TPRM glossary

Right to audit, a clause worth having and rarely worth using

A right to audit is a contractual clause letting a customer — and often its regulator — inspect a supplier’s controls, records and premises relating to the service. It is standard in regulated outsourcing and required by GDPR Article 28 for processors, though in practice it is exercised through evidence far more often than on site. Also called Audit clause, Access and audit rights.

What the clause should cover

A usable clause states who may audit — you, your appointed auditor, and your regulator — what is in scope, how much notice is required, how often, who pays, and what happens in an emergency such as a material incident where the standard notice period is useless. It should also flow down to material sub-contractors, because a right that stops at your direct supplier stops before the part of the chain you most wanted to see.

For processors, UK and EU GDPR make the substance non-negotiable: the data processing agreementmust require the processor to make available the information needed to demonstrate compliance and to allow for and contribute to audits, including inspections. In regulated financial services, the equivalent expectation extends explicitly to the supervisor's own access.

How it actually gets used

Rarely as written. Large providers will not host thousands of individual customer audits, and most customers lack the capacity to run them, so the right is generally satisfied by pooled evidence: SOC 2 Type II reports, ISO 27001 certificates with the statement of applicability, penetration test summaries and standardised questionnaire responses. That is a reasonable settlement, provided the evidence is current and its scope covers the service you buy.

The value of the clause is mostly in what it makes possible when something goes wrong. After a material incident, a firm with an audit right and an emergency trigger has a basis to demand answers; a firm without one is asking for a favour at the least convenient moment in the relationship.

Common questions

Is a right to audit legally required?
For processors of personal data, UK and EU GDPR Article 28 requires the contract to allow for and contribute to audits and inspections by the controller or its appointed auditor. In regulated financial services, supervisory expectations extend access rights to the regulator as well. Outside those contexts it is contractual rather than mandatory.
Can a vendor refuse an on-site audit?
Many large providers decline individual on-site audits and offer pooled assurance instead — third-party audit reports, certifications and standardised questionnaires. That is usually acceptable where the evidence is current and its scope matches your service, but the contract should still preserve the right, particularly for use after a material incident.
Should the audit right flow down to sub-contractors?
Yes, for material arrangements. A right that stops at your direct supplier gives no visibility of the fourth parties actually running part of the service. The usual mechanism is a contractual obligation on the supplier to secure equivalent rights in its own sub-contracts.

Definitions are the easy part. Evidence is not.

See what your vendors actually expose — scored, monitored and evidenced in one place.