Auditing Sustainability Reporting: What Requires Limited Assurance
The sustainability report prepared in accordance with the Corporate Sustainability Reporting Directive (CSRD) is subject to an audit. Unlike with annual financial statements, however, many companies are unclear about what this audit actually entails, who is authorized to conduct it, and what factors influence it in practice. The Omnibus Package also makes one thing clear: the previously announced tightening of requirements to an audit providing reasonable assurance will not take effect. In this article, you’ll learn which rules apply today, what auditors require, and which preparatory steps yield the greatest returns.
As of August 2026. The information is based on Directive (EU) 2026/470 and the status of the German implementation process as of August 2026. For details on the scope and timeline of the CSRD as a whole, please see our article on the CSRD Implementation Act.
The audit will continue to be conducted with limited assurance
The CSRD originally called for a phased approach: first, an audit providing limited assurance, followed by a transition to an audit providing reasonable assurance. To this end, the European Commission was to develop its own standards by October 1, 2028.
This level has been eliminated. Directive (EU) 2026/470 explicitly justifies this in Recital 5 by stating that companies should not incur higher audit costs. The Commission’s obligation to issue standards for reasonable audit assurance has been completely removed. Limited assurance will therefore remain in place in the long term.
At the same time, the timeline for the binding European examination standards has been pushed back. The Commission was originally supposed to develop them by October 1, 2026; the deadline is now July 1, 2027. Until then, the Member States’ national examination standards will apply.
Limited assurance means fewer audit procedures and a differently worded opinion
The difference from a financial statement audit is not a matter of degree, but rather one of structure. When seeking reasonable assurance, auditors perform extensive audit procedures, including an assessment of the internal control system and case-by-case tests of specific assertions. When seeking limited assurance, the scope of the work is narrower and more specifically targeted at areas where errors are likely to occur.
This is reflected in the audit opinion. It is phrased in the negative: The auditors state that nothing has come to their attention that would lead them to believe that the sustainability statement was not prepared, in all material respects, in accordance with the European Sustainability Reporting Standards (ESRS). There is no positive opinion here, as is included in the auditor’s report on the annual financial statements.
However, this wording is adjusted if the audit uncovers any issues. Possible outcomes include a qualified opinion in the case of non-pervasive errors, an adverse opinion in the case of pervasive errors, and a refusal to issue an opinion if the scope of the audit was impermissibly limited. A limited-assurance engagement is therefore not a mere formality with a guaranteed outcome.
Four sub-areas are under scrutiny
The scope of the audit is broader than the term “sustainability report” might suggest. According to the Accounting Directive as amended by the CSRD (Article 34(1), second subparagraph, letter aa of Directive 2013/34/EU), the audit opinion covers four points:
- The consistency of the reporting with the requirements of the Directive, including compliance with the ESRS.
- The process the company used to determine the information to be reported, particularly the derivation of the dual materiality analysis—and not just its result.
- Compliance with the mandatory tagging requirements in the standardized electronic reporting format. Our article on ESRS-xBRL tagging explains what this means from a technical perspective.
- Compliance with the disclosure requirements under Article 8 of the EU Taxonomy Regulation.
The second point is regularly underestimated in projects. The focus is not on whether your materiality assessment is the only reasonable one, but rather on whether the process leading to that assessment is documented in a transparent manner.
Examiners follow the CEAOB guidelines to ensure compliance with EU standards
For the transitional period leading up to the final auditing standards, the Committee of European Auditing Oversight Bodies (CEAOB) published non-binding guidelines on limited assurance engagements on September 30, 2024. These guidelines are expressly non-binding and do not supersede national pronouncements. Nevertheless, they are the most useful resource for preparation because they describe where auditors should begin. Five points from these guidelines are directly relevant to companies:
- The auditor’s materiality is not the same as your materiality. The guidelines make it clear that the two terms are related but not identical. Reviewers assess whether a false statement could influence the decisions of the intended audience.
- Understanding the process takes precedence over examining individual cases. Auditors gain an understanding of the entity, its environment, and the controls relevant to the reporting. Substance tests and tests of functions are not required, but may be performed if they appear to be effective.
- Forward-looking statements are reviewed using this method. Targets, transition plans, and scenarios are not evaluated based on whether they will be achieved, but rather on whether the underlying methodology is applied appropriately and consistently.
- Estimates require a well-founded method. For estimates, the guidelines do not require a detailed review, but they do require a critical assessment of the procedure.
- Data from the value chain is part of the audit. Auditors evaluate how you collect this data and how reliable it is. The guidelines do not require external verification of the data by your business partners.
The last point pertains to a new provision in the Omnibus Package. There is now a cap on the amount of information you are permitted to request from smaller companies in your value chain. Your record-keeping must therefore make do with what can be collected within this limit. This makes it all the more important to clearly describe the origin and scope of this data.
In Germany, auditors conduct audits, and the audit process is now regulated differently
The government’s draft of the CSRD Implementation Act provides for specific provisions regarding audits in the German Commercial Code. These provisions are set forth in §§ 324b et seq. of the proposed Commercial Code (HGB-E), alongside the provisions on the audit of financial statements, with § 324b HGB-E addressing the audit requirement and § 324c HGB-E addressing the subject matter and scope of the audit.
Only a certified public accountant or an auditing firm may perform the audit. This may be the same auditor who prepared the financial statements, but it does not have to be: the draft allows for the appointment of a different certified public accountant. Independent providers of assurance services, such as environmental verifiers, are excluded under the government’s draft; the possibility of opening this up in the future will be examined. In addition, there is a qualification requirement: Anyone who audits sustainability reports must register with the Chamber of Public Accountants as an auditor of sustainability reports and provide proof of the required continuing education.
In practice, this means two things. First, the pool of auditors is smaller than for the financial statement audit, which is relevant for scheduling. Second, the decision on whether the financial statement auditor and the sustainability auditor should be the same person must be made early on: A separate auditor requires its own access to your data and its own coordination processes. Accordingly, our recommendation here is to engage the financial statement auditor to also serve as the sustainability auditor.
Important: The CSRD Implementation Act has not yet been enacted as of August 2026. The provisions cited are in draft form.
What the initial tests have shown
The study by DRSC and Deloitte from November 2025, which analyzed 77 reports from German DAX, MDAX, and SDAX companies for the 2024 fiscal year, provides reliable practical data:
- About 73% of the reports were audited with limited assurance, and one report was audited with reasonable assurance.
- For just under 20%, an audit providing reasonable assurance was also performed on certain items.
- Six reports—about 8%—were not audited.
- All audits were conducted by certified public accountants and resulted in unqualified audit opinions.
Context: As of the 2024 fiscal year, there was still no legal requirement in Germany for audits of ESRS reports. The audits were conducted on a voluntary basis, typically by companies with well-established reporting processes. The fact that all audit opinions were unqualified does not, therefore, indicate that the audit is easy to pass.
In our article on CSRD reports in practice, we’ve outlined the factors that determine the quality of reporting in these same analyses. The weaknesses mentioned there are also the typical points of discussion during an audit: a lack of objectives for material topics, vague descriptions of impacts, risks, and opportunities, and an imprecisely defined value chain.
What Pays Off the Most Before the First Exam
The limited-assurance audit rewards preparation in one specific area: traceability, not wording. Based on our project experience, five points are the most effective:
Document the source of each number. For each data point, the source, responsible unit, collection method, and reference date should be documented. This is the documentation that auditors request first.
Document the process used to arrive at the materiality analysis. Stakeholders, criteria, thresholds, assessment results, and decisions should be included in a comprehensive documentation, even if they are not included in the report. Our overview of ESRS sustainability topics outlines which topics are generally relevant.
Justify your estimates before you are asked to do so. Whenever you work with factors, projections, or approximations, the methodology, data sources, and range should be included in the documentation.
Describe the scope of your value chain data. Which levels are included, which are not, and which information is based on secondary data. A disclosed limit can be verified; an unstated one cannot.
Plan the exam as a separate project. Auditor selection, appointment, interim results, and system access all require their own deadlines. The sustainability report is included in the management report and therefore follows the timeline for the preparation of the financial statements.
Audit-Ready Sustainability Reporting with CONSUST
The audit hinges on the source of the data, not the text itself. This is precisely where our FramesCube CSRD/ESRS software comes in: It collects data across all companies, records the source, responsible party, and date for each value, and documents the dual materiality analysis in an audit-proof manner. You retain control over the substantive decisions; the audit trail is generated as the process unfolds and does not need to be reconstructed before the audit.
You can find the complete roadmap leading up to the first report in our white paper , “Implementing CSRD Safely: Four Phases to the First Report for 2027.” Contact us for a no-obligation consultation to prepare for your audit.
This article presents a professional assessment based on the sources cited, as of August 2026, and is not a substitute for a legal review of a specific case.
