Sustainability information has moved from being a voluntary section of the annual report to a set of indicators subject to mandatory external verification in a growing number of organizations. This shifts direct pressure onto Internal Audit, which must provide assurance over the reliability of that data before it reaches the external verifier. This article explains which risks are specific to ESG data and how to approach its audit with a practical methodology.
Why sustainability information now demands the same rigor as financial information
From voluntary disclosure to mandatory reporting
For years, sustainability information was published with a level of detail and rigor that varied widely between organizations, without a regulatory requirement comparable to that of financial reporting. The progressive expansion of mandatory sustainability reporting obligations has changed this picture: a growing number of ESG indicators are now subject to external verification, in a way similar to what already happens with annual financial statements.
What changes for Internal Audit compared to traditional financial reporting
Financial reporting relies on mature accounting systems, with controls consolidated over decades. ESG data, by contrast, often comes from highly heterogeneous sources: energy consumption recorded at facility level, human resources data, supplier information, or estimates of indirect emissions. This heterogeneity of sources is precisely what makes ESG data a higher risk area for error or inconsistency.
What role does Internal Audit play alongside external verification
Internal assurance ahead of external verification
Before the external verifier reviews sustainability indicators, Internal Audit can provide a prior layer of assurance that identifies and corrects weaknesses in data collection processes. This reduces the risk of findings from the external verifier and improves the overall quality of the information ultimately published.
Difference between the role of Internal Audit and that of the independent verifier
The external verifier issues a formal opinion on the published sustainability information, with a scope and methodology defined by applicable regulation. Internal Audit, on the other hand, evaluates the internal processes and controls that underpin that information throughout the year, complementing the verifier's work rather than replacing it.
Risks specific to ESG data that Internal Audit should evaluate
Traceability and origin of non-financial data
Unlike an accounting transaction, a data point on energy consumption or emissions may come from a supplier invoice, an industrial monitoring system, or a manual estimate. Verifying the exact origin of each indicator, and whether there is documentary evidence to support it, is one of the first steps in any ESG audit.
Estimates and assumptions in environmental indicators
Many environmental indicators, particularly those related to indirect value chain emissions, are calculated using conversion factors and methodological assumptions. Internal Audit should assess whether those assumptions are documented, reasonable, and applied consistently across periods.
Greenwashing risk in how results are communicated
Beyond the technical accuracy of the data itself, there is a risk that the narrative accompanying ESG indicators conveys a more favorable image than the data actually supports. Internal Audit can help detect this gap by comparing disclosed content against the evidence that genuinely backs each claim.
A practical methodology for auditing ESG indicators
Step 1: map the data collection process for each indicator
For each relevant indicator, identify who collects it, how often, from which source, and which system or file consolidates it before it reaches the final report.
Step 2: identify the key controls over non-financial data
Determine what reviews exist before the data is considered final: validation by a responsible owner, reconciliation against external sources, or cross-checking between different areas that handle related information.
Step 3: test traceability from source data to the published report
Select a sample of indicators and follow their full journey, from the originating document or system to the final figure published, verifying that no manual adjustments were made along the way without documented justification.
Step 4: assess the reasonableness of estimates and assumptions
When an indicator depends on an estimate, assess whether the method used is reasonable, aligned with recognized sector practices, and applied consistently relative to prior periods, to avoid artificial swings in the reported trend.
Common mistakes when auditing ESG information
- Treating ESG data with less rigor than financial data. Growing regulatory pressure is, in practice, already equating the level of control expected over both types of information.
- Failing to involve the operational areas that generate the source data. Much ESG information is generated outside traditional finance systems, in areas such as operations, human resources, or facilities management.
- Accepting estimates without reviewing the documentation behind the assumptions used. An estimate without a documented methodology is difficult to defend in front of an external verifier or any later challenge.
- Focusing only on numerical accuracy without reviewing the narrative that accompanies the data. Greenwashing risk often sits more in how results are interpreted and communicated than in the figure itself.
Key control point: if a material ESG indicator cannot be traced back to a clear source document or system, it is unlikely to withstand the scrutiny of an independent external verifier either.
An audit management platform that allows each indicator's traceability to be documented, links supporting evidence at the source, and records the assumptions used in estimates makes this type of audit significantly easier, especially when ESG indicators originate from multiple areas and systems across the organization.
ESG information audit checklist
- Does each relevant indicator have a documented collection process and an identified owner?
- Is there traceable evidence from the source data all the way to the figure published in the final report?
- Are estimates and methodological assumptions documented and applied consistently?
- Has the disclosed narrative been checked against the evidence available to support it?
- Do the operational areas generating the source data understand the controls they need to apply?
- Is Internal Audit's work coordinated with the external verifier's timeline?
Conclusion
ESG information now faces a level of scrutiny that already resembles traditional financial reporting, but with the added complexity of more heterogeneous data sources and less mature controls. Internal Audit's role in this area is not to replace the external verifier, but to provide a prior layer of assurance that reduces the risk of error and strengthens the credibility of the information the organization ultimately communicates.