Will Your Auditor Accept AI-Generated ESG Data?

Horizon ESG emission factor matching screen explaining how each calculation stores the factor used, any unit conversion and a confidence score

Your sustainability team wants to use AI to match emission factors, fill Scope 3 gaps and draft the narrative. Your assurance provider is due in the spring. Somebody in the finance function has to decide whether those two facts are compatible, and that somebody is usually you.

The short answer is yes, an auditor can accept figures that AI helped produce. The condition is that the method is visible. Assurance providers do not have a rule against a particular technology; they have a rule against evidence they cannot follow. This piece sets out what that means in practice, where AI creates real control risk, and the four things that make AI output assurable.


What the assurance standard actually says about AI

There is no separate test for AI, and that is the useful part. ISSA 5000, the IAASB’s standard for sustainability assurance engagements, applies to periods beginning on or after 15 December 2026. It is risk based. The practitioner identifies where the information could be materially misstated, then evaluates whether the information they are given as evidence is relevant and reliable. That test is the same whether a figure came from a meter, a spreadsheet formula, a consultant or a model.

So the question your provider will ask is the one they ask of every figure: where did it come from, what method produced it, who checked it, and can it be reproduced? We set those questions out in detail in what ISSA 5000 changes. AI output passes or fails on exactly the same basis.

Where AI gets into trouble is when it makes those questions harder to answer. A number that appears in a cell with no record of the prompt, the source data, the factor chosen or the person who accepted it is unassurable. The model is irrelevant to that finding. The missing trail is the whole of it.


Where the control risk really sits

Three uses of AI in ESG reporting carry most of the risk, and each has a clear failure mode.

Emission factor matching

Matching thousands of purchase lines or activity records to the right factor is slow, error prone work, and a sensible job to automate. The risk is a match that looks plausible and is wrong: the wrong geography, an outdated factor year, a spend-based factor where an activity-based one existed. If the chosen factor, its source and its version are stored on the calculation, a reviewer can catch that and a practitioner can test it. If they are not, the error is invisible until someone recalculates.

Estimates for missing data

Scope 3 cannot be reported without estimation, and practitioners know it. The GHG Protocol Scope 3 Standard already expects companies to describe their data sources and data quality. What draws a finding is an estimate presented with the confidence of a measurement. An AI estimate that is labelled as an estimate, with its basis shown, is a normal part of the engagement. The same number sitting unlabelled next to metered data is a misstatement risk. Our earlier guide to managing carbon reporting estimates covers the labelling side.

Narrative drafting

Generated narrative can state things the data does not support: a reduction that was really a boundary change, a policy that exists only in draft. Where narrative sits inside the scope of the engagement, every factual claim in a drafted paragraph needs to tie back to a datapoint or a document, and a named person needs to have approved it.


Four conditions that make AI output assurable

If you are setting policy for your team, or assessing a platform, these are the controls to insist on.

  • Every estimate is labelled. Measured, calculated and estimated figures are distinguished in the dataset and in the report, with the basis of each estimate recorded where the figure sits.
  • Factor sources and versions are visible. The factor set, its year and version, any unit conversion and, where the system produces one, a confidence score are stored on the individual calculation. A methodology note written at year end is a poor substitute.
  • AI output goes into the same audit trail as manual entry. One change log, one lineage chain. If AI suggestions live in a separate tool and are pasted in, the trail breaks at the exact point the practitioner will want to test.
  • A human approves before anything reaches a report. Mandatory approval, enforced by the system, by someone other than the preparer. AI output that can reach a disclosure without review is the single fastest way to lose the argument with your provider.

Notice that none of these are AI controls. They are the controls you would apply to any preparer. Treat the model as a fast junior analyst whose work is always reviewed, and the assurance position largely follows. The six tests an assurance provider runs apply unchanged.


The sustainability of AI objection

Someone on your board or in your sustainability team will ask whether using AI to report on emissions creates emissions of its own. It does, and it is worth answering plainly. Model inference uses electricity and, through data centre cooling, water. The International Energy Agency’s Energy and AI report (April 2025) estimated data centres used around 1.5% of global electricity in 2024, with AI a fast growing share.

For a reporting workload the relevant comparison is with the process it replaces: weeks of manual matching, reconciliation and rework across a reporting cycle, plus the travel and consultant time that often comes with it. The footprint of the inference involved is small against that, though it is not zero, and a credible reporting team says so. If it matters to your stakeholders, ask your provider where its models run and on what energy.


What to do before your next engagement

  • Tell your provider now which parts of the process use AI. It is a planning conversation, and they will want to scope procedures around it.
  • Write a short AI use policy covering which tasks are permitted, who approves output, and how estimates are labelled.
  • Run a trace test on AI-assisted figures. Pick five and follow each back to its source data, factor and approver. Any figure you cannot trace in a minute is on the remediation list.
  • Keep the two teams on one dataset. If the sustainability team answers customer questionnaires with AI-assisted figures from one place and finance assures figures from another, the numbers will drift apart.

That last point is where most AI risk actually surfaces. When you are comparing ESG platforms on their audit trail, check whether AI output lands in the same trail as everything else.

In Horizon ESG, the intelligence layer is called Nova. It speeds up collection and factor matching, and every output it produces is sourced, labelled, editable, and recorded in the same audit trail as manual entry, with human approval required before it reaches a report. You can read more on how Nova works, or see the controls from the finance side on Horizon ESG for finance teams. The most useful test is a live one: book a short demo, pick an AI-assisted figure, and ask us to show its working.

Comments

Leave a Reply

Book Your Free Demo

Discover more from HORIZON ESG

Subscribe now to keep reading and get access to the full archive.

Continue reading