Reporting

Limited Assurance CSRD: The complete guide to auditing sustainability reports

Limited Assurance is the minimum level of audit depth required by the CSRD for sustainability reporting. An independent auditor – in Germany, a public auditor (Wirtschaftsprüfer) – provides a statement of limited assurance: no evidence was found to suggest that the report contains material misstatements. While this represents a lower level of audit depth than a financial statement audit (Reasonable Assurance), it is by no means a mere formality. With the Omnibus I Directive (EU) 2026/470, the EU decided in February 2026 that Limited Assurance will remain the permanent standard – the originally planned transition to Reasonable Assurance has been removed entirely.
  1. Lorem ipsum dolor sit amet
The software for automated CSRD reporting.
Learn more!

When preparing for a limited assurance engagement, you will typically encounter two problems online: many articles only explain the definition without providing concrete recommendations for action. Furthermore, some of the content is now outdated because it still assumes a planned transition to reasonable assurance—an assumption that was rendered obsolete by the Omnibus I Directive in February 2026. This guide closes both gaps: it clarifies the current legal status and shows how companies can prepare for the audit step by step.

What is limited assurance? Definition and context

Limited assurance is a form of external audit in which an independent auditor performs less extensive audit procedures than in a full financial statement audit. The result is a negative form of conclusion: the auditor does not actively confirm the accuracy of all information, but rather states that nothing has come to their attention during the audit that would indicate a material misstatement.

Simply put: In a reasonable assurance engagement, the auditor essentially says, "I have audited this, and the information is accurate." In a limited assurance engagement, they say, "Nothing has come to my attention during my—more limited—audit that suggests the information is inaccurate." The difference lies not only in the scope of the audit procedures but also in the wording of the audit opinion.

In the context of the CSRD (Corporate Sustainability Reporting Directive), limited assurance is the legally required minimum level of assurance for the sustainability report, which is published as part of the management report. The CSRD justifies this audit requirement on the grounds that sustainability disclosures are only reliable for investors, customers, and regulatory authorities if they are subject to independent external verification, just like financial figures.

Who requires limited assurance under the CSRD?

In principle, any company required to prepare a sustainability report under the CSRD is subject to the audit requirement. However, the scope of application was significantly reduced by the Omnibus I Directive (EU) 2026/470, which entered into force on March 18, 2026.

Scope of application under Omnibus I

Criterion Rule Since Omnibus I
Thresholds More than 1,000 employees AND more than €450 million revenue (both criteria cumulative)
Affected Companies EU-Wide Around 5,000–6,000 companies (instead of the originally estimated ~50,000)
Capital-Market-Oriented SMEs No longer within scope
Value Chain Cap Suppliers with fewer than 1,000 employees may only be asked for data according to the voluntary VSME standard

The audit requirement applies directly alongside the reporting requirement: anyone who must prepare a CSRD sustainability report must also have it audited. There is no way to fulfill the reporting obligation without the audit obligation.

Special case: Germany – national implementation not yet finalized

A point of practical importance: The German CSRD Implementation Act (CSRD-UmsG), which transposes the directive into the German Commercial Code (HGB), was still in the parliamentary process at the time this article was written. Following the public hearing in the Bundestag's Legal Affairs Committee on April 13, 2026, the legislative process was expected to be completed during 2026. Until it is published in the Federal Law Gazette, the 2017 CSR-RUG, with its existing 500-employee threshold for capital-market-oriented companies, formally remains in effect in Germany.

Practical tip

Since the legislative status can change at short notice, companies should check the current status of the CSRD-UmsG directly with the IDW, WPK, or in the Federal Law Gazette before making important decisions. The timing of the law's entry into force does not change the substantive preparation for the audit itself: the requirements for data quality, evidence, and processes described in this article apply regardless of when the law specifically takes effect.

Limited assurance vs. reasonable assurance: the difference

Both terms refer to different levels of assurance in the external audit of sustainability disclosures. The difference primarily concerns the scope of the audit procedures, the nature of the audit opinion, and the associated residual risk of an undetected misstatement.

Characteristic Limited Assurance Reasonable Assurance
Audit Depth Limited: mainly inquiries, analytical procedures Comprehensive: additionally includes detailed testing, third-party confirmations
Audit Opinion Negative wording: "Nothing has come to our attention that would indicate otherwise" Positive wording: "The disclosures are accurate"
Level of Assurance Moderate High (comparable to financial statement audit)
Effort & Cost Lower Significantly higher
CSRD Status (as of 08/2026) Binding standard, permanent Not planned – tightening removed by Omnibus I

Important clarification on the current legal status

The original CSRD provided for a gradual transition from limited assurance to reasonable assurance, comparable to the level of assurance for annual financial statements. With the Omnibus I Directive (EU) 2026/470, published in the Official Journal of the EU on February 26, 2026, the legislator has deleted this obligation to introduce reasonable assurance standards without replacement. Limited assurance therefore remains the mandatory level of assurance for the CSRD sustainability report for the foreseeable future. Many older online sources still assume the originally planned tightening—this information is outdated.

Legal basis and audit standards: ISAE 3000, ISSA 5000 & Co.

The CSRD itself mandates that a limited assurance engagement be performed but does not specify a dedicated audit standard. Instead, the European Commission was to establish harmonized audit standards via a delegated act. This timeline has been postponed several times.

Current status of auditing standards

  • ISAE 3000 (Revised): The standard currently used in practice for assurance engagements other than audits of financial statements. While not specifically developed for sustainability reporting, it is being used across the EU as a transitional standard for CSRD audits.
  • ISSA 5000: A standalone auditing standard developed by the International Auditing and Assurance Standards Board (IAASB) specifically for sustainability reporting. It will be applicable from December 2026 and is intended to become the global reference standard in the future.
  • Harmonized EU auditing standards: The European Commission was originally scheduled to adopt these via a delegated act by October 1, 2026. The Omnibus I Directive extended this deadline to July 1, 2027. Until then, national auditing standards or the guidelines issued by the Committee of European Auditing Oversight Bodies (CEAOB) will apply.

Who conducts the audit?

The CSRD requires an audit by an independent sustainability assurance provider. Depending on national implementation, this may be restricted to the statutory auditor or, where national legislation permits, an independent, accredited assurance services provider (IASP).

For Germany, the government draft of the CSRD implementation act (CSRD-UmsG) proposes restricting the audit exclusively to auditors or auditing firms. The IDW (Institute of Public Auditors in Germany) has expressly welcomed this decision, citing the profession's existing capacity, training, and quality assurance structure. It is often the same auditor who already audits the annual financial statements—this can be efficient, but it is not a requirement under European law.

For independence reasons, the auditing firm must not have been involved in the preparation of the underlying data, processes, or evidence, as this would create a self-review threat. Consulting services for preparation and the actual audit must therefore be organizationally separated.

What does a limited assurance engagement actually involve?

Similar to a financial audit, limited assurance follows a structured, multi-phase process. While the exact approach varies by auditor, the basic framework is comparable.

Phase Content
1. Engagement Acceptance Auditor assesses independence, competence, and auditability of the report; engagement letter is finalized
2. Planning & Risk Assessment Understanding of the business model, materiality assessment, and internal control system; determination of audit focus areas
3. Execution Inquiries, analytical procedures, sampling at the data-point level, reconciliation with source documents
4. Evaluation & Reporting Assessment of findings, alignment with management, preparation of the audit opinion

The duration of a limited assurance engagement depends heavily on the size of the company, data quality, and how well the evidence is prepared. In practice, companies should not view the audit as a one-off event at the end of the year, but as a process spanning several months. Assurance capacity is limited across Europe; engaging an auditor early—ideally six to twelve months before the planned publication date—secures both capacity and a realistic timeline.

At the end of the audit, the auditor expects a consolidated, accessible audit file: the data point list with source mapping, calculation files with visible formulas, the emission factor register, process descriptions, evidence of internal controls and approvals, documentation of the materiality analysis, the management representation letter, and reconciliation documentation with financial reporting. Keeping these eight documents in mind from the start saves a great deal of searching during the final phase before the audit.

What exactly is examined during the audit?

The entire sustainability report published in the management report is audited in accordance with the European Sustainability Reporting Standards (ESRS)—not just selected key performance indicators. The scope of the audit is closely aligned with the double materiality analysis: the topics identified as material determine what is reported—and therefore what is audited.

A common misconception is that the auditor "recalculates" the materiality analysis or evaluates the "correctness" of the result. In reality, they primarily check the traceability of the process: Was the methodology applied consistently? Were relevant stakeholders involved? Can the actual scope of the report be derived from the result of the materiality analysis? A poorly documented materiality analysis therefore potentially jeopardizes the entire report, regardless of the content-related outcome.

Scope 1 and Scope 2 emissions are subject to audit just like all other material data points. Scope 3 data and other information from the value chain are considered the most challenging area of the audit because they are often based on third-party data, estimates, and assumptions, the origin and quality of which are naturally harder for companies to control than their own data. Forward-looking statements—such as climate targets or transition plans—are also audited; here, the disclosure of underlying assumptions is particularly important, as it is naturally impossible to provide "hard" evidence for them.

Audit readiness: the five building blocks of audit preparedness

Audit readiness means that a company prepares its sustainability report in such a way that it can be audited without major rework: fully documented, traceably derived, and with clear responsibilities. The following five building blocks form a field-tested framework for this.

Building block 1: Data quality

Goal: The reported data is complete, consistent, and plausible.

  • All essential ESRS data points are captured—gaps are intentionally justified, not simply "forgotten."
  • The figures stated in the report match the underlying raw data exactly.
  • Units (e.g., tCO₂e, kWh, MWh) and reporting periods are defined consistently throughout.
  • Anomalous values or year-over-year changes are briefly commented on and explainable.

Common mistake: Data points are omitted without documented justification—auditors systematically cross-reference the report scope with the materiality analysis, and unjustified gaps are among the most frequent audit findings.

Building Block 2: Evidence & Audit Trail

Goal: Every key performance indicator is fully traceable back to its source.

  • A continuous chain exists for every data point: KPI → calculation → source document.
  • Four mandatory details are provided for each data point: source document, calculation method, responsible person, and date.
  • Emission factors are documented with source, version, and validity year (e.g., DEFRA, GEMIS).
  • Formulas and calculation methods are transparent and reproducible—no hard-coded final values without derivation.

Common mistake: "The number is correct, but its origin cannot be traced" is the most frequent point of contention during audits. Verifiability often counts for more than perfection—the audit trail is the heart of any limited assurance.

Building Block 3: Internal Controls

Goal: The control system makes errors unlikely and is fully documented.

  • Significant calculations and data transfers are verified using the four-eyes principle.
  • Data points and report sections undergo defined, documented approval steps.
  • Subsequent changes to data are logged—what, when, by whom, and why.
  • Access rights to sustainability data are regulated; roles and permissions are defined.

Pro tip: The more robustly the internal control system is documented, the more the auditor can rely on it for their risk assessment—which tends to reduce the sample size and, consequently, the duration and cost of the audit.

Module 4: Processes & Data Collection

Goal: Data collection is a repeatable, documented process, not a one-off task.

  • For every data category, it is specified: who collects what, when, and from which source.
  • Supporting documentation is created at the time of collection—not reconstructed retroactively.
  • The process is designed as an annual cycle, including documented handovers of roles.

Common mistake: "Manufactured" documentation created shortly before an audit is easily spotted by auditors and is considered a critical finding. Reproducibility—achieving the same result regardless of who performs the collection—is a key audit criterion.

Module 5: Governance & Management Statements

Goal: Sustainability data is anchored at the management level, not treated as an isolated task for individual departments.

  • Roles, committees, and responsibilities are defined up to the management level.
  • The executive board confirms the completeness and accuracy of the information in writing (management representation letter).
  • The involvement of management and supervisory bodies in the report is documented, for example through meeting minutes.

Pro tip: Auditors view a clear governance structure as a signal that sustainability reporting is strategically embedded—this strengthens confidence in the reliability of all other disclosures.

Four cross-cutting topics often underestimated during audits

In addition to the five modules, there are four thematic areas that cut across these modules and regularly lead to follow-up questions or findings in practice.

Materiality analysis as the basis for the audit

The methodology, stakeholders involved, assessment logic, and results of the double materiality analysis must be documented—and it must be clear how the specific reporting scope (and thus the audit scope) is derived from this materiality. The audit focuses on the traceability of the process, not on achieving a "correct" result.

Estimates, Scope 3, and forward-looking data

For estimates—such as those for Scope 3 emissions or target values—the methodology, assumptions, and uncertainties must be documented and justified. An estimate without a traceable derivation is considered a standard audit finding. Consistency of methods over the years is also crucial: changing methods without documented justification impairs comparability and, consequently, the reliability of the disclosures.

Consistency with the financial report

Sustainability disclosures must be consistent with the figures, assumptions, and timeframes in the financial report—for example, regarding revenue, investments, or consolidation scope. The auditor specifically checks for this consistency, as contradictions between financial and sustainability reporting call the credibility of both reports into question.

Independence, auditor setup, and digital tagging

Clarifying early on who will perform the audit—the statutory auditor or an independent assurance provider—secures capacity and ensures the schedule is met. Furthermore, the separation between preparatory consulting and the actual audit must be strictly maintained to avoid a self-review threat. Looking ahead, the machine-readable tagging of disclosures according to ESRS/ESEF-XBRL is also becoming an increasing focus of the audit.

Typical mistakes companies make in practice

  • Starting preparation just before the audit instead of establishing data collection as an annual process.
  • Omitting data points without documented justification instead of identifying intentional gaps.
  • Using emission factors without citing the source and version, or failing to update them over several years.
  • Calculations in spreadsheets without visible formulas—providing only final values that cannot be reproduced.
  • Treating the materiality analysis as a one-time exercise instead of updating and documenting it annually.
  • Adopting Scope 3 and supply chain data without documented origins and estimation methodology.
  • Failing to clearly assign responsibilities for individual data points, leaving no one able to provide specific information during an audit.
  • Involving the auditor too late instead of securing capacity and an audit schedule early on.

Costs and effort of a limited assurance

It is not possible to provide reliable, standardized pricing for Germany—the costs of a limited assurance engagement depend on too many company-specific factors and are negotiated individually between the company and the auditor. The following factors significantly influence the effort and, consequently, the costs:

  • Scope and complexity of the ESRS topics identified as material.
  • Maturity of existing data quality, documentation, and internal controls at the start of the audit.
  • Number and complexity of locations, subsidiaries, and consolidation groups.
  • Availability and quality of Scope 3 and supply chain data.
  • Whether the same audit firm is already auditing the annual financial statements (potential efficiency gains through combined engagements).

The most effective lever for reducing audit effort—and thus indirectly costs—does not lie with the auditor, but with the company itself: the better the data, evidence, and processes are set up before the audit begins, the fewer follow-up questions, additional data collection, and sampling will be required.

How can software support preparation for limited assurance?

A large portion of the requirements described above—consistent audit trails, versioned emission factors, documented approvals, and traceable calculations—can hardly be maintained reliably over several years using manual spreadsheets. ESG software can provide support here by mapping data points, source attribution, calculation logic, and approval workflows digitally throughout, and providing them to the auditor in a structured, exportable format.

cubemos offers a modular ESG compliance software portfolio for this purpose, supporting the five building blocks described here: audit trails for each data point, versioned emission factors, documented approval workflows, and an auditor-friendly export. The independent assessment of the content remains—as required by audit independence regulations—solely with the auditor.

12. Outlook: How will the auditing of sustainability reporting continue to evolve?

  • Reasonable Assurance: The originally planned tightening to reasonable assurance was removed without replacement by the Omnibus I Directive. A new legislative process at the EU level would be required for any renewed tightening—currently, there is no foreseeable timeline for this.
  • ISSA 5000: The IAASB's standalone sustainability audit standard will be applicable from December 2026 and is expected to become the global reference standard for sustainability assurance in the medium term—even beyond the CSRD.
  • Harmonized EU audit standards: The EU Commission must now adopt these via delegated act by July 1, 2027, at the latest. Until then, varying national transitional arrangements will continue to exist within the EU.
  • German implementation: Once the CSRD implementation act (CSRD-UmsG) is finally promulgated, there will be legal certainty regarding the application date, thresholds, and the authorization of auditors in Germany. Companies should actively monitor the status until then.
  • Digital tagging: The machine-readable labeling of sustainability disclosures (ESRS/ESEF-XBRL) is likely to be increasingly included in the scope of audits in the future.

Is your audit file complete? An overview of the most important documents

These eight documents should be bundled and easily accessible for the auditor:

  1. Data point list with source mapping
  1. Calculation files including visible formulas
  1. Emission factor register with source and version
  1. Process descriptions for data collection
  1. Evidence of internal controls and approvals
  1. Documentation of the materiality analysis
  1. Management representation letter
  1. Reconciliation documentation for financial reporting

Your next step

Would you like to check if your company is already optimally prepared for a limited assurance engagement? Use our free audit readiness checklist to review your current status step by step — covering all five building blocks and the four cross-cutting topics from this article.

Frequently asked questions about CSRD limited assurance

Is limited assurance mandatory?

Yes. It is part of the statutory CSRD reporting requirement; anyone required to report under the CSRD must also have their report audited. There is no way to fulfill the reporting obligation without an audit.

When does the audit requirement apply to my company?

That depends on when your company first becomes subject to CSRD reporting requirements. Under Omnibus I, this generally applies to companies with more than 1,000 employees and over €450 million in revenue. For Germany, the exact application date is linked to the entry into force of the CSRD implementation act (CSRD-UmsG).

Are Scope 1, Scope 2, and Scope 3 data all audited?

Scope 1 and Scope 2 emissions are subject to audit just like other material data points. Scope 3 data is also audited, but is considered particularly challenging due to its reliance on third-party data and estimates.

Are all ESRS standards audited?

The entire published sustainability report is audited—the scope is determined by the topics identified as material in the double materiality assessment, rather than by all theoretically possible ESRS topics.

Is the double materiality assessment itself audited?

The audit focuses on the traceability of the methodology, stakeholder engagement, and derivation—not on whether the substantive outcome is "correct."

How can the audit effort be reduced?

The most effective lever is thorough preparation: complete data point lists, consistent audit trails, documented controls, and early involvement of the auditor reduce follow-up questions and the sample size.

Which departments should be involved early on?

In addition to sustainability/ESG, this typically includes Finance/Controlling (for consistency with the financial report), IT (for data origin and systems), Procurement (for supply chain data), and Executive Management (for governance and the representation letter).

Can the same auditor audit both the annual financial statements and the sustainability report?

Yes, this is permitted and often makes sense in practice for efficiency reasons—provided that combined capacity and the schedule are coordinated with the auditor at an early stage.

What happens if the auditor identifies issues?

The auditor first discusses findings with executive management; depending on the severity, this may lead to adjustments in the report, additional explanations, or—in the case of unresolvable material errors—a qualified or adverse audit opinion.

Is voluntary reasonable assurance possible?

Yes. Companies can voluntarily agree to reasonable assurance for the entire report or for individual KPIs, even if only limited assurance is required by law.

Does the audit requirement also apply to voluntary VSME reports?

No. The VSME standard is a voluntary, simplified reporting standard for companies not subject to the CSRD (particularly SMEs) and is not subject to any statutory audit requirement.

How does limited assurance differ from a voluntary sustainability audit prior to the CSRD?

Before the CSRD, there was no uniform statutory audit requirement; audits were voluntary and inconsistent, following various standards. The CSRD makes the audit mandatory for the first time and ties it to a (prospectively harmonized) standard.

Checklist: Limited Assurance for the CSRD
Use our free audit readiness checklist to check step-by-step whether your data, processes, and evidence meet the typical requirements of an external audit.
Download now!

Discover cubemos now.

AI-powered software for ESG reporting, CO2 and supply chain

Always up to date

Never miss an update or webinar.