Closed and root-reviewed 9 September 2026. This bounded lane acquired the Commission audit index and the linked AliExpress 2024/25 audit and implementation report. It inspected the public-data access obligation, selected audit identity/method/evidence passages, and report dates. It did not read all 365 audit pages or test the live system.
The [FTI audit](http[local research file] PDF295-297, gives Article40(12) a positive conclusion with no recommendation. The explanation expressly concerns intention and capability. It describes a public application form, an SOP for evaluation/amendment/communication, Legal-team management, designated staff applying40(8)(b)-(e), and standardized approval/rejection/clarification emails. Approved access is described as DSA Ads, Items and Punishments datasets via dashboard and request-dependent API queries. This is the auditor's account of the process, not our exercised access.
The consequential observation is that no applications were approved during 1 July2024-30 June2025. The request count is redacted. The auditor says it inspected all applications and verified them as incomplete or invalid on their submitted information. That statement must accompany the zero-approval finding: the record is not merely a provider assertion accepted without claimed examination. The conclusion describes preparedness for a future qualifying request; its statement that no instance required application of the obligation cannot mean that no requests existed. Neither improper rejection nor successful data delivery is demonstrated by the public report. Application files, clarification/rejection reasons and the operative eligibility SOP would test those alternatives.
The stated evidence includes public/internal documents, written attestations, interviews and substantive electronic-process testing. PDF296 names EV207 (the prior audit/implementation repository) and EV208 (a prior DSA audit report), with other entries confidential. Those are explicit prior-report references; they are not the complete basis and do not prove circular assurance. No individual applications, interview records, actual tests or audit workpapers were acquired. No applicant is identified as GDI or AI4TRUST.
The [implementation report](http[local research file] PDF4, names FTI Consulting LLP as engaged by Alibaba.com Singapore E-commerce Private Limited. It dates adoption to29August2025 and audit work to5May-29August2025. FTI's exact LLP identity is also visible in the audit footers. The evaluation period largely precedes the18June2025 commitments and entirely precedes Ankura's23September appointment and full implementation after30September. This audit cannot establish performance under the first November2025 trustee cycle or the current2026 access system.
Selected audit front matter describes conflict checks, noncontingent fees, independence and quality methods. These are the auditor's declarations, not independently verified conflict or engagement records. Its stated absence of a single global quality-management policy is accompanied by segment/professional controls; it is not by itself proof of a deficient opinion. Provider implementation contents and closing improvement statements are not an independent validation of Article40 access. The report contains no Article40 section in the inspected contents; no full recommendation audit is claimed.
The parallel trustee lane closed after13 indexed queries and two original HTML route captures. Its note correctly distinguishes required reports and permitted two-way auditor sharing from reports actually delivered and exchanges actually made. The current Commission AliExpress entry is a main-activity index, not a full docket. Ankura's generic service page contains no case-specific findings and adds no proof of performed AliExpress work. Report confidentiality/recipient rules make private delivery plausible, but do not establish delivery, non-delivery or a Commission refusal to disclose. The2026 reporting cycle has not yet ended.
Commission index: AliExpress table rows and their actual audit/implementation links only. Audit text: PDF1,3-6,10-14,295-297; visual:295-296. Keyword locations on other pages are discovery only. Implementation text:PDF1-5,37; no visual or whole-report review. On continuation, audit295-297 and implementation4 were reread to verify the key result/date. Root also read the complete oversight note/manifest, scoped index derivative and Ankura substantive derivative; reused decision/appointment reading remains in the preceding accepted packet. Original and derivative custody is in root-captures.json and oversight-captures.json.
The administrative gate has a named operating owner: the provider's Legal team, under the reported SOP. A positive access opinion can coexist with no delivered access when all requests are judged ineligible. That is a concrete mechanism for testing gatekeeping, not evidence by itself of obstruction. The best next public record is an actual request and reasoned response, preferably with the missing-information exchange; this connects the formal entitlement to the judgment that made it usable or unusable.