Reporting

When preparing for a limited assurance engagement, you will typically encounter two problems online: many articles only explain the definition without providing concrete recommendations for action. Furthermore, some of the content is now outdated because it still assumes a planned transition to reasonable assurance—an assumption that was rendered obsolete by the Omnibus I Directive in February 2026. This guide closes both gaps: it clarifies the current legal status and shows how companies can prepare for the audit step by step.
Limited assurance is a form of external audit in which an independent auditor performs less extensive audit procedures than in a full financial statement audit. The result is a negative form of conclusion: the auditor does not actively confirm the accuracy of all information, but rather states that nothing has come to their attention during the audit that would indicate a material misstatement.
Simply put: In a reasonable assurance engagement, the auditor essentially says, "I have audited this, and the information is accurate." In a limited assurance engagement, they say, "Nothing has come to my attention during my—more limited—audit that suggests the information is inaccurate." The difference lies not only in the scope of the audit procedures but also in the wording of the audit opinion.
In the context of the CSRD (Corporate Sustainability Reporting Directive), limited assurance is the legally required minimum level of assurance for the sustainability report, which is published as part of the management report. The CSRD justifies this audit requirement on the grounds that sustainability disclosures are only reliable for investors, customers, and regulatory authorities if they are subject to independent external verification, just like financial figures.
In principle, any company required to prepare a sustainability report under the CSRD is subject to the audit requirement. However, the scope of application was significantly reduced by the Omnibus I Directive (EU) 2026/470, which entered into force on March 18, 2026.
The audit requirement applies directly alongside the reporting requirement: anyone who must prepare a CSRD sustainability report must also have it audited. There is no way to fulfill the reporting obligation without the audit obligation.
A point of practical importance: The German CSRD Implementation Act (CSRD-UmsG), which transposes the directive into the German Commercial Code (HGB), was still in the parliamentary process at the time this article was written. Following the public hearing in the Bundestag's Legal Affairs Committee on April 13, 2026, the legislative process was expected to be completed during 2026. Until it is published in the Federal Law Gazette, the 2017 CSR-RUG, with its existing 500-employee threshold for capital-market-oriented companies, formally remains in effect in Germany.
Practical tip
Since the legislative status can change at short notice, companies should check the current status of the CSRD-UmsG directly with the IDW, WPK, or in the Federal Law Gazette before making important decisions. The timing of the law's entry into force does not change the substantive preparation for the audit itself: the requirements for data quality, evidence, and processes described in this article apply regardless of when the law specifically takes effect.
Both terms refer to different levels of assurance in the external audit of sustainability disclosures. The difference primarily concerns the scope of the audit procedures, the nature of the audit opinion, and the associated residual risk of an undetected misstatement.
The original CSRD provided for a gradual transition from limited assurance to reasonable assurance, comparable to the level of assurance for annual financial statements. With the Omnibus I Directive (EU) 2026/470, published in the Official Journal of the EU on February 26, 2026, the legislator has deleted this obligation to introduce reasonable assurance standards without replacement. Limited assurance therefore remains the mandatory level of assurance for the CSRD sustainability report for the foreseeable future. Many older online sources still assume the originally planned tightening—this information is outdated.
The CSRD itself mandates that a limited assurance engagement be performed but does not specify a dedicated audit standard. Instead, the European Commission was to establish harmonized audit standards via a delegated act. This timeline has been postponed several times.
The CSRD requires an audit by an independent sustainability assurance provider. Depending on national implementation, this may be restricted to the statutory auditor or, where national legislation permits, an independent, accredited assurance services provider (IASP).
For Germany, the government draft of the CSRD implementation act (CSRD-UmsG) proposes restricting the audit exclusively to auditors or auditing firms. The IDW (Institute of Public Auditors in Germany) has expressly welcomed this decision, citing the profession's existing capacity, training, and quality assurance structure. It is often the same auditor who already audits the annual financial statements—this can be efficient, but it is not a requirement under European law.
For independence reasons, the auditing firm must not have been involved in the preparation of the underlying data, processes, or evidence, as this would create a self-review threat. Consulting services for preparation and the actual audit must therefore be organizationally separated.
Similar to a financial audit, limited assurance follows a structured, multi-phase process. While the exact approach varies by auditor, the basic framework is comparable.
The duration of a limited assurance engagement depends heavily on the size of the company, data quality, and how well the evidence is prepared. In practice, companies should not view the audit as a one-off event at the end of the year, but as a process spanning several months. Assurance capacity is limited across Europe; engaging an auditor early—ideally six to twelve months before the planned publication date—secures both capacity and a realistic timeline.
At the end of the audit, the auditor expects a consolidated, accessible audit file: the data point list with source mapping, calculation files with visible formulas, the emission factor register, process descriptions, evidence of internal controls and approvals, documentation of the materiality analysis, the management representation letter, and reconciliation documentation with financial reporting. Keeping these eight documents in mind from the start saves a great deal of searching during the final phase before the audit.
The entire sustainability report published in the management report is audited in accordance with the European Sustainability Reporting Standards (ESRS)—not just selected key performance indicators. The scope of the audit is closely aligned with the double materiality analysis: the topics identified as material determine what is reported—and therefore what is audited.
A common misconception is that the auditor "recalculates" the materiality analysis or evaluates the "correctness" of the result. In reality, they primarily check the traceability of the process: Was the methodology applied consistently? Were relevant stakeholders involved? Can the actual scope of the report be derived from the result of the materiality analysis? A poorly documented materiality analysis therefore potentially jeopardizes the entire report, regardless of the content-related outcome.
Scope 1 and Scope 2 emissions are subject to audit just like all other material data points. Scope 3 data and other information from the value chain are considered the most challenging area of the audit because they are often based on third-party data, estimates, and assumptions, the origin and quality of which are naturally harder for companies to control than their own data. Forward-looking statements—such as climate targets or transition plans—are also audited; here, the disclosure of underlying assumptions is particularly important, as it is naturally impossible to provide "hard" evidence for them.
Audit readiness means that a company prepares its sustainability report in such a way that it can be audited without major rework: fully documented, traceably derived, and with clear responsibilities. The following five building blocks form a field-tested framework for this.
Goal: The reported data is complete, consistent, and plausible.
Common mistake: Data points are omitted without documented justification—auditors systematically cross-reference the report scope with the materiality analysis, and unjustified gaps are among the most frequent audit findings.
Goal: Every key performance indicator is fully traceable back to its source.
Common mistake: "The number is correct, but its origin cannot be traced" is the most frequent point of contention during audits. Verifiability often counts for more than perfection—the audit trail is the heart of any limited assurance.
Goal: The control system makes errors unlikely and is fully documented.
Pro tip: The more robustly the internal control system is documented, the more the auditor can rely on it for their risk assessment—which tends to reduce the sample size and, consequently, the duration and cost of the audit.
Goal: Data collection is a repeatable, documented process, not a one-off task.
Common mistake: "Manufactured" documentation created shortly before an audit is easily spotted by auditors and is considered a critical finding. Reproducibility—achieving the same result regardless of who performs the collection—is a key audit criterion.
Goal: Sustainability data is anchored at the management level, not treated as an isolated task for individual departments.
Pro tip: Auditors view a clear governance structure as a signal that sustainability reporting is strategically embedded—this strengthens confidence in the reliability of all other disclosures.
In addition to the five modules, there are four thematic areas that cut across these modules and regularly lead to follow-up questions or findings in practice.
Materiality analysis as the basis for the audit
The methodology, stakeholders involved, assessment logic, and results of the double materiality analysis must be documented—and it must be clear how the specific reporting scope (and thus the audit scope) is derived from this materiality. The audit focuses on the traceability of the process, not on achieving a "correct" result.
Estimates, Scope 3, and forward-looking data
For estimates—such as those for Scope 3 emissions or target values—the methodology, assumptions, and uncertainties must be documented and justified. An estimate without a traceable derivation is considered a standard audit finding. Consistency of methods over the years is also crucial: changing methods without documented justification impairs comparability and, consequently, the reliability of the disclosures.
Consistency with the financial report
Sustainability disclosures must be consistent with the figures, assumptions, and timeframes in the financial report—for example, regarding revenue, investments, or consolidation scope. The auditor specifically checks for this consistency, as contradictions between financial and sustainability reporting call the credibility of both reports into question.
Independence, auditor setup, and digital tagging
Clarifying early on who will perform the audit—the statutory auditor or an independent assurance provider—secures capacity and ensures the schedule is met. Furthermore, the separation between preparatory consulting and the actual audit must be strictly maintained to avoid a self-review threat. Looking ahead, the machine-readable tagging of disclosures according to ESRS/ESEF-XBRL is also becoming an increasing focus of the audit.
It is not possible to provide reliable, standardized pricing for Germany—the costs of a limited assurance engagement depend on too many company-specific factors and are negotiated individually between the company and the auditor. The following factors significantly influence the effort and, consequently, the costs:
The most effective lever for reducing audit effort—and thus indirectly costs—does not lie with the auditor, but with the company itself: the better the data, evidence, and processes are set up before the audit begins, the fewer follow-up questions, additional data collection, and sampling will be required.
A large portion of the requirements described above—consistent audit trails, versioned emission factors, documented approvals, and traceable calculations—can hardly be maintained reliably over several years using manual spreadsheets. ESG software can provide support here by mapping data points, source attribution, calculation logic, and approval workflows digitally throughout, and providing them to the auditor in a structured, exportable format.
cubemos offers a modular ESG compliance software portfolio for this purpose, supporting the five building blocks described here: audit trails for each data point, versioned emission factors, documented approval workflows, and an auditor-friendly export. The independent assessment of the content remains—as required by audit independence regulations—solely with the auditor.
12. Outlook: How will the auditing of sustainability reporting continue to evolve?
These eight documents should be bundled and easily accessible for the auditor:
Would you like to check if your company is already optimally prepared for a limited assurance engagement? Use our free audit readiness checklist to review your current status step by step — covering all five building blocks and the four cross-cutting topics from this article.
Is limited assurance mandatory?
Yes. It is part of the statutory CSRD reporting requirement; anyone required to report under the CSRD must also have their report audited. There is no way to fulfill the reporting obligation without an audit.
When does the audit requirement apply to my company?
That depends on when your company first becomes subject to CSRD reporting requirements. Under Omnibus I, this generally applies to companies with more than 1,000 employees and over €450 million in revenue. For Germany, the exact application date is linked to the entry into force of the CSRD implementation act (CSRD-UmsG).
Are Scope 1, Scope 2, and Scope 3 data all audited?
Scope 1 and Scope 2 emissions are subject to audit just like other material data points. Scope 3 data is also audited, but is considered particularly challenging due to its reliance on third-party data and estimates.
Are all ESRS standards audited?
The entire published sustainability report is audited—the scope is determined by the topics identified as material in the double materiality assessment, rather than by all theoretically possible ESRS topics.
Is the double materiality assessment itself audited?
The audit focuses on the traceability of the methodology, stakeholder engagement, and derivation—not on whether the substantive outcome is "correct."
How can the audit effort be reduced?
The most effective lever is thorough preparation: complete data point lists, consistent audit trails, documented controls, and early involvement of the auditor reduce follow-up questions and the sample size.
Which departments should be involved early on?
In addition to sustainability/ESG, this typically includes Finance/Controlling (for consistency with the financial report), IT (for data origin and systems), Procurement (for supply chain data), and Executive Management (for governance and the representation letter).
Can the same auditor audit both the annual financial statements and the sustainability report?
Yes, this is permitted and often makes sense in practice for efficiency reasons—provided that combined capacity and the schedule are coordinated with the auditor at an early stage.
What happens if the auditor identifies issues?
The auditor first discusses findings with executive management; depending on the severity, this may lead to adjustments in the report, additional explanations, or—in the case of unresolvable material errors—a qualified or adverse audit opinion.
Is voluntary reasonable assurance possible?
Yes. Companies can voluntarily agree to reasonable assurance for the entire report or for individual KPIs, even if only limited assurance is required by law.
Does the audit requirement also apply to voluntary VSME reports?
No. The VSME standard is a voluntary, simplified reporting standard for companies not subject to the CSRD (particularly SMEs) and is not subject to any statutory audit requirement.
How does limited assurance differ from a voluntary sustainability audit prior to the CSRD?
Before the CSRD, there was no uniform statutory audit requirement; audits were voluntary and inconsistent, following various standards. The CSRD makes the audit mandatory for the first time and ties it to a (prospectively harmonized) standard.


.avif)
