Article 37 · Regulation (EU) 2022/2065
Independent audit
An annual audit of compliance with the whole asymmetric chapter, at the provider’s own expense.
- Applies to
- VLOPs and VLOSEs
- Frequency
- At least annually
Designated providers must submit to an independent audit, at their own expense and at least once a year, covering compliance with the obligations of Chapter III and with any commitments made under codes of conduct or crisis protocols.
Auditors must be independent of the provider, free of conflicts of interest, and demonstrably competent in risk management and technical assessment. The audit produces an opinion — positive, positive with comments, or negative — and where it is not positive, operational recommendations.
The provider must then adopt an audit implementation report setting out what it has done about each recommendation, or explain why it has not.
This is one of the more consequential design choices in the DSA: it puts a private assurance market between the regulator and the regulated, and the quality of that market is a live question in its own right.
Worth knowing
- Audit reports and implementation reports are published under Article 42(4).
- The first full audit cycle for the 2023 cohort concluded in 2024; opinions were largely qualified rather than clean.
- The August 2026 cohort — ChatGPT, Reddit, Roblox — enters its first audit cycle after the end-of-2026 compliance date.