CADA tracker · source extraction
(56)
The audit report should be substantiated to give a meaningful account of the activities
undertaken and the conclusions reached during the audit. It should help provide
information for, and where appropriate suggest improvements to, the measures taken
by the cloud computing service providers to comply with the applicable criteria and
their obligations under this Regulation. The audit report should include an audit
opinion based on the conclusions drawn from the audit evidence obtained. A ‘positive
opinion’ should be given where all evidence shows that the provider complies with the
audit criteria and obligations set out by this Regulation. A ‘negative opinion’ should
be given where the auditing organisations considers that the provider does not comply
with the criteria set out in this Regulation. Where the audit opinion cannot reach a
conclusion on specific aspects that fall within the scope of the audit, an explanation of
the reasons why this was not possible should be included in the audit opinion. Where
applicable, the report should include a description of specific points that could not be
audited, and an explanation as to why they could not.