CADA tracker · source extraction

Recital (56)

printed pages 28–29 · source locator: Recital (56); printed pages 28–29

Official source: COM(2026) 502 final — Proposal for a Cloud and AI Development Act

(56)

The audit report should be substantiated to give a meaningful account of the activities
            undertaken and the conclusions reached during the audit. It should help provide
            information for, and where appropriate suggest improvements to, the measures taken
            by the cloud computing service providers to comply with the applicable criteria and
            their obligations under this Regulation. The audit report should include an audit
            opinion based on the conclusions drawn from the audit evidence obtained. A ‘positive
            opinion’ should be given where all evidence shows that the provider complies with the
            audit criteria and obligations set out by this Regulation. A ‘negative opinion’ should

            be given where the auditing organisations considers that the provider does not comply
            with the criteria set out in this Regulation. Where the audit opinion cannot reach a
            conclusion on specific aspects that fall within the scope of the audit, an explanation of
            the reasons why this was not possible should be included in the audit opinion. Where
            applicable, the report should include a description of specific points that could not be
            audited, and an explanation as to why they could not.

Qualifications