CADA tracker · source extraction
Article 20
Independent audit
1. Cloud computing service providers seeking recognition in accordance with Article
17 as offering Union assurance level 2, 3, or 4, shall undergo at their own expense,
independent third-party audits to obtain an audit report and an audit opinion from an
auditing organisation. An audited provider undergoing an audit procedure at a higher
Union assurance level shall satisfy all the applicable cumulative criteria under Annex
II applicable to the lower Union assurance levels. Failure to meet any requirements
of a lower assurance level shall preclude conformity with the higher Union assurance
levels.
2. Audited providers shall cooperate with auditing organisations and provide them
assistance necessary to enable them to conduct those audits in an effective, efficient
and timely manner, including by giving them access to all relevant data and premises
and by answering oral or written questions. Audited providers shall refrain from
hampering, unduly influencing or undermining the performance of the audit.
3. Auditing organisations shall ensure an adequate level of confidentiality and
professional secrecy in respect of the information obtained from the audited
providers and third parties as part of the audits, including after the audits have ended.
That requirement shall not adversely affect the performance of the audits and other
provisions of this Regulation. Under Article 23, the auditing organisation shall only
share information that are necessary for the reporting purposes and do not contain
any information that could reasonably be considered confidential.
4. Audits referred to paragraph 1 shall be performed by auditing organisations that:
(a) are independent from, and do not have any conflicts of interest with, the cloud
computing service provider concerned, and any legal person connected to that
provider, in particular:
i. have not provided non-audit services related to the matters audited to the
cloud computing service provider concerned or to any legal person
connected to that provider in the 12-month period before the beginning of
the audit, and have committed to not providing them with such services
in the 12-month period after the completion of the audit;
ii. have not provided auditing services pursuant to this Article to the cloud
computing service provider concerned or any legal person connected to
that provider in the 10-year period before the beginning of the audit;
iii. are not performing the audit in return for fees that are contingent on the
result of the audit;
(b) have proven expertise, technical competence and capabilities in auditing cloud
computing services;
(c) have proven objectivity and professional ethics, based in particular on
adherence to codes of practice or appropriate standards.
5. Auditing organisations that perform the audits shall prepare an audit report for each
audit. That report shall be substantiated, in writing, and shall include at least the
following:
(a) the name, address and point of contact of the provider subject to the audit, and
the period covered;
(b) the name and address of the auditing organisation or organisations performing
the audit;
(c) a declaration of interests;
(d) a description of the specific aspects audited, and the methodology applied;
(e) a description and a summary of the main findings drawn from the audit;
(f) a list of the third parties consulted as part of the audit;
(g) a ‘positive’ or ‘negative’ audit opinion and any information on whether the
audited service of the audited provider complies with the applicable audit
criteria for Union assurance level 2, 3 or 4 pursuant to Annex II;
(h) where the audit opinion is ‘negative’, operational recommendations on specific
measures to achieve compliance and the recommended timeframe to achieve
compliance;
(i) where the audit opinion is ‘positive’, the Union assurance level that needs to be
recognised under Article 17, issued to the audited service of the audited
provider pursuant to the applicable criteria set out in Annex II.
6. Where the auditing organisation was unable to audit certain aspects or to express an
audit opinion based on its investigations, the audit report shall include an explanation
of the circumstances and the reasons why those aspects could not be audited.
7. The auditing organisation may revoke its audit report and audit opinion where the
audited provider, intentionally or negligently, supplied incorrect or misleading audit
evidence.
8. The audited provider shall annually submit for review the audit report and the
associated ‘positive’ audit opinion to the same or a different auditing organisation
which shall assess the continued compliance of the audited service with the
applicable criteria set out in Annex II. On the basis of the annual review, the auditing
organisation may confirm, update, or revoke the initial audit report and audit opinion.
9. The Commission is empowered to adopt delegated acts in accordance with Article 45
to supplement this Regulation by laying down rules on the performance of audits on
the procedural steps, rules for auditing organisations and their technical
competences, auditing methodologies and templates for the audit reports.