Chapter 17 of 17
Auditing Control, Software Integrity, and Operational Separation
The final audit criteria probe beneath formal corporate structures into ownership chains, governance rights, financial dependence, technical support, software features, and foreign-government access. Closing the course, this module uses that evidence framework to consolidate how the proposal combines industrial expansion, sovereign assurance, public demand, and enforceable technical controls.
Reading the Audit Framework: Evidence, Not Assumptions
The common audit method
Audit criteria E through K use an evidence-based method. The auditing organisation should assess specified documents, technical records, contracts, and operating arrangements.
Status of this text
As of July 21, 2026, the text is in Commission proposal COM(2026)502, dated June 3, 2026. Teach its wording as a proposal, not as a final adopted regulation.
Verb discipline
Should remains non-mandatory wording in this text. Must remains mandatory. Can permits a route; it does not make that route exclusive.
The central question
The criteria test more than corporate form: who can influence decisions, reach systems, use data, alter software, operate support, or act on foreign-government requests?
Audit Criterion E: Certification Evidence for Cloud Security
Criterion E's main certificate
The evidence begins with "A valid European cybersecurity certificate issued by a competent conformity assessment body" tied to basic, substantial, or high assurance.
Certificate plus service context
A certification report should describe the main components used to develop and operate the cloud service covered by the audit certificate.
When the cloud scheme is absent
Until a European cloud cybersecurity certification scheme has been established, valid alternative cybersecurity certifications can demonstrate compliance.
Permitted examples
Examples include CEN-based certification, a national competent authority's certificate, or, without a national scheme, evidence of the highest cybersecurity standards available on the market.
Audit Criterion F: AI Purpose Limitation and EU Data Flows
The AI risk being tested
Criterion F tests whether service-generated data can train or fine-tune AI operated by a third country or third-country legal entity, or leave the Union.
Exact purpose limitation
"data are processed solely for the delivery of the audited service and not for service improvements or model or system enhancements or any other secondary purpose."
Trace the full lifecycle
Data-flow diagrams should cover ingestion, storage, processing, deletion, and where AI pipelines or MLOps connect with customer data.
Prove operations and provenance
MLOps records should show EU build, test, and release locations. Model cards, per-record lineage evidence, and subcontractor countries complete the evidence chain.
Quiz: Certification and AI Evidence
Choose the best answer based strictly on Audit criteria E and F.
A provider submits a model card saying that data remain in the Union. However, it has no contractual clause limiting processing to delivery of the audited service, and its data-flow diagram does not show where MLOps connects with customer data. Which answer is most accurate?
Which evidence is still missing under Audit criterion F?
- Nothing: a model card alone completes the criterion.
- The exact purpose-limitation contractual clause and a diagram showing MLOps connections with customer data.
- Only a European cybersecurity certificate under Audit criterion E.
- Only a list of shareholders holding at least 5%.
Show Answer
Answer: B) The exact purpose-limitation contractual clause and a diagram showing MLOps connections with customer data.
Criterion F calls for contractual clauses specifying the exact purpose limitation and for end-to-end data-flow diagrams that also show where AI pipelines or MLOps connect with customer data. A model card is required evidence, but it does not replace those other items.
Audit Criterion G and Section 7.1: Finding Control Beyond Share Ownership
Start with the ownership chain
The auditing organisation should analyse direct and indirect shareholders up to ultimate owners, the cap table, strategic bodies, appointment rules, voting thresholds, and other influence.
The 5% disclosure trigger
Owners that "hold, directly or indirectly, at least 5% of the capital or at least 5% of the voting rights" must be detailed, including relevant voting agreements.
Rights can matter without majority shares
The source identifies vetoes over share transfers, pre-emption rights, and conditional rights to buy additional shares or investments as specific rights to disclose.
Trace legal-person owners
For legal-person shareholders at the 5% threshold, evidence should include an ownership-chain graph to ultimate owners, constitutional documents, and director/officer/signatory registers.
Control is multi-factor
"ownership structures and specific rights, corporate governance, commercial links conferring control, financial links conferring control and any other sources of control."
Control-Test Workshop: Map the Influence Paths
Control-Test Workshop: Map the Influence Paths
Consider this hypothetical provider:
- UnionCloud Ltd. is headquartered in a Member State.
- Investor A owns 4% directly but has a voting agreement with Investor B, which owns 3%.
- Supplier C provides a long-term credit arrangement and a critical software supply agreement. The arrangement gives Supplier C leverage over strategic spending.
- Parent D has no shares, but it can nominate two directors and has approval rights over major acquisitions.
- A subcontractor is financially dependent on a lender established in a third country.
Your task
Make a four-column evidence map in your notes:
- Ownership and specific rights: Which investors or agreements cross the 5% disclosure threshold? Which veto, nomination, pre-emption, or approval rights must be examined?
- Corporate governance: Which board composition, appointment, quorum, and voting documents would show who can make or block strategic decisions?
- Commercial and financial links: Which contracts, credits, cooperation agreements, loan documents, and by-laws could demonstrate a control-like relationship?
- Other sources of control: Is there another long-duration means, process, or link producing a similar level of control over management and resources as share ownership?
Debrief
Investor A and Investor B together have 7% through a voting agreement, so the source's 5% threshold is relevant. Parent D may exert control through governance rights despite having no shares. Supplier C and the lender may be relevant because the source treats commercial and financial dependence as possible control pathways. The auditor should not stop after reading the cap table; it should test the full control framework and obtain equivalent information from subcontractors.
Which item most directly reflects the source's broader approach to control?
- Only shareholders with more than 50% of capital can be relevant.
- A long-term supply agreement or credit arrangement may be relevant where it produces a similar level of control over management and resources as ownership.
- A provider never needs information from subcontractors.
- Board nomination rights matter only if the nominating shareholder owns at least 50%.
Show Answer
Answer: B) A long-term supply agreement or credit arrangement may be relevant where it produces a similar level of control over management and resources as ownership.
Section 7.1 requires evidence of commercial links conferring control, including very important long-term supply agreements or credits coupled with structural links. The stated test is broader than majority share ownership.
Section 7.2 and Audit Criterion H: Separation and Union-Only Operations
A finding of control changes the evidence burden
If third-country control is determined, section 7.2 should trigger requests for an Article 19 decision, separation measures, notice and refusal evidence, and an up-to-date request record.
Required separation outcome
The evidence should show effective legal, technical, and organisational separation so the provider is unable legally, technically, and operationally to comply with prohibited access or disruption requests.
Union-only operational rule
"all support, administration, maintenance, monitoring, incident response, and operational activities must be initiated and performed exclusively in the Union."
Operational evidence
Evidence should cover subcontractor registers, no external remote support, Union-based SOC/NOC and administration, privileged access, backups, disaster recovery, and Union-based access paths.
Access lifecycle and sub-outsourcing
The provider should revoke access when personnel depart and have procedures addressing effective third-country control, including later layers of sub-outsourcing.
Audit Criterion I: Software Supply-Chain Transparency and Source-Code Auditability
Start with the SBOM
The provider should provide "a complete and up-to-date software bill of materials (SBOM) for all software components, including open-source software (OSS)."
Map every dependency
The dependency list should identify modules, libraries, APIs, tools, origin and governing jurisdiction, non-EU reliance, OSS reliance, and the manufacturer/sub-manufacturer chain.
Plan for a vendor failure
The provider should identify alternatives and migration capability. "If equivalent software cannot be identified, a solution ensuring minimal viable functionality must be identified."
Test remote-feature risk
Evidence should cover testing, change management for firmware, BIOS and updates, and maintenance procedures designed to prevent disruptive or tampering remote mechanisms.
Source-code access is mandatory
"the third-party independent auditor is granted the right to access and audit the source code of such software." Required technical material must be complete, accurate, and accessible.
Audit Criteria J and K: Open Source and Third-Country Subsidiaries
Open-source is not automatically low-risk
Criterion J asks for evidence addressing weak community support, missed updates, deprecation, and discontinued maintenance of OSS.
Maintain and replace OSS
The provider should apply up-to-date OSS without undue delay and identify alternative OSS. If no equivalent exists, it must identify minimal viable functionality and test migration.
Acquisition notice
For open-source-licensed software, providers should "implement mechanisms to detect and provide timely notice to the public sector body if the software is acquired by or comes under control of a third country".
Subsidiary separation
Criterion K requires legal and operational independence, no customer-data-system access, and no privileged accounts in Union production environments.
Foreign-government requests
"all foreign government requests received by the subsidiary are formally redirected to the competent Union entity for legal assessment under Union and Member State law."
Flashcards: Precision Review
Flashcards: Precision Review
Flip each card, then restate the evidence requirement in your own words. Pay particular attention to the difference between should and must.
- What does Criterion E require as its primary certification evidence?
- A valid European cybersecurity certificate issued by a competent conformity assessment body, showing assessment and compliance at basic, substantial, or high assurance under an established European scheme adopted under Regulation (EU) 2019/881.
- What is the exact AI purpose-limitation clause in Criterion F?
- data are processed solely for the delivery of the audited service and not for service improvements or model or system enhancements or any other secondary purpose.
- What is the ownership disclosure threshold in section 7.1?
- hold, directly or indirectly, at least 5% of the capital or at least 5% of the voting rights
- What five factor groups must be considered when assessing control?
- ownership structures and specific rights, corporate governance, commercial links conferring control, financial links conferring control and any other sources of control.
- What does Criterion H say about where support activities occur?
- all support, administration, maintenance, monitoring, incident response, and operational activities must be initiated and performed exclusively in the Union.
- What source-code right is mandatory under Criterion I?
- the third-party independent auditor is granted the right to access and audit the source code of such software.
- What must happen to foreign-government requests received by a subsidiary?
- all foreign government requests received by the subsidiary are formally redirected to the competent Union entity for legal assessment under Union and Member State law.
Final Quiz: Build the Audit Conclusion
A cloud provider has an SBOM and a list of dependencies, but it cannot show a tested migration plan for alternatives. Its third-country subsidiary has no direct customer-data access, but retains privileged IAM accounts in a Union production environment. Select the best conclusion under the source text.
Which conclusion follows most closely from Audit criteria I and K?
- The provider has met both criteria because an SBOM and lack of direct data access are sufficient.
- The provider should provide tests and a switchover plan for alternatives, while it must demonstrate that the subsidiary has no privileged IAM accounts in Union production environments.
- Only the subsidiary issue matters because software supply chains are outside the audit scope.
- The provider automatically complies if the subsidiary is legally incorporated in a third country.
Show Answer
Answer: B) The provider should provide tests and a switchover plan for alternatives, while it must demonstrate that the subsidiary has no privileged IAM accounts in Union production environments.
Criterion I calls for alternative solutions, implemented tests, and a switchover plan. Criterion K states that the audited provider must demonstrate that the subsidiary has no privileged accounts in Union production environments, expressly including IAM. An SBOM alone and lack of direct data-system access do not resolve these gaps.
Key Terms
- IAM
- Identity and Access Management; listed in Criterion K as an area in which a third-country subsidiary must have no privileged accounts within Union production environments.
- OSS
- Open-source software. Criteria I and J require visibility, dependency management, risk controls, alternatives, and in specified circumstances notice of third-country acquisition or control.
- PAM
- Privileged Access Management; listed in Criterion K as an area in which a third-country subsidiary must have no privileged accounts within Union production environments.
- SBOM
- Software bill of materials: an inventory that Criterion I says should be complete, up to date, and cover all software components, including OSS.
- MLOps
- Machine learning operations. Under Criterion F, diagrams should show where MLOps connects with customer data, and records should demonstrate EU build, test, and release locations.
- Union
- The European Union, the required location for specified data, operations, administrative access paths, and legal assessment arrangements in these criteria.
- cap table
- A record documenting a company's ownership structure.
- data lineage
- Policies and implementation documentation showing, per record, what data has been used for.
- third country
- A country outside the Union, as used throughout the source text when assessing control, access, support, vendor restrictions, and government requests.
- assurance level
- The source refers to basic, substantial, and high cybersecurity assurance levels, and to Union assurance levels 2, 3, and 4 in Annex II.
- audited provider
- The provider whose cloud computing service is being assessed against the audit criteria.
- auditing organisation
- The organisation that should assess the applicable criterion based on the evidence specified in the source text.
- customer-derived data
- Data derived from a customer and included by the source among data that must not be used to train or fine-tune certain AI models or systems.