Audit process and levels of assurance
1. Certification schemes shall require that operators or groups of operators successfully pass a certification audit carried out by a certification body selected from a list of certification bodies appointed by the certification scheme, before allowing them to participate in the scheme. Such audit shall always be on-site and shall as a minimum provide reasonable assurance of the effectiveness of its internal processes.
2. Certified operators or groups of operators shall be subject to regular re-certification and monitoring audits, whose frequency is set out in the relevant certification methodologies, adopted pursuant to Article 8 of the Regulation (EU) 2024/3012. The certification audit and the first re-certification audit may take place at the same time, upon request by the operators. In the case of group audits, the audits may cover a sample of the group members in accordance with Article 12 of this Regulation. The technical reviewer of the certification body shall be responsible for validating the results of the audits.
3. Certification schemes shall establish detailed guidance setting out how audits are planned and carried out and how audit reports are drawn up. Certification schemes shall ensure that certification bodies conduct audits in accordance with EN ISO/IEC 17021-1 in conjunction with EN ISO/IEC 19011 or the equivalent. Certification schemes shall ensure an efficient and timely exchange of audit information between them to support the effective preparation and conduct of the audit.
4. Certification and re-certification audits shall cover at least the following elements:
(a)
identification of the activity undertaken by the operator which is relevant to the certification scheme’s rules;
(b)
identification of the relevant control systems of the operator and its overall organisation with respect to the certification scheme’s rules and checks of the effective implementation of relevant control systems;
(c)
analysis of the risks which could lead to a material misstatement, based on the auditor’s professional knowledge and the information submitted by the operator;
(d)
a validation or verification plan which corresponds to the risk analysis and the scope and complexity of the operator’s activity, and which defines the sampling methods to be used with respect to that operator’s activity;
(e)
implementation of the validation or verification plan by gathering evidence in accordance with the defined sampling methods, plus all relevant additional evidence, upon which the auditor’s conclusion will be based;
(f)
a request by the certification body to the operator to provide any missing elements of audit trails, an explanation of variations, or the revision of claims or calculations, before reaching a final audit conclusions;
(g)
verification of the accuracy of data recorded by the operator;
(h)
For the purposes of point (c), the analysis of risks shall take into consideration the overall risk profile of the activity, depending on the level of risk of the operator. The audit intensity or scope, or both, shall be adapted to the level of overall risk items.
5. Certification bodies shall only certify operators or groups of operators where they comply with all the following requirements:
(a)
have a documentation management system;
(b)
have an auditable system for safekeeping and reviewing all evidence related to the claims they make or rely on;
(c)
keep all evidence necessary to comply with this Regulation and Regulation (EU) 2024/3012 for a minimum of 5 years after the end of the monitoring period, or longer if requested by national legislation;
(d)
accept responsibility for preparing any information related to the auditing of such evidence.
Auditing of carbon removal and soil emission calculations
1. Certification schemes shall require operators to provide the certification bodies with the activity plan and the monitoring plan in advance of the certification audit, and with the relevant monitoring reports in advance of the re-certification audits or monitoring audits.
2. For the purposes of the re-certification audits, the monitoring report shall include the necessary information relating to the calculation of the net carbon removal benefit or the net soil emission reduction benefit, in accordance with the relevant certification methodology, and any relevant information on the compliance of the activity with the liability and sustainability criteria, as set out in the applicable certification methodology.
3. For the purposes of the monitoring audits, the monitoring report shall include the necessary information relating to the monitoring of the stored carbon, and any case of reversals.
4. Upon request, certification schemes shall provide the Commission and the national authorities responsible for supervision of the certification bodies with access to the respective audit reports and the certificates of compliance.
Group auditing for carbon farming
1. Certification schemes shall allow for group auditing upon request of a group of operators for carbon farming activities only in the following cases:
(a)
the areas where the activities to be certified take place are in geographical proximity to each other and have similar pedoclimatic characteristics, such as climatic or soil conditions;
(b)
for the purpose of calculating carbon removals and soil emission reductions, the activities have similar processes and procedures;
(c)
all group members apply the same relevant certification methodology adopted pursuant to Article 8(2) of Regulation (EU) 2024/3012;
(d)
the group of operators has established a system for internal controls comprising a documented set of risk-based control activities and procedures in accordance with which an identified person or body (group manager) is responsible for verifying compliance of each member of the group with the applicable certification methodology.
2. A group of operators applying for a group audit shall designate a group manager, who shall legally represent the group of operators and shall be responsible for ensuring that each operator complies with the applicable certification methodology.
3. Certification bodies carrying out group auditing may verify all activities concerned on the basis of a sample of group members. Certification schemes shall set out guidelines on the implementation of group auditing, including at least the following elements:
(a)
role of the group manager, including with regard to the internal management system and internal group inspection procedures and their frequency;
(b)
size of the sample of the activities concerned, determined in accordance with paragraph 5.
4. A sample consisting of a number of group members equivalent to the square root of the total number of group members shall be audited individually at a frequency set out in the applicable certification methodology. That number shall be increased in the event of a higher level of risk.
5. For group auditing, if a critical or major non-conformity is identified in one operator of the initial sample of group members, an additional sample of group members of the same size shall be audited. Systemic non-conformity of group members across the whole sample shall lead to the suspension or withdrawal of the whole group certification, as applicable. Certification schemes shall establish criteria for determining the general level of risk in the areas covered by the activities of the group and the consequences of that level of risk for the auditing approach. The sample shall be representative of the whole group and determined using a combination of risk and random selection. Random selection shall represent at least 25% of the members of the sample and at least 25% of the total area covered by the activities of the sample. The members selected for the group audit shall vary at each verification, which frequency is set out in the applicable certification methodology. Critical or major non-compliance of individual group members identified during an audit shall be addressed in accordance with Article 7, paragraphs 2 to 6, as applicable.
6. Audits of the group manager shall always be conducted on-site. Audits of group members may be desk-based, provided that desk audits are able to provide a comparable level of assurance as an on-site audit. Certification schemes shall determine what evidence is required to allow for desk audits. Self-declarations from operators shall not be considered to be sufficient evidence.
Source: EUR-Lex (Publications Office of the EU), © European Union, reuse permitted under Commission Decision 2011/833/EU.