← Back to Blogs
Insights/Blogs
All IndustriesJuly 20265-6 min

What ESG Assurance Providers Are Finding When They Verify BRSR Data?

A Candid Industry View

What ESG Assurance Providers Are Finding When They Verify BRSR Data?

Reading Time

4 min

Article Sections

6

Share Links

3

01

Article Section

Introduction

Part 01

Assurance providers spend months each year verifying BRSR disclosures, and what they find rarely matches the polished narrative in the published report. The numbers are usually directionally right. The systems behind them are often not ready to prove it.

As BRSR Core assurance requirements expand to more companies and SEBI's expectations around assessment and assurance evolve, the quality of the underlying data infrastructure, not just the final disclosed figure, is coming under increasing scrutiny.

This article draws on what assurance engagements are actually surfacing: the recurring gaps, where they cluster, and what separates companies that pass through assurance cleanly from those that don't.

02

Article Section

The Assurance Process Up Close

Part 02

BRSR assurance involves independent verification of specific disclosed indicators against underlying source data, sampling methodology, evidence requests, and management representation letters. It is distinct from a simple compliance check.

There is an important distinction between limited assurance and reasonable assurance levels under applicable assurance standards. Even limited assurance requires defensible evidence trails, not just plausible numbers.

The assurance process, by design, surfaces exactly where a company's reporting infrastructure is solid and where it is improvised. That pattern is consistent across most engagements regardless of company size or sector.

03

Article Section

What Assurance Providers Are Actually Finding?

Part 03

Data lives in spreadsheets, not systems

The most common finding is not incorrect data but unverifiable data: numbers pulled together annually from disconnected spreadsheets and emails rather than from a system with a built-in audit trail. Assurance providers can usually validate the final number eventually, but the process reveals how fragile the underlying collection process is.

Scope 3 estimates often cannot survive their own footnotes

Companies frequently disclose Scope 3 figures built on industry-average emission factors or supplier estimates that, on closer inspection, the company itself cannot fully explain or defend when asked how the number was derived.

Site-level data collection is inconsistent across the same company

In multi-site organisations, assurance providers commonly find that different facilities use different methods, different units, or different reporting cadences for the same indicator, producing a consolidated number that looks clean but rests on inconsistent inputs.

Governance sign-off often lags the actual data review

Board or audit committee sign-off on sustainability disclosures sometimes happens before the underlying data has been fully reconciled, meaning governance accountability is procedurally present but substantively thin at the point of approval.

04

Article Section

What This Means for Companies Preparing for Assurance?

Part 04

Treat data collection as a continuous process, not an annual event

Companies that build monthly or quarterly data capture into their operating rhythm consistently produce smoother assurance outcomes than those that reconstruct a year of data in the weeks before the reporting deadline.

Document the methodology behind every estimate as you make it

Where actual data is unavailable and estimates are necessary, particularly for Scope 3, recording the methodology and assumptions at the time of estimation, rather than after the fact, is what allows the figure to survive assurance scrutiny.

Standardise data collection across sites before standardising the dashboard

Investing in a unified reporting dashboard means little if the underlying site-level inputs feeding it are inconsistent. The standardisation work needs to happen at the data collection layer first.

Involve assurance-readiness thinking earlier in the reporting calendar

Companies that engage their assurance provider or internal audit function early in the reporting cycle, rather than only at year-end, tend to catch gaps while there is still time to address them.

05

Article Section

Conclusion

Part 05

What assurance providers are finding is not, in most cases, a story of misrepresentation. It is a story of reporting infrastructure that has not caught up to the seriousness with which BRSR disclosures are now being treated, by regulators, investors, and the companies' own boards.

As assurance requirements expand and scrutiny deepens, the companies that close this infrastructure gap before it is exposed in an assurance engagement will be the ones whose ESG disclosures hold up, not just on paper, but under examination.

06

Article Section

Frequently Asked Questions

Part 06

What is the difference between limited assurance and reasonable assurance for BRSR data?

Limited assurance involves a narrower scope of procedures and provides moderate confidence in the disclosed data, while reasonable assurance involves more extensive testing and provides a higher level of confidence.

Why do Scope 3 emissions figures often face the most scrutiny during ESG assurance?

Scope 3 figures often rely on industry-average emission factors or supplier estimates rather than primary data, making the methodology and assumptions behind the number harder for companies to defend.

What kind of evidence do assurance providers typically request when verifying BRSR disclosures?

Assurance providers typically request source data, sampling documentation, methodology records, and management representation letters that trace each disclosed figure back to its origin.

How can companies prepare their data systems before an assurance engagement begins?

Companies can prepare by building continuous data collection into their operating rhythm, standardising methods across sites, and documenting estimation assumptions at the time they are made.

Is BRSR assurance currently mandatory for all listed companies in India?

BRSR Core assurance currently applies to a defined set of large listed companies based on market capitalisation, with the scope expanding in phases rather than applying to all listed companies at once.

Keep Reading

Related Blogs

Next Step

Ready to turn ESG complexity into strategic advantage?

Talk to ESG Astraa about disclosures, climate strategy, governance controls, and execution support for your team.

We use cookies to run this site and, with your consent, to understand how it is used. See our Cookie Policy for details.