Glossary term

Cluster A · A39

Tier 1 · differentiator

ASSA 5000

Definition

ASSA 5000 is the Australian standard that governs assurance over sustainability information, including the climate disclosures in a Corporations Act sustainability report. It sets the requirements for the whole engagement: ethics, evidence, materiality, group scoping and the assurance report itself. It covers both limited and reasonable assurance, and both mandatory and voluntary engagements.

· ASSA 5000, compiled July 2025 · in force for reporting periods beginning on or after 1 January 2025

In practice

This is the standard most captured entities name wrongly. Before the mandatory regime almost all Australian sustainability assurance ran under ASAE 3000, or ASAE 3410 for emissions specifically. For a statutory sustainability report under Chapter 2M, neither is the governing standard any more. ASSA 5000 is, and it is a substantially heavier document than what it replaced.

ASSA 5000 is the Australian adoption of the international standard ISSA 5000, with Australian-specific paragraphs marked with an Aus prefix. Two things follow from that structure. The bulk of what your assurer does is internationally consistent, so global-firm methodology transfers. But the Aus paragraphs are where the local surprises sit, and they are the ones worth knowing.

ASSA 5000 tells you what the engagement is. ASSA 5010 tells you how much of your report is inside it this year. You need both to answer “what is being assured.” Reading ASSA 5000 alone leads entities to assume the whole report is in scope from year one, which for Groups 1, 2 and 3 in their first reporting year it is not.

The standard is written to be framework-neutral and topic-neutral. It is drafted so it can be applied to any sustainability subject matter under any reporting framework, not only to AASB S2 climate disclosures. For a captured Australian entity that neutrality has a practical edge: if you also seek voluntary assurance over a modern slavery statement or a waste metric, the same standard governs it, and your assurer will apply the same evidence bar.

What the assurer does with it

ASSA 5000 drives the engagement in a fixed sequence, and knowing the sequence is how a controller stops being surprised.

At acceptance the practitioner tests whether the engagement is even capable of being performed: whether the criteria are suitable, whether the subject matter is measurable, and whether they can get evidence. If your basis of preparation does not state the criteria you applied, this is where the engagement stalls, before any testing starts.

They then agree written terms under paragraphs 85 to 88, obtain an understanding of the entity and its internal control, assess risk, design and perform procedures scaled to the assurance level, evaluate the misstatements they found, obtain written representations from management, and report under paragraphs 188 to 212.

What they accept is a file organised the way the standard thinks: criteria first, then the measurement, then the evidence. What they reject is a report figure with no stated criteria behind it. Under ASSA 5000 the practitioner cannot conclude on information that has no criteria, because there is nothing to conclude against. “We used the GHG Protocol” is not sufficient on its own; they will ask which edition, which boundary approach, which factor set and which version of it.

The procedure that catches most first-year entities is the evaluation of uncorrected misstatements. The assurer accumulates every difference they find, including ones you declined to fix because they looked small, and assesses them in aggregate against materiality at the end. Entities that push back on individual small adjustments through the engagement often find the accumulated total is what drives the conversation about modifying the conclusion.

Commonly confused with

ISSA 5000, which is the international parent and is not what your Australian assurer signs under. And with ASAE 3000, the general assurance standard that governed this work before 2025 and still governs assurance engagements outside Chapter 2M.

Timing and relief

ASSA 5000 is in force now, not transitioning. For Chapter 2M sustainability reports it applies to periods beginning on or after 1 January 2025. For all other assurance engagements it applies as at a specified date on or after 31 December 2025, and for periods ending on that date, unless the period commenced before 1 January 2025. The phasing that entities care about sits in ASSA 5010, not here. ASSA 5000 has been amended twice since first issue, in May 2025 and July 2025; cite the compiled version, not the January 2025 original.

Sources

1

ASSA 5000 General Requirements for Sustainability Assurance Engagements

AUASB

2

Climate and sustainability assurance requirements approved

AUASB

3

FAQs: Review or audit of sustainability reports

ASIC

Review status

Review required

Last reviewed

15 September 2026

Editorial pass, unsigned

Reviewer required

Registered company auditor

Next scheduled review

1 July 2027

Part of

Cluster A, Assurance, audit evidence and working papers

47 terms on what an assurance provider tests, what they accept as evidence, and what a preparer has to be able to produce.