§ 04 Guide 4 / 4

Unrestricted audit rights, and the evidence pack that survives them

Updated 10 min read dorasupplier.eu

Audit clauses are the part of a DORA addendum suppliers skim, because every enterprise contract has one. This one is different: it names three parties, it overrides your other contract terms, it flows down to your subcontractors, and a separate delegated regulation tells your customer it may not rely on your certificate alone. This guide sets out exactly what was granted and what to have ready before the first request arrives.

What Article 30(3)(e) actually grants

The clause is a right to monitor your performance “on an ongoing basis”, and it is broken into four sub-points. The first is the one that matters.

unrestricted rights of access, inspection and audit by the financial entity, or an appointed third party, and by the competent authority, and the right to take copies of relevant documentation on-site if they are critical to the operations of the ICT third-party service provider, the effective exercise of which is not impeded or limited by other contractual arrangements or implementation policies

Three parties, not one: the financial entity, a third party it appoints, and the competent authority. The right extends to taking copies of documentation on site. And the closing subordinate clause is a conflict rule: no other contractual arrangement and no implementation policy may impede or limit the effective exercise of the right. A confidentiality term elsewhere in your master agreement, a security policy that forbids visitors to the data centre, or a standard clause limiting audits to one per year does not survive it.

The remaining sub-points fill in the shape. Point (ii) allows the parties “to agree on alternative assurance levels if other clients’ rights are affected”. Point (iii) obliges you to “fully cooperate during the onsite inspections and audits performed by the competent authorities, the Lead Overseer, financial entity or an appointed third party”. Point (iv) obliges the contract to “provide details on the scope, procedures to be followed and frequency of such inspections and audits”.

One derogation exists, and it will not help you. The final subparagraph of Article 30(3) allows the audit right to be delegated to an independent third party appointed by the provider, but only where the financial entity is a microenterprise: fewer than ten staff and turnover or balance sheet total not exceeding EUR 2 million, per Article 3(60). Banks and insurers are not microenterprises.

Unrestricted is not unlimited: use Article 28(6)

The counterweight sits in a different article, and most suppliers never read it. Article 28(6) obliges the financial entity, when exercising access, inspection and audit rights, to “on the basis of a risk-based approach, pre-determine the frequency of audits and inspections as well as the areas to be audited through adhering to commonly accepted audit standards in line with any supervisory instruction on the use and incorporation of such audit standards”.

Ask for that plan. It is your customer’s own obligation, not a concession, and getting it in writing converts an unrestricted right into a schedulable one. The same article adds a second useful sentence: where the arrangement entails high technical complexity, the entity “shall verify that auditors, whether internal or external, or a pool of auditors, possess appropriate skills and knowledge to effectively perform the relevant audits and assessments”. If a generalist audit team is booked for a week on your platform, that clause is the polite way to raise it.

The audit surface, and who can reach it
WhoWhat they may doBasis
The financial entityAccess, inspect and audit without restriction, take copies of documentation on siteArt. 30(3)(e)(i)
A third party it appointsThe same rights, exercised on its behalfArt. 30(3)(e)(i)
The competent authorityThe same rights, plus on-site inspection you must fully cooperate withArt. 30(3)(e)(i), (iii)
The Lead OverseerOn-site inspections and audits you must fully cooperate withArt. 30(3)(e)(iii)
Several entities jointlyPooled audits and pooled ICT testing, including threat-led penetration testingRTS 2024/1773, Art. 8(2)(b)
Your own subcontractorsMust grant the entity and the authorities the same rights you grantedRTS 2025/532, Art. 4(1)(j)

Why your certificate is not enough, in the Regulation’s own words

Commission Delegated Regulation (EU) 2024/1773 specifies the policy every financial entity must adopt for contracts covering critical or important functions. Its Article 8(2) lists the assurance methods the contract must allow: the entity’s own internal audit or an appointed third party; pooled audits and pooled ICT testing, including threat-led penetration testing, organised jointly with other firms that use the same provider; third-party certifications; and internal or third-party audit reports the provider makes available.

Article 8(3) then constrains the last two.

The financial entity shall not over time rely solely on certifications referred to in paragraph 2, point (c), or audit reports referred to in point (d) of that paragraph.

Reliance is permitted only where the entity is satisfied with your audit plan for the arrangement; ensures the scope of the certification or report covers “the systems and key controls identified by it” and compliance with the relevant regulatory requirements; thoroughly assesses the content on an ongoing basis and verifies that the reports are not obsolete; ensures key systems and controls are covered in future versions; is satisfied with the aptitude of the certifying or auditing party; is satisfied that the work was done against widely recognised professional standards and “include[s] a test of the operational effectiveness of the key controls in place”; retains the contractual right to request scope changes with a reasonable frequency; and retains the contractual right to perform individual and pooled audits at its discretion.

Two of those conditions do real work against a supplier. The scope test is external: it is the systems and key controls the entity identified, not the ones your certification body happened to include. And the operational-effectiveness test rules out any assurance product that only checks control design. An ISO/IEC 27001 certificate shortens the conversation; it does not end it, and a supplier that offers only a certificate is offering something the Regulation has already told the customer not to accept on its own.

What your customer must ask you for, and why

The due-diligence and monitoring questions in a financial-sector questionnaire are not arbitrary. Nearly all of them trace to a specific obligation on the customer, and knowing which one turns an interrogation into a negotiation.

  • Article 6(1) of the delegated regulation sets the pre-contract assessment: business reputation, abilities, expertise, financial, human and technical resources, information security standards, organisational structure, risk management and internal controls; the ability to monitor technological developments; whether you use ICT subcontractors; whether you are located or process data in a third country; whether you consent to arrangements that make on-site audits effectively possible; and whether you act ethically and respect human rights, environmental principles and appropriate working conditions.
  • Article 6(3) lists what may serve as the required assurance: audits or independent assessments by or for the entity, independent audit reports you commission, your internal audit reports, appropriate third-party certifications, or other relevant information. Article 6(4) says more than one element shall be used where appropriate.
  • Article 9(2)(a) requires you to provide “appropriate reports on their activities and services … including periodic reports, incidents reports, service delivery reports, reports on ICT security and reports on business continuity measures and testing”.
  • Article 9(2)(b) tells the entity to assess your performance using key performance indicators, key control indicators, audits, self-certifications and independent reviews.
  • Article 10 requires a documented, periodically reviewed and tested exit plan per arrangement that is “realistic, feasible, based on plausible scenarios and reasonable assumptions”. Your transition obligations under Article 30(3)(f) are the supplier half of it.

The annual data request, and where it comes from

Separately from assurance, a data request arrives every year. Article 28(3) requires every financial entity to maintain a register of information on all its ICT contracts, at entity, sub-consolidated and consolidated level, documented so as to distinguish critical-function contracts from the rest, and to make it available to its competent authority. Implementing Regulation (EU) 2024/2956 sets the templates.

Two of its rules land on you directly. Article 3(5) requires the entity to identify every provider that is a legal person by a valid and active LEI or the European Unique Identifier, and both where available; third-country providers are identified by LEI only. Article 3(6) requires the entity to ensure, through you, that every subcontractor which effectively underpins a critical-function service also has a valid LEI or provides its EUID.

Annex III sets the service taxonomy your contract is filed under, S01 to S19, from ICT project management through ICT security management services and non-cloud data storage to the three cloud codes for IaaS, PaaS and SaaS. Pick your codes deliberately: the classification travels with your name into a supervisory filing, and it is what the ESAs aggregated when they designated the nineteen critical providers in November 2025.

The filing dates are national. Latvijas Banka states that after the first submission, due 15 April 2025 on 31 March 2025 data, financial entities file annually by 1 March using the previous year’s 31 December data. From the supplier’s side that means the confirmation request arrives in January or February, from every financial customer, every year.

One pack, not one per customer

The single highest-leverage decision here is to stop answering each customer separately. The obligations that generate the questions are the same across every financial entity in the Union, which means the artefacts can be too.

  1. Identity and classification. LEI and EUID for your entity and for every subcontractor underpinning a critical-function service, plus your chosen S01 to S19 codes and the countries of provision, processing and storage.
  2. Contract map. Which of your arrangements sit under Article 30(2) and which under Article 30(3), with the customer’s written determination attached to each.
  3. Independent test. A current penetration test or independent assessment, with a scope statement that names systems and controls rather than IP ranges, so a customer can check it against the ones it identified under Article 8(3)(b) of the delegated regulation.
  4. Control evidence. Certification and its statement of applicability, plus operational-effectiveness evidence for the key controls, because the certificate alone fails Article 8(3)(f).
  5. Operational reporting. The periodic, incident, service delivery, ICT security and business continuity reports named in Article 9(2)(a), on a cadence and in a format you defined rather than one negotiated four times.
  6. Continuity and exit. Contingency plans that have been tested under Article 30(3)(c), and a rehearsed transition plan matching the mandatory transition period in Article 30(3)(f).
  7. Subcontractor chain. The list, the identifiers, the flow-down audit clause required by Article 4(1)(j) of Delegated Regulation (EU) 2025/532, and the material-change notification process in its Article 5.
  8. Audit calendar. The frequency and areas your customers have pre-determined under Article 28(6), consolidated into one schedule so that four customers do not each pick the same week in November.

Point eight is where Article 30(3)(e)(ii) earns its place. “The right to agree on alternative assurance levels if other clients’ rights are affected” is the textual basis for proposing a pooled audit programme, and Article 8(2)(b) of the delegated regulation expressly contemplates pooled audits and pooled ICT testing organised jointly by firms that use the same provider. Proposing that programme yourself, with a published calendar and a shared independent test report, is both cheaper than four separate audits and a stronger signal than resisting any of them.

The same logic extends to testing. Where the customer relationships justify it, the pooled route in Article 26(4) lets you contract the external tester for a threat-led exercise covering several financial customers at once. The TLPT guide covers how that works. If you are still at the drafting stage, the addendum guide sets out where to put the audit calendar and the assurance route in the negotiation order.

Sources

  1. Regulation (EU) 2022/2554 (DORA), Articles 28, 30(3)(e) and 3(60) EUR-Lex · 2022
  2. Commission Delegated Regulation (EU) 2024/1773, Articles 6, 8, 9 and 10 EUR-Lex · 2024
  3. Commission Delegated Regulation (EU) 2025/532, Articles 4 and 5 EUR-Lex · 2025
  4. Commission Implementing Regulation (EU) 2024/2956, Article 3 and Annex III EUR-Lex · 2024
  5. Informācijas reģistra (RoI) iesniegšana: register of information submission dates Latvijas Banka · 2026

Related questions

Can we limit audits to once a year in the contract?

Not unilaterally, and not by a term elsewhere in your paper. Article 30(3)(e)(i) states that the effective exercise of the rights must not be “impeded or limited by other contractual arrangements or implementation policies”. What you can do is rely on your customer’s own duty under Article 28(6) to pre-determine, on a risk basis, the frequency and areas of audits and inspections, and ask for that plan in writing.

Do we have to let a competitor audit us?

The right extends to “an appointed third party”, and the Regulation does not name who that may be. Article 30(3)(e)(ii) allows the parties to agree alternative assurance levels where other clients’ rights are affected, which is the right hook for objecting to a specific appointee and proposing an alternative, such as a pooled audit or an independent assessor acceptable to both sides. Refusing the concept of an appointed auditor is not available.

Does the competent authority really turn up at our offices?

It can, and Article 30(3)(e)(iii) obliges you to cooperate fully with on-site inspections by the competent authorities, the Lead Overseer, the financial entity or its appointee. In practice most supervisory attention reaches suppliers through the entity rather than directly, because the entity remains fully responsible under Article 28(1)(a). The right exists regardless, and a security policy that has no visitor process for it is a finding waiting to happen.

We are a subcontractor, not the direct provider. Are we exposed?

Yes, where the service supports a critical or important function. Delegated Regulation (EU) 2025/532, Article 4(1)(j), requires the direct provider’s contract to specify that the subcontractor grants the financial entity and the relevant competent and resolution authorities the same rights of access, inspection and audit as Article 30(3)(e). Implementing Regulation (EU) 2024/2956, Article 3(6), also requires you to hold an LEI or supply an EUID.

What counts as a current independent test report?

The Regulation does not set a validity period, and any site that quotes one is inventing it. What the delegated regulation does require, in Article 8(3)(c), is that the financial entity assess the content on an ongoing basis and verify that reports and certifications “are not obsolete”. In practice that means a test dated inside the customer’s own assurance cycle, retested after significant change, with a scope statement that maps to the systems and key controls the customer identified.

Can we charge for audit support?

The Regulation is silent, so the contract decides, and the time to decide is at signature. Article 30(2)(f) shows the drafting pattern: assistance at no additional cost, or at a cost determined ex ante. Applying the same structure to audit support, evidence production and questionnaire responses is reasonable, and it is far easier to agree before the first audit than during the third.