Introduction
Owing to an increasing awareness around climate change and greenhouse gas emissions, ESG disclosures have emerged to be one of the top priorities for business leaders worldwide. Sustainability has become an essential consideration for businesses, with investor, customer, and other stakeholder expectations evolving around
business performance and impacts. Stakeholders, both internal and external, expect transparency around how businesses operate, and are also interested in understanding business impacts on society in addition to financial impacts on companies.
Key contributors to this growing impetus are maturing sustainability regulations and ratings. Globally, policy makers are focusing on developing sustainability disclosure regimes, which necessitate reporting of sustainability information and data. ESG data reflects the non-financial performance of an organization, and includes resource utilization, energy, water, materials, waste, carbon emissions, human capital management, employee health and safety, community engagement, and more.
Furthermore, stakeholders, investors, and policy makers demand comparable and veritable ESG information to inform financial and other decisions.
Therefore, authenticity, uniformity, and auditability of ESG data have become key concerns when the data is published publicly in sustainability or annual reports. For example, ESG ratings agencies pick this data for presenting ratings across sectors along with key risks for organizations. Having a robust sustainability framework and strategy in place, accompanied with an evidence-based approach on how to measure key performance indicators, is thus necessary to meet growing stakeholder expectations.
Uniformity to transform sustainability reporting
In the recent years, there has been an increase in demand from internal and external stakeholders for more transparent, consistent, and comparable disclosures on
non-financial reporting parameters from organizations. Given the significance of sustainability disclosures, trust in what is being reported is of paramount importance. Regulators across the world are also demanding a level of rigour in non-financial reporting which meets that of standards set for financial reporting.
To enable consistency and comparability in non-financial reporting, standards setters and regulators in various jurisdictions have recently issued proposals on disclosures relating to sustainability. Notable among these are:
1. The IFRS Sustainability Standards:
IFRS S1 General Requirements for Disclosure of Sustainability-related Financial Information and IFRS S2 Climate-related Disclosures issued by the International Sustainability Standards Board (ISSB).
2. The IFRS Sustainability Standards:
12 standards which provide a comprehensive reporting framework for a full range of sustainability issues under the EU Corporate Sustainability Reporting Directive (CSRD).
The U.S. SEC’s proposed rule, ‘The Enhancement and Standardization of Climate-Related Disclosures for Investors’.
These standards and proposals will more closely intertwine financial and non-financial reporting, assisting investors and other stakeholders in identifying sustainability-related risk and opportunities embedded within companies in which they have financial or other interests. Further, the multitude of frameworks and standards are likely to converge as they are more widely implemented by businesses and investors, which will help broader comparability of sustainability reporting between companies in various jurisdictions – a long-standing need expressed by various stakeholders.
Case for reporting rigour on non-financial information in sustainability reporting
Unlike financial reporting, non-financial information in sustainability reporting is an evolving area of interest. The drivers of non-financial data also present some unique challenges:
- Stakeholder expansion
- Voluntary reporting ecosystem
- Acceleration toward regulation
- Unique data management needs
- Talent availability and competence
- Lack of evolved information technology solutions
- Use of third-party data
- Demands for external assurance
ll these factors necessitate companies to equip themselves for a robust adoption of sustainability standards by establishing a strong governance structure which includes processes and controls over the integrity of non-financial data, akin to those widely adopted to govern corporate financial reporting. Within the United States, businesses widely utilize the ‘Internal Control – Integrated Framework’ (ICIF) published by the Committee of Sponsoring Organizations of the Treadway Commission (COSO) to design, implement, and evaluate systems of control over corporate financial reporting. In March 2023, COSO issued a supplementary guidance, entitled ‘Achieving Effective Internal Control Over Sustainable Reporting (ICSR): Building Trust and Confidence through the COSO Internal Control – Integrated Framework’. This new guidance is based on the widely utilized ICIF, and offers a systematic, consistent framework for achieving internal control over ESG-related business activities and reporting. Although the COSO framework is most applicable to companies domiciled or listed in the US, ICSR, and therefore ICIF represents the most comprehensive framework on systems of control over sustainability reporting which can be adopted by companies across the globe.
Introduction to the Internal Control – Integrated Framework (ICIF)
While large organizations have made some progress in developing an internal control framework for non-financial information that forms part of sustainability reporting, most companies have yet to develop a rigorous internal control framework that meets the standards set for financial reporting. In order to implement the ICIF, one must first understand its processes. The figure provides a useful illustration on how an internal control framework can be developed for sustainability reporting.
Internal control is a process, effected by an entity’s board of directors, management, and other personnel, designed to provide reasonable assurance regarding the achievement of objectives relating to operations, reporting, and compliance.
Uniqus’ point of view
Standardized Data Collation Templates:
Organizations can prepare or identify standardized data collation templates and indicator calculators that are consistent with the requirements of applicable legislations and standards.
Process Documents:
Organizations can develop process documents and risk control matrices to enable testing of processes and controls, including IT controls.
Technology Platform:
There are several technology solutions available in the market (e.g., Uniqus’ ESG UniVerse) which can enable central collation, automation, and verification of KPIs from a warehouse of reporting standards and legislations.
Third-Party Expertise:
Management teams and the board of directors can better prepare for disclosures by engaging third party partners and consultancies to help understand disclosure requirements.
Sustainability assurance
In the past fifteen years, as the importance of sustainability issues has grown steadily, stakeholders have gradually demanded increasing levels of transparency and accountability from companies. To meet these requirements, many organizations have started conducting voluntarily assurance for the sustainability data being published in their reports. There have been two types of assurances: limited and reasonable assurances. These are provided by an external assurance provider.
In the United States, the AICPA standards that apply include AT-C 105 Concepts Common to All Attestation Engagements, AT-C 210 Review Engagements, and AT-C 205 Assertion- Based Examination Engagements. In Europe and internationally, the relevant standards are the International Auditing and Assurance Standards Board’s International Standard on Assurance Engagements (ISAE) 3000.
According to “The State of Sustainability Reporting and Information Assurance”, a report co-authored by the International Federation of Accountants (IFAC), AICPA, and CIMA, there has been a notable increase in the number of companies looking to obtain sustainability assurance all around the world. This change signifies a broader
recognition of the importance of ESG metrics and the need for reliability in sustainability reporting. The percentage of companies opting for external assurance is gradually increasing. As companies prepare for sustainability assurance, developing a robust internal control framework on reporting of sustainability-related information will support them in effectively completing external audits.
Limited Assurance:
Limited assurance is often chosen when the risk of material misstatement in the reported data is relatively low and achieving a higher level of assurance would be too costly or impractical. As part of a limited assurance assignment, the auditor performs a limited range of testing. This may involve evaluating key data points, performing selective testing and reviewing relevant literature. Despite these limitations, limited assurance can still enhance the reliability of reported data and give stakeholders some assurance that the data is free of material misstatement, although the degree of certainty is less than that of reasonable assurance.
Reasonable Assurance:
Reasonable assurance represents the highest degree of reliability and goodwill achievable through an undertaking of assurance. Companies choose reasonable assurance audits when there is a higher risk of material misstatement of the reported information and stakeholders require a more thorough and rigorous data review. This level of assurance includes an in-depth and comprehensive review of financial or non-financial data. As part of a reasonable assurance audit, the auditor performs extensive testing, including detailed testing of controls, verification of data, and full consideration of underlying assumptions and methods used to compute the data. Reasonable assurance provides stakeholders with a greater degree of certainty about the reliability of the data being audited.
How to be ESG Assurance-Ready: Uniqus Recommendations
Control environment:
- Embed elements of sustainability reporting into the existing internal control framework and policies of an organization
- Prepare a framework for interacting with external owners of ESG data and information relevant to your own organization, and establish protocols for how that data should be generated and provided
- Review the scope and remit of internal audit to cover prioritized elements of sustainability reporting
- Educate and equip the Board of Directors on various sustainability reporting elements and recent developments
Risk assessment:
- Incorporate non-financial risks, especially those aligned with applicable reporting standards, into the enterprise risk management framework
- Identify the potential risk factors on non-financial reporting (e.g., fraud) and embed them in the risk assessment
- Identify additional entity-level risks emanating from sustainability topics, in particular risks relating to third-party data and forward looking statements
- Conclude with the internal and external auditors on risks to be evaluated on estimates and judgments
Control activities:
- Document the process for obtaining non-financial information from the organization on the lines of process flows for financial information
- Document additional non-financial controls in the risk control matrices
- Identify both IT general controls and application-level controls on the various tools, technology products, and workflows used for collating and reporting non-financial information
- Give careful consideration to the control attributes for non-financial reporting, such as segregation of duties, skills and competence of control owners
Communications and monitoring:
- Develop controls over internal and external communications on non-financial reporting
- Implement a due diligence and integrity check process by management and the board of directors
- Maintain a process over evaluating the work performed by internal and external auditors – with the remit of the audit committee to be amended to include non-financial information
- Evaluate the remediation plan and action taken reports by internal audits based on materiality
- Ensure a process for the evaluation of control deficiencies and modifications by external auditors
Conclusion
In conclusion, now more than ever, companies must address growing demands – from regulators, standards setters, investors, and other stakeholders – for veritable, comprehensive information on sustainability-related risks and opportunities relevant to their businesses. In particular, many reporting regimes in major market jurisdictions are recommending or requiring assurance of non-financial data to give users of such information more confidence. In order to be assurance ready, companies seeking
to report on ESG should develop an internal controls framework aligned with best practices, such as the ICIF model.
Companies should develop processes for the auditable collation of sustainable business information, bringing the rigor of accounting and financial reporting to their ESG reporting needs.
Annexure
The ICIF is comprised of five components. Entailed below is more detail around these components and the accompanying principles organizations can implement to embody the internal control framework. More, specifically, an organization which employs an ICIF:
Component 1
Demonstrates commitment to integrity and ethical values – all organizations have a set of values and purpose to which they subscribe. These reflect the ethos of the organization, and no longer point only towards maximizing shareholder return. Companies are making commitments to sustainability as part of their organizational purpose. A company demonstrates its commitment to sustainability by effectively • Setting the tone at the top – thereby ensuring congruence of goals between senior leadership and rest of the organization. • Establishing and adhering to standards of conduct – by establishing standards of conduct (e.g., anti-bribery and corruption policy) as well as building systems or processes to assess and monitor compliance with those standards. • Dealing with outliers – by adopting an unyielding approach to anyone that diverges from the set standards, such as investigative and disciplinary procedures for alleged violations.
Exercises board of directors’ oversight responsibilities – The board of directors displays independence from the management team and actively monitors the establishment and effectiveness of internal controls. The board of directors aligns with the organization’s sustainable business goals by effectively
- Establishing oversight responsibilities – thereby ensuring sustainable business management by implementing oversight mechanisms and potentially modifying organizational documents to meet mandates and expectations.
- Applying relevant expertise and operating independently – by ensuring that board members charged with oversight responsibilities regarding sustainable business have the knowledge base and skill set to be effective and operate independently (e.g., through the nominations committee function and board review mechanisms).
- Providing oversight for the system of control – by supervising the organization’s sustainable business practices, including controls, systems, and resource utilization, to ensure alignment with its goals and mandates.
Establishes structures, authority, and responsibilities – Management, guided by the board of directors, puts in place the necessary structures and responsibilities to achieve their goals, including sustainability objectives by effectively
- Considering all structures of the entity – to support sustainable business activities and information systems, which include structures like the establishment and the interaction of operating units, affiliates, subsidiaries, divisions, geographic regions, and third-party providers.
- Establishing reporting line – by designating responsibilities among the organization’s stakeholders (e.g., employees) and systems (e.g., ERP software) to ensure the flow of information regarding sustainable business activities.
- Defining, assigning and limiting authorities and responsibilities – by the board of directors and management for sustainable business activities, and delineating the informationand processes, including the utilization of technology, to define these roles.
Component 2
Risk Assessment
Specifies suitable objectives – for successful implementation of a company’s sustainability objectives, it is important that there is alignment between its purpose or mission and its strategy. This requires setting out the appropriate sustainability objectives. These objectives must be congruent with the company’s operations, external financial reporting, external non-financial reporting, internal reporting, and compliance requirements. Alignment with these seemingly disparate set of objectives requires consideration of
- Operational and financial performance goals – which are driven by the sector or the industry in which the entity operates, and which forms the basis for committing resources. • Financial reporting objectives – which include the relevant accounting standards and financial materiality.
- Non-financial reporting objectives – which include compliance with the appropriate non-financial reporting frameworks such as the GRI, ISSB or the CSRD and the sustainability related impact and financial materiality (if computed).
- Compliance with laws and regulations.
Identifies and analyzes risks to meeting sustainable business objectives – including sustainable business goals, to develop strategies for managing these potential challenges by effectively –
- Including entity, subsidiary, division, operating unit, and functional levels – and performing their robust and effective risk analysis.
- Extending the risk assessment to value chain partners – and building process to identify risks across the value chain (both upstream and downstream).
- Analyzing internal and external factors – by considering scenarios that may result in impairment or loss of value to both tangible (recognized) assets and intangible (unrecognized) assets.
- Involving appropriate levels of management – in identifying and assessing sustainable business risks.
- Estimating significance of risks identified and determining the appropriate response – by estimating the potential effects of various scenarios on its sustainable business objectives qualitatively and quantitatively.
Component 3
Control Activities
Selects and develops control activities – The organization chooses and creates control activities to reduce risks to acceptable levels in alignment with its sustainable business objectives and related risks by effectively
- Building a control framework that considers entity – specific factors on how the control activities and oversight can be developed – thereby overseeing sustainable business objectives and addressing the risks identified.
- Developing control activities – by using a combination of structures, policies, procedures, and methods of overseeing these activities.
- Ensuring segregation of duties – to ensure internal checks and balances which properly reconcile, initiate, approve, process, and report sustainable business objectives with other financial and sustainable business information.
Selects and develops general controls over technology – Organizations are realizing that in developing an effective internal control system, the role of technology must be enhanced. The existing IT systems, built largely around financial information, may not be fit for purpose partly due to lack of a common denominator in sustainability data. In developing an effective internal control environment leveraging technology, it is important to ensure that the information is complete and accurate. Also, IT security is required to ensure the reliability and integrity of sustainable business information as it is processed from source to ultimate user.
Component 4
Information and Communication
Obtains and uses high quality information – The organization acquires or creates high-quality, pertinent information to aid in the effectiveness of internal control, particularly in assessing how well its processes align with achieving sustainable business goals by effectively
- Identifying information requirements – to deliver reliable, decision-aiding sustainable business information and how the systems themselves are functioning.
- Capturing internal and external sources of data – to build an effective oversight system of an organization’s sustainable business activities.
- Processing relevant data into information – by employing tools for summarizing and analyzing the data into decision-aiding information.
- Maintaining quality throughout processing – by ensuring an effective system of controls as it flows through various processes from source to decision maker.
- Considering the costs and benefits – in designing oversight and control systems, and the risks of decision-making on imperfect or potentially unreliable information along with the resources that would need to be expended to reduce the risk to an acceptable level
Communicates internally – The organization ensures effective internal communication of information, including objectives and responsibilities related to internal control, to promote a shared understanding of roles and facilitate the pursuit of sustainable business goals by effectively –
- Communicating internal control information – to those with responsibilities for carrying out an organization’s sustainable business activities about expectations regarding the process.
- Communicating with the board of directors – to bring decision-aiding information to the board that helps meet oversight responsibilities of the organization’s sustainable business activities.
- Providing separate communication lines – outside regular reporting lines that allow for the delivery of information about system functionality directly to decision makers without dilution or interference. • Selecting relevant methods of communication – in facilitating a responsible and meaningful response.
Component 5
Monitoring Activities
Conducts ongoing and/or separate evaluations – The organization periodically assesses its internal control components to determine their presence and functionality, especially in the context of facilitating sustainable business objectives, through scheduled or as-needed evaluations by effectively
- Considering a mix of ongoing and separate evaluations – by conducting regular or ongoing reviews of how well its oversight systems regarding its sustainable business activities are functioning.
- Considering rate of change – to assess how quickly demands and drivers for additional change will emerge that may require a reassessment of the effectiveness of existing processes.
- Establishing baseline understanding – for monitoring its systems regarding sustainable business activities, before it can drive improvements and respond to new risks and opportunities.
- Integrating with business processes – by considering the organization’s actual business, transactions, operations, processes, and expectations. 2
- Adjusting scope and frequency – by reassessing the timing of its assessments and review of its processes regarding its sustainable business activities as situations change.
- Objectively evaluating the effectiveness of an organization’s system of oversight of its sustainable business activities – by conducting periodic or ad hoc oversight assessments.
Evaluates and communicates deficiencies – The organization promptly assesses and communicates internal control weaknesses to relevant parties, such as senior management and the board of directors, as it reviews its structures and procedures related to sustainable business activities, facilitating alignment with the organization’s objectives by effectively
- Assessing results – of its periodic or ad hoc evaluations to identify means for improvement and progress.
- Communicating deficiencies – of the results of its periodic or ad hoc evaluations to the appropriate actors to facilitate improvements and progress.
- Monitoring corrective actions – by following up to ascertain whether the upgrades and improvements are working as expected and enhancing its ability to meet its sustainable business objectives



