ANNEX IISupplementary provisions
ANNEX II Model for the audit strategy 1. INTRODUCTION This section shall include the following information: — Identification of the operational programme(s) (title(s) and CCI ( 1 ) ) and period covered by the audit strategy. — Identification of the audit authority responsible for drawing up, monitoring and updating the audit strategy and of any other bodies that have contributed to this document. — Reference to the status of the audit authority (national, regional or local public body) and the body in which it is located. — Reference to the mission statement, audit charter or national legislation (where applicable) setting out the functions and responsibilities of the audit authority and other bodies carrying out audits under its responsibility. — Confirmation by the audit authority that the bodies carrying out audits pursuant to Article 34(2) of Regulation (EU) No 223/2014 have the requisite functional independence (and organisational independence, where applicable under Article 31(5) of Regulation (EU) No 223/2014). 2. RISK ASSESSMENT This section shall include the following information: — Explanation of the risk assessment method followed. — Reference to internal procedures for updating the risk assessment. 3. METHODOLOGY This section shall include the following information: 3.1. Overview — Reference to audit manuals or procedures containing the description of the main steps of the audit work, including the classification and treatment of the errors detected. — Reference to the internationally accepted audit standards that the audit authority shall take into account for its audit work, as established by Article 34(3) of Regulation (EU) No 223/2014. — Reference to the procedures in place for drawing up the control report and audit opinion to be submitted to the Commission in accordance with Article 34(5) of Regulation (EU) No 223/2014. 3.2. Audits on the functioning of management and control systems (system audits) Indication of the bodies to be audited and the related key requirements in the context of system audits. Where applicable, reference to the audit body on which the audit authority relies to perform these audits. Indication of any system audits targeted to specific thematic areas, such as: — quality of the administrative and on-the-spot verifications referred to in Article 32(5) of Regulation (EU) No 223/2014, including in relation to the respect of public procurement rules, equal opportunities, reduction and prevention of food waste, and Union law on consumer product safety; — functioning and security of IT systems set up in accordance with Articles 28(d), 32(2)(d) and 33(d) of Regulation (EU) No 223/2014; and their connection with the IT system, referred to in Article 30(4) of Regulation (EU) No 223/2014 (‘SFC 2014’); — reliability of data relating to indicators and, for OP II, data relating to the progress of the operational programme in achieving its objectives provided by the managing authority under Article 32(2)(a) of Regulation (EU) No 223/2014; — reporting of withdrawals and recoveries; — implementation of effective and proportionate anti-fraud measures underpinned by a fraud risk assessment in line with Article 32(4)(c) of Regulation (EU) No 223/2014. 3.3. Audits of operations Description of (or reference to internal document specifying) the sampling methodology to be used in line with Article 34(1) Regulation (EU) No 223/2014 and Article 6 of Commission Delegated Regulation (EU) No 532/2014 ( 2 ) and other specific procedures in place for audits of operations, namely related with the classification and treatment of the errors detected, including suspected fraud. 3.4. Audits of the accounts Description of the audit approach for the audit of the accounts. 3.5. Verification of the management declaration Reference to the internal procedures setting out the work involved in the verification of the assertions contained in the management declaration, for the purpose of the audit opinion. 4. AUDIT WORK PLANNED This section shall include the following information: — Description and justification of the audit priorities and specific objectives in relation to the current accounting year and the two subsequent accounting years, together with an explanation of the linkage of the risk assessment results to the audit work planned. — An indicative schedule of audit assignments in relation to the current accounting year and the two subsequent accounting years for system audits (including audits targeted to specific thematic areas), as follows: Authorities/Bodies or specific thematic areas to be audited CCI OP Title Body responsible for auditing Result of risk assessment 20xx Audit objective and scope 20xx Audit objective and scope 20xx Audit objective and scope 5. RESOURCES This section shall include the following information: — Organisation chart of the audit authority and information on its relationship with any audit body that carries out audits as referred to in Article 34(2) of Regulation (EU) No 223/2014, where appropriate. — Indication of planned resources to be allocated in relation to the current accounting year and the two subsequent accounting years. ( 1 ) Indicate the operational programmes covered by a common management and control system, in case a single audit strategy is prepared for two operational programmes, as foreseen in Article 34(4) of Regulation (EU) No 223/2014. ( 2 ) Commission Delegated Regulation (EU) No 532/2014 of 13 March 2014 supplementing Regulation (EU) No 223/2014 of the European Parliament and of the Council on the Fund for European Aid to the Most Deprived ( OJ L 148, 20.5.2014, p. 54 ).