Skip to content
7 min read

Unlocking the Value of Third-Party ESG Verification: A Strategic Guide for Forward-Thinking Companies

Featured Image

ESG verification is an independent check of the sustainability data a company publishes: an external body tests whether the figures in a sustainability report are backed by evidence, and issues a written opinion on them.

Below: what the words mean, which rules require it, and how to pick a verifier.

What ESG Verification Is, and What Limited and Reasonable Assurance Mean

Four terms get treated as synonyms. Verification tests whether a stated figure is accurate. Validation tests whether a forward-looking claim is plausible. Assurance is the formal engagement an auditor or accredited body performs under a standard such as ISAE 3000, ending in a signed opinion. Certification confirms a management system meets a scheme's criteria, and says nothing about whether your emissions figure is right.

Third-party means the check comes from an organisation with no stake in the outcome. A first-party audit is your own internal review, a second-party audit is one your customer runs on you. Only the third-party version carries weight with regulators and lenders.

Limited assurance Reasonable assurance Certification
Issued by Auditor or accredited provider Auditor or accredited provider Accredited certification body
What is tested Enquiry, analytical review, samples Controls and substantive evidence, as in a financial audit Conformity with scheme criteria
The statement says Nothing came to our attention suggesting material misstatement Fairly stated in all material respects The system meets the standard

A signed opinion confirms the number, not the decision behind it. Assurance says a figure traces back to evidence. It does not say the figure is good, or that the data is any use for running the business.

How an Assurance Engagement Runs, Step by Step

Scoping comes first: which disclosures, which standard, which sites and entities, at what assurance level. Most providers then run a readiness review before the report is drafted, because findings raised then are cheap to fix and findings raised after publication are not.

Evidence review is the bulk of the work. The provider traces reported figures back to meter readings, invoices, payroll and supplier statements, and tests whether the process producing them is repeatable. Site visits follow for the locations carrying most risk. The engagement closes with a findings memo and the opinion.

A mid-sized manufacturer with three sites shows the realistic shape: one site gets a full evidence walk-through, the other two are sampled, and most of the time goes on energy data and purchased goods, because that is where restatements originate. Plan across the reporting cycle, not as a few weeks at the end.

Which Rules Require Verification: CSRD, ESRS and CSDDD

Under the Omnibus I package in force since 18 March 2026, the CSRD covers companies with more than 1,000 employees and more than 450 million euro net turnover, both criteria together, for financial years starting on or after 1 January 2027, with first reports due in 2028. Listed SMEs are out of scope. Companies in scope must have their sustainability report assured at limited assurance level against the ESRS.

The CSDDD requires no assurance opinion, but obliges large companies to run value chain due diligence, which pushes evidence requests down to suppliers outside CSRD scope. The Empowering Consumers Directive (EU) 2024/825 applies from 27 September 2026 and requires environmental claims made to consumers to be substantiated.

So the honest answer to "does the law require verification" is: for most companies, no, and it barely matters. The demand arrives through customer contracts and lender questionnaires long before it arrives through a directive.

How to Choose an Assurance Provider: Criteria and Red Flags

Almost every page ranking on this topic is written by an organisation that sells assurance. I do not issue assurance opinions, so here is the buyer-side version.

Check before you sign:

  • Accreditation covering your case: the standard the opinion is issued under, and for CSRD work, authorisation in the member state where you report.
  • A sector team, not sector marketing: which named people on the proposal have worked on your industry's emissions profile?
  • A written methodology: sampling, materiality, treatment of estimated data, and what triggers a qualified opinion.
  • Separation of advice and assurance. A provider that also consults you on the same data cannot credibly opine on it.

Red flags worth walking away from:

  • No accreditation scope for ESRS or ISAE 3000, only general management-system certifications.
  • An unusually fast turnaround, or any sign of the conclusion preceding the evidence.
  • A quote given without asking about your site count, entity structure or data maturity.

The provider you want is the one whose first meeting produces uncomfortable questions rather than a proposal.

Getting Own and Supplier Data Ready for Assurance

Across the CSRD and ESRS reports I have reviewed, the same items fail first review: Scope 3 category boundaries that shift between reporting years, target baselines that cannot be reconstructed from the data, and energy mix figures taken from supplier marketing rather than contractual instruments. All are cheaper to fix before an auditor names them.

Settle four things first: one named owner per datapoint, a documented calculation method per reported figure, retained source evidence for the full period, and a materiality assessment you can defend. If your ESG data management already produces an audit trail, the engagement is a review; if not, you are paying an auditor to build one.

Supplier data is the harder half. Scope 3 figures are only as verifiable as the records behind them, so concentrate on suppliers carrying most of the spend or emissions, and agree audit rights in the contract rather than by email. For smaller suppliers, a VSME report is a more realistic request than assurance.

Frequently Asked Questions

What makes an ESG audit provider a credible choice?
Accreditation for the standard the opinion is issued under, a named sector team, a written methodology, and no advisory relationship on the same data.
What is the difference between a third-party and a second-party audit?
A second-party audit is run by a party with an interest in you, typically a customer auditing its supplier. A third-party audit comes from an independent organisation.
Who is allowed to act as a verifier?
For CSRD reporting, statutory auditors or assurance service providers authorised in the member state where you report. Otherwise, accreditation for the applicable standard, usually ISAE 3000 or AA1000AS.
How do I verify ESG data supplied by my suppliers?
Prioritise by spend and emissions, put audit rights into contracts, and ask for primary records rather than questionnaire answers. A documented estimate beats an unsourced figure.
What does an assurance engagement cost?
Cost follows the assurance level, the sites and entities in scope, and how much evidence the provider must reconstruct. Compare a fee breakdown by phase, not a headline number.
How long does an assurance engagement take?
It runs alongside the reporting cycle: scoping months ahead of the report, evidence work as figures firm up, the opinion once the numbers are locked.

Unsure whether your data would survive a first review? That is what my sustainability consulting is for.

Johannes Fiegenbaum

Johannes Fiegenbaum

ESG and sustainability consultant based in Hamburg, specialised in VSME reporting and climate risk analysis. Has supported 300+ projects for companies and financial institutions, from mid-sized manufacturers to major banks and insurers.

More about