← Back to Blogs
Insights/Blogs
All IndustriesJune 20267-8 min

ESG Assurance in India

What 'Reasonable Assurance' Actually Means When Auditors Sign Your BRSR

ESG Assurance in India

Reading Time

7 min

Article Sections

6

Share Links

3

01

Article Section

Introduction

Part 01

SEBI has mandated reasonable assurance on BRSR Core KPIs for top listed companies, with a phased rollout that began with the top-150 in FY2023-24 and expands to the top-1000 by FY2026-27. Most companies have responded by treating it as they would any audit formality: compile the numbers, hand them to the assurance provider, and collect the sign-off.

That approach misunderstands what reasonable assurance actually is. It is the highest level of assurance available in non-financial reporting (the equivalent of a financial audit in its evidentiary demands). It does not ask whether the numbers look plausible. It asks whether the numbers are correct and whether the process that produced them can be independently verified.

Companies that are not prepared for this are discovering the gap mid-assurance, when auditors begin asking for source data, documented methodologies, and data governance records that do not exist. This piece explains what reasonable assurance actually demands, how it differs from limited assurance, and where Indian companies are most commonly getting caught out.

02

Article Section

The Assurance Landscape: What SEBI Has Actually Mandated

Part 02

BRSR Core is the subset of 49 key performance indicators within the broader BRSR framework on which SEBI has made reasonable assurance mandatory. These KPIs span environmental metrics like emissions, energy, water, waste, social metrics including workforce safety, gender diversity, and training, and governance indicators covering transparency and business conduct. They represent the indicators SEBI considers most decision-relevant for investors.

Assurance comes in two levels and the distinction matters significantly. Limited assurance provides negative assurance: the assurance provider states that nothing has come to their attention to suggest the information is materially misstated. It relies primarily on inquiry and analytical procedures. Reasonable assurance provides positive assurance: the provider states that the information is, in all material respects, correct. It requires substantive evidence collection, process verification, and sample testing of underlying data. The preparation required for each is not comparable.

SEBI's phased mandate covers the top-150 listed companies from FY2023-24, top-250 from FY2024-25, top-500 from FY2025-26, and top-1000 from FY2026-27. On the provider side, SEBI permits both chartered accountants and SEBI-registered ESG rating providers to conduct BRSR assurance. The applicable standards are ISAE 3000 for non-financial assurance engagements, AA1000AS, and guidance issued by the ICAI. The choice of provider and standard affects the nature of the engagement and the rigour of the process.

It is worth being precise about what BRSR Core assurance covers. Assurance applies to the specific KPIs designated under BRSR Core not to the entire BRSR disclosure. Companies that conflate the two may under-prepare on the KPIs that matter most while over-investing in areas that are not subject to the same standard of scrutiny.

03

Article Section

What Reasonable Assurance Actually Involves

Part 03

When an assurance provider walks into a reasonable assurance engagement, they are not checking whether the numbers look right. They are verifying that the numbers are right and that the process that produced them is sound, consistent, and documented. This involves evidence collection like meter readings, invoices, HR records, production logs, and energy bills that tie back to the reported figures. It involves process walkthroughs, understanding how each KPI is collected, who collects it, how it is aggregated across business units, and who reviews it before disclosure. And it involves sample testing like selecting a representative set of underlying data points and tracing them through to the reported number.

The methodology question is where many companies first encounter difficulty. If there is no documented methodology for how a KPI was calculated, which emission factor was used, how the organisational boundary was defined, how estimates were applied where metered data was unavailable then the auditor cannot verify it. A number without a documented process is, from an assurance standpoint, unverifiable.

What Reasonable vs Limited Assurance Means in Practice

The practical difference between limited and reasonable assurance is most visible in what the assurance provider must do to reach their conclusion. Under limited assurance, the provider asks questions, reviews disclosures, and looks for reasons to believe something is wrong. If nothing alarming surfaces, they issue a negative assurance conclusion. Under reasonable assurance, the provider must gather positive evidence that everything is right. The burden is reversed and the preparation required on the company's side is substantially greater. A useful way to understand the difference: limited assurance is a walkthrough; reasonable assurance is a full audit. Companies accustomed to limited assurance engagements or to financial audits where processes and controls are well-established, often underestimate what the shift to reasonable assurance on ESG data demands. Financial data benefits from decades of accounting standards, ERP systems, and internal controls. ESG data, in most Indian companies, does not yet have an equivalent infrastructure.

04

Article Section

Where Indian Companies Are Getting Caught Out?

Part 04

No documented data collection methodology

Numbers exist but the process that produced them is not recorded. Which emission factor was applied? How was the organisational boundary defined? How were partial-year figures annualised? Without answers to these questions in documented form, the auditor has no process to verify but only a number.

Fragmented data ownership

ESG data sits across HR, facilities, procurement, and finance, with no central owner, no standardised collection template, and no audit trail connecting source data to reported figures. When an auditor asks to trace a reported number back to its source, the answer is often a spreadsheet maintained by someone who has since left the team.

Emissions boundary inconsistencies

What is included in the Scope 1 and Scope 2 boundary shifts between reporting years without documented rationale. A facility added mid-year, a leased asset treated differently across periods, or a subsidiary included in one year and excluded in the next. Each of these creates inconsistencies that reasonable assurance will surface.

BRSR reporting mistaken for a GHG inventory

Many companies have been reporting emissions under BRSR using informal or undisclosed methodologies; energy bills converted using default factors, estimates applied without documentation. These figures may satisfy BRSR disclosure requirements but do not constitute a GHG Protocol-aligned inventory. Reasonable assurance applies a higher standard, and the gap becomes visible quickly.

Treating assurance as a year-end exercise

Data that has not been collected, documented, and reviewed through the year cannot be reconstructed at year-end for assurance purposes. Reasonable assurance requires a continuous data governance process, not a retrospective data-gathering exercise. Companies that start preparing when the auditor is already scheduled will not have enough time to close the gaps.

05

Article Section

Conclusion

Part 05

Reasonable assurance is not a formality. It is the highest evidentiary standard in non-financial reporting, and it demands a level of data governance, methodology documentation, and process rigour that most Indian listed companies have not yet built. The companies that navigate it well are the ones that treat it as a year-round commitment not a year-end exercise.

For companies approaching their first reasonable assurance engagement, or looking to improve after a difficult first cycle, the starting point is an honest gap assessment: where is data ownership unclear, where are methodologies undocumented, and where are boundaries inconsistent. ESG Astraa works with Indian listed companies to build the data infrastructure and governance processes that make reasonable assurance manageable.

06

Article Section

Frequently Asked Questions

Part 06

What is BRSR Core assurance?

BRSR Core assurance is the independent third-party verification of a defined set of 49 KPIs within the BRSR framework, mandated by SEBI for top listed companies in a phased rollout. Reasonable assurance is required, meaning the assurance provider must gather positive evidence that the reported figures are correct.

What is the difference between limited and reasonable assurance in ESG?

Limited assurance provides a negative conclusion: nothing has come to the provider's attention suggesting material misstatement. Reasonable assurance provides a positive conclusion: the information is correct in all material respects. Reasonable assurance requires substantially more evidence, process verification, and data governance preparation from the company.

Who can provide BRSR assurance in India?

SEBI permits both chartered accountants and SEBI-registered ESG rating providers to conduct BRSR Core assurance. The applicable standards include ISAE 3000 for non-financial assurance, AA1000AS, and ICAI guidance. The choice of provider affects the nature and rigour of the engagement.

Which companies need BRSR Core assurance and from when?

SEBI's phased mandate covers the top-150 listed companies from FY2023-24, top-250 from FY2024-25, top-500 from FY2025-26, and top-1000 from FY2026-27. Companies approaching the threshold should begin building assurance-ready data infrastructure well before their first mandated engagement.

How should companies prepare for reasonable assurance on BRSR?

Preparation requires building documented data collection methodologies for each BRSR Core KPI, establishing clear data ownership across functions, defining and consistently applying organisational and emissions boundaries, and maintaining an audit trail from source data to reported figures throughout the year and not just at year-end.

Keep Reading

Related Blogs

Next Step

Ready to turn ESG complexity into strategic advantage?

Talk to ESG Astraa about disclosures, climate strategy, governance controls, and execution support for your team.

We use cookies to run this site and, with your consent, to understand how it is used. See our Cookie Policy for details.