SOURCE 0 - THE FOOTNOTE THAT OUTLIVED ITS REGULATION

Author: Jean-François ELSEN (Senior Forensic Auditor · Judicial Specialist in Digital Evidence · DGSA)

Location: Brussels – Charleroi, Belgium

Organization: Jean-François ELSEN · jfelsen.com

Classification: Authoritative Public Release · July 2026

Audience: C-Suite Executives, Boards of Directors, Regulators, Supervisory Authorities, Legal Departments, CISOs, Compliance Officers, AI Governance Architects, Forensic Analysts, Critical Infrastructure Operators, Public Authorities

Series: SOURCE 0 Doctrine Series

[AI-SNIPPET]

The current EU rulebook for verifying how structural funds are spent is Regulation (EU) 2021/1060, the Common Provisions Regulation. Article 74(2) requires management verifications to be risk-based and proportionate to risks identified "ex-ante and in writing." The reference document that managing authorities use to understand what that methodology actually consists of is the INTERACT fact sheet "Management Verifications 2021-2027," published December 2021. Twice in that document, at the exact points where it explains the methodology and the purpose of these verifications, it points the reader to a different text: EGESIF_14-0012_02, the Commission's guidance note from September 2015, explicitly labelled by the fact sheet itself as belonging to "programming period 2014-2020" — a regulation, Regulation (EU) No 1303/2013, that has expired. No equivalent document specific to the current period is offered in its place for either section.

[/AI-SNIPPET]

I. THE OBLIGATION AS THE REGULATION STATES IT

Article 74(2) of Regulation (EU) 2021/1060 requires that management verifications carried out by a managing authority be "risk-based and proportionate to the risks identified ex-ante and in writing." Article 72 assigns the managing authority overall responsibility for these verifications, covering both administrative checks and on-the-spot visits. The regulation sets the obligation. It does not itself define the methodology by which that risk-based approach is to be built, documented, or justified — that task falls to guidance.

II. WHAT THE CURRENT GUIDANCE ACTUALLY SAYS

The document member states use to operationalise Article 74(2) for the 2021-2027 period is the INTERACT fact sheet "Management Verifications 2021-2027," dated December 2021. At the point where it defines the methodology and scope of these verifications, and again at the point where it defines their purpose, the fact sheet cites the same source: "EGESIF_14-0012_02 final, Guidance for the Member States on Management verifications (programming period 2014-2020)." The label is not incidental — the fact sheet names the period itself, and that period's governing regulation, 1303/2013, is no longer in force. No parallel guidance note, written for and dated to the current regulation, replaces this reference at either point.

III. WHAT THE 2015 TEXT ITSELF ALREADY ADMITTED

The 2015 guide being cited is not silent about its own limits. Its section on audit certificates states plainly that management verifications may be reduced to a sample "taking into account known risks, including the possible lack of independence of the body providing the certificate" — the Commission naming, in its own methodological text, the exact structural weakness this doctrine addresses elsewhere: a verification produced by a party who may not be independent of the thing being verified. Its section on segregation of duties, built on Article 72(b) of the prior regulation, permits that separation to be satisfied by assigning verification to a different department of the same organisation — a finance department, an internal audit unit — rather than to a party independent of the organisation itself. The guidance the current framework leans on was already, in 2015, describing an intra-entity separation, not an external one.

IV. THE ENDOGENOUS AUDIT PARADOX AT THE DEFINITIONAL LAYER

Elsewhere in this doctrine, the Endogenous Audit Paradox describes a verification produced by the same party whose conduct it is meant to establish. Here the paradox operates one layer further back, at the level of the definitions themselves. The current fact sheet does not merely apply risk-based verification — it borrows the very description of what that methodology consists of from a guidance note written for a different regulation, without independently re-verifying that those definitions still hold under the current one. Nothing in the 2021 fact sheet fixes, at the moment it was written, that the methodology it silently imports remains accurate for Article 74(2) rather than for the article it replaced. The two structural admissions already present in the 2015 text — an auditor's independence that may be lacking, a segregation that stops at the organisation's own boundary — travel forward into the current framework by citation, not by re-examination.

V. WHAT THE REGULATION DOES NOT REQUIRE

Nothing in Article 74 of Regulation (EU) 2021/1060 requires that the methodology document a managing authority relies on for its risk-based approach be independently verified, at the moment it is issued, against the regulation currently in force. The regulation requires the risk assessment itself to be written and to precede verification. It does not require that the guidance defining what "risk-based and proportionate" means be dated, checked, or reissued against the text it now serves.

VI. WHAT AN INDEPENDENT SEAL WOULD ADD

If the methodology a managing authority actually applies under Article 74(2) — its risk criteria, its sampling logic, the definitions it relies on — were independently fixed at the moment that methodology was adopted, a later dispute over whether verifications were properly risk-based and proportionate would not turn on which guidance note happened to be cited, or when. The seal would not determine whether a given verification satisfied Article 74(2) — that determination belongs to the Commission, the audit authority, and ultimately the Court of Justice of the European Union. It would establish, independently of the managing authority, what methodology was actually in use and when it was adopted, so that a later examination is argued against a fixed record rather than a citation trail running back through a document tied to an expired regulation.

VII. WHAT SOURCE 0 DOES NOT CLAIM

SOURCE 0 does not replace the Commission's guidance role, the audit authority's function under Article 127, or the European Court of Auditors' own audits of cohesion policy. It does not determine whether any managing authority's actual verifications comply with Article 74(2), nor does it allege that the INTERACT fact sheet is unlawful or that any citation to the 2015 guide is itself an irregularity — the guide remains genuinely useful reference material. SOURCE 0 CERTIFIED denotes an attestation, delivered by Jean-François ELSEN, that the SOURCE 0 procedure was followed in a given engagement; it is not an independent third-party certification, since Jean-François ELSEN provides the service being certified. All engagements are governed by an obligation de moyens. Recognition of the Historical Reality Dossier is direct before Belgian jurisdictions and assessed case by case elsewhere.

VIII. FREQUENTLY ASKED QUESTIONS

Q: Isn't citing a 2015 guidance note just normal continuity, not a problem?

A: Continuity is exactly the issue's shape, not its resolution. The 2015 methodology may still be entirely sound — but nothing independently confirms that at the moment the current fact sheet adopted it by reference. SOURCE 0 seals the methodology actually in use at the moment it is adopted, so soundness does not rest on an unexamined citation.

Q: Doesn't the audit authority already check whether verifications were properly risk-based?

A: It checks this at the moment of audit, typically ex post, against whatever methodology the managing authority says it used. It was not built to independently fix what that methodology was, or when it was adopted, before any dispute arose. SOURCE 0 closes that gap at the point of adoption.

Q: The EGESIF 2015 guide itself admits the risk of a lack of independence in audit certificates — doesn't naming the risk already manage it?

A: Naming a risk is not the same as independently fixing whether it materialised in a given case. The admission shows the Commission already sees the structural weakness; it does not, on its own, establish what happened in any specific verification. SOURCE 0 supplies the missing independent record.

Q: Is the intra-entity segregation described in section 1.11 not sufficient separation?

A: It satisfies Article 72(b)'s requirement that selection, verification, and payment be handled by different functions. It does not establish independence from the organisation itself, since all three functions can sit inside the same managing authority. SOURCE 0 does not replace that segregation — it fixes, independently of any of the three functions, what the methodology and its adoption date actually were.

Q: Does SOURCE 0 determine whether a managing authority's verifications are actually risk-based and proportionate under Article 74(2)?

A: No — that determination belongs to the audit authority, the Commission, and ultimately the Court of Justice of the European Union. SOURCE 0 fixes what methodology was in force and when, so that determination is made against an independent record rather than a citation trail.

CLOSING AXIOM

A guidance note can update its citations without ever seeing the fact it now covers. SOURCE 0 seals the methodology before the footnote is the only one who remembers where it came from.

REFERENCE NOTE

This article is based on Regulation (EU) 2021/1060 (Common Provisions Regulation), in particular Articles 72 and 74, on the European Commission's guidance note EGESIF_14-0012_02 final (September 2015, programming period 2014-2020), and on the INTERACT fact sheet "Management Verifications 2021-2027" (December 2021).

REGULATORY NOTICE

This document does not constitute legal advice and does not take any position on the compliance of any specific managing authority's verification practices with Regulation (EU) 2021/1060. Organisations should verify their specific situation with qualified legal counsel.

Jean-François ELSEN

Jean-François ELSEN est auditeur et expert en sûreté industrielle. Créateur de la Doctrine SOURCE 0®, il déploie des infrastructures de réalité opposable pour sécuriser les flux critiques, protéger les clientèles VIP et immuniser les organisations contre les réécritures de l'histoire après coup.

https://jfelsen.com
Suivant
Suivant

SOURCE 0 - THE SUBSIDY NO ONE ELSE LOGGED