Compliance

Third-party assurance for GHG emissions: what it is, when you need it, and how to prepare

A

Anand Srinivasan

20 Jul 2026 · 7 min read

Third-party assurance is the GHG equivalent of an external audit. A qualified independent verifier reviews your emissions data, your methodology, and your internal controls, and issues a statement on whether the disclosures present a true and fair view. It is required under CSRD from FY2025 and under California SB 253 from FY2026. If you are in scope for either regulation and do not have an assurance engagement planned, you are already late.

Limited versus reasonable assurance

There are two levels of assurance and they are not interchangeable.

                    LIMITED ASSURANCE          REASONABLE ASSURANCE
                    ─────────────────          ────────────────────
Standard:           ISAE 3000/3410             ISAE 3000/3410 (higher procedures)
What verifier does: Inquiry + analytical        + Substantive testing of records
                    procedures                  + Controls evaluation
                    Nothing came to our         Presents fairly in all material
Conclusion form:    attention suggesting...     respects...
Typical cost:       $15k–40k                   $50k–150k+
Timeline:           4–8 weeks                  8–16 weeks
Required for CSRD:  FY2025 S1+2, FY2026 S3     S1+2 from FY2028
Required for SB253: FY2026 S1+2                Not yet required

For a first filing, limited assurance is the entry requirement. It is not a light-touch box-tick — verifiers still need full access to your data and methodology — but it is substantially less intensive than a financial audit. Reasonable assurance, required for CSRD S1+2 from FY2028, involves testing individual emission records against source data and evaluating your data governance controls.

Who provides it

PROVIDER TYPE                 EXAMPLES                        TYPICAL SCOPE
──────────────────────────────────────────────────────────────────────────────
Big 4 accounting firms        PwC, Deloitte, EY, KPMG        S1+2+3 full scope
                              Sustainability practices         Regulatory filings
                              Most expensive; preferred by
                              regulated industries

Specialist sustainability     Bureau Veritas, DNV,            S1+2+3 full scope
assurance firms               Lloyd's Register, SGS           CDP verification
                              Lower cost than Big 4           ISO 14064-1

Boutique ESG assurance        Various regional firms          S1+2 only
                              Lowest cost; suitable for       Smaller companies
                              first limited assurance

For a software company doing its first SB 253 or CSRD limited assurance engagement, a specialist sustainability firm (Bureau Veritas, DNV) is typically the right choice — experienced with GHG Protocol, familiar with tech company emission profiles, faster than Big 4 engagement processes, and $10k–20k cheaper.

What they need from you

Assurance providers cannot work without four things. If any of these are missing, they cannot issue a statement.

① Methodology documentation
  → Describes how each category was calculated
  → References emission factor sources and vintage
  → States organisational boundary and consolidation method
  → Quantifies uncertainty ranges per data source
  → EmitCI: download Methodology PDF from Emissions page

② Emission factor sources
  → IEA regional grid intensities (year + version)
  → DEFRA spend-based factors (year + publication)
  → Manufacturer PCF data (source + date + device model)
  → AWS/GCP native API (source documentation)

③ Raw data → calculation trail
  → Billing row → energy → carbon for each cloud resource
  → CI run log → runner energy → carbon per run
  → Spend → DEFRA factor → carbon for each SaaS tool
  → Headcount → embodied CO₂ for hardware
  → EmitCI: all records are queryable; export available

④ Data governance documentation
  → Who owns the data? What is the approval process?
  → How are errors corrected?
  → How long is data retained?
  → What internal controls exist over the calculation process?

Item ④ is where most companies are unprepared. Verifiers are increasingly asking about data governance — not just "is the number correct" but "how do we know the number is correct and will remain correct." A written policy covering data ownership, error correction, and retention (even a two-page internal document) satisfies this requirement.

How assurance and EmitCI work together

EmitCI tracks the assurance details you provide for each Scope 1 and Scope 2 declaration: provider name, assurance level, engagement date, and reference number. These are stored per reporting year — FY2025 and FY2026 have independent assurance records.

When you download the CDP Excel workbook from the Emissions page, C6.1c (Scope 1 third-party verification) and C6.3e (Scope 2 third-party verification) are auto-populated from those records. If you have limited assurance from Bureau Veritas with reference BV-2026-0142, that information goes directly into the CDP questionnaire without manual re-entry.

The Methodology PDF that EmitCI generates covers items ① and ② above. It includes the boundary method, data sources table, emission factor table with vintage, and uncertainty bounds per source. Most assurance providers have accepted it as the methodology basis without requiring additional documentation, though they will supplement it with their own findings.

Practical timeline for a first engagement

  MONTH -3         MONTH -2         MONTH -1         FILING
     │                │                │                │
     ▼                ▼                ▼                ▼
  Select           Share            Receive           Submit
  provider         EmitCI           assurance         CDP
  and scope        Methodology      statement         response
  engagement       PDF + data       from provider
                   room access

  ─────────────────────────────────────────────────────────────
  For SB 253 FY2026 filing due January 2027:
  Start provider engagement: October 2026 at the latest
  Share data access: November 2026
  Receive statement: December 2026
  Submit CDP: January 2027

If you are starting from zero today (July 2026), you have exactly enough time to meet the FY2026 SB 253 deadline if you begin the provider selection process this month. Providers book out; a Q4 assurance engagement started in October is borderline, in November is probably too late.

Get started free

Start measuring your CI carbon today

Connect your GitHub account in 2 minutes. Per-workflow carbon and cost estimates appear within 24 hours. No code changes required.

Install GitHub App — free for 14 days