Join our Newsletter — 33% off our NHI Course

Why does Article 37 require external audits for VLOPs and VLOSEs under the DSA?

Article 37 creates an external verification layer because the DSA is built around accountability, transparency, and repeated validation of platform conduct. Independent auditors reduce the risk that a platform’s own controls, reporting, or interpretations mask misstatements, omissions, or weak implementation. The requirement also aligns audit work with annual risk assessments and broader due diligence obligations.

Why external audits exist under Article 37

Article 37 is not just a reporting formality. It is a verification mechanism that helps ensure very large platforms are being assessed by someone other than the operator itself, so the compliance picture is not defined solely by internal controls, internal interpretations, or self-selected evidence. That matters because the DSA expects repeatable accountability, not one-time assurances.

An external audit creates a stronger check on whether risk assessments, mitigation measures, and platform governance are actually operating as described. For VLOPs and VLOSEs, the scale of impact means the legal requirement is aimed at credibility, comparability, and traceability, not merely paperwork completion.

That is why the audit requirement fits the wider due diligence structure of the DSA. It gives regulators and stakeholders a more reliable basis for judging whether the platform has identified the right systemic risks, applied proportionate controls, and corrected weaknesses over time.

  • It reduces the chance that a platform’s own reporting obscures control gaps.
  • It forces evidence to be tested against a more independent standard.
  • It makes recurring compliance a measurable obligation rather than a declared state.

How external audits support accountability and risk validation

For VLOPs and VLOSEs, Article 37 is best understood as a governance control with a verification function. The practical issue is not whether a platform can produce a compliance narrative, but whether that narrative survives independent scrutiny when systemic risk, mitigation design, and operating reality are compared.

Independent audits are especially useful where the control environment is complex, because gaps often arise in the space between policy and execution. A platform may have moderation rules, recommendation safeguards, complaint handling, or incident processes on paper, but the audit asks whether those measures are consistently implemented, documented, and evidenced.

Used well, external audit also improves comparability across assessment cycles. It helps distinguish temporary remediation from sustained control maturity, and it creates pressure to close the loop between annual risk assessments and the corrective actions that follow.

That is why the requirement supports both transparency and due diligence. It does not replace the platform’s own obligation to assess and manage risk, but it makes self-assessment more trustworthy by introducing a second line of verification.

The broader accountability logic also aligns with SOC 2 Trust Services Criteria (AICPA), where independent examination is used to test whether controls are suitably designed and operating effectively.

Where a platform’s governance is built around documented process, the audit becomes most valuable when it checks the evidence trail, not just the policy language. In practice, that means traceability from risk identification to mitigation, and from mitigation to observable operation.

Risk and Threat Considerations

The main risk Article 37 addresses is self-validated compliance. Without an external audit layer, a VLOP or VLOSE can understate weaknesses, overstate effectiveness, or leave material gaps unchallenged for too long. That is especially important where the platform’s own assessment covers high-impact systemic risks and the consequences of failure extend beyond the company itself.

Failure mechanism: Internal reporting can drift from operational reality when management controls, legal interpretation, or evidence selection are not independently tested. Over time, that can allow weak mitigation, incomplete documentation, or unresolved issues to persist across assessment cycles.

Impact: Regulators and other stakeholders receive a less reliable view of platform conduct, which weakens accountability and can delay correction of risks that affect users, public discourse, or systemic platform behaviour.

For a legal and governance context like this, the threat is less about a single technical exploit and more about assurance failure, where the organisation’s own version of compliance becomes the main source of evidence. The audit requirement exists to break that loop.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and CIS Controls v8 set the technical controls, while DORA and NIS2 define the regulatory obligations.

Framework Control / Reference Relevance
NIST CSF 2.0 GV.OV — Oversight Article 37 requires independent oversight of platform risk handling and compliance claims.
GV.RM — Risk Management Strategy The audit requirement supports recurring validation of systemic-risk management under the DSA.
GV.SC — Supply Chain Risk Management VLOP and VLOSE governance often depends on third-party assurance and auditability across services.
Recommendation — Use oversight reviews to test whether platform risk controls are evidenced, current, and independently defensible. Align audit evidence to the organisation’s risk management strategy and remediation commitments. Require third-party evidence and contractual audit support for externally delivered platform controls.
CIS Controls v8 5 — Account Management External audits often test whether account and access governance match stated controls and records.
6 — Access Control Management Audit work must confirm that access restrictions and permissions are enforced as described.
8 — Audit Log Management Independent audits rely on logs and records to test whether compliance claims are supportable.
Recommendation — Verify that account governance evidence matches actual access assignments and review outcomes. Validate that access control decisions are implemented consistently and documented for review. Preserve complete logs and evidence trails so auditors can verify control operation and exceptions.
DORA 5 — ICT third-party risk management The audit logic parallels independent assurance over operational risk and governance in regulated environments.
Recommendation — Require independent assurance over outsourced or platform-dependent controls that affect compliance evidence.
NIS2 21 — Risk-management measures Article 37 reinforces recurring validation of organisational risk measures and their implementation.
Recommendation — Demonstrate that risk measures are implemented, monitored, and corrected on a recurring basis.

Practitioner Guidance

What to verify: Treat the audit as a test of evidence quality, not a document review. The most useful question is whether the platform can show that its annual risk assessment, mitigations, and follow-up actions are linked by durable records, consistent ownership, and observable outcomes.

What good looks like: The platform can produce a clear chain from identified systemic risk to applied control, remediation status, and residual-risk acceptance. That chain should still make sense when examined by someone outside the original control owners.

Practitioner takeaway: Article 37 is doing assurance work, not ceremonial work, and the real value of the external audit is whether it can expose the difference between declared compliance and demonstrated control.