ESG Data Quality: What Auditors Actually Check
ESG data quality has become a compliance question. CSRD requires limited assurance on sustainability data from the first reporting year. California's SB 253 requires third-party verification of Scope 1, 2, and 3 emissions. Any investor conducting serious climate due diligence now expects to trace a disclosed figure back to the data that produced it.
The problem is that most ESG data, particularly GHG emissions data, is collected through a combination of spreadsheets, email requests, ERP extractions, and supplier estimates. That process can produce accurate numbers. It rarely produces auditable ones.

The Five Dimensions of ESG Data Quality
Assurance providers evaluate ESG data quality across five dimensions. These map directly to what your systems and processes need to deliver:
- Completeness: does the data cover all material sources within the defined reporting boundary? A missing emissions source is a finding, not a footnote
- Accuracy: does the data represent what actually happened? Accuracy failures include wrong emissions factors, unit conversion errors, transposition mistakes in manual data entry, and estimates used where actual data was available
- Consistency: is the same methodology applied in the same way across all entities, facilities, and reporting periods? Inconsistency emerges when different sites use different factor databases, or when methodology changes between years without documentation
- Timeliness: was the data collected within the defined reporting period and cut-off dates? Late data that is estimated and corrected post-publication weakens the audit trail
- Auditability: can every reported figure be traced to a source document, with a clear record of who provided it, who processed it, and who reviewed it? This is the dimension most ESG data processes fail. A correct number that cannot be audited is, from an assurance perspective, an unverified number
Where ESG Data Quality Typically Breaks Down
The most common failure points are systemic, not accidental:
- Manual data collection: where data moves through email and spreadsheets, version control is unreliable, formula errors are common, and there is no automatic record of who changed what and when
- Emissions factor version mismatches: teams update their factor databases inconsistently. The same company-level report may use 2021 factors for some sources and 2024 factors for others. The inconsistency may be invisible in the final number but becomes visible under audit
- Boundary drift: as businesses acquire entities, divest operations, or restructure, the reporting boundary needs to be updated. Without a documented boundary management process, what is included shifts between years without explanation
- Undocumented estimates: where actual data is unavailable, estimates are acceptable under GHG Protocol. But the estimation methodology must be documented. An estimate with no documented basis is an unverified assumption
- No internal QA process: without a formal review step before data is finalised, errors reach the reported figure and are discovered only when an auditor samples the data
What Assurance Providers Actually Check
During a limited assurance engagement under ISO 14064-3 or ISAE 3410, assurance providers follow a structured testing approach. Understanding it helps you build the right controls. See our full guide to GHG assurance for the complete process; the data quality elements they focus on:
- Methodology documentation: reviewing your GHG Inventory Management Plan to understand your documented boundary and methodology
- Tracing: selecting a sample of reported figures and tracing them from the report to the calculation to the raw data to the source document
- Emissions factor testing: comparing your factors to current published databases and checking geographic and activity-type appropriateness
- Control assessment: reviewing your internal QA process, sign-off records, and change log
- Boundary consistency: comparing this year's boundary to last year's and verifying that any changes are documented and justified
The questions an auditor cannot answer from documents — 'who reviewed this figure?', 'why was this factor chosen?', 'what changed between years?' — become findings. The goal of an ESG data quality programme is to make those questions answerable from documentation alone.

Building Audit-Ready ESG Data Systems
The difference between ESG data that passes assurance and ESG data that generates findings is usually systems, not intentions:
- Source linkage: every emissions figure should be traceable to a source document or system record. Calculated figures should link to the input data and the formula or factor used
- Change log: any correction or update to a submitted figure should be logged with the reason, the person who made it, and the date. This enables auditors to see what changed and why
- Emissions factor version control: the specific version of each factor database should be locked at reporting period start and applied consistently across all sources in scope
- Boundary documentation: any entity added to or removed from scope during the year should be recorded with effective dates and justification
- Internal sign-off: a formal QA review with documented approval before data is finalised for reporting
These requirements can be implemented in well-structured spreadsheets. They are much harder to maintain at scale without a system designed for it. The GHG Inventory Management Plan is the document that governs these processes — it is what an assurance provider reads first.
ESG Data Quality Requirements by Framework
Each major reporting framework sets specific data quality expectations:
- CSRD / ESRS: requires limited assurance from year one. ESRS requires the auditor to evaluate whether sustainability disclosures are free from material misstatement. Data quality is the primary risk factor in that assessment
- ISO 14064-3 / ISAE 3410: the assurance standards used for GHG emissions. Both require testing of completeness, accuracy, and consistency. A GHG Inventory Management Plan is effectively required for a clean assurance opinion
- GHG Protocol Corporate Standard: sets the quality criteria that major assurance standards use as their benchmark. Requires that inventory data be relevant, complete, consistent, transparent, and accurate
- SBTi: the validation process evaluates whether your inventory is credible enough to base long-term targets on. Quality gaps identified during validation often surface the same issues an assurance provider would find
- California SB 253: requires third-party verification of Scope 1, 2, and 3 emissions for companies with California revenues above $1 billion. Data traceability and methodology documentation are explicitly required
ESG Data Quality and Your Reporting Programme
The most effective time to build ESG data quality into your process is before your first assured report — not after a finding. The documentation requirements (boundary, methodology, factor selection, QA procedures) take time to establish. Companies that treat the first year of CSRD as a documentation sprint tend to produce assurance reports with more findings and longer remediation cycles. Companies that build ESG data collection infrastructure 12–18 months ahead of their assurance deadline consistently achieve cleaner results.

Simplify Your Sustainability
Preparing for GHG assurance or CSRD disclosure? Brightest helps sustainability teams build the data infrastructure to collect, organise, and verify ESG data to audit-ready standards.
