SUSTAINABILITY8 min read

What Is a Sustainability Assurance Pack and Why Will Your Auditor Ask for One?

External assurance on greenhouse gas emissions becomes mandatory for SGX-listed companies in FY2029. For many Singapore businesses, this is the first time a third party will formally attest to the accuracy of non-financial data. The companies that find the experience straightforward will be the ones who have been building an evidence trail for years — not the ones who scramble to reconstruct a justification for figures they reported from a spreadsheet. This article explains what an assurance pack is, what assurers actually examine, and how to start preparing now so that FY2029 feels like a formality rather than a crisis.

The Coming Assurance Requirement

In Singapore, the SGX Listing Rules now require listed issuers to disclose Scope 1 and Scope 2 greenhouse gas emissions in their annual sustainability reports. Disclosure phased in based on company size, with the largest issuers reporting from FY2025. External assurance — meaning a qualified third party formally attesting to the accuracy of those disclosures — is required from FY2029.

Assurance is not a new concept. Every Singapore listed company goes through annual financial audit. Sustainability assurance is the carbon equivalent: a qualified assurance provider reviews your methodology, examines your source data, tests your internal controls, and issues a formal conclusion about whether your reported emissions figures are materially accurate. The key difference from financial audit is that the evidence base is different — utility bills and refrigerant invoices instead of general ledger entries — and the methodology standards are still maturing.

What has not changed: the fundamental logic of audit. Can you trace every number back to a source document? Is that source document authentic and unaltered? Was there a human who reviewed the data before it was reported? If those three conditions are met, assurance proceeds smoothly. If they are not, the assurer issues a qualified opinion — or worse.

What Assurance Providers Actually Look At

The common misconception about sustainability assurance is that the assurer checks whether your final number is "right." In practice, they check whether your process is defensible enough that the final number is very likely to be materially correct. That is a subtle but important distinction.

A sustainability assurance engagement typically examines four things:

Methodology: Did you apply a recognised, appropriate standard? In Singapore practice, the GHG Protocol Corporate Accounting and Reporting Standard and ISO 14064-1 are the accepted frameworks. Your methodology statement needs to document which standard you followed, which consolidation approach you used (operational control or equity share), and why those choices are appropriate for your operations.

Emission factors: Did you use the right factors, from the right source, for the right year? The Energy Market Authority publishes an annual grid emission factor for Singapore electricity. That factor changes year to year. If you applied FY2023's factor to FY2024 data, that is a methodological error the assurer will flag. Your emission factor registry must document: the factor value used, the source publication, and the version year — for every emission source, every year.

Source data: Can every tonne of CO2e in your report be traced back to an underlying source document — a utility bill, a fuel receipt, a refrigerant recharge invoice? This is where many first-time reporters struggle. They calculated their emissions from figures they transcribed into a spreadsheet, and the original documents were not systematically retained. When the assurer asks to see the SP Group bill for Q3 2025 for your Jurong facility, "we've got the number in our Excel" is not a satisfactory response.

Internal controls: Is your data collection and recording process designed to prevent and detect errors? Assurers look for: separation of duties (the person entering data should not be the only person approving it), immutability (can entries be changed after the fact without a logged record?), and human review gates (is there documented evidence that a responsible person reviewed the AI extraction or manual entry before it was accepted?).

What assurers mean by "internal controls"

A sustainability assurer asking about internal controls is asking the same question a financial auditor asks: is there a system that makes errors unlikely, detectable, and correctable? For sustainability data, that means: entries cannot be silently edited; every change is logged with a timestamp and a user ID; a second person reviewed and approved data before it entered the record; and the system that holds the data is separate from the spreadsheet that calculated it. This is the structural difference between an evidence vault and an Excel file.

What an Assurance Pack Is

An assurance pack is the structured document collection that satisfies all four of the above dimensions. It is not a single document — it is an organised body of evidence. A well-prepared assurance pack for Scope 1 and Scope 2 typically contains six components:

Methodology statement: A concise description of the GHG accounting standard applied, the organisational boundary approach, the operational boundary (which emission sources are included and why), and the base year definition. Two to four pages.

Source document index: A structured log of every source document — each utility bill, fuel receipt, or refrigerant invoice — with the document reference, facility, reporting period, and the emission entry it supports. This is the chain of custody for your data.

Emission factor registry: A version-controlled table of every emission factor used: the source category, the factor value, the unit, the source publication, and the version year. Updated annually as new EMA or DESNZ publications are released.

Calculation workings: The full arithmetic from activity data to CO2e for every emission source and reporting period. For each line: source document reference → activity data quantity and unit → emission factor applied → CO2e result.

Calculation chain: A system-generated or manually maintained audit trail showing the unbroken link from bill to factor to CO2e, with timestamps on each step.

Internal review log: A record of who reviewed and approved each data entry, when, and whether any corrections were made. This is the human-in-the-loop evidence the assurer needs to confirm that a responsible person — not just an automated system — signed off on the data.

Why a Spreadsheet Won't Survive Assurance

The most common error made by companies approaching their first assurance engagement is assuming that a well-organised Excel spreadsheet constitutes an adequate evidence system. It does not, for a structural reason: spreadsheets are not immutable. A cell can be changed, a formula can be replaced, a row can be deleted — and there is no system-generated log of what changed, when, or by whom. The spreadsheet you show the assurer today is not provably the same document you used to produce last year's report.

Assurers who work across multiple client engagements are increasingly familiar with this limitation. The response from leading assurance firms has been to require or recommend that clients use systems where data entries are append-only — where corrections are made by adding a new entry that supersedes the old one, not by overwriting the original. Every entry carries a timestamp and a user identifier. The system generates the audit trail automatically, not as an afterthought.

This is the concept behind an evidence vault: a system where the source documents, the emission factor applications, the calculation workings, and the human review events are all stored together in a structure that cannot be altered retrospectively without leaving a visible record. It is less about software sophistication and more about data discipline — but a purpose-built system makes that discipline much easier to maintain at scale.

Limited vs Reasonable Assurance

Not all assurance is the same, and the SGX FY2029 requirement specifies limited assurance — not reasonable assurance. Understanding the difference helps you calibrate how much preparation is appropriate.

Limited assurance involves analytical procedures, inquiries, and selective document review. The assurer's conclusion is phrased in negative form: "Nothing came to our attention that causes us to believe the reported Scope 1 and Scope 2 emissions are materially misstated in accordance with the GHG Protocol." This is a meaningful check — assurers conducting limited engagement will typically sample 20–40% of source documents and test your emission factor applications — but it is not an exhaustive examination of every transaction.

Reasonable assurance is the higher standard used in financial audit. The conclusion is positive: "We are satisfied that the reported figures are materially correct." Achieving reasonable assurance requires more extensive testing, a more complete evidence review, and substantially more assurer time — which translates to higher fees and a more demanding preparation process. Some listed companies and many institutional investors will eventually push for reasonable assurance, but it is not the regulatory baseline in Singapore for FY2029.

How to Prepare Years Before FY2029

The companies that find FY2029 assurance straightforward will be the ones who started building their evidence trail in FY2025 or FY2026 — not the ones who begin in FY2028. The reason is simple: assurers often request historical data to verify year-on-year trends and confirm that your base year calculation is correct. If you cannot produce source documents for FY2025, that weakness surfaces in your FY2029 engagement.

The practical preparation steps are: establish a document retention system for source documents now, using a structure that organises by facility, period, and emission source; document your methodology in writing this year, even if it is a simple two-page internal document; implement a human review gate for every data entry, so there is a named approver and a timestamp for every figure in your records; and conduct a pre-assurance gap review with an external sustainability advisor 12 to 18 months before your first assurance engagement.

The pre-assurance gap review is particularly valuable. An experienced sustainability assurance professional reviewing your evidence pack before the formal engagement will identify weaknesses that you can fix. The cost of fixing a methodology error internally is a few days of staff time. The cost of receiving a qualified assurance opinion is reputational, regulatory, and financial — potentially triggering disclosure obligations under SGX rules and investor scrutiny.

What Happens If Assurance Fails

Assurance engagements do not simply produce "pass" or "fail." They produce one of four outcomes:

Unqualified conclusion: The assurer found nothing material to flag. Your emissions data is presented as credible. This is the outcome to aim for.

Qualified conclusion: The assurer found specific issues — perhaps one facility's data could not be verified, or a particular emission source used an inappropriate factor — but the overall report is otherwise acceptable. The qualification must be disclosed.

Adverse conclusion: The assurer concluded that the reported emissions are materially misstated. This is the sustainability equivalent of a financial audit qualification and carries significant consequences for investor confidence and regulatory scrutiny.

Refusal to provide assurance: The assurer declined because the evidence base was too weak to support even a limited engagement. This outcome essentially tells the market that your company's sustainability data is unreliable.

The business case for early preparation

An unqualified limited assurance conclusion from FY2029 requires three to four years of clean evidence trail. Companies that begin building that trail in FY2025 will spend roughly 40–60% less on their assurance engagement than companies who try to reconstruct historical evidence in the months before the deadline. The maths of early action are consistently favourable.

Frequently Asked Questions

What is a sustainability assurance pack?
A sustainability assurance pack is the structured collection of documents that a company provides to a third-party assurer to enable them to verify the accuracy of sustainability disclosures — particularly greenhouse gas emissions. It typically contains: a methodology statement, a source document index (every utility bill and fuel receipt referenced), an emission factor registry (version-controlled factors used), full calculation workings, and an internal review log documenting who approved each entry and when.
What does a sustainability assurer look at?
Sustainability assurers examine four things: (1) Methodology — did the company apply a recognised standard such as the GHG Protocol or ISO 14064-1? (2) Emission factors — are the factors correct, appropriately sourced, and the right version for the reporting year? (3) Source data — can every reported tonne of CO2e be traced back to an underlying source document? (4) Internal controls — is there an immutable audit trail showing that entries cannot be changed after the fact, and that a human reviewer approved each data point?
When is external assurance required for Singapore companies?
For SGX-listed companies, external assurance on Scope 1 and Scope 2 greenhouse gas emissions becomes mandatory from financial year 2029. The SGX climate reporting timeline works in phases: Scope 1 and Scope 2 disclosure became mandatory for large listed companies from FY2025, with assurance phased in later. Non-listed companies and SMEs are not currently subject to mandatory external assurance, but supply chain pressure is increasingly driving SME adoption.
What is the difference between limited and reasonable assurance?
Limited assurance involves analytical procedures and selective document review, with a negative-form conclusion: "nothing came to our attention that causes us to believe the figures are materially misstated." Reasonable assurance involves more extensive testing and a positive conclusion: "we are satisfied the figures are materially correct." The SGX FY2029 requirement specifies limited assurance. Reasonable assurance is more expensive and time-consuming, but may be demanded by institutional investors over time.
How do I prepare for sustainability assurance?
Start building your evidence trail as early as possible: (1) Establish an immutable document store for utility bills and source documents. (2) Document every emission factor used, including the version year. (3) Implement a human review gate with a named approver and timestamp for every data entry. (4) Maintain calculation workings from activity data to CO2e for every entry. (5) Conduct a pre-assurance gap review 12 to 18 months before your first assurance engagement to identify and fix weaknesses before the assurer does.

Build Your Assurance Pack Automatically — Starting Today

VerityOS is designed from the ground up for the assurance requirement. Its append-only hash-chained evidence vault stores every source document, emission factor application, and human approval event — automatically generating the methodology record and calculation chain your assurer will ask for. Start clean in FY2025 and arrive at FY2029 with four years of unbroken, audit-ready evidence.