ISSA 5000: What the New Assurance Standard Changes

Horizon ESG calculation view showing activity data, the emission factor applied and its source and version for a single figure

Somebody will mention ISSA 5000 in your next audit planning meeting, if they have not already. Its date sits inside your next reporting cycle, and the question that follows is the one finance always gets: what does it cost, and what do we need to have ready?

The short answer is that ISSA 5000 does not change what your company reports. It changes how the people assuring those figures are required to work, and that lands on your evidence rather than your arithmetic. Here is what the standard is, when it applies, what the practitioner will actually test, and what to have in place a year before fieldwork.


What ISSA 5000 is

ISSA 5000, General Requirements for Sustainability Assurance Engagements, is the International Auditing and Assurance Standards Board’s (IAASB) global standard for assuring sustainability information, published in November 2024. Three design choices matter for you:

  • It is framework neutral. It applies whether the information is prepared under ESRS, the ISSB standards (and therefore UK SRS), GRI, the GHG Protocol or a voluntary basis.
  • It covers both limited and reasonable assurance, with the work effort for each set out separately.
  • It is profession agnostic. Accounting firms and non-accountant providers can both use it, whoever you appoint.

Because it governs the engagement rather than the obligation, it applies to voluntary assurance too. If a lender or customer asks for assured figures and you commission a provider, that engagement will be run to ISSA 5000 once it is in force.


The date, and why it is closer than it looks

ISSA 5000 applies to assurance engagements on sustainability information reported for periods beginning on or after 15 December 2026, or as at a specific date on or after 15 December 2026. Early application is permitted.

For a calendar-year company, the first period fully under the standard is FY2027. The controls that produce the FY2027 figures need to be operating from 1 January 2027, and the evidence the practitioner will sample is created throughout that year, not assembled at the end. Planning conversations with a provider usually start in the autumn before the period begins, which is now.

The regulatory picture around the standard is still settling. In the EU, the Omnibus package removed the Commission’s power to mandate reasonable assurance under CSRD; the delegated act on limited assurance is now due by 1 July 2027, with CEAOB advice on EU add-ons and carve-outs to ISSA 5000 due 30 September 2026 (Commission letter to CEAOB, 27 January 2026). Australia is consulting on scrapping or delaying its move to reasonable assurance, closing 2 October 2026. California has made assurance optional for its 2026 cycle only. The pattern is the same everywhere: limited assurance, kept permanently, done properly. And since CSRD now reaches only around 5,000 companies after the March 2026 threshold change, for most readers the driver is a lender, a customer or a voluntary target, not a regulator.


Limited versus reasonable assurance

The way ISSA 5000 draws this distinction determines how much evidence you will be asked for.

Limited assurance

The practitioner assesses risks of material misstatement at the level of the disclosure, then designs procedures that respond to them. The conclusion is negative in form: nothing has come to their attention that suggests the information is materially misstated. Enquiry and analytical review carry more weight, but for a high-risk disclosure such as a Scope 3 estimate the practitioner is still required to obtain evidence, not simply ask.

Reasonable assurance

Risks are assessed at the assertion level for each disclosure, the financial audit model: completeness, accuracy, cut-off, classification. That means more testing, more evidence, and where the practitioner intends to rely on your controls, testing that they operated throughout the period. The conclusion is positive in form. Most first engagements are limited assurance, and in the EU and Australia that now looks like the destination rather than a stepping stone.

The point for planning: the gap between the two is a gap in evidence and controls testing, not in the numbers. A dataset with datapoint-level lineage and enforced approval can be stepped up from one to the other. One built from spreadsheets cannot reach either without reconstruction. We covered the engagement mechanics for in-scope EU reporters in our earlier piece on what limited assurance means and how to prepare.


What the practitioner actually tests

The misunderstanding that costs the most money is the belief that the provider recalculates your totals. They do not. ISSA 5000 is risk-based: the practitioner works out where the information could be materially wrong, then tests the process, documentation and controls that would prevent or detect that. The engagement is a sequence of questions, each needing evidence behind the answer:

  • Where did this figure come from? A disclosed number is followed back through the calculation to the activity data and the source document. They want the invoice attached to the figure, not a folder that contains it somewhere.
  • Which method and which factor version? The factor set, its year, the boundary and any allocation rule need to sit on the figure at the point of calculation, not in a methodology note written afterwards.
  • Who changed it, when, and why? A change history that cannot be edited or cleared, showing the original value alongside any correction.
  • Who approved it, and was it the person who prepared it? Segregation of duties is a control they will test if they intend to rely on it, and a policy document is not a control.
  • Is this a measurement or an estimate? Estimates are expected in Scope 3. What the practitioner objects to is an estimate presented with the confidence of a meter reading. Labelled data quality and a stated basis turn a potential finding into a normal conversation.
  • Can last year be reproduced? Comparatives get tested. If factor updates overwrite prior periods, every restatement query becomes an argument.

We set these out as a checklist, with the one demo request that settles whether a platform can do them, in our post on the six tests an assurance provider actually runs.


Twelve months ahead: what to have in place

  • Speak to your provider before the period starts. Agree the scope, the assurance level and which disclosures they consider high risk; that tells you where to concentrate.
  • Fix the boundary and the factor sets for the period and record them where the calculation happens.
  • Attach evidence as data is entered. Source documents linked to datapoints in January are evidence; the same documents gathered the month before fieldwork are a project.
  • Assign preparer and approver roles and let the system enforce them, so the control is testable rather than asserted.
  • Label estimates and close prior periods, so comparatives can be regenerated on the methodology that applied then.
  • Run the trace test yourself. Pick ten disclosed figures at random and follow each back to its source. Anything over a minute is on the remediation list.
  • Budget for it. The fee is driven less by the complexity of your numbers than by how much fieldwork goes on reconstructing evidence; where lineage is visible the practitioner samples less. Put the fee and the internal time in the FY2027 plan now.

One last point. If your sustainability team answers customer questionnaires from a different dataset to the one you will have assured, the two will diverge. One evidenced dataset feeding both closes that gap.

Horizon ESG holds datapoint-level lineage, an immutable change log, enforced separation between preparer and approver, factor version on every calculation, and reproducible prior periods: the controls described above. Our ISSA 5000 page sets out what is available today and what we are still building. If FY2027 is your first period under the standard, book a short demo, pick a figure, and ask us to trace it live. Horizon ESG for finance teams is built for that request.

Comments

Leave a Reply

Book Your Free Demo

Discover more from HORIZON ESG

Subscribe now to keep reading and get access to the full archive.

Continue reading