Level 2 · Decision guide·ESRS · Disclosure guides
ESRS Data Governance and Internal Controls: From Datapoint Owners to Assurance Evidence
An operating model for the data dictionary, evidence register, calculations, access, review, change control, representations and issue remediation
Published passport
Current as at 10 August 2026
Reviewed by
Dr Ross KurinkoLinkedIn
Strategic ESG Advisor · IFRS S1 & S2 / GRI / ESRS expert
GRI Certified Global Trainer · PhD, University of Cambridge · ESG-AI expert
15+ years on FTSE 100 & Fortune Global 500 disclosures
Canary Wharf, London
LRA educational guidance · Not issued or endorsed by European Commission
Edition written against
ESRS 2023 legal baseline and Commission-adopted revised ESRS 2026, with explicit version gate
Published
10 Aug 2026
Knowledge Hub guide
Last reviewed
10 Aug 2026
Short answer
The answer, before the reasoning
ESRS data governance should create a traceable chain from the material IRO and disclosure requirement to the datapoint definition, source system, calculation, estimate, evidence, review, approval and published statement. A workable model combines a controlled data dictionary, evidence register, calculation and model standards, role-based access, preparer-reviewer segregation, period-end controls, change management, issue remediation and management representations.
Revised ESRS 2 GOV-4 requires disclosure of the scope, main features and components of risk management and internal controls over sustainability reporting, while its Application Requirement highlights completeness and integrity of data and accuracy of estimates. The control design must therefore cover narrative claims as well as metrics.
A sustainability metric can be arithmetically correct and still be misleading because the wrong entities were included, the denominator changed, a site estimate was silently replaced, supplier data were duplicated, a late incident was omitted or the narrative claim goes beyond the evidence. ESRS internal control therefore has to cover the full reporting chain: material IRO, disclosure requirement, definition, boundary, source, calculation, judgement, review, approval, presentation and publication.
Revised ESRS 2 GOV-4 requires disclosure of the scope, main features and components of risk management and internal control processes and systems in relation to sustainability reporting. Its AR 10 highlights completeness and integrity of data and accuracy of estimation results. GDR-M requires method, sources, relevant estimates and assumptions, value-chain proxies, context and significant changes for each metric. These provisions create a clear reporting expectation, but they do not prescribe one universal control framework or control catalogue.
Figure 5. ESRS data governance from material IRO and source systems to assurance evidence and publication.
The dictionary is not only a list of names and units. It is the controlled contract between the standard, the data owner, the calculation and the disclosure. At minimum, each record should contain:
Unique datapoint or narrative-claim ID, related material IRO, ESRS requirement and report locator.
Approved name, plain-language definition, official defined terms, unit and classification rules.
Reporting period, cut-off, comparative basis and events-after-period treatment.
Organisational, operational and value-chain boundary; included and excluded entities, sites, products or populations.
Primary source system, report or evidence; extraction method; data owner and backup owner.
Calculation, transformation, consolidation, emission or conversion factor, numerator, denominator and double-counting rules.
Estimate, proxy or model methodology, assumptions, uncertainty, validation and data-quality improvement plan.
Preparer, reviewer, approver, control frequency, evidence retained and issue escalation.
Method version, effective date, change rationale, comparative impact and restatement decision.
Access classification, privacy or privilege note and retention requirement.
1. Separate source data from transformations and outputs. An independent reviewer should be able to identify the population received, adjustments made and final value.
2. Lock formulas and protect controlled cells. Manual overrides should be visible, justified, approved and included in the change history.
3. Maintain factor and methodology registers. Record source, version, geography, period, unit conversion and replacement decisions for external factors.
4. Validate models and estimates proportionately. Test logic, reasonableness, sensitivity, completeness of inputs and known bias; document uncertainty and limitations.
5. Control consolidation. Reconcile entity submissions to the reporting population, prevent duplicates, eliminate internal flows where required and investigate unexplained movements.
6. Retain reproducible period-end versions. A live dashboard that changes after publication is not the complete evidence for the reported figure.
The public GOV-4 disclosure should explain the scope, main features and components of the risk-management and internal-control system over sustainability reporting. It should be specific enough for users to understand how the undertaking manages reporting risk, but it does not need to publish the full internal control matrix or sensitive system details. Relevant information may include governance, risk assessment, data ownership, main control types, estimate governance, monitoring, deficiencies and remediation.
Adaptation warning. The wording must reflect the actual system, findings and governance. A generic statement that “robust controls are in place” is not supported merely by having data owners or assurance.
Detection. A central classification and variance control identifies inconsistent worker populations and an implausible increase. The reviewer traces samples to HR and learning systems and finds that the group instruction did not define completion, population or unit consistently.
Correction. The group issues an approved definition, restates the dry-run data, records the comparative impact and updates the data dictionary, local sign-off and review control. Where reliable historical data cannot be reconstructed, the statement explains the limitation rather than presenting a false trend.
Root cause and remediation. The issue is classified as a design deficiency, not a one-off input error. The group adds a mandatory local population reconciliation, test examples in the reporting manual and targeted training. Internal audit verifies implementation in the next cycle.
Building controls around a list of datapoints without linking them to material IROs, disclosure objectives and report claims.
Using one generic owner sign-off as the only evidence of completeness and accuracy.
Leaving estimates, proxies and external factors outside model and change governance.
Allowing unrestricted workbook access and invisible manual overrides.
Retaining links to live systems but not the period-end extract or calculation version used for publication.
Failing to reconcile source populations, group scope, acquisitions and disposals.
Treating narrative disclosures and legal assertions as editorial text rather than controlled information.
Closing assurance findings without root-cause analysis or verifying remediation.
Describing controls publicly in a way that overstates maturity or omits significant unresolved limitations.
Every material disclosure has an owner, reviewer, method, source and evidence locator.
Data dictionary records are approved, versioned and consistent with group instructions and public wording.
Source populations and reporting boundaries are reconciled and exceptions resolved or disclosed.
Calculations, factors, estimates, proxies and manual adjustments are reproducible and independently reviewed.
Restricted evidence has lawful, secure and workable assurance access.
Narrative claims, target progress, effectiveness and limitations are included in the claim ledger and review.
Changes and restatements have approved rationale and comparative treatment.
Open findings have severity, disclosure impact, owner, due date, compensating control and governance escalation.
Final values and narrative tie to the exact published version and release archive.
Management representations disclose known gaps, unresolved issues and post-close changes.
1. Could an independent reviewer reproduce the final disclosure without relying on the preparer’s memory?
2. Which control would detect a complete but wrongly bounded dataset?
3. Are narrative effectiveness claims subject to the same evidence and approval discipline as quantitative metrics?
Source check completed on 2 August 2026. This article is an educational publication draft. It does not provide legal, assurance or organisation-specific advice. Confirm the applicable ESRS edition, the final Official Journal text, national implementation and the undertaking’s facts before public use.
Changes to ESRS GOV-4, GDR-M, estimates, value-chain data or relief provisions.
New EU or national assurance standards and assurance-provider evidence expectations.
ERP, consolidation, data-platform or access-control changes affecting reporting lineage.
Control failures, restatements, significant deficiencies or recurring assurance findings.
Do not claim that the sample matrix is complete or sufficient for every organisation.
Tailor control owners and evidence to actual systems, legal entities and segregation constraints.
Include narrative disclosures, legal claims and governance approvals in the control universe.
Review retention, privacy, privilege, information security and cross-border access with specialists.
Rule
KNOWLEDGE CARD PACKAGE
<p>Public practitioner article followed by an editor and publisher pack with SEO, requirement mapping, update triggers and release controls.</p>
Rule
ESRS-EVD-001
<p>ESRS Data Governance and Internal Controls: From Datapoint Owners to Assurance Evidence An operating model for the data dictionary, evidence register, calculations, access, review, change control, representations and issue remediation</p>
In practice
Type
| Type | Tier | Audience — Current context |
|---|---|---|
| Data governance, internal control and assurance-readiness guide | Tier 4 · Expert Controls Guide | Finance, sustainability, data, IT, internal control, internal audit, legal, group reporting, data owners and assurance teams — Revised ESRS 2 GOV-4, AR 10 and GDR-M checked to 2 August 2026 |
Rule
2026 VERSION GATE
<p>The European Commission adopted revised ESRS on 3 July 2026. At the source-check date, the delegated act was not yet in force because publication in the Official Journal follows scrutiny. This article therefore uses the Commission-adopted 2026 text as forward-looking implementation guidance and keeps the 2023 ESRS as the current legal baseline. The adopted act provides for mandatory use from financial year 2027 and optional use for financial year 2026 once the act is in force. Confirm the final Official Journal text, national law and reporting period before publication.</p>
Quick orientation
Quick orientation
- Applies to
- Metrics and narrative disclosures prepared across group entities, source systems, spreadsheets, models, surveys and value-chain data.
- Primary decision
- What governance, definitions, controls and evidence make each disclosure traceable, reproducible and reviewable?
- Key sources
- Revised ESRS 2 GOV-4 and AR 10; GDR-M; ESRS 1 qualitative characteristics and boundary provisions.
- Common confusion
- A data-owner sign-off or a reviewed spreadsheet is the complete control system.
In practice
Layer
| Layer | Purpose | Minimum controlled artefacts |
|---|---|---|
| Governance and policy | Define accountability, risk appetite, roles, escalation, access, retention and change authority. | Reporting policy, RACI, committee terms, issue severity rules, sign-off and representation framework. |
| Disclosure architecture | Connect material IROs to requirements, datapoints, narrative, metrics and report locations. | IRO register, disclosure matrix, information-materiality decisions and content owner map. |
| Data dictionary | Create one approved meaning for every metric and key narrative population. | Definition, unit, boundary, population, source, method, estimates, owner, reviewer, frequency and standard version. |
| Source and evidence register | Make source evidence findable and protect restricted material. | Evidence ID, claim/datapoint link, source, period, owner, access class, review status, retention and locator. |
| Calculation and model layer | Control transformations, formulas, factors, proxies, estimates and consolidation. | Version-controlled workbook/model, input-output map, formula checks, factor register, assumptions and validation. |
| Operational controls | Prevent or detect incomplete, inaccurate, late, unauthorised or inconsistent information. | Access controls, reconciliations, variance analysis, cut-off, duplicate checks, local and central review evidence. |
| Reporting and release | Ensure disclosed text and figures match approved information and claims. | Disclosure proof, source-to-report tie-out, legal review, assurance adjustments, board approval and release archive. |
| Monitoring and remediation | Track control failures, data gaps, findings and improvement. | Issue log, root cause, owner, due date, compensating control, closure evidence and recurring-finding analysis. |
In practice
Evidence class
| Evidence class | Examples | Control expectation |
|---|---|---|
| Public / publishable | Approved policy, public target, published methodology, disclosed table and assurance report. | Version and publication approval; reconcile to the report and website. |
| Internal controlled | System extracts, calculations, reconciliations, management review, local sign-off and methodology papers. | Named owner, period, immutable or versioned copy, reviewer evidence and retention. |
| Restricted | Personal data, grievances, investigation files, legal advice, commercially sensitive contracts and security information. | Need-to-know access, legal basis, privacy/privilege review, redacted reporting output and controlled assurance access. |
| External / third party | Supplier data, emission factors, geospatial tools, expert reports, certification and assurance evidence. | Source, date, scope, competence, licence, reliability assessment and change monitoring. |
Hypothetical scenario
ILLUSTRATIVE CONTROL MATRIX
<p>This matrix is an LRA implementation example. It is not a complete control framework and must be tailored to actual reporting risks, systems, material IROs, legal requirements and assurance scope.</p>
Illustrative only. It shows how the decision is made, not wording that can be copied or relied on.
In practice
Risk / assertion
| Risk / assertion | Illustrative control | Owner / frequency — Evidence retained |
|---|---|---|
| Completeness of reporting population | Quarterly reconcile legal entities, sites and significant operations to financial consolidation and approved ESRS boundary; investigate differences. | Group reporting + finance / quarterly and close — Population reconciliation, exceptions and approval. |
| Completeness of source data | Compare received submissions with expected entities and source-system populations; follow up missing or zero values. | Datapoint owner / each cycle — Submission tracker, source count and exception closure. |
| Accuracy of calculation | Independent reviewer recalculates material formulas and checks unit conversions, factors and manual adjustments. | Technical reviewer / each reporting period — Reperformance sheet, reviewer sign-off and resolved findings. |
| Estimate accuracy and integrity | Approve estimation method; perform reasonableness and sensitivity review; compare estimates with later actual data where available. | Method owner + finance / at design and close — Method paper, sensitivity, back-test and limitation note. |
| Cut-off and period | Define incident, workforce and transaction cut-off; review late items and events after reporting period. | Functional owner / period end — Cut-off checklist, late-item log and decision. |
| Boundary and classification | Sample records against legal-entity, worker, emissions, site or product classification rules; review exceptions. | Data owner + central review / quarterly — Sample file, exception analysis and correction evidence. |
| Narrative validity and balance | Trace each material claim to evidence; challenge causal and effectiveness statements; check adverse results and limitations. | Reporting + legal / draft and final — Claim ledger, legal comments and approved wording. |
| Change control | Require approval for definition, formula, factor, source or boundary changes; assess comparative and disclosure effect. | Method governance group / as needed — Change request, testing, approval and restatement decision. |
| Access and segregation | Restrict edit rights; separate preparer, reviewer and approver where practical; review access periodically. | IT + process owner / quarterly — Access listing, review sign-off and remediation. |
| Source-to-report tie-out | Tie final disclosed values and key narrative to approved calculation/evidence versions and confirm report locator. | Reporting owner / final release — Tie-out sheet, final proof and version hash. |
| Issue remediation | Classify findings, assign owner/due date, assess disclosure impact and verify closure; escalate overdue significant issues. | Programme lead / ongoing — Issue log, root-cause analysis and closure evidence. |
| Management representation | Data owners and executives confirm responsibility, completeness, known limitations, fraud/error concerns and post-close changes. | Management / final close — Signed representations and exception schedule. |
Hypothetical scenario
ILLUSTRATIVE WORDING
<p>“Sustainability reporting controls cover the group reporting boundary, material IRO-to-disclosure mapping, metric definitions, data extraction and consolidation, significant estimates, narrative claims and final publication. Functional owners prepare information using the group data dictionary; central reviewers perform population, reconciliation, variance and evidence checks. Significant methodology changes and unresolved control issues are escalated to [body]. During the period, the group identified [nature of significant limitation] and implemented [remediation], with [remaining limitation] at the reporting date.”</p>
Illustrative only. It shows how the decision is made, not wording that can be copied or relied on.
Hypothetical scenario
ILLUSTRATIVE SCENARIO
<p>A group reports training hours for employees and non-employee workers. Three subsidiaries include contractors in the denominator, two exclude them, and one submits total course registrations rather than completed hours. The consolidated trend appears favourable.</p>
Illustrative only. It shows how the decision is made, not wording that can be copied or relied on.
In practice
Weak pattern
| Weak pattern | Risk | Stronger pattern |
|---|---|---|
| Data owner emails a spreadsheet and confirms it is correct. | No controlled definition, population evidence, independent review or reproducible version. | Use an approved dictionary, controlled template or system, evidence index, reviewer control and retained final version. |
| Assurance provider finds and explains all errors. | Transfers management responsibility and leaves no sustainable internal process. | Management designs and operates controls; assurance independently evaluates within the engagement scope. |
| Only quantitative metrics are controlled. | Narrative claims, due-diligence statements, target progress and limitations can be materially misleading. | Include narrative claims, legal statements, methods, omissions and presentation in the control universe. |
| Method changes are made directly in the workbook. | Comparability, audit trail and disclosed methodology can become inconsistent. | Use formal change request, testing, approval, versioning and comparative impact assessment. |
Myth
“Limited assurance means the assurance provider owns the data-quality risk.”
Reality
Management remains responsible for the sustainability statement, methods, evidence, judgements and internal controls. Limited assurance involves less extensive procedures than reasonable assurance and does not replace management’s control system or guarantee that every error will be detected.
In practice
Source
| Source | Role in this article | Official link |
|---|---|---|
| European Commission, Commission Delegated Regulation C(2026) 5010 and annexes, 3 July 2026 | Commission-adopted revised ESRS text, explanatory memorandum, application and transition context | Open source |
| Commission Delegated Regulation (EU) 2023/2772 | Current ESRS legal baseline at the source-check date | Open source |
| European Commission adoption announcement, 3 July 2026 | Adoption and scrutiny status of revised ESRS | Open source |
| Commission-adopted revised ESRS annex, 3 July 2026 | GOV-4, AR 10, GDR-M and qualitative characteristics | Open source |
| CEAOB guidelines on limited assurance, 30 September 2024 | High-level limited-assurance context and risk-based procedures; subject to national requirements | Open source |
| Accounting Directive, consolidated 18 March 2026 | EU reporting and assurance legal context | Open source |
Rule
INTERNAL PRODUCTION NOTE
<p>This section is for editorial, CMS, AI and technical-review workflows. It is not intended to be published as part of the public article body.</p>
Rule
PUBLICATION GATE
<p>Confirm the applicable legal text and reporting period, review all normative claims against the final Official Journal text, adapt examples to the undertaking, and obtain technical, legal, assurance and editorial sign-off before release.</p>
In practice
Instrument / requirement
| Instrument / requirement | Relationship | Role and limitation |
|---|---|---|
| Revised ESRS 2 GOV-4 | Direct | Scope, main features and components of risk management and internal controls over sustainability reporting. |
| Revised ESRS 2 GOV-4 AR 10 | Direct | Completeness and integrity of data and accuracy of estimation results. |
| Revised ESRS 2 GDR-M | Direct | Metric, unit, method, sources, estimates, proxies, context and changes. |
| Revised ESRS 1 qualitative characteristics | Supporting | Relevance, faithful representation, comparability, verifiability and understandability. |
| CEAOB limited-assurance guidelines / national pronouncements | Assurance context | Evidence and risk-based procedures; not a control framework or assurance conclusion. |
Take it with you
The checklists as a working spreadsheet
Every checklist and table on this page, with empty status, owner and evidence columns for your team to fill in and keep.
✓ LRA AI Assistant · Human-in-the-loop
Ask about this guide
It answers from this page, and reaches into the linked disclosure cards when your question is about the standard itself. Your first two answers are free without signing in.
Go deeper · ESRS
ESRS and CSRD training
Double materiality, datapoints and the sustainability statement, with a mentor on your own report.
Available as Guided Flex, Live Cohort, 1:1 Expert Mentorship or Corporate Programme.