Articles
Article 37Independent audit
- (a)the obligations set out in Chapter III;
- (b)any commitments undertaken pursuant to the codes of conduct referred to in Articles 45 and 46 and the crisis protocols referred to in Article 48.
Such audits shall ensure an adequate level of confidentiality and professional secrecy in respect of the information obtained from the providers of very large online platforms and of very large online search engines and third parties in the context of the audits, including after the termination of the audits. However, complying with that requirement shall not adversely affect the performance of the audits and other provisions of this Regulation, in particular those on transparency, supervision and enforcement. Where necessary for the purpose of the transparency reporting pursuant to Article 42(4), the audit report and the audit implementation report referred to in paragraphs 4 and 6 of this Article shall be accompanied with versions that do not contain any information that could reasonably be considered to be confidential.
- (a)are independent from, and do not have any conflicts of interest with, the provider of very large online platforms or of very large online search engines concerned and any legal person connected to that provider; in particular:
- (i)have not provided non-audit services related to the matters audited to the provider of very large online platform or of very large online search engine concerned and to any legal person connected to that provider in the 12 months’ period before the beginning of the audit and have committed to not providing them with such services in the 12 months’ period after the completion of the audit;
- (ii)have not provided auditing services pursuant to this Article to the provider of very large online platform or of very large online search engine concerned and any legal person connected to that provider during a period longer than 10 consecutive years;
- (iii)are not performing the audit in return for fees which are contingent on the result of the audit;
- (i)
- (b)have proven expertise in the area of risk management, technical competence and capabilities;
- (c)have proven objectivity and professional ethics, based in particular on adherence to codes of practice or appropriate standards.
- (a)the name, address and the point of contact of the provider of the very large online platform or of the very large online search engine subject to the audit and the period covered;
- (b)the name and address of the organisation or organisations performing the audit;
- (c)a declaration of interests;
- (d)a description of the specific elements audited, and the methodology applied;
- (e)a description and a summary of the main findings drawn from the audit;
- (f)a list of the third parties consulted as part of the audit;
- (g)an audit opinion on whether the provider of the very large online platform or of the very large online search engine subject to the audit complied with the obligations and with the commitments referred to in paragraph 1, namely ‘positive’, ‘positive with comments’ or ‘negative’;
- (h)where the audit opinion is not ‘positive’, operational recommendations on specific measures to achieve compliance and the recommended timeframe to achieve compliance.
https://dsa.digiphile.law/article/article-37.html
Text as at 19 September 2026.
This is an unofficial convenience version of the EU Digital Services Act (Regulation (EU) 2022/2065). It is presented “as is” without guarantee of accuracy, completeness or reliability. See the source text for the official version. This site was last updated in September 2026.