
Literature & commentary
NOREA (beroepsorganisatie van IT-auditors)
NOREA is the Dutch professional body for IT auditors and maintains the register of Registered EDP Auditors (RE). Norea.nl carries three things side by side: professional regulation (articles of association, rules on the code of conduct, professional ethics, quality management and disciplinary law), the standards for engagement performance — including Standard 3000 for assurance engagements, 3402 for assurance reports and 4400 for agreed-upon procedures — and a growing series of guidance notes on subjects such as DigiD and ENSIA assessments, DPIAs, the Privacy Control Framework, DORA and NIS2. The documents can be downloaded as PDFs without a login.
Go to the publisher’s websiteWhich products consult this source
BEVER — Direct consultation
The source is consulted directly while the work is being done.
IRMA — Direct consultation
The source is consulted directly while the work is being done.
Availability depends on your organisation’s configuration and access rights.
What this source does not give you
What NOREA publishes is professional standard-setting, not legislation: its standards and rules bind IT auditors affiliated with NOREA through the profession's disciplinary system, not the organisations they audit. A guidance note on NIS2 or DORA, for instance, is a translation of a statutory regime into audit work and does not replace the regulation, the statute or the supervisory framework — those remain the legal source to consult.
Frequently asked questions
- Is a NOREA standard legally binding?
- Not as law, but as a professional norm. NOREA's rules and standards apply to affiliated Registered EDP Auditors; departing from them can be raised through the profession's disciplinary system. No independent obligation arises from them for the audited organisation. The practical significance is indirect but real: where a contract, grant condition or supervisory framework requires an assurance report, it will almost always refer to the NOREA standard under which that report must be produced.
- When do I use Standard 3000 and when 3402?
- Standard 3000 is the general standard for assurance engagements, both attestation and direct engagements, and sets the frame within which an IT auditor issues an opinion providing assurance. Standard 3402 deals specifically with assurance reports at a service organisation: the report through which a provider accounts to its clients and their auditors for the control of outsourced processes. Standard 4400 covers agreed-upon procedures, where precisely no assurance opinion is given — a distinction regularly overlooked in contract negotiations.
- Are NOREA's guidance notes freely downloadable?
- Yes. The guidance notes are listed by year on the site as direct downloads, in PDF or Word, without a membership or account. There is a members-only area for NOREA members, but the technical guidance and the professional rules sit on the public side. Watch the version numbers: for some guidance, such as the Privacy Control Framework, successive versions sit alongside each other on the page.
- What does NOREA add to a compliance or ISMS file?
- Mainly the translation from norm to testable procedure. A statutory regime or standard says what must be in place; NOREA's guidance describes which controls an auditor expects, what counts as evidence and how it is documented. For areas such as DigiD assessments, ENSIA, DPIAs and the audit trail around data processing this provides a worked-out control framework that functions as the de facto reference in the sector.