Emissions data assurance readiness: getting audit-ready for GHG disclosure
What third-party assurers check, the difference between limited and reasonable assurance, and why utility bills and meter data are the primary evidence behind a defensible GHG number.
The first time an assurer asks to trace a reported emissions figure back to source, most teams discover the same thing: the number in the disclosure is three spreadsheets away from any document that proves it. The consumption came from a bill, the bill was keyed into a tracker, the tracker fed a model, and the model produced a tonne figure with no clean path back. Assurance readiness is largely the work of rebuilding that path before someone else asks to walk it.
This is moving from good practice to requirement. Disclosure mandates in Canada, the EU, and parts of the US are attaching third-party assurance to reported emissions, and assurance means an independent party has to be able to verify your numbers against evidence.
Limited versus reasonable assurance
Assurance comes in two levels. Limited assurance produces a negatively worded conclusion, that nothing came to the assurer's attention to indicate the information is materially misstated, and relies mainly on inquiry and analytical procedures. Reasonable assurance produces a positive opinion, that the information is fairly stated, and requires more extensive substantive testing. Reasonable assurance is more work and more confidence.
The global standard for this work is now ISSA 5000, the IAASB's general requirements for sustainability assurance engagements, which covers both limited and reasonable engagements and can be applied by accountant and non-accountant practitioners alike. It is effective for periods beginning on or after December 15, 2026, with early adoption encouraged.
The Canadian picture first
In December 2024 the Canadian Sustainability Standards Board (CSSB) released its first standards, CSDS 1 on general sustainability-related financial disclosure and CSDS 2 on climate-related disclosures, both effective for annual periods beginning on or after January 1, 2025. They are modelled on the ISSB's IFRS S1 and S2 with Canadian modifications, currently voluntary unless mandated, and include transition relief that defers Scope 3 disclosure to periods beginning on or after January 1, 2027.
For federally regulated financial institutions, OSFI Guideline B-15 already requires climate-related disclosures, including Scope 1 and 2 GHG emissions, phasing in from fiscal year-end 2024 and 2025, with Scope 3 expected from fiscal year-end 2028. The direction of travel is clear: reported emissions in Canada increasingly need to stand up to independent examination.
What the mandates require, elsewhere
California's SB 253, the Climate Corporate Data Accountability Act, is the sharpest US example. As written, the statute requires large companies doing business in California to report Scope 1 and 2 emissions and obtain limited assurance beginning in 2026 and reasonable assurance beginning in 2030, with Scope 3 limited assurance from 2030. In practice the implementing rulemaking has shifted the timing: under the California Air Resources Board's approach, the first limited-assurance requirement for Scope 1 and 2 is now expected to begin in 2027 rather than 2026.
In the EU, the Corporate Sustainability Reporting Directive requires third-party assurance starting at a limited assurance level from the first reporting year. The earlier expectation of an automatic step-up to reasonable assurance was removed through the EU's Omnibus process, so the current position is limited assurance without a mandated escalation.
The US federal picture is a caution against assuming any rule is permanent. The SEC adopted climate disclosure rules in March 2024, stayed them the following month, and in 2026 proposed to rescind them entirely. The rules never took effect. The lesson is to build data that satisfies the strictest applicable regime, not the loosest.
What assurers actually check
Assurance is not a review of your prose. It is a trace from the reported number to evidence. Assurers require that activity data, such as fuel use and electricity consumption, ties back to primary source evidence: utility bills, meter readings, invoices, and system reports, with transparent calculations showing activity data multiplied by emission factor. If a figure has no supporting document, it cannot be verified.
Utility bills are treated as among the most precise activity data for consumed electricity within an organization's boundary. Both limited and reasonable engagements sample underlying data such as utility bills, with reasonable assurance using larger samples and more substantive testing, and assurers recalculate key figures and investigate year-over-year anomalies. Beyond source data, they verify the organizational boundary and completeness and check emission-factor sourcing.
Emission factors deserve their own attention. Assurers check not only that a factor is documented but that it is the correct one for the region and the correct vintage for the reporting year, since grid factors change annually and a stale factor produces a defensible-looking but wrong number. The same goes for the boundary: an assurer will test whether every site and meter that should be in scope actually is, because a quietly omitted facility is a completeness error even when every included figure is accurate.
Where teams commonly fail
The recurring findings are mundane and preventable: incomplete data, poor or absent documentation, spreadsheet errors, and estimates without support. A gap in coverage, a broken formula, or an estimated month with no basis is enough to hold up a conclusion. Clean, complete, traceable consumption data removes most of these before an assurer arrives.
What a good audit trail looks like
The practical target is that any figure in your disclosure can be reproduced from source in a few steps: reported tonnes, back to the activity total, back to the individual bills or interval reads, with the emission factor and its vintage recorded alongside. Estimated periods should be flagged as estimates, with the method noted, rather than blended invisibly into actuals. When that trail exists as data rather than as a memory in one analyst's spreadsheet, a limited assurance engagement moves quickly and a step up to reasonable assurance later becomes a question of sample size, not a rebuild.
| What assurers examine | Evidence they expect | Common failure |
|---|---|---|
| Activity data | Utility bills, meter reads, invoices | Missing months, no source document |
| Calculations | Activity data times emission factor, shown | Spreadsheet errors, opaque models |
| Boundary and completeness | List of sites and meters in scope | Gaps, double counting |
| Emission factors | Sourced, dated, correct vintage | Wrong or undocumented factors |
| Estimates | Documented basis and method | Unsupported placeholder values |
Assurance is already widespread
This is not a distant concern. In the IFAC, AICPA, and CIMA State of Play study, 75% of companies obtained some level of assurance on their sustainability disclosures in 2024, up from 73%, with most performed at the limited assurance level and audit firms providing 59% of engagements. If your peers are already being examined, the audit trail is worth building now rather than during your first engagement.
The groundwork overlaps with adjacent tasks. Our guides on preparing utility data for an ESG audit and why carbon accounting needs clean utility data cover the mechanics of getting source data into shape.
Frequently asked questions
What is the difference between limited and reasonable assurance?
Limited assurance gives a negatively worded conclusion, that nothing came to the assurer's attention suggesting a material misstatement, using mainly inquiry and analytics. Reasonable assurance gives a positive opinion and requires more extensive substantive testing and larger samples.
Are Canadian companies required to get emissions assurance?
The CSSB's CSDS 1 and CSDS 2 are currently voluntary unless mandated, but OSFI Guideline B-15 already requires federally regulated financial institutions to disclose Scope 1 and 2 emissions, and global assurance standards like ISSA 5000 take effect for periods beginning on or after December 15, 2026.
What documents do assurers ask for?
They trace reported figures to primary evidence such as utility bills, meter readings, invoices, and system reports, and they expect calculations that show activity data multiplied by emission factors, plus documentation for boundaries, factors, and any estimates.
Why do companies fail GHG audits?
The common findings are incomplete data, poor or missing documentation, spreadsheet errors, and estimates without a documented basis. Clean, complete, traceable consumption data prevents most of these issues.
- 1IAASB: understanding ISSA 5000, the sustainability assurance standard
- 2IAASB: ISSA 5000 extracts on limited and reasonable assurance
- 3CPA Ontario: CSDS 1 and CSDS 2 sustainability reporting standards
- 4OSFI: Guideline B-15 Climate Risk Management
- 5California Legislative Information: SB 253 bill text
- 6PwC: California SB 253 assurance timing update
- 7SEC: proposed rescission of climate-related disclosure rules
- 8IFAC, AICPA & CIMA: State of Play sustainability assurance study
Preparing utility data for an ESG audit
Assurance turns your energy and emissions numbers into claims an auditor can test. Here is how to make utility data assurance ready before the audit starts.
Carbon accounting software still needs clean utility data
Carbon accounting platforms apply emission factors well. They do not fix bad inputs. Here is why activity data quality, not the software, decides whether your emissions number holds up.
