IAASB’s ISSA 5000 Sets the Global Standard for Sustainability Assurance In brief: The International Standard on Sustainability Assurance, or ISSA 5000, developed by the International Auditing and Assurance Standards Board (IAASB) in late 2024, is widely expected to be the global benchmark for sustainability assurance, influencing the future of sustainability audits. As regulatory mandates for sustainability reporting increase, organisations seeking to enhance the credibility of their reports are strongly encouraged to understand the assessment criteria of ISSA 5000 in order to receive reasonable or limited assurance conclusion that meets investor and regulatory expectations.Dive deeper. Topics Internal Audit and Corporate Governance Risk Management and Regulatory Compliance ESG/Sustainability As the importance of sustainability has grown globally, so has the need for reliable, credible and consistent information about organisations’ sustainability performance. Many regulations globally require a level of assurance over sustainability reporting — in some cases, commencing with limited assurance and progressing to reasonable assurance in the next several years (as applicable).To facilitate this assurance requirement, the IAASB published ISSA 5000 in November 2024. It is designed for assurance practitioners and applies to assurance engagements on sustainability information reported for periods beginning on or after 15 December 2026. Organisations should understand the standard as well — see“Why should this matter to companies?,” below.ISSA 5000 replaces the International Standard on Assurance Engagements 3000 (Revised) (ISAE 3000), used to audit non-financial information. Once ISSA 5000 comes into effect, ISAE 3000 will no longer apply to sustainability assurance engagements.[1]ISSA 5000 is supported by the International Organisation of Securities Commissions (IOSCO), the international body of securities regulators, which sees it as fulfilling its recommendations to establish a comprehensive global assurance framework for sustainability-related corporate reporting.The standard is expected to be adopted by regulators in several countries in the Asia–Pacific region (e.g., Australia, Hong Kong, Japan, Malaysia and Singapore) and eventually by the European Union.Why should this matter to companies?While the standard is intended for use by assurance practitioners (i.e., external audit firms), organisations that produce sustainability reports under regulatory regimes should be familiar with what the standard entails and prepare reports aligned with the standard to receive the assurance they need. Specifically, organisations should focus on two key aspects internally: auditability of sustainability data and the role of the internal audit (IA) function. We provide recommended steps at the end of this blog.ISSA 5000: What are the key highlights?ISSA 5000 applies to sustainability information, regardless of how this information is presented or which framework is used to prepare it. It covers limited and reasonable assurance and works with both single materiality and double materiality concepts.ISSA 5000 aligns with most global reporting standards and frameworks, such as the European Sustainability Reporting Standards (ESRS), the IFRS Sustainability Standards and the Global Reporting Initiative (GRI). This is good news for organisations reporting under these standards and frameworks, as the alignment would help them achieve the relevant assurance conclusion.Below are some notable aspects of ISSA 5000:It is specifically applicable to sustainability assurance engagements.It provides specific methodologies for assessing the completeness, accuracy and reliability of sustainability data instead of relying solely on the practitioner’s judgement. This includes consideration of the processes for collecting, analysing and reporting sustainability information.It relies on the work of the internal audit function, whose competence in sustainability matters is a key criterion.It requires the assurance practitioner to conclude whether the sustainability information is prepared or fairly presented, in all material respects, in accordance with the applicable criteria. (Criteria refers to the reporting standard or framework in which the sustainability information is prepared.)It considers the relevance of the criteria in determining when financial and/or impact materiality applies. For example, in the case of ESRS, both financial and impact materiality apply.It provides a definition of the intended users of the report (internal and external) to ensure that the expressed conclusions and the confidence in the information reported are of decision-making relevance to those users.When assessing whether the sustainability information is materially misstated, ISSA 5000 requires consideration of qualitative factors such as impact severity, potential non-compliance and inaccurate narrative disclosure.It focuses on reporting compliance, specifically for greenhouse gas (GHG) emissions, ensuring that they align with the relevant framework (e.g., the GHG Protocol).It reiterates the importance of auditability of data. Estimates and forward-looking information need to be supported by evidence and based on proper methods, assumptions and management intentions.How can organisations prepare?To ensure auditability of sustainability data, organisations should implement robust data management practices and perform regular reviews of their sustainability reporting processes and controls, including data validation prior to assurance, to help reduce the risk of misstatement.The IA function should be trained in sustainability matters in order to assess the controls over the organisation’s sustainability disclosures. This includes evaluating the adequacy of controls to mitigate sustainability-related risks as well as reviewing whether the measurement and reporting of sustainability data is aligned with the relevant reporting frameworks (e.g., the GHG Protocol).Other specific steps organisations can take right now include the following:Conduct a readiness assessmentEvaluate the current ESG framework to identify potential gaps which may impact the organisation’s sustainability disclosures. Define an action plan to enhance alignment with ISSA 5000 objectives.Capacity buildingProvide training for internal stakeholders such as the Chief Financial Officer, Chief Sustainability Officer, Chief Audit Executive, and internal audit and ESG teams. Foster cross-functional collaboration between sustainability and operations teams.Auditability of ESG dataConduct a data gap analysis to assess availability, completeness and accuracy of ESG data. Establish data governance protocols to improve data integrity and reliability. Ensure that ESG data is traceable and verifiable for assurance audits under ISSA 5000.Protiviti has published a Guide of Frequently Asked Questions which has answers to many of the questions organisations face as they prepare to comply with current and future regulations and standards. In addition, we assist clients by providing expertise in ESG data management, readiness assessment such as data validation of sustainability data and evaluating internal controls over sustainability reporting processes. We also offer capacity-building sessions to train our clients on reporting requirements, ensuring reliable and auditable sustainability disclosures.IAASB-ISSA-5000-Sustainability-Assurance-Frequently-Asked-Questions.pdf Find out more about our solutions: Sustainability Consulting Sustainability continues to evolve as companies recognise supporting environmental, social and governance (ESG) issues is essential to survive in the marketplace. ESG Reporting and Governance Gain transparency and accountability by controlling the programme and its implementation. We enable better decision-making and focus on regulatory requirements, including the timeliness and accuracy of reporting and external communication with regulators. Internal Audit Our strategic Internal Audit sourcing models deliver specialised talent, methodology, and technology to meet the evolving needs of Internal Audit functions ranging from full outsourced solutions and delivery centers to tactical staff-augmentation. Leadership Rich Turley Rich is a managing director with over 20 years’ experience in assurance, audit, risk, and compliance management. He leads major internal audit, risk and compliance management engagements for various ASX-listed companies and major government agencies. He is a leader in ... Learn More Ranadip Datta Rana is a commercially focused and highly driven risk professional specialising in multi-channel complex solution consulting in APAC. A long career in institutional banking , solution sales and consulting with global clients in several industry verticals ... Learn More Featured insights WHITEPAPER Sustainability regulation: ESG disclosures and demand for accountability set the tone for the future In recent years, increasing pressures from a variety of stakeholders have combined to drive companies toward more sustainable practices in their business operations and greater transparency. The real game-changer, however, has been the proliferation... BLOGS Sustainability FAQs: Your top questions answered As regulatory and stakeholder expectations around sustainability continue to evolve on a near daily basis, Protiviti has created an online guide of frequently asked questions to help business leaders navigate this dynamic complexity. The FAQ Guide... BLOGS The ESG Controller—A “Job Of The Future” That’s Actually Here Now As the stakes increase for ensuring the integrity of sustainability reports, CFOs across all industries should not only consider adding the ESG controller role in the finance function but also determine where it sits in the organisational structure... BLOGS COSO issues supplemental guidance on internal control over sustainability reporting – With examples Last Thursday, the Committee of Sponsoring Organisations of the Treadway Commission (COSO) released interpretive guidance on how to effectively apply the 2013Internal Control — Integrated Framework (ICIF)— which is currently applied to... BLOGS ISSB sets new IFRS sustainability disclosure standards: Jurisdictions must act The ISSB has released the first sustainability disclosure standards. They’re voluntary, but wide adoption is expected among IFRS reporters around the globe.The standards focus on climate disclosures, targets and metrics, initially through ISSB S2... Button Pagination Button