←
AI for ESG & Sustainability Reporting
Strategic · M14 · lesson 14 of 23 · queued
Preview — browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll →
Managing the External Assurer Relationship
📖
now learning

Managing the External Assurer Relationship

15 min

The first time a disclosure lead meets the external assurance team is the worst possible moment to discover what they are going to ask. By then the report is half drafted, the supplier data is partly in, and an AI tool has produced narrative the team has not fully traced. The assurer opens with a quiet, devastating question: walk me through how this Scope 3 figure was built. If the answer is improvised, the engagement has already gone wrong. The professionals who never get surprised by an assurer are the ones who run the relationship as a managed, year-round process: agree the scope early, host the walkthroughs on their terms, and close every finding before it hardens. This lesson is about running the external assurer relationship so the engagement confirms what you already know, rather than exposing what you did not.

Why the Assurer Relationship Is the Job, Not a Formality

Assurance is the spine of modern sustainability disclosure. IFAC and AICPA & CIMA report that 73% of large global companies now obtain external assurance on at least some sustainability disclosures, up from 51% in 2019, and GHG emissions are the most-assured category. That means every disclosed figure is now an audited figure, read by an independent professional whose job is to test whether it is supported. The reporting team that treats the assurer as a box-ticking visitor at the end of the cycle has misunderstood the regime. The assurer is the reader who decides whether your numbers can stand, and managing that relationship well is one of the highest-leverage things a reporting strategist does.

The relationship is also where AI-assisted work meets its real test. The team can draft, extract, and compute at speed, but none of that matters if the assurer cannot follow each number to its evidence. So the assurer relationship is not separate from the AI strategy; it is the proving ground for it. A workflow that produces a traceable file makes the engagement smooth, and a workflow that produces fast but unsupported output makes the engagement a series of findings. The strategist's aim is to design the relationship so that the assurer's tests confirm the team's own controls rather than catching their absence.

Limited Versus Reasonable Assurance: What Each Expects

The first thing a strategist must hold precisely is the difference between the two levels of assurance, because they set the bar for everything else. Limited assurance, the level most sustainability engagements operate at today, produces a conclusion expressed in the negative: based on the procedures performed, nothing has come to the assurer's attention that causes them to believe the information is materially misstated. The assurer's procedures are narrower, weighted toward inquiry and analytical review, and the evidence threshold is lower than for a full audit. Reasonable assurance, the level financial-statement audits use and the level sustainability assurance is trending toward, produces a positive conclusion: in the assurer's opinion, the information is fairly stated. It requires more extensive, deeper testing and a higher evidence threshold.

The practical consequence for the reporting team is that the level sets how hard the file gets tested. Under limited assurance the assurer leans on inquiry and analytical procedures, asking how a number was produced and whether it moves plausibly against the prior period and against expectations. Under reasonable assurance the assurer reperforms more, samples more, and traces more individual numbers back to source. A strategist preparing for a likely future move from limited to reasonable assurance does not wait to be told; they build the file to reasonable-assurance standards now, because a file that can survive reperformance can always survive inquiry, but not the reverse. The direction of travel is one way, and building ahead of it is cheaper than scrambling behind it.

An assurer does not need you to be perfect. They need you to be reconstructable. The number you can rebuild without them in the room is the number that survives the engagement.

What the Assurer Actually Tests

A strategist manages the relationship better by understanding what the assurer is actually doing, because most of the anxiety in an engagement comes from not knowing what is being looked for. The assurer is testing three things. First, existence and accuracy: does the number reflect something real, and is it computed correctly? For an emissions figure that means tracing activity data to a source and a factor to a database and checking the arithmetic. Second, completeness: is anything missing that should be there, such as a Scope 3 category quietly excluded or a facility left out of the boundary? Completeness is where undocumented exclusions surface. Third, presentation and disclosure: does the report describe the numbers honestly, including the estimates, the uncertainties, and the methods, without overstating progress or softening a negative impact? Greenwashing findings live in this third category, where an AI-drafted narrative is most likely to have smoothed an inconvenient truth.

Knowing these three lenses lets the team prepare the file the assurer will actually read rather than the file they imagine. Existence and accuracy are served by provenance on every datapoint. Completeness is served by a documented boundary that lists exclusions with reasons. Presentation is served by linking every narrative claim back to evidence and by labeling every estimate as an estimate. A team that has built for these three lenses walks into the engagement with the answers already assembled, which is the entire point of running the relationship as a managed process rather than reacting to each request as it arrives.

Scoping the Engagement Early

Scoping is where the engagement is won or lost, and it happens months before any testing. Scoping defines what is covered, which disclosures and which datapoints fall inside the assurance opinion, at which level, against which criteria, and on which timeline. A strategist drives this conversation rather than receiving it. The aim is to remove ambiguity before it becomes a dispute: agree which Scope 3 categories are in scope, agree the materiality threshold the assurer will apply, agree the reporting boundary, and agree the criteria, meaning the standards and the basis of preparation against which the numbers will be judged.

Two scoping moves matter most. The first is agreeing the materiality threshold early, because it determines which differences the assurer will care about and therefore where the team must concentrate its evidence. The second is surfacing the hard areas yourself. If a Scope 3 category rests heavily on estimates, say so in scoping and agree how it will be assured, rather than letting the assurer discover the estimation mid-engagement and treat it as a surprise. Surfacing your own weak points is counterintuitive but powerful: it converts a potential finding into a planned, agreed treatment, and it builds the credibility that makes the rest of the engagement run on trust.

The Walkthrough: Showing Your Working

The walkthrough is the moment the assurer asks the team to trace a transaction or a number from start to finish: where did the activity data come from, which emission factor was applied and from which source, what method tied them together, who reviewed it, and how did it reach the disclosure. Walkthroughs test whether the controls the team claims to have actually operate. A strategist prepares for walkthroughs by making sure that for any number the assurer might pick, the team can show the lineage end to end without improvising. This is exactly what a provenance-tagged workflow and a basis of preparation are for: they turn the walkthrough from an interrogation into a guided tour.

The walkthrough is also where AI-assisted work is explained to the assurer, and how you explain it matters enormously. The wrong explanation is "the AI generated this." That answer fails, because it locates the source of the number in a model, and a model is not evidence. The right explanation locates AI as a tool inside a controlled process: the model helped extract the activity data from the supplier file, here is the source document and the extracted value side by side; the model proposed the emission factor, here is the named, dated database the factor was verified against; the model drafted the narrative, here is the evidence each claim was checked against and the named reviewer who signed it. AI is presented as an accelerator whose every output was verified by a human against evidence, never as the authority behind the number. An assurer can get comfortable with AI used that way. They cannot get comfortable with a number whose only provenance is a model.

The Findings Loop: Closing Before It Hardens

A finding is the assurer's identification of an issue: a number they cannot support, a control that does not operate as described, an estimate that is undisclosed, a claim with no evidence. The difference between a well-run and a badly-run engagement is almost entirely in how findings are handled. The findings loop is the disciplined cycle of receiving a finding, understanding precisely what the assurer is concerned about, remediating it with real evidence or a corrected number, and confirming closure with the assurer, all logged. The strategist runs this loop actively, treating each finding as a defined task with an owner and a deadline, not as a vague worry to be resolved later.

The cardinal discipline is to close findings before they harden into the assurer's report. A finding raised during fieldwork and remediated promptly is a normal part of an engagement. The same finding unaddressed until the end becomes a qualification or a modified conclusion, which is a public signal that something in the disclosure could not be supported. So the strategist front-loads: encourages the assurer to raise concerns early, keeps a live findings log visible to both sides, and resolves issues while there is still time to gather the evidence. A finding about an AI-drafted target, for instance, is closed by producing the board minutes that show the target was actually set, or by correcting the disclosure if it was not, and that closure is far easier in week three of fieldwork than in the final week before sign-off.

The findings log is more than a tracker; it is itself evidence of a functioning control environment, and a sophisticated assurer reads it that way. A team that detects, owns, remediates, and confirms closure of its own issues systematically is demonstrating that controls operate, which raises the assurer's confidence in the parts of the report they have not yet tested. A team with no findings log and a stack of unresolved verbal concerns is demonstrating the opposite. So the strategist treats the log not as an admission of imperfection but as a working artifact that, run well, makes the whole engagement more efficient because it shows the machine working. Each entry carries an owner, a clear statement of the concern, the remediation, the evidence, and the confirmed closure, and the log is reviewed jointly on a cadence rather than sprung at the end.

Independence and the Boundary of the Relationship

Managing the assurer relationship well does not mean making the assurer comfortable at the expense of their independence, and a strategist must hold that line carefully. The assurer's value comes precisely from their independence; a cosy relationship that discourages hard questions produces an opinion not worth having and a disclosure not actually tested. So the goal is a relationship that is collaborative on process and rigorous on substance: the team makes the assurer's job easy by being transparent, organized, and reconstructable, and in return the assurer does their testing properly. The strategist does not lobby to soften a finding that is correct; they remediate the underlying issue. The trust being built is trust that the team will surface its own problems and fix them, not trust that the assurer will look away. That distinction is what keeps the relationship defensible if a regulator ever reviews the engagement.

Worked Example: The Walkthrough That Did Not Surprise

Two reporting teams face the same assurer asking the same question about the same Scope 3 freight figure. Watch the first team. The assurer asks how the figure was built. The lead says an AI tool calculated the freight emissions from the logistics data. The assurer asks to see the activity data behind it; the team produces a spreadsheet, but the tonne-kilometre values do not obviously tie to any source document, and the emission factor used has no recorded source. The assurer asks whether the figure is primary or estimated; nobody is certain. Within an hour the engagement has three open findings and a tone of suspicion, and the team spends the next month reconstructing provenance after the fact, which is the exact thing an assurer distrusts most.

Now the second team. The same question lands. The lead opens the file and walks the assurer through it: here is the carrier's reported tonne-kilometre data, tagged primary, with the source document and the page it came from; here is the emission factor, with its database, version, and identifier; here is the calculation, activity data times factor; here is the analyst who reviewed it and the date; and here, in the basis of preparation, is the method and the rule that says how primary and secondary freight data are treated. The AI's role is explained cleanly: the model extracted the carrier data, and here is the extracted value beside the source; the model suggested the factor, and here is the verification against the named database. The assurer tests two more numbers at random and finds the same structure. No finding is raised on the freight figure, because there is nothing to find. The walkthrough confirmed the team's controls instead of exposing their absence, and the difference between the two teams was not the AI tools, which were identical. It was that the second team ran the assurer relationship as a managed process and built a file designed to be walked through.

Key Takeaways

  • Assurance is the spine of the regime: 73% of large global companies now obtain external assurance on at least some sustainability disclosures, up from 51% in 2019, with GHG emissions the most-assured category, so every disclosed figure is an audited figure.
  • Run the assurer relationship as a managed, year-round process so the engagement confirms what you already know rather than exposing what you did not.
  • Know the difference between limited assurance (a negative conclusion, narrower inquiry-and-analytical procedures) and reasonable assurance (a positive opinion, deeper reperformance and sampling), and build the file to reasonable-assurance standards because the direction of travel is one way.
  • Scope the engagement early: agree the in-scope datapoints, the materiality threshold, the boundary, and the criteria, and surface your own hard areas so a potential finding becomes a planned, agreed treatment.
  • Prepare for walkthroughs by making every number reconstructable end to end without improvising; a provenance-tagged workflow and a basis of preparation turn an interrogation into a guided tour.
  • Explain AI as a tool inside a controlled process: the model extracted, proposed, or drafted, and a named human verified each output against evidence; never present a number whose only provenance is a model.
  • Run the findings loop actively: receive, understand, remediate with evidence, and confirm closure, all logged, and close findings before they harden into a qualification or modified conclusion.
  • Understand the three lenses the assurer tests through, existence and accuracy, completeness, and presentation and disclosure, and build the file so each lens finds its answer already assembled.
  • Keep the relationship collaborative on process and rigorous on substance: make the assurer's job easy by being transparent and reconstructable, but never lobby to soften a correct finding, because the assurer's independence is the source of the opinion's value.
  • The professionals who never get surprised are not the ones with the best AI tools; they are the ones who run the relationship and build a file designed to be walked through.