditing body wishes to include in the audit report (such as a description of possible inherent limitations).
Include as many lines as necessary in accordance with the allocation of responsibilities and empowerment as referred to in Article 7(1) point (b)
Date:
Signed by:
Place:
In the name of:
Responsible for:

Annexes to the Audit Report (as applicable):

Documents requested pursuant to Article 7(2) of this Regulation.

Documents relating to the audit risk analysis pursuant to Article 9 of this Regulation.

Documents attesting that the auditing organisation complies with the obligations laid down in Article 37(3), point (a) of Regulation (EU) 2022/2065.

Documents attesting that the auditing organisation complies with the obligations laid down in Article 37(3), point (b) of Regulation (EU) 2022/2065.

Documents attesting that the auditing organisation complies with the obligations laid down in Article 37(3), point (c) of Regulation (EU) 2022/2065.

Documentation and results of any tests performed by the auditing organisation, including as regards algorithmic systems of the audited provider.

Codes of conduct referred to in Article 45 and 46 of Regulation (EU) 2022/2065 under which the audited provider made commitments, including a clear indication of any commitment undertaken and of any agreed key performance indicator for that commitment.

Crisis protocols referred to in Article 48 of Regulation (EU) 2022/2065 implemented by the audited provider.

Any other annex the auditing organisation wishes to include.

ANNEX II

Table of contents

SECTION A: General Information
1. Audited provider: …
2. Address of the audited provider: …
3. Audit report on which this implementation report is based Date of adoption of the audit report: … Reference to the audit report (for example an URL): …
4. Information on the underlying audit and the involved parties (refer to sections A and B of the audit report of reference): …
5. Does the audit implementation report refer to an audit report on compliance with all the obligations and commitments pursuant to Article 37(1) of Regulation (EU) 2022/2065 applicable to the audited provider? Yes/No (if ‘No’, indicate which obligations and commitments are covered in the audit report of reference) …
6. Where applicable, references to other audit reports resulting from audits pursuant to Article 37 of Regulation (EU) 2022/2065 that the audited provider is or will be subject to concerning the audited period: …