Assurance: The Critical Dimension of the CSRD
The Corporate Sustainability Reporting Directive (CSRD) aims to bring sustainability reporting in Europe to a reliability level equivalent to financial reporting. One of the most tangible manifestations of this goal is the mandatory requirement for sustainability reports to undergo independent assurance.
Article 34 of the Directive requires that sustainability reporting by in-scope companies be supported by an "assurance opinion from a statutory auditor or audit firm" (Directive 2022/2464, Article 34). This means sustainability data is no longer merely declarative — it must be verified by an independent third party.
For many companies, this is an entirely new process. Even with financial audit experience, sustainability assurance operates under different standards, involves different data types, and demands different internal control requirements.
Limited Assurance vs. Reasonable Assurance: Key Differences
The CSRD initially requires limited assurance, while envisaging that the European Commission will evaluate a transition to reasonable assurance in subsequent periods.
Limited Assurance
Limited assurance is the level at which the auditor expresses a negative-form conclusion, stating that "nothing has come to our attention that causes us to believe the subject matter is materially misstated." The auditor works primarily through inquiry and analytical procedures, with relatively fewer detailed tests.
ISAE 3000 (Revised) defines limited assurance engagements as follows: "Engagement risk is the risk that the practitioner expresses an inappropriate conclusion when the subject matter information is materially misstated. In a limited assurance engagement, this risk is higher than for a reasonable assurance engagement but is still at an acceptable level" (IAASB, ISAE 3000 (Revised), paragraph 11).
Reasonable Assurance
Reasonable assurance is the level at which the auditor expresses a positive-form opinion, stating that "the report has been prepared, in all material respects, in accordance with the criteria." This is equivalent to the audit opinion on financial statements. It requires more extensive testing, more evidence gathering, and significantly more audit hours.
Under the CSRD's phased transition plan:
| Period | Assurance Level | Basis |
|---|---|---|
| 2024-2028 (estimated) | Limited assurance | Directive 2022/2464, Article 34(1) |
| Post-2028 (estimated) | Transition to reasonable assurance under review | Commission evaluation report |
Practical Interpretation: Limited assurance is not "easier" than reasonable assurance — it is simply less extensive. Auditors will still apply procedures designed to detect material misstatements. Treating limited assurance as a low bar to clear is a strategic mistake.
Assurance Standards: ISAE 3000 and ISSA 5000
ISAE 3000 (Revised): The Current Standard
Published by the International Auditing and Assurance Standards Board (IAASB), ISAE 3000 (Revised) provides the general framework for assurance engagements on non-financial information. Sustainability assurance engagements currently rely heavily on this standard (IAASB, International Standard on Assurance Engagements 3000 (Revised), Assurance Engagements Other than Audits or Reviews of Historical Financial Information).
The core requirements of ISAE 3000 include:
- Ethical requirements: Independence, objectivity, and professional competence
- Quality management: Ensuring engagement quality
- Planning: Risk assessment and engagement strategy determination
- Evidence gathering: Obtaining sufficient and appropriate evidence
- Reporting: Presenting the assurance conclusion clearly and understandably
ISSA 5000: The New Sustainability-Specific Standard
The IAASB is developing ISSA 5000 (International Standard on Sustainability Assurance), a new standard designed specifically for sustainability assurance engagements. This standard aims to deepen the general framework of ISAE 3000 with sustainability-specific requirements.
The ISSA 5000 exposure draft was released for public comment in August 2023, with finalisation planned for December 2024 (IAASB, "Proposed International Standard on Sustainability Assurance 5000," Exposure Draft, 2023). The standard provides specific guidance in the following areas:
- Structural characteristics of sustainability information (estimates, forward-looking statements, qualitative data)
- Information reliability across the value chain
- Compatibility with multiple reporting frameworks
- Use of the work of other practitioners
Important Note: Although ISSA 5000 has not yet been finalised, the CSRD's assurance requirements are expected to align with this standard. Companies are advised to monitor both standards.
What Do Auditors Look For?
Assurance auditors examine sustainability reports from a specific perspective. The following areas constitute their focal points:
1. Data Trail
Every data point must be traceable back to its source. When your report states "Our Scope 1 emissions are 12,450 tonnes CO2e," the auditor will ask: Where did this number come from? Which facilities' data are included? Which emission factors were used? Where is the raw data stored?
In EFRAG's CSRD implementation guidance, "data quality and traceability" is explicitly listed among the assurance areas that companies should prepare for (EFRAG, "ESRS Implementation Guidance," 2024).
2. Internal Controls
As with financial reporting, internal control mechanisms that ensure the accuracy of sustainability data will be examined:
- Segregation of duties in data collection processes
- Input validation and approval procedures
- Documentation of calculation logic
- Error detection and correction mechanisms
- Regular internal reviews
3. Governance
The integration of sustainability reporting into the corporate governance structure is expected. Auditors will examine:
- The board's role and responsibility in sustainability reporting
- The competence of personnel responsible for the reporting process
- Senior management's involvement in the reporting process
- The existence of sustainability reporting policies
4. Consistency and Comparability
Reporting methods must be applied consistently across periods, produce comparable results, and any methodology changes must be clearly disclosed.
5. Completeness
Auditors will assess whether the reporting scope meets ESRS requirements and whether any material topics have been excluded.
Building the Internal Control Infrastructure
The most effective way to prepare for assurance is to establish a robust internal control infrastructure. Extending the internal control framework that already exists for financial reporting to cover sustainability data is far more efficient than starting from scratch.
Data Collection Controls
- Defined data owners: Assign a responsible person and a backup for each data stream
- Standardised templates: Ensure data from facilities is collected in a consistent format
- Automated validation rules: Logical limits, year-over-year comparisons, unit checks
- Timestamps: Recording when and by whom each data entry was made
Calculation Controls
- Documented methodology: Written record of which calculation method was used and why
- Emission factor register: Factors recorded with source, date, and rationale
- Four-eyes principle: Calculations reviewed by someone other than the preparer
- Change log: Recording any corrections or recalculations
Reporting Controls
- Internal review: The report passes through at least one internal review cycle before publication
- Management sign-off: Final report approved by the authorised management body
- Consistency checks: Data in the report is consistent internally and with other public disclosures
Readiness Timeline
Preparation for assurance should begin well before the reporting period. The following timeline represents a recommended approach for companies facing assurance for the first time:
12-18 Months Before the Reporting Period
- Gap analysis of current data collection processes
- Design of the internal control framework
- Preliminary discussions with assurance provider
- Identification of training needs and planning of training programmes
6-12 Months Before the Reporting Period
- Implementation of internal controls
- Running a pilot data collection cycle
- Making process improvements
- Assurance readiness assessment — many audit firms offer this service
During the Reporting Period
- Regular operation of controls
- Building evidence files
- Interim reviews
- Timely identification and correction of deviations
After the Reporting Period
- Report preparation and internal review
- Submission of evidence files to the assurance auditor
- Timely responses to auditor queries
- Planning identified improvement areas for the next period
CSRD-Specific Assurance Requirements
There are several specific requirements to note regarding the assurance dimension of the CSRD:
Reporting Framework Compliance
The assurance auditor will assess the report's compliance with the European Sustainability Reporting Standards (ESRS). This includes checking whether the disclosure requirements of each applicable ESRS have been met.
Double Materiality Assessment Verification
The appropriateness of the company's double materiality assessment process also falls within the scope of assurance. The auditor will question whether the assessment methodology, stakeholder engagement process, and results are reasonable.
Digital Tagging
The CSRD requires sustainability reports to be presented in digital format (with XBRL tagging). Whether the scope of assurance extends to digital tagging will be clarified through the European Commission's secondary legislation.
Common Readiness Gaps
The most frequently encountered gaps among companies preparing for assurance are:
- Undocumented data sources: Data has been collected but sources, calculation methods, or assumptions have not been recorded in writing.
- No traceability in Scope 3 data: Supply chain emissions are estimate-based but the estimation methodology is undocumented.
- No internal control structure: Data is being collected but not controlled; no error detection mechanism exists.
- Missing governance integration: Sustainability reporting is run as an operational process without board-level ownership.
- Time management: Insufficient time allocated to the assurance process; working under pressure to respond to auditor queries.
Conclusion: Assurance Is the Beginning of the Journey
Assurance is not an obstacle but a mechanism that enhances reporting quality. While this process is mandatory for companies within the CSRD scope, assurance readiness also serves as a transformation opportunity that strengthens data quality, internal processes, and corporate governance.
The journey that begins with limited assurance today will evolve toward reasonable assurance in the future. Preparing for this transition now means lower costs and less friction in the years ahead.
Action Item: Evaluate your current sustainability data collection process through an auditor's lens. For each data point, ask: "How would I evidence this to an auditor?" The points where you cannot find an answer are the areas where your internal control infrastructure needs strengthening.