Skip to the answer

Disclosure GuidesPillar guides, articles, FAQ and expert notes

Level 2 · Decision guide·ESRS · Disclosure guides

ESRS Data Governance and Internal Controls: From Datapoint Owners to Assurance Evidence

Reliable ESRS reporting depends on a controlled information system, not a year-end data chase. This guide provides a practical operating model, evidence architecture and sample control matrix for assurance-ready sustainability information.

Who this is for A 20-minute read for reporting teams working through Running the reporting cycle: governance, data and controls, and for reviewers testing whether the evidence behind it holds.
RK Published passportReviewed by Dr Ross Kurinko Strategic ESG Advisor · IFRS S1 & S2 / GRI / ESRS Current as at
GRI and ISSB-IFRS S1 & S2 Certified Global Trainer · PhD, University of Cambridge · ESG-AI expert 15+ years on FTSE 100 & Fortune Global 500 disclosures Canary Wharf, London LRA educational guidance · Not issued or endorsed by European Commission LinkedIn

Edition written against

ESRS 2023 legal baseline and Commission-adopted revised ESRS 2026, with explicit version gate

Published

10 Aug 2026

Knowledge Hub guide

Last reviewed

10 Aug 2026

Short answer

The answer, before the reasoning

An ESRS control system should connect every material disclosure to a defined owner, controlled methodology, source data, calculation, evidence file, reviewer, approval and report location. The core operating tools are a disclosure matrix, data dictionary, evidence register, calculation inventory, control matrix, issue log and sign-off record.

External assurance can test this system, but it cannot replace management's responsibility for complete, accurate, balanced and traceable sustainability information.

Prepared in British English as a practitioner Knowledge Card Package: answer, explanation, application, evidence, connections and publishing layer.

Why data governance is more than a spreadsheet problem

ESRS reporting combines information with very different characteristics: consolidated metrics, estimates, site data, value-chain information, policies, targets, forward-looking plans, qualitative judgements and narrative claims. These items may originate in finance systems, HR platforms, environmental logs, procurement tools, legal records, surveys, consultant models and manually maintained files. A single sustainability statement may therefore depend on hundreds of contributors and transformations that are invisible in the published report.

The reporting risk is not limited to an incorrect number. Material misstatement can also arise from:

an omitted disclosure or missing entity;

the wrong boundary, period, unit or definition;

an unsupported statement about policy implementation or effectiveness;

a changed model that has not been approved;

an estimate presented without its assumptions or limitations;

a target that does not reconcile to its baseline;

a late adjustment that bypasses review;

a version of the report that no longer matches the controlled evidence pack.

The objective is not to create finance-style controls for their own sake. It is to build an information chain that allows management, the board and the assurance provider to understand where information came from, why it is appropriate, how it was reviewed and what limitations remain.

Figure 1
Data-lineage architecture from material IRO and source systems through data dictionary, calculations, evidence, review controls, assurance and published ESRS disclosure.
ESRS data lineage from source systems to published disclosure and assurance evidence. Branded educational visual by London Reporting Academy. · London Reporting Academy

Quick orientation

Quick orientation
Practical answer
Applies to
Companies and groups designing or improving ESRS reporting controls
Primary decision
How to organise ownership, evidence, calculations, review and remediation
Current ESRS anchor
ESRS 2 GOV-5 under the 2023 standards
Revised ESRS anchor
ESRS 2 GOV-4 and AR 10 in the adopted 2026 standards
Common confusion
Believing that an evidence folder or external assurance engagement is itself an internal control system

What ESRS requires - and what it does not prescribe

The current 2023 ESRS require the undertaking to disclose the main features of its risk management and internal control system in relation to the sustainability reporting process. The disclosure includes the scope and main components of the system, the risk assessment and prioritisation approach, the principal risks and mitigation strategies, integration of findings into internal functions and periodic reporting to administrative, management and supervisory bodies.

The adopted 2026 ESRS simplify the main disclosure to the scope, main features and components of the risk management and internal control processes and systems. The related Application Requirement says the undertaking shall consider the completeness and integrity of data and the accuracy of estimation results as relevant aspects of reporting risk management.

ESRS does not prescribe one control framework, one software product, one three-lines model, one evidence folder structure or one mandatory frequency for every control. The organisation must design proportionate controls for its reporting risks, structure and data maturity. It may align the system with existing financial reporting, enterprise risk management, compliance or internal audit processes, but the design must address the distinctive risks of sustainability information.

A practical operating model

A reliable model separates preparation, ownership, review and approval while avoiding an unmanageable number of hand-offs.

For a smaller undertaking, one person may perform several operational roles. However, significant information should not be prepared and finally approved by the same individual without an additional review.

Three linked levels of control

1. Entity-level controls govern scope, responsibilities, reporting policy, risk assessment, ethics, escalation and board oversight.

2. Process-level controls govern data collection, consolidation, calculations, estimates, narratives, close and report assembly.

3. Disclosure-level controls verify a particular metric or statement against its specification, evidence and ESRS presentation requirements.

A mature system links all three. A perfectly recalculated metric can still be misleading if the entity boundary was wrong. A well-designed group policy can still fail if a site uploads an uncontrolled workbook.

In practice

Role Primary responsibility Evidence of responsibility
Sustainability reporting owner Overall reporting architecture, disclosure matrix, close calendar and final assembly Reporting policy, timetable, final sign-off and issue escalation
Datapoint or disclosure owner Accountable for the definition, boundary, source, result and explanation Owner certification and approved specification
Data preparer Extracts, compiles or calculates information in accordance with the specification Source extract, calculation file and preparer sign-off
Control owner / reviewer Performs an independent review or control procedure Review evidence, exceptions and approval
Methodology owner Approves formulas, factors, assumptions, estimation methods and changes Methodology paper and version history
System owner Maintains source-system access, configuration, data lineage and change records Access report, change ticket and system documentation
Evidence custodian Maintains the evidence register, retention, restricted access and archive Controlled repository and evidence index
Narrative claim owner Supports policies, actions, progress and effectiveness statements Policy, minutes, action records, outcome evidence and claim approval
Technical ESRS reviewer Confirms disclosure requirement, materiality, boundary and presentation Technical review notes and disclosure sign-off
Assurance coordinator Coordinates requests and tracks findings without taking over management ownership Prepared-by-client list, request tracker and resolution log
Management / board approver Challenges significant judgements, unresolved issues and final statement Committee papers, minutes and representation records

The controlled disclosure matrix

The disclosure matrix is the organising layer between materiality and data collection. It should record, for each material IRO and applicable disclosure:

ESRS standard, DR, paragraph or datapoint;

material topic and IRO linkage;

reporting boundary and period;

disclosure owner and contributor;

quantitative or narrative status;

data dictionary or narrative specification ID;

source system or evidence category;

calculation or methodology ID;

control ID and review frequency;

report section and cross-reference;

assurance status and open findings;

current version and last change date.

A list of ESRS datapoints is not yet a control matrix. The organisation must determine which information is material, how it applies to its facts and which evidence supports fair presentation.

The data dictionary: one approved meaning for each metric

A data dictionary prevents different sites, functions and periods from using the same label for different information. Each controlled metric record should contain at least:

The dictionary should be approved before the final data call. Changing definitions during the close creates inconsistent comparatives and undocumented management bias.

In practice

Dictionary field What to document
Metric ID and name Stable identifier and reader-friendly label
ESRS linkage DR, datapoint, topic and IRO supported
Definition Inclusion and exclusion criteria in plain and technical language
Unit and sign convention Tonnes, MWh, headcount, percentage, currency and treatment of negative values
Reporting period and cut-off Start/end dates, accrual or event basis and late-data treatment
Organisational boundary Entities, operations, sites, joint arrangements and exclusions
Value-chain boundary Categories, counterparties, geography and estimation perimeter where relevant
Source hierarchy Preferred source system, accepted alternatives and prohibited sources
Formula and transformations Calculation steps, factors, conversions, allocation and rounding
Estimate method Model, assumptions, uncertainty, validation and improvement plan
Comparative and restatement rule Baseline, prior-period treatment and material-change criteria
Owner / preparer / reviewer Named roles with due dates and segregation
Evidence requirement Source extract, invoice, log, policy, confirmation, model or approval
Control IDs Completeness, accuracy, boundary, calculation and review controls
Version and effective date Current specification and change history

The evidence register: traceability without uncontrolled duplication

An evidence register records where support is held and how it relates to a disclosure. It is not necessary to copy every source document into one folder, but the link must be durable and accessible to authorised reviewers.

Recommended fields include:

evidence ID, title and description;

related metric, narrative claim, target or judgement;

source owner and custodian;

original system or repository;

reporting period and extraction date;

version, file hash or immutable identifier where available;

access classification: public, internal, restricted, privileged or personal data;

retention period;

review performed and reviewer;

limitations or missing support;

link to issue and remediation record;

final report version supported.

Evidence quality hierarchy

Evidence is stronger when it is contemporaneous, complete, independently generated or system-controlled, directly linked to the reported period and capable of reperformance. A management explanation may be necessary, but it should not replace source records where those records should exist.

For narrative disclosures, evidence may include approved policies, board minutes, programme records, contracts, stakeholder engagement logs, grievance data, training attendance, budgets, action trackers and outcome analysis. A policy proves that wording was approved; it does not by itself prove implementation or effectiveness.

Calculation, model and estimate controls

Sustainability metrics frequently require transformations that are more complex than the final number suggests. A calculation inventory should identify every workbook, script, model and external calculation used in reporting.

Minimum controls include:

1. Formula approval. The methodology owner confirms the formula, factors, units and boundary.

2. Source-to-input reconciliation. Inputs reconcile to source-system totals or documented extracts.

3. Automated or independent recalculation. A reviewer reproduces significant calculations or tests formula integrity.

4. Factor governance. Emission factors, conversion rates and classification tables have source, version and effective period.

5. Estimate validation. Assumptions are reasonable and supportable, uncertainty is assessed and actual outcomes are compared with prior estimates where possible.

6. Change control. Model changes require a documented reason, impact assessment, approval and comparative review.

7. Protection. Locked cells, code repositories, access permissions and controlled master files reduce accidental or unauthorised changes.

8. Output reconciliation. Final tables and narrative values reconcile to the approved calculation output and report version.

A spreadsheet can be controlled if ownership, versioning, access, formula review and evidence are disciplined. A sophisticated platform can be uncontrolled if definitions or approvals are weak.

Access, security, confidentiality and privacy

The evidence required for ESRS may include personal information, grievances, worker records, supplier findings, legal advice and commercially sensitive assumptions. Broad access is not evidence transparency.

A practical access model should:

apply least-privilege permissions;

separate preparer, reviewer and administrator rights where proportionate;

restrict personal and grievance data and provide de-identified reporting extracts;

identify legally privileged or investigation material;

prevent deletion or silent overwriting after approval;

retain access logs for high-risk repositories;

use controlled transfer methods for subsidiaries and external providers;

define what the assurance provider may inspect and how restricted evidence will be handled;

revoke access after role changes or project completion.

The public report should be traceable to evidence without disclosing confidential details that are unnecessary for the statement.

Review, certification and sign-off

A reviewer should do more than confirm that a field is populated. The review should address the assertion relevant to the information.

A staged sign-off model commonly includes:

preparer certification;

datapoint owner approval;

control-owner review;

technical ESRS review;

functional or legal review for sensitive narratives;

topic-level management sign-off;

group reporting certification;

final management and board approval.

Sign-offs should identify the exact data and report version approved. A generic email saying “looks fine” is weak evidence.

In practice

Assertion Reviewer question
Completeness Are all required entities, sites, events, categories and disclosures included?
Accuracy Does the information agree to source data and approved calculations?
Boundary Does the result use the approved organisational and value-chain perimeter?
Cut-off Is the information recorded in the correct period and are late items controlled?
Classification Are definitions, categories and units applied consistently?
Presentation Is the report balanced, understandable and consistent with the evidence?
Occurrence / existence Did the described action, event or outcome actually occur?
Rights and approval Is the policy, target or commitment approved by the appropriate authority?
Estimate integrity Are assumptions supportable, unbiased, documented and appropriately disclosed?

Change control, corrections and restatements

Every controlled information item needs a rule for changes after initial submission. The change log should record:

item and version changed;

date and person making the change;

reason: new source data, error correction, methodology change, boundary change or presentation edit;

quantitative and qualitative impact;

effect on comparatives, targets, financial effects and connected disclosures;

required re-performance of controls;

approvals obtained;

whether the assurance provider and board were informed;

final report version affected.

Late changes should follow a defined threshold and escalation route. The objective is not to prohibit correction, but to ensure that a correction does not create new inconsistencies elsewhere in the statement.

Management representations

Management representations support accountability; they do not replace evidence or controls. The CEAOB's non-binding limited-assurance guidelines state that practitioners should request a representation letter signed by at least one responsible member of senior management or those charged with governance, including confirmation of responsibility for the sustainability statements.

An internal representation process may ask responsible executives to confirm that, to the best of their knowledge:

information in their area is complete and prepared under approved definitions;

significant estimates, judgements and limitations have been disclosed;

known errors, fraud concerns and non-compliance relevant to the statement have been reported;

material subsequent events and changes have been communicated;

policies, actions and targets are accurately described;

evidence has been retained and is available;

unresolved issues are listed rather than concealed.

The representation letter is the final layer of responsibility, not a cure for missing source documentation.

Issue management and remediation

Findings should be managed in one controlled issue log, whether they arise from management review, internal audit, assurance, regulator feedback or post-publication correction.

A useful workflow is:

1. Log the issue with affected disclosure, source, control and report version.

2. Classify the issue: data, boundary, method, evidence, control execution, narrative, presentation or governance.

3. Assess severity based on potential misstatement, pervasiveness, regulatory risk and time to publication.

4. Contain the immediate risk, such as suspending a number or restricting an unsupported claim.

5. Correct the current-period information and reperform affected controls.

6. Analyse root cause: design failure, execution failure, capacity, system, definition or oversight.

7. Remediate with owner, deadline, funding and success evidence.

8. Validate closure independently and update the control matrix, dictionary or methodology.

9. Report significant or overdue issues to management and the board.

Closing an assurance request is not the same as remediating the underlying process. Sustainable closure changes the system that caused the finding.

Sample ESRS control matrix

The matrix below is illustrative. Control frequency and evidence should be tailored to risk, reporting timetable and system maturity.

Figure 2. Illustrative ESRS control matrix linking risks, controls, owners and evidence. Branded educational visual by London Reporting Academy.

How to use the matrix

Each control should have a separate design record specifying objective, population, procedure, evidence, reviewer competence, failure criteria and escalation. The table in the report may describe the overall system; the detailed matrix remains internal evidence.

In practice

Control ID Reporting risk / assertion Illustrative control activity — Owner / reviewer — Frequency — Evidence retained
GOV-01 Incomplete disclosure population Reporting owner reconciles material IROs and applicable DRs to the disclosure matrix; exceptions require technical approval — Reporting owner / ESRS reviewer — At DMA approval and pre-close — Approved disclosure matrix and exception log
BND-01 Missing or incorrectly included entities/sites Finance consolidation list is reconciled to the sustainability reporting boundary; changes are investigated — Group controller / reporting lead — Quarterly and final close — Reconciliation, entity list and approval
DAT-01 Inconsistent definitions Data call uses only current dictionary versions; local owners certify application of inclusions and exclusions — Datapoint owner / control owner — Each submission — Dictionary version and certification
CMP-01 Incomplete source extraction System totals, record counts or control totals are reconciled to uploaded inputs — Data preparer / reviewer — Each extraction — Source extract and reconciliation
ACC-01 Formula or unit error Significant calculations are independently recalculated; formula changes are compared with the prior version — Methodology owner / independent reviewer — Each close and change — Recalculation and change log
EST-01 Biased or unsupported estimate Assumptions, source hierarchy, uncertainty and alternatives are reviewed and approved; back-testing is performed where possible — Model owner / finance or technical reviewer — Each estimate cycle — Estimate paper, approval and validation
CUT-01 Wrong-period data Cut-off rules are applied; late submissions and post-close adjustments require escalation — Datapoint owner / group reporting — Final close — Late-item log and adjustment approval
NAR-01 Unsupported narrative or effectiveness claim Each significant claim is linked to evidence; claims of outcomes require outcome evidence and balanced limitations — Narrative owner / legal or technical reviewer — Drafting and final review — Claim ledger and marked-up draft
TAR-01 Target does not reconcile to baseline or scope Target boundary, baseline, methodology and progress calculation are reconciled and reapproved after changes — Strategy owner / control reviewer — Annual and on change — Target specification and reconciliation
ACS-01 Unauthorised alteration or data exposure Access rights are reviewed; approved files are locked and restricted evidence is segregated — System owner / information security — Quarterly and at close — Access report and exception closure
CHG-01 Uncontrolled methodology or report change Changes require impact assessment, approval, control reperformance and comparative review — Methodology owner / reporting lead — On change — Change ticket and approvals
REP-01 Published report differs from approved data Final report tables and key narratives are reconciled to approved outputs; the publication file is checksum-locked — Publisher / reporting controller — Final publication — Final reconciliation and locked archive
ISS-01 Findings remain unresolved or hidden Open issues are reviewed by severity, ageing and publication impact; significant items are escalated — Programme director / steering committee — Fortnightly during close — Issue dashboard and minutes
GOV-02 Management unaware of reporting risks Control findings, estimates, significant judgements and unresolved issues are reported to the relevant committee and board — Reporting lead / company secretary — At defined governance gates — Board paper and minutes

Hypothetical example: controlling a Scope 3 estimate

Profile. A diversified manufacturer estimates purchased-goods emissions using procurement spend and industry emission factors because supplier-specific activity data are incomplete.

Initial risk. The procurement extract excludes two newly acquired entities, currencies are converted using different rates, factor versions are not documented and a consultant sends only the final number.

Control design. The group:

1. reconciles the entity list to financial consolidation;

2. extracts procurement spend under a controlled query and reconciles totals to finance;

3. applies one approved currency-conversion convention;

4. documents factor source, version, classification and effective period;

5. retains the model and requires sufficient detail for reperformance;

6. performs sensitivity analysis and identifies the largest uncertainty drivers;

7. compares the result with prior year and business activity changes;

8. obtains methodology and datapoint-owner approval;

9. discloses the estimate method and limitations proportionately;

10. records a plan to increase supplier-specific data coverage.

Assurance evidence. The evidence pack contains the consolidation reconciliation, procurement extract, mapping table, factor library, model, sensitivity analysis, review record and disclosure cross-reference.

Limitation. This is an illustrative control design. The appropriate GHG methodology, category boundary and disclosure depend on the undertaking's facts and applicable ESRS requirements.

In practice

Weak versus stronger control evidence

Weak evidence Why it is weak Stronger evidence pattern
“Reviewed” typed in a spreadsheet It does not identify who reviewed what, when or how Dated reviewer sign-off linked to the exact version, procedure performed and exceptions
Final consultant PDF only The calculation cannot be reperformed or changed assumptions identified Source inputs, model, methodology, factor references, version history and management review
Policy in the evidence folder Policy existence does not demonstrate implementation Approved policy plus implementation records, monitoring results, exceptions and corrective actions
Email approval of the report The approved content and version are ambiguous Formal sign-off sheet or workflow tied to the controlled publication file
Screenshot of a system total Population, extraction logic and completeness are unclear Controlled extract, query parameters, control totals and source-owner confirmation

Common mistakes and corrections

1. Assigning one “ESRS owner” to hundreds of datapoints. Allocate accountable owners at disclosure or metric level and identify contributors and reviewers.

2. Building the evidence register after drafting. Define evidence requirements in the dictionary and disclosure matrix before the data call.

3. Treating narrative disclosures as uncontrolled prose. Use a claim ledger and evidence review for policies, actions, targets, progress and effectiveness.

4. Using the same review for every metric. Design controls around the actual assertion and risk: completeness, boundary, cut-off, estimate or presentation.

5. Allowing local spreadsheets to overwrite group definitions. Lock master specifications and require documented exceptions.

6. Keeping models in external-provider systems only. Contract for data, methodology and outputs sufficient for management ownership and reperformance.

7. Using management representations to cover missing evidence. Representations supplement, but do not replace, records and controls.

8. Closing findings without root-cause remediation. Update the process, owner, system or control design and validate effectiveness.

9. Failing to control the final Word, design or tagging file. Reconcile the published version to approved data and archive the exact final package.

10. Overengineering low-risk datapoints while neglecting high-risk estimates and boundaries. Use a documented risk assessment to prioritise effort.

Readiness

Assurance-readiness checklist

  • Every material disclosure has an accountable owner and technical reviewer.
  • The disclosure matrix reconciles material IROs, DRs, data specifications, controls and report locations.
  • Data dictionary records are versioned and approved before the final data call.
  • Evidence requirements include quantitative and narrative disclosures.
  • Significant calculations and models can be reperformed from retained inputs.
  • Estimate assumptions, uncertainty, validation and improvement plans are documented.
  • Access rights and restricted evidence are reviewed and controlled.
  • Preparers and reviewers sign off the exact data or narrative version.
  • Changes, late adjustments and restatements follow a documented approval process.
  • Management representations list unresolved matters rather than concealing them.
  • Assurance and internal-review findings are tracked to root-cause remediation.
  • The final publication file reconciles to the controlled disclosure matrix and evidence archive.
  • Significant reporting risks and open issues are reported to the board or relevant committee.

Self-check

  1. Can a reviewer reproduce each significant metric from source evidence without relying on the preparer's memory?
  2. Can management identify which report claims are estimates, judgements, future plans or statements of effectiveness?
  3. Does closing an issue change the underlying reporting process, or only answer the immediate assurance request?

Related standards and guidance

• Current ESRS 2 GOV-5: risk management and internal controls over sustainability reporting.

• Adopted revised ESRS 2 GOV-4 and AR 10: scope, main features and components of the control system; consideration of data completeness, integrity and estimate accuracy.

• ESRS 1: fair presentation, qualitative characteristics, material information, estimates, value-chain information and preparation of the sustainability statement.

• GDR-M and GDR-T: methodology and contextual information for metrics and targets.

• EFRAG IG 3: non-authoritative datapoint inventory for the 2023 ESRS; useful for architecture, but not a substitute for materiality or control design.

• CEAOB limited-assurance guidelines: risk-based procedures, sufficient appropriate evidence, recalculation, reperformance, value-chain information and representation letters, subject to national pronouncements.

• ISSA 5000: comprehensive international standard for sustainability assurance engagements where adopted or otherwise applicable.

Frequently asked questions

Does ESRS require a formal internal-control framework?

ESRS requires disclosure of the reporting risk management and internal control system, but does not prescribe one named framework. The organisation should use a proportionate, documented system that addresses its material reporting risks.

Is an evidence register mandatory?

The standards do not prescribe a tool called an evidence register. It is a practical way to demonstrate traceability, ownership, access and review and is particularly useful for assurance readiness.

Can the sustainability team own all controls?

The central team can own the reporting framework, but source information should normally remain accountable to the relevant business, finance, HR, procurement, legal or operational owner. Independent review should be proportionate to risk.

Do limited-assurance providers test every control?

No. Assurance work is risk-based. The practitioner designs procedures to obtain sufficient appropriate evidence for the conclusion and may use inspection, observation, confirmation, recalculation, reperformance, analytics or inquiry. Management should not assume every control or datapoint will be tested.

How should narrative claims be controlled?

Create a claim ledger linking each significant statement to evidence, owner, review and report version. Distinguish policy existence, implementation activity, output, outcome and effectiveness.

Framework references

Disclosures this page affects

Take it with you

The checklists as a working spreadsheet

Every checklist and table on this page, with empty status, owner and evidence columns for your team to fill in and keep.

Download .xlsx

✓ Knowledge Hub AI Assistant · Human-in-the-loop

Ask about this guide

It answers from this page, and reaches into the linked disclosure cards when your question is about the standard itself. Your first two answers are free without signing in.

Try
Automated · the LRA team is one click away

Go deeper · ESRS

Certified ESRS (CSRD) Applied Sustainability Reporting

This page settles one Disclosure Requirement. The ESRS / CSRD course walks the whole European cycle — double materiality, datapoints, evidence and assurance — with drafting exercises on your own data.

See the course →
/en/knowledge-hub/disclosure-guides/esrs/esrs-reporting-cycle-and-controls/esrs-data-governance-and-internal-controls-from-datapoint-owners-to-as/