Skip to content
Auditors examining an ESG report with a magnifying glass over charts and data
Voltar ao blog
Product 13 min de leituraApril 24, 2026

What an auditable ESG report actually means

What auditors expect to find in an ESG report, the difference between limited and reasonable assurance, and how to secure full traceability.

Alexandre Kelemen
Alexandre Kelemen
Co-founder & CEO · Mangue
Share

The difference between publishing a report and auditing one

Publishing an ESG report is relatively simple. Hire a designer, compile indicators, write progress narratives and post a PDF on the company website. Plenty of companies do that and stop there.

Auditing a report is something else. It means an independent third party examined the data, tested the calculations, traced the sources and issued an opinion on how reliable the information is. Audit turns a communications document into an accountability document.

CVM 193 set the IFRS S1/S2 standard for listed companies (CVM 244 made it voluntary, but the market keeps asking). The direction is unmistakable: publishing is not enough, the data has to be verifiable. CDP already distinguishes companies with independent verification. IFRS S2 requires disclosures at a level of rigour comparable to financial statements. And SBTi validates targets on the basis of verified inventories.

The distance between a publishable report and an auditable one is, in practice, the distance between having organised data and having traceable data. And that distance is wider than it looks.

Limited assurance vs reasonable assurance

Independent verification of sustainability information can be done at two levels of assurance, defined by ISAE 3000 and ISAE 3410 (the GHG-specific standard).

Limited assurance. The auditor performs analytical procedures and enquiries to determine whether anything has come to their attention that would lead them to believe the information is materially misstated. It is a negative conclusion: "nothing came to our attention". The procedures are less extensive: analytical review, interviews, sample testing. It is the most common level for sustainability reports today.

Reasonable assurance. The auditor obtains sufficient and appropriate evidence to express a positive opinion: "the information is fairly presented, in all material respects". It requires substantive testing, verification of original documents, independent recalculation and third-party confirmation procedures. It is the same level of assurance as audited financial statements.

The global regulatory direction is a progressive move from limited to reasonable. The European CSRD requires limited assurance initially, with a transition to reasonable. In Brazil, CVM 193 starts with limited assurance for listed companies.

Audit trail: traceable source, referenced factor, owner and date

The audit trail is the heart of an auditable report. Every disclosed figure needs four traceable elements.

The data source. Where did the information come from? An energy bill, an ERP report, an employee survey, a waste manifest. The source document has to be accessible and linked to the data point in the inventory. If the auditor cannot get to the source document, the data point is not verifiable.

The emission factor with its reference. Which factor converted the activity data into emissions? What source (MCTI, IPCC, Defra)? Which version and year of publication? Which GWP applied (AR5, AR6)? A factor without a reference is an arbitrary number, and the auditor will challenge it.

The person who validated it. Who reviewed and approved the data point? In manual processes, that information is lost. On platforms with an approval workflow, each data point has a recorded owner. That matters especially when several areas contribute data: the validator is what confirms the data was reviewed by someone who knows the process.

Date and version. When was the data collected? When was it validated? If it was corrected, when and why? Version control is essential to stop partial or stale data from contaminating the final result. The auditor needs to know they are looking at the final version, not a draft.

Calculation memo and evidence data room

Beyond the record-by-record audit trail, two structural elements are needed.

The calculation memo. A document describing the methodology applied: which organisational boundaries were set (operational control vs financial control vs equity share), which emission sources were included and excluded (and the justification for exclusions), which calculation methodologies were used for each source type, which assumptions were made (particularly for Scope 3 using secondary data), and how the base year was defined and when it should be recalculated.

The calculation memo is the inventory's recipe. Without it, the auditor does not know what was being calculated, and cannot assess whether the result is right.

The evidence data room. An organised repository holding every supporting document: energy and fuel invoices, travel reports, waste manifests, renewable energy contracts, I-REC certificates, waste analysis reports, commuting surveys, production and revenue data (for intensity metrics).

The data room can be physical (a file folder) or digital (a shared drive, a document management platform). What matters is that it is organised by emission source, period and site, and that the auditor can navigate it without needing the analyst as a guide.

What the auditor expects to find

Sustainability auditors, specialist firms such as SGS and Bureau Veritas, and the large accounting firms, carry a mental checklist of what a robust process looks like. Here is what they look for.

Inventory governance. Who owns it? Is there a committee or working group? Is there an internal emissions management policy? Are roles and responsibilities documented? A lack of governance is not a technical non-conformity, but it signals low maturity and raises the auditor's scepticism.

Methodological consistency. Is the methodology the same across sites and across periods? If site A calculates fleet emissions by kilometres driven and site B by litres refuelled, the auditor will question comparability. Consistency does not demand perfection, it demands clear documentation of the differences.

Completeness. Were all material emission sources included? If the company has 50 sites and reported data for 45, the missing 10% needs a justification, and an estimate of the impact of the exclusion. The GHG Protocol rule is clear: exclusions representing more than 5% of total emissions need a detailed justification.

Accuracy. Are the calculations right? The auditor recalculates a sample of records to check. If emission factors are wrong, if unit conversions carry an error, if formulas sum incorrectly, those errors show up in the test.

Transparency. Are assumptions and uncertainties documented? Scope 3 data on a spend-based approach carries more uncertainty than Scope 1 data from direct measurement. The auditor expects that difference in quality to be acknowledged and documented.

How Mangue Tech produces reports ready for verification

The Mangue Tech platform was designed with auditability as a design principle.

Native audit trail. Every record has full provenance: source document, emission factor with its reference, the person who validated it, the date and the change history. The auditor navigates from the consolidated result to the source document without leaving the platform.

Automatic calculation memo. The platform generates the methodological documentation automatically: inventory boundaries, sources included and excluded, methodologies by source type, emission factors used with full references, assumptions made for estimates.

Integrated data room. Every supporting document, invoices, reports, certificates, surveys, is stored in the platform, organised by source, period and site. Auditor access can be configured with specific permissions (read only, by period, by site).

Multi-framework reports. The same database produces reports in the formats required by GHG Protocol, CDP, CVM 193 and IFRS S2. Each report pulls the same data under each framework's rules, with no reprocessing and no risk of inconsistency between versions.

Approval workflow. Data entered goes through a review flow before it enters the final calculation. The analyst enters it, the coordinator validates it, the manager approves it. Each step is recorded in the audit trail. That meets the segregation-of-duties requirement auditors expect.

The result: by the time the auditor arrives, the inventory is already ready for verification, with all the documentation organised, traceable and accessible. Audit time falls, rework falls, and confidence in the result goes up.

Key takeaways
  • Auditability is a design principle, not a feature added later
  • Invest in the audit trail and the calculation memo before the auditor asks for them
  • Moving from limited to reasonable assurance demands substantially more rigorous documentation
  • Multi-framework reports from a single database eliminate inconsistencies

Perguntas frequentes

Do I need independent verification for CDP?+

It is not mandatory, but CDP awards extra points to companies with independent verification of Scopes 1 and 2. For an A score, verification is effectively necessary.

What is the difference between an ESG report audit and a financial audit?+

The structure is similar (planning, testing, conclusion), but the standards differ. Financial audit follows ISA. Sustainability audit follows ISAE 3000/3410. The auditors may be the same firms or specialist verification bodies.

Does Mangue Tech carry out the independent verification?+

No. Mangue Tech prepares the inventory and the documentation. Independent verification is done by accredited third parties. The verifier's independence is a fundamental requirement.

Glossary
Assurance
The level of confidence the independent auditor provides over the quality of the verified information.
ISAE 3000
International Standard on Assurance Engagements, the standard for verifying non-financial information.
ISAE 3410
The specific standard for verifying greenhouse gas inventories.
Data room
An organised repository of supporting documents for verification and audit.
Materiality
The threshold above which an error or omission is significant enough to influence the decision of the user of the information.
Sources

Frameworks mencionados neste artigo

Related services

Get ESG analysis by email

Regulatory updates, practical guides and market data. No spam.

Share

Want to apply this at your company?