Getting assurance-ready: what auditors will ask for that you probably don’t have

Sustainability reporting is entering its audit era. What began as voluntary narrative is becoming assured disclosure: CSRD requires limited assurance; the FCA’s proposals for UK SRS reporting sit alongside a new assurance standard, ISSA (UK) 5000, effective for periods beginning on or after 15 December 2026. Even where assurance isn’t yet mandatory, lenders, investors and large customers increasingly expect sustainability claims to survive scrutiny.

Here’s the uncomfortable news: most organisations’ sustainability information was never built to be audited. It was built to be published. The difference becomes very visible the first time an assurance provider sits down and asks for evidence.

What they will actually ask for

  • The trail behind every number. Where did this emissions figure come from? Which meters, invoices, suppliers, conversion factors? Who extracted the data, who transformed it, and can you show the working? A number in a report with a spreadsheet behind it and a methodology in someone’s head is not evidence; it’s an assertion.

  • Documented methodology and boundaries. Which entities, sites and activities are in scope, and why? What estimation methods fill the gaps, and are they applied consistently year to year? Auditors are less troubled by estimation than by undocumented, shifting estimation.

  • Controls, not heroics. Who checks the data before it’s reported? Is there segregation between the person who compiles the figures and the person who signs them off? Most sustainability data processes are one person and a spreadsheet; a single point of failure that assurance frameworks are specifically designed to catch.

  • Evidence for claims, not just metrics. If your report says the board oversees climate risk, expect to show board papers and minutes proving it. If you claim supplier engagement, expect to show the correspondence. Narrative disclosures are assured too, and vague ones get challenged.

  • Consistency with the financial statements. Does your stated climate risk position match the assumptions in your accounts? Saying “material transition risk” in the front half and assuming business-as-usual asset lives in the back half is exactly the inconsistency reviewers now look for.

The gaps we find most often

When we run readiness reviews, the same issues recur. Emissions data is aggregated in ways nobody can decompose. Conversion factors are updated inconsistently. Scope 3 estimates rest on a supplier spreadsheet from three years ago. Governance claims outrun governance reality. And methodology decisions — often perfectly reasonable ones — were never written down, so the organisation can’t demonstrate consistency even where it exists.

None of this means the organisation is behaving badly. It means the information was produced for communication, not verification. That’s fixable, but not in the month before the audit.

Working backwards from the audit

Getting ready is mostly unglamorous, structural work, and it pays for itself even if formal assurance is years away because the same rigour makes your internal decision-making better.

Start with a gap assessment: take your most recent report and interrogate it as an auditor would. Every number, every claim: where’s the evidence? Then document your methodology — boundaries, estimation approaches, data sources, conversion factors — in a form that survives staff turnover. Build simple controls: a second pair of eyes, a sign-off step, a change log. Fix your data architecture where it’s weakest, usually Scope 3 and social metrics. And rehearse: a dry run with an internal or external reviewer surfaces problems while they’re still cheap.

Pre-assurance readiness is part of our disclosure and reporting practice precisely because the earlier it starts, the less it costs. If your next report might face external scrutiny — from an assurance provider, a lender or a major customer — it’s worth knowing now what they’ll find. Take our maturity assessment, or get in touch for a readiness conversation.

Previous
Previous

The operating model gap: why good strategies fail at the org chart