Singapore legislation
Regulation 34
of Electronic Transactions (Certification Authority) Regulations 2010
Regulation 34
Audit
Subregulation 1
The Controller may, by written notice, require an accredited certification authority to undergo and pass an audit.
Subregulation 2
The audit mentioned in paragraph (1) must be —
conducted in accordance with the auditing requirements specified in this regulation; and
completed within the time that the Controller may, by written notice, specify.
Subregulation 3
The audit must be conducted by a qualified independent audit team approved by the Controller for this purpose comprising a person who is a Certified Public Accountant and a person who is a Certified Information Systems Auditor and either of whom must possess sufficient knowledge of digital signatures and certificates.
Subregulation 4
The firm or company to which the audit team belongs must be independent of the certification authority being audited and must not be a software or hardware vendor that is providing or has provided services or is supplying or has supplied equipment to the certification authority.
Subregulation 5
Auditing fees must be borne by the certification authority.
Subregulation 6
A copy of the audit report must be submitted to the Controller within 4 weeks of the completion of an audit.