Who Actually Checks If an ESG Report Is True? A Guide to Assurance and Verification
Five real assurance statements, pulled from five 2025 and 2026 sustainability reports, say five different things. EY tells BSI Group that its emissions figures are assured, but only the specific numbers marked with an asterisk. KPMG Canada tells TC Energy the same, marking covered figures with a small caret symbol, and adds that one particular Scope 2 calculation method wasn't assured at all because TC Energy didn't use it. PwC tells Macquarie Group its assurance work specifically did not include verifying the underlying data Macquarie received from third parties. ERM CVS, a specialist firm that isn't one of the Big Four, tells AT&T its US carbon footprint holds up. And BDO tells SAP something rarer: not limited assurance, but reasonable assurance, on selected figures, while everything else in the same statement gets the lighter limited assurance treatment instead.
None of these five statements say what most readers assume an "audit" says. This article explains what assurance actually is, the real difference between its two levels, who is actually allowed to provide it, and exactly what a signature from a Big Four firm does and doesn't guarantee, using these five real 2025 to 2026 disclosures as evidence throughout.

What "Assurance" Actually Means (It's Not an Audit, and It's Not a Guarantee)

The standard nearly every ESG assurance statement is built on is ISAE 3000 (Revised), issued by the International Auditing and Assurance Standards Board (IAASB), formally titled Assurance Engagements Other than Audits or Reviews of Historical Financial Information. The name matters: it's explicitly not a financial audit. It's a separate kind of engagement where an independent practitioner reaches a conclusion about whether a specific piece of disclosed information is free from material misstatement, based on agreed criteria.
That conclusion is usually written in a very specific, deliberately hedged form of language, and once you can recognize it, assurance statements stop being intimidating boilerplate. EY's report for BSI Group states that nothing has come to their attention that causes them to believe the disclosed figures are not prepared, in all material respects, in accordance with the stated criteria. Notice what that sentence is not: it is not "we confirm these numbers are correct." It's a negative form of assurance, common to limited assurance engagements specifically, and the distinction between that phrasing and a positive "in our opinion, the figures present fairly" is itself one of the clearest signals of which assurance level you're looking at.
Key takeaway: assurance is a bounded professional opinion about specific, named information, checked against specific, named criteria, not a general verification that a company's ESG claims are true.
Limited vs. Reasonable Assurance: What Actually Changes

Limited assurance is the level used in the large majority of ESG assurance engagements today. Industry surveys put it at roughly 80% of large companies obtaining assurance, and a 2025 analysis by the Center for Audit Quality found that among S&P 500 companies that obtained any assurance at all, most still chose limited assurance over reasonable. EY's own assurance report for BSI Group states the mechanism plainly: the procedures performed in a limited assurance engagement vary in nature and are less extensive than those for a reasonable assurance engagement, and consequently the level of assurance obtained is substantially lower than what reasonable assurance would provide. In practice, that means the practitioner relies heavily on inquiry of company personnel and analytical review, essentially asking questions and checking whether numbers move the way you'd expect, rather than independently testing the underlying records.
Reasonable assurance is the higher bar, closer to what a traditional financial statement audit provides, though still not identical to one. It requires deeper procedures: testing of underlying source data, more extensive sampling, and often site visits to verify how data is actually collected at the operational level. It's also, consistently, described as costing meaningfully more and demanding more mature internal data systems, which is a large part of why so few companies choose it voluntarily. SAP's most recent sustainability statement is a useful real example of the two levels coexisting in one document: BDO provided reasonable assurance on a selected subset of sustainability information, while the broader Group Sustainability Statement around it received only limited assurance, an intentional two-speed structure rather than an inconsistency.
Key takeaway: the difference isn't a formality. Limited assurance is a practitioner saying nothing looked wrong when they checked; reasonable assurance is a practitioner saying they actively tested the data and it held up. Most companies, even large, sophisticated ones, are still only doing the former.
Who Is Actually Allowed to Provide Assurance, and Why It's Often Not Who You'd Expect

There's a common assumption that ESG assurance comes from "the auditors," meaning a company's existing Big Four financial statement auditor. Sometimes that's exactly right: KPMG Canada, TC Energy's own statutory auditor, provided its GHG assurance; PwC did the same for Macquarie Group; EY did the same for BSI Group; BDO did the same for SAP. There's a practical logic to this pattern: the financial auditor already has deep knowledge of the company's internal controls and reporting systems, and can often extend existing audit relationships and independence structures to cover sustainability data at lower incremental cost.
But it's just as common, and completely legitimate, for assurance to come from a specialized, non-audit verification body instead. AT&T's carbon footprint assurance was performed by ERM CVS, Environmental Resources Management's dedicated certification and verification arm, not a Big Four firm at all. Firms like ERM CVS, DNV, Bureau Veritas, SGS, and TÜV built their core business on environmental and technical verification long before ESG reporting existed, and many companies view that specialist technical background, particularly for complex Scope 3 supply chain emissions or industry-specific metrics, as a better fit than a generalist financial auditor. Under CSRD specifically, EU member states are permitted to authorize these kinds of Independent Assurance Services Providers (IASPs) to perform statutory sustainability assurance alongside, or instead of, traditional statutory auditors, a deliberate regulatory choice to keep the assurance market from becoming a Big Four monopoly.
Key takeaway: a Big Four name on an assurance statement reflects an efficient use of an existing audit relationship, not a superior or more rigorous form of assurance. A specialist verifier's opinion, built on deep technical environmental expertise, can be just as rigorous, sometimes more so for technical subject matter like emissions factor methodology.
What a "Big Four Sign-Off" Does and Doesn't Mean

This is where reading the fine print pays off directly. Every one of the five real assurance statements referenced in this article makes a point of narrowing its own scope, explicitly and in writing:
BSI Group's EY report covers only the specific metrics marked with an asterisk in the report; EY states directly that it does not express any opinion or conclusion on any other information in the document.
TC Energy's KPMG report marks assured figures with a caret symbol, and separately discloses that TC Energy's Scope 2 emissions were not calculated using a market-based method, and that no environmental instruments such as renewable energy certificates were assured, because they simply weren't part of what TC Energy submitted for assurance.
Macquarie Group's PwC report states explicitly that the assurance scope did not include performing procedures over the underlying data Macquarie received from third parties, meaning the reliability of that upstream data is, by PwC's own account, outside what was checked.
AT&T's ERM CVS report is scoped narrowly to AT&T's US carbon footprint specifically, not the company's full global sustainability disclosure.
SAP's BDO engagement applies reasonable assurance to some figures and limited assurance to the rest of the same statement, a split that's easy to miss unless a reader notices the two separate conclusion levels printed side by side.
The pattern across all five: a signature from a major firm, even a reasonable assurance conclusion, almost never covers "the whole report." It covers a specifically defined subject matter, checked against specifically defined criteria (usually the GHG Protocol for emissions figures), and every one of these real statements says so in writing, usually within the first few paragraphs.
Key takeaway: "assured by [Big Four firm]" is not a blanket stamp of truth on a report. The actual coverage is almost always narrower than a first glance suggests, and the honest version of that limitation is written directly into the statement itself, not hidden.
The Standard That's About to Change Everything: ISSA 5000

Every assurance statement discussed so far was built on ISAE 3000 (Revised), a general-purpose standard originally designed to cover any non-financial assurance engagement, sustainability included. That's about to shift. In September 2024, the IAASB approved ISSA 5000, General Requirements for Sustainability Assurance Engagements, the first assurance standard purpose-built specifically for sustainability reporting rather than adapted from a general framework. It becomes effective for periods beginning on or after 15 December 2026, and the IAASB and major accounting networks widely expect it to become the global baseline for sustainability assurance, gradually replacing ISAE 3000 in that role.
ISSA 5000 tightens several things that matter directly to a reader. It elevates a specific statement, previously buried in the body of a limited assurance report, explaining that limited assurance procedures are less extensive than reasonable assurance procedures, up into the basis-for-conclusion section where it's harder to miss. For listed companies specifically, it now requires the individual engagement leader's name to appear in the assurance report, mirroring a rule that already applies to financial statement audits, so a reader can identify exactly who signed off, not just which firm.
Key takeaway: the rules governing what an assurance statement has to disclose are actively getting stricter, not looser. A report assured under ISSA 5000 from 2027 onward should be genuinely easier for an outside reader to interpret than one assured under the older, more general ISAE 3000 language.
The Regulatory Patchwork: Who's Actually Required to Get Assurance, and When

This part varies enormously by jurisdiction, and it's worth being precise, since the rules are moving quickly in more than one direction at once.
In the EU, CSRD makes assurance mandatory for companies within its scope, starting at limited assurance, with the European Commission's own stated direction of travel toward reasonable assurance sometime in the early 2030s, a timeline that, like much of CSRD, has been affected by the 2026 Omnibus simplification covered elsewhere in this series.
In the United States, at the federal level, there currently is no mandatory assurance requirement at all. The SEC's 2024 climate disclosure rule, which would eventually have phased in limited and then reasonable assurance for large filers, was never actually implemented: the Commission voted in March 2025 to stop defending the rule in ongoing litigation, and in 2026 formally proposed to rescind the climate disclosure rules in their entirety, citing concerns that they exceeded the agency's statutory authority. Barring a reversal, US public companies should not expect an SEC-driven assurance mandate.
That federal vacuum is being filled at the state level. California's SB 253 requires large companies doing business in the state, generally those over $1 billion in annual revenue, to report Scope 1 and 2 emissions starting in 2026, with Scope 3 following in 2027. Assurance wasn't required for the very first 2026 submissions, but limited assurance phases in for subsequent years, with reasonable assurance required by 2030, an independent state-level track that continues to apply to large US companies regardless of what happens federally.
Key takeaway: whether a company is legally required to obtain assurance, and at what level, depends entirely on where it operates and which specific law applies, not on some single global standard. A US company with no EU exposure and under California's revenue threshold may currently face no binding assurance mandate at all, which is exactly why voluntary assurance choices, like AT&T's or SAP's, are still worth reading closely rather than assumed to be equivalent to a compliance requirement.
How to Read an Assurance Statement Like You Know What You're Looking For
Find the word "limited" or "reasonable" in the first paragraph. It's almost always stated explicitly, and it changes what the rest of the statement actually means.
Look for the scope marker. Real reports mark exactly which figures were assured, an asterisk in BSI Group's report, a caret symbol in TC Energy's. If a report doesn't clearly mark which numbers were checked, that's a real gap worth noticing.
Check who signed it. A Big Four name signals an existing audit relationship extended to sustainability data. A specialist name like ERM CVS, DNV, Bureau Veritas, or SGS signals deep technical environmental expertise instead. Neither is automatically stronger; both are legitimate, and worth knowing which one you're reading.
Read the exclusions, not just the conclusion. The most useful sentence in Macquarie's PwC report isn't the conclusion, it's the specific line stating that underlying third-party data wasn't independently tested. That kind of disclosed limitation is far more informative than the headline opinion.
Check the criteria, not just the standard. Almost every emissions assurance statement in this article names the GHG Protocol as its criteria. If a report's assurance statement doesn't name its criteria at all, that's a meaningfully weaker disclosure than one that does.

References
International Auditing and Assurance Standards Board (IAASB), ISAE 3000 (Revised): Assurance Engagements Other than Audits or Reviews of Historical Financial Information
IAASB, ISSA 5000: General Requirements for Sustainability Assurance Engagements, approved September 2024, effective for periods beginning on or after 15 December 2026
IAASB / IFAC, Non-Authoritative Guidance on Applying ISAE 3000 (Revised) to Extended External Reporting (EER) Assurance Engagements, April 2021
Center for Audit Quality, S&P 500 Companies' Sustainability Reporting and Assurance Practices, 2025
US Securities and Exchange Commission, Proposed Rescission of Climate-Related Disclosure Rules, Federal Register, 2026
California Senate Bill 253 (Climate Corporate Data Accountability Act) and Senate Bill 261, as amended
EY, Independent Limited Assurance Report to BSI Group, GHG Emissions, FY2025
KPMG LLP (Canada), Independent Practitioner's Limited Assurance Report to TC Energy, 2025 Report on Sustainability
PwC, Independent Assurance Report to Macquarie Group Limited, FY2025 Basis of Preparation for Sustainability Reporting
ERM Certification & Verification Services (ERM CVS), Independent Limited Assurance Report to AT&T Inc., 2024 data
BDO, Assurance Reports on the SAP Group Sustainability Statement, FY2025




Comments