22 September 2026 ·

Working Paper serving as the basis for a conference and an article

🚧The Audit Clause, Carousel of the Contractualisation of Compliance

complianceTech®️.

LinkedIn X

► Full reference: M.-A. Frison-Roche, The Audit Clause, Carousel of the Contractualisation of Compliance, Working Paper, September 2026.

____

📝 This Working Paper served as the basis for the conference « La clause d’audit corrélée à l’Obligation de Compliance » (The Audit Clause Correlated with the Compliance Obligation) (in French), given on 25 September 2026 in Lyon at the colloquium 🧮La contractualisation de la Compliance : clause après clause, organised by the Journal of Regulation & Compliance (JoRC) and the Université Jean Moulin Lyon 3, as part of the 🏗️2026 cycle of colloquia Compliance and Contract.

📘 It is the basis of the article to be published in the book 📘Compliance and Contract, in the 📚Compliance & Regulation series, co-published by the Journal of Regulation & Compliance (JoRC) and Bruylant.

____

► Summary of the Working Paper: The audit clause is the most frequently cited and most common Compliance clause: it outsources internal control techniques onto a third party. A distinction must be drawn between the audit clause securing one’s own interests, the audit clause ensuring one’s own conformity and the audit clause carrying out a Compliance project. The audit clause then appears as the “necessary accessory” to the conformity and Compliance clause. It is the “objective reflection” of the legal Compliance Obligation, which requires “detecting” in order to act, and its “subjective reflection”, since the regulated party is in charge of those who, notably in value chains, are “concerned third parties”.

In a first part, the Working Paper places itself inside the audit clause. It shows how to draft it in order to obtain the relevant information from the persons who hold it and where it is located: designating in advance the information sought, the persons, documents and places, the event triggering the audit, periodic or linked to an event, who conducts it and its modalities, according to a criterion of proportionality between the extent of the information sought and the objective pursued. It also shows how to integrate from the drafting stage the limits and risks of this audit contractually imposed on others, notably with regard to the rights of the defence and the strategic use of the audit report.

In a second part, the Working Paper places itself outside the clause. The audit clause leans on other stipulations, conformity clause or Compliance clause, corporate relationships and governance techniques. Other clauses lean on it, in order to strike (dispute resolution, sanction and termination clauses) or to draw closer (remediation clause). The court will have to interpret it in the light of its purpose, as the “necessary accessory” to the application of Compliance Law.

In conclusion, the Compliance audit clause appears as the carousel of the contractualisation of Compliance: where it is knotted, where conformity and Compliance are distinguished, where the judge contributes to the deployment of Compliance Law.

____

🔓read the developments below⤵️

1. The audit clause: the most frequently cited and most common Compliance clause, the outsourcing of internal control techniques onto a third party. In the silence that still surrounds the active contractual practice of Compliance, a practice masked by the obsession with the regulatory corpus, the clause providing for an audit organised by one of the contracting parties within the undertaking of the other is without doubt the one most cited by legal scholarsThe "audit clause" is generally little described and commented upon. See however the interesting studies by Arnaud Lecourt, « La clause d’audit », AJ Contrats d’affaires – Concurrence – Distribution (AJCA), 2014, pp. 271-272, and by F.-L. Simon, « Les mystères de la clause d’audit : les écueils à éviter », La Lettre des réseaux, 28 March 2022. On the mention of an audit technique within a broader conformity or Compliance clause, see in French legal scholarship: 🕴️M.-A. Frison-Roche, 📝« Contrat de Compliance, clauses de Compliance », D. 2022, chron., pp. 2115-2117; J.-Ch. Roda, « La clause de compliance », in F. Buy, J. Heinich, M. Lamoureux, J. Mestre and J.-Ch. Roda (eds.), Les principales clauses des contrats d’affaires, 3rd ed., Lextenso - LGDJ, 2025; L. Tenreira, « La rédaction des clauses d’application du devoir de vigilance par les Global Lawyers : l’exemple des clauses de flow-down », Revue de droit des affaires internationales, no. 5, 2022, pp. 453-466; N. Ida, « Contrat et devoir de vigilance des sociétés », JCP E, July 2023, pp. 17-26; Y. Queinnec, « La clause RSE, levier incontournable de vigilance », Revue Lamy droit des affaires, July 2018, no. 139. In English-language scholarship: D. V. Snyder, S. Maslow and S. Dadush, "Balancing Buyer and Supplier Responsibilities: Model Contract Clauses to Protect Workers in International Supply Chains, Version 2.0", The Business Lawyer, vol. 77, no. 1, 2021-2022, pp. 115-182; K. Parella, "Contractual Stakeholderism", Boston University Law Review, vol. 102, 2022, pp. 865 ff.; Robert C. Bird, "Contractual Deterrence and the Ethical Supply Chain", Boston College Law Review, vol. 63, 2022, pp. 2539 ff.; S. Dadush, "Prosocial Contracts: Making Relational Contracts More Relational", Law and Contemporary Problems, vol. 85, no. 2, 2022, pp. 153-175; J. L. Short, M. W. Toffel and A. R. Hugill, "Monitoring Global Supply Chains", Strategic Management Journal, vol. 37, no. 9, 2016, pp. 1878-1897.. Most often, it is a matter of one contracting party making sure that its co-contractor “complies” with Compliance regulations in respect of which it must itself be accountable. We shall see its modalities, but this is indeed the essential point today: it is because the various Compliance regulations require those subject to them to carry out controls and assessments of third parties, whose failures may engage the liability of the first contracting party, a powerful undertaking legally subject to those rules, that such stipulations appear in order to put in place the technique of auditRegulation (EU) 2016/679 of 27 April 2016, Art. 28(3)(h); Regulation (EU) 2022/2554 of 14 December 2022, Art. 30(3)(e); French Order (arrêté) of 6 January 2021 on the system and internal control for anti-money laundering, counter-terrorist financing and asset freezing, Art. 10, 8° and 10°; AMF General Regulation, Arts. 318-61 and 321-96, II; Lieferkettensorgfaltspflichtengesetz of 16 July 2021, § 6 Abs. 4 Nr. 4..

Yet while an audit is easily carried out within a structure one controls, a management act requiring no legal formality, “internal audit”An internal audit which may itself be a "Compliance audit". See A. Gutierrez-Crespin, « L’audit du dispositif de compliance : un outil clé pour en vérifier la robustesse », in 🕴️M.-A. Frison-Roche (ed.), 📕Les outils de la Compliance, JoRC and Dalloz, « Régulations & Compliance » series, 2021, pp. 133-140. being a natural component of “internal control”Recommendations of the French Anti-Corruption Agency (AFA), notice published in JORF no. 10 of 12 January 2021, text no. 61, §§ 61 to 68 and §§ 69 to 74., or even of the “internal investigation”, the contractual route must be taken for the audit to take place at a third party’s premises. It is nonetheless remarkable that in practice the qualifier “internal” is often retained for these audits, controls and investigationsOn internal investigation techniques and their deployment within international groups, O. Catherine, « La spécificité des enquêtes internes pratiquées par les groupes internationaux », in 🕴️M.-A. Frison-Roche and 🕴️M. Boissavy (eds.), 📕Compliance et droits de la défense. Enquête interne – CJIP – CRPC, JoRC and Lefebvre-Dalloz, « Régulations & Compliance » series, 2024, pp. 141-155. On the risks and limits of the audit clause, see infra §§ 26 to 36., which thus continue to be called internal although they are precisely conducted on third parties. Thanks to the contract, the audit can therefore be conducted on a third party as if it were not one, allowing, as it were, the beneficiary of the audit to act as if it were at home. We shall see the limits of such a disappearance, through the power of contract, of the boundary between the internal and the externalOn the risks and limits of the audit clause, see infra §§ 26 to 36..

PRELIMINARY: AUDIT CLAUSE SECURING ONE’S INTERESTS, CONFORMITY AUDIT CLAUSE, COMPLIANCE AUDIT CLAUSE

2. Through the “conformity audit clause”, the regulated entity places itself in a position to obey the Law. Audit clauses concerning third parties are often found, notably in distribution relationships. But the audit clause here differs in its purpose, and therefore in its object. Indeed, the audit clause on the co-contractor’s business found in distribution relationships is there to protect the interests of the “network head”This is described and assumed as such. See F.-L. Simon, « Les mystères de la clause d’audit : les écueils à éviter », La Lettre des réseaux, 17 December 2021, updated 28 March 2022.. Where Compliance is concerned, the contractual route is required and used by a powerful undertaking to control the other, but in order to obey its own regulatory obligation of conformityFor it will answer for the regulatory failures committed by its partners. and of ComplianceFor it can thereby make sure that it has the necessary support from its partners to contribute to the preservation and sustainability of systems. See A. Oumedjkane, « Le devoir de vigilance est-il soluble dans le droit des contrats publics ? », in 🕴️M.-A. Frison-Roche (ed.), 📕Compliance et Contrat, JoRC and Lefebvre-Dalloz, « Régulations & Compliance » series, 2027.. Contractual power is thus exercised only in order to submit to the Law and to be able to be accountable oneselfFrench Act no. 2016-1691 of 9 December 2016 on transparency, the fight against corruption and the modernisation of economic life ("Sapin 2"), Art. 17, II, 4° and 8°; Directive (EU) 2024/1760 of 13 June 2024, Art. 10(2)(b) and (5).. Through the audit clause, the powerful co-contractor draws the other into the space of its own legal obligation.

3. Audit clause securing one’s interests / audit clause ensuring one’s own conformity / audit clause carrying out a Compliance project. This is why it is expressed by “ordering companies”Directive (EU) 2024/1760 of 13 June 2024, Art. 10(2)(b) and (4); Lieferkettensorgfaltspflichtengesetz of 16 July 2021, § 9 Abs. 3; Transparency International, Global Anti-Bribery Guidance, § 13.3.5. since, as the Conseil constitutionnel held, it is always a personal liability that the undertaking controlling the value chain bearsConseil constitutionnel, 23 March 2017, no. 2017-750 DC, Loi relative au devoir de vigilance des sociétés mères et des entreprises donneuses d’ordre. The decision states in § 27 that the contested provisions do not establish a regime of vicarious liability, as is moreover apparent from the parliamentary debates, and therefore do not infringe the principle of liability. On this question of personal liability and liability for others, see A. Danis-Fatôme and G. Viney, « La responsabilité civile dans la loi relative au devoir de vigilance des sociétés mères et des entreprises donneuses d’ordre », D. 2017, no. 28, pp. 1610-1618; T. Sachs and J. Tricot, « La loi sur le devoir de vigilance : un modèle pour (re)penser la responsabilité des entreprises », Droit & Société 2020, no. 106, pp. 683-698; M. Mekki, « Peut-on repenser la responsabilité à l’aune du devoir de Vigilance, pointe avancée de la Compliance ? », in 🕴️M.-A. Frison-Roche (ed.), 📕L’obligation de compliance, JoRC and Dalloz, « Régulations & Compliance » series, 2025, pp. 599-615. See also M. Fabre-Magnan, « Critique de la convergence des responsabilités contractuelle et délictuelle. L’exemple du devoir de vigilance », in Mélanges en l’honneur du Professeur Loïc Cadiet, LexisNexis, 2023, pp. 547-561., yet what is required of it is precisely the detection of what is happening, or may happen, all along that chain within other undertakings. This consolidation of the value chain through the audit clause is essential. On the vertical integration thus produced by "regulation contracts" required not only by management choices but also by compliance imperatives.

The legal situation is therefore different from what could be called an audit clause “securing one’s interests” (as found in distribution contracts), since the party entitled to carry out audits seeks to put itself in a position to be “compliant” with the regulation with respect to which it must show its obedienceIn this respect, the audit clause is associated with "conformity", and not with the Compliance obligation.. Further still, and its regime will vary accordingly, the audit clause concerning the co-contractor’s business may aim to better associate it with the preservation of systems and the protection of the human beings involved in them, which then fully deserves to be described no longer merely as a “conformity audit clause” but as a “Compliance audit clause”.

This difference of purpose is not merely one of degree: it changes the sign of the stipulation. The conformity audit clause bears the mark of submission — one checks that the other obeys, and the audit is the severe form of that check. The Compliance audit clause, because it serves a goal that exceeds both contracting parties, may bear the opposite mark, that of collaboration: what one goes to seek at the other’s premises is no longer the token of its obedience, but the part it takes in preserving the system and protecting the human beings involved in it. The same technical instrument thus receives two opposite meanings, and it is the drafter of the clause who chooses which.

4. The audit clause, “necessary accessory” to the conformity and Compliance clause. From the perspective of “conformity”, the audit clause appears as a necessary accessoryOn the theory of the accessory applied to contractual stipulations, see J.-B. Seube, L’indivisibilité et les actes juridiques, foreword M. Cabrillac, Litec, « Bibliothèque de droit de l’entreprise » series, vol. 40, 1999; M. Cottet, Essai critique sur la théorie de l’accessoire en droit privé, thesis, Paris-Sud, supervised by J. Rochfeld, 2011, the author showing that the theory rests on the notion of function, understood as the contribution to the achievement of a purpose, including where a contractual clause is concerned.. An audit clause, or an audit power over the third party inserted within a global conformity clause, operates for the benefit of the party that has the legal, or even contractual, obligation to be compliant, which will produce audit clauses in cascade. So conceived, it can only take the severe form of control. Indeed, the audit clause then appears as a “necessary accessory” to the “conformity clause” since the regulated undertaking must measure, as early as possible, what is going on, its Compliance obligation consisting in “detecting” failures (conformity) and systemic risks (Compliance) present at its partner’s. The audit clause by nature has an evidentiary dimension, since it will enable the legally regulated undertaking to demonstrate later the diligence it has exercisedOn the evidentiary dimension of the audit clause, see infra § 32.. Because it binds a third party for the benefit of a legally bound undertaking, it must not, however, thereby transfer the legal obligation of the one onto the otherOn the limits of the audit clause, see infra §§ 27 to 32..

Moreover, the formula “necessary accessory” describes only a function, not a regime. The ordinary law of contract knows no category named “accessory clause”: the theory of the accessory operates between goods, between claims, between contracts, not between stipulations of the same instrument. What it grasps is thus not the hierarchy of clauses but their divisibility, and the question is not which of the two commands the other, but whether one can survive without the other. The distinction is not merely one of vocabulary: it governs the fate of the audit clause when the stipulation it serves falls, and conversely the fate of the conformity obligation when the audit is deprived of effect. We shall return to this, for the articulation of the audit clause with the other Compliance stipulations depends on this shift (see infra § 38).

This consubstantiality between Compliance clause and audit clause explains why, in practice, one quite frequently finds first a lavish “conformity clause”, a generic clause requiring the co-contractor to comply with such and such regulations, the GDPR, Sapin 2, etc., or even, if the powerful drafter’s contractual pen is as heavy as the regulator’s, all applicable regulationsJ.-Ch. Roda, « Utilité comparée des clauses de conformité et des clauses de Compliance », in 🕴️M.-A. Frison-Roche (ed.), 📕Compliance et Contrat, JoRC and Lefebvre-Dalloz, « Régulations & Compliance » series, 2027. See infra §§ 40 to 42., and then, to make sure of this, a stipulation which, as a necessary accessory, either in the same paragraph or in the following one, provides that the contracting party that has demanded this feat from the other may carry out audits.

5. The audit clause, a violent clause, not so much in itself as through its presupposition and the consequences drawn from it by other clauses of the contract. Thus informed by the audit, the party holding the contractual powerThe fact that it is a contractual audit does not necessarily rule out a legal characterisation or a regime involving rights of the defence. If there must be one, it is best to organise that regime by contract as well. On this point, see infra §§ 33 to 35. to conduct it may draw all the consequences. Here again, this is stipulated either in the same global so-called “conformity” clauseThe audit clause changes depending on whether it supports a "conformity clause" or a genuine "Compliance clause". On the audit clause leaning on other stipulations, see infra §§ 37 to 50., or in the audit clause, or in the sanctionL. Sautonie-Laguionie, « Les clauses de Compliance relatives aux sanctions », in 🕴️M.-A. Frison-Roche (ed.), Compliance et Contrat, op. cit. or remediationM. Tirel, « Les clauses de Compliance relatives à la remédiation », in 🕴️M.-A. Frison-Roche (ed.), Compliance et Contrat, op. cit. clause which, addressing the co-contractor’s non-conformity, takes a detour by referring to the audit clause, since it is on the occasion of its implementation that the non-conformity to be sanctioned or remedied has been established.

6. Better understanding the audit clause because it is the “objective reflection” of the legal Compliance Obligation: “detecting” in order to act. But it is easier to understand the Compliance audit clause by starting from the legal Compliance Obligation: it requires those subject to it, mainly large undertakings, to contribute to preserving systems in order to ensure their sustainability and to protect the human beings involved in them.🕴️M.-A. Frison-Roche, 📝« Concevoir l’Obligation de Compliance : faire usage de sa position pour participer à la réalisation des Buts Monumentaux de la Compliance », in 🕴️M.-A. Frison-Roche (ed.), 📕L’obligation de compliance, op. cit., pp. 3-44. Adde, by the same author, 🕴️M.-A. Frison-Roche, 🏛️Déployer le Droit de la Compliance pour renforcer la souveraineté et accroître l’attractivité de la France avec l’Europe, Report to the French Minister of Justice, September 2026. For those subject to it, most often large undertakings, this implies the obligation to “detect” systemic risks, in order to remedy harmful consequences that have already materialised or, above all, to prevent their occurrence. The first requirement, even if it does not necessarily translate into an identified legal obligation, is therefore to be informed.

7. To act, being informed, including about what is far away: audit, the adequate technique, and the obligation to be powerful. Audit then becomes the technique that is called for in order to satisfy regulations expressly requiring knowledge. We thus find the technique, altogether classical, of internal control and audit. One might even argue that these ordinary management instruments, now extended to the StateThese techniques have reached the State itself: Decree no. 2022-634 of 22 April 2022 on internal control and internal audit of the State, which repealed Decree no. 2011-775 of 28 June 2011 on internal audit in the administration, requires each minister to have an internal control system based on a risk analysis, and entrusts a ministerial internal audit mission, reporting to the minister, with verifying the quality and effectiveness of that system. Harmonisation of methods and practices falls to the interministerial committee for internal control and audit (CICAI), which succeeded the committee for the harmonisation of the State's internal audit (CHAIE)., are in no way revolutionary. That is not true. For precisely, it is by no means the internal that is concerned. For example, Article 17, II, 4°, of the so-called “Sapin 2” Act, in requiring the regulated undertaking to have “procedures for assessing the situation of customers, first-tier suppliers and intermediaries with regard to the risk map”On assessment procedures, a major tool of Compliance Law, N. Guillaume, « Cartographie des risques de compliance. Premiers aperçus des enjeux, des limites et des bonnes pratiques », in 🕴️M.-A. Frison-Roche (ed.), 📕Les outils de la Compliance, JoRC and Dalloz, « Régulations & Compliance » series, 2021, pp. 63-70. Adde, on the implementation of this measure, the work of the French Anti-Corruption Agency (AFA): « L’évaluation des tiers en question : résultats de notre dernière enquête auprès des entreprises », May 2024, showing that 59% of undertakings regard third-party assessment as the most difficult anti-corruption measure to deploy, notably because of the "difficulty of accessing and integrating data". A Compliance audit clause may provide support. See also, on the stipulations organising this assessment within the value chain, G. J. Martin, « Clauses et contrats, modalités de l’obligation de vigilance », in 🕴️M.-A. Frison-Roche (ed.), 📕L’obligation de compliance, op. cit., pp. 663-678., is revolutionary because it requires risks to be measured no longer only at home, but at others’ premises.

In this, the Compliance audit clause validates the legal obligation to be powerful, since the regulated party, insofar as it has the obligation to be informed, transitively has the obligation to obtain, notably by contract, the legitimate power to obtain the information. The audit clause thus illustrates the legal obligation to be powerful implied by Compliance Law. If the co-contractors are of equal power, and if they are in the same position, the audit power may be reciprocal.

8. The legal Compliance obligation to control partners implies information that must be sought out, failing its being easily delivered, which the audit clause makes concrete. In this collection of information, the contracting party may ask for it to be brought to it. But even if an audit clause places the burden of collecting information on the undertaking that needs it, the controlA cost which may moreover be allocated by contract, or even transferred, provided this is not abusive. over the information produced by the audit technique justifies this. The use of the audit clause in third-party assessment shows it. Thus, in the survey conducted by the French Anti-Corruption Agency (AFA) among undertakings subject to third-party assessment, the audit clause is among the most frequently stipulated vigilance measures, immediately after the anti-corruption clause and the conformity clause, and ahead of the subcontracting clause and the outsourcing clauseFrench Anti-Corruption Agency, Résultats de l’enquête « évaluation des tiers au regard du risque de corruption » menée par l’Agence française anticorruption auprès des entreprises, April 2024, 72 p., Q22, p. 57. Anonymous questionnaire of 28 questions, circulated by trade federations from 10 October to 10 December 2023; self-reported answers; 72 respondents to this question. The AFA specifies that the practices thus shared had not, at the time of publication, been approved by it.. This clause is all the more necessary as the same survey repeatedly stresses, among the difficulties encountered in performing the legal obligation of third-party assessment, the lack of cooperation of those third parties. The virtue of the contract is then to bring back binding forceOn binding force, see more generally 🕴️M.-A. Frison-Roche, « Autonomie de la volonté et compliance », in 🕴️M.-A. Frison-Roche (ed.), 📕Compliance et Contrat, JoRC and Lefebvre-Dalloz, « Régulations & Compliance » series, 2027..

Contractual undertakings among the vigilance measures implemented
Extract from question no. 22: the only measures qualified as “contractual undertakings”. AFA, survey cited above; 72 respondents. The other measures reported relate to internal control (accounting controls, 72.2%; expense reports, 70.8%; conflicts of interest, 61.1%), communication or training; ad hoc audit missions account for 65.3%. The asterisk marks the only line highlighted by me, that of the audit clause.

Anti-corruption clause 100.0%
Subcontracting clause 56.9%
Conformity clause 80.6%
Framework for gifts and invitations 47.2%
Audit clause* 69.4%
Outsourcing clause 25.0%
Framework for conflicts of interest 65.3%

9. Inserting an audit clause because it is the “subjective reflection” of the legal Compliance Obligation: being in charge of those who, notably in value chains, are “concerned third parties”. The audit clause thus makes it possible to treat technically as parties entities or persons who are economically third partiesThe AFA survey cited above mentions that one of the "difficulties" encountered in assessment lies in "the autonomy of subsidiaries". A legally autonomous entity is certainly less open… On the economic integration effect produced by Compliance clauses, notably within a value chain, see 🕴️M.-A. Frison-Roche and E. Maclouf, « Les stratégies d’entreprises dans l’organisation contractuelle des chaînes de valeur », in 🕴️M.-A. Frison-Roche (ed.), Compliance et Contrat, JoRC and Lefebvre-Dalloz, « Régulations & Compliance » series, 2027.. Through a kind of ripple effect, insofar as the audit brings information about persons linked to the co-contractor, a whole set of “concerned third parties” is reached, in concentric circles, by the initial audit clause. They may be “third parties concerned” by the conformity and Compliance burden, notably through information about their diligence or lack of it. They may also be “concerned third parties” who, because they benefit from the behaviours encouraged by the Compliance obligation, may be led to produce information useful for the audit.On these third-party beneficiaries, see infra § 42.

10. The Compliance audit clause: seen from the inside and seen from the outside. Outline. The audit clause is an instrument of the Compliance Obligation that must be unfolded in order to look at the various elements that make it up, thus seeing it “from the inside”. But it is also an instrument that never operates alone: it derives its interest from its articulation with the other contractual Compliance mechanisms. It must therefore also be examined “from the outside”. We thus measure how the clause must be drafted: it must stipulate what makes it possible to obtain the relevant information from those who hold it – the material and temporal scope of the audit, the choice of who will conduct it – and reckon with what the ordinary law opposes to such drafting, the ever-present shadow of significant imbalance and the tacit obligation to carry out the audit that the stipulation creates against the very party that demanded it (I). Examined from the outside, the clause leans: because it needs other clauses to function well and exists to make other clauses function well, it can only be understood through its articulation with the other Compliance stipulations, which it supports and from which it receives support (II).

I. INSIDE AN AUDIT CLAUSE INSERTED FOR THE PERFORMANCE OF THE COMPLIANCE OBLIGATION OF ONE OF THE CONTRACTING PARTIES

11. Organising the search for information by contract, while integrating in advance the limits to be set to such interference. Outline. Two perspectives, those of whoever wields the contractual art of Compliance, must be adopted and articulated. First, the stipulation must be built so that it produces useful information: fixing its material and temporal scope, and first of all the triggering event – periodic audits, or audits prompted by an event or by information other than that which the audit will reveal, notably the red flag –, designating who will conduct the audit, the regulated party’s auditor or a third party chosen by both contracting parties, which then brings the clause closer to a discovery procedure, and finally setting out the modalities of its conduct (A). Then, within that very drafting, the risks and limits of an audit contractually imposed on others to satisfy one’s Compliance obligation must be integrated in advance: the ever-present shadow of significant imbalance, the tacit obligation to carry out the audit that the clause creates against the party that stipulated it, and the fact that the audit remains an investigative measure like any other, to which the co-contractor’s freedom is opposed and in which the rights of the defence take root (B).

A. DRAFTING THE AUDIT CLAUSE TO OBTAIN THE RELEVANT INFORMATION FROM THE PERSONS WHO HOLD IT AND WHERE IT IS LOCATED

12. The heart of the clause: the information that the audit will bring for the fulfilment of the Compliance obligation. Outline. Four questions arise for the drafter, and they arise in this order, because each governs the next. What information must the audit bring back, and therefore from whom, on which documents and in which places will it be sought (1)? At what moment, and upon the occurrence of what fact, is the audit triggered (2)? Who will conduct it (3)? And according to what modalities will it be carried out (4)? The order is not indifferent: a clause that designates an auditor before saying what they must look for confers a power without an object, and a clause that settles the modalities without having fixed the trigger organises a procedure that never gets under way.

1. Through the audit clause, contractually fixing the information to be sought by the Compliance audit conducted at the co-contractor’s

13. The information that the contractual Compliance audit must make it possible to reach: that which enables the regulated party to detect and prevent failure and systemic risk. Link between the legal obligation and the stipulation. The audit does not seek all the information available at the co-contractor’s, but that which the beneficiary of the clause needs in order to meet its legal Compliance ObligationThe Compliance Obligation is understood here as the obligation placed on crucial operators to contribute to the preservation of systems and to the protection of the human beings involved in them; see supra § 6.. It is the legal obligation that shapes, by ricochet, the object of the stipulation, and not the powerful undertaking’s interest in knowing as much as possible about its partner. A well-drafted clause starts from there: it refers to the regulation under which its beneficiary must be accountable, it deduces from it what must be detected, and it admits within the scope of the audit only the information that serves that detection. Two layers overlap, which must not be confused. The first is that of conformity: the aim is to establish whether or not the co-contractor obeys the requirements applicable to it or contractually transferred to it, the information sought then being the failure, observed or probable, that is to say the risk of non-conformity. The second is that of Compliance: the aim is to measure what, within the partner’s organisation, puts the system itself at risk, and the information sought is no longer a failure but a vulnerability, which is not necessarily a fault. The distinction is as practical as it is theoretical, for the first is proved whereas the second is assessed: a clause that asked only for the first would leave its beneficiary helpless for the properly systemic part of its obligation. The result is a drafting criterion, which is also a measuring criterion: relevant is the information without which the regulated party can neither detect nor prevent, the stipulation having to remain proportionate to the risks identified by the risk mapThe criterion of proportionality to the risk map is the one adopted by the French Anti-Corruption Agency (AFA) for third-party assessment: Avis relatif aux recommandations de l’Agence française anticorruption destinées à aider les personnes morales de droit public et de droit privé à prévenir et à détecter les faits de corruption, de trafic d’influence, de concussion, de prise illégale d’intérêts, de détournement de fonds publics et de favoritisme, JORF no. 0010 of 12 January 2021, text no. 61, section « Évaluation de l’intégrité des tiers », §§ 201 to 245, esp. § 207, according to which the nature and depth of the assessments and of the information to be gathered are determined according to homogeneous groups of third parties with comparable risk profiles, as the risk map allows them to be drawn up. See supra § 17.. What exceeds that perimeter is no longer Compliance: it is the capture of information about a partner, to which the ordinary law opposes its own instruments.

14. Designating in advance the persons likely to provide this information. Information is not in the walls: it is in people. A clause that merely opens a “right of audit” without saying who may be seen gives its beneficiary only a theoretical power, which the co-contractor will satisfy by presenting the least informed contact person in its company. Three designation techniques are found, which may be combined. Designation by functional category refers to persons by the place they occupy in the organisation – compliance officer, purchasing director, site manager, whistleblowing officer – and has the advantage of surviving staff turnover. Designation by place refers to those who are where the risk lies: the establishment, the factory, the subsidiary, the lower-tier supplier. Nominative designation, finally, only makes sense for positions whose holders are stable and known on the day of the contract; it is the most fragile and calls for an updating stipulation. The choice between them is not a matter of convenience: it is made in the light of what the audit must produce, and thus in the light of the objectives pursued and the Compliance regulations concerned, which do not designate the same holders of informationThird-party assessment under Article 17 of the so-called "Sapin 2" Act, op. cit., leads to the purchasing and sales functions; the duty of vigilance, to the industrial and social functions; data protection, to the controller and the data protection officer.. Hence the temptation, which must be resisted, to write that the audit may hear “any person”. The formula seems to give everything and gives nothing certain: besides exposing the stipulation to the complaint of significant imbalance, it deprives the beneficiary of the only argument that secures performance, that of necessity, and it leaves the co-contractor free to choose the person it will present. The list of persons is therefore not a technical annex to the clause: it is part of it, and it must be revisable, since the risk map from which it derives is itself revisable.

15. Designating in advance the documents through which information can be reached. Duplication of an internal audit. The most natural approach is to refer to the documents that the co-contractor already draws up for itself: the reports of its internal control and internal audit, its accounting and financial documents, its risk map, its third-party assessment procedures. The Compliance audit clause then operates less as a new investigation than as a duplication: it transfers from one undertaking to another the product of a control already organised, which explains its frequency and its low cost. The stipulation must still say so, for the internal audit report is not in itself communicable: it was drawn up for the co-contractor’s management body, not for its partnerThis is the first effect of the clause: it makes contractually obtainable a document which, by its purpose, was not. The stipulation should therefore refer to reports by their object and period, and not by their title alone, which the co-contractor controls.. But the document is only a starting point. It says what was looked at by the one who was looking at itself; it says neither what was not, nor what one preferred not to write. This is why the clause must answer the question that the document raises: should one go further, and by what method? Three degrees follow one another, which are not of the same nature. Communication of documents leaves the co-contractor master of what it hands over. On-site visits let the auditor into the undertaking and give access to what has not been sorted for it. The interview, finally, no longer concerns documents but persons, and it is there that the audit changes nature: it becomes an investigationSoft law confirms this sequence, but only on the side of the undertaking examining itself: the practical guide of the French Anti-Corruption Agency (AFA) and the National Financial Prosecutor's Office (PNF) holds that internal control or internal audit reports, where they reveal facts resembling corruption or failures in prevention and detection procedures, may serve as a basis for opening an internal investigation. AFA and PNF, Les enquêtes internes anticorruption. Guide pratique, March 2023. No text or guideline, however, addresses the same sequence where the audit takes place at a third party's premises: that is the gap the clause must fill.. The word is not excessive, for the powers deployed are those of the internal investigation – gathering statements, confronting versions, access to e-mail systems and traces – exercised this time outside any subordination, on other people’s employees, and for the benefit of an undertaking that is not their employer. The clause must therefore provide for this transformation, and provide for it as such: not through an extension formula (“and more generally any necessary act”), but by naming the acts, designating who will perform them, setting out what the person heard knows before being heard and what they may objectThe limits then come from the ordinary law, not from the contract: trade secrets (Arts. L. 151-1 ff. of the French Commercial Code); the protection of the data of the persons heard, who are not the beneficiary's employees (GDPR, Art. 14; CNIL framework of 18 July 2019 on professional whistleblowing); the professional secrecy of the lawyer where the auditor is one, which the Paris Bar recalled in response to the aforementioned guide; and, downstream, Articles 434-4 and 434-15 of the French Criminal Code, to which the guide itself refers.. If this is not provided for, the beneficiary faces the worst alternative: either it stops at the documents and its detection obligation remains unfulfilled, or it goes ahead, and the acts it then performs are without title – the contract does not cover them, no text authorises them, and what it has gathered risks being worthless on the day it must be used. The same reason condemns the temptation to write that the audit will cover “all documents”: the formula seems to give everything, but it moves the stipulation from the ground of necessity to that of power, where the ordinary law awaits itSee infra § 24, on the shadow of significant imbalance (Art. 1171 of the Code civil; Art. L. 442-1, I, 2°, of the French Commercial Code)..

16. Designating in advance the places in which information can be reached. Place is not a detail of performance: it governs what the audit can reach. Three series of places must be named. Physical places first – head office, establishments, production sites, warehouses –, bearing in mind that a clause referring only to the registered office leaves outside its scope precisely what is most rarely found there: risk lies in factories and at suppliers’, not in the management’s offices. Intangible places next, which are today the foremost: information systems, professional e-mail systems, hosting spaces, including when entrusted to a service provider, so that the clause must provide for the case where the information is held by a third party to the contract. Finally, other people’s places, those of lower-tier suppliers, which the beneficiary can only reach by requiring its co-contractor itself to obtain the corresponding stipulation: this is the cascade effect, by which the audit clause spreads along the value chain without its initial beneficiary ever having a contractual link with those it ultimately reachesThis is one of the points where the audit clause most visibly turns third parties into quasi-parties: the lower-tier supplier undergoes an audit whose beneficiary is contractually a stranger to it. See supra § 9, on "concerned third parties".. To this is added the geographical dimension, which is not only a matter of distance: an audit that travels outside France, or that takes the information gathered out of the European Union, encounters rules that are not those of the contract, and that the contract cannot set asideNotably the rules on transfers outside the European Union (GDPR, Chapter V) and, conversely, French Act no. 68-678 of 26 July 1968 on the communication of economic, commercial, industrial, financial or technical documents and information to foreign natural or legal persons, known as the "blocking statute".. The clause must therefore designate places as it designates persons: by category rather than by address, in the light of the risk to be detected, and with the possibility of revision that a moving risk map requires.

17. The drafting criterion: proportionality between the extent of the information sought and the legal objective or the undertaking’s own objective. The three designations above – persons, documents, places – have no value in themselves. They are neither maxima nor minima, and nothing imposes a priori one extent rather than another: drafts vary, and must vary. What holds them together is a teleological reasoning, which relates the extent of the information captured to the purpose in the name of which it is captured. Yet these purposes are not of equal strength. That of the regulations is the most solid, because the co-contractor is deemed to accept it: no one disputes that a regulated undertaking must assess its partnersThis is the movement described by Antoine Oumedjkane: texts no longer so much grant undertakings powers of control as oblige them to use them, third-party assessment under Article 17 of the so-called "Sapin 2" Act, op. cit., being the example. The regulatory purpose therefore need not be negotiated: it is already in the Law (« Puissance publique et pouvoir de contrôle des entreprises », D. 2025, pp. 1636-1642).. That of Compliance Law, which the regulation implements, stands behind the first and gives it its meaning. That of the undertaking itself is of another nature: where the audit serves the beneficiary’s purpose (raison d’être) rather than a text, it is no longer justified by the Law but by agreement, and it must therefore be expressly accepted. The practical consequence is simple: the more specific to the beneficiary the information sought, and the more invasive the method used to reach it, the more the stipulation must be written, reasoned and acceptedThis is also what shields the stipulation from significant imbalance: what is censured is the discretionary and barely legible dimension of the reserved power, not its unilateral nature, so that a clause reproducing a clear text escapes it, whereas a standard clause, indifferent to the auditee's resources and position in the chain, is exposed to it. See M. D’Angelo Petrucci, « Réflexions sur l’essor des clauses de compliance dans les contrats d’affaires », Revue internationale de la compliance et de l’éthique des affaires, no. 1, 10 February 2025, study 18..

18. A piece of drafting advice: the further the capture of information by the Compliance audit is from legal normality, the more it must be, on the one hand, justified and, on the other, accepted by the other party. The rule can be formulated as a scale. What is within legal normality – requesting the documents an undertaking already draws up for itself, checking a figure declared, verifying once a year the performance of a precise obligation – is stipulated briefly and performed without discussion. What departs from it – entering premises, accessing information systems, hearing persons, reaching entities that are not parties to the contract, having the audit survive the end of the relationship – can only be obtained at the price of an express stipulation, reasoned by the risk it serves to detect, and accepted as such. The drafter who forgets this thinks they are saving time by writing broadly; they obtain the opposite, for it is vagueness, not breadth, that the ordinary law sanctionsThe observation has long been made about software licence audits, whose effectiveness depends entirely on the prior clarity of the standard: absent precision, the clause turns into an instrument of pressure and in fact constitutes « un pouvoir de police exorbitant ». See Mathieu Martin, « Pratique contractuelle. Contrats de l’informatique. La clause d’audit de licence », Communication Commerce électronique, no. 3, March 2015, pratique 4..

2. Through the audit clause, contractually fixing the triggering event of the conformity or Compliance audit

19. Setting a periodic timetable means feeding the documents through which the undertaking is accountable. Periodicity looks like a modality of performance; it is a decision of substance. Once a year, sometimes on a fixed date: the rhythm is not chosen at random, it is aligned with that at which the beneficiary must itself be accountable. The audit must have delivered its result before the sustainability report, the vigilance plan and the management report are finalised, failing which the information arrives after the document it was meant to feed. The audit clause is thus set to the calendar of accountability, not to that of the service providedExpress annual periodicity is found in the best-drafted clauses: Article 13.4 of the services contract at issue in CA Paris, pôle 1, ch. 3, 5 March 2024, Coopérative U Enseigne v. Carrefour France and Carrefour World Trade, RG no. 23/06899, opens the right to have the proper application of the contract checked « une fois par an ». Arnaud Lecourt, « La clause d’audit », AJ Contrats d’affaires – Concurrence – Distribution, 2014, pp. 271-272, recommends the same frequency limit, audits being costly and disruptive, but advises against a fixed date..

20. Setting a periodic timetable also means integrating the partner into one’s Compliance obligation. What periodicity produces, beyond the information it brings back, is a habit. The audit ceases to be an event and becomes a deadline; the co-contractor puts it in its calendar, allocates resources to it, designates its contact persons, prepares its documents. The third party is then treated as an internal department of the beneficiary, and this is precisely the effect sought by the Compliance Obligation, which requires the regulated undertaking to hold the value chain as it holds its own organisation. The advantage is real: cooperation replaces constraint, the cost can be foreseen, refusal becomes harder to justify. The price is real too, and it is twofold: a known deadline can be anticipated, and an expected audit shows only what has been prepared for itThis is the objection raised by Arnaud Lecourt, « La clause d’audit » (op. cit.), against fixed-date audits and against notice, which ruin the element of surprise and may reduce the audit to a staged performance. This risk has been compared with that existing in the control exercised by undertakings on behalf of public authorities, by Antoine Oumedjkane (« Puissance publique et pouvoir de contrôle des entreprises », op. cit.): a control based on the documents produced becomes excessively formal and then bears on methodology rather than actual effectiveness..

21. The other trigger: the event, uneventful or already a source of concern (red flag). Alongside the periodic audit, the clause must provide for the prompted audit, the one triggered not by the calendar but by a fact. This fact may come from outside – a report, an investigation opened at the partner’s, press information, an alert from a non-governmental organisation – or from within the system itself: an anomaly detected by third-party assessment, an indicator going off track, what practice calls the red flag. The drafter of the Compliance audit clause has a choice to make here. Either they list the triggering facts, and gain in certainty what they lose in flexibility, for what is not on the list triggers nothing. Or they adopt an open formula – any fact such as to give rise to suspicion of a failure or a risk –, and gain in coverage what they lose in enforceability, the co-contractor being entitled to dispute the reality of the suspicion. The workable solution lies in combining the two: a list of facts that trigger automatically, and a catch-all clause which then requires the beneficiary to give written reasons for its request. The audit indeed lies exactly where suspicion is not yet a failure: it is what comes in between the one and the other, and this is why it can be made conditional neither on proof of what it is meant to establish, nor on the mere assertion of the party requesting itThe question whether mere suspicion suffices, or whether a characterised breach must be awaited, is for instance left open by Antoine Oumedjkane, « Puissance publique et pouvoir de contrôle des entreprises » (op. cit.), with regard to the moment of termination. It is better resolved once one sees that the audit is precisely the step that comes between suspicion and sanction: it is not the sanction, it is what makes it possible to know whether there are grounds for sanction..

3. Through the audit clause, contractually designating who will carry out the conformity or Compliance audit

22. Having the beneficiary of the Compliance audit bear the burden of organising it and/or transferring all or part of that burden onto the co-contractor within whose undertaking the audit will be conducted: the concentric circles of the burden of the contractual Compliance audit. Before saying who will conduct the audit, the clause must say who will bear it: who organises it, who materially carries it out, who bears its cost. The answer is not single, and the configurations are arranged in circles, whose centre is the legally regulated undertaking. At the centre, the beneficiary assumes everything: it triggers, organises, sends its teams or mandates its auditor, pays. This is the most costly and most faithful configuration, for the legal obligation is its own and nothing of it is delegated. In the first circle, the burden is transferred wholly or partly onto the co-contractor within whose undertaking the audit takes place: questionnaires to be completed, self-assessment, declaratory audit conducted under its own responsibility, certifications to be produced, costs charged to it. The beneficiary no longer carries out the audit, it receives it. The gain is obvious, the risk equally so: the information is then produced by the very party to be controlled, and it is only worth what its sincerity is worthM. Martin usefully distinguishes the declaratory audit, carried out under the auditee's responsibility and in principle binding on the creditor save for bad faith, from the audit conducted by the creditor, who can no longer dispute its scope afterwards. The choice of who bears the burden thus governs the evidentiary value of the result (« Pratique contractuelle. Contrats de l’informatique. La clause d’audit de licence », op. cit.).. In the second circle, the burden does not stop at the co-contractor: it passes it on in turn to its own suppliers, who pass it on again, so that it spreads along the value chain, multiplying. The last-tier supplier then undergoes audits in large numbers, with contradictory standards, without having the means to respond: the burden has shifted to the one least able to bear it, while the systemic risk has stayed where it wasRobert C. Bird, "Contractual Deterrence and the Ethical Supply Chain" (op. cit.), notes that some suppliers undergo more than fifty audits a year, with contradictory standards, without this accumulation improving detection in any way. Sabrina Dupouy draws the legal consequence: transferring vigilance in cascade to an under-resourced subcontractor does not exonerate the ordering company (« Le tiers face à la contractualisation de la compliance », op. cit.).. Three drafting requirements follow. Say who organises, rather than implying it. Say who pays, and according to what rule the cost is redistributed if the audit reveals a failureOn the three models of cost allocation, see infra note no. 55. American practice, for its part, places all costs on the auditee, unconditionally: J.-Ch. Roda, « Clause de compliance » (op. cit.).. Say finally what the auditee’s own output is worth, failing which the beneficiary will discover, when relying on it, that it holds only a declaration. And one limit dominates these three requirements: transferring the burden is not transferring the obligation. The regulated undertaking remains bound to detect, and having placed the audit on someone else does not exempt it either from checking it or from answering for it.

23. The choice of the technical expert by the beneficiary of the audit. It may happen that the internal departments of the contracting party benefiting from the clause carry it out, notably if the undertaking has a large internal control department that could apply its technical skills externallyOn the analogy between internal control and audit, see supra § 1.. Most often, it is the regulated party’s auditor who will carry out the audit. In such a case, either the auditor may be designated in advance in the clause, or the contracting party with the contractual power to have the Compliance audit carried out reserves the power to designate that technical expert when it activates the clause and informs its co-contractor that it wishes to have a Compliance audit carried outThis is the most frequent practice, and Arnaud Lecourt, « La clause d’audit » (op. cit.), advises against it for that very reason, recommending that the mission be entrusted first to a regulated profession with a code of ethics, whose name and standing appear in the clause..

24. The risk of conflict of interest and the possibility of a technical expert external to the beneficiary of the audit to carry it out. The most frequent choice – the beneficiary’s own departments – is also the most open to challenge, and three objections of unequal strength are raised against it. The first concerns conflict of interest: the person conducting the audit is the agent of the party that will draw the consequences, so that they are both judge and party. The second concerns significant imbalance: under cover of Compliance, the beneficiary undertaking would exercise a power whose triggering, object and outcome it alone would determine. The third, more radical, is that of potestativity: one contracting party’s obligation would then depend on the sole will of the other. The answer is known, and it lies in two elements: the objectivity of the standard against which the audit is conducted, and the standing of the person who conducts it. Once the outcome of the audit depends not on the beneficiary’s will but on rules defined in advance, applied by a person whose professional ethics guarantee independence, the complaint falls awayThis is the criterion adopted by CA Paris, 25e ch. B, 28 June 2002, Fernandez v. Sté Puissance 5, unreported, commented on by Jacques Mestre and Bertrand Fages: the stipulation is not a potestative condition where the price results from an audit by the statutory auditor subject to strictly defined accounting rules, and not from the beneficiary's sole decision (RTD civ. 2002, pp. 804-805). The requirement echoes that of the functional independence of the controller – sufficient authority, absence of instructions, non-participation in operational activities – a requirement noted by Antoine Oumedjkane, « Puissance publique et pouvoir de contrôle des entreprises » (op. cit.). The judgment commented on is unreported and could not be found.. Hence the three techniques that practice has developed: entrusting the mission to a regulated profession; confining the choice to a closed list of firms set in the contract; or relying on a third party designated by mutual agreement – in which case the clause must imperatively provide for its own fallback designation mechanism, failing which disagreement suffices to paralyse itArticle 7 of the contract at issue in the Coopérative U case, op. cit., confines the choice to a closed list – PwC, Deloitte, EY, KPMG, through their Paris offices – and then, failing agreement within five working days, allows the more diligent party to have a third party appointed by the President of the Paris Commercial Court. It is the best model in the file, and yet it failed: the procedure referred to – the President ruling "en la forme des référés" – had been repealed by the Order of 17 July 2019, so that the judge declared that it had no power. The procedural referral in an audit clause must therefore be dated, and checked at each renewal.. This last route brings the clause closer to a discovery procedure: the two contracting parties agree on who will seek the information, and accept in advance what they will find.

4. Through the audit clause, fixing the modalities of the Compliance audit

25. Fixing the modalities of the audit. Modalities pass for logistics; in reality they decide everything. It is there that the balance is struck between what the audit must produce and the interference it represents, and it is there that the value of what it will bring back is at stake: an audit whose conduct has not been settled yields information whose conditions of collection the co-contractor can always dispute. Seven points must be settled, none of which goes without saying.

Notice first, the most debated point: prior announcement allows the auditee to mobilise its resources, but it also gives it time to prepare what it will showAuthors are divided. Arnaud Lecourt formally advises against any notice stipulation, which would ruin the element of surprise (« La clause d’audit », op. cit.). Conversely, Mathieu Martin deems it necessary, since the audit mobilises considerable resources at the auditee's (« Pratique contractuelle. Contrats de l’informatique. La clause d’audit de licence », op. cit.). The disagreement in fact depends on the object of the audit: surprise is useful to check declared figures, cooperation is indispensable to reconstruct a system known only to the auditee. The Compliance clause, which pursues both, does well to distinguish according to the trigger: notice for the periodic audit, no notice for the audit prompted by a red flag.. Duration and hours next, which prevent the audit from becoming, by its sheer length, a disruption of business. The auditee’s cooperation, which must be stipulated as an obligation to act and not assumed: making contact persons available, access to premises and systems, handing over documents within a time limit. Costs, whose allocation admits several formulas, and which are best borne by the beneficiary unless the audit reveals a failureThree models are found: costs borne by the creditor, passed on to the auditee if the audit reveals a failure, possibly above a set threshold (A. Lecourt, « La clause d’audit », op. cit.); costs borne by the auditee unconditionally, the formula of American practice; costs advanced and then reimbursed, reimbursement finding its cause in the option reserved to the other party (J. Mestre and B. Fages, « La clause d’audit est-elle potestative ? », op. cit.).. Confidentiality, the point at which the clause protects the auditee: ring-fencing commercially sensitive information, fate of copies taken, sanction for disclosure. Obstruction finally – sabotaged audit, cursory information, concealment – whose sanction must be written, failing which the beneficiary is left with no remedy other than the courts. And the report, which closes the operation: delivered to both parties, discussed adversarially, its conclusions stated without reservationM. Martin requires transparency of conclusions and rules out conclusions "subject to…", which leave the auditee under an indefinite threat. He usefully distinguishes the declaratory audit, carried out under the auditee's responsibility and in principle binding on the creditor save for bad faith, from the audit conducted by the creditor, who can no longer dispute its scope afterwards (« Pratique contractuelle. Contrats de l’informatique. La clause d’audit de licence », op. cit.). As to the follow-up – basis of the adjustment, associated costs, time limits, third-party claims – the clause does well to be as precise as it is about the conduct of the audit., together with what will be done with what it has established.

B. INTEGRATING INTO THE DRAFTING OF THE CLAUSE THE RISKS AND LIMITS OF THIS AUDIT CONTRACTUALLY IMPOSED ON OTHERS TO SATISFY COMPLIANCE

26. The wisdom of integrating the limits and risks of the Compliance audit clause from the drafting stage. Outline. A well-made audit clause does not merely organise the power it confers: it integrates, from its drafting, what will resist it. Two orders of considerations arise, which must not be confused. Limits first, that is to say what the audit will not be able to reach, which the drafter has every interest in naming rather than ignoring, because a written limit becomes a justification on the day the outcome of the audit is disputed (1). Risks next, that is to say what the audit exposes the very party that stipulated it to: the tacit burden of carrying it out, the complaint based on the rights of the defence, and the use others will make of its report (2).

1. Integrating into the Compliance audit clause its very limits

27. Giving oneself the contractual power to conduct a Compliance audit also means taking on a tacit obligation to conduct it. Power turns into burden. The party that demanded the clause has thereby declared that the audit was necessary for the performance of its legal obligation; it can no longer argue afterwards that it could dispense with it. Failure to perform the audit clause is therefore not a mere abstention: it is a breach, and that breach can be invoked not only by the co-contractor but by those who have suffered from the risk that the audit should have detected. The drafter who measures this draws two practical consequences. The first is that one should not stipulate an audit clause one has neither the intention nor the means to implement: better a narrow clause that is performed than a broad and dormant oneThe mechanism is formulated by Maxime D’Angelo Petrucci, who recommends not stipulating the clause if the creditor has neither the intention nor the resources to implement it, failure to implement it being liable to be perceived as negligent (« Réflexions sur l’essor des clauses de compliance dans les contrats d’affaires », op. cit.). Sabrina Dupouy presents the situation of the undertaking "benefiting" from the audit clause more severely: the injured third party may invoke the mere contractual breach as a tortious fault, without further proof, which applies to non-performance of an audit clause (« Le tiers face à la contractualisation de la compliance », Droit des sociétés, no. 4, April 2024, study 5). Robert C. Bird, "Contractual Deterrence and the Ethical Supply Chain", Boston College Law Review, vol. 63, no. 8, 2022, pp. 2539-2620, documents it by noting that lead firms rarely pursue the failures observed, which ruins the deterrent effect of the audit.. The second is that it must be stipulated that not exercising the right of audit at a given deadline does not amount to a waiver of exercising it laterThis is the contractual answer of the Model Contract Clauses: D. V. Snyder, S. A. Maslow and S. Dadush (Working Group to Draft Model Contract Clauses, ABA Business Law Section), "Balancing Buyer and Supplier Responsibilities: Model Contract Clauses to Protect Workers in International Supply Chains, Version 2.0", The Business Lawyer, vol. 77, no. 1, 2021-2022, pp. 115-182, whose section 5.1 provides that the parties' conduct, including the buyer's failure effectively to exercise its audit rights, constitutes neither a waiver nor an element in assessing its remedies. The MCC 2.0 moreover contain no stand-alone audit clause: they presuppose audit rights stipulated elsewhere and regulate their effects..

28. Limiting the benefit of the contractual Compliance audit to the contracting party bearing the Compliance obligation, so that its co-contractor, or even the concerned third parties outside the contract, cannot rely on it. The clause is stipulated in the interest of the party bearing the legal obligation, and this must be written, for two diversions lie in wait. The first comes from the co-contractor itself, which would be tempted to rely on the audit undergone as a discharge: audited without reservation, it would claim to be compliant, and would turn the silence of its own report against the beneficiary. The second comes from the concerned third parties, who might see in the clause a stipulation made for their benefit and demand its performance. It must therefore be written that the audit report is neither approval, nor discharge, nor acknowledgement of conformity, that it does not exhaust the other means of control, and that the clause creates no right for the benefit of a third party. The precision is not a matter of style: it prevents the instrument of detection from becoming the instrument of exonerationSabrina Dupouy likewise notes that an undertaking's communication on its contractual mechanisms, audit clauses included, is a signal sent to the market that is sometimes mere greenwashing, and that transferring vigilance in cascade to an under-resourced subcontractor does not exonerate the ordering company (« Le tiers face à la contractualisation de la compliance », op. cit.)..

29. Turning the limits linked to the legal autonomy of persons, the confidentiality of information and the inaccessibility of places into so many justifications with regard to the outcome of the contractual Compliance audit. Three limits are irreducible, and it is futile to draft as if they did not exist. The legal autonomy of persons first: the co-contractor is master neither of its own partners nor of its employees, whose consent it cannot deliver nor whose word it can guarantee. Confidentiality next, which is not a pretext but a right: trade secrets, personal data, the professional secrecy of those who advise the auditee. The inaccessibility of places finally, whether due to foreign law, to the location of data or to the fact that the information is held by a third party to the contract. The reversal the drafter must perform is as follows: these limits, named in the clause, cease to be failures attributable to the auditee and become the justifications for the result obtained. The audit that has not seen everything, but says why and within what bounds, establishes the diligence of whoever conducted it; the audit silent about its own limits proves nothingRobert C. Bird, "Contractual Deterrence and the Ethical Supply Chain" (op. cit.), lists the avoidance techniques encountered by social audits: bribing the local auditor, selecting and coaching the employees interviewed, restoring emergency exits and removing children before an announced inspection, undeclared subcontractors, showcase factories, double bookkeeping. He derives four drafting requirements: making control visible and its consequences known, defining concretely the object of control, ensuring the perceived legitimacy of the standard, limiting the complexity of standards. Failing this, the audit degenerates into public relations vehicles, auditors having an interest in reassuring in order to keep their mandate..

30. Always drafting the description of the limits in the light of the aforementioned purposes of the Compliance audit clause. The description of limits obeys the same criterion as the description of scope: purpose. A limit is enforceable only if it makes sense in the light of what the audit must establish. Writing that the co-contractor may refuse access to “any sensitive information” protects no one, for the formula is as broad as the one which, conversely, would open the audit to “all documents”. Writing, on the other hand, that the auditor has no access to the pricing data of other customers, since detecting the risk of corruption does not depend on it, sets out a limit that holds, because it is measured against the purposeSee supra § 17, on the criterion of proportionality and teleological reasoning, of which the description of limits is merely the reverse application.. Symmetry is the rule here: what applies to delimiting the power applies to delimiting what escapes it.

31. Organising by contract the burdens of proof with regard to the limits, framed as exceptions to the principle of accessibility. There remain the burdens of proof, which the clause must allocate before the dispute freezes them. The technique is that of principle and exception: the principle is the accessibility of information falling within the defined scope, the limits are its exceptions, and it is for the party invoking them to establish them. The co-contractor that raises trade secrecy, material impossibility or a third party’s refusal must therefore prove it, not merely allege it. Absent such allocation, the burden is reversed: it is the beneficiary who will have to prove that the information was owed to it, at the very moment it does not have what would enable it to prove it, since that is precisely what is being refused to itHence the interest in also stipulating the sanction for obstruction – sabotaged audit, cursory information, concealment – most often termination and damages, together with delivery of the documents under penalty: A. Lecourt, « La clause d’audit » (op. cit.)..

32. Always keeping a record, from the time of drafting to the time of performance of the audit clause. The audit clause has an evidentiary dimension that only operates if records have been kept. From the time of drafting: what the parties intended to cover, the risk map to which the scope referred, the successive versions of the stipulation. From the time of performance: the audit request and its reasons, the date on which the auditor was appointed, the period covered by their work, the documents handed over and those refused, the persons heard, the limits encountered. This is not archiving: it is the very substance of the demonstration that the regulated undertaking will have to make, not to the co-contractor, but to the authority or the court before which it will account for its diligenceThe report of the Audit Responses Committee, ABA Business Law Section, "Report on Audit Response Timing Issues", The Business Lawyer, vol. 77, no. 1, 2021-2022, pp. 183-190, although devoted to letters addressed to auditors, offers a transposable temporal grammar: the perimeter is fixed by identifying the entities and the financial year, the effective date of the response is distinguished from its date of issue, the subsequent updating obligation may lawfully be excluded, and the method of delimiting the period – Entire Period Approach or Snapshot Approach – must be stated..

2. Integrating into the Compliance audit clause its risks

33. Integrating the fact that the audit may be characterised as an investigative measure like any other when it is a matter of identifying a failure: the risk of complaint with regard to the rights of the defence. As long as the audit checks declarations and reconciles figures, it remains a control. As soon as its object is to identify a failure and its author, it becomes, by its object if not by its name, an investigative measure: evidence is sought, persons are heard, responsibility is attributed. The complaint is then foreseeable, and it does not come from contract law: the person implicated by an audit conducted at their employer’s, for the benefit of an undertaking that does not employ them, will argue that they did not know what they were suspected of, that they were not usefully heard, that they could not put forward their version. The risk is not only moral: it affects the result, for evidence gathered in such conditions may be worthless before the court that will one day have to hear itSee supra § 15, on the point at which the audit changes nature by moving from the document to the person. The vocabulary of intrusion is found in the mouths of auditees themselves: in CA Paris, pôle 5, ch. 4, 14 January 2026, Centre Vidéo Distribution v. RDM Video, RG no. 24/04702, the distributor required, on simple written request, to hand over its detailed balance sheets for the last three financial years speaks of « inquisition »; the court notes that access to all accounting documents without justification is perceived as interference in management..

34. Organising in advance minimal respect for the rights of the defence if circumstances call for them. There is no trial, and therefore no rights of the defence in the procedural sense; there is nonetheless a minimum to be organised, and the clause is the only place where it can be. This minimum is modest: the person heard knows why and in what capacity, they are not bound to incriminate themselves, their statements are recorded and read back, they may be assisted, what they say does not go beyond the object for which the audit was triggered. None of this slows the audit down; all of it conditions the value of what it brings back. And what is written in the clause is better than what will be improvised on site, for an auditor who applies a procedure agreed in advance does not have to justify their ownThe AFA-PNF practical guide, op. cit., although it reasons on the investigation conducted by an undertaking on its own employees, provides the material for these stipulations: informing the persons concerned, conducting interviews, archiving and retaining the evidence gathered, strict confidentiality. There is to date no text or guideline governing the same question where the investigation takes place at the co-contractor's, on other people's employees: the clause alone makes up for it..

35. Organising by contract the burden of proof as to the triggering of procedural rights in the conduct of an exercise that is primarily accounting and financial. One must still know when this regime applies, for the exercise is primarily accounting and financial and is not meant to be weighed down with procedural safeguards at every step. The threshold must therefore be stipulated, and the burden of proving it allocated. The simplest is to make the switch a question of object rather than intensity: as long as the audit concerns documents and procedures, it follows the ordinary regime; as soon as it concerns the conduct of an identified person, it follows the reinforced regime. The party arguing that the threshold has been crossed – most often the person heard – must establish it; but the party conducting the audit must have kept enough to prove the contrary, which brings us back to records.

36. Integrating the risk that the contractual Compliance audit report may be used as a lateral or subsequent strategic weapon: limiting it through confidentiality and/or integrating it into the conduct and the drafting. Once drawn up, the report lives its own life, and this is the last risk, the least anticipated. Laterally, it may serve in a quite different relationship from the one for which it was made: price renegotiation, commercial dispute, communication to the market, handing over to an authority. Subsequently, it may be produced in proceedings to which the party that commissioned it is not a party, or used against it on the day it must explain what it knew and did not prevent. Two techniques respond to this risk, and they are cumulative rather than mutually exclusive. The first is confidentiality: recipients exhaustively listed, prohibition of communication except as provided by law, fate of copies, duration. The second, more demanding, consists in integrating the risk into the very conduct of the audit and the drafting of the report: distinguishing finding from attribution, not giving a legal characterisation to what is merely an anomaly, writing in the knowledge that the document will be read by others than its addressee. An audit report is an exhibit; it must be written as suchThe Coopérative U case, op. cit., gives the reverse illustration: the audit request made after the partnership ended was analysed as a purely evidentiary measure intended to prepare a dispute rather than to preserve evidence, and Article 145 of the French Code of Civil Procedure was set aside. The contract moreover provided that the audit be carried out « dans des conditions excluant toute communication d’informations commerciales sensibles »: ring-fencing is the first of the techniques. On subsequent use, CA Paris, pôle 5, ch. 4, 16 June 2021, SPI International v. EuropaCorp, RG no. 17/05010, gives the complete chain – the audit establishes the failure, the failure feeds the formal notice, the formal notice triggers the termination clause – and the evidentiary regime: the report is authoritative as long as the auditee produces nothing..

II. OUTSIDE AN AUDIT CLAUSE INSERTED TO FULFIL ONE’S COMPLIANCE OBLIGATION: ITS LEANING ON THE OTHER STIPULATIONS

37. It needs other clauses to function well; it exists to make other clauses function well. Outline. An isolated audit clause produces nothing. It provides knowledge, and knowledge is not an end: its value lies only in what it makes it possible to demand, refuse, correct or terminate. This is why the examination from within, which we have just carried out, is not enough: the clause must be looked at from outside, in the interplay of the stipulations around it. This interplay has two directions. In the first, the audit clause is carried: it leans on what precedes it, the stipulation it serves and the structure in which the parties are already caught, and it is from this support that it derives its measure (A). In the second, it carries: other clauses lean on it, which can only operate on the fact it will have established, and it is then the audit clause that gives the others their point of application (B). Received and given, it is the point through which information passes in the Compliance contract.

38. Leaning rather than accessory: what the ordinary law opposes to the vocabulary of hierarchy between clauses. As already said: the formula “necessary accessory” describes a function, not a regime, and what the ordinary law grasps is not the hierarchy of clauses but their divisibility. The question is resolved by the function each performs within the intended economy, not by the place it occupies in the instrument. The shift in vocabulary is not cosmetic: it governs the answer to the two situations that practice will encounter, that of the conformity clause annulled while the audit is already organised, and that of the audit clause deprived of effect while the conformity obligation remains.The ordinary law knows no category named "accessory clause": the theory of the accessory operates between goods, claims and contracts, not between stipulations of the same instrument. It is Article 1184 of the Code civil that governs divisibility, and consolidated scholarship adopts a hierarchised dual set of criteria, teleological first, subjective second: T. Genicon, « Conséquences de la nullité d’une clause sur le sort du contrat », and, by the same author, « De la nullité partielle à la clause réputée “partiellement” non écrite »; A. D’Adda, « Nullité partielle, clause réputée non écrite et intégration corrective du contrat », which gives the modern reading of the criterion: no longer the search for a hypothetical will, but the objective assessment of the weight of the stipulation within the economy of the instrument. Compare, for the interdependence of contracts within the same transaction, Cass. ch. mixte, 17 May 2013, nos. 11-22.768 and 11-22.927. No decision has to date ruled on the fate of an audit clause after the fall of the clause it serves: the comparison is a construction, and it is assumed as such.

A. THE COMPLIANCE AUDIT CLAUSE LEANING ON OTHER COMPLIANCE CLAUSES

39. What the audit clause leans on: the stipulation it serves, and the structure in which it fits. Outline. The audit clause is never understood on its own, and its first support lies upstream of itself. It is twofold. It leans first on the stipulation it is meant to make effective, and its regime depends on it: as accessory to a conformity clause, it is only an instrument of verification, measured by the co-contractor’s obedience to a text; as accessory to a Compliance clause, it becomes something quite different, since it is no longer a matter of observing obedience but of preserving a system, which opens it to third parties with whom the undertaking has no contractual link (1). It leans next, and this time outside the contract that carries it, on the structure in which the parties are already caught: when that structure is integrated by the Law or by the market, the audit does not have to create the subjection that makes it possible, it finds it, and its justification is lightened accordingly (2).

1. The audit clause, according to whether it leans on a conformity clause or on a Compliance clause

40. The audit clause, a mere effectiveness tool for greater conformity. Leaning on a conformity clause, the audit clause is only an instrument of verification, and its whole regime follows from this. What it seeks is binary: the co-contractor has done, or has not done, what a text or a stipulation required of it. The standard is given in advance, external to the parties, and the audit need only confront it with the facts. Hence three features. The scope is narrow, because it is limited to what the clause served requires. Proof is simple, because a failure is observed. And the complaint of imbalance almost dies out of itself, because a stipulation that merely verifies obedience to a clear text confers no discretionary power. This is the oldest configuration, that of distribution networks and licences, where the audit checks declared figures. It gives the clause its maximum effectiveness and its minimum ambition: it increases conformity, it does nothing elseThis is the configuration described by Arnaud Lecourt with regard to distribution networks (« La clause d’audit », op. cit.), and by M. Martin with regard to software licences, who expressly characterises this audit as an audit of conformity of licence use (« Pratique contractuelle. Contrats de l’informatique. La clause d’audit de licence », op. cit.). As to immunity with regard to Article L. 442-1, I, 2°, of the French Commercial Code, a clause that merely reproduces a clear and precise text escapes it, what is censured being « la dimension discrétionnaire et peu lisible » of the measure and not its unilateral nature (Cass. com., 28 February 2024 and Cass. com., 4 September 2024, reported by Jean-Christophe Roda, « Clause de compliance », in F. Buy, J. Heinich, M. Lamoureux, J. Mestre and J.-Ch. Roda, Les principales clauses des contrats d’affaires, Lextenso - LGDJ, « Droit et pratique professionnelle » series, 3rd ed., 2025, chapter 17)..

41. The audit clause, leaning on a Compliance strategy: a new development of the contractual audit. Leaning on a Compliance clause, the same technique changes nature. The standard is no longer a text to be confronted but a goal to be served, and the audit no longer seeks only a failure: it seeks a vulnerability, in an organisation the beneficiary does not control. The scope widens, the duration lengthens, the means grow heavier, and the stipulation leaves the register of verification for that of strategy. The American practice of monitoring clauses gives its extreme form, which is no longer an audit clause but a surveillance regime, and one measures there both the power of the instrument and the point at which it tips over. This is where the new development of the contractual audit lies: no longer verifying what is due, but organising continuous knowledge of the other, in the name of a goal that goes beyond the contractOn American monitoring clauses, which go well beyond the classic audit clause – considerable volume of information, transmission of confidential information subsequently passed on to federal authorities with loss of privileges, obligation to keep books and accounts open several years after performance, Halliburton's model audit right clauses providing for four years, verification by the creditor at the debtor's premises or by a monitor, costs borne entirely by the auditee, termination in case of refusal of periodic inspections – see J.-Ch. Roda, « Clause de compliance » (op. cit.). On the model clauses that the so-called CS3D Directive entrusts to the Commission, see M. D’Angelo Petrucci, « Réflexions sur l’essor des clauses de compliance dans les contrats d’affaires » (op. cit.)..

42. The audit clause from the perspective of Compliance Law: a contractual path to forge alliances with third parties to the undertaking in order to contribute together to a collective ambition. There remains a third state, the most interesting and the one most likely to be developed in practice. If the Compliance Obligation aims to preserve systems and protect the human beings involved in them, then the audit cannot remain indefinitely what it is in the first two states: the control of one over the other. It becomes a path through which the regulated undertaking forges, with those who are not parties to the contract, something resembling an alliance. The “concerned third parties” then cease to be merely the objects of the audit and become its sources, and sometimes its beneficiaries: their working conditions, their safety, the reality of what they experience come within its scope because that is precisely what the audit must detect. The most advanced model clauses have understood this, placing obligations on the buyer itself and abandoning the unilateral nature of control in favour of shared responsibility. The audit then becomes less a weapon than a bond, and that is, in the long run, the only way to make it effective: control undergone produces concealment, shared control produces information. Now, in matters of compliance, concealment quickly amounts to a breach.This is the shift brought about by the MCC 2.0, op. cit., which impose obligations on the buyer itself and abandon the model of unilateral control, and theorised by Kishanthi Parella, "Contractual Stakeholderism", Boston University Law Review. Robert C. Bird, "Contractual Deterrence and the Ethical Supply Chain" (op. cit.), provides the demonstration a contrario: the audit undergone generates avoidance techniques, and since auditors have an interest in reassuring in order to keep their mandate, control degenerates when it is not perceived as legitimate.

One must measure what this shift entails. In conformity, the audit is a sign of submission: the party demanding it shows the authority that it holds its partners, the party undergoing it shows that it obeys, and the instrument circulates only from top to bottom, producing at best docility. In Compliance, the audit can become the sign of collaboration: what the two contracting parties organise together is no longer proof of one’s obedience, but their common contribution to an ambition that goes beyond both of them, the sustainability of the system to which they belong and the fate of the human beings that this system carries. The stipulation then ceases to be the instrument by which a powerful undertaking treats another’s business as if it were its own, and becomes the one by which two undertakings acknowledge a common charge. It is the same humanism that underlies the Compliance Obligation and this reading of the clause: the partner is no longer a risk to be measured, it becomes an ally to be equipped.

This third state is not one variant among others: it is the specifically European expression of Compliance Law, and it is through it that the latter distinguishes itself from the two other great constructions. American Compliance Law, whose monitoring clauses give the most accomplished contractual form, regards the undertaking as a relay of enforcement: the audit there is the instrument by which the authority, through the undertaking, reaches the latter’s partners, and sanction remains its horizon. Chinese Compliance Law goes even further in the same direction, the undertaking being an instrument of control in the service of political power and the information gathered at the partner’s flowing back to a centre that is not that of the contract. In both cases, the audit clause remains a mechanism of submission, and only the identity of the one to whom one submits changes. European Compliance Law rests on an entirely different idea: the Monumental Goals are not the objectives of an authority that the undertaking would serve, they are a systemic ambition that it shares, because the human beings to be protected are its own too. This is why the audit clause can take the form of an alliance there, when it cannot elsewhere: it is not the arm of a power, it is the bond by which two undertakings jointly hold a charge that neither would bear aloneOn the European conception defended here, see 🕴️M.-A. Frison-Roche, 🏛️Déployer le Droit de la Compliance pour renforcer la souveraineté et accroître l’attractivité de la France avec l’Europe, Report to the French Minister of Justice, September 2026. On the American conception, as reflected in contractual stipulations, see J.-Ch. Roda, « Clause de compliance », op. cit., on monitoring clauses; J. L. Short, M. W. Toffel and A. R. Hugill, "Monitoring Global Supply Chains", Strategic Management Journal, vol. 37, no. 9, 2016, pp. 1878-1897; R. C. Bird, "Contractual Deterrence and the Ethical Supply Chain", op. cit. The Model Contract Clauses 2.0 (D. V. Snyder, S. Maslow and S. Dadush, op. cit.) and K. Parella, "Contractual Stakeholderism", op. cit., mark within American scholarship itself the shift towards shared responsibility. On the Chinese conception, which uses the same techniques for opposite ends, see 🕴️M.-A. Frison-Roche, interview with O. Dufour, 💬« La nouvelle loi de protection des données en Chine est un “anti-RGPD” », Actu-Juridique, 2 September 2021: Compliance mechanisms there serve to obtain obedience, the State being exempt from the constraints it imposes on undertakings, whereas European Law makes the protection of the person the very aim of the system..

43. The purpose pursued by the contracting parties: in application of the Law, but also autonomously from it. A consequence must be drawn that practice has not yet measured. If the audit clause derives its measure from the purpose it serves, that purpose is not always given by the Law. It is when the stipulation comes to perform a legal obligation of assessment or vigilance, and the co-contractor can then hardly dispute it, since it merely carries into the contract what the text imposes. But it may also be set by the contracting parties themselves, autonomously from the Law: two undertakings may agree on an audit that no text requires, because both consider that they must answer for the sustainability of a system in which they take part, or for the fate of the human beings their value chain carries. The stipulation is then no longer the contractual fallout of a public constraint: it is a commitment of their own, and it is the contract itself that becomes the source of the Monumental Goal that the audit serves. The regime shifts on two points. Justification first: what was accepted because the Law required it must here be expressly willed and accepted, failing which the voluntary audit is exposed to the complaint that no legal obligation any longer covers. Scope next: what the contracting parties willed autonomously, they willed for good, and it is hard to see how the party that stipulated such an audit could then argue that it was not bound by it. Autonomy therefore does not make the clause weaker: it makes it more demanding.

2. The audit clause, leaning on a structure already legally integrated

44. The audit clause leaning on conformity and/or Compliance reports within corporate relationships. The first case of leaning on a structure is that where integration is through capital. Between parent company and subsidiaries, information already flows: consolidated accounts, group internal control, escalation of risks, management report and sustainability report. The audit clause is almost superfluous there, since the power exists without it. Its usefulness appears at the margins of the perimeter: the minority subsidiary, the joint venture, the non-controlling shareholding, where corporate power stops and the contract must take over. The drafter then does well to model the clause on what company law already organises, rather than inventing a parallel regime: same periodicities, same recipients, same vocabulary. Above all, they do well to remember that the contractual audit does not carry with it the prerogatives of corporate power: it is only a substitute for it, and a more fragile oneThe figure of the independent third-party body of the mission-driven company (société à mission, Articles L. 210-10 and L. 210-11 of the French Commercial Code) provides a useful point of comparison for the choice of auditor: see S. Dupouy, « Le tiers face à la contractualisation de la compliance » (op. cit.)..

45. The audit clause leaning on legal governance techniques. The second case is richer, because integration owes nothing to capital there. It comes sometimes from the Law, sometimes from the market. From the Law, when regulation itself requires the regulated undertaking to secure by contract access and control over the party to which it entrusts part of its activity: banking and financial outsourcing is the finished example, where the audit clause is no longer a contractual freedom but the condition for complying with one’s own prudential obligations. From the market, when the parties already belong to an organised whole that circulates information and standardises practices: distribution network, purchasing centre, grouping, certification scheme, access to an infrastructure or a market system, financing conditional on sustainability criteria. In all these cases, the audit does not create the subjection, it finds it, and three consequences follow: the justification of the clause is lightened, since membership carries it; the complaint of interference in management loses its force, since control is in the nature of the bond; and the standard is external to the parties, which at the same time rules out potestativityThe finished example is banking outsourcing: on the basis of Articles 238 and 239 of the Order of 3 November 2014, the ACPR Sanctions Committee sanctioned the institution that had assessed the risk arising from outsourcing for none of its outsourced essential services, rejecting the argument that the contracts did not provide for it: ACPR, Sanctions Committee, decision no. 2023-02 of 9 October 2024, Tunisian Foreign Bank. The audit clause there is the condition for complying with prudential obligations, not the expression of contractual freedom. See also supra § 24 on potestativity..

B. THE AUDIT CLAUSE, ON WHICH OTHER COMPLIANCE CLAUSES LEAN

46. What the audit clause makes contractually possible: striking, or drawing closer. Leaning also works the other way round: other Compliance stipulations rest on the audit clause, because they can only take effect on what the performance of the audit clause will have made it possible to establish. All indeed presuppose a known fact, and it is the audit that supplies it. But they divide according to what they do with this fact, and the division is not one of degree: it is one of direction. Some arm the party that knows thanks to the contractual Compliance audit, through the clause anticipating disputes and their resolution, the sanction clause, the termination clause, which turn the finding into a complaint, the complaint into formal notice, formal notice into termination. The audit clause is then what provides the means to strike (1). The other clauses that lean on the audit clause do the opposite: the remediation clause, the corrective action plan, support for the defaulting partner draw from the audit contractually performed not the finding of a failure but the fact of a vulnerability, or even of a need, and derive from it an obligation to do together what has not been done. The performance of the audit clause then provides the means to draw closer (2).

The same information, the same report, thus refers to two opposite contractual economies: which is to say that the audit clause derives its meaning only from those that follow it, and that the drafter chooses, by stipulating them, being able to integrate into the audit clause what the results of the audit are meant to serve. Both will finally come before the court, which will have to interpret the audit clause in the light of the functions it performs, and this must be taken into account from the drafting stage (3).

1. The audit clause to have the means to strike afterwards

47. The audit clause, on which clauses anticipating disputes and their resolution lean. The first family is that of clauses organising the dispute before it arises: escalation clause, expert assessment, prior mediation, jurisdiction clause. They only have an object if there is something to discuss, and that something is produced by the audit. Hence two requirements of articulation, which practice neglects. The first is that the audit report be characterised in the contract: is it an enforceable finding, a mere opinion, prima facie evidence? Failing this, the parties will first quarrel over the value of the document before quarrelling over what it establishes. The second is that the stipulated procedure be workable: the clause referring to a judge, an appointment or a procedural route must be dated and checked, for a procedure repealed between signature and implementation suffices to deprive the clause of all effect, and the most diligent party then finds itself without a judgeThis is exactly what happened in the Coopérative U case, op. cit.: the clause referred to the President of the Commercial Court ruling "en la forme des référés", a procedure repealed by the Order of 17 July 2019; the judge declared that it had no power and the claim was held inadmissible, Article 145 of the French Code of Civil Procedure being moreover set aside for lack of a protective nature of the measure within the meaning of Article 31 of the Lugano Convention. See supra § 24..

48. The audit clause, on which the sanction and/or termination clause leans. The second family strikes. The sequence is well known and mechanical: the audit establishes the failure, the failure feeds the formal notice, the formal notice triggers the termination clause, which may extend to all the contracts binding the parties. Three precautions are required of the drafter. First, the evidentiary regime: the report is authoritative as long as the auditee produces nothing, which is considerable and must be assumed as such. Next, gradation: moving directly from finding to termination is rarely workable, and authors as well as recent texts recommend a scale – remediation, warning, loss of preferred partner status, publicity, termination as a last resort. Finally, measure: a clause that arms control without leaving any way out other than termination is not only harsh, it is ineffective, for the party that knows every finding condemns it no longer has any interest in letting anything be seenThe complete chain is given by CA Paris, pôle 5, ch. 4, 16 June 2021, SPI International v. EuropaCorp, RG no. 17/05010, op. cit., which also holds that the report is authoritative as long as the auditee produces nothing. On gradation, Robert C. Bird, "Contractual Deterrence and the Ethical Supply Chain" (op. cit.), argues for a scale – training and remediation, formal warning, loss of preferred supplier status, public denunciation, termination as a last resort – and adds the power to reward; Maxime D’Angelo Petrucci likewise reasons in terms of graduated response, the so-called CS3D Directive moreover requiring termination where the corrective action plan cannot reasonably succeed (« Réflexions sur l’essor des clauses de compliance dans les contrats d’affaires », op. cit.). On termination, see also Cass. com., 20 November 2019, Biomet, and CA Paris, 4 December 2024, Carrefour, reported by Jean-Christophe Roda, « Clause de compliance » (op. cit.). Finally, the unilateral insertion of a severe audit clause may cost the relationship without being wrongful: CA Paris, pôle 5, ch. 4, 14 January 2026, Centre Vidéo Distribution v. RDM Video, RG no. 24/04702, op. cit..

49. When sanction lies at the end of the audit, notice changes nature: from the element of surprise to the rights of the defence. We must then return to a question that seemed purely logistical: notice. Authors are divided, some ruling it out because it ruins the element of surprise, others deeming it necessary because the audit mobilises considerable resources at the auditee’s (see infra note no. 53). The disagreement is resolved when one looks no longer at the audit in itself, but at the clause on which it leans. Leaning on a mere verification, the audit can dispense with announcement: surprise is what makes it possible to observe the real state of affairs, and nothing more is at stake. Leaning on a sanction clause, it changes nature, for what it establishes will serve to strike: the party that will be sanctioned must then have been given the opportunity to explain itself, and notice ceases to be a convenience offered to the auditee and becomes the first of the safeguards. We measure here what the Compliance Obligation does to the rights of the defence: because sanction is anticipated from the control stage, these rights move back in time and settle in the stipulation itself, well before any trialOn this moving back in time of the rights of the defence, brought about by the anticipation of sanction, and on what it requires of Compliance systems, see 🕴️M.-A. Frison-Roche, 📝« Circuler dans le temps pour mettre en phase Compliance et droits de la défense », in 🕴️M.-A. Frison-Roche and 🕴️M. Boissavy (eds.), 📕Compliance et droits de la défense. Enquête interne – CJIP – CRPC, JoRC and Dalloz, « Régulations & Compliance » series, 2024, pp. 33-58.. A well-made clause therefore distinguishes according to what the audit leads to: no notice for an audit prompted by a red flag concerning only documents; notice, and information of the person concerned, as soon as the audit concerns the conduct of an identified person from which a sanction may result. It is the same criterion as the one governing the switch of regime: not the intensity of the audit, but its object.

2. An audit clause to have the means to draw closer afterwards

50. The audit clause on which the remediation clause leans. The third family draws closer, and it is the one the Compliance Obligation calls for. From the same finding, the remediation clause derives not a complaint but a programme: corrective action plan, timetable, indicators, new verification audit, sometimes cost sharing. Its economy is the reverse of the previous one, and the difference is not only moral: it is one of yield. The partner that knows the audit will lead to remediation has an interest in showing what is wrong; the one that knows it will lead to a sanction has an interest in hiding it, and has the means to do so. Termination remains at the end of the chain, and it is sometimes necessary: but it must come only afterwards, failing which the regulated undertaking deprives itself of the information on which its legal obligation depends, and shifts the systemic risk instead of addressing itRobert C. Bird, "Contractual Deterrence and the Ethical Supply Chain" (op. cit.), notes that lead firms rarely pursue the failures they observe, which ruins the deterrent effect of the audit; the observation applies a fortiori to remediation, which presupposes a long-term commitment. Breaking with the defaulting supplier may relieve the regulated undertaking of its legal risk without changing anything in the situation of the persons whom the Compliance Obligation aims to protect.. This is where the audit clause ceases to be an instrument of power and becomes an instrument of Compliance.

We find here, at the last stage, what separated from the outset the conformity audit clause from the Compliance audit clause. The first asks for a sign of submission and is satisfied with obtaining it; the second asks for a sign of collaboration, and is worth only as much as it obtains it. Remediation is therefore neither a mitigation of sanction nor a favour granted to the defaulting partner: it is the form the alliance takes when the audit has shown it to be necessary.

3. Judicial interpretation of the Compliance audit clause as a “necessary accessory”

51. What the court will have to take into account: a clause that does not serve only those who stipulated it. All of the above has an addressee that the drafter must never lose sight of: the court. For the audit clause will come before it, and in three ways. The auditee will challenge the implementation of the audit it undergoes, its extent, its conditions, the use made of what it has delivered. The beneficiary will ask for the clause to be performed, or for its non-performance to be sanctioned. The concerned third party, finally, will reproach the regulated undertaking for not having carried out the audit it had given itself the power to carry out, and this is by far the newest scenario. Decisions already handed down show that courts grasp the audit clause, but through the ordinary law alone: they see in it a power granted by one contracting party to the other, and measure its extent with the instruments used to contain powers — significant imbalance, potestativity, interference in management, the protective or purely evidentiary nature of the measure. This reading is not wrong; it is incomplete, for it treats as a stipulated advantage what is also, and sometimes first, the performance of an obligation.

52. Interpretation by purpose: what the court must seek in a Compliance audit clause. A contract is interpreted according to the common intention of the parties rather than the literal meaning of its terms (Article 1188 of the Code civil), and each clause is interpreted in the light of the instrument as a whole (Article 1189 of the Code civil). Applied to the Compliance audit clause, these principles lead further than it seems. Common intention is not exhausted there by the exchange of advantages, since the contracting parties intended, beyond themselves, to serve a goal of which neither has disposal; and the instrument as a whole to which the clause refers is not only the contract carrying it, but the Compliance system into which that contract fits. The court will therefore have to seek what the audit was meant to detect, and measure the stipulation against that purpose: a broad clause reasoned by the risk it serves is not the discretionary power that is censured, whereas a narrow but dormant clause is not the restraint that is approved. It will also have to take into account that what is at stake in this stipulation does not concern the signatories alone: behind the audit lie the various systems that the Compliance Obligation is meant to preserve and the human beings involved in them. It is on this condition that the court will make of the audit clause neither one more weapon in the hand of the strongest, nor a formality to be set aside, but what it must be: the instrument by which the contract makes possible what the Law alone cannot achieve.

53. The interpretation expected when the audit clause is accessory to the effective application of regulatory corpora. The first function of the audit clause is to make obedience to texts effective. The standard is then external to the parties, and the court need not seek between them a balance that the stipulation was not intended to establish: it has to verify that the clause enables the regulated party to do what the regulatory corpus requires of it. Three consequences follow. A clause that merely carries into the contract a clear legal requirement escapes the complaint of significant imbalance, as has already been held, since what is censured is the discretionary dimension of the reserved power and not its unilateral nature. The extent of the audit is then measured against the perimeter of the regulatory obligation: what exceeds it has no title and becomes again the capture of information about a partner, which the ordinary law grasps. Non-performance, finally, is not assessed between the parties alone, since the regulated party will have to account for its diligence before the supervisory authority: the contract judge is not the only one to read the clause, and must know it. The criterion here is effectiveness: the clause is worth what it makes it possible to obtain for the performance of the text.

54. The interpretation expected when the audit clause is accessory to the efficient application of Compliance Law. The second function is of another order, and it calls for another criterion. The standard is no longer a text to be confronted but a goal to be served, so that effectiveness is no longer enough: it is efficiency that is at stake, that is to say the relationship between what the audit costs — to the party undergoing it, to the relationship, to the whole chain — and what it really contributes to preserving the system and protecting the persons involved in it. The court will therefore have to ask not only whether the audit could be carried out, but whether it was the adequate means: whether the information could not have been obtained otherwise, whether the extent of the capture was proportionate to the mapped risk, whether the burden passed along the chain did not end up placing the audit on the one least able to bear it, while the systemic risk stayed where it was. An audit that overwhelms a destitute supplier without improving anything is not efficient, and the court may say so; conversely, the audit that detected and made remediation possible deserves protection, even if intrusive, for that is what it was for.

55. The interpretation expected when the audit clause is accessory to the coordinated application of the other Compliance clauses. The third function is the one that has occupied this second part: the audit clause is worth only through the stipulations it serves and through those that lean on it. The court will therefore have to interpret it together with them, as invited by the interpretation of each clause in the light of the instrument as a whole. Four directions follow. The evidentiary value of the audit report is governed first by what the parties have said about it, and failing that by what the function of the clause commands, not by the sole force of the document. The choice between striking and drawing closer, next, does not belong to the court: it belongs to the economy that the contracting parties designed by stipulating a sanction clause or a remediation clause, and the court respects it. The fall of the clause served, moreover, is resolved not by hierarchy between stipulations, which the ordinary law ignores, but by divisibility, that is to say by the function each performs within the intended economy. The court will finally ensure the consistency of the party invoking the clause: the party that stipulated the audit in order to remedy cannot use it to terminate without having followed the gradation it had set itself, and the party that never implemented it cannot reproach the other for what it did not want to see.Article 1189 of the Code civil provides that all the clauses of a contract are to be interpreted in relation to one another, giving each the meaning that respects the consistency of the instrument as a whole, its second paragraph extending the rule to the stipulations of several contracts contributing to the same transaction; Article 1191 adds the effectiveness principle. On consistency as a guiding principle for reading the contract, see D. Houtcieff, Le principe de cohérence en matière contractuelle, foreword H. Muir Watt, Presses universitaires d’Aix-Marseille, « Institut de droit des affaires » series, 2001, 2 vols. On the articulation of stipulations and instruments with one another, see also J.-B. Seube, L’indivisibilité et les actes juridiques, op. cit., and M. Cottet, Essai critique sur la théorie de l’accessoire en droit privé, op. cit., both relating articulation to the function each element performs in the intended transaction, which is exactly what the Compliance audit clause calls for.

CONCLUSION: THE COMPLIANCE AUDIT CLAUSE, CAROUSEL OF THE CONTRACTUALISATION OF COMPLIANCE

56. The audit clause, where the contractualisation of Compliance is knotted. The audit clause appears as the point where everything is knotted. It receives from upstream: from the legal obligation, which gives it its object; from the clause it serves, which gives it its measure; from the structure in which the parties are caught, which gives it its legitimacy. It gives downstream: to the sanction clause, the termination clause, the remediation clause, which only apply to what it has established. And the movement starts again, for what the audit brings to light feeds the risk map, which redefines the scope of the next audit. That is why it is the carousel of the contractualisation of Compliance: not one piece among others, but the one through which information enters the contract and through which the contract acts upon the world. The instrument nonetheless remains ambivalent, as the article has tried to show: the same power to know can serve to strike a partner or to set it right, to protect a system or to capture information about a competitor. What decides is not the technique, which is neutral, but the purpose for which it is stipulated – and that is why, from beginning to end, the criterion has remained the same: the audit is worth only through the Monumental Goal it serves.

57. The audit clause, where conformity and Compliance are distinguished. There remains what the audit clause can aim for when it is conceived from Compliance Law and not from conformity alone. Stipulating an audit does not necessarily mean demanding from a partner the sign of its submission; it may mean giving it, through the contract, the means of collaboration. The information flowing back is then no longer the token of obedience, it is the material of common action, and the “concerned third parties” cease to be the objects of control and become its beneficiaries. It is there that the audit clause joins what makes the unity of Compliance Law: the preservation of systems only makes sense through the human beings involved in them, and a contract organising one party’s knowledge of the other serves this ambition only if it makes both contracting parties allies in the same humanism.The report submitted to the French Minister of Justice develops this conception: 🕴️M.-A. Frison-Roche, 🏛️Déployer le Droit de la Compliance pour renforcer la souveraineté et accroître l’attractivité de la France avec l’Europe, Report to the French Minister of Justice, September 2026, notably on the distinction between conformity, which calls for obedience, and Compliance, which calls for the participation of crucial operators in the preservation of systems and the protection of the human beings involved in them.

58. The audit clause, where the judge contributes to the deployment of Compliance Law. And it will be for the judge to decide, since it is before the judge that the audit clause will be discussed. Of all this — the purpose it serves, whether it derives from the Law or from the autonomy of the contracting parties, as well as the various systems it helps to preserve and the persons involved in them —, the judge will have to take account in interpreting this essential clause.On this overall conception, see 🕴️M.-A. Frison-Roche, 🏛️Déployer le Droit de la Compliance pour renforcer la souveraineté et accroître l’attractivité de la France avec l’Europe, Report to the French Minister of Justice, September 2026, op. cit.

____

🌐follow Marie-Anne Frison-Roche on LinkedIn

🌐follow Marie-Anne Frison-Roche on Instagram

🌐subscribe to the Newsletter MAFR Regulation, Compliance, Law

🌐subscribe to the Video Newsletter MAFR Surplomb

🌐subscribe to the Newsletter MaFR Droit & Art

  1. The "audit clause" is generally little described and commented upon. See however the interesting studies by Arnaud Lecourt, « La clause d’audit », AJ Contrats d’affaires – Concurrence – Distribution (AJCA), 2014, pp. 271-272, and by F.-L. Simon, « Les mystères de la clause d’audit : les écueils à éviter », La Lettre des réseaux, 28 March 2022. On the mention of an audit technique within a broader conformity or Compliance clause, see in French legal scholarship: 🕴️M.-A. Frison-Roche, 📝« Contrat de Compliance, clauses de Compliance », D. 2022, chron., pp. 2115-2117; J.-Ch. Roda, « La clause de compliance », in F. Buy, J. Heinich, M. Lamoureux, J. Mestre and J.-Ch. Roda (eds.), Les principales clauses des contrats d’affaires, 3rd ed., Lextenso - LGDJ, 2025; L. Tenreira, « La rédaction des clauses d’application du devoir de vigilance par les Global Lawyers : l’exemple des clauses de flow-down », Revue de droit des affaires internationales, no. 5, 2022, pp. 453-466; N. Ida, « Contrat et devoir de vigilance des sociétés », JCP E, July 2023, pp. 17-26; Y. Queinnec, « La clause RSE, levier incontournable de vigilance », Revue Lamy droit des affaires, July 2018, no. 139. In English-language scholarship: D. V. Snyder, S. Maslow and S. Dadush, "Balancing Buyer and Supplier Responsibilities: Model Contract Clauses to Protect Workers in International Supply Chains, Version 2.0", The Business Lawyer, vol. 77, no. 1, 2021-2022, pp. 115-182; K. Parella, "Contractual Stakeholderism", Boston University Law Review, vol. 102, 2022, pp. 865 ff.; Robert C. Bird, "Contractual Deterrence and the Ethical Supply Chain", Boston College Law Review, vol. 63, 2022, pp. 2539 ff.; S. Dadush, "Prosocial Contracts: Making Relational Contracts More Relational", Law and Contemporary Problems, vol. 85, no. 2, 2022, pp. 153-175; J. L. Short, M. W. Toffel and A. R. Hugill, "Monitoring Global Supply Chains", Strategic Management Journal, vol. 37, no. 9, 2016, pp. 1878-1897.
  2. Regulation (EU) 2016/679 of 27 April 2016, Art. 28(3)(h); Regulation (EU) 2022/2554 of 14 December 2022, Art. 30(3)(e); French Order (arrêté) of 6 January 2021 on the system and internal control for anti-money laundering, counter-terrorist financing and asset freezing, Art. 10, 8° and 10°; AMF General Regulation, Arts. 318-61 and 321-96, II; Lieferkettensorgfaltspflichtengesetz of 16 July 2021, § 6 Abs. 4 Nr. 4.
  3. An internal audit which may itself be a "Compliance audit". See A. Gutierrez-Crespin, « L’audit du dispositif de compliance : un outil clé pour en vérifier la robustesse », in 🕴️M.-A. Frison-Roche (ed.), 📕Les outils de la Compliance, JoRC and Dalloz, « Régulations & Compliance » series, 2021, pp. 133-140.
  4. Recommendations of the French Anti-Corruption Agency (AFA), notice published in JORF no. 10 of 12 January 2021, text no. 61, §§ 61 to 68 and §§ 69 to 74.
  5. On internal investigation techniques and their deployment within international groups, O. Catherine, « La spécificité des enquêtes internes pratiquées par les groupes internationaux », in 🕴️M.-A. Frison-Roche and 🕴️M. Boissavy (eds.), 📕Compliance et droits de la défense. Enquête interne – CJIP – CRPC, JoRC and Lefebvre-Dalloz, « Régulations & Compliance » series, 2024, pp. 141-155. On the risks and limits of the audit clause, see infra §§ 26 to 36.
  6. On the risks and limits of the audit clause, see infra §§ 26 to 36.
  7. This is described and assumed as such. See F.-L. Simon, « Les mystères de la clause d’audit : les écueils à éviter », La Lettre des réseaux, 17 December 2021, updated 28 March 2022.
  8. For it will answer for the regulatory failures committed by its partners.
  9. For it can thereby make sure that it has the necessary support from its partners to contribute to the preservation and sustainability of systems. See A. Oumedjkane, « Le devoir de vigilance est-il soluble dans le droit des contrats publics ? », in 🕴️M.-A. Frison-Roche (ed.), 📕Compliance et Contrat, JoRC and Lefebvre-Dalloz, « Régulations & Compliance » series, 2027.
  10. French Act no. 2016-1691 of 9 December 2016 on transparency, the fight against corruption and the modernisation of economic life ("Sapin 2"), Art. 17, II, 4° and 8°; Directive (EU) 2024/1760 of 13 June 2024, Art. 10(2)(b) and (5).
  11. Directive (EU) 2024/1760 of 13 June 2024, Art. 10(2)(b) and (4); Lieferkettensorgfaltspflichtengesetz of 16 July 2021, § 9 Abs. 3; Transparency International, Global Anti-Bribery Guidance, § 13.3.5.
  12. Conseil constitutionnel, 23 March 2017, no. 2017-750 DC, Loi relative au devoir de vigilance des sociétés mères et des entreprises donneuses d’ordre. The decision states in § 27 that the contested provisions do not establish a regime of vicarious liability, as is moreover apparent from the parliamentary debates, and therefore do not infringe the principle of liability. On this question of personal liability and liability for others, see A. Danis-Fatôme and G. Viney, « La responsabilité civile dans la loi relative au devoir de vigilance des sociétés mères et des entreprises donneuses d’ordre », D. 2017, no. 28, pp. 1610-1618; T. Sachs and J. Tricot, « La loi sur le devoir de vigilance : un modèle pour (re)penser la responsabilité des entreprises », Droit & Société 2020, no. 106, pp. 683-698; M. Mekki, « Peut-on repenser la responsabilité à l’aune du devoir de Vigilance, pointe avancée de la Compliance ? », in 🕴️M.-A. Frison-Roche (ed.), 📕L’obligation de compliance, JoRC and Dalloz, « Régulations & Compliance » series, 2025, pp. 599-615. See also M. Fabre-Magnan, « Critique de la convergence des responsabilités contractuelle et délictuelle. L’exemple du devoir de vigilance », in Mélanges en l’honneur du Professeur Loïc Cadiet, LexisNexis, 2023, pp. 547-561.
  13. On the vertical integration thus produced by "regulation contracts" required not only by management choices but also by compliance imperatives.
  14. In this respect, the audit clause is associated with "conformity", and not with the Compliance obligation.
  15. On the theory of the accessory applied to contractual stipulations, see J.-B. Seube, L’indivisibilité et les actes juridiques, foreword M. Cabrillac, Litec, « Bibliothèque de droit de l’entreprise » series, vol. 40, 1999; M. Cottet, Essai critique sur la théorie de l’accessoire en droit privé, thesis, Paris-Sud, supervised by J. Rochfeld, 2011, the author showing that the theory rests on the notion of function, understood as the contribution to the achievement of a purpose, including where a contractual clause is concerned.
  16. On the evidentiary dimension of the audit clause, see infra § 32.
  17. On the limits of the audit clause, see infra §§ 27 to 32.
  18. J.-Ch. Roda, « Utilité comparée des clauses de conformité et des clauses de Compliance », in 🕴️M.-A. Frison-Roche (ed.), 📕Compliance et Contrat, JoRC and Lefebvre-Dalloz, « Régulations & Compliance » series, 2027. See infra §§ 40 to 42.
  19. The fact that it is a contractual audit does not necessarily rule out a legal characterisation or a regime involving rights of the defence. If there must be one, it is best to organise that regime by contract as well. On this point, see infra §§ 33 to 35.
  20. The audit clause changes depending on whether it supports a "conformity clause" or a genuine "Compliance clause". On the audit clause leaning on other stipulations, see infra §§ 37 to 50.
  21. L. Sautonie-Laguionie, « Les clauses de Compliance relatives aux sanctions », in 🕴️M.-A. Frison-Roche (ed.), Compliance et Contrat, op. cit.
  22. M. Tirel, « Les clauses de Compliance relatives à la remédiation », in 🕴️M.-A. Frison-Roche (ed.), Compliance et Contrat, op. cit.
  23. 🕴️M.-A. Frison-Roche, 📝« Concevoir l’Obligation de Compliance : faire usage de sa position pour participer à la réalisation des Buts Monumentaux de la Compliance », in 🕴️M.-A. Frison-Roche (ed.), 📕L’obligation de compliance, op. cit., pp. 3-44. Adde, by the same author, 🕴️M.-A. Frison-Roche, 🏛️Déployer le Droit de la Compliance pour renforcer la souveraineté et accroître l’attractivité de la France avec l’Europe, Report to the French Minister of Justice, September 2026.
  24. These techniques have reached the State itself: Decree no. 2022-634 of 22 April 2022 on internal control and internal audit of the State, which repealed Decree no. 2011-775 of 28 June 2011 on internal audit in the administration, requires each minister to have an internal control system based on a risk analysis, and entrusts a ministerial internal audit mission, reporting to the minister, with verifying the quality and effectiveness of that system. Harmonisation of methods and practices falls to the interministerial committee for internal control and audit (CICAI), which succeeded the committee for the harmonisation of the State's internal audit (CHAIE).
  25. On assessment procedures, a major tool of Compliance Law, N. Guillaume, « Cartographie des risques de compliance. Premiers aperçus des enjeux, des limites et des bonnes pratiques », in 🕴️M.-A. Frison-Roche (ed.), 📕Les outils de la Compliance, JoRC and Dalloz, « Régulations & Compliance » series, 2021, pp. 63-70. Adde, on the implementation of this measure, the work of the French Anti-Corruption Agency (AFA): « L’évaluation des tiers en question : résultats de notre dernière enquête auprès des entreprises », May 2024, showing that 59% of undertakings regard third-party assessment as the most difficult anti-corruption measure to deploy, notably because of the "difficulty of accessing and integrating data". A Compliance audit clause may provide support. See also, on the stipulations organising this assessment within the value chain, G. J. Martin, « Clauses et contrats, modalités de l’obligation de vigilance », in 🕴️M.-A. Frison-Roche (ed.), 📕L’obligation de compliance, op. cit., pp. 663-678.
  26. A cost which may moreover be allocated by contract, or even transferred, provided this is not abusive.
  27. French Anti-Corruption Agency, Résultats de l’enquête « évaluation des tiers au regard du risque de corruption » menée par l’Agence française anticorruption auprès des entreprises, April 2024, 72 p., Q22, p. 57. Anonymous questionnaire of 28 questions, circulated by trade federations from 10 October to 10 December 2023; self-reported answers; 72 respondents to this question. The AFA specifies that the practices thus shared had not, at the time of publication, been approved by it.
  28. On binding force, see more generally 🕴️M.-A. Frison-Roche, « Autonomie de la volonté et compliance », in 🕴️M.-A. Frison-Roche (ed.), 📕Compliance et Contrat, JoRC and Lefebvre-Dalloz, « Régulations & Compliance » series, 2027.
  29. The AFA survey cited above mentions that one of the "difficulties" encountered in assessment lies in "the autonomy of subsidiaries". A legally autonomous entity is certainly less open… On the economic integration effect produced by Compliance clauses, notably within a value chain, see 🕴️M.-A. Frison-Roche and E. Maclouf, « Les stratégies d’entreprises dans l’organisation contractuelle des chaînes de valeur », in 🕴️M.-A. Frison-Roche (ed.), Compliance et Contrat, JoRC and Lefebvre-Dalloz, « Régulations & Compliance » series, 2027.
  30. On these third-party beneficiaries, see infra § 42.
  31. The Compliance Obligation is understood here as the obligation placed on crucial operators to contribute to the preservation of systems and to the protection of the human beings involved in them; see supra § 6.
  32. The criterion of proportionality to the risk map is the one adopted by the French Anti-Corruption Agency (AFA) for third-party assessment: Avis relatif aux recommandations de l’Agence française anticorruption destinées à aider les personnes morales de droit public et de droit privé à prévenir et à détecter les faits de corruption, de trafic d’influence, de concussion, de prise illégale d’intérêts, de détournement de fonds publics et de favoritisme, JORF no. 0010 of 12 January 2021, text no. 61, section « Évaluation de l’intégrité des tiers », §§ 201 to 245, esp. § 207, according to which the nature and depth of the assessments and of the information to be gathered are determined according to homogeneous groups of third parties with comparable risk profiles, as the risk map allows them to be drawn up. See supra § 17.
  33. Third-party assessment under Article 17 of the so-called "Sapin 2" Act, op. cit., leads to the purchasing and sales functions; the duty of vigilance, to the industrial and social functions; data protection, to the controller and the data protection officer.
  34. This is the first effect of the clause: it makes contractually obtainable a document which, by its purpose, was not. The stipulation should therefore refer to reports by their object and period, and not by their title alone, which the co-contractor controls.
  35. Soft law confirms this sequence, but only on the side of the undertaking examining itself: the practical guide of the French Anti-Corruption Agency (AFA) and the National Financial Prosecutor's Office (PNF) holds that internal control or internal audit reports, where they reveal facts resembling corruption or failures in prevention and detection procedures, may serve as a basis for opening an internal investigation. AFA and PNF, Les enquêtes internes anticorruption. Guide pratique, March 2023. No text or guideline, however, addresses the same sequence where the audit takes place at a third party's premises: that is the gap the clause must fill.
  36. The limits then come from the ordinary law, not from the contract: trade secrets (Arts. L. 151-1 ff. of the French Commercial Code); the protection of the data of the persons heard, who are not the beneficiary's employees (GDPR, Art. 14; CNIL framework of 18 July 2019 on professional whistleblowing); the professional secrecy of the lawyer where the auditor is one, which the Paris Bar recalled in response to the aforementioned guide; and, downstream, Articles 434-4 and 434-15 of the French Criminal Code, to which the guide itself refers.
  37. See infra § 24, on the shadow of significant imbalance (Art. 1171 of the Code civil; Art. L. 442-1, I, 2°, of the French Commercial Code).
  38. This is one of the points where the audit clause most visibly turns third parties into quasi-parties: the lower-tier supplier undergoes an audit whose beneficiary is contractually a stranger to it. See supra § 9, on "concerned third parties".
  39. Notably the rules on transfers outside the European Union (GDPR, Chapter V) and, conversely, French Act no. 68-678 of 26 July 1968 on the communication of economic, commercial, industrial, financial or technical documents and information to foreign natural or legal persons, known as the "blocking statute".
  40. This is the movement described by Antoine Oumedjkane: texts no longer so much grant undertakings powers of control as oblige them to use them, third-party assessment under Article 17 of the so-called "Sapin 2" Act, op. cit., being the example. The regulatory purpose therefore need not be negotiated: it is already in the Law (« Puissance publique et pouvoir de contrôle des entreprises », D. 2025, pp. 1636-1642).
  41. This is also what shields the stipulation from significant imbalance: what is censured is the discretionary and barely legible dimension of the reserved power, not its unilateral nature, so that a clause reproducing a clear text escapes it, whereas a standard clause, indifferent to the auditee's resources and position in the chain, is exposed to it. See M. D’Angelo Petrucci, « Réflexions sur l’essor des clauses de compliance dans les contrats d’affaires », Revue internationale de la compliance et de l’éthique des affaires, no. 1, 10 February 2025, study 18.
  42. The observation has long been made about software licence audits, whose effectiveness depends entirely on the prior clarity of the standard: absent precision, the clause turns into an instrument of pressure and in fact constitutes « un pouvoir de police exorbitant ». See Mathieu Martin, « Pratique contractuelle. Contrats de l’informatique. La clause d’audit de licence », Communication Commerce électronique, no. 3, March 2015, pratique 4.
  43. Express annual periodicity is found in the best-drafted clauses: Article 13.4 of the services contract at issue in CA Paris, pôle 1, ch. 3, 5 March 2024, Coopérative U Enseigne v. Carrefour France and Carrefour World Trade, RG no. 23/06899, opens the right to have the proper application of the contract checked « une fois par an ». Arnaud Lecourt, « La clause d’audit », AJ Contrats d’affaires – Concurrence – Distribution, 2014, pp. 271-272, recommends the same frequency limit, audits being costly and disruptive, but advises against a fixed date.
  44. This is the objection raised by Arnaud Lecourt, « La clause d’audit » (op. cit.), against fixed-date audits and against notice, which ruin the element of surprise and may reduce the audit to a staged performance. This risk has been compared with that existing in the control exercised by undertakings on behalf of public authorities, by Antoine Oumedjkane (« Puissance publique et pouvoir de contrôle des entreprises », op. cit.): a control based on the documents produced becomes excessively formal and then bears on methodology rather than actual effectiveness.
  45. The question whether mere suspicion suffices, or whether a characterised breach must be awaited, is for instance left open by Antoine Oumedjkane, « Puissance publique et pouvoir de contrôle des entreprises » (op. cit.), with regard to the moment of termination. It is better resolved once one sees that the audit is precisely the step that comes between suspicion and sanction: it is not the sanction, it is what makes it possible to know whether there are grounds for sanction.
  46. M. Martin usefully distinguishes the declaratory audit, carried out under the auditee's responsibility and in principle binding on the creditor save for bad faith, from the audit conducted by the creditor, who can no longer dispute its scope afterwards. The choice of who bears the burden thus governs the evidentiary value of the result (« Pratique contractuelle. Contrats de l’informatique. La clause d’audit de licence », op. cit.).
  47. Robert C. Bird, "Contractual Deterrence and the Ethical Supply Chain" (op. cit.), notes that some suppliers undergo more than fifty audits a year, with contradictory standards, without this accumulation improving detection in any way. Sabrina Dupouy draws the legal consequence: transferring vigilance in cascade to an under-resourced subcontractor does not exonerate the ordering company (« Le tiers face à la contractualisation de la compliance », op. cit.).
  48. On the three models of cost allocation, see infra note no. 55. American practice, for its part, places all costs on the auditee, unconditionally: J.-Ch. Roda, « Clause de compliance » (op. cit.).
  49. On the analogy between internal control and audit, see supra § 1.
  50. This is the most frequent practice, and Arnaud Lecourt, « La clause d’audit » (op. cit.), advises against it for that very reason, recommending that the mission be entrusted first to a regulated profession with a code of ethics, whose name and standing appear in the clause.
  51. This is the criterion adopted by CA Paris, 25e ch. B, 28 June 2002, Fernandez v. Sté Puissance 5, unreported, commented on by Jacques Mestre and Bertrand Fages: the stipulation is not a potestative condition where the price results from an audit by the statutory auditor subject to strictly defined accounting rules, and not from the beneficiary's sole decision (RTD civ. 2002, pp. 804-805). The requirement echoes that of the functional independence of the controller – sufficient authority, absence of instructions, non-participation in operational activities – a requirement noted by Antoine Oumedjkane, « Puissance publique et pouvoir de contrôle des entreprises » (op. cit.). The judgment commented on is unreported and could not be found.
  52. Article 7 of the contract at issue in the Coopérative U case, op. cit., confines the choice to a closed list – PwC, Deloitte, EY, KPMG, through their Paris offices – and then, failing agreement within five working days, allows the more diligent party to have a third party appointed by the President of the Paris Commercial Court. It is the best model in the file, and yet it failed: the procedure referred to – the President ruling "en la forme des référés" – had been repealed by the Order of 17 July 2019, so that the judge declared that it had no power. The procedural referral in an audit clause must therefore be dated, and checked at each renewal.
  53. Authors are divided. Arnaud Lecourt formally advises against any notice stipulation, which would ruin the element of surprise (« La clause d’audit », op. cit.). Conversely, Mathieu Martin deems it necessary, since the audit mobilises considerable resources at the auditee's (« Pratique contractuelle. Contrats de l’informatique. La clause d’audit de licence », op. cit.). The disagreement in fact depends on the object of the audit: surprise is useful to check declared figures, cooperation is indispensable to reconstruct a system known only to the auditee. The Compliance clause, which pursues both, does well to distinguish according to the trigger: notice for the periodic audit, no notice for the audit prompted by a red flag.
  54. Three models are found: costs borne by the creditor, passed on to the auditee if the audit reveals a failure, possibly above a set threshold (A. Lecourt, « La clause d’audit », op. cit.); costs borne by the auditee unconditionally, the formula of American practice; costs advanced and then reimbursed, reimbursement finding its cause in the option reserved to the other party (J. Mestre and B. Fages, « La clause d’audit est-elle potestative ? », op. cit.).
  55. M. Martin requires transparency of conclusions and rules out conclusions "subject to…", which leave the auditee under an indefinite threat. He usefully distinguishes the declaratory audit, carried out under the auditee's responsibility and in principle binding on the creditor save for bad faith, from the audit conducted by the creditor, who can no longer dispute its scope afterwards (« Pratique contractuelle. Contrats de l’informatique. La clause d’audit de licence », op. cit.). As to the follow-up – basis of the adjustment, associated costs, time limits, third-party claims – the clause does well to be as precise as it is about the conduct of the audit.
  56. The mechanism is formulated by Maxime D’Angelo Petrucci, who recommends not stipulating the clause if the creditor has neither the intention nor the resources to implement it, failure to implement it being liable to be perceived as negligent (« Réflexions sur l’essor des clauses de compliance dans les contrats d’affaires », op. cit.). Sabrina Dupouy presents the situation of the undertaking "benefiting" from the audit clause more severely: the injured third party may invoke the mere contractual breach as a tortious fault, without further proof, which applies to non-performance of an audit clause (« Le tiers face à la contractualisation de la compliance », Droit des sociétés, no. 4, April 2024, study 5). Robert C. Bird, "Contractual Deterrence and the Ethical Supply Chain", Boston College Law Review, vol. 63, no. 8, 2022, pp. 2539-2620, documents it by noting that lead firms rarely pursue the failures observed, which ruins the deterrent effect of the audit.
  57. This is the contractual answer of the Model Contract Clauses: D. V. Snyder, S. A. Maslow and S. Dadush (Working Group to Draft Model Contract Clauses, ABA Business Law Section), "Balancing Buyer and Supplier Responsibilities: Model Contract Clauses to Protect Workers in International Supply Chains, Version 2.0", The Business Lawyer, vol. 77, no. 1, 2021-2022, pp. 115-182, whose section 5.1 provides that the parties' conduct, including the buyer's failure effectively to exercise its audit rights, constitutes neither a waiver nor an element in assessing its remedies. The MCC 2.0 moreover contain no stand-alone audit clause: they presuppose audit rights stipulated elsewhere and regulate their effects.
  58. Sabrina Dupouy likewise notes that an undertaking's communication on its contractual mechanisms, audit clauses included, is a signal sent to the market that is sometimes mere greenwashing, and that transferring vigilance in cascade to an under-resourced subcontractor does not exonerate the ordering company (« Le tiers face à la contractualisation de la compliance », op. cit.).
  59. Robert C. Bird, "Contractual Deterrence and the Ethical Supply Chain" (op. cit.), lists the avoidance techniques encountered by social audits: bribing the local auditor, selecting and coaching the employees interviewed, restoring emergency exits and removing children before an announced inspection, undeclared subcontractors, showcase factories, double bookkeeping. He derives four drafting requirements: making control visible and its consequences known, defining concretely the object of control, ensuring the perceived legitimacy of the standard, limiting the complexity of standards. Failing this, the audit degenerates into public relations vehicles, auditors having an interest in reassuring in order to keep their mandate.
  60. See supra § 17, on the criterion of proportionality and teleological reasoning, of which the description of limits is merely the reverse application.
  61. Hence the interest in also stipulating the sanction for obstruction – sabotaged audit, cursory information, concealment – most often termination and damages, together with delivery of the documents under penalty: A. Lecourt, « La clause d’audit » (op. cit.).
  62. The report of the Audit Responses Committee, ABA Business Law Section, "Report on Audit Response Timing Issues", The Business Lawyer, vol. 77, no. 1, 2021-2022, pp. 183-190, although devoted to letters addressed to auditors, offers a transposable temporal grammar: the perimeter is fixed by identifying the entities and the financial year, the effective date of the response is distinguished from its date of issue, the subsequent updating obligation may lawfully be excluded, and the method of delimiting the period – Entire Period Approach or Snapshot Approach – must be stated.
  63. See supra § 15, on the point at which the audit changes nature by moving from the document to the person. The vocabulary of intrusion is found in the mouths of auditees themselves: in CA Paris, pôle 5, ch. 4, 14 January 2026, Centre Vidéo Distribution v. RDM Video, RG no. 24/04702, the distributor required, on simple written request, to hand over its detailed balance sheets for the last three financial years speaks of « inquisition »; the court notes that access to all accounting documents without justification is perceived as interference in management.
  64. The AFA-PNF practical guide, op. cit., although it reasons on the investigation conducted by an undertaking on its own employees, provides the material for these stipulations: informing the persons concerned, conducting interviews, archiving and retaining the evidence gathered, strict confidentiality. There is to date no text or guideline governing the same question where the investigation takes place at the co-contractor's, on other people's employees: the clause alone makes up for it.
  65. The Coopérative U case, op. cit., gives the reverse illustration: the audit request made after the partnership ended was analysed as a purely evidentiary measure intended to prepare a dispute rather than to preserve evidence, and Article 145 of the French Code of Civil Procedure was set aside. The contract moreover provided that the audit be carried out « dans des conditions excluant toute communication d’informations commerciales sensibles »: ring-fencing is the first of the techniques. On subsequent use, CA Paris, pôle 5, ch. 4, 16 June 2021, SPI International v. EuropaCorp, RG no. 17/05010, gives the complete chain – the audit establishes the failure, the failure feeds the formal notice, the formal notice triggers the termination clause – and the evidentiary regime: the report is authoritative as long as the auditee produces nothing.
  66. The ordinary law knows no category named "accessory clause": the theory of the accessory operates between goods, claims and contracts, not between stipulations of the same instrument. It is Article 1184 of the Code civil that governs divisibility, and consolidated scholarship adopts a hierarchised dual set of criteria, teleological first, subjective second: T. Genicon, « Conséquences de la nullité d’une clause sur le sort du contrat », and, by the same author, « De la nullité partielle à la clause réputée “partiellement” non écrite »; A. D’Adda, « Nullité partielle, clause réputée non écrite et intégration corrective du contrat », which gives the modern reading of the criterion: no longer the search for a hypothetical will, but the objective assessment of the weight of the stipulation within the economy of the instrument. Compare, for the interdependence of contracts within the same transaction, Cass. ch. mixte, 17 May 2013, nos. 11-22.768 and 11-22.927. No decision has to date ruled on the fate of an audit clause after the fall of the clause it serves: the comparison is a construction, and it is assumed as such.
  67. This is the configuration described by Arnaud Lecourt with regard to distribution networks (« La clause d’audit », op. cit.), and by M. Martin with regard to software licences, who expressly characterises this audit as an audit of conformity of licence use (« Pratique contractuelle. Contrats de l’informatique. La clause d’audit de licence », op. cit.). As to immunity with regard to Article L. 442-1, I, 2°, of the French Commercial Code, a clause that merely reproduces a clear and precise text escapes it, what is censured being « la dimension discrétionnaire et peu lisible » of the measure and not its unilateral nature (Cass. com., 28 February 2024 and Cass. com., 4 September 2024, reported by Jean-Christophe Roda, « Clause de compliance », in F. Buy, J. Heinich, M. Lamoureux, J. Mestre and J.-Ch. Roda, Les principales clauses des contrats d’affaires, Lextenso - LGDJ, « Droit et pratique professionnelle » series, 3rd ed., 2025, chapter 17).
  68. On American monitoring clauses, which go well beyond the classic audit clause – considerable volume of information, transmission of confidential information subsequently passed on to federal authorities with loss of privileges, obligation to keep books and accounts open several years after performance, Halliburton's model audit right clauses providing for four years, verification by the creditor at the debtor's premises or by a monitor, costs borne entirely by the auditee, termination in case of refusal of periodic inspections – see J.-Ch. Roda, « Clause de compliance » (op. cit.). On the model clauses that the so-called CS3D Directive entrusts to the Commission, see M. D’Angelo Petrucci, « Réflexions sur l’essor des clauses de compliance dans les contrats d’affaires » (op. cit.).
  69. This is the shift brought about by the MCC 2.0, op. cit., which impose obligations on the buyer itself and abandon the model of unilateral control, and theorised by Kishanthi Parella, "Contractual Stakeholderism", Boston University Law Review. Robert C. Bird, "Contractual Deterrence and the Ethical Supply Chain" (op. cit.), provides the demonstration a contrario: the audit undergone generates avoidance techniques, and since auditors have an interest in reassuring in order to keep their mandate, control degenerates when it is not perceived as legitimate.
  70. On the European conception defended here, see 🕴️M.-A. Frison-Roche, 🏛️Déployer le Droit de la Compliance pour renforcer la souveraineté et accroître l’attractivité de la France avec l’Europe, Report to the French Minister of Justice, September 2026. On the American conception, as reflected in contractual stipulations, see J.-Ch. Roda, « Clause de compliance », op. cit., on monitoring clauses; J. L. Short, M. W. Toffel and A. R. Hugill, "Monitoring Global Supply Chains", Strategic Management Journal, vol. 37, no. 9, 2016, pp. 1878-1897; R. C. Bird, "Contractual Deterrence and the Ethical Supply Chain", op. cit. The Model Contract Clauses 2.0 (D. V. Snyder, S. Maslow and S. Dadush, op. cit.) and K. Parella, "Contractual Stakeholderism", op. cit., mark within American scholarship itself the shift towards shared responsibility. On the Chinese conception, which uses the same techniques for opposite ends, see 🕴️M.-A. Frison-Roche, interview with O. Dufour, 💬« La nouvelle loi de protection des données en Chine est un “anti-RGPD” », Actu-Juridique, 2 September 2021: Compliance mechanisms there serve to obtain obedience, the State being exempt from the constraints it imposes on undertakings, whereas European Law makes the protection of the person the very aim of the system.
  71. The figure of the independent third-party body of the mission-driven company (société à mission, Articles L. 210-10 and L. 210-11 of the French Commercial Code) provides a useful point of comparison for the choice of auditor: see S. Dupouy, « Le tiers face à la contractualisation de la compliance » (op. cit.).
  72. The finished example is banking outsourcing: on the basis of Articles 238 and 239 of the Order of 3 November 2014, the ACPR Sanctions Committee sanctioned the institution that had assessed the risk arising from outsourcing for none of its outsourced essential services, rejecting the argument that the contracts did not provide for it: ACPR, Sanctions Committee, decision no. 2023-02 of 9 October 2024, Tunisian Foreign Bank. The audit clause there is the condition for complying with prudential obligations, not the expression of contractual freedom. See also supra § 24 on potestativity.
  73. This is exactly what happened in the Coopérative U case, op. cit.: the clause referred to the President of the Commercial Court ruling "en la forme des référés", a procedure repealed by the Order of 17 July 2019; the judge declared that it had no power and the claim was held inadmissible, Article 145 of the French Code of Civil Procedure being moreover set aside for lack of a protective nature of the measure within the meaning of Article 31 of the Lugano Convention. See supra § 24.
  74. The complete chain is given by CA Paris, pôle 5, ch. 4, 16 June 2021, SPI International v. EuropaCorp, RG no. 17/05010, op. cit., which also holds that the report is authoritative as long as the auditee produces nothing. On gradation, Robert C. Bird, "Contractual Deterrence and the Ethical Supply Chain" (op. cit.), argues for a scale – training and remediation, formal warning, loss of preferred supplier status, public denunciation, termination as a last resort – and adds the power to reward; Maxime D’Angelo Petrucci likewise reasons in terms of graduated response, the so-called CS3D Directive moreover requiring termination where the corrective action plan cannot reasonably succeed (« Réflexions sur l’essor des clauses de compliance dans les contrats d’affaires », op. cit.). On termination, see also Cass. com., 20 November 2019, Biomet, and CA Paris, 4 December 2024, Carrefour, reported by Jean-Christophe Roda, « Clause de compliance » (op. cit.). Finally, the unilateral insertion of a severe audit clause may cost the relationship without being wrongful: CA Paris, pôle 5, ch. 4, 14 January 2026, Centre Vidéo Distribution v. RDM Video, RG no. 24/04702, op. cit.
  75. On this moving back in time of the rights of the defence, brought about by the anticipation of sanction, and on what it requires of Compliance systems, see 🕴️M.-A. Frison-Roche, 📝« Circuler dans le temps pour mettre en phase Compliance et droits de la défense », in 🕴️M.-A. Frison-Roche and 🕴️M. Boissavy (eds.), 📕Compliance et droits de la défense. Enquête interne – CJIP – CRPC, JoRC and Dalloz, « Régulations & Compliance » series, 2024, pp. 33-58.
  76. Robert C. Bird, "Contractual Deterrence and the Ethical Supply Chain" (op. cit.), notes that lead firms rarely pursue the failures they observe, which ruins the deterrent effect of the audit; the observation applies a fortiori to remediation, which presupposes a long-term commitment. Breaking with the defaulting supplier may relieve the regulated undertaking of its legal risk without changing anything in the situation of the persons whom the Compliance Obligation aims to protect.
  77. Article 1189 of the Code civil provides that all the clauses of a contract are to be interpreted in relation to one another, giving each the meaning that respects the consistency of the instrument as a whole, its second paragraph extending the rule to the stipulations of several contracts contributing to the same transaction; Article 1191 adds the effectiveness principle. On consistency as a guiding principle for reading the contract, see D. Houtcieff, Le principe de cohérence en matière contractuelle, foreword H. Muir Watt, Presses universitaires d’Aix-Marseille, « Institut de droit des affaires » series, 2001, 2 vols. On the articulation of stipulations and instruments with one another, see also J.-B. Seube, L’indivisibilité et les actes juridiques, op. cit., and M. Cottet, Essai critique sur la théorie de l’accessoire en droit privé, op. cit., both relating articulation to the function each element performs in the intended transaction, which is exactly what the Compliance audit clause calls for.
  78. The report submitted to the French Minister of Justice develops this conception: 🕴️M.-A. Frison-Roche, 🏛️Déployer le Droit de la Compliance pour renforcer la souveraineté et accroître l’attractivité de la France avec l’Europe, Report to the French Minister of Justice, September 2026, notably on the distinction between conformity, which calls for obedience, and Compliance, which calls for the participation of crucial operators in the preservation of systems and the protection of the human beings involved in them.
  79. On this overall conception, see 🕴️M.-A. Frison-Roche, 🏛️Déployer le Droit de la Compliance pour renforcer la souveraineté et accroître l’attractivité de la France avec l’Europe, Report to the French Minister of Justice, September 2026, op. cit.