CADA tracker · source extraction
(55)
Independent audits are an important tool for monitoring the compliance of cloud
compuring services provided by cloud computing service. Given the need to ensure
that the applicable criteria for Union assurance levels 2, 3 or 4 are verified by third-
party independent experts, cloud computing service providers should be accountable,
through independent auditing, for their compliance with the criteria set out by this
Regulation. Cloud computing service providers should be free to select the auditing
organisation of their choice as long as the auditing organisation demonstrates the
necessary independence and compliance with the requirements in this Regulation. To
ensure that audits are carried out in an effective, efficient and timely manner, cloud
computing service providers should provide the necessary cooperation and assistance
to the organisations carrying out the audits, including by giving the auditing
organisations access to all relevant data and premises necessary to perform the audit
properly and answering oral or written questions. Auditing organisations should also
be able to make use of other sources of objective information. Cloud computing
service providers should not undermine the performance of the audit. Audits should be
performed in accordance with best industry practices and high professional ethics and
objectivity, with due regard for auditing standards and codes of practice. Auditing
organisations should guarantee the confidentiality, security and integrity of the
information, such as trade secrets, that they obtain when performing their tasks. That
guarantee should not be a means to circumvent the applicability of audit obligations in
this Regulation. Auditing organisations should have the necessary expertise in risk
management and technical competence to audit cloud computing services. They
should comply with core independence requirements for prohibited non-auditing
services, firm rotation and non-contingent fees. If their independence or technical
competence of auditing organisations is not beyond doubt, they should abstain or
resign from the audit engagement.