Unrestricted audit rights, and the evidence pack that survives them
Audit clauses are the part of a DORA addendum suppliers skim, because every enterprise contract has one. This one is different: it names three parties, it overrides your other contract terms, it flows down to your subcontractors, and a separate delegated regulation tells your customer it may not rely on your certificate alone. This guide sets out exactly what was granted and what to have ready before the first request arrives.
What Article 30(3)(e) actually grants
The clause is a right to monitor your performance “on an ongoing basis”, and it is broken into four sub-points. The first is the one that matters.
unrestricted rights of access, inspection and audit by the financial entity, or an appointed third party, and by the competent authority, and the right to take copies of relevant documentation on-site if they are critical to the operations of the ICT third-party service provider, the effective exercise of which is not impeded or limited by other contractual arrangements or implementation policies
Three parties, not one: the financial entity, a third party it appoints, and the competent authority. The right extends to taking copies of documentation on site. And the closing subordinate clause is a conflict rule: no other contractual arrangement and no implementation policy may impede or limit the effective exercise of the right. A confidentiality term elsewhere in your master agreement, a security policy that forbids visitors to the data centre, or a standard clause limiting audits to one per year does not survive it.
The remaining sub-points fill in the shape. Point (ii) allows the parties “to agree on alternative assurance levels if other clients’ rights are affected”. Point (iii) obliges you to “fully cooperate during the onsite inspections and audits performed by the competent authorities, the Lead Overseer, financial entity or an appointed third party”. Point (iv) obliges the contract to “provide details on the scope, procedures to be followed and frequency of such inspections and audits”.
One derogation exists, and it will not help you. The final subparagraph of Article 30(3) allows the audit right to be delegated to an independent third party appointed by the provider, but only where the financial entity is a microenterprise: fewer than ten staff and turnover or balance sheet total not exceeding EUR 2 million, per Article 3(60). Banks and insurers are not microenterprises.
Unrestricted is not unlimited: use Article 28(6)
The counterweight sits in a different article, and most suppliers never read it. Article 28(6) obliges the financial entity, when exercising access, inspection and audit rights, to “on the basis of a risk-based approach, pre-determine the frequency of audits and inspections as well as the areas to be audited through adhering to commonly accepted audit standards in line with any supervisory instruction on the use and incorporation of such audit standards”.
Ask for that plan. It is your customer’s own obligation, not a concession, and getting it in writing converts an unrestricted right into a schedulable one. The same article adds a second useful sentence: where the arrangement entails high technical complexity, the entity “shall verify that auditors, whether internal or external, or a pool of auditors, possess appropriate skills and knowledge to effectively perform the relevant audits and assessments”. If a generalist audit team is booked for a week on your platform, that clause is the polite way to raise it.
| Who | What they may do | Basis |
|---|---|---|
| The financial entity | Access, inspect and audit without restriction, take copies of documentation on site | Art. 30(3)(e)(i) |
| A third party it appoints | The same rights, exercised on its behalf | Art. 30(3)(e)(i) |
| The competent authority | The same rights, plus on-site inspection you must fully cooperate with | Art. 30(3)(e)(i), (iii) |
| The Lead Overseer | On-site inspections and audits you must fully cooperate with | Art. 30(3)(e)(iii) |
| Several entities jointly | Pooled audits and pooled ICT testing, including threat-led penetration testing | RTS 2024/1773, Art. 8(2)(b) |
| Your own subcontractors | Must grant the entity and the authorities the same rights you granted | RTS 2025/532, Art. 4(1)(j) |
Why your certificate is not enough, in the Regulation’s own words
Commission Delegated Regulation (EU) 2024/1773 specifies the policy every financial entity must adopt for contracts covering critical or important functions. Its Article 8(2) lists the assurance methods the contract must allow: the entity’s own internal audit or an appointed third party; pooled audits and pooled ICT testing, including threat-led penetration testing, organised jointly with other firms that use the same provider; third-party certifications; and internal or third-party audit reports the provider makes available.
Article 8(3) then constrains the last two.
The financial entity shall not over time rely solely on certifications referred to in paragraph 2, point (c), or audit reports referred to in point (d) of that paragraph.
Reliance is permitted only where the entity is satisfied with your audit plan for the arrangement; ensures the scope of the certification or report covers “the systems and key controls identified by it” and compliance with the relevant regulatory requirements; thoroughly assesses the content on an ongoing basis and verifies that the reports are not obsolete; ensures key systems and controls are covered in future versions; is satisfied with the aptitude of the certifying or auditing party; is satisfied that the work was done against widely recognised professional standards and “include[s] a test of the operational effectiveness of the key controls in place”; retains the contractual right to request scope changes with a reasonable frequency; and retains the contractual right to perform individual and pooled audits at its discretion.
Two of those conditions do real work against a supplier. The scope test is external: it is the systems and key controls the entity identified, not the ones your certification body happened to include. And the operational-effectiveness test rules out any assurance product that only checks control design. An ISO/IEC 27001 certificate shortens the conversation; it does not end it, and a supplier that offers only a certificate is offering something the Regulation has already told the customer not to accept on its own.
What your customer must ask you for, and why
The due-diligence and monitoring questions in a financial-sector questionnaire are not arbitrary. Nearly all of them trace to a specific obligation on the customer, and knowing which one turns an interrogation into a negotiation.
- Article 6(1) of the delegated regulation sets the pre-contract assessment: business reputation, abilities, expertise, financial, human and technical resources, information security standards, organisational structure, risk management and internal controls; the ability to monitor technological developments; whether you use ICT subcontractors; whether you are located or process data in a third country; whether you consent to arrangements that make on-site audits effectively possible; and whether you act ethically and respect human rights, environmental principles and appropriate working conditions.
- Article 6(3) lists what may serve as the required assurance: audits or independent assessments by or for the entity, independent audit reports you commission, your internal audit reports, appropriate third-party certifications, or other relevant information. Article 6(4) says more than one element shall be used where appropriate.
- Article 9(2)(a) requires you to provide “appropriate reports on their activities and services … including periodic reports, incidents reports, service delivery reports, reports on ICT security and reports on business continuity measures and testing”.
- Article 9(2)(b) tells the entity to assess your performance using key performance indicators, key control indicators, audits, self-certifications and independent reviews.
- Article 10 requires a documented, periodically reviewed and tested exit plan per arrangement that is “realistic, feasible, based on plausible scenarios and reasonable assumptions”. Your transition obligations under Article 30(3)(f) are the supplier half of it.
The annual data request, and where it comes from
Separately from assurance, a data request arrives every year. Article 28(3) requires every financial entity to maintain a register of information on all its ICT contracts, at entity, sub-consolidated and consolidated level, documented so as to distinguish critical-function contracts from the rest, and to make it available to its competent authority. Implementing Regulation (EU) 2024/2956 sets the templates.
Two of its rules land on you directly. Article 3(5) requires the entity to identify every provider that is a legal person by a valid and active LEI or the European Unique Identifier, and both where available; third-country providers are identified by LEI only. Article 3(6) requires the entity to ensure, through you, that every subcontractor which effectively underpins a critical-function service also has a valid LEI or provides its EUID.
Annex III sets the service taxonomy your contract is filed under, S01 to S19, from ICT project management through ICT security management services and non-cloud data storage to the three cloud codes for IaaS, PaaS and SaaS. Pick your codes deliberately: the classification travels with your name into a supervisory filing, and it is what the ESAs aggregated when they designated the nineteen critical providers in November 2025.
The filing dates are national. Latvijas Banka states that after the first submission, due 15 April 2025 on 31 March 2025 data, financial entities file annually by 1 March using the previous year’s 31 December data. From the supplier’s side that means the confirmation request arrives in January or February, from every financial customer, every year.
One pack, not one per customer
The single highest-leverage decision here is to stop answering each customer separately. The obligations that generate the questions are the same across every financial entity in the Union, which means the artefacts can be too.
- Identity and classification. LEI and EUID for your entity and for every subcontractor underpinning a critical-function service, plus your chosen S01 to S19 codes and the countries of provision, processing and storage.
- Contract map. Which of your arrangements sit under Article 30(2) and which under Article 30(3), with the customer’s written determination attached to each.
- Independent test. A current penetration test or independent assessment, with a scope statement that names systems and controls rather than IP ranges, so a customer can check it against the ones it identified under Article 8(3)(b) of the delegated regulation.
- Control evidence. Certification and its statement of applicability, plus operational-effectiveness evidence for the key controls, because the certificate alone fails Article 8(3)(f).
- Operational reporting. The periodic, incident, service delivery, ICT security and business continuity reports named in Article 9(2)(a), on a cadence and in a format you defined rather than one negotiated four times.
- Continuity and exit. Contingency plans that have been tested under Article 30(3)(c), and a rehearsed transition plan matching the mandatory transition period in Article 30(3)(f).
- Subcontractor chain. The list, the identifiers, the flow-down audit clause required by Article 4(1)(j) of Delegated Regulation (EU) 2025/532, and the material-change notification process in its Article 5.
- Audit calendar. The frequency and areas your customers have pre-determined under Article 28(6), consolidated into one schedule so that four customers do not each pick the same week in November.
Point eight is where Article 30(3)(e)(ii) earns its place. “The right to agree on alternative assurance levels if other clients’ rights are affected” is the textual basis for proposing a pooled audit programme, and Article 8(2)(b) of the delegated regulation expressly contemplates pooled audits and pooled ICT testing organised jointly by firms that use the same provider. Proposing that programme yourself, with a published calendar and a shared independent test report, is both cheaper than four separate audits and a stronger signal than resisting any of them.
The same logic extends to testing. Where the customer relationships justify it, the pooled route in Article 26(4) lets you contract the external tester for a threat-led exercise covering several financial customers at once. The TLPT guide covers how that works. If you are still at the drafting stage, the addendum guide sets out where to put the audit calendar and the assurance route in the negotiation order.
Sources
- Regulation (EU) 2022/2554 (DORA), Articles 28, 30(3)(e) and 3(60)
- Commission Delegated Regulation (EU) 2024/1773, Articles 6, 8, 9 and 10
- Commission Delegated Regulation (EU) 2025/532, Articles 4 and 5
- Commission Implementing Regulation (EU) 2024/2956, Article 3 and Annex III
- Informācijas reģistra (RoI) iesniegšana: register of information submission dates