This report presents the joint response of the European Supervisory Authorities regarding the assessment of including statutory auditors and audit firms within the scope of DORA. It examines the implications of this inclusion on the market, the auditees, supervision, implementation, and cooperation between authorities. The Authorities conclude that the implications of applying DORA to these entities appear to…
This joint report of the European Supervisory Authorities (EBA, EIOPA, ESMA) responds to the European Commission's consultation under Article 58(3) of Regulation (EU) 2022/2554 (DORA). Dated December 2025, it assesses the relevance of including statutory auditors and audit firms within the scope of DORA or amending Directive 2006/43/EC to strengthen their digital operational resilience requirements. The scope covers statutory auditors, audit firms, their role in the financial and economic sector, as well as regulatory and supervisory implications related to a potential extension of DORA.
The report analyzes the possibility of applying DORA to statutory auditors and audit firms, who play a key role in financial transparency and market stability by certifying the accuracy of financial statements, notably of public interest entities. Although confidentiality, integrity, and availability of audit data are critical, audit activities are not part of the direct operational chain of audited entities and do not directly affect the continuity of financial services. Inclusion in DORA would raise several issues: increased market concentration due to higher fixed costs, likely higher audit fees impacting mainly SMEs, significant need for retraining of national supervisory authorities, complex adjustments to governance and cooperation mechanisms between authorities, as well as regulatory inconsistency compared to other essential non-regulated service providers. Auditors already benefit from a multi-layered regulatory and contractual framework ensuring data protection. In conclusion, the ESAs consider that the drawbacks related to extending DORA to auditors outweigh the potential benefits and do not recommend this inclusion at this stage (p. 1-8).
The report was drafted in response to the European Commission's request, dated 29 October 2025, under Article 58(3) of the DORA Regulation. The objective is to assess whether statutory auditors and audit firms should be subject to enhanced digital operational resilience requirements, either by their inclusion in DORA or by amending Directive 2006/43/EC. This assessment takes place in a context where supervision of auditors is mainly national, with a limited role for the ESAs, and where protection of audit data is essential for market confidence and financial stability. The report aims to provide a detailed analysis of the regulatory, economic, supervisory, and governance implications related to this potential extension, while highlighting current limitations of the applicable framework (p. 1-3).
Regulatory framework and role of the ESAs: Statutory auditors are governed by Directive 2006/43/EC and Regulation 537/2014, with supervision ensured by national authorities and cooperation at the European level via the CEAOB. The ESAs (EBA, EIOPA, ESMA) have no direct supervisory powers over these entities, although ESMA plays a more active role in convergence of practices related to financial transparency (p. 3-5).
Importance of auditors in the financial ecosystem: Auditors provide independent assurance on financial statements, essential to investor confidence and market stability. Confidentiality, integrity, and availability of audit data are critical, but audit activities are not integrated into the operational chain of audited entities and do not directly affect the continuity of financial services. The current framework imposes general organizational requirements on continuity and incident management, as well as document retention obligations (p. 5-6).
Operational measures and existing protections: Data exchanges between auditors and audited entities are secured through contractual and technical means (encrypted portals, confidentiality clauses). Auditors must also comply with GDPR and other cross-sector regulations, reinforcing data protection. Client financial entities already apply DORA, which indirectly impacts auditors when accessing client systems (p. 6-7).
Implications of extending DORA:
- Market: Full application of DORA would increase fixed costs, reinforcing market concentration dominated by the Big Four, reducing competition and choice for audited entities.
- Audited entities: Increased compliance costs would be passed on to fees, particularly affecting SMEs and micro-enterprises, without guaranteed proportional benefit in terms of resilience.
- Supervision: National authorities would need to retrain their teams to manage DORA requirements (incident management, risk registers, TLPT testing, general supervision).
- Governance: Integrating auditors into DORA mechanisms would require complex adjustments to reporting flows, designation of TLPT authorities, participation in supervisory forums, and follow-up responsibilities.
- Cooperation: Inclusion would raise questions about integrating auditors' supervisory authorities into ESAs' decision-making processes and existing cooperation groups.
- Regulatory consistency: Unlike other essential non-regulated providers, auditors would be subject to DORA, posing a consistency issue in the treatment of critical suppliers (p. 6-8).
Findings: The European audit market is highly concentrated, with the Big Four dominating certification of public interest entities. Auditors play a key role in financial market confidence, but their activities are not critical to the operational continuity of audited entities. The current regulatory framework imposes general continuity and incident management requirements, as well as contractual and legal protections on data (p. 1-7).
Assumptions: Applying DORA requirements to auditors would significantly increase compliance costs, reinforcing market concentration and increasing audit fees, notably for SMEs. Supervision would require upskilling of national authorities, with significant organizational and governance impacts.
Interpretations: The ESAs consider that the costs and complexities related to extending DORA to auditors outweigh the expected benefits in terms of operational resilience. They also highlight inconsistencies in the regulatory treatment of essential providers.
Uncertainties: The report does not rely on specific empirical data collected but on public information and existing analyses, which limits the precision of some impact assessments (p. 1-8).
The ESAs recognize the public importance of statutory auditors in certifying financial statements of public interest entities. They note that, although the current framework contains general references to digital operational resilience, applying DORA to auditors would involve costs, supervisory complexities, and regulatory inconsistencies that outweigh potential benefits. Consequently, they do not recommend including statutory auditors and audit firms in the scope of DORA at this stage. The report emphasizes the importance of joint measures between auditors and audited entities to protect audit data within the existing regulatory framework (p. 1-8).
Synthesis note written from the full document by DataSAI Academy. This note comes from the scientific library of the DataSAI Academy, open to all.