VND-014 Customer and Regulator Audit and Inspection Rights
Description
A published audit and inspection procedure states the access the organisation grants a customer, a third party the customer appoints and an authority supervising that customer, together with the scope available, the procedure followed and the frequency. It names the on-site inspection route, the evidence that may be copied on site, the organisation's undertaking to cooperate during an inspection, the pooled route offered to customers sharing a service and the alternative assurance offered where one customer's access would reach another customer's data. Where the organisation offers an independent report or certification in place of an audit, the procedure states that a customer may ask for its scope to be changed and that the offer does not displace a right the procedure grants. No other contract, policy or operating practice restricts the exercise of a right the procedure grants. Each audit or inspection exercised is recorded with its scope, date, requester and outcome, and the reports a customer agreement commits the organisation to produce, among them periodic, incident, service delivery, security and continuity testing reports, are produced on the committed cadence with each delivery recorded.
Rationale
A regulated customer cannot sign a contract whose audit clause its own supervisor will not accept, and a right that another contract or an implementation policy impedes is not a right. The usual answer to an audit clause is an attestation, which is allowed only where the customer keeps a contractual route to widen the report's scope and to audit anyway, so the procedure has to say both. Publishing it turns an audit clause from a negotiation each time into a term a buyer can read before it asks. The reporting limb belongs here rather than beside the review discipline because it is the same inversion: the organisation produces the pack instead of reading one, and the continuity testing report is the substantive item, since it means handing a customer the results of exercises BCM-006 runs. Boundaries. VND-006 reviews a supplier the organisation buys from; this control serves a customer it sells to, and an assessor cannot satisfy both with one artefact because the counterparties differ. GOV-020 produces the independent assessment a customer may read instead of auditing; this control states the right that survives when the customer will not accept it. GOV-021 governs the organisation's internal audit function, which is inward facing. VND-011 publishes the responsibility boundary a customer scopes its own audit against. VND-015 flows the same access rights down into a subcontract. Provider seat (ADR-031): the frequency a customer chooses, the areas it audits and the competence of the auditors it appoints are the customer's side and are not written here.
Applicability (9 profiles)
A customer scoping its own controls over a workload it does not run needs a stated route to inspect the provider. VND-011 publishes the boundary; this states the access across it.
The deployer exercises audit rights rather than granting them; VND-006 is where it reviews the suppliers it buys from. Where it supplies a service to external customers it holds the provider seat for that service.
Condition: deployment_model in cloud-saas, cloud-single-tenant
A customer scoping its own controls over a workload it does not run needs a stated route to inspect the provider. VND-011 publishes the boundary; this states the access across it. Conditional since 1.1: the profile lists every deployment model and this row is a commitment of a hosted service, so a provider that publishes weights or runs on infrastructure the customer controls has no hosted service to carry it (ADR-046 amendment, 2026-09-16).
A customer scoping its own controls over a workload it does not run needs a stated route to inspect the provider. VND-011 publishes the boundary; this states the access across it.
The deployer exercises audit rights rather than granting them; VND-006 is where it reviews the suppliers it buys from. Where it supplies a service to external customers it holds the provider seat for that service.
A customer scoping its own controls over a workload it does not run needs a stated route to inspect the provider. VND-011 publishes the boundary; this states the access across it.
Art. 30(3)(e) makes the access right unrestricted and makes any other contract or implementation policy that impedes it a breach in its own right. RTS 2024/1773 Art. 8(3) allows an attestation in place of an audit only where the customer keeps a contractual right to widen its scope and to audit at its discretion anyway, and Art. 3(8)(d) extends the access to premises. Art. 9(2)(a) adds the five standing reports, among them the continuity testing report, which means handing a customer the results of the exercises BCM-006 runs. Pooled threat-led penetration testing sits on APP-005.
A customer scoping its own controls over a workload it does not run needs a stated route to inspect the provider. VND-011 publishes the boundary; this states the access across it.
A customer scoping its own controls over a workload it does not run needs a stated route to inspect the provider. VND-011 publishes the boundary; this states the access across it.
Framework Mappings (8)
| DORA-Art.28.6 | Exercise of access, inspection and audit rights | informative |
| DORA-Art.30.3.e | Rights of access, inspection and audit | full |
| DORA-RTS-2024/1773-Art.3.7 | Independent review and inclusion in the audit plan | informative |
| DORA-RTS-2024/1773-Art.3.8 | Statements the contractual arrangement must carry | partial |
| DORA-RTS-2024/1773-Art.8.2 | Contractual audit, inspection and testing methods | partial |
| DORA-RTS-2024/1773-Art.8.3 | Conditions for relying on certifications and audit reports | partial |
| DORA-RTS-2024/1773-Art.9.2 | Reports the provider supplies to the financial entity | partial |
| DORA-RTS-2025/532-Art.4.1 | Contract conditions for subcontracting critical or important functions | informative |
Evidence (2)
Audit and inspection procedure as published to customers, with the register of audits and inspections exercised in the period showing scope, date, requester and outcome.
Example: Customer audit and inspection procedure v3.1, published 8 January 2026, with the audit register extract of 30 June 2026 covering five exercised audits and one pooled audit.
Test: Verify: (1) the published procedure states the parties granted access, the scope available, the procedure followed and the frequency, (2) it states the on-site route, what may be copied on site and the undertaking to cooperate during an inspection, (3) it states the alternative assurance offered where access would reach another customer's data and the pooled route for customers sharing a service, (4) where a report or certification is offered in place of an audit, the procedure states the customer's route to ask for its scope to be changed and that the offer does not displace the audit right, (5) the register records at least the audits the stated frequency implies for the period, or records that none were requested, (6) for one audit in the register, the outcome and every restriction applied trace to a term the published procedure states rather than to a decision taken at the time, (7) no contract, policy or operating practice sampled restricts a right the procedure grants.
Delivery register for the reports customer agreements commit the organisation to produce, giving the customer, the report type, the committed cadence, the period covered and the date delivered.
Example: Customer reporting delivery register extract 2026-H1, generated 3 July 2026, covering 41 committed reports across nine customers.
Test: Verify: (1) every report a sampled customer agreement commits appears in the register with its committed cadence, (2) each delivery date falls within the cadence committed and a late or missing delivery carries a recorded reason, (3) the register reaches the continuity testing report and the report delivered carries the result of an exercise rather than a statement that one took place, (4) the delivered report for one entry is produced and covers the service the agreement names rather than the organisation as a whole.
Questions (3)
Is there a published procedure stating the audit and inspection rights granted to customers?
Published means a customer or a prospective customer can read it rather than negotiate it. An audit clause in a signed contract with no published procedure behind it is a no, as is a procedure that exists only as an internal playbook.
Which of the following does the procedure state?
Tick an element only where the published procedure states it. A right the organisation would grant on request but has not written down does not count here. The premises option is about physical sites, including sites operated by a subcontractor, not about remote access to systems.
How often may a customer exercise an audit under the published terms?
Options run from the widest right to the narrowest. Answer on the terms as published, not on how often customers have actually asked.