ESG reporting audit in practice: What companies (do not) manage and how to do it

Audit

The European CSRD introduces new sustainability obligations from 2025. With the so-called Omnibus Amendment, formal amendments have already been made that change the scope and timing of obligations. But the key point remains: companies that prepare early will manage reporting more efficiently and without unnecessary errors. Below is an overview of the steps that work well in practice – along with the specific challenges we encounter most often in ESG reporting audits. The advantage of such companies is that it is easier to obtain funding or new collaboration with companies that already include ESG in their decision-making process.

What our approach to ESG auditing looks like

  1. Harvesting – Mapping the environment and expectations

We determine, which regulations are relevant (e.g. CSRD, ESRS, GRI, EU taxonomy) and what is the context of the company – industry, size, local legislation, company strategy and stakeholder expectations. Already here, weak or formal stakeholder involvement is often evident, leading to a superficial notion of materiality.

  1. Scanning – Mapping systems and IT environments

We examine ESG data collection tools and their connection to controlling, ERP or accounting. The problem tends to be the fragmentation of data, their manual management in Excel and zero connection to synthetic accounts – especially when meeting the requirements of the EU taxonomy (Capex, Opex).

  1. Mapping – Processes and Responsibilities

We examine who in the company is responsible for what ESG data, how the data go through the approval workflow and how the processes are documented. In practice, there is often a lack of formal assignment of responsibilities and ESG is not sufficiently integrated into decision-making processes.

  1. Assessment – Double Materiality

Methodologies for assessing impacts, opportunities and risks tend to be unclear and biased – especially when relevant data are missing. Important topics are often determined intuitively or by current trends, not by analysing the impact and influence on the company. Stakeholders tend to be minimally involved in the evaluation.

  1. Alignment – Interconnection with accounting and taxonomy

We help reconcile accounting and ESG data – we identify missing analytics and verify correct categorisation in the EU taxonomy. In practice, it is often difficult to trace relevant Capex in sustainable activities, for example, because of the lack of separate accounts.

  1. Calculation – Carbon footprint calculation and data collection

We validate the methodologies used (GHG Protocol, ISO 14064) and data recalculations. A common limitation is the lack of input data – companies are often unable to cover Scope 3 because data from suppliers are not available or not of the required quality.

  1. Control – Internal controls and audit trail

We check how ESG data are controlled and how their consistency over time is ensured. Companies often lack mechanisms for tracking changes or formal validation, which complicates later verification and auditing.

  1. Review – Final check and verification

Before publishing the report, we verify compliance with ESRB and other standards. We check that outputs are consistent with the results of the materiality assessment and are supported by data. The reports sometimes appear formal and do not contain specific examples or links to the company’s strategy.

In our experience, the biggest challenge is not the regulation itself, but the readiness of companies to collect, validate and interpret data. If you are just starting out, we recommend setting up processes and responsibilities first – the technology, reporting tools and standards themselves can then be adapted.

We will be happy to review your specific situation with you and propose an effective plan of action.