Skip to content

Advanced Audit and Assurance (International) · Audit-related and assurance services

ISAE 3000 Assurance on ESG, Integrated Reports and Controls

Updated 11 October 2026 · Fact-checked

Other assurance means an independent conclusion on non-financial subject matter, such as ESG data, integrated reports or controls at a service organisation. ISAE 3000 is the base standard. ISAE 3410 covers greenhouse gas statements and ISAE 3402 covers service organisation controls. Solve questions by checking the criteria, the level of assurance, the evidence and the report wording.

Understand Other Assurance: Integrated Reporting, ESG and Internal Controls

An assurance engagement is one where a practitioner gives a conclusion that increases the confidence of intended users in the subject matter information. The subject matter is measured against criteria. In an audit, the criteria are the financial reporting framework. In other assurance, the subject matter may be carbon emissions, a sustainability report, an integrated report or the controls of a service provider.

ISAE 3000 (Revised) is the umbrella standard for assurance other than audits or reviews of historical financial information. It sets the five elements of an engagement: a three-party relationship (practitioner, responsible party, intended users), an appropriate subject matter, suitable criteria, sufficient appropriate evidence, and a written report. It also allows two levels of assurance. Reasonable assurance gives a positive conclusion, such as 'in our opinion, the statement is fairly stated'. Limited assurance gives a negative form of conclusion, such as 'nothing has come to our attention that causes us to believe the statement is materially misstated'. Limited assurance involves fewer procedures and is cheaper.

Two standards sit under ISAE 3000. ISAE 3410 deals with assurance on a greenhouse gas statement. Emissions are often estimated, not measured, so there is real uncertainty. You must understand how the entity calculates emissions, including emission factors, the organisational boundary and the data sources. ISAE 3402 deals with assurance on controls at a service organisation, such as a payroll processor or cloud host. A service auditor reports to the service organisation. The user entity and its auditor then use the report. A Type 1 report covers the design of controls at a point in time. A Type 2 report also covers operating effectiveness over a period.

For integrated reports and ESG reports, the main difficulty is suitable criteria. Criteria must be relevant, complete, reliable, neutral and understandable. Frameworks such as the Integrated Reporting Framework or the ISSB standards can supply criteria. If the entity invents its own criteria, you must judge whether they are suitable and whether they are disclosed to users. Much of the information is narrative, forward-looking or qualitative, so you need to plan how to get evidence on it.

The practitioner must also meet ethical requirements, including independence, and apply quality management. Competence is important. The team may need a specialist, such as an environmental scientist, and you must evaluate that expert's work.

Key rules to remember

Elements of an assurance engagement (ISAE 3000)
Three parties + appropriate subject matter + suitable criteria + sufficient appropriate evidence + written assurance report
If one element is missing, it is not an assurance engagement. Use this as a checklist in acceptance questions.
Characteristics of suitable criteria
Relevance, completeness, reliability, neutrality, understandability
Criteria must also be available to users. Say which characteristic fails in the scenario.
Reasonable assurance conclusion
Positive form: 'In our opinion, the subject matter information is, in all material respects, in accordance with the criteria'
Requires more extensive procedures, including risk assessment and testing of controls where relevant.
Limited assurance conclusion
Negative form: 'Nothing has come to our attention that causes us to believe...'
Mainly enquiry and analytical procedures. The report must make clear that the procedures were more limited.
ISAE 3402 report types
Type 1 = design and implementation at a date; Type 2 = design, implementation and operating effectiveness over a period
A Type 1 report gives no evidence that controls worked over time.
Main parties in a service organisation report
Service organisation (responsible party) → service auditor → user entity and user auditor
The report is for existing users and their auditors, not for prospective customers in general.

How to solve Other Assurance: Integrated Reporting, ESG and Internal Controls questions

Use this method for any question on assurance over ESG, integrated reports or controls. Always tie each point to the scenario.

  1. 1Identify the subject matter and the standard that applies: ISAE 3000 generally, ISAE 3410 for greenhouse gas statements, ISAE 3402 for service organisation controls.
  2. 2Check the engagement is acceptable: the five elements, suitable criteria, the practitioner's competence, independence and any limits on scope.
  3. 3Decide the level of assurance, reasonable or limited, and say what that means for the work and the wording of the conclusion.
  4. 4Assess the risks to the subject matter information, such as estimates, weak data systems, subjective narrative, or bias towards favourable results.
  5. 5Design procedures that respond to the risks: understand the process, test source data, recalculate, test the controls, use analytical procedures, and use an expert if needed.
  6. 6Evaluate the evidence and any misstatements, and consider management's written representations.
  7. 7Choose the report form: unmodified, qualified, adverse or disclaimer of conclusion, with clear description of criteria and level of assurance.
  8. 8Close with a professional judgement line: state your recommendation and the reason, using the facts given.

Quickest way: Five-line scenario scan

When to use it: Use when time is short and the requirement asks for matters to consider or procedures to perform.

  1. Write 'Subject matter / criteria / level / risk / evidence' as five headings in your plan.
  2. Under each heading, pull one fact from the scenario and one point of standard.
  3. For criteria, ask: who set them, are they disclosed, are they neutral?
  4. For evidence, give two or three specific procedures tied to named data, not general ones such as 'check records'.
  5. Finish with the report wording or the effect on the conclusion, and keep the professional skills mark in mind by being clear and commercial.

Common mistakes in Other Assurance: Integrated Reporting, ESG and Internal Controls

  • Treating ISAE 3000 work as if it were an ISA audit and giving an audit opinion on financial statements.

    Students are most familiar with the audit and carry that structure over.

    Fix: Refer to the practitioner, subject matter information and criteria. Use the conclusion wording of ISAE 3000, not 'true and fair'.

  • Ignoring whether the criteria are suitable.

    Students jump straight to procedures.

    Fix: Always comment on criteria first. If they are not available, biased or incomplete, the engagement may not be acceptable.

  • Confusing reasonable and limited assurance, or saying limited assurance means no evidence is needed.

    The word 'limited' suggests very little work.

    Fix: Say limited assurance still needs sufficient appropriate evidence for a meaningful level, but with fewer procedures, mainly enquiry and analytical procedures. Reasonable assurance gives a higher level.

  • Mixing up ISAE 3402 Type 1 and Type 2 reports.

    Both have similar names and cover controls.

    Fix: Link Type 1 to design at a date and Type 2 to operation over a period. If the user auditor needs reliance on controls, Type 2 is normally needed.

  • Giving generic procedures for an ESG report, such as 'review the report for accuracy'.

    Students lack a clear list of what evidence exists for non-financial data.

    Fix: Name the procedure: trace data to meter readings or invoices, recalculate emissions using the emission factors, check the boundary, and test the data collection controls.

  • Forgetting the practitioner's own competence, independence and use of experts.

    Students focus on the client, not the firm.

    Fix: Add a short point on the engagement team's skills, any need for a specialist, and independence threats such as helping the client prepare the data.

Worked examples

Example 1

Greenfield Co is a manufacturer. It asks your firm to give limited assurance on its greenhouse gas statement for the year, prepared using its own internal methodology that is not published. Explain the matters you would consider before accepting, and the procedures you would perform.

Show the solution
  1. Standard: this is an ISAE 3410 engagement, applying the requirements of ISAE 3000.
  2. Criteria: the methodology is internal and unpublished. Users cannot see how emissions were measured, so the criteria may not be available or understandable. You would ask the company to disclose the basis in the statement, or use a recognised protocol.
  3. Other acceptance points: confirm the entity's boundary is clear, data is available, the team has the competence (or an expert is available), and you are independent. If the firm helped design the methodology there could be a self-review threat.
  4. Level: limited assurance means mainly enquiry and analytical procedures, and the conclusion is in negative form.
  5. Procedures: understand how emissions data is collected and the emission factors used; agree a sample of source data, such as fuel and electricity invoices, to the statement; recalculate emissions; compare with prior year and with production levels and investigate unusual changes; check that the organisational boundary matches the statement.
  6. Estimates: emissions often rely on estimates, so assess the reasonableness of the factors and the uncertainty disclosed.
  7. Obtain written representations from management on completeness and the methodology.

Answer: Accept only if the criteria are made suitable and available and the competence and independence requirements are met. Then perform enquiry, analytical, recalculation and source-data tests suited to limited assurance, and report a negative-form conclusion.

Example 2

Payco provides payroll processing for many clients. A client, Retailco, uses Payco's service. Retailco's auditor receives a Payco ISAE 3402 Type 1 report. Explain why this may not be enough for the auditor and what else could be done.

Show the solution
  1. Define the report: an ISAE 3402 Type 1 report covers the description of the system and the design of controls at a specified date, as reported on by Payco's service auditor.
  2. Limitation: it gives no evidence that the controls operated effectively over the period. Retailco's auditor wants to rely on controls for the full year, so a Type 1 report will not be enough for that.
  3. Other limits: the report date may not match Retailco's year end, and the controls tested may not cover the processes that matter to Retailco. Complementary user entity controls at Retailco also need testing.
  4. Alternatives: obtain a Type 2 report covering the period; if none exists, perform tests of controls at Payco (if access is allowed); or use substantive procedures at Retailco, such as recalculating payroll and agreeing to bank payments.
  5. Also read the service auditor's opinion for any qualification, and consider the service auditor's competence and independence.

Answer: A Type 1 report only covers design at a date, so Retailco's auditor cannot rely on operating effectiveness during the year. The auditor should obtain a Type 2 report, test controls directly, or carry out more substantive procedures.

Exam tips

  • Start every answer by naming the subject matter and the criteria. Markers look for this first.
  • Be specific on evidence. Name the source documents and recalculations, not 'obtain evidence'.
  • Always state the level of assurance and what it means for the wording of the conclusion.
  • In scenarios, use the facts: a self-made methodology, a new data system or pressure from management each point to a risk you can develop.
  • Keep a line for ethics and competence. The professional skills marks reward balanced, commercial judgement, so give a recommendation.

Practice questions from Audit-related and assurance services

Other Assurance: Integrated Reporting, ESG and Internal Controls in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

Other Assurance: Integrated Reporting, ESG and Internal Controls: frequently asked questions

What is ISAE 3000 and when does it apply?

ISAE 3000 (Revised) applies to assurance engagements that are not audits or reviews of historical financial information. It covers subject matter such as sustainability reports, controls and non-financial performance. It sets out the elements of an engagement and the requirements for planning, evidence and reporting.

What is the difference between ISAE 3410 and ISAE 3402?

ISAE 3410 covers assurance on a greenhouse gas statement. ISAE 3402 covers assurance on controls at a service organisation. Both build on ISAE 3000, but the subject matter and the users of the report are different.

What is the difference between limited and reasonable assurance?

Reasonable assurance is a high level of assurance and gives a positive conclusion. Limited assurance is a lower level, with fewer procedures, and gives a negative-form conclusion. Both require sufficient appropriate evidence for the level given.

How do I answer a question on assuring an ESG report?

Identify the criteria and judge if they are suitable. Then set the level of assurance, assess the risks, and list specific procedures such as tracing data, recalculating, and testing controls. End with the report conclusion and any ethical or competence points.