ESG Audit: Process, Checklist & What Auditors Look For

|Olivia Paul
ESG Audit: Process, Checklist & What Auditors Look For

An ESG audit is a structured review of a company's environmental, social and governance data, along with it's policies and processes against a defined standard. It is simple to state but hard to execute. Auditing proves that the ESG numbers a company reports would survive scrutiny from a regulator, an assurance provider, an investor or a customer.

The stakes have changed everywhere and has brought in regulatory scrutiny across the globe. The EU's CSRD makes assurance of sustainability statements mandatory for companies in its scope, SEBI requires independent verification of BRSR Core KPIs in India, and large buyers push ESG questionnaires down their supply chains worldwide.

This guide covers what the audit includes, the step by step process, a working checklist, how audits differ from assurance and due diligence, and what IPO-bound companies should do before listing.

What is an ESG Audit?

An ESG audit is an evidence-based examination of how a company measures, manages and reports its environmental, social and governance performance. It compares what the company claims against what its records support, and it tests whether the systems producing those claims are reliable.

Unlike a financial audit, there is no single statutory format. The benchmark is the framework that the company reports under such as:

  1. GRI for global reporting

  2. CSRD/ESRS in the EU

  3. BRSR for Indian listed companies

  4. CDP for climate disclosures

  5. Customer's supplier code.

ESG auditing borrows the financial-audit discipline, evidence, sampling and traceability, and applies it to sustainability data.

What an ESG Audit Covers

Scope varies by framework, but a full audit examines the five pillars mentioned below:

  • Environmental Data: This is the data that accounts for greenhouse gas inventories across scope 1, 2 and 3 emissions, energy, water, waste, and the emission factors and assumptions behind them.

  • Social Records: This data pertains to workforce composition, health and safety incidents, training, grievance mechanisms, and human rights processes in the supply chain.

  • Governance: This related to board oversight of ESG policies and their approval trail, ethics and anti-corruption controls, and related-party safeguards.

  • Reporting Systems: This audits where each disclosed number comes from, who owns it, and whether the same question yields consistent answers.

  • Framework Compliance: It verifies whether disclosures actually meet the requirements of GRI, ESRS, BRSR or whichever standard the company claims.

ESG Audit vs Assurance vs Due Diligence

Three similar-sounding exercises serve different purposes, and confusing one for the other incurrs heavy costs.

ESG Audit

ESG Assurance

ESG Due Diligence

Purpose

Systematically verifies internal non-financial data against set standards.

Provides independent third-party certification of public disclosures

Investigates broad operational risks before a business deal or investment

Commissioned by

The company itself

The company, for its stakeholders

An investor, acquirer or lender

Output

Findings and an action plan

Assurance statement (e.g. on BRSR Core KPIs)

Risk report feeding valuation and deal terms

Standard

Chosen framework

ISAE 3000 and equivalents

Investor's own criteria

Frequency

Recurring

Annual, tied to reporting

One-off, transaction-driven

The sequence is of utmost importance: A company that runs its own audit before the assurance engagement controls the findings; one that does not faces the risk of discovering its gaps from the assurance provider's queries.

Internal vs External ESG Audits

An ESG internal audit is run by the company's own audit function, often with ESG advisory support, and reports it to management or the audit committee. It is the often the most cost effective process to catch problems.

External reviews come in two forms:

  1. Advisory audits by a consulting partner, useful when internal capacity is thin

  2. Formal assurance engagements, which are independent by definition.

Most mature reporters now run an annual internal cycle timed a quarter ahead of their filing window, whether that is CSRD or BRSR, so findings can be fixed before the assured KPIs are locked.

The ESG Audit process, Step by Step:

How Scope 3 Automation Turns Data into Decisions (14).png
  1. Define scope and criteria: Which entities, sites and reporting period are included within the scope along with which framework the evidence is tested against.

  2. Map disclosures to data owners: Every reported figure gets a attached to a data owner and a named source system.

  3. Collect evidence: Source documents, meter data, HR records, policy approvals, and supplier responses.

  4. Test the numbers: Recalculate samples, trace figures to source, check emission factors and conversion assumptions.

  5. Test the processes: Can the system produce the same number twice; are estimates flagged as estimates; who reviews before publication.

  6. Report findings: Gaps get ranked by severity, each with an owner and a deadline.

  7. Track remediation: Findings without follow-through reappear in next year's audit, or in the assurance provider's report.

Is an ESG Audit Mandatory? Requirements by Region

The internal audit itself is voluntary everywhere. The external scrutiny it prepares you for is increasingly becoming mandatory.

Region

What is mandated

European Union

CSRD requires limited assurance of sustainability statements for companies in scope, moving towards reasonable assurance over time

India

SEBI requires independent assurance or assessment of BRSR Core KPIs for the largest listed companies, phasing down the top-1,000 by market capitalisation

Malaysia

The NSRF phases in sustainability disclosure aligned to ISSB standards for listed issuers, with assurance expectations following

GCC

Exchange ESG disclosure guidance (ADX, DFM, Tadawul); assurance is largely voluntary today but standard practice for large issuers

If your company reports under any of these regimes, some of your ESG data sets already face, or will soon face, an external opinion. An internal audit cycle is how you make sure that opinion is ready for scrutiny. For Indian filers, our guide to the BRSR reporting format covers which disclosures sit where.

ESG Readiness for IPO-Bound Companies

Companies preparing to be listed on the stock exchange face ESG scrutiny from two directions, and neither is optional in practice.

  1. Regulatory lag: Listing brings disclosure obligations the company never carried when it was private, whether that is BRSR for a company entering India's top-1,000 by market capitalisation, CSRD for an EU listing, or stock exchange ESG requirements elsewhere. Building the emissions inventory and workforce data trail well in advance is far cheaper than rebuilding history under a filing deadline.

  2. Investor diligence: Anchor investors and institutional subscribers increasingly run ESG due diligence alongside financial diligence. An ESG gap assessment, effectively is a scoped-down audit, giving the company its own findings before outsiders arrive, and its output feeds the risk-factor and sustainability sections of the offer documents. Our earlier piece on integrating ESG strategies pre-IPO covers the strategic side; the audit process is what makes it real.

How Oren Can Help

Audit findings in ESG almost always trace back to the same root cause that the was data assembled manually, without an evidence trail. Oren's platform gives audit and sustainability teams a single system where every ESG figure carries its source, from GHG accounting to workforce metrics, mapped to CSRD, BRSR, GRI and CDP fields and ready for assurance. Whether you are preparing for CSRD assurance, BRSR Core, or an IPO, schedule a demo and we will run through the checklist above against your current setup.

Conclusion

An ESG audit tests whether the reported ESG information is accurate, complete and evidenced, using whichever framework the company reports under as the yardstick. Audit, assurance and due diligence are different exercises: the audit is internal and for the company, assurance is for the company's stakeholders, and due diligence belongs to whoever is about to undertake the transaction.

Assurance mandates are converging worldwide: CSRD in the EU, BRSR Core in India, and ISSB-aligned regimes elsewhere make the internal ESG audit a matter of self-defence, and IPO-bound companies gain the most from auditing early, before obligations and investors arrive together.

Companies that centralise their ESG data before the audit spend the engagement fixing real gaps instead of hunting for documents.

Frequently Asked Questions (FAQs)

Q1. What is an ESG audit?

An ESG audit is a structured review of a company's environmental, social and governance data, policies and processes against a defined standard or framework. It tests whether reported ESG information is accurate, complete and backed by evidence, and identifies gaps before regulators, investors or customers find them.

Q2. What does an ESG audit cover?

A typical ESG audit covers emissions and environmental data, workforce and safety records, supply chain practices, governance policies and board oversight, and the systems that produce the reported numbers. The exact scope depends on the framework in use, such as BRSR, GRI or a customer's supplier code.

Q3. What is the difference between an ESG audit and ESG assurance?

An ESG audit is usually an internal or advisory exercise to find and fix gaps. Assurance is a formal engagement where an independent practitioner issues an opinion on specified disclosures, such as BRSR Core KPIs, under standards like ISAE 3000.

Q4. What is the difference between an ESG audit and ESG due diligence?

An ESG audit examines a company's own reporting and systems on a recurring basis. ESG due diligence is transaction-driven carried out by an investor, acquirer or lender to examine a target's ESG risks before committing capital. The techniques overlap, but due diligence is transaction based, for the purpose of decision making of external stakeholders.

Q5. Is an ESG audit mandatory?

The internal audit itself is not mandated anywhere, but external scrutiny increasingly is: the EU's CSRD requires limited assurance of sustainability statements, and SEBI requires independent assurance or assessment of BRSR Core KPIs for India's largest listed companies. Companies run internal ESG audits first so their data survives that scrutiny.

Q6. Who can conduct an ESG audit?

Internal audits can be run by the company's own audit function or an ESG advisory partner. Formal assurance must come from an independent practitioner, typically accounting firms or specialist certification bodies applying standards such as ISAE 3000. Each regime sets its own eligibility rules, so verify providers against the local regulator's requirements.

Q7. How long does an ESG audit take?

A focused readiness audit of one reporting cycle typically takes four to eight weeks, depending on the number of sites, the state of the data and how many frameworks are in scope. Companies with centralised ESG data platforms move materially faster because evidence gathering is not manual.

Q8. Do IPO-bound companies need an ESG audit?

There is no ESG audit requirement to list your organisation on the exchange, but companies entering the top 1,000 by market capitalisation take on BRSR obligations after listing, and anchor investors increasingly run ESG due diligence before subscribing. A pre-IPO ESG gap assessment prevents post-listing compliance surprises and awkward diligence findings.

Olivia Paul

About the author

Olivia Paul

ESG & Sustainability Advisor

Olivia is an ESG & Sustainability Advisor at Oren, focused on ESG reporting and strategy, materiality assessments, GHG inventory, and net-zero roadmaps across manufacturing, financial services, and infrastructure.

Share this article

Go Beyond Reporting.Start Driving Real Impact.

Oren ESG Dashboard