(1) All agencies, consultants, advisors and other service providers engaged by the Authority and ecosystem partners such as the Registrar, requesting entities, Authentication User Agencies and Authentication Service Agencies shall get their operations audited by an information system’s auditor certified by a recognised body under the Information Technology Act, 2000 (Central Act No.
21 of 2000) and furnish certified audit reports to the Authority, upon request or at time periods specified by the Authority.
(2) In addition to the audits referred to in sub-rule (1), the Authority may conduct audits of the operations and systems of such entities or persons, either by itself or through an auditor appointed by the Authority.