Short answer
The answer, before the reasoning
GRI 2-5 does not require an organisation to obtain external assurance. It requires the organisation to describe its policy and practice for seeking assurance, including whether and how the highest governance body and senior executives are involved.
If any sustainability reporting has been externally assured, the organisation must link or refer to the provider’s report or statement, explain what was assured and on what basis — including the assurance standard, level and limitations — and describe its relationship with the provider. Internal audit, management sign-off, data validation and performance certification can strengthen credibility, but they are not automatically external assurance.
GRI 2-5 requires transparency over the assurance approach and, where assurance exists, over the engagement’s scope, basis, level, limitations and provider relationship.
In practice
At a glance
| Question | Practical answer |
|---|---|
| Does GRI require external assurance? | No. GRI recommends external assurance, but it is not a condition for reporting in accordance or with reference. |
| What must always be disclosed? | The organisation’s policy and practice for seeking external assurance and whether and how governance and senior executives are involved. |
| What is added when assurance was obtained? | A link or reference to the report or statement; the assured subject matter and basis; assurance standard, level and limitations; and the provider relationship. |
| Can internal audit be called assurance? | Not external assurance. Internal audit can test systems and controls, but it is an internal function and does not create an independent external conclusion. |
| Does limited assurance cover the whole report? | Only if the signed assurance statement says so. Scope may be limited by indicators, entities, sites, periods, methods or sections. |
Why GRI 2-5 is often misunderstood
The disclosure sits in the reporting-practices section of GRI 2, so it is sometimes reduced to a one-line sentence such as “selected information was assured”. That wording rarely tells the reader what the engagement covered, what level of assurance was obtained, which criteria were used or whether the provider’s conclusion applies to the whole report.
The opposite error is to treat GRI 2-5 as an obligation to buy assurance. GRI explicitly recommends external assurance as a way to strengthen credibility, but the Universal Standards do not make it mandatory. The reporting obligation is transparency about the organisation’s policy and practice and, where assurance exists, transparency about the engagement.
Rule
REQUIREMENT / RECOMMENDATION BOUNDARY
Requirement: disclose the policy and practice, governance involvement and — where assurance has occurred — the assurance report, scope, basis, level, limitations and provider relationship. Recommendation: seek external assurance. Good practice: retain an engagement-scoping and publication-control file that reconciles the report wording to the signed assurance statement.
In practice
What GRI 2-5 requires
| Required element | What the reader should be able to understand | Evidence normally retained |
|---|---|---|
| Policy and practice for seeking external assurance | Whether assurance is routinely sought, selectively commissioned, planned for future periods or not currently obtained. | Assurance policy, reporting procedure, prior engagements, procurement and approval records. |
| Highest governance body and senior executive involvement | Whether and how they approve policy, scope, provider appointment, findings or publication wording. | Committee terms of reference, agendas, minutes, approval papers and management sign-off. |
| Assurance report or statement | Where the signed external conclusion can be found. | Final signed statement, publication permission and stable link. |
| What was assured and on what basis | The subject matter, reporting boundary, criteria, period and any exclusions. | Engagement letter, scope schedule, content-index mapping and criteria list. |
| Assurance standard and level | The professional standard or framework used and whether the engagement provided limited, reasonable or another clearly defined level. | Assurance report, engagement acceptance and technical review. |
| Limitations | Any scope, evidence, methodological, system or availability constraints stated by the provider. | Provider’s limitation wording, data-gap log and management response. |
| Relationship with provider | The nature of the relationship and information relevant to independence. | Appointment, tenure, non-assurance services, safeguards and conflicts review. |
Rule
REFERENCE THE SIGNED STATEMENT PRECISELY
Where the linked assurance statement already contains the required details, the GRI disclosure can be concise. The reference must still be stable, precise and consistent with the statement; it should not broaden the scope or level through paraphrasing.
Assurance statement, limited review, internal audit and management validation
These labels describe different activities. The safest classification method is to read the signed output and identify who performed the work, the criteria, independence, scope, procedures, level and conclusion. The title used by management or a website button is not enough.
External assurance, internal audit, management validation and performance certification have different purposes, accountability and outputs.
In practice
| Activity | Typical output | What it can support — What it does not prove |
|---|---|---|
| External assurance engagement | Signed independent assurance report or statement under identified criteria and assurance standard. | Credibility of specified sustainability information within the defined scope and level. — Assurance over information outside the scope, or assurance over management performance itself. |
| Limited assurance / limited-review-style engagement | A negative-form conclusion based on procedures appropriate to a limited level, if performed as an assurance engagement. | A lower but meaningful level of confidence over the specified subject matter. — Reasonable assurance, a financial-statement audit opinion or assurance over the entire report unless explicitly scoped. |
| Internal audit | Internal report to management or an audit committee on controls, systems, governance or data. | Control improvement, testing evidence and assurance readiness. — An independent external conclusion for users of the published report. |
| Management validation or certification | Owner sign-off, representation, management review or system certification. | Accountability, process discipline and evidence that management reviewed the information. — External assurance or provider independence. |
| Performance or product certification | Certificate or opinion against product, site, system or performance criteria. | Credibility of the certified subject matter. — Assurance over the GRI report or other sustainability information outside that subject matter. |
How to describe scope and level without overstating the engagement
Assurance scope is multi-dimensional. A statement such as “our ESG data was assured” leaves unanswered whether the provider covered the complete sustainability statement, selected GRI disclosures, selected metrics, one region, a subset of entities, a methodology or only the calculation process. The report wording should mirror the signed statement across every scope dimension.
In practice
| Scope dimension | Control question | Example of precise wording |
|---|---|---|
| Information covered | Which disclosures, metrics, narrative sections or claims were within the engagement? | “Limited assurance covered Scope 1 and Scope 2 emissions and total energy consumption.” |
| Entities and operations | Which subsidiaries, sites, joint ventures or value-chain information were included? | “The scope covered consolidated entities and excluded two recently acquired sites listed in the assurance statement.” |
| Reporting period | Which dates and comparative figures were covered? | “The engagement covered the year ended 31 December 2026; prior-year comparatives were not assured.” |
| Criteria | Against what reporting criteria or methodologies was the information evaluated? | “The subject matter was evaluated against the GRI Standards cited in the content index and the emissions methodology note.” |
| Level | Was the conclusion limited, reasonable or otherwise defined? | “The provider expressed a limited assurance conclusion.” |
| Limitations | What restrictions or data constraints affected the work? | “Supplier estimates were included in the reported metric but excluded from the provider’s assurance scope.” |
Provider relationship and independence
GRI 2-5 requires the organisation to describe its relationship with the assurance provider. GRI guidance emphasises independence, competence and objective assessment. The public description does not need to reproduce the provider’s entire ethics analysis, but it should avoid implying independence where material relationships or services have not been considered.
Name the provider and its professional role.
State whether the provider also audits the financial statements or supplies other services relevant to independence.
Explain governance responsibility for appointment and oversight.
Describe safeguards or separation where non-assurance services exist and the information is material to users.
Do not write “independent” solely because the provider is external; independence is a substantive condition.
Reconcile the relationship disclosure with procurement, audit-committee and provider statements.
In practice
A practical drafting and control process
| # | Step | Action — Owner / input — Output / control |
|---|---|---|
| 1 | Collect the signed source documents | Obtain the final engagement letter, scope schedule, signed assurance statement, criteria list and provider publication permission. — Reporting owner + legal/procurement — Controlled assurance source pack. |
| 2 | Extract the engagement facts | Record subject matter, boundary, period, criteria, assurance standard, level, limitations and conclusion. — Technical reporting lead — Assurance factsheet. |
| 3 | Map assured items to the report | Link each assured disclosure or metric to its published location and identify unassured adjacent information. — Content-index owner — Scope-to-report mapping. |
| 4 | Confirm governance involvement | Document policy approval, provider appointment, scope decisions, findings and publication approval. — Company secretary / governance lead — Governance evidence record. |
| 5 | Assess the provider relationship | Confirm independence review, tenure, other services and safeguards with the responsible governance body. — Audit committee + procurement — Relationship disclosure basis. |
| 6 | Draft and challenge the disclosure | Compare every public phrase to the signed statement and remove any broadened scope, level or conclusion. — Author + technical reviewer — Approved GRI 2-5 wording. |
| 7 | Test the final links | Confirm the assurance statement is accessible, correctly titled and available when the report is published. — Publisher — Publication QA record. |
Illustrative case: selected metrics under limited assurance
A diversified manufacturer publishes a GRI-based sustainability report. Its audit committee approves a two-year assurance policy. In the first year, the provider performs limited assurance over Scope 1 and Scope 2 greenhouse-gas emissions, total energy consumption, total workforce and lost-time injury frequency. Scope 3 estimates and narrative statements are outside the engagement.
Illustrative GRI 2-5 disclosure
Illustrative wording — adapt to the organisation’s facts, reporting boundary and applicable requirements.
The example demonstrates how to disclose a selective engagement without suggesting that the entire report was assured.
The policy and governance roles are explicit.
The four assured metrics are named and the unassured areas are not hidden.
The level, standard, criteria and period are stated.
The provider relationship and independence oversight are described.
The reader is directed to the signed conclusion rather than a management summary.
Rule
ADAPTATION WARNING
Replace the assurance standard, level, scope, provider relationship and governance description with the facts of the actual engagement. Do not cite ISSA 5000 unless it was the standard used.
In practice
Weak and stronger drafting
| Weak wording | Why it is weak | Stronger wording pattern |
|---|---|---|
| “Our sustainability report was externally assured.” | Scope, level, criteria, period and limitations are unknown. | Name the exact assured information, level, standard, period and location of the signed statement. |
| “The data were reviewed by internal audit.” | This is valuable internal control evidence but not external assurance. | Describe internal audit under internal controls and separately disclose any external assurance. |
| “Independent assurance was provided by our auditor.” | The relationship and basis for independence are not explained. | Describe the provider relationship, governance oversight and any relevant other services. |
| “Limited assurance confirms the data are accurate.” | An assurance conclusion is not a guarantee and the wording may misstate the signed conclusion. | Use the provider’s engagement title and refer readers to the signed conclusion. |
| “Selected KPIs were assured.” | Users cannot identify which KPIs or adjacent information are unassured. | List the KPIs or provide a precise mapping and state material exclusions. |
In practice
Common mistakes
| Common mistake | Why it creates risk | Correction |
|---|---|---|
| Treating external assurance as mandatory under GRI. | The organisation overstates the standard and may procure an engagement without a clear reporting objective. | Separate GRI’s recommendation to seek assurance from the disclosure requirements of 2-5. |
| Calling internal audit or management sign-off “external assurance”. | Users receive a false impression of independence and professional conclusion. | Use the exact activity label and describe external assurance only where an independent engagement exists. |
| Writing that the report is assured when only selected metrics are in scope. | The assurance claim extends beyond the provider’s conclusion. | Name the assured subject matter and material exclusions. |
| Omitting the assurance level or standard. | Users cannot understand the nature and strength of the conclusion. | State the level and professional standard exactly as in the signed statement. |
| Publishing a broken or temporary assurance link. | The mandatory reference is not accessible to report users. | Use a stable publication location and test it at final QA. |
| Ignoring the provider relationship. | Independence questions remain unanswered and the disclosure is incomplete. | Describe appointment, relevant other services and governance safeguards. |
In practice
Myth versus reality
| Layer | Statement |
|---|---|
| MYTH | A GRI report is only credible — or only “in accordance” — if the entire report receives external assurance. |
| REALITY | GRI recommends assurance but does not make it a condition of either reporting route. Credibility also depends on reporting principles, controls, evidence and accurate claims. Where assurance is obtained, its scope and level must be described without implying coverage beyond the signed conclusion. |
| PRACTICAL CONSEQUENCE | Design assurance around material information, user needs and evidence maturity, then communicate the engagement precisely. |
Readiness
GRI 2-5 disclosure checklist
- The assurance policy and current practice are described.
- The involvement of the highest governance body and senior executives is clear.
- The signed assurance report or statement is linked or precisely referenced.
- Every assured metric, disclosure, section, entity, site and period can be identified.
- The reporting criteria and assurance standard are stated.
- The assurance level uses the provider’s exact terminology.
- Material limitations and exclusions are visible.
- The provider relationship and relevant independence oversight are described.
- The report wording does not broaden the provider’s conclusion.
- Internal audit, management validation and certification are labelled separately.
- The content index and assurance scope mapping agree.
- The final link is accessible and publication permission is recorded.
- Governance approval and management representations are retained.
Sources
Primary sources
Take it with you
The checklists as a working spreadsheet
Every checklist and table on this page, with empty status, owner and evidence columns for your team to fill in and keep.
✓ LRA AI Assistant · Human-in-the-loop
Ask about this guide
It answers from this page, and reaches into the linked disclosure cards when your question is about the standard itself. Your first two answers are free without signing in.
Go deeper · GRI
GRI Standards Certified Training
A full reporting cycle with a mentor: impact inventory, threshold, Topic Standard selection, Content Index and assurance readiness.
Available as Guided Flex, Live Cohort, 1:1 Expert Mentorship or Corporate Programme.
