Skip to content
Gaia
Open menu

Decarbonisation

How to Prepare for a CSRD Audit: A Step-by-Step Guide

By Harriet Mackie11 min read

A meeting to discuss corporate sustainability

Key Takeaways:

  • CSRD requires independent sign-off from an accredited auditor, starting on limited assurance before reasonable assurance becomes mandatory in later years.
  • Only large companies (1000+ employees, €450M+ turnover) must comply, after the 2025 scope narrowing removed around 80% of previously in-scope companies.
  • A double materiality assessment (DMA) decides which of the 1,200+ ESRS data points actually need reporting in full.
  • Non-EU companies generating €450M+ within the EU must comply from 2029, the same year CSRD's third rollout wave begins, alongside connected frameworks like the EU Taxonomy Regulation and CSDDD.
  • Assurance providers must be accredited and registered with the relevant oversight body, and bringing them in early during data collection avoids last-minute surprises when the final report is being reviewed.


CSRD turned sustainability reporting from a nice-to-have into a legal obligation, complete with independent auditor sign-off and real consequences for getting it wrong. For companies now in scope, an unprepared audit means delays, corrections, and auditors flagging gaps that should have been caught months earlier.

Getting audit-ready really means building the data, governance, and evidence trail behind the report long before an auditor ever sees it. Our latest article breaks this down into 8 practical steps, from your first materiality assessment through to engaging an assurance provider, so nothing catches you out at the last minute.

What Is a CSRD Audit?

CSRD is the Corporate Sustainability Reporting Directive, made by the EU, and formally adopted in 2022.

The concept is simple: companies have looked at finances in such a rigorous way for decades. If we accord sustainability the same level of mandatory transparency, it forces accountability and makes room for tangible change.

How It Differs From a Financial Audit

Financial audits involve balance sheets, profits, losses, and have existed for over a century. 

Because of this they hold significant rigour, importance and legal weight, whereas sustainability auditing is fresh off the press and lacks social understanding.

CSRD applies the same principles to zoom into how a business affects people, planet, and supply chain.

Limited Assurance vs Reasonable Assurance

For good reason, CSRD made self-reporting illegal. All official conclusions must be signed off by an independent auditor and given their stamp of approval. 

Limited assurance involves the auditor spot-checking data, whereas reasonable assurance involves checking every single part thoroughly.

All companies that must report to CSRD start on limited assurance, with reasonable assurance mandatory in upcoming years.

Who Needs to Comply With CSRD?

Large Companies and Listed SMEs

CSRD is only mandatory for companies meeting their ‘large’ criteria: 1000+ employees plus €450M+ annual turnover.

The required scope was drastically narrowed in 2025, with it hitting companies too fast and being too expensive and burdensome. This removed around 80% of companies from needing to report.

Non-EU Companies With EU Operations

Non-EU companies must report to CSRD from 2029.

This is only if they generate €450M within the EU, such as through local subsidiaries, EU branches (either over €200M turnover), or simply by selling products into EU markets. 

While EU companies face the burden 4-5 years ahead of competitors, companies that report to frameworks like CSRD get a massive set up in terms of optimisation, budget cuts, future-aligned processes, and investor confidence. 

The CSRD Audit Timeline

Phased Rollout by Company Size

CSRD applies to larger, better-resourced companies first, so these more powerful giants can iron out processes, systems and workflows to make it easier for smaller companies to follow.

Criteria is outlined in revenue, employee size, turnover, and assets. While there are different timelines for different company scales, those that wait until the last second will struggle most with audit readiness.

Key Deadlines to Know

The rollout is organised in waves:

  • Wave 1 have had to report since 2025, the largest companies, already reporting under the older framework of NFRD (Non-Financial Reporting Directive).
  • Wave 2 reports from 2028, for the large EU companies hitting new thresholds. 
  • Wave 3 reports from 2029, for non-EU companies with major EU operations.

Understanding the ESRS Framework

What the European Sustainability Reporting Standards Require

The European Sustainability Reporting Standards (ESRS) is a rulebook within CSRD focusing on sustainability accounting standards.

ESRS makes it standardised and auditable, with 12 cross-sector standards across ESG with 1,200+ individual data points for rigorous reporting. 

Investors can easily compare two companies using the same reporting framework, and the standards leave small space for vague, green-washed claims.

Sector-Specific ESRS Standards

Sector-specific standards add reporting requirements specific to a range of industries from banks, manufacturing, retail or software. 

They’re currently being developed by EFRAG and have been delayed by the EU, instead prioritising the ESRS’s simplification to make CSRD more adoptable. 

Step 1: Assess Your Reporting Obligations

To gauge if you must report under CSRD, ask yourself these questions:

  • Am I based in the EU?
  • If not, do I generate more than €450M revenue within the EU?
  • Do I have an EU subsidiary or branch that triggers reporting requirements?
  • Do I exceed the employee and turnover thresholds?
  • When does my reporting obligation begin?
  • Am I reporting at company level, subsidiary level, or group level?
  • Has the 2025 Omnibus reform changed my obligations?

If yes, you can begin planning data collection and reporting.

Step 2: Set Up Governance and Assign Responsibilities

Building a Cross-Functional CSRD Task Force

CSRD needs data from various places from HR and procurement to finance and IT. 

This is why a cross-functional CSRD task force is instrumental in achieving smooth reporting, taking members from various departments to ensure all areas are covered and streamline processes.

Involving Senior Management and the Board

CSRD is a legal reporting obligation, leaving directors and senior leaders accountable.

Companies with more board ESG involvement report higher confidence in sustainability reporting.

Without someone senior taking responsibility, projects lose authority, momentum, and cross-department cooperation.

Embedding Sustainability Into Corporate Culture

Sustainability should be an everyday decision instead of an annual reporting exercise.

The goal of CSRD is to expose problem areas, and bring tangible change within a business’ buying, hiring, investing and planning decisions.

This could be procurement choosing sustainable suppliers, HR tracking diversity, or finance factoring climate into investment.

Step 3: Conduct a Double Materiality Assessment

Impact Materiality vs Financial Materiality

Frameworks like SECR focus on single materiality, or what impacts a company financially. Key examples are energy prices rising, fuel costs increasing, or extreme weather.

These factors feed directly into risk management strategy and can materially affect a company's balance sheet.

By expanding into double materiality, CSRD also considers what the company is affecting. This can then look like considering working conditions, deforestation, pollution, or wasteful packaging.

Rather than focusing only on the company, double materiality also considers the company’s impact on the world.

Using DMA Findings to Define Reporting Scope 

Only topics that come out "material" from the DMA get reported on in full, saving companies from having to report on over 1,200 data points.

All excursions must be professionally justified, else will be flagged by auditors. 

Breaking down these terms simply: 

  • Financial materiality = does this matter to our money?
  • Impact materiality = does this matter to the world?
  • Double materiality = we check both.

Step 4: Identify and Map Your ESG Data Sources

Internal Data Collection

Internal data collection means raiding what you already have. HR holds headcount, turnover, and training hours. Finance holds spend data, the backbone of emissions estimates. Procurement and ERP systems hold purchases and logistics: the raw material of Scope 3. The data isn't missing, it's scattered.

Value Chain and Supplier Data

Most of a company's footprint doesn't happen in-house, it happens in the supply chain. A BCG/CDP report found Scope 3 emissions 26 times greater than Scope 1 and 2 combined.

Suppliers rarely track data digitally, so companies are often left estimating instead of measuring.

Gaia's automated supplier engagement feature keeps that chasing in one place, and its data completion tool fills genuine gaps with a reasoned estimate rather than a guess, accurate to within 80%.

Step 5: Build Robust Documentation and an Audit Trail

What Auditors Will Want to See

Auditors want a paper trail, not just a final number. Every disclosure needs to show where the data came from, how it was calculated, and who signed it off.

Version history matters too. If a number changes between drafts, auditors expect a clear reason why.

Establishing an Internal Control System

An internal control system is really just proof that someone checked the work: assigned data owners, a review step before anything gets signed off, and one actual system tracking it, rather than a scatter of spreadsheets emailed between departments and hoped for the best.

Whatever a double materiality assessment turns up, it's the internal controls sitting underneath it that actually protect data quality once multiple departments start feeding into the same repor

Step 6: Conduct a Gap Analysis

Prioritising Gaps by Strategic Importance

Not every gap in a gap analysis carries equal weight. Some sit inside your material topics: the ones your DMA already flagged as reportable, so auditors go through those first.

Others simply aren't urgent yet. A missing spreadsheet is a quick fix. Years of missing supplier data usually isn't.

Setting a Timeline for Closing Gaps

Timelines should work backwards from your wave deadline, not forwards from today. Wave 2 companies reporting from 2028 need fixes locked in a year before that, not a scramble in Q4 2027.

Supplier data gaps need lead time: chasing years of missing figures from external companies isn't a two-week task.

Step 7: Engage Your Assurance Provider Early

How to Choose a Qualified Auditor

Not every accountant can sign off on CSRD assurance.

It has to be an accredited statutory auditor or an independent assurance provider registered with the relevant oversight body, and ideally one with experience in your actual sector, since an auditor used to manufacturing won't necessarily know software-specific ESRS standards.

What Early Engagement Looks Like in Practice

Early engagement means the auditor is involved while data is still being collected, seeing weak evidence while there's still time to fix it, rather than being handed a finished report and asked to trust it.

That familiarity also cuts down on surprises later, since they already understand how the numbers were built.

Step 8: Structure Your Sustainability Disclosure

Organising Information Around ESRS Data Points

So how do you lay the report out? Not by department, not by whoever finished their section first. Every disclosure should map straight onto an ESRS data point, so an auditor, or an investor scanning ten reports in a row, can find exactly what they're looking for in seconds, not pages.

Well-structured sustainability disclosures are what separate genuine ESG reporting from a box-ticking exercise nobody outside the company can actually verify.

Digital Tagging and Machine-Readable Reporting

Machine-readable just means tagged data, not a PDF someone has to read line by line. CSRD reports use XBRL tagging, specifically iXBRL, so software can pull out exact figures automatically.

Why bother? Because regulators and investors comparing thousands of reports can't manually extract numbers from every single one.

Limited Assurance in Practice: What the Audit Process Looks Like

So what does limited assurance actually involve? Auditors sample a chunk of your data, ask management questions, and check things look plausible, rather than substantiating every single figure with evidence.

The sign-off reflects this too. It won't say your report is accurate, just that nothing looked wrong.

Common Mistakes to Avoid in CSRD Audit Preparation

The biggest mistake? Treating the DMA as a box-tick instead of the thing that defines your entire report. Get materiality wrong and everything built on top of it needs redoing.

Second most common: starting data collection in the final quarter. Supplier data alone can take months to chase down properly.

Cost Considerations and Resourcing

Most CSRD budgets account for consultant and auditor fees but forget the internal cost, since the weeks your own finance and HR teams lose to data requests never actually show up as a line item.

The DMA and gap analysis alone can eat months before an auditor is even involved.

Gaia's document extraction tool cuts a chunk of that internal time, scanning invoices, spreadsheets and PDFs and calculating the emissions automatically instead of someone doing it by hand.

How CSRD Audit Readiness Connects to Other EU Regulations

EU Taxonomy Regulation

The EU Taxonomy Regulation isn't a separate audit, it's baked into the same CSRD report, since it defines exactly which activities count as environmentally sustainable, using six environmental objectives like climate mitigation and biodiversity.

Companies subject to CSRD must disclose what percentage of turnover, capex and opex aligns with it.

Corporate Sustainability Due Diligence Directive (CSDDD)

CSDDD gets confused with CSRD, but they ask different things: CSRD wants companies to report their impacts, while CSDDD requires them to actually identify, prevent and account for harm across their own operations and supply chain.

Ignore CSDDD, and you risk civil liability, not just a reporting gap.

The Strategic Case for Early CSRD Compliance

Reporting early means building processes and data systems on your own timeline, rather than scrambling once a wave deadline catches up with a much tighter one already set for you. 

It also reads well to investors and lenders, who increasingly expect the same confidence in sustainability numbers as financial ones.

Tools and Software to Support CSRD Compliance

Spreadsheets get you through year one, barely, but CSRD's scale (12 standards, 1,200+ data points, XBRL tagging) makes manual tracking unsustainable fast.

Carbon management software like Gaia's automates data collection across Scope 1, 2 and 3, and turns it into audit-ready SECR and CSRD reports without an army of consultants.

More Information

https://www.bdo.com/insights/sustainability-and-esg/csrd-post-omnibus-revised-scope-and-requirements

https://www.efrag.org/en

https://www.theaustralian.com.au/business/cfo-journal/cfos-own-sustainability-reporting-heres-what-they-need-to-know/news-story/b70635e00c98341394fdfa5edfd8cb99?

https://gaiacompany.io/carbon-accounting-software/

https://gaiacompany.io/

FAQs\

What is a CSRD audit?
CSRD is the Corporate Sustainability Reporting Directive, an EU rule requiring companies to report on sustainability with the same rigour as financial reporting, signed off by an independent auditor.

What's the difference between limited and reasonable assurance?
Limited assurance involves an auditor spot-checking data, while reasonable assurance means checking every part thoroughly. All CSRD companies start on limited assurance, with reasonable assurance becoming mandatory in later years.

Who needs to comply with CSRD?
Large companies meeting the €450M+ turnover and 1000+ employee thresholds, plus non-EU companies generating €450M+ within the EU, reporting from 2029.

What is a double materiality assessment?
A DMA scores each ESG topic on both financial materiality (does it affect the company's money) and impact materiality (does the company affect the world). Only topics that score as "material" get reported on in full.

What happens if a company gets its DMA wrong?
Auditors will flag unjustified exclusions. Since the DMA defines the entire reporting scope, getting it wrong means redoing everything built on top of it.

Does CSRD apply to UK companies?
Only if they have significant EU operations, such as an EU subsidiary or branch generating over €450M in EU revenue, or shares listed on an EU stock exchange.

\