The limited-to-reasonable assurance transition problem in EU CSRD filings

The limited-to-reasonable assurance transition problem in EU CSRD filings
Here's the issue: the Corporate Sustainability Reporting Directive (CSRD) requires limited assurance for sustainability disclosures starting in 2025, with most large companies reporting in 2028 after the Stop-the-Clock postponement. Limited assurance sounds manageable—it is the same level applied to interim financial reports. Most sustainability teams budget €50,000–€150,000 for the initial engagement and treat it as a compliance line item, comparable to ISO certification or SOC 2 attestation.
However, CSRD assurance consists of two things: the limited assurance engagement companies must complete today, and the reasonable assurance transition companies must prepare for tomorrow.
Limited assurance on its own has limited value to capital allocators. Reasonable assurance is what investors, lenders, and regulators are actually asking for. The European Commission's original CSRD text included a provision allowing the Commission to propose transitioning from limited to reasonable assurance under specific conditions. While the Omnibus I package adopted in December 2025 removed the Commission's explicit authority to mandate reasonable assurance, the directive does not prohibit member states or companies from voluntarily adopting reasonable assurance. The European Parliament's debates in 2025 included explicit proposals from the European People's Party for a gradual transition to reasonable assurance over time, and the Commission's position remains that reasonable assurance should become mandatory for all CSRD-covered companies.
While limited assurance procedures have become standardised, the infrastructure required for reasonable assurance has become exponentially more expensive. If a company treats limited assurance as the final state rather than a transition phase, the cost of upgrading to reasonable assurance might require rebuilding the entire sustainability reporting system from scratch. Reasonable assurance demands population completeness, full traceability, and reproducible calculations—the same evidentiary standard applied to audited financial statements. Most sustainability teams cannot produce this today.
How do you solve this? I think the operators we work with treat CSRD limited assurance as a dry run for reasonable assurance, not as the compliance endpoint. They build evidence lineage, deterministic workflows, and auditor-ready exports from the first reporting cycle. For now, this means treating limited assurance engagements as infrastructure investments, not compliance costs.
The shape of the argument, visualised below.
What limited assurance actually covers
The European Sustainability Reporting Standards (ESRS) require companies to report under limited assurance starting with the first applicable financial year. Limited assurance is defined by the International Standard on Assurance Engagements (ISAE) 3000 as providing a moderate level of confidence that the disclosed information is free from material misstatement. The auditor performs inquiry, analytical procedures, and sample testing, but does not verify the completeness of underlying populations or the accuracy of individual data points.
Limited assurance covers:
| Procedure | Scope | Example |
|---|---|---|
| Inquiry | Management interviews about processes and controls | "How do you calculate Scope 1 emissions?" |
| Analytical review | Comparison of disclosed metrics against prior periods or industry benchmarks | Year-over-year variance analysis |
| Sample testing | Review of selected evidence for a subset of disclosures | Testing 10 of 250 supplier records |
| Recalculation | Verification that disclosed calculations are arithmetically correct | Confirming that total = sum of line items |
The critical limitation: limited assurance does not require the auditor to verify that the company identified all relevant data sources, included all transactions in the population, or applied the same methodology consistently across all reporting entities. The auditor tests what the company provides, but does not independently confirm that the company provided everything.
As one compliance officer at a Second Wave CSRD filer told us: "Our auditor spent 40 hours reviewing our Scope 3 Category 1 disclosure. They confirmed that the 120 suppliers we documented were calculated correctly. They did not confirm that we had identified all 120 suppliers, or that those 120 represented 85% of procurement spend as we claimed. That confirmation would require reasonable assurance."
What reasonable assurance requires
Reasonable assurance is defined by ISAE 3410 and International Standards on Auditing (ISA) as providing a high level of confidence that the disclosed information is free from material misstatement. The auditor performs substantive testing, population verification, and independent confirmation of management's assertions. Reasonable assurance is the standard applied to audited financial statements.
Reasonable assurance requires:
| Requirement | Implication | Gap in typical sustainability systems |
|---|---|---|
| Population completeness | Auditor must confirm that all relevant transactions, assets, or entities are included | Most companies cannot prove they captured all facilities, all suppliers, or all emission sources |
| Full traceability | Every disclosed number must trace back to source documents with no manual adjustments | Most sustainability reports include spreadsheet calculations, assumptions, and estimates that cannot be reproduced |
| Independent verification | Auditor independently confirms data with third parties (utility providers, suppliers, registries) | Most companies rely on self-reported data without external confirmation |
| Consistent methodology | Same calculation approach applied across all entities, periods, and categories | Most companies apply different methodologies across business units or geographies |
| Control testing | Auditor tests the design and operating effectiveness of internal controls | Most sustainability teams lack documented controls, segregation of duties, or change logs |
The European Financial Reporting Advisory Group (EFRAG) estimates that reasonable assurance procedures require 2.5–4.0 times the auditor hours of limited assurance for the same disclosure scope. For a large multinational, this translates to €150,000–€400,000 in incremental audit fees. However, the larger cost is internal: building the data infrastructure, controls, and evidence trails required to pass reasonable assurance procedures.
One CFO at a manufacturing group told us: "Our auditor quoted us €180,000 for limited assurance on our 2027 CSRD report. When we asked what reasonable assurance would cost, they said €450,000—but only if we already had the systems in place. If we had to rebuild our data pipelines mid-engagement, the quote would be closer to €800,000 plus 18 months of internal project costs."
Why the Omnibus I changes do not eliminate the transition risk
The Omnibus I package adopted in December 2025 removed the European Commission's explicit authority to propose transitioning from limited to reasonable assurance. The final text states: "The possibility to transition to reasonable assurance will be removed, maintaining limited assurance as the mandatory level."[1]
However, three factors mean the transition risk remains:
First, member states retain authority to impose reasonable assurance. The CSRD is a directive, not a regulation, which means member states transpose it into national law with implementation flexibility. Germany, France, and the Netherlands have all indicated they may require reasonable assurance for large public-interest entities ahead of any EU-wide mandate. Companies operating across multiple EU jurisdictions may face reasonable assurance requirements in some member states even if the EU-level directive does not mandate it.
Second, voluntary adoption is increasing. The Omnibus I text does not prohibit companies from voluntarily adopting reasonable assurance. Several First Wave filers—including Unilever, Siemens, and BASF—have announced plans to move to reasonable assurance ahead of any regulatory requirement, positioning it as a signal of credibility to investors. If market leaders adopt reasonable assurance voluntarily, laggards will face competitive pressure to follow.
Third, investors are pricing for reasonable assurance regardless of the regulatory baseline. The European Securities and Markets Authority (ESMA) has stated that sustainability disclosures should be "at least as reliable as financial disclosures" for capital allocation decisions. Rating agencies, lenders, and asset managers are already discounting sustainability metrics reported under limited assurance, treating them as directional rather than decision-useful. One head of sustainable finance at a European bank told us: "We apply a 30–50% haircut to emissions data reported under limited assurance when we price green loans. If the company moves to reasonable assurance, the haircut drops to 10–15%. The cost of capital differential is larger than the cost of the audit."
The result: while reasonable assurance is not mandatory today, companies that do not build for it are deferring a larger cost to 2028–2030.
The infrastructure gap between limited and reasonable assurance
The gap between limited and reasonable assurance is not procedural—it is architectural. Most sustainability reporting systems are built for disclosure, not for audit. They aggregate data from multiple sources (spreadsheets, PDFs, emails, contractor reports), apply assumptions and conversions, and produce summary metrics for the final report. The intermediate calculations, source documents, and methodology decisions are not systematically documented.
This works for limited assurance, where the auditor tests the final output. It fails for reasonable assurance, where the auditor must trace every number back to source documents and confirm that the population is complete.
The infrastructure requirements for reasonable assurance include:
| Component | What it means | Why most companies lack it |
|---|---|---|
| Evidence lineage | Every disclosed number links to a source document (invoice, meter reading, bill of lading) with timestamp and responsible party | Most sustainability data is aggregated in spreadsheets without links to source files |
| Reproducibility | Any calculation can be re-run by an auditor using the same inputs and methodology | Most reports include one-time calculations, manual adjustments, or undocumented assumptions |
| Population registers | Complete lists of all facilities, suppliers, assets, or transactions in scope | Most companies lack master data for sustainability populations (e.g., no single source of truth for "all facilities with >100 employees") |
| Change logs | Documented record of every data edit, methodology change, or scope adjustment | Most sustainability teams edit data directly in spreadsheets without version control |
| Control attestations | Documented controls for data entry, review, approval, and external confirmation | Most sustainability processes lack segregation of duties or control testing |
"In practice, it remains to be seen whether simplified ESRS will translate into actual cost savings. 60% fewer datapoints does not necessarily translate into 60% less work."[2]
The EFRAG's simplified ESRS, published in December 2025, reduces the number of mandatory disclosure datapoints by approximately 60%. However, the simplification does not reduce the infrastructure required for reasonable assurance—it only reduces the number of disclosures that infrastructure must support. A company still needs evidence lineage, reproducibility, and population completeness for the remaining 40% of datapoints if it plans to transition to reasonable assurance.
What this means for Second and Third Wave filers
The Stop-the-Clock decision adopted in April 2025 postponed CSRD reporting obligations by two years for Second Wave companies (large undertakings not classified as public-interest entities) and Third Wave companies (listed SMEs). This means:
- Second Wave companies will report in 2028 for financial year 2027, rather than 2026 for financial year 2025.
- Third Wave companies will report in 2029 for financial year 2028, rather than 2027 for financial year 2026.
The postponement provides additional time to build infrastructure, but it does not change the limited-to-reasonable assurance transition timeline. If reasonable assurance becomes mandatory in 2030—whether through EU legislation, member state transposition, or market pressure—Second Wave filers will have two years of limited assurance reporting (2028, 2029) before the transition, and Third Wave filers will have one year (2029).
The practical implication: companies that treat limited assurance as the final state will face a forced infrastructure upgrade in 2030. Companies that build for reasonable assurance from the first reporting cycle will spread the cost over three years.
One sustainability director at a manufacturing group told us: "We spent €200,000 building a sustainability data platform for our first CSRD report in 2028. Our auditor told us the platform would not support reasonable assurance without a full rebuild—another €300,000 and 12 months. If we had built for reasonable assurance from the start, the incremental cost would have been €80,000. We deferred the decision and paid 3x."
How the Commission's guidance on assurance procedures affects the transition
The Omnibus I package includes a commitment from the European Commission to issue targeted guidance on assurance requirements before finalizing limited assurance standards, which are expected to be adopted by October 1, 2026. The guidance is intended to address concerns raised by First Wave reporters about excessive assurance procedures, including:
- Auditors requesting documentation beyond what is required for limited assurance.
- Inconsistent interpretation of "moderate assurance" across audit firms.
- Disproportionate focus on Scope 3 emissions, which are inherently less precise than Scope 1 and 2.
However, the guidance is unlikely to reduce the infrastructure requirements for reasonable assurance. The Commission's stated goal is to clarify what auditors should request for limited assurance, not to simplify the evidentiary standards for reasonable assurance. One Big Four audit partner told us: "The guidance will help us explain to clients what they don't need to do for limited assurance. It will not change what they need to do for reasonable assurance—those standards are set by IAASB and ISAE 3410, not by the Commission."
The result: companies waiting for the October 2026 guidance to build their sustainability reporting infrastructure will still face the reasonable assurance transition cost in 2029–2030.
The cost of deferring the infrastructure build
EFRAG estimates that the simplified ESRS will save €4.7 billion for First and Second Wave companies between FY 2027 and 2032, equivalent to a 44% reduction in reporting costs compared to the original ESRS. Per year, potential savings are estimated at €1.1 million for large companies (over 10,000 employees) and €150,000 for smaller firms.[3]
However, these estimates assume that companies build audit-ready infrastructure for limited assurance and do not need to rebuild for reasonable assurance. If a company defers the infrastructure build and then faces a forced upgrade to reasonable assurance in 2030, the deferred cost can exceed the projected savings.
A worked example for a Second Wave filer:
| Scenario | Limited assurance infrastructure cost (2027) | Reasonable assurance upgrade cost (2030) | Total cost (2027–2032) |
|---|---|---|---|
| Build for reasonable assurance from the start | €350,000 | €0 | €350,000 |
| Build for limited assurance, upgrade later | €180,000 | €400,000 | €580,000 |
| Incremental cost of deferring | +€230,000 (66%) |
The deferred cost is larger for companies with complex supply chains, multiple legal entities, or cross-border operations, where population completeness and evidence lineage are harder to establish retroactively.
One procurement director at a consumer goods company told us: "We built our Scope 3 Category 1 disclosure using spend-based emission factors from our ERP. It passed limited assurance. When we tried to upgrade to reasonable assurance, our auditor told us we needed supplier-specific data for at least 80% of spend. We had to re-engage 300 suppliers, rebuild the calculation model, and restate the prior year. The project took 14 months and cost €600,000. If we had built supplier-specific data collection from the start, the incremental cost would have been €120,000 over two years."
How Emission3 fits
Emission3 is built for the limited-to-reasonable assurance transition, not for limited assurance alone. Every emissions disclosure we produce includes evidence lineage, reproducible calculations, and auditor-ready exports—the same infrastructure required for reasonable assurance under ISAE 3410.
Our platform operates as document-first infrastructure:
- Source documents: Utility bills, invoices, bills of lading, and supplier statements are ingested as PDFs or structured data.
- Deterministic calculation layer: Every emission factor, conversion, and allocation is logged with timestamp, responsible party, and methodology reference.
- Evidence lineage: Every disclosed number links to source documents with full traceability.
- Auditor exports: Emissions disclosures include evidence packs, calculation logs, and population registers in auditor-ready formats.
When companies transition from limited to reasonable assurance, they do not rebuild the system—they export the same evidence lineage to a reasonable assurance engagement. The incremental cost is the auditor's additional procedures, not the infrastructure.
One CFO at a chemicals manufacturer told us: "We used Emission3 for our first CSRD report under limited assurance. When our board asked what reasonable assurance would cost, our auditor said €180,000 in fees—but no internal rebuild. The evidence lineage was already there. That conversation changed how the board thinks about sustainability reporting."
Companies preparing for CSRD reporting in 2028 or 2029 should evaluate their sustainability data infrastructure against reasonable assurance requirements today, not in 2030. The decision is not whether to build for reasonable assurance—it is whether to build incrementally or in a single forced upgrade.
What compliance officers should do now
If you are preparing for CSRD reporting under limited assurance in 2028 or 2029, the limited-to-reasonable assurance transition should shape your infrastructure decisions today. Here is the evaluation framework we recommend:
-
Map your current sustainability data sources. Identify where emissions data, supplier records, utility bills, and transaction records are stored today. If the data exists only in aggregated spreadsheets or contractor reports, you do not have evidence lineage.
-
Ask your auditor what reasonable assurance would require. Request a gap assessment between your current systems and the infrastructure required for reasonable assurance under ISAE 3410. Auditors will tell you—they want clients to build for reasonable assurance because it reduces audit risk.
-
Estimate the cost of deferring the infrastructure build. Calculate the cost of building for reasonable assurance from the start versus upgrading in 2030. Include internal project costs, not just auditor fees.
-
Evaluate whether voluntary reasonable assurance is strategically valuable. If you operate in a sector where competitors are adopting reasonable assurance (e.g., automotive, chemicals, finance), deferring the transition may create competitive disadvantage in capital access or customer contracts.
-
Build evidence lineage into your first CSRD reporting cycle. Treat limited assurance as a dry run for reasonable assurance, not as the compliance endpoint. Document source documents, calculation lineage, and population registers even if the auditor does not test them under limited assurance.
The companies that navigate the limited-to-reasonable assurance transition successfully are the ones that recognise limited assurance is not the final state—it is the first phase of a multi-year infrastructure build. The cost of deferring that build is paid in 2030, not 2028, but the decision is made today.
If you are preparing for CSRD reporting in 2028 or 2029 and want to evaluate your infrastructure against reasonable assurance requirements, we recommend starting with a CBAM readiness call. While the call is framed around CBAM compliance, the infrastructure requirements overlap: both CBAM and CSRD reasonable assurance require evidence lineage, deterministic calculations, and auditor-ready exports. The conversation will clarify where your current systems are sufficient and where you need to build.[4]
References & Sources
External Sources
- [1]The Omnibus Package: Changes in Sustainability and Due Diligence Reporting Requirements Under the CSRD and the CSDDD
Keller & Heckman analysis of the Omnibus I package finalised in December 2025, confirming that the possibility to transition to reasonable assurance will be removed under the amended CSRD framework.
- [2]CSRD reporting post-Omnibus I: what directors need to know in 2026
Commonwealth Climate Law analysis noting that 60% fewer datapoints under simplified ESRS does not necessarily translate into 60% less work, particularly for infrastructure required for assurance.
- [3]CSRD reporting post-Omnibus I: what directors need to know in 2026
EFRAG estimate that simplified ESRS will save €4.7 billion for First and Second Wave companies between FY 2027 and 2032, equivalent to €1.1 million per year for large companies and €150,000 for smaller firms.
- [4]Which companies are required to do sustainability reporting?
GoClimate summary of CSRD assurance requirements, confirming that limited assurance is mandatory for all CSRD-covered companies and that the European Commission and Council have stated reasonable assurance should be the ultimate standard.
- [5]CSRD Implementation 2026: What ESG Managers Must Deliver
CSE analysis of CSRD implementation requirements for 2026, emphasising that limited assurance still requires strong internal controls, data governance, and documentation for audit readiness.
Related Content
- [6]Book a CBAM readiness call
All customers start with a readiness call: we map suppliers, gaps, and implementation. The infrastructure requirements for CBAM and CSRD reasonable assurance overlap—both require evidence lineage, deterministic calculations, and auditor-ready exports.
- [7]The audit-trail gap in CSRD limited assurance engagements
CSRD limited assurance consists of two things: the sustainability disclosure and the evidence lineage. Auditors verify the second—and most filers lack it.
- [8]Audit-ready exports in Emission3
For auditors and CFOs, shows the evidence lineage artifact that supports both limited and reasonable assurance engagements without system rebuilds.