Knowledge guide
For first-time reporters
GRI / SECR / TCFD / CSRD
If your buyers, regulators or board have started asking about an ESG audit and you’re not sure what one actually involves – this page explains it. The frameworks, the workflow, the evidence, what auditors look for, and what “audit-ready” means in practice. Written for people who haven’t reported before.
Frameworks we cover
Audit pass rate (clients)
English. No jargon.
Start here
Most organisations meet ESG audit requirements for the first time when a buyer, lender, regulator or parent group requests assurance over published sustainability data. The audit itself is independent assurance — somebody outside your business testing whether the numbers, narrative and evidence in your sustainability report can be believed. It is the same idea as a financial audit, applied to non-financial data.
Two questions decide most of the work. First, which framework are you reporting against? GRI, SECR, TCFD and CSRD are the four most common in the UK. Second, what level of assurance is required? “Limited” is the most common starting point; “reasonable” is a higher bar and is increasingly demanded for CSRD-in-scope groups. The framework determines what is in the report; the assurance level determines how thoroughly the auditor tests it.
The four frameworks · which one applies
GRI
The most-used voluntary global standard. Universal Standards 2021 plus sector-specific add-ons. Strong on stakeholder narrative and material-topic disclosure. Often the “spine” of an annual sustainability report.
SECR
UK statutory. Mandatory for large companies and quoted entities. Reports Scope 1, Scope 2, intensity ratio and energy-efficiency narrative. Filed in the Directors’ Report alongside statutory accounts.
TCFD
UK statutory for FCA-listed and large companies. Four pillars: governance, strategy, risk management, metrics & targets. Increasingly absorbed into ISSB / IFRS S2 globally.
CSRD
EU framework, phased in from FY24/25. Double-materiality assessment, EFRAG ESRS data points, assurance-required. UK groups with EU revenues, subsidiaries or branches are typically in scope.
What auditors actually test
Whatever framework you’ve picked, an assurance review walks the same five layers. If these five are in good order, the audit becomes administrative.
01
Auditors will ask how you calculated each number – emission factors, conversion factors, boundary definitions, exclusions. The methodology needs to be written down and applied consistently year-on-year.
02
For every figure in the report, the auditor will sample the supporting evidence – utility bills, fleet logs, supplier data, payroll records. The evidence trail needs to be organised, not reconstructed in panic.
03
Auditors test whether you’re reporting on the right things. A materiality assessment (single or double, depending on framework) is the document that proves you have.
04
What the report says in prose has to match what the numbers say. Over-claiming, vague claims, or claims unsupported by evidence are the most common cause of qualified opinions.
05
Auditors will ask who signed off the strategy, who owns the targets, and where ESG sits on the board agenda. Board minutes, policies and committee terms-of-reference are part of the evidence file.
A typical first-time workflow
Match framework to size, sector, listing status and buyers. Most organisations end up with a hybrid – GRI for narrative, SECR/TCFD for statutory, CSRD-readiness if EU-exposed.
Scope 1, Scope 2, and material Scope 3. Defensible emission factors, written methodology, exclusions documented. This is where most year-one effort sits.
Stakeholder mapping, topic prioritisation, single or double materiality matrix. The document that justifies what your report does and doesn’t cover.
Numbers, narrative, governance disclosures, risk register, targets, progress. Plain English. No greenwashing. Cross-checked against the framework checklist.
Internal review against the assurance criteria. Evidence file finalised. Walk-through with finance and audit lead. Fix gaps before the auditor arrives.
Auditor samples data, tests methodology, reviews narrative. Issues an opinion. Year-two onwards is materially faster — the system is built.
Common pitfalls
01
Reporting against a voluntary framework when statutory SECR / TCFD obligations are unmet is a common mistake. The statutory layer comes first.
02
“Carbon-neutral” and “net-zero” claims without supporting methodology are the single biggest cause of qualified opinions. Plain language with caveats survives audit.
03
Pulling supporting evidence in the week before audit guarantees gaps. Building an evidence library through the year removes most of the audit risk.
04
ESG reports are signed by directors and assured by auditors. They are governance documents, not marketing materials. The reporting workflow should sit in finance, not brand.
Common questions
An ESG audit is independent assurance over the sustainability information you publish – your carbon footprint, your social impact data, your governance disclosures. It tests whether what you’ve said is true, complete and consistent with the framework you’ve picked. Auditors are increasingly required by regulators (FCA-listed entities, CSRD-in-scope groups) and by buyers (sustainability-weighted procurement).
It depends on your size, your sector, your listing status and your buyers. UK SECR is a statutory requirement for large companies. TCFD is mandatory for FCA-listed and large UK firms. GRI is the most-used voluntary global standard. CSRD applies to EU-active groups and is being phased in. Most organisations end up running a hybrid – GRI for the narrative, SECR/TCFD for the statutory layer, with CSRD-readiness for groups with EU exposure.
Most first cycles take six to twelve weeks depending on framework and data maturity. Year two is materially faster because the baseline, the methodology and the evidence library already exist. Most cost and time goes into data architecture in year one – not into writing the report.
It means three things. (1) Your numbers are calculated against a methodology you can defend. (2) Your evidence trail – invoices, meter reads, supplier data – is organised and accessible. (3) Your narrative says what the numbers say, with no over-claiming. If those three are in place, the audit is administrative, not adversarial.
Your assurance provider (Big Four or independent) will sample your data, test your methodology, walk your evidence file, and check your narrative against your numbers. They issue an opinion – typically “limited” or “reasonable” assurance. A clean opinion means no qualifications. A qualified opinion means specific items couldn’t be verified – usually fixable in year two.
For a starting point, yes. For an audit-ready disclosure, no. Free calculators give you indicative numbers but not a methodology your auditor can defend. The gap shows up under scrutiny. Most organisations move from a calculator to a defensible methodology in year one of formal reporting.
If you’ve been asked for an ESG audit and you’re not sure what’s actually required, book a no-obligation 30-min call. We’ll explain the framework that applies to you, what audit-ready looks like for your size and sector, and what a sensible first-cycle workflow would involve.
Get in touch with the One Earth Education team!