From the “no matter how bad you think it is, it’s worse” department.

  • It doesn’t. You can check the full text at:

    https://eur-lex.europa.eu/eli/reg/2016/679/oj

    The only references to audits, are that supervisors can require an audit, processors need to allow audits by controllers, DPOs need to prepare for audits, and corporations or groups of enterprises need to have audit procedures in place.

    It doesn’t say anything about what kind of audits these need to be, other than to ensure compliance with the law.