Skip to content

Evidence request lists

Digital Services Act (DSA) - Regulation (EU) 2022/2065

Evidence request list. 36 controls, 36 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

DSA Chapter II: Liability of Intermediary Service Providers

DSA-Art.10
Orders to provide information

Upon receipt of an order to provide specific information about one or more individual recipients, providers shall inform the issuing authority of effect given; orders must meet the listed conditions.

Artefacts an auditor will ask for
  • Process for handling information orders and notifying the authority
Where this commonly fails
  • No defined process for information orders
DSA-Art.4
Mere conduit

A provider of a mere conduit service is not liable for transmitted information where it does not initiate the transmission, does not select the receiver, and does not select or modify the information, without prejudice to orders to terminate or prevent an infringement.

Artefacts an auditor will ask for
  • Documented procedure/system implementing the obligation
  • Records evidencing operation (logs, reports, notices)
Where this commonly fails
  • No documented procedure
  • Procedure exists on paper but no operating evidence
DSA-Art.5
Caching

A provider of a caching service is not liable for the automatic, intermediate and temporary storage of information performed for the sole purpose of making onward transmission more efficient, where it meets the listed conditions (no modification, compliance with access/update rules, expeditious removal on obtaining knowledge of removal at source).

Artefacts an auditor will ask for
  • Documented procedure/system implementing the obligation
  • Records evidencing operation (logs, reports, notices)
Where this commonly fails
  • No documented procedure
  • Procedure exists on paper but no operating evidence
DSA-Art.6
Hosting

A hosting provider is not liable for stored information where it does not have actual knowledge of illegal content and, upon obtaining such knowledge, acts expeditiously to remove or disable access to it; the exemption does not apply where the recipient acts under the authority or control of the provider.

Artefacts an auditor will ask for
  • Documented procedure/system implementing the obligation
  • Records evidencing operation (logs, reports, notices)
Where this commonly fails
  • No documented procedure
  • Procedure exists on paper but no operating evidence
DSA-Art.8
No general monitoring or active fact-finding obligations

No general obligation may be imposed on providers to monitor the information they transmit or store, or actively to seek facts or circumstances indicating illegal activity.

Artefacts an auditor will ask for
  • Policy confirming no general-monitoring obligation is imposed and how voluntary measures are bounded
Where this commonly fails
  • Mischaracterising voluntary measures as a general monitoring duty
DSA-Art.9
Orders to act against illegal content

Upon receipt of an order to act against specific illegal content issued by national authorities, providers shall inform the issuing authority of effect given to the order; the order must meet the listed conditions (legal basis, territorial scope, redress information, e-translation).

Artefacts an auditor will ask for
  • Process for receiving and actioning authority orders
  • Records of effect given and information back to the authority
Where this commonly fails
  • No process to receive or respond to authority orders

DSA Chapter III Section 1: Obligations for All Intermediary Services

DSA-Art.11
Points of contact for Member States authorities, the Commission and the Board

Providers shall designate a single point of contact enabling direct electronic communication with Member State authorities, the Commission and the European Board for Digital Services, and make the necessary information public.

Artefacts an auditor will ask for
  • Designated and published authority point of contact
Where this commonly fails
  • No published authority point of contact
DSA-Art.12
Points of contact for recipients of the service

Providers shall designate a single point of contact enabling recipients to communicate directly and rapidly by electronic means and in a user-friendly manner, including by means other than solely automated tools.

Artefacts an auditor will ask for
  • Published recipient point of contact allowing non-automated communication
Where this commonly fails
  • Only an automated/chatbot channel with no human route
DSA-Art.13
Legal representatives

Providers not established in the Union but offering services there shall designate, in writing, a legal representative in a Member State and notify its details to the Digital Services Coordinator.

Artefacts an auditor will ask for
  • Appointment of an EU legal representative and notification to the DSC
Where this commonly fails
  • No EU legal representative despite offering services in the Union
DSA-Art.14
Terms and conditions

Providers shall set out in their terms and conditions information on any restrictions on the use of their service (including content-moderation policies, procedures, tools and rules of procedure, algorithmic decision-making and human review), in clear, plain, intelligible, user-friendly and unambiguous language, and act diligently, objectively and proportionately when applying them.

Artefacts an auditor will ask for
  • Published terms and conditions describing content-moderation policies and tools
  • Evidence of diligent, objective, proportionate enforcement
Where this commonly fails
  • T&Cs silent on content moderation/algorithmic decisions
  • Arbitrary or non-transparent enforcement
DSA-Art.15
Transparency reporting obligations for providers of intermediary services

Providers of intermediary services (except micro/small enterprises that are not VLOPs) shall publish, at least annually, clear and comprehensible reports on any content moderation they engaged in during the period.

Artefacts an auditor will ask for
  • Annual content-moderation transparency report meeting the prescribed content
Where this commonly fails
  • No annual transparency report
  • Report missing prescribed data points

DSA Chapter III Section 2: Additional Obligations for Hosting Services

DSA-Art.16
Notice and action mechanisms

Hosting providers shall put in place easy-to-access, user-friendly, electronic notice-and-action mechanisms allowing any individual or entity to notify the presence of specific items they consider illegal content, confirm receipt, and notify their decision with redress information; notices giving actual knowledge are relevant for liability.

Artefacts an auditor will ask for
  • A working notice-and-action mechanism with confirmation and decision notices
  • Records of notices received and actioned
Where this commonly fails
  • No notice mechanism or no acknowledgement/decision notices
DSA-Art.17
Statement of reasons

Hosting providers shall provide affected recipients a clear and specific statement of reasons for any restriction imposed on the ground that information is illegal content or incompatible with the terms and conditions, covering the listed elements, and (for online platforms) submit it to the Commission transparency database.

Artefacts an auditor will ask for
  • Statement-of-reasons issued for restrictions, with the required elements
  • Submission to the DSA transparency database (platforms)
Where this commonly fails
  • Restrictions applied with no statement of reasons
DSA-Art.18
Notification of suspicions of criminal offences

Where a hosting provider becomes aware of information giving rise to a suspicion that a criminal offence involving a threat to the life or safety of a person has taken place, is taking place or is likely, it shall promptly inform the relevant law-enforcement or judicial authorities.

Artefacts an auditor will ask for
  • Procedure to notify law enforcement of life/safety threats
  • Records of any such notifications
Where this commonly fails
  • No escalation route to law enforcement for life-threatening content

DSA Chapter III Section 3: Additional Obligations for Online Platforms

DSA-Art.20
Internal complaint-handling system

Online platforms shall provide recipients (and notifiers) access, for at least six months following a moderation decision, to an effective internal complaint-handling system allowing electronic and free-of-charge lodging of complaints, with decisions taken under non-arbitrary supervision of qualified staff (not solely automated).

Artefacts an auditor will ask for
  • An internal complaint-handling system meeting the 6-month/free/non-automated requirements
Where this commonly fails
  • No internal appeals system
  • Appeals decided solely by automated means
DSA-Art.21
Out-of-court dispute settlement

Recipients affected by moderation decisions shall be entitled to select any certified out-of-court dispute settlement body to resolve disputes; platforms shall engage in good faith and bear the body's fees as specified.

Artefacts an auditor will ask for
  • Information provided to users on certified out-of-court dispute bodies
  • Records of engagement with such bodies
Where this commonly fails
  • No information on out-of-court dispute settlement
DSA-Art.22
Trusted flaggers

Online platforms shall take the necessary technical and organisational measures to ensure that notices submitted by trusted flaggers (awarded that status by the Digital Services Coordinator) through the notice-and-action mechanisms are given priority and processed without undue delay.

Artefacts an auditor will ask for
  • Mechanism prioritising trusted-flagger notices
  • Records distinguishing trusted-flagger notices
Where this commonly fails
  • No priority handling for trusted-flagger notices
DSA-Art.23
Measures and protection against misuse

Online platforms shall suspend, for a reasonable period and after prior warning, the provision of services to recipients that frequently provide manifestly illegal content, and the processing of notices/complaints from those that frequently submit manifestly unfounded notices or complaints.

Artefacts an auditor will ask for
  • A documented misuse policy with warning and suspension thresholds
  • Records of warnings/suspensions
Where this commonly fails
  • No measures against repeat illegal-content posters or abusive notifiers
DSA-Art.24
Transparency reporting obligations for providers of online platforms

Online platforms shall include additional information in their transparency reports (disputes, suspensions, average monthly active recipients) and publish their average monthly active recipients in the Union at least every six months.

Artefacts an auditor will ask for
  • Platform transparency report with the additional data points
  • Published average monthly active recipients figure
Where this commonly fails
  • Active-user figures not published
  • Platform-specific report data missing
DSA-Art.25
Online interface design and organisation

Providers of online platforms shall not design, organise or operate their online interfaces in a way that deceives or manipulates recipients or otherwise materially distorts or impairs their ability to make free and informed decisions (prohibition of dark patterns).

Artefacts an auditor will ask for
  • Interface-design review confirming no manipulative/dark-pattern practices
Where this commonly fails
  • Use of dark patterns (e.g. preselected consent, nagging, obstruction)
DSA-Art.26
Advertising on online platforms

Providers of online platforms presenting advertising shall ensure recipients can identify in real time that the content is an advertisement, on whose behalf it is presented, who paid for it, and the main parameters used to target them; and shall not present advertising based on profiling using special categories of personal data.

Artefacts an auditor will ask for
  • Per-advertisement disclosures (advertiser, payer, targeting parameters)
  • Controls preventing ad targeting on special-category data
Where this commonly fails
  • No real-time ad disclosure
  • Targeting ads using special-category personal data
DSA-Art.27
Recommender system transparency

Providers of online platforms that use recommender systems shall set out in their terms and conditions, in plain and intelligible language, the main parameters used in their recommender systems and any options for recipients to modify or influence those parameters.

Artefacts an auditor will ask for
  • Plain-language disclosure of recommender-system main parameters
  • User options to modify recommender parameters
Where this commonly fails
  • No disclosure of recommender-system parameters
DSA-Art.28
Online protection of minors

Providers of online platforms accessible to minors shall put in place appropriate and proportionate measures to ensure a high level of privacy, safety and security of minors, and shall not present advertising based on profiling using personal data of a recipient they are aware is a minor.

Artefacts an auditor will ask for
  • Measures protecting minors privacy/safety/security on the service
  • Controls preventing profiling-based ads to known minors
Where this commonly fails
  • No minor-protection measures
  • Profiling-based advertising shown to known minors

DSA Chapter III Section 4: Obligations for Online Marketplaces

DSA-Art.30
Traceability of traders

Online platforms allowing consumers to conclude distance contracts with traders shall obtain, verify the reliability of, and keep specified information on traders before allowing them to use the platform (know-your-business-customer), and make best efforts to assess whether such information is reliable.

Artefacts an auditor will ask for
  • Collected and verified trader identity/registration/payment information
  • Process to assess reliability of trader information
Where this commonly fails
  • Allowing traders to operate without KYBC verification
DSA-Art.31
Compliance by design

Online platforms allowing distance contracts shall design and organise their interface to enable traders to comply with their obligations regarding pre-contractual information, compliance and product safety information under applicable Union law.

Artefacts an auditor will ask for
  • Interface fields enabling traders to provide pre-contractual/safety information
Where this commonly fails
  • Interface that prevents traders meeting their information obligations
DSA-Art.32
Right to information

Where an online platform becomes aware that an illegal product or service was offered, it shall inform consumers who purchased it of the illegality, the identity of the trader and any means of redress (or, where contact details are unavailable, publish the information).

Artefacts an auditor will ask for
  • Process to inform affected consumers of illegal products/services
Where this commonly fails
  • No mechanism to notify consumers of illegal offerings

DSA Chapter III Section 5: Additional Obligations for VLOPs and VLOSEs

DSA-Art.34
Risk assessment

Providers of VLOPs and VLOSEs shall diligently identify, analyse and assess at least annually the systemic risks stemming from the design, functioning and use of their services (dissemination of illegal content; effects on fundamental rights; civic discourse and electoral processes; gender-based violence, protection of minors and public health/wellbeing).

Artefacts an auditor will ask for
  • A documented annual systemic-risk assessment covering the four risk categories
  • Methodology and supporting analysis
Where this commonly fails
  • No systemic-risk assessment
  • Assessment omitting required risk categories
DSA-Art.35
Mitigation of risks

VLOPs and VLOSEs shall put in place reasonable, proportionate and effective mitigation measures tailored to the systemic risks identified, with particular consideration to impacts on fundamental rights (e.g. adapting design, terms, content-moderation processes, advertising and recommender systems).

Artefacts an auditor will ask for
  • Documented risk-mitigation measures mapped to identified risks
Where this commonly fails
  • Risks identified but no corresponding mitigation
DSA-Art.36
Crisis response mechanism

Where the Commission adopts a decision under the crisis-response mechanism, VLOPs and VLOSEs shall assess whether and how the functioning of their services contributes to a serious threat and apply specific, effective and proportionate crisis-response measures.

Artefacts an auditor will ask for
  • Procedure to implement Commission crisis-response decisions
  • Records of measures applied during a declared crisis
Where this commonly fails
  • No capability to respond to a crisis-response decision
DSA-Art.37
Independent audit

VLOPs and VLOSEs shall be subject, at their own expense and at least annually, to independent audits to assess compliance with the Chapter III obligations and any commitments under codes of conduct and crisis protocols, and shall take due account of audit recommendations.

Artefacts an auditor will ask for
  • Annual independent audit report with an audit opinion
  • An audit implementation report addressing recommendations
Where this commonly fails
  • No independent audit
  • Audit recommendations ignored
DSA-Art.38
Recommender systems

VLOPs and VLOSEs that use recommender systems shall provide at least one option for each recommender system that is not based on profiling within the meaning of the GDPR.

Artefacts an auditor will ask for
  • A non-profiling recommender option available to users
Where this commonly fails
  • Only profiling-based recommendation with no alternative
DSA-Art.39
Additional online advertising transparency

VLOPs and VLOSEs presenting advertising shall compile and make publicly available, through a searchable and reliable repository, information on the advertisements presented (content, advertiser, payer, period, targeting parameters and recipients reached) for the period they were presented and one year after.

Artefacts an auditor will ask for
  • A public, searchable advertisement repository with the required fields
Where this commonly fails
  • No advertisement repository
  • Repository missing required fields
DSA-Art.40
Data access and scrutiny

VLOPs and VLOSEs shall provide the Digital Services Coordinator of establishment or the Commission, on reasoned request, access to data necessary to monitor compliance, and provide vetted researchers access to data for the sole purpose of researching systemic risks.

Artefacts an auditor will ask for
  • Process for regulator data-access requests
  • Process for vetted-researcher data access
Where this commonly fails
  • No mechanism to provide regulator or researcher data access
DSA-Art.41
Compliance function

VLOPs and VLOSEs shall establish a compliance function, independent from operational functions, with sufficient authority, stature and resources, headed by a compliance officer reporting to the management body, to monitor compliance with the Regulation.

Artefacts an auditor will ask for
  • An established, independent compliance function with a compliance officer
  • Reporting line to the management body
Where this commonly fails
  • No independent compliance function
  • Compliance officer without authority/resources
DSA-Art.42
Transparency reporting obligations

VLOPs and VLOSEs shall publish the transparency reports at least every six months, including the human resources dedicated to content moderation per language, measures taken for training and assistance, and the results of the systemic-risk assessment and audit reports.

Artefacts an auditor will ask for
  • Six-monthly VLOP transparency reports with the additional content
  • Published audit and risk-assessment outcomes
Where this commonly fails
  • Reports not published six-monthly
  • Required VLOP-specific content missing
DSA-Art.43
Supervisory fee

VLOPs and VLOSEs shall pay an annual supervisory fee to the Commission upon designation, set to cover the estimated costs of the Commission's supervisory tasks and not exceeding the stated cap.

Artefacts an auditor will ask for
  • Payment of the annual supervisory fee
  • Records confirming fee calculation/payment
Where this commonly fails
  • Non-payment of the supervisory fee
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.