EPSOHQ
EU audit foundationsVerified 31 Jul 2026

EU Public Audit Architecture and Legal Framework

Treaty accountability, ECA and internal-audit roles, Financial Regulation, management modes and EU audit trails.

Independent training. Official notice and EPSO communications prevail.Open official notice
All 12 modules

Snapshot

Treaty accountability, ECA and internal-audit roles, Financial Regulation, management modes and EU audit trails.

Module status

  • Track: EU audit foundations
  • Last verified: 2026-07-31
  • Scope: Independent competition training; official sources always prevail.

Accountability chain

EU public audit sits inside a wider accountability system. The European Parliament and Council adopt the budget. The Commission implements it, often together with Member States or other partners. The European Court of Auditors provides external audit. The Parliament, acting on a Council recommendation, decides whether to grant the Commission discharge for implementation of the budget.

Article 317 TFEU places implementation of the budget on the Commission, in cooperation with Member States, in accordance with the Financial Regulation and the principles of sound financial management. Article 287 TFEU defines the Court of Auditors' audit mandate. Article 319 TFEU governs discharge.

European Court of Auditors

The ECA is the EU's independent external auditor. It examines whether EU revenue has been received and expenditure incurred lawfully and regularly, whether financial management has been sound, and whether accounts are reliable. It reports on any irregularity it finds. It has no judicial power and does not itself impose criminal or administrative sanctions.

Core ECA products include:

  • annual reports on implementation of the EU budget and European Development Funds;
  • specific annual reports on EU bodies and agencies;
  • special reports presenting selected performance-audit results;
  • opinions on proposals with significant financial-management impact;
  • reviews and other publications that synthesise policy or management issues.

The annual statement of assurance covers reliability of the accounts and legality and regularity of underlying transactions.

Internal audit and control actors

The Commission's Internal Audit Service provides independent assurance and consulting within the Commission and, under arrangements, other EU bodies. Internal Audit Capabilities operate within Commission departments. Management remains responsible for internal control, risk management and corrective action; internal audit does not own those controls.

Authorising officers are responsible for implementing revenue and expenditure in accordance with sound financial management and for ensuring legality and regularity. The accounting officer is responsible for payments, collection of revenue and recoveries, treasury management, keeping accounts and laying down accounting rules and methods within the applicable framework. Separation of duties reduces incompatible authority.

Financial Regulation 2024/2509

Regulation (EU, Euratom) 2024/2509 is the recast Financial Regulation applicable to the general budget of the Union. It governs budget principles, implementation methods, financial actors, procurement, grants, financial instruments, accounts, control and audit.

The classic budget principles include unity and budget accuracy, annuality, equilibrium, unit of account, universality, specification, sound financial management and transparency. Sound financial management is implemented through performance-oriented principles and effective, efficient internal control.

Management modes

  • Direct management: the Commission and EU executive agencies implement the budget directly.
  • Shared management: the Commission and Member States share implementation responsibilities; this is used for major spending areas such as cohesion and the common agricultural policy.
  • Indirect management: implementation tasks are entrusted to partner organisations or bodies under the Financial Regulation.

An auditor identifies the management mode before designing work. It changes the control chain, available evidence, responsible actors and audit access.

Multi-level assurance

EU funds commonly pass through layered systems: Commission services, national managing authorities, intermediate bodies, paying agencies, beneficiaries and contractors. Audit design must distinguish the entity responsible for a control from the entity producing the underlying transaction. Reliance on other auditors requires evaluation of their competence, independence, scope and work quality.

Key legal distinctions

  • Legality and regularity asks whether transactions comply with the applicable legal and regulatory framework.
  • Reliability of accounts asks whether financial statements are complete, accurate and fairly presented under the applicable reporting framework.
  • Sound financial management asks whether resources are used economically, efficiently and effectively.
  • Discharge is a political and institutional accountability decision, not an audit opinion issued by the ECA.

Audit trail and access

An audit trail connects an authorised budget commitment through legal commitment, validation, authorisation, payment, accounting and supporting evidence. Digital systems may distribute that trail across workflow engines, document repositories, databases and external systems. Auditors must establish completeness and integrity before relying on extracted records.

Practical decision path

  1. Identify legal basis, programme rules and management mode.
  2. Identify responsible financial and control actors.
  3. Map objectives, expenditure streams and information systems.
  4. Determine relevant assertions, compliance requirements and performance questions.
  5. Locate first-level controls, management verification, certification and audit layers.
  6. Assess where assurance can be used and where direct testing remains necessary.

Official sources