ISSA 5000: what changes for the company being assured
Almost everything written about ISSA 5000 is addressed to audit firms. That is reasonable — it is their standard. It is also unhelpful if you are the one who has to answer their questions.
This is the other side of the engagement. Not what your assurance provider must do, but what lands on your desk because of it.
Key points
- ISSA 5000 binds your assurance provider, not you. You cannot breach it. You can still be the reason they cannot conclude.
- It applies to sustainability information for periods beginning on or after 15 December 2026, with early application permitted.
- It covers limited and reasonable assurance in one standard, so moving between the two is a change of depth, not of rulebook.
- It broadens tests of controls. If you have no controls to test, the work moves to testing individual figures instead — which costs you more time, not less.
What ISSA 5000 is, and who it binds
ISSA 5000, General Requirements for Sustainability Assurance Engagements, was published by the IAASB in November 2024. It is a stand-alone standard covering sustainability assurance engagements across any sustainability topic, and it is written to work with information prepared under different reporting frameworks.
Two features matter more to you than they might appear to.
It is profession-agnostic. It is designed for use by professional accountants and non-accountant assurance practitioners alike. Your assurer may not be your financial statement auditor.
And it covers both limited and reasonable assurance in a single standard. That is genuinely useful, because most jurisdictions are phasing from one to the other. The rulebook does not change under you. The depth of work does.
The date that matters
ISSA 5000 applies to assurance engagements on sustainability information reported for periods beginning on or after 15 December 2026, or as at a specific date on or after 15 December 2026. Early application is permitted.
Read that carefully, because the phrasing catches people out. It is not about when your assurer does the work. It is about the period the information covers.
A December year-end company reporting FY2027 is squarely in scope. A company whose FY2026 runs January to December is not — unless its assurance provider chooses to apply the standard early, which some will, because they would rather run one methodology than two.
Ask your provider which basis they intend to use. It is a reasonable question and the answer changes what they will ask you for.
What that means you will be asked to produce
The process. How sustainability information actually gets prepared: who collects what, in what order, from which systems. Most teams have this in their heads and not on paper. Writing it down is a week of work that saves considerably more.
The controls over that process. This is where ISSA 5000 has teeth. The standard strengthens work on internal controls and broadens the scope of tests of controls, encouraging — though not mandating — a controls-based approach.
Note the word "encouraging". You are not obliged to build a control environment. But if there is nothing to test, your assurer falls back on substantive testing of individual numbers, which means bigger samples and more requests aimed at your team.
Your materiality process. This one surprises people. The practitioner obtains evidence about the entity's materiality process at various points across the engagement, per the IAASB's materiality FAQs. Not only your conclusion about what was material — how you reached it.
If your materiality assessment lives in a slide deck with no record of who was consulted or what was weighed, that is a gap.
The evidence behind selected figures. The familiar part: source documents, the record of review and approval, the history of any change. This is the ground covered in the audit trail behind your climate numbers.
Limited and reasonable assurance under one standard
Under limited assurance, the conclusion is expressed negatively: nothing came to the practitioner's attention. Under reasonable assurance, they express an opinion on the information itself.
The practical difference is depth. ISSA 5000 differentiates the requirements for obtaining an understanding of the entity's system of internal control between the two levels.
The shift most preparers underestimate is this: at limited assurance you mostly need to show that figures are supported. At reasonable assurance you need to show that a control operated, repeatedly, over the whole period. A sign-off that happened once, in March, for the annual figure, does not demonstrate a control that ran monthly.
What to put in place before your first engagement
Four things, in the order that recovers the most ground.
Write down the process. One document. Who provides what, when, from where, and who checks it. Boring, and the single most useful artefact you can hand over on day one.
Record approvals as records. Named person, timestamp, what was approved. If your only evidence of review is an email thread, you have a story rather than a record.
Keep the change history. When a figure moves, keep the previous value and the reason. You can test what an append-only record looks like if you want to see the shape of it.
Document how you reached materiality, not just what you concluded. Who was consulted, what was considered, what was ruled out and why.
The opinion, since this piece has one: treat ISSA 5000 as a procurement document rather than a compliance one. You are not being examined against it. You are being asked to supply inputs to someone who is. Teams that read it that way prepare the right things and spend far less of the engagement scrambling.
Common questions
When does ISSA 5000 take effect?
It applies to assurance engagements on sustainability information reported for periods beginning on or after 15 December 2026, or as at a specific date on or after 15 December 2026. Early application is permitted, so an assurance provider may apply it sooner. The standard itself was published by the IAASB in November 2024.
Does ISSA 5000 apply to my company or to my auditor?
It binds the assurance practitioner, not the reporting entity. You are never non-compliant with ISSA 5000. But because it sets what your assurer must obtain before they can conclude, its requirements arrive at your door as requests for evidence, process documentation and access.
Does ISSA 5000 cover both limited and reasonable assurance?
Yes. It is a single standard covering both levels, which is part of why it matters. The same framework applies as your jurisdiction moves from limited to reasonable assurance, so the direction of travel is a deepening of work under one standard rather than a change of rulebook.
Do I need a formal control environment for sustainability data?
ISSA 5000 broadens the scope of tests of controls and encourages a controls-based approach without mandating one. So a formal control environment is not strictly required, but its absence pushes your assurer toward substantive testing of individual figures, which usually means more sampling, more requests and more of your team's time.
Where do you stand against IFRS S2?
A free 6-minute diagnostic scores your readiness across all four pillars and sends a 12-page gap report naming what is missing.
Run the free diagnostic →