Policies, Procedures and Controls at Eye-Able
How does Eye-Able ensure regular, risk-based audits and assurance measures in compliance with legal and regulatory requirements?
This article gives an overview of Eye-Able's audit and assurance framework as well as the associated policies, procedures and controls.
Audit and assurance framework
Eye-Able has established a structured audit and assurance framework that is aligned with ISO/IEC 27001, ISO/IEC 27002 and the requirements of DORA and RTS 2024/1774.
Documented and internally approved policies are in place, which are reviewed annually and updated as required.
Audit processes
- Regular audits: External and internal audits take place at least annually on the basis of an approved, risk-based audit plan.
- Coverage: The audits cover regulatory, contractual and legal requirements.
- Independence: The roles for planning, performing, approving and evaluating are organisationally separated to ensure independence.
- Documentation: All audit measures and results are documented in an audit-proof manner.
- Deviations: Deviations feed into risk-based measure management with clearly defined responsibilities, deadlines and tracking processes.
Supplementary audits
Emergency audits and ad-hoc assessments are covered by supplementary protocols.
Monitoring and reporting
The progress of measures is evaluated regularly and disclosed to management reporting.
Further help
Do you have further questions or need personal support? The following article explains how you can get in touch with us: