CADA tracker · source extraction

Article 20

printed pages 54–56 · source locator: Article 20 occurrence 1; printed pages 54–56

Official source: COM(2026) 502 final — Proposal for a Cloud and AI Development Act

Article 20

Independent audit
     1.   Cloud computing service providers seeking recognition in accordance with Article
          17 as offering Union assurance level 2, 3, or 4, shall undergo at their own expense,
          independent third-party audits to obtain an audit report and an audit opinion from an
          auditing organisation. An audited provider undergoing an audit procedure at a higher
          Union assurance level shall satisfy all the applicable cumulative criteria under Annex
          II applicable to the lower Union assurance levels. Failure to meet any requirements
          of a lower assurance level shall preclude conformity with the higher Union assurance
          levels.

     2.   Audited providers shall cooperate with auditing organisations and provide them
          assistance necessary to enable them to conduct those audits in an effective, efficient
          and timely manner, including by giving them access to all relevant data and premises
          and by answering oral or written questions. Audited providers shall refrain from
          hampering, unduly influencing or undermining the performance of the audit.
     3.   Auditing organisations shall ensure an adequate level of confidentiality and
          professional secrecy in respect of the information obtained from the audited
          providers and third parties as part of the audits, including after the audits have ended.
          That requirement shall not adversely affect the performance of the audits and other
          provisions of this Regulation. Under Article 23, the auditing organisation shall only
          share information that are necessary for the reporting purposes and do not contain
          any information that could reasonably be considered confidential.
     4.   Audits referred to paragraph 1 shall be performed by auditing organisations that:
          (a)   are independent from, and do not have any conflicts of interest with, the cloud
                computing service provider concerned, and any legal person connected to that
                provider, in particular:
                i.     have not provided non-audit services related to the matters audited to the
                       cloud computing service provider concerned or to any legal person
                       connected to that provider in the 12-month period before the beginning of
                       the audit, and have committed to not providing them with such services
                       in the 12-month period after the completion of the audit;
                ii.    have not provided auditing services pursuant to this Article to the cloud
                       computing service provider concerned or any legal person connected to
                       that provider in the 10-year period before the beginning of the audit;
                iii.   are not performing the audit in return for fees that are contingent on the
                       result of the audit;
          (b)   have proven expertise, technical competence and capabilities in auditing cloud
                computing services;
          (c)   have proven objectivity and professional ethics, based in particular on
                adherence to codes of practice or appropriate standards.
     5.   Auditing organisations that perform the audits shall prepare an audit report for each
          audit. That report shall be substantiated, in writing, and shall include at least the
          following:
          (a)   the name, address and point of contact of the provider subject to the audit, and
                the period covered;
          (b)   the name and address of the auditing organisation or organisations performing
                the audit;
          (c)   a declaration of interests;
          (d)   a description of the specific aspects audited, and the methodology applied;
          (e)   a description and a summary of the main findings drawn from the audit;
          (f)   a list of the third parties consulted as part of the audit;
          (g)   a ‘positive’ or ‘negative’ audit opinion and any information on whether the
                audited service of the audited provider complies with the applicable audit
                criteria for Union assurance level 2, 3 or 4 pursuant to Annex II;

          (h)   where the audit opinion is ‘negative’, operational recommendations on specific
                measures to achieve compliance and the recommended timeframe to achieve
                compliance;
          (i)   where the audit opinion is ‘positive’, the Union assurance level that needs to be
                recognised under Article 17, issued to the audited service of the audited
                provider pursuant to the applicable criteria set out in Annex II.
     6.   Where the auditing organisation was unable to audit certain aspects or to express an
          audit opinion based on its investigations, the audit report shall include an explanation
          of the circumstances and the reasons why those aspects could not be audited.
     7.   The auditing organisation may revoke its audit report and audit opinion where the
          audited provider, intentionally or negligently, supplied incorrect or misleading audit
          evidence.
     8.   The audited provider shall annually submit for review the audit report and the
          associated ‘positive’ audit opinion to the same or a different auditing organisation
          which shall assess the continued compliance of the audited service with the
          applicable criteria set out in Annex II. On the basis of the annual review, the auditing
          organisation may confirm, update, or revoke the initial audit report and audit opinion.
     9.   The Commission is empowered to adopt delegated acts in accordance with Article 45
          to supplement this Regulation by laying down rules on the performance of audits on
          the procedural steps, rules for auditing organisations and their technical
          competences, auditing methodologies and templates for the audit reports.

Qualifications