Glossary›Measurement and governance / Governance, board and directors›Assurance committee reporting
Glossary term
Cluster E · E10
Tier 2
Assurance committee reporting
Definition
Assurance committee reporting is the communication an assurance provider makes to the audit and risk committee about a sustainability assurance engagement. Under ASSA 5000 the practitioner must communicate significant matters on a timely basis during the engagement, including internal control deficiencies and instances of fraud.
On this page
In practice
Most Australian audit and risk committees have inherited climate oversight without inheriting a reporting rhythm for it, and the first year is usually run as a single appearance by the assurer at the meeting that approves the report. That is too late to be useful and it is not what the standard contemplates.
Paragraph 68 requires communication of significant matters that in the practitioner’s professional judgement merit the attention of management or those charged with governance, as appropriate, and to do so on a timely basis during the engagement. Two words in that do work. “Timely” means during, not at the end. “As appropriate” means the practitioner decides whether a matter goes to management or escalates to the committee, and a matter that management has been told about and not acted on is exactly the kind that escalates.
What the standard does supply is the subject matter. Application paragraphs A166 to A168 list what may merit the committee’s attention: identified deficiencies in internal control; management bias in preparing the sustainability information; material misstatements management has refused to correct; reporting policies that are inappropriate or inconsistent with the applicable criteria; circumstances affecting the form and content of the assurance report; matters relating to estimates, forward-looking information and inherent uncertainties; significant matters discussed or corresponded on with management; and significant difficulties encountered during the engagement. A167 expands the seventh of those to include significant events or transactions during the year, concerns about management’s use of an expert or externally sourced information, and matters on which the practitioner disagreed with management. A168 expands the eighth to include delays by management, unavailability of personnel, and unwillingness to provide information.
A committee that wants a useful engagement can simply work that list. It is the standard’s own agenda.
The cadence below is practice, not requirement. ASSA 5000 has no dedicated communication-with-those-charged-with-governance section and prescribes no meeting schedule; paragraph 68 and its application material are the whole of the obligation. What follows is what works, drawn from established governance-communication practice in financial report audits.
Touchpoint
What it covers
Planning
Scope for the reporting year under ASSA 5010, materiality, the identified risk areas and the timetable.
Interim
Once fieldwork has found what it is going to find, which is when control deficiencies surface and while there is still time to fix them.
Completion
Uncorrected misstatements, significant judgements, the proposed report wording, and the representations the CFO is being asked to sign.
The interim touchpoint is the one entities skip and the one that has value. A control deficiency raised in month two can be remediated before year four’s audit. The same deficiency raised at the approval meeting is a finding the committee can only note.
What the assurer does with it
The practitioner communicates their planned scope and materiality, then reports what they found. Expect control deficiencies over the sustainability data to be reported in writing, expect significant judgements and estimates to be named individually, and expect a schedule of uncorrected misstatements with the practitioner’s assessment of them in aggregate.
They also ask the committee questions rather than only presenting to it. Paragraph 64 requires the practitioner to maintain professional scepticism throughout, recognising that a material misstatement due to fraud could exist regardless of past experience of management’s honesty, and paragraph 65 requires them to stay alert to non-compliance with laws and regulations. In practice that produces inquiries covering the committee’s own view of fraud risk in the sustainability information, its knowledge of any actual or suspected fraud, whether it is aware of relevant non-compliance, and whether it knows of events since year end bearing on the report.
Those inquiries are evidence, and they are documented as such. A committee that answers “no concerns” without having asked management anything is giving the practitioner a representation it has not tested. The committee members most exposed here are the ones who treat the assurer’s visit as a briefing rather than a two-way examination.
What the practitioner escalates without waiting is a disagreement with management they cannot resolve, a limitation on their scope imposed by management, and any indication of fraud. Any of those arriving at the committee mid-engagement is a signal to intervene, not to wait for the report.
Commonly confused with
The management representation letter. That is signed by management and given to the practitioner. Committee communication runs the other way, from the practitioner to those charged with governance. The committee should see the representation letter before management signs it, because it is being signed partly on the committee’s oversight.
Sources
1
ASSA 5000 General Requirements for Sustainability Assurance Engagements, full text (January 2025)
AUASB
2
ASSA 5000 General Requirements for Sustainability Assurance Engagements
AUASB
3
Review status
Review required
Last reviewed
15 September 2026
Editorial pass, unsigned
Reviewer required
Registered company auditor
Next scheduled review
1 July 2027
Part of
Cluster E, Measurement and governance / Governance, board and directors
10 terms on what the board must be able to evidence, what personal exposure directors carry, and how the audit and risk committee engages with the assurer. Governance disclosures sit inside the year-one assurance scope.
Related terms
The body the practitioner communicates to, and what it must be able to evidence
The communication running the other way, from management to the practitioner
The deficiencies paragraph 68 requires the practitioner to report
Related questions
What will our audit and risk committee ask us?
−
The same questions they ask about the financial report, applied to information the committee has never seen before. Expect them on capture and scope, where each number comes from and what controls sit over it, the significant judgements and materiality, who your assurance provider is and whether they are independent of the preparer, and what liability protection applies and until when. It works as a self-test: anything you cannot answer today is a work item.
What happens if the assurance provider disagrees with our numbers?
+
Disagreement is normally resolved before it reaches the conclusion: the practitioner raises a query, you produce more evidence or adjust the number, and the file moves on. A modified conclusion only arrives if you decline to adjust something material, or if they cannot obtain the evidence they need. The second case is far more common in a first year and is entirely preventable through documentation.
What is a management representation letter and what will we be signing?
+
A letter management signs near the end of the assurance engagement, confirming matters the practitioner cannot verify independently. You confirm that the disclosures are complete, that you have provided all relevant information, that your judgements and estimates are reasonable, and that you have disclosed any known errors or later events.
Other terms in this cluster
Assurance committee reporting