ANNEX IISupplementary provisions
ANNEX II Model for the report of an independent audit body under Article 35(2) of Regulation (EU) No 223/2014 1. Introduction 1.1. Identify the objective of the report, i.e. to set out the results of the assessment of the compliance of the managing authority and the certifying authority with the designation criteria relating to internal control environment, risk management, management and control activities and monitoring set out in Annex IV to Regulation (EU) No 223/2014, in order to express an opinion on their compliance with the designation criteria. 1.2. Identify the scope of the report, i.e. the body(ies) covered, namely the managing authority and the certifying authority (and, where appropriate, the delegated functions of these authorities) and their compliance with the designation criteria relating to internal control environment, risk management, management and control activities and monitoring set out in Annex IV to Regulation (EU) No 223/2014, with reference to the operational programmes covered. 1.3. Indicate the body that has prepared the report (Independent Audit Body) and specify if it is the audit authority for the operational programme(s) covered. 1.4. Indicate how the functional independence of the Independent Audit Body from the managing and certifying authorities is ensured (see Article 35(2) of Regulation (EU) No 223/2014). 2. Methodology and scope of the work 2.1. Indicate the period and timeframe of the audit (date when the final description of functions and procedures in place for the managing authority and, where appropriate, the certifying authority was received by the Independent Audit Body, date when the audit started and ended and resources allocated). 2.2. Specify: (a) the extent of the use of audit work carried out by other bodies; and (b) the quality control performed on such audit work with respect to the adequacy of the work. 2.3. Describe the work done for assessing, in line with Article 35(2) of Regulation (EU) No 223/2014, the fulfilment, by the managing and certifying authorities being designated by [Member State], of the criteria relating to the internal control environment, risk management, management and control activities, and monitoring set out in Annex IV to Regulation (EU) No 223/2014, covering among other elements, the following: 2.3.1. Examination of the description of functions and procedures in place for the managing authority and, where appropriate, the certifying authority, in accordance with the model defined in Annex I to this Regulation. 2.3.2. Examination of other relevant documents concerning the system; indicate any review of laws, ministerial acts, circulars, internal procedure/other manuals, guidelines and/or checklists. 2.3.3. Interviews with the staff in the main bodies (including intermediate bodies, if relevant). Include description of the method and criteria for selection, what subjects have been covered, how many interviews have taken place and who has been interviewed. 2.3.4. Review of the description and procedures relating to the information systems, covering in particular the requirements set out in Annex IV to Regulation (EU) No 223/2014 and the verification of whether these systems are operational and have been set-up in order to ensure: (i) an adequate audit trail; (ii) protection of personal data; (iii) integrity, availability and authenticity of data; and (iv) reliable, accurate and complete information on the implementation of the operational programme (in line with Article 32(2)(a) of Regulation (EU) No 223/2014), data on each operation necessary for monitoring, evaluation, financial management, verification and audit (in line with Article 32(2)(d) and (e) of Regulation (EU) No 223/2014) and data required for drawing up payment applications and accounts (as required by Article 33(d), (g) and (h) of Regulation (EU) No 223/2014). 2.3.5. Where functions have been delegated by the managing authority or the certifying authority to other bodies, describe the audit work done to verify that the managing and/or certifying authority have assessed the capacities of these bodies to carry out delegated tasks, that they have sufficient supervisory procedures in place over these intermediate bodies and any other relevant audit work. 2.4. Indicate if any contradictory procedures have taken place prior to issuing this report and indicate the relevant authorities/bodies. 2.5. Confirm that the work has been carried out taking account of internationally accepted audit standards. 2.6. Identify if there were any limitation of scope ( 1 ) , in particular the ones with affecting the opinion of the independent audit body. 3. Results of assessment for each authority/system 3.1. For each authority/system complete the table: CCI or system (group of CCIs) Concerned Authority (Managing or Certifying authority) Completeness and accuracy of description (Y/N) Conclusion (unqualified, qualified, adverse) Designation criteria affected Section of description of functions and procedures affected Shortcomings Recommendations/Corrective measures Timeframe agreed with concerned authority for implementation of corrective measures CCI x Managing authority Certifying authority System y Managing authority Certifying authority 3.2. Provide results of the assessment on areas not fully covered in the table above, including but not limited to: 3.2.1. The procedures in place for drawing up the accounts referred to in Article 59(5)(a) of Regulation (EU, Euratom) No 966/2012 (Article 33(b) of Regulation (EU) No 223/2014); 3.2.2. The arrangements for certifying the completeness, accuracy and veracity of the accounts and that the expenditure entered in the accounts complies with applicable law and has been incurred in respect of operations selected for funding in accordance with the criteria applicable to the operational programme and complying with applicable law (Article 33(c) of Regulation (EU) No 223/2014); 3.2.3. The procedures in place for ensuring effective and proportionate anti-fraud measures taking account of the risks identified (Article 32(4)(c) of Regulation (EU) No 223/2014); 3.2.4. The framework to ensure that an appropriate risk management exercise is conducted when necessary, and in particular in the event of major modifications to the management and control system (Annex IV, point 2, to Regulation (EU) No 223/2014); 3.2.5. The arrangements for drawing up the management declaration and annual summary of final audits and controls and weaknesses identified (Article 32(4)(e) of Regulation (EU) No 223/2014); 3.2.6. The arrangements for collecting, recording and storing, in computerised form, data on each operation necessary for monitoring, evaluation, financial management, verification and audit, including data on indicators and outputs (Article 32(2)(d) and (e) of Regulation (EU) No 223/2014); 3.2.7. The framework for ensuring, in the event of delegation of tasks to intermediate bodies, the definition of their respective responsibilities and obligations, the verification of their capacities to carry out delegated tasks and the existence of reporting procedures (Annex IV, point 1(ii), to Regulation (EU) No 223/2014). ( 1 ) Limitation of scope: a limitation on the scope of the auditor's work may sometimes be imposed by the entity (for example, when the terms of the engagement specify that the auditor will not carry out an audit procedure that the auditor believes is necessary). A scope limitation may be imposed by circumstances. It may also arise when, in the opinion of the auditor, the entity's accounting records are inadequate or when the auditor is unable to carry out an audit procedure believed desirable.