Skip to the answer

Disclosure GuidesPillar guides, articles, FAQ and expert notes

Level 2 · Decision guide·IFRS S1 / S2 · Disclosure guides

Internal Controls Over IFRS Sustainability Disclosures: A Practical Framework

Control environment, data dictionary, evidence, segregation, reconciliations, models and remediation

Who this is for A 20-minute read for reporting teams working through Climate risks, scenario analysis and resilience under IFRS S2, and for reviewers testing whether the evidence behind it holds.
RK Published passportReviewed by Dr Ross Kurinko Strategic ESG Advisor · IFRS S1 & S2 / GRI / ESRS Current as at
GRI and ISSB-IFRS S1 & S2 Certified Global Trainer · PhD, University of Cambridge · ESG-AI expert 15+ years on FTSE 100 & Fortune Global 500 disclosures Canary Wharf, London LRA educational guidance · Not issued or endorsed by IFRS LinkedIn

Edition written against

IFRS S1 / S2 (August 2026)

Source cut-off: 1 August 2026. Official texts and jurisdictional implementation requirements can change. Before publication or …

Published

12 Aug 2026

Knowledge Hub guide

Last reviewed

11 Aug 2026

Short answer

The answer, before the reasoning

IFRS S1 and IFRS S2 do not prescribe COSO, SOX or any other named internal-control framework. They do, however, require information that is material, fairly presented, connected, timely and supported by consistent data and assumptions.

A practical control framework should therefore be risk-based and integrated with finance: establish clear accountability, define every data field, retain evidence, separate preparation from review, reconcile boundaries and assumptions, govern models and estimates, control disclosure approval, obtain management representations and remediate deficiencies. COSO’s 2023 sustainability reporting guidance can provide a useful non-authoritative structure through its five components and 17 principles.

A finance-aligned internal-control framework for producing reliable IFRS S1 and IFRS S2 disclosures without pretending that financial and sustainability information are identical.

In practice

Article map

Stage What the reader will be able to do
Answer Explain what IFRS requires and what it does not prescribe about controls.
Design Set control objectives, environment, data definitions and evidence architecture.
Operate Apply segregation, reconciliations, model governance and disclosure review.
Align Integrate the sustainability process with the finance close.
Improve Assess deficiencies, remediate root causes and monitor the system.

Why sustainability controls must be designed as a reporting system

A sustainability report can look complete while still depending on fragile processes: uncontrolled spreadsheets, ambiguous metric definitions, manually copied supplier data, assumptions that differ from financial planning, management review that leaves no evidence, and disclosures assembled from multiple versions. These weaknesses are not solved by adding a final sign-off. The system must be capable of producing reliable information repeatedly, detecting error or bias and retaining evidence of how judgements were made.

The closest operational analogy is the financial close—not because sustainability information is identical to accounting information, but because the discipline is transferable. Both need a controlled perimeter, a reporting calendar, data ownership, cut-off, consolidation, reconciliations, review, exception management and authorisation. Sustainability reporting adds its own risks: value-chain data, estimates, scientific methodologies, external factors, scenarios, forward-looking information and narrative claims about governance or effectiveness.

Rule

IMPORTANT BOUNDARY

Applying COSO or finance-style controls does not, by itself, demonstrate compliance with IFRS S1/S2, make a disclosure material, or guarantee an assurance conclusion. The control framework supports reliable preparation; technical reporting judgements remain subject to the Standards and applicable jurisdictional requirements.

A five-component framework aligned to finance

Internal control framework aligned to finance

The five COSO components can organise sustainability controls, while the year-end close disciplines of scope, cut-off, consolidation, reconciliation, review and sign-off provide an operational backbone.

COSO’s 2023 publication Achieving Effective Internal Control over Sustainability Reporting applies the five components and 17 principles of the 2013 Internal Control—Integrated Framework to sustainability information. The publication is explicitly non-authoritative and interpretative. It is useful as an organising model, but an entity should tailor control objectives, owners and evidence to its reporting risks, jurisdiction, maturity and assurance scope.

In practice

Component IFRS sustainability application Finance-aligned practice
Control environment Board and management accountability, competence, ethical reporting culture, reporting policy and consequences for unsupported claims. Close governance, role descriptions, certification policy and escalation routes.
Risk assessment Identify where material misstatement, omission, bias or inconsistency could arise across data, judgements, models and narrative. Risk-and-control matrix linked to financial statement, process and fraud-risk assessments.
Control activities Preventive and detective controls over data capture, calculations, access, estimates, reconciliations, disclosures and changes. Standard close controls, account reconciliations, journal approval analogues and system controls.
Information and communication Controlled definitions, data requests, evidence retention, issue escalation and communication to governance bodies. Chart-of-accounts discipline translated into a sustainability data dictionary and disclosure instructions.
Monitoring Ongoing checks, separate evaluations, internal audit, assurance feedback, deficiency assessment and remediation. Quarterly control testing, close retrospectives and deficiency tracking.

Step 1: define control objectives before listing controls

Controls should respond to a clear reporting objective. Without that objective, teams often produce long checklists that prove activity but do not address the risk. For IFRS S1/S2, the control objectives can be organised around the qualities and requirements of the disclosures.

In practice

Control objective Question the system must answer Illustrative risk
Completeness Have all material sustainability-related risks, opportunities and required disclosures been considered? A significant value-chain risk is omitted because it is not in the enterprise risk system.
Accuracy / faithful representation Do numbers and narratives depict the underlying facts completely, neutrally and accurately? The report describes a policy as implemented group-wide when only selected subsidiaries adopted it.
Occurrence / existence Did the disclosed event, governance action, target or control actually occur? A board oversight claim is based on a planned agenda rather than a meeting record.
Boundary and classification Is information assigned to the correct reporting entity, scope, category, geography, period and unit? Scope 3 emissions are reported under a group context that excludes a major acquired business.
Cut-off and period consistency Does the information cover the same reporting period and correct event cut-off? Supplier data from an earlier twelve-month period is presented without explanation.
Valuation / estimation Are estimates, models, factors and assumptions reasonable, supportable and transparently described? A scenario model uses an undocumented carbon price and reports a precise single amount.
Presentation and connected information Are disclosures understandable and consistent with the financial statements, strategy and other reported information? The transition plan assumes capex not included in the approved financial plan.
Compliance and claim integrity Is the reporting claim supported by the full applicable requirements? An explicit IFRS compliance statement is made before all requirements and reliefs are assessed.

Step 2: establish the control environment

The control environment determines whether individual controls will operate when pressure increases. Sustainability reporting often spans functions that do not report to one owner. The board may oversee the reporting, finance may own publication, sustainability may own methodology, operations may own data and IT may own systems. Without explicit authority and accountability, gaps sit between functions.

Board and committee oversight: define which body oversees sustainability-related financial disclosures, material judgements, significant deficiencies and the final reporting claim.

Executive accountability: appoint a named executive responsible for the reporting system, not only for the final document.

Reporting policy: document the framework, scope, reporting entity, standards hierarchy, terminology, materiality process, use of estimates, evidence expectations and approval route.

Competence: assess whether owners and reviewers have the technical, sector, finance, climate, data and control skills required for their responsibilities.

Integrity and challenge: prohibit unsupported claims, hidden data gaps and silent method changes; create escalation routes that protect reviewers from deadline pressure.

Accountability: include control performance and remediation in role objectives, close certifications and governance reporting.

Rule

PRACTICAL TEST

Ask three people—reporting lead, data owner and reviewer—who is authorised to approve a methodology change, accept a control exception and release the compliance statement. If the answers differ, the control environment is not yet operational.

Step 3: create a controlled sustainability data dictionary

A data dictionary is the equivalent of a reporting chart of accounts. It prevents one metric name from carrying several meanings across the group and gives controls a stable object to test. The dictionary should cover quantitative and narrative fields. For example, “Board oversight frequency” is a controlled disclosure field just as “Scope 2 location-based emissions” is a controlled metric.

In practice

Field Required content
Data / claim ID Stable identifier used across systems, evidence, controls and disclosure mapping.
Official name and plain-language description Precise technical label plus a definition that a data owner can apply.
Reporting basis IFRS paragraph, SASB metric, jurisdictional rule or entity-specific disclosure rationale.
Unit and data type Currency, tCO2e, percentage, count, narrative, date, Boolean or other controlled type.
Boundary Reporting entity, facility, workforce, value-chain population, asset class or other perimeter.
Period and cut-off Measurement period, event cut-off, lagged-data policy and comparative basis.
Method Formula, methodology, hierarchy of inputs, emission factor, model or narrative evidence rule.
Source system / file System of record, report name, extraction logic and data lineage.
Owner / reviewer Responsible preparer, control owner, technical reviewer and approver.
Estimation and uncertainty Measured versus estimated status, assumptions, limitations and sensitivity.
Control references Key controls, evidence generated, frequency and escalation threshold.
Disclosure location Final report paragraph/table and digital taxonomy mapping where applicable.
Version and change history Effective date, reason for change, approval and comparative/restatement treatment.

Step 4: maintain an evidence register

The data dictionary defines what the information means; the evidence register shows what supports the reported fact. A single item can have several evidence types: source data, methodology, calculation, review and governance approval. The register should be claim-based rather than organised only by department or file name.

In practice

Register field Purpose
Evidence ID and claim/data ID Links the record to a specific disclosed fact or judgement.
Evidence type Source data, methodology, judgement memo, calculation, reconciliation, review, governance or external source.
File / system location Allows retrieval without depending on an individual email account.
Version / extraction date Identifies the exact record used for the reporting period.
Prepared by / reviewed by Demonstrates segregation and accountability.
Control performed States what was checked, the criteria and the outcome.
Exceptions / limitations Prevents a clean file reference from hiding unresolved issues.
Confidentiality / access Protects personal, commercially sensitive or restricted information.
Retention period Keeps evidence available for assurance, regulator review, restatement and future comparatives.

Step 5: design segregation of duties and access controls

A small team cannot always separate every task, but it should separate the most consequential decisions. The person who creates or changes a metric should not be the only person who approves the method and final result. Where full segregation is impracticable, use compensating review by someone with appropriate competence and authority.

In practice

Activity Preparation role Review / approval role — Key access control
Data extraction Operational or system data owner Independent data reviewer — Read-only source-system access or logged extraction query.
Calculation / model Metric or model owner Methodology reviewer and recalculation reviewer — Version-controlled model; restricted formula and factor changes.
Materiality judgement Cross-functional assessment team Executive or governance approver — Locked decision register after approval; changes require workflow.
Disclosure drafting Technical author Framework specialist and data owner — Controlled report version and tracked changes.
Compliance statement Reporting lead proposes wording Final technical approver / authorised governance body — Release only after checklist gate; no communications override.
Digital filing Tagging specialist Substantive reviewer and filing approver — Separate production and submission credentials.

Step 6: build reconciliations and consistency controls

Reconciliations convert “connected information” from a drafting principle into an operational control. They should not be limited to agreeing totals. The team must reconcile boundaries, definitions, periods, currencies, assumptions and narratives across the sustainability disclosures, financial statements, management reporting and external communications.

In practice

Reconciliation Control procedure Evidence
Reporting entity Compare legal and consolidation structures used in financial statements with each sustainability metric boundary. Boundary reconciliation with documented differences and rationale.
Period and cut-off Compare reporting periods, lagged datasets, acquisitions/disposals and subsequent events. Cut-off checklist and adjustment log.
Financial effects Map disclosed current/anticipated effects to financial line items, budgets, forecasts and planning assumptions. Finance sign-off and difference explanation.
GHG and energy Reconcile facility populations, energy invoices, activity data, emission factors and totals across scopes. Data-to-total bridge and factor-change log.
Targets Agree baseline, current performance, target boundary and restatement basis. Target-progress calculation and methodology approval.
Narrative vs metric Check whether qualitative claims are consistent with trends, limitations and negative performance. Disclosure challenge checklist.
Cross-report consistency Compare annual report, financial statements, investor presentation, website, regulatory filing and questionnaires. Published-claims cross-check and exception approval.

Step 7: govern models, spreadsheets and estimates

Many sustainability disclosures depend on models rather than direct measurement. Examples include Scope 3 emissions, financed emissions, climate scenarios, asset exposure, avoided emissions, workforce estimates and anticipated financial effects. Model governance should be proportionate, but it should address the same core questions: purpose, ownership, inputs, assumptions, logic, validation, change, access and limitations.

In practice

Control area Minimum practice
Model inventory and classification List material models and spreadsheets; risk-rank by complexity, judgement, data quality and disclosure significance.
Method approval Approve model purpose, calculation logic, boundary, assumptions and intended use before production.
Input controls Validate source, completeness, period, unit and transformations; retain external factor versions.
Logic controls Protect formulas, review code, test calculations, use reasonableness checks and independent recalculation.
Assumption governance Record owner, source, range, alternative assumptions, sensitivity and consistency with financial planning.
Change management Log changes, rationale, testing, approval, comparative effect and disclosure impact.
Output review Challenge outliers, unexpected trends, sign, magnitude and consistency with narrative.
Limitations and uncertainty Identify data gaps and model limitations; ensure the disclosure does not overstate precision.

Rule

SPREADSHEET WARNING

A password-protected workbook is not a control framework. Protection may restrict editing, but it does not demonstrate source completeness, correct formulas, appropriate assumptions, independent review or change approval.

Step 8: control the disclosure review and release

Data-to-disclosure control lifecycle

Controls should operate from data definition and collection through transformation, review, disclosure drafting, governance approval, publication and post-close remediation.

Disclosure controls should protect both the numbers and the meaning. A quantitatively correct metric can still be misleading if the boundary, method, uncertainty or comparative change is omitted. A narrative can be technically elegant but unsupported by evidence. The review process should therefore combine data-owner confirmation, framework review, finance consistency review, legal/claims review and governance approval.

In practice

Review layer Questions
Owner certification Is the source complete? Was the approved method used? Are limitations and changes disclosed?
Technical reporting review Does the disclosure meet the applicable IFRS requirement and preserve conditions, reliefs and materiality?
Finance consistency review Are reporting entity, period, currency, assumptions and financial-effects connections consistent?
Legal / claims review Could wording imply a legal commitment, guaranteed outcome, broader scope or compliance claim not supported by evidence?
Governance review Has the responsible body received sufficient information to oversee and approve the disclosure and reporting claim?
Publisher control Is the released file the approved version, with correct cross-references, links, digital tags and simultaneous publication?

Step 9: obtain focused management representations

Management representations are not a substitute for other evidence, but they can close the accountability loop. The representation process should be specific to the reporting system and signed by people who control the relevant information. It may include confirmation that data populations are complete, methods and changes have been disclosed, known fraud or error has been reported, material subsequent events have been considered and no material evidence has been withheld.

Use representations at multiple levels: data owner, business unit, functional executive and group reporting.

Tie each representation to identified responsibilities and reporting-period controls.

List known exceptions rather than asking owners to sign an unrealistic unconditional statement.

Escalate contradictions between representations and other evidence.

Retain the final representation set with the release and assurance evidence package.

Step 10: assess and remediate deficiencies

A deficiency process should distinguish an isolated evidence gap from a control design failure or a material reporting risk. Severity should consider the likelihood and magnitude of a potential misstatement or omission, the importance of the affected disclosure, the pervasiveness of the process and whether compensating controls exist. The terminology used for financial-control deficiencies may be adapted, but the organisation should define its own escalation thresholds clearly.

In practice

Deficiency stage Required action
Identify Describe the control objective, expected control, actual condition, affected claims and evidence.
Contain Correct the current-period disclosure or data where possible and prevent release of unsupported information.
Assess Evaluate root cause, recurrence, scope, potential misstatement, related disclosures and assurance impact.
Escalate Report significant matters to the appropriate executive, committee, audit committee or board under the policy.
Remediate Change process, role, system, method, training or review—not only the missing file.
Retest Define evidence of operating effectiveness and confirm the corrective control works before closure.
Monitor Track overdue actions, repeated findings and aggregate themes across metrics and locations.

In practice

A finance-aligned reporting calendar

Timing Sustainability control activity Finance integration point
Pre-year / Q1 Update reporting policy, data dictionary, risk assessment, methods, factor sources and control matrix. Align planning assumptions, group structure and close calendar.
Quarterly Collect selected data, operate key controls, test retrieval, monitor estimates and remediation. Use management reporting and financial close to validate trends and boundaries.
Pre-close Freeze methods, confirm populations, issue instructions, test systems and agree evidence requirements. Coordinate acquisition/disposal treatment, cut-off and forecast updates.
Close Extract data, calculate, reconcile, review exceptions and prepare disclosures. Run parallel close meetings and finance consistency checks.
Governance approval Resolve findings, approve judgements, finalise representations and compliance statement. Align audit committee/board timetable and financial-statement authorisation.
Publication Release approved human- and machine-readable versions; archive evidence and filing receipts. Confirm simultaneous publication and cross-reference integrity.
Post-close Evaluate control deficiencies, assurance findings and methodology changes. Integrate actions into ICFR/internal audit and next-year planning.

In practice

Illustrative control matrix

Control ID Risk Control activity — Owner / reviewer — Evidence
ICSR-01 A material risk/opportunity is omitted. Quarterly cross-functional review of the risk/opportunity universe against strategy, ERM, SASB topics, stakeholder and external information. — Reporting lead / risk committee — Universe, change log, minutes and approval.
ICSR-02 Metric boundary does not match the approved reporting basis. Metric owner reconciles the population to the group structure and documents approved differences. — Metric owner / finance controller — Boundary bridge and sign-off.
ICSR-03 Emission factors are outdated or unauthorised. Central factor register is updated, impact-assessed and approved before calculation. — GHG methodology owner / technical reviewer — Factor source, version, effective date and change test.
ICSR-04 Spreadsheet formula error affects a disclosed metric. Locked calculation model undergoes independent recalculation and analytical review. — Preparer / independent reviewer — Test sheet, exception log and approval.
ICSR-05 Anticipated financial-effects assumptions conflict with planning. Finance compares sustainability model assumptions with approved planning assumptions and explains significant differences. — FP&A / CFO delegate — Assumption reconciliation and memo.
ICSR-06 Narrative overstates policy implementation or effectiveness. Data owner and legal/technical reviewer inspect evidence and challenge scope, causality and limitations. — Policy owner / disclosure committee — Annotated disclosure review and evidence links.
ICSR-07 Compliance statement is unsupported. Final requirements checklist must show no unresolved material exceptions before release approval. — Technical reporting lead / authorised approver — Checklist, findings log and release gate.

Hypothetical example: a group replaces a spreadsheet-only process

The group first creates a data dictionary and assigns stable metric IDs. It then risk-ranks the metrics and selects key controls over group perimeter, factors, estimates and methodology changes. Finance owns the consolidated reporting calendar; sustainability owns technical methods; operations own source data; and reviewers are separate from preparers. Quarterly dry runs identify that one region uses a different safety denominator and that Scope 3 logistics data lag by three months.

Rather than hide the differences, the group defines the approved denominator, restates the comparative where appropriate, documents the lag policy and uncertainty, and creates a remediation plan for more timely supplier data. The final report is supported by reconciliations and owner certifications. The process is not “fully automated”, but it is controlled, repeatable and capable of being assured.

Hypothetical scenario

ILLUSTRATIVE SCENARIO

A manufacturing group reports Scope 1–3 emissions, water exposure, employee safety metrics and anticipated financial effects of transition risks. Each metric owner submits a workbook to the sustainability team at year-end. A senior manager reviews the final report, but definitions and evidence differ by business unit.

Illustrative only. It shows how the decision is made, not wording that can be copied or relied on.

In practice

Common mistakes

Mistake Why it fails Correction
Copying an ICFR control catalogue without sustainability risk assessment. The controls address financial processes but miss value-chain data, narrative claims, models and scientific methods. Start with IFRS disclosure risks, then reuse finance controls where the objective and evidence genuinely match.
Treating a data owner’s sign-off as the only control. Self-review does not challenge method, bias, boundary or calculation logic. Separate method approval, data preparation, review and release where risk warrants.
Creating a dictionary after the data is collected. Business units have already interpreted fields differently. Define and train controlled fields before the reporting period or data request.
Reviewing totals but not the population. A correct calculation over an incomplete population remains wrong. Reconcile the perimeter and completeness before recalculating totals.
Keeping assumptions inside models only. Reviewers cannot evaluate changes, consistency or uncertainty. Maintain an approved assumption register linked to the model and disclosure.
Closing findings by obtaining a missing document. The root control weakness persists and recurs next year. Remediate the process, assign an owner, retest and monitor recurrence.
Allowing communications edits after technical sign-off. Claims can become broader or more certain than the evidence. Route all post-sign-off changes through controlled technical and claims review.

Rule

MYTH VERSUS REALITY

Myth: “If finance signs the sustainability report, it has financial-reporting-grade controls.” Reality: finance involvement is valuable, but control quality depends on design and operation. Sustainability-specific data sources, boundaries, methodologies, estimates and narrative claims need controls that respond to their own risks.

In practice

Implementation roadmap

Horizon Priority Deliverable
0–30 days Governance and scoping Reporting policy, owner, control objectives, critical claims and initial risk assessment.
31–60 days Data and evidence architecture Data dictionary, evidence register, source inventory and disclosure IDs.
61–90 days Key controls and finance integration Risk-control matrix, close calendar, reconciliations, segregation and model inventory.
Before close Dry run and remediation Sample testing, retrieval exercise, deficiency log and corrective actions.
Year-end Operate and evidence controls Completed controls, representations, governance approvals and release gate.
Post-publication Monitor and improve Assurance/regulator findings, root-cause review, updated controls and next-year plan.

Readiness

Control-framework checklist

  • A named executive and governance body are accountable for IFRS sustainability reporting.
  • Control objectives are linked to specific disclosure risks, not copied from a generic checklist.
  • A controlled data dictionary covers quantitative and narrative information.
  • An evidence register links each material claim to source, method, controls and approval.
  • Preparation, review, methodology change and release are segregated or compensated by independent review.
  • Reporting entity, period, units, assumptions and financial effects are reconciled to finance.
  • Material models, spreadsheets, factors and estimates are inventoried, validated and change-controlled.
  • Disclosure review challenges boundary, balance, causality, uncertainty and consistency—not only grammar.
  • Management representations are specific, exception-based and retained.
  • Deficiencies are severity-assessed, escalated, remediated at root cause and retested.
  • The compliance statement and digital filing are protected by final release controls.
  • The framework is monitored throughout the year rather than activated only at year-end.

A sustainability data dictionary should give every quantitative and narrative field a stable identifier, definition, reporting basis, unit, boundary, period, method, source, owner, reviewer, estimation status, controls, disclosure location and change history. It prevents one metric name from carrying different meanings and gives controls a stable object to test.

Scope 3 spreadsheets should be governed as models: define their purpose, owner, inputs, assumptions, logic, validation, access, version changes and limitations. Lock calculation logic, retain source and factor evidence, separate preparation from review, reconcile boundaries and totals, and document estimates and exceptions.

Reconcile boundaries, definitions, periods, currencies, assumptions and narratives across sustainability disclosures, financial statements, management reporting and external communications. For GHG and energy, also reconcile facility populations, invoices, activity data, emission factors and totals; retain documented differences, factor changes and finance sign-off.

First distinguish an isolated evidence gap from a control-design failure or material reporting risk, then assess severity using potential misstatement, affected disclosure, pervasiveness and compensating controls. Correct or contain the current issue, analyse root cause, escalate significant matters, remediate the process or system, retest effectiveness and monitor recurrence.

Self-check

  1. Which three disclosures would create the greatest decision risk if misstated or omitted, and which controls address them?
  2. Can every material metric be reproduced from retained source data using the approved methodology?
  3. Which sustainability assumptions should be reconciled to financial planning, and who approves differences?
  4. What would prevent a communications edit from changing the technical meaning after sign-off?

Questions

Questions people ask

Does IFRS S1 require COSO?

IFRS S1 and IFRS S2 do not prescribe COSO, SOX or any other named internal-control framework. They do, however, require information that is material, fairly presented, connected, timely and supported by consistent data and assumptions.

What should a sustainability data dictionary contain?

A sustainability data dictionary should give every quantitative and narrative field a stable identifier, definition, reporting basis, unit, boundary, period, method, source, owner, reviewer, estimation status, controls, disclosure location and change history. It prevents one metric name from carrying different meanings and gives controls a stable object to test.

How should Scope 3 spreadsheets be controlled?

Scope 3 spreadsheets should be governed as models: define their purpose, owner, inputs, assumptions, logic, validation, access, version changes and limitations. Lock calculation logic, retain source and factor evidence, separate preparation from review, reconcile boundaries and totals, and document estimates and exceptions.

What reconciliations are needed?

Reconcile boundaries, definitions, periods, currencies, assumptions and narratives across sustainability disclosures, financial statements, management reporting and external communications. For GHG and energy, also reconcile facility populations, invoices, activity data, emission factors and totals; retain documented differences, factor changes and finance sign-off.

How are control deficiencies remediated?

First distinguish an isolated evidence gap from a control-design failure or material reporting risk, then assess severity using potential misstatement, affected disclosure, pervasiveness and compensating controls. Correct or contain the current issue, analyse root cause, escalate significant matters, remediate the process or system, retest effectiveness and monitor recurrence.

Practical conclusion

A credible internal-control framework is not measured by the number of controls. It is measured by whether the system prevents or detects material reporting failures, preserves evidence and enables timely correction. Use finance discipline where it fits, add sustainability-specific controls where it does not, and organise everything around the information that IFRS S1/S2 users are meant to receive.

Framework references

Disclosures this page affects

Take it with you

The checklists as a working spreadsheet

Every checklist and table on this page, with empty status, owner and evidence columns for your team to fill in and keep.

Download .xlsx

✓ Knowledge Hub AI Assistant · Human-in-the-loop

Ask about this guide

It answers from this page, and reaches into the linked disclosure cards when your question is about the standard itself. Your first two answers are free without signing in.

Try
Automated · the LRA team is one click away

Go deeper · IFRS S1 / S2

Certified IFRS S1 & S2 (ISSB) Applied Sustainability Reporting

This page settles one requirement. The IFRS S1 & S2 course walks the whole ISSB workflow — governance, strategy, risk management, metrics and targets — with drafting exercises on your own data.

See the course →
/en/knowledge-hub/disclosure-guides/ifrs-issb/ifrs-issb-climate-risk-scenarios-resilience/internal-controls-over-ifrs-sustainability-disclosures-a-practical-fra/