Skip to the answer

Disclosure GuidesPillar guides, articles, FAQ and expert notes

Level 2 · Explainer·GRI · Disclosure guides

GRI 2-5 External Assurance Explained: assurance policy, scope, level, provider independence, limitations and disclosure checklist

A practitioner guide to assurance policy, governance involvement, provider relationships and accurate disclosure wording

Who this is for A 11-minute read for reporting teams working through Data, evidence, controls and assurance, and for reviewers testing whether the evidence behind it holds.

Published passport

Current as at 11 August 2026
RK Reviewed by Dr Ross KurinkoLinkedIn Strategic ESG Advisor · IFRS S1 & S2 / GRI / ESRS expert GRI Certified Global Trainer · PhD, University of Cambridge · ESG-AI expert 15+ years on FTSE 100 & Fortune Global 500 disclosures Canary Wharf, London LRA educational guidance · Not issued or endorsed by GRI

Edition written against

GRI 2: General Disclosures 2021 Disclosure 2-5

TECHNICAL STATUS: Technical basis checked on 1 August 2026. Assurance terminology and effective dates must be …

Published

12 Aug 2026

Knowledge Hub guide

Last reviewed

11 Aug 2026

Short answer

The answer, before the reasoning

GRI 2-5 does not require an organisation to obtain external assurance. It requires the organisation to describe its policy and practice for seeking assurance, including whether and how the highest governance body and senior executives are involved.

If any sustainability reporting has been externally assured, the organisation must link or refer to the provider’s report or statement, explain what was assured and on what basis — including the assurance standard, level and limitations — and describe its relationship with the provider. Internal audit, management sign-off, data validation and performance certification can strengthen credibility, but they are not automatically external assurance.

GRI 2-5 requires transparency over the assurance approach and, where assurance exists, over the engagement’s scope, basis, level, limitations and provider relationship.

In practice

At a glance

Question Practical answer
Does GRI require external assurance? No. GRI recommends external assurance, but it is not a condition for reporting in accordance or with reference.
What must always be disclosed? The organisation’s policy and practice for seeking external assurance and whether and how governance and senior executives are involved.
What is added when assurance was obtained? A link or reference to the report or statement; the assured subject matter and basis; assurance standard, level and limitations; and the provider relationship.
Can internal audit be called assurance? Not external assurance. Internal audit can test systems and controls, but it is an internal function and does not create an independent external conclusion.
Does limited assurance cover the whole report? Only if the signed assurance statement says so. Scope may be limited by indicators, entities, sites, periods, methods or sections.

Why GRI 2-5 is often misunderstood

The disclosure sits in the reporting-practices section of GRI 2, so it is sometimes reduced to a one-line sentence such as “selected information was assured”. That wording rarely tells the reader what the engagement covered, what level of assurance was obtained, which criteria were used or whether the provider’s conclusion applies to the whole report.

The opposite error is to treat GRI 2-5 as an obligation to buy assurance. GRI explicitly recommends external assurance as a way to strengthen credibility, but the Universal Standards do not make it mandatory. The reporting obligation is transparency about the organisation’s policy and practice and, where assurance exists, transparency about the engagement.

Rule

REQUIREMENT / RECOMMENDATION BOUNDARY

Requirement: disclose the policy and practice, governance involvement and — where assurance has occurred — the assurance report, scope, basis, level, limitations and provider relationship. Recommendation: seek external assurance. Good practice: retain an engagement-scoping and publication-control file that reconciles the report wording to the signed assurance statement.

In practice

What GRI 2-5 requires

Required element What the reader should be able to understand Evidence normally retained
Policy and practice for seeking external assurance Whether assurance is routinely sought, selectively commissioned, planned for future periods or not currently obtained. Assurance policy, reporting procedure, prior engagements, procurement and approval records.
Highest governance body and senior executive involvement Whether and how they approve policy, scope, provider appointment, findings or publication wording. Committee terms of reference, agendas, minutes, approval papers and management sign-off.
Assurance report or statement Where the signed external conclusion can be found. Final signed statement, publication permission and stable link.
What was assured and on what basis The subject matter, reporting boundary, criteria, period and any exclusions. Engagement letter, scope schedule, content-index mapping and criteria list.
Assurance standard and level The professional standard or framework used and whether the engagement provided limited, reasonable or another clearly defined level. Assurance report, engagement acceptance and technical review.
Limitations Any scope, evidence, methodological, system or availability constraints stated by the provider. Provider’s limitation wording, data-gap log and management response.
Relationship with provider The nature of the relationship and information relevant to independence. Appointment, tenure, non-assurance services, safeguards and conflicts review.

Rule

REFERENCE THE SIGNED STATEMENT PRECISELY

Where the linked assurance statement already contains the required details, the GRI disclosure can be concise. The reference must still be stable, precise and consistent with the statement; it should not broaden the scope or level through paraphrasing.

Assurance statement, limited review, internal audit and management validation

These labels describe different activities. The safest classification method is to read the signed output and identify who performed the work, the criteria, independence, scope, procedures, level and conclusion. The title used by management or a website button is not enough.

External assurance, internal audit, management validation and performance certification have different purposes, accountability and outputs.

In practice

Activity Typical output What it can support — What it does not prove
External assurance engagement Signed independent assurance report or statement under identified criteria and assurance standard. Credibility of specified sustainability information within the defined scope and level. — Assurance over information outside the scope, or assurance over management performance itself.
Limited assurance / limited-review-style engagement A negative-form conclusion based on procedures appropriate to a limited level, if performed as an assurance engagement. A lower but meaningful level of confidence over the specified subject matter. — Reasonable assurance, a financial-statement audit opinion or assurance over the entire report unless explicitly scoped.
Internal audit Internal report to management or an audit committee on controls, systems, governance or data. Control improvement, testing evidence and assurance readiness. — An independent external conclusion for users of the published report.
Management validation or certification Owner sign-off, representation, management review or system certification. Accountability, process discipline and evidence that management reviewed the information. — External assurance or provider independence.
Performance or product certification Certificate or opinion against product, site, system or performance criteria. Credibility of the certified subject matter. — Assurance over the GRI report or other sustainability information outside that subject matter.

How to describe scope and level without overstating the engagement

Assurance scope is multi-dimensional. A statement such as “our ESG data was assured” leaves unanswered whether the provider covered the complete sustainability statement, selected GRI disclosures, selected metrics, one region, a subset of entities, a methodology or only the calculation process. The report wording should mirror the signed statement across every scope dimension.

In practice

Scope dimension Control question Example of precise wording
Information covered Which disclosures, metrics, narrative sections or claims were within the engagement? “Limited assurance covered Scope 1 and Scope 2 emissions and total energy consumption.”
Entities and operations Which subsidiaries, sites, joint ventures or value-chain information were included? “The scope covered consolidated entities and excluded two recently acquired sites listed in the assurance statement.”
Reporting period Which dates and comparative figures were covered? “The engagement covered the year ended 31 December 2026; prior-year comparatives were not assured.”
Criteria Against what reporting criteria or methodologies was the information evaluated? “The subject matter was evaluated against the GRI Standards cited in the content index and the emissions methodology note.”
Level Was the conclusion limited, reasonable or otherwise defined? “The provider expressed a limited assurance conclusion.”
Limitations What restrictions or data constraints affected the work? “Supplier estimates were included in the reported metric but excluded from the provider’s assurance scope.”

Provider relationship and independence

GRI 2-5 requires the organisation to describe its relationship with the assurance provider. GRI guidance emphasises independence, competence and objective assessment. The public description does not need to reproduce the provider’s entire ethics analysis, but it should avoid implying independence where material relationships or services have not been considered.

Name the provider and its professional role.

State whether the provider also audits the financial statements or supplies other services relevant to independence.

Explain governance responsibility for appointment and oversight.

Describe safeguards or separation where non-assurance services exist and the information is material to users.

Do not write “independent” solely because the provider is external; independence is a substantive condition.

Reconcile the relationship disclosure with procurement, audit-committee and provider statements.

In practice

A practical drafting and control process

# Step Action — Owner / input — Output / control
1 Collect the signed source documents Obtain the final engagement letter, scope schedule, signed assurance statement, criteria list and provider publication permission. — Reporting owner + legal/procurement — Controlled assurance source pack.
2 Extract the engagement facts Record subject matter, boundary, period, criteria, assurance standard, level, limitations and conclusion. — Technical reporting lead — Assurance factsheet.
3 Map assured items to the report Link each assured disclosure or metric to its published location and identify unassured adjacent information. — Content-index owner — Scope-to-report mapping.
4 Confirm governance involvement Document policy approval, provider appointment, scope decisions, findings and publication approval. — Company secretary / governance lead — Governance evidence record.
5 Assess the provider relationship Confirm independence review, tenure, other services and safeguards with the responsible governance body. — Audit committee + procurement — Relationship disclosure basis.
6 Draft and challenge the disclosure Compare every public phrase to the signed statement and remove any broadened scope, level or conclusion. — Author + technical reviewer — Approved GRI 2-5 wording.
7 Test the final links Confirm the assurance statement is accessible, correctly titled and available when the report is published. — Publisher — Publication QA record.

Illustrative case: selected metrics under limited assurance

A diversified manufacturer publishes a GRI-based sustainability report. Its audit committee approves a two-year assurance policy. In the first year, the provider performs limited assurance over Scope 1 and Scope 2 greenhouse-gas emissions, total energy consumption, total workforce and lost-time injury frequency. Scope 3 estimates and narrative statements are outside the engagement.

Illustrative GRI 2-5 disclosure

Illustrative wording — adapt to the organisation’s facts, reporting boundary and applicable requirements.

The example demonstrates how to disclose a selective engagement without suggesting that the entire report was assured.

The policy and governance roles are explicit.

The four assured metrics are named and the unassured areas are not hidden.

The level, standard, criteria and period are stated.

The provider relationship and independence oversight are described.

The reader is directed to the signed conclusion rather than a management summary.

Rule

ADAPTATION WARNING

Replace the assurance standard, level, scope, provider relationship and governance description with the facts of the actual engagement. Do not cite ISSA 5000 unless it was the standard used.

In practice

Weak and stronger drafting

Weak wording Why it is weak Stronger wording pattern
“Our sustainability report was externally assured.” Scope, level, criteria, period and limitations are unknown. Name the exact assured information, level, standard, period and location of the signed statement.
“The data were reviewed by internal audit.” This is valuable internal control evidence but not external assurance. Describe internal audit under internal controls and separately disclose any external assurance.
“Independent assurance was provided by our auditor.” The relationship and basis for independence are not explained. Describe the provider relationship, governance oversight and any relevant other services.
“Limited assurance confirms the data are accurate.” An assurance conclusion is not a guarantee and the wording may misstate the signed conclusion. Use the provider’s engagement title and refer readers to the signed conclusion.
“Selected KPIs were assured.” Users cannot identify which KPIs or adjacent information are unassured. List the KPIs or provide a precise mapping and state material exclusions.

In practice

Common mistakes

Common mistake Why it creates risk Correction
Treating external assurance as mandatory under GRI. The organisation overstates the standard and may procure an engagement without a clear reporting objective. Separate GRI’s recommendation to seek assurance from the disclosure requirements of 2-5.
Calling internal audit or management sign-off “external assurance”. Users receive a false impression of independence and professional conclusion. Use the exact activity label and describe external assurance only where an independent engagement exists.
Writing that the report is assured when only selected metrics are in scope. The assurance claim extends beyond the provider’s conclusion. Name the assured subject matter and material exclusions.
Omitting the assurance level or standard. Users cannot understand the nature and strength of the conclusion. State the level and professional standard exactly as in the signed statement.
Publishing a broken or temporary assurance link. The mandatory reference is not accessible to report users. Use a stable publication location and test it at final QA.
Ignoring the provider relationship. Independence questions remain unanswered and the disclosure is incomplete. Describe appointment, relevant other services and governance safeguards.

In practice

Myth versus reality

Layer Statement
MYTH A GRI report is only credible — or only “in accordance” — if the entire report receives external assurance.
REALITY GRI recommends assurance but does not make it a condition of either reporting route. Credibility also depends on reporting principles, controls, evidence and accurate claims. Where assurance is obtained, its scope and level must be described without implying coverage beyond the signed conclusion.
PRACTICAL CONSEQUENCE Design assurance around material information, user needs and evidence maturity, then communicate the engagement precisely.

Readiness

GRI 2-5 disclosure checklist

  • The assurance policy and current practice are described.
  • The involvement of the highest governance body and senior executives is clear.
  • The signed assurance report or statement is linked or precisely referenced.
  • Every assured metric, disclosure, section, entity, site and period can be identified.
  • The reporting criteria and assurance standard are stated.
  • The assurance level uses the provider’s exact terminology.
  • Material limitations and exclusions are visible.
  • The provider relationship and relevant independence oversight are described.
  • The report wording does not broaden the provider’s conclusion.
  • Internal audit, management validation and certification are labelled separately.
  • The content index and assurance scope mapping agree.
  • The final link is accessible and publication permission is recorded.
  • Governance approval and management representations are retained.

Sources

Primary sources

Take it with you

The checklists as a working spreadsheet

Every checklist and table on this page, with empty status, owner and evidence columns for your team to fill in and keep.

Download .xlsx

✓ LRA AI Assistant · Human-in-the-loop

Ask about this guide

It answers from this page, and reaches into the linked disclosure cards when your question is about the standard itself. Your first two answers are free without signing in.

Try
2 free answers Automated · the LRA team is one click away

Go deeper · GRI

GRI Standards Certified Training

A full reporting cycle with a mentor: impact inventory, threshold, Topic Standard selection, Content Index and assurance readiness.

Available as Guided Flex, Live Cohort, 1:1 Expert Mentorship or Corporate Programme.

See course formats
/en/knowledge-hub/disclosure-guides/gri/gri-evidence-controls-and-assurance/gri-2-5-external-assurance-explained-assurance-policy-scope-level-prov/