An ESG (environmental, social, and governance) audit tests whether an organization’s ESG disclosures are complete, accurate, and supportable. It doesn’t test whether the organization “is sustainable.”

Most published ESG checklists are really risk-category inventories. They list environmental, social, and governance questions to ask the business, but they don’t say how to test, sample, or document the answers.

This checklist follows the same structure an audit already uses: plan, gather evidence, test, and report, mirroring the approach applied to financial statement and internal control audits. It works for internal audit functions building an ESG assurance program, and for external auditors or independent assurance providers engaged to opine on ESG disclosures.

Phase 1: Define Scope, Materiality, and the Assurance Level

Start with the materiality assessment output: which topics, entities, and reporting periods are in scope. From there, decide what level of assurance the engagement needs to deliver.

Assurance comes in two levels. 

Reasonable assurance is the higher bar, close to a financial statement audit, with the practitioner stating a positive opinion that the information is fairly presented. Limited assurance is closer to a review: the practitioner performs inquiry and analytical procedures and reports that nothing came to their attention suggesting the information is materially misstated. Reasonable assurance takes meaningfully more fieldwork. 

Confirm which level the engagement requires before building the audit program, because it changes the sample sizes and testing depth in every later phase.

Phase 2: Select the Standard and Set the Audit Program

Next, pick the assurance standard. Internationally, that’s the International Standard on Assurance Engagements (ISAE) 3000 (Revised) for general sustainability information, or ISAE 3410 when a separate conclusion on greenhouse gas (GHG) statements is required. 

Domestically, US engagements follow the AICPA’s attestation standards: an examination engagement (AT-C 205) for reasonable assurance, or a review engagement (AT-C 210) for limited assurance.

A note for readers planning ahead:

According to the IAASB, its new International Standard on Sustainability Assurance (ISSA) 5000 becomes effective for periods beginning on or after December 15, 2026, with early adoption permitted. It will replace ISAE 3000 (Revised) for sustainability work, and the IAASB has said ISAE 3410 will be withdrawn once ISSA 5000 takes effect. On the US side, the AICPA issued exposure drafts in 2026 proposing dedicated attestation sections (AT-C 325 and AT-C 330) built to align with ISSA 5000. Neither is final yet, but both are worth building toward now, before an engagement forces the switch.

With the standard picked, set the audit program: scope, timeline, sampling approach, and which controls get tested for operating effectiveness versus which data gets tested substantively.

Phase 3: Gather Evidence in the Field

Before testing starts, build a data source inventory. This list should include every system ESG data originates from, such as utility billing, HR and payroll, supplier questionnaires, environmental health and safety platforms, and the spreadsheets that inevitably sit between them. 

For each ESG control, walk through how the data gets captured, who approves it, and where it lands before it reaches the report. Run structured interviews with the people who own the data and the controls: how employees experience health and safety practices, how leadership talks about governance commitments. Document these consistently enough that they hold up as audit evidence.

Evidence standards matter here as much as they do in a financial statement audit. 

Phase 4: Test ESG Controls Like Financial Controls

Apply the same control-testing discipline used in SOX or financial statement work.

  • Test for existence and completeness: does every facility or site report into the consolidated ESG figure, or are some excluded without a documented reason? 
  • Test for accuracy: recalculate a sample of GHG emissions figures from raw activity data, fuel use and energy consumption, rather than accepting the totals as calculated. 
  • Test for consistency: compare how the same metric was treated period over period and flag any undocumented change in methodology.

Scale sample sizing and selection to the assurance level set in Phase 1. Reasonable assurance needs meaningfully more testing depth, not just more questions asked.

Tie qualitative, forward-looking claims, “committed to reducing emissions 30% by 2030” is the classic example, back to a documented, board-approved target. Unsupported forward-looking claims are one of the more common drivers of ESG-related regulatory and legal scrutiny, so this step is worth the extra time.

Phase 5: Analyze Findings and Report Them

Group findings by severity: control deficiency, data quality issue, or unsupported disclosure. Each carries a different remediation path and a different audit committee reporting requirement.

Draft the assurance report or internal audit report to match the standard selected in Phase 2, then route findings to the audit committee or ESG steering committee with a documented management response and a remediation timeline attached.

Common ESG Audit Obstacles (And What Fixes Them)

  • Fragmented data across systems with no single source of truth. Centralizing ESG evidence the same way financial workpapers get centralized shortens fieldwork significantly.
  • Subjective, qualitative metrics like culture or community engagement resist standard testing. Document the judgment applied, not just the conclusion.
  • Framework churn. ISSB standards get adopted at the jurisdiction level rather than applying globally by default, so multinational entities may track more than one regime at once.
  • Resource and skills gaps. Most finance and audit teams weren’t trained on ESG-specific frameworks. Pairing existing audit methodology with ESG-specific criteria closes that gap faster than building a parallel ESG audit function from scratch.

How Trullion Supports ESG Audit Evidence

Each phase above has a point where evidence can drift from the conclusion it’s meant to support.

Fragmented data (Phase 3) calls for the same traceability discipline Trullion’s Connected Audit applies to financial statement evidence. When evidence gets detached from findings (Phases 4 and 5), Financial Statement Validation ties disclosure and testing conclusions directly back to the underlying record, so a reviewer questioning a finding three weeks later finds the evidence attached to it, not reconstructed after the fact. And when frameworks shift (Phases 1 and 6), Trullion’s Knowledge Room holds current standard requirements and internal policy in one place, so this year’s testing gets checked against this year’s version of the framework, not a rolled-forward assumption.

It’s the same rigor applied to financial statement evidence, not a separate ESG methodology.

See how Trullion supports faster, error-free audits. Learn more today. 

FAQs

What is an ESG audit checklist?

An ESG audit checklist is a structured set of phases, evidence requirements, and control tests auditors work through to verify an organization’s environmental, social, and governance disclosures, mirroring the discipline used in financial statement audits.

What’s the difference between an ESG audit and a materiality assessment?

A materiality assessment determines which ESG topics matter enough to report on and sets the scope. An ESG audit is the independent testing that follows, checking whether the resulting disclosures are complete, accurate, and supported by evidence.

Is ESG assurance mandatory, and where?

It depends on the jurisdiction. Under the EU’s 2026 Omnibus reform, companies still in CSRD scope must obtain limited assurance on their sustainability reporting. California’s SB 253 will require assurance starting with the 2027 reporting year, with no assurance required for the first 2026 filing. At the US federal level, the SEC’s climate disclosure rule was never enforced and is now headed toward formal rescission.

What frameworks are used in ESG audits today, and is the Task Force on Climate-related Financial Disclosures (TCFD) still relevant?

Common frameworks include the ISSB’s IFRS S1 and S2, the EU’s simplified European Sustainability Reporting Standards (ESRS), and, for US companies, California’s SB 261 reporting requirements. The TCFD itself was formally disbanded in October 2023, with its monitoring role absorbed by the ISSB. Its recommendations are fully incorporated into IFRS S2, so companies applying IFRS S1 and S2 already meet the TCFD’s original recommendations, though some regulations, including SB 261, still reference TCFD by name as an accepted framework.

What’s the difference between limited assurance and reasonable assurance in ESG audits?

Reasonable assurance is the higher level, involving more extensive testing and a positive opinion that the information is fairly presented, similar to a financial statement audit. Limited assurance involves inquiry and analytical procedures, with the practitioner reporting that nothing came to their attention indicating a material misstatement, similar to a financial statement review.

See how Trullion supports faster, error-free audits.

Learn more