Skip to the answer

Disclosure GuidesPillar guides, articles, FAQ and expert notes

Level 2 · Decision guide·GRI · Disclosure guides

How to Prepare a GRI Report for External Assurance

An 8-12 week readiness project covering scope, criteria, provider procurement, evidence mapping, data controls, walkthroughs, representations, remediation and publication wording

Who this is for A 21-minute read for reporting teams working through Data, evidence, controls and assurance, and for reviewers testing whether the evidence behind it holds.

Published passport

Current as at 11 August 2026
RK Reviewed by Dr Ross KurinkoLinkedIn Strategic ESG Advisor · IFRS S1 & S2 / GRI / ESRS expert GRI Certified Global Trainer · PhD, University of Cambridge · ESG-AI expert 15+ years on FTSE 100 & Fortune Global 500 disclosures Canary Wharf, London LRA educational guidance · Not issued or endorsed by GRI

Edition written against

Technical status: Source review completed on 1 August 2026. This draft separates source requirements from implementation …

Published

12 Aug 2026

Knowledge Hub guide

Last reviewed

11 Aug 2026

Short answer

The answer, before the reasoning

Prepare for external assurance as a controlled reporting project, not as a late review of the finished PDF. First define the subject matter, reporting boundary, criteria, assurance level and exclusions; then procure an independent, competent provider, map every assured disclosure to evidence, test data and narrative controls, run walkthroughs and a dry review, remediate findings, obtain appropriate management representations and align the final publication wording with the practitioner’s report.

External assurance is encouraged by GRI but is not required for reporting in accordance. The organisation remains responsible for the report, the underlying controls and the accuracy of its assurance claims.

Technical status: source-grounded publication draft; final human technical review required before release.

Quick orientation

Quick orientation

Applies to
Primary decision
GRI reporting teams preparing a first or expanded assurance engagement
How to make the reporting system and evidence ready before the practitioner starts final testing

Start with the right premise

GRI encourages organisations to use internal controls and seek external assurance to enhance the credibility of sustainability reporting, but GRI 1 does not make external assurance a condition for reporting in accordance. Disclosure 2-5 requires the organisation to explain its policy and practice for seeking external assurance and, where assurance has been obtained, to provide the assurance report and describe the scope, basis, standards, level, limitations and relationship with the provider.

Assurance readiness therefore has two objectives. It prepares information that can be tested against suitable criteria, and it ensures the public description of assurance is accurate. The project should strengthen the reporting system even if the final engagement covers only selected disclosures.

Rule

Requirement versus practice

GRI requirement: report Disclosure 2-5 and comply with the underlying GRI disclosures used as criteria. Assurance engagement requirement: the practitioner determines whether preconditions, criteria, scope, evidence and engagement terms are appropriate under the applicable assurance standard. Implementation practice: run a structured readiness project before final assurance procedures begin.

1. Define the assurance proposition before procurement

A request for proposal that says “assure our GRI report” is not sufficiently precise. The organisation should first prepare a scope-and-criteria memorandum. It does not need to predetermine the practitioner’s procedures, but it should define the intended subject matter and what management is prepared to support.

In practice

Scope decision Questions to resolve Readiness output
Subject matter Whole sustainability statement, selected GRI disclosures, selected metrics, GHG statement, or a combination? Controlled list of disclosures and data points.
Reporting period Which period and publication date? Are comparatives in scope? Period and comparative treatment memo.
Reporting boundary Which entities, sites, workers, value-chain activities and joint arrangements are covered by each disclosure? Boundary register and reconciliations to GRI 2-2 and financial reporting.
Criteria Which GRI Standards, calculation methodologies, policies or entity-developed criteria will be used? Criteria register with exact editions and public availability.
Assurance level Limited, reasonable or a combined engagement for different information? Approved target level by disclosure group.
Exclusions What is explicitly outside scope and why? Exclusion list that will align with the assurance report and public wording.
Intended users and purpose Who will use the conclusion and for what decision? Rationale for scope and level.
Timing When will evidence freeze, walkthroughs, remediation and final sign-off occur? Integrated reporting and assurance calendar.

Rule

Scope discipline

Do not describe selected-metric assurance as assurance over the “GRI report” unless the practitioner’s conclusion genuinely covers the report as a whole. Use exact language that identifies the assured information and excluded information.

2. Procure a provider without compromising independence

GRI 1 recommends an assurance provider that is independent of the organisation, demonstrably competent in the subject matter and assurance practices, quality controlled, systematic, documented and evidence based. ISSA 5000 is profession agnostic: it can be applied by professional accountants and other assurance practitioners who meet the applicable ethical, quality-management and competence requirements.

The procurement process should evaluate the engagement team, not only the firm brand. Ask who will lead the work, which specialists will test GHG, social, human-rights or value-chain information, how group components will be covered, what quality review applies, and how independence threats are identified and addressed.

In practice

Procurement test Evidence to request Reason for the test
Independence and ethics Written independence confirmation; description of other services and safeguards. Readiness or consulting work by the same firm can create self-review threats.
Competence Team CVs, sector experience, sustainability subject-matter expertise and assurance credentials. GRI criteria and specialised metrics require both reporting and technical knowledge.
Quality management Applicable quality-management framework, engagement quality review and escalation process. Supports consistent performance and review of difficult judgements.
Proposed standard ISSA 5000 or other applicable assurance standard, with rationale and effective-period treatment. The public report must identify the basis accurately.
Scope understanding Initial view of subject matter, criteria, boundary, materiality and component coverage. Reveals whether the proposal matches the intended engagement.
Deliverables and timetable Planning outputs, findings protocol, draft/final report, management letter and key gates. Prevents late disagreement over evidence deadlines and wording.
Use of experts / other practitioners Roles, responsibility, communication and review arrangements. Group and specialist evidence still needs integrated responsibility.
Data and security Secure portal, access management, retention and confidentiality arrangements. Assurance evidence may contain personal, grievance, commercial or site-sensitive information.

3. Build the disclosure-to-evidence map

The evidence map is the central readiness deliverable. It decomposes each in-scope disclosure into criteria and connects each published claim to source evidence, calculation or narrative files, control owners and approvals. It also identifies which evidence is public and which remains restricted.

Figure 1. Assurance readiness requires traceability from the published disclosure to criteria, calculation, source evidence and control.

In practice

Evidence-map field What to record Example
Disclosure / requirement Exact GRI disclosure and lettered requirement in scope. 3-3-d-ii: processes used to determine effectiveness.
Published claim Final or controlled draft sentence, table cell or metric. “Corrective actions reduced repeat incidents by 18%.”
Criteria interpretation How the requirement applies to the organisation’s facts. Definition of repeat incident; population and period.
Source evidence System extracts, policies, minutes, invoices, contracts, survey files, grievance records or expert reports. Incident register extract and corrective-action tracker.
Calculation / narrative file Formulae, assumptions, allocation, estimate method and drafting evidence. Reconciliation and trend calculation workbook.
Control Preparation, review, exception challenge, access and change control. OHS data owner prepares; internal control team reperforms; executive approves.
Owner and location Named owner and retained repository path. OHS analytics lead; controlled assurance room.
Status / finding Ready, gap, remediation, not in scope or representation only. Gap: two sites not reconciled to HR headcount.

4. Test controls before testing the final numbers

A calculation can be numerically correct once and still be difficult to assure if the process is uncontrolled. Readiness testing should ask how data are initiated, captured, changed, consolidated, reviewed and approved. Important controls include master-data governance, access rights, unit validation, automated interfaces, manual journal review, completeness reconciliations, factor version control, estimate approval, variance analysis, restatement assessment and publication sign-off.

For narrative disclosures, controls are equally important. The team should retain the policy or commitment in force during the reporting period, evidence of implementation, results used to support effectiveness claims, governance minutes, stakeholder evidence, limitations and approvals. A polished paragraph without a source trail is an assurance risk.

Walkthrough design

Select a sample of high-risk disclosures and follow them end to end: from source event to system, consolidation, calculation, review and published text. The walkthrough should involve the actual preparer and reviewer. It should identify manual hand-offs, unrecorded judgement, spreadsheet overrides, inconsistent boundaries and evidence that is produced only after the fact.

In practice

Walkthrough Start point End point — Questions
Scope 1 emissions Fuel invoice / meter / refrigerant event GRI 102 metric and methodology note — How is completeness reconciled? Who controls factors and GWP values? How are acquisitions and restatements handled?
Workers HR and contractor source systems GRI 2-7 / 2-8 tables — How are worker definitions applied across countries? How are duplicates, leavers and missing categories handled?
Material topics Impact evidence and assessment records GRI 3-1 and 3-2 disclosure — How were impacts identified, assessed and prioritised? How were Sector Standards and stakeholder evidence used?
Management of topic Policy, action register and KPI evidence GRI 3-3 narrative — Which evidence supports effectiveness and lessons learned rather than only activities?
Supplier metric Supplier file or questionnaire Topic Standard table — How are boundary, allocation, sampling, non-response and estimate limitations controlled?

Materiality and GRI 3-1 / 3-2

Assurance risk arises when the organisation cannot show a complete impact universe, the role of Sector Standards, the sources used to identify impacts, significance criteria, how stakeholder evidence informed judgement, why thresholds were selected and who approved the final material topics. A matrix without the underlying evidence trail is rarely sufficient.

GRI 2 reporting practices and boundary

Disclosures 2-1 to 2-5 cannot use reasons for omission. Common issues include inconsistency between legal entities and the sustainability boundary, unexplained departures from financial consolidation, reporting-period mismatch, undocumented restatements and assurance wording that is broader than the practitioner’s report. Worker and governance disclosures also create cross-system definition challenges.

GRI 3-3 management of material topics

Generic policy descriptions are not enough. The evidence map should cover actual and potential impacts, policies or commitments, actions, tracking effectiveness, stakeholder engagement and how lessons are incorporated. Effectiveness claims need outcome evidence or careful limitation wording. Activities such as training delivered or audits performed do not by themselves prove that impacts improved.

Topic Standard metrics

Common findings concern reporting boundary, definitions, units, factor source, estimation, completeness, changes in methodology, base-year recalculation, inconsistent comparatives and lack of reconciliation to operational or financial systems. For value-chain metrics, the provider will often challenge supplier data quality, sampling and extrapolation.

In practice

Area Typical finding Readiness response
Material topics Long list reconstructed after scoring; no evidence for excluded impacts. Freeze the impact inventory and retain source, judgement and approval records.
GRI 2-2 Entities in the report do not reconcile to the stated boundary. Create an entity-by-disclosure boundary register and explain legitimate differences.
GRI 2-4 Prior-year numbers changed with no restatement disclosure. Maintain a change and restatement assessment log.
GRI 2-5 Report says “independently assured” without scope or level. Align wording with the final practitioner’s report and link it.
GRI 3-3 Effectiveness is asserted from activity counts. Separate action evidence from outcome evidence and disclose limitations.
Topic metric Calculation file has hard-coded factors and undocumented overrides. Lock factor master data, record changes and add independent reperformance.
Website disclosure Evidence changed after assurance cut-off. Version-lock the assured information or describe the cut-off clearly.

6. Run a dry review and manage findings

A dry review should occur while there is still time to change the report and strengthen evidence. Test a representative mix of high-risk quantitative metrics, narrative management disclosures, estimates, group components and web references. Findings should be recorded with severity, affected disclosure, criterion, evidence gap, owner, due date and accepted resolution.

Not every issue requires more text. The correct remedy may be to improve a control, correct a number, narrow a claim, disclose a limitation, revise a boundary, add a reason for omission, or remove unsupported wording. The reporting lead should maintain a single finding log so that the practitioner, data owners, editor and final approver work from the same status.

7. Prepare management representations appropriately

ISSA 5000 requires written representations on matters such as management’s responsibility for preparing the sustainability information, providing all relevant information and access, uncorrected misstatements, assumptions, control deficiencies, fraud or non-compliance and subsequent events, as applicable. Representations are dated as near as practicable to the assurance report.

Rule

Representations are not a substitute for evidence

A representation can confirm management’s responsibility and knowledge. It cannot repair an unsupported metric, missing boundary record or absent control. If sufficient appropriate evidence cannot be obtained, a scope limitation may affect the practitioner’s conclusion.

8. Use precise publication wording

The final report should make it easy to identify what was assured, against which criteria, at what level and for which period. Disclosure 2-5 should link to the assurance report and describe the provider relationship. The report design should not separate a reassuring assurance badge from the scope limitation or imply that unaudited narrative is covered.

In practice

Risky wording Safer pattern
“Our GRI report has been independently assured.” “The disclosures identified in the Independent Practitioner’s Report on pp. 190-196 were subject to limited assurance under [standard] for the year ended [date]. Other information in this report was not included in the engagement.”
“The assurer verified our sustainability performance.” “The practitioner expressed a conclusion on the prepared sustainability information within the defined scope and criteria. The conclusion does not constitute a rating of performance or future outcomes.”
“No issues were found.” “The practitioner’s conclusion and any qualifications or scope limitations are reproduced in the assurance report. Management’s separate remediation actions are described only where supported.”

Illustrative 10-week readiness timeline

Figure 2. Illustrative ten-week assurance-readiness plan.

In practice

Weeks Primary work Gate / deliverable
1-2 Approve scope, subject matter, criteria, reporting boundary, intended level and provider procurement. Scope locked; RFP / engagement discussion.
2-3 Decompose in-scope disclosures into requirements and build the evidence map. Criteria and evidence-map baseline.
2-5 Collect source evidence, calculation files, policies, minutes, methodology and prior-period records. Evidence freeze for dry review.
3-6 Document controls, perform walkthroughs, reconcile boundaries and test high-risk calculations. Control and walkthrough findings.
5-7 Run dry review and requirement-level disclosure testing. Consolidated finding log.
6-9 Correct numbers, strengthen controls, narrow or balance wording, disclose limitations and close evidence gaps. Remediation close and approval.
9-10 Prepare representations, subsequent-events check, final document consistency and assurance wording. Final management pack and publication sign-off.

Hypothetical readiness case

The readiness team first removes the ambiguous phrase “assurance over the sustainability report” from the draft. It creates a metric-level scope table, reconciles employee data to the HR consolidation boundary, documents the market- and location-based Scope 2 methods, tests waste contractor evidence and separates cash contributions from programme outcomes. A dry review finds that two community metrics were based on project-team estimates with no retained support. Management either obtains evidence or removes the metrics from the assured scope and explains the limitation.

At publication, the report links to the practitioner’s conclusion, identifies the selected information and limited-assurance level, and makes clear that the materiality process and other narrative disclosures were not included. The project also creates a Year 2 plan to expand assurance only after GRI 3-3 evidence and value-chain controls mature.

Hypothetical scenario

Hypothetical example - first limited-assurance engagement

A bank plans limited assurance over Scope 1, Scope 2, operational waste, employee numbers and selected community-investment metrics. Its GRI report also contains material-topic and GRI 3-3 disclosures outside the planned assurance scope.

Illustrative only. It shows how the decision is made, not wording that can be copied or relied on.

In practice

Common mistakes

Mistake Why it creates risk Correction
Starting assurance after the final report is designed. Page, scope and evidence changes become expensive and delay publication. Lock scope early and run dry testing on controlled drafts.
Letting the provider define management’s criteria and prepare key calculations. Management responsibility and provider independence can be blurred. Management owns criteria and preparation; address any readiness-service independence threats.
Mapping one evidence file to an entire complex disclosure. Requirement-level gaps remain hidden. Decompose disclosure requirements and map each claim or metric.
Using representations to cover missing source evidence. Representations cannot create sufficient appropriate evidence. Obtain evidence, narrow scope, correct the disclosure or accept the effect on the conclusion.
Publishing broader assurance wording than the report. Readers may believe unaudited information is assured. Have assurance liaison and practitioner review the final public description.
Treating assurance findings as the provider’s problem. Underlying controls and future reporting do not improve. Assign management owners, root-cause actions and post-publication follow-up.

Rule

Myth: “If the assurer signs the report, management no longer owns the information.”

Reality: management remains responsible for preparing the sustainability information, selecting or applying the criteria, maintaining relevant internal control, providing access and correcting identified misstatements. The practitioner provides an independent conclusion within the engagement scope.

Next step

After publication, convert the finding log into the next reporting-cycle control plan. Track recurring issues by disclosure, root cause and owner; retain the final evidence pack; and decide whether assurance scope should expand, remain stable or narrow. A mature assurance programme grows with the reliability of the reporting system, not with the ambition of the report design.

Rule

Internal use

This section supports technical review, CMS assembly, SEO, design and controlled reuse. It is not part of the public article body.

The assurance provider may perform some readiness work where the applicable ethical and independence requirements permit it and the work does not create an unmanaged self-review or other threat. Define the services and roles before appointment, assess safeguards and keep management responsible for decisions, evidence and preparation.

Management representations support an assurance engagement but do not replace underlying evidence, data controls or remediation. They should confirm management responsibility, completeness, methods, assumptions and known limitations, while unresolved evidence gaps remain findings that can affect the engagement scope or conclusion.

Questions

Questions people ask

Is external assurance required for a GRI report?

First define the subject matter, reporting boundary, criteria, assurance level and exclusions; then procure an independent, competent provider, map every assured disclosure to evidence, test data and narrative controls, run walkthroughs and a dry review, remediate findings, obtain appropriate management representations and align the final publication wording with the practitioner’s report. External assurance is encouraged by GRI but is not required for reporting in accordance.

What should be assured first?

Prepare for external assurance as a controlled reporting project, not as a late review of the finished PDF. First define the subject matter, reporting boundary, criteria, assurance level and exclusions; then procure an independent, competent provider, map every assured disclosure to evidence, test data and narrative controls, run walkthroughs and a dry review, remediate findings, obtain appropriate management representations and align the final publication wording with the practitioner’s report.

Can the assurance provider perform the readiness review?

The assurance provider may perform some readiness work where the applicable ethical and independence requirements permit it and the work does not create an unmanaged self-review or other threat. Define the services and roles before appointment, assess safeguards and keep management responsible for decisions, evidence and preparation.

Do management representations solve evidence gaps?

Management representations support an assurance engagement but do not replace underlying evidence, data controls or remediation. They should confirm management responsibility, completeness, methods, assumptions and known limitations, while unresolved evidence gaps remain findings that can affect the engagement scope or conclusion.

Sources

Primary sources

Take it with you

The checklists as a working spreadsheet

Every checklist and table on this page, with empty status, owner and evidence columns for your team to fill in and keep.

Download .xlsx

✓ LRA AI Assistant · Human-in-the-loop

Ask about this guide

It answers from this page, and reaches into the linked disclosure cards when your question is about the standard itself. Your first two answers are free without signing in.

Try
2 free answers Automated · the LRA team is one click away

Go deeper · GRI

GRI Standards Certified Training

A full reporting cycle with a mentor: impact inventory, threshold, Topic Standard selection, Content Index and assurance readiness.

Available as Guided Flex, Live Cohort, 1:1 Expert Mentorship or Corporate Programme.

See course formats
/en/knowledge-hub/disclosure-guides/gri/gri-evidence-controls-and-assurance/how-to-prepare-a-gri-report-for-external-assurance/