Glossary term

Cluster E · E10

Tier 2

Assurance committee reporting

Definition

Assurance committee reporting is the communication an assurance provider makes to the audit and risk committee about a sustainability assurance engagement. Under ASSA 5000 the practitioner must communicate significant matters on a timely basis during the engagement, including internal control deficiencies and instances of fraud.

· paragraph 68 ·

In force

In practice

Most Australian audit and risk committees have inherited climate oversight without inheriting a reporting rhythm for it, and the first year is usually run as a single appearance by the assurer at the meeting that approves the report. That is too late to be useful and it is not what the standard contemplates.

Paragraph 68 requires communication of significant matters that in the practitioner’s professional judgement merit the attention of management or those charged with governance, as appropriate, and to do so on a timely basis during the engagement. Two words in that do work. “Timely” means during, not at the end. “As appropriate” means the practitioner decides whether a matter goes to management or escalates to the committee, and a matter that management has been told about and not acted on is exactly the kind that escalates.

What the standard does supply is the subject matter. Application paragraphs A166 to A168 list what may merit the committee’s attention: identified deficiencies in internal control; management bias in preparing the sustainability information; material misstatements management has refused to correct; reporting policies that are inappropriate or inconsistent with the applicable criteria; circumstances affecting the form and content of the assurance report; matters relating to estimates, forward-looking information and inherent uncertainties; significant matters discussed or corresponded on with management; and significant difficulties encountered during the engagement. A167 expands the seventh of those to include significant events or transactions during the year, concerns about management’s use of an expert or externally sourced information, and matters on which the practitioner disagreed with management. A168 expands the eighth to include delays by management, unavailability of personnel, and unwillingness to provide information.

A committee that wants a useful engagement can simply work that list. It is the standard’s own agenda.

The cadence below is practice, not requirement. ASSA 5000 has no dedicated communication-with-those-charged-with-governance section and prescribes no meeting schedule; paragraph 68 and its application material are the whole of the obligation. What follows is what works, drawn from established governance-communication practice in financial report audits.

Touchpoint

What it covers

Planning

Scope for the reporting year under ASSA 5010, materiality, the identified risk areas and the timetable.

Interim

Once fieldwork has found what it is going to find, which is when control deficiencies surface and while there is still time to fix them.

Completion

Uncorrected misstatements, significant judgements, the proposed report wording, and the representations the CFO is being asked to sign.

The interim touchpoint is the one entities skip and the one that has value. A control deficiency raised in month two can be remediated before year four’s audit. The same deficiency raised at the approval meeting is a finding the committee can only note.

What the assurer does with it

The practitioner communicates their planned scope and materiality, then reports what they found. Expect control deficiencies over the sustainability data to be reported in writing, expect significant judgements and estimates to be named individually, and expect a schedule of uncorrected misstatements with the practitioner’s assessment of them in aggregate.

They also ask the committee questions rather than only presenting to it. Paragraph 64 requires the practitioner to maintain professional scepticism throughout, recognising that a material misstatement due to fraud could exist regardless of past experience of management’s honesty, and paragraph 65 requires them to stay alert to non-compliance with laws and regulations. In practice that produces inquiries covering the committee’s own view of fraud risk in the sustainability information, its knowledge of any actual or suspected fraud, whether it is aware of relevant non-compliance, and whether it knows of events since year end bearing on the report.

Those inquiries are evidence, and they are documented as such. A committee that answers “no concerns” without having asked management anything is giving the practitioner a representation it has not tested. The committee members most exposed here are the ones who treat the assurer’s visit as a briefing rather than a two-way examination.

What the practitioner escalates without waiting is a disagreement with management they cannot resolve, a limitation on their scope imposed by management, and any indication of fraud. Any of those arriving at the committee mid-engagement is a signal to intervene, not to wait for the report.

Commonly confused with

The management representation letter. That is signed by management and given to the practitioner. Committee communication runs the other way, from the practitioner to those charged with governance. The committee should see the representation letter before management signs it, because it is being signed partly on the committee’s oversight.

Sources

1

ASSA 5000 General Requirements for Sustainability Assurance Engagements, full text (January 2025)

AUASB

2

ASSA 5000 General Requirements for Sustainability Assurance Engagements

AUASB

3

Regulatory Guide 280 Sustainability reporting

ASIC

Review status

Review required

Last reviewed

15 September 2026

Editorial pass, unsigned

Reviewer required

Registered company auditor

Next scheduled review

1 July 2027

Part of

Cluster E, Measurement and governance / Governance, board and directors

10 terms on what the board must be able to evidence, what personal exposure directors carry, and how the audit and risk committee engages with the assurer. Governance disclosures sit inside the year-one assurance scope.