Quick Read
Audit committees typically oversee financial audits through structured quarterly agendas and private sessions with external auditors, yet most organizations relegate non-financial assurance to a single annual agenda item despite its growing materiality. This whitepaper outlines a four-quarter non-financial audit committee agenda with standing items, required competencies, and critically, a private session between the audit committee, assurance provider, and certification body—excluding management—that would fundamentally strengthen governance. The paper argues that non-financial assurance belongs in the audit committee (not a separate sustainability committee) to ensure independent challenge of management's assertions, mirroring the financial audit model.
IN BRIEF
Non-financial assurance is an audit committee matter, not a sustainability committee matter. Where a separate ESG or sustainability committee exists, it should own strategy and performance; the audit committee should own assurance, controls and independence.
The audit committee's private session with the external auditor, held with management excluded, is standard practice in financial audit. No equivalent session with the assurance provider or certification body exists in most organisations.
Independence confirmation must occur at plan approval, before any engagement letter is signed, in writing, covering the current and three preceding years.
The materiality determination should be reviewed by the audit committee mid-cycle, while the evidence supporting it is still obtainable, rather than after the reporting period has closed.
An audit committee that cannot ask what a limited assurance conclusion does not cover is not overseeing the engagement. It is receiving it.
Executive summary
Audit committees are accustomed to a well-defined set of financial matters: the audit plan, the auditor's independence, the management letter, the significant judgements, the going concern assessment, and — most importantly and least visibly — a private session with the external auditor from which management is excluded.
The non-financial equivalent, in most organisations, consists of a single agenda item once a year, four minutes long, at which a clean limited assurance conclusion is noted.
THE GOVERNING PRINCIPLE
If a matter can produce a public misstatement, a regulatory action, a covenant breach or a litigation exposure, it belongs on the audit committee agenda, not the sustainability committee agenda. Sustainability committees oversee performance. Audit committees oversee whether what is said about performance is true.
This paper sets out a four-quarter agenda, the standing items that belong on every meeting, the competence that oversight requires, and the meeting that would change more than all of it combined: a private session with the assurance provider and the certification body, with management excluded, at which one question is asked.
1. Where non-financial assurance belongs
Many organisations have established a sustainability or ESG committee, and have quietly routed assurance matters to it. The reasoning is sensible on its face: the committee understands the subject matter, and the audit committee's agenda is already full.
The reasoning is wrong, and it is wrong for a reason that generalises.
A sustainability committee is populated by directors selected for their interest in and commitment to the sustainability agenda. It oversees the programme. Its natural relationship with the sustainability function is supportive. This is precisely the right composition for overseeing strategy and performance, and precisely the wrong composition for overseeing whether the function's assertions can be evidenced.
You do not ask the people who championed the programme to determine whether its numbers are true. This is not a comment on their integrity. It is the reason audit committees exist. | |||
|---|---|---|---|
Matter | Sustainability committee | Audit committee | |
Strategy and targets | Owns | Notes | |
Performance against targets | Owns | Notes | |
Materiality determination | Consulted | Owns — it determines what must be disclosed and is within assurance scope | |
Assurance and certification plan | Notes | Approves | |
Provider independence | — | Owns, and confirms in writing before appointment | |
Internal controls over sustainability reporting | — | Owns | |
Assurance findings and remediation | Notes | Owns | |
Connected information with the financial statements | — | Owns | |
Where both committees exist, the recommendation is a standing cross-membership: at least one director sits on both, and the audit committee chair receives the sustainability committee's papers.
2. The four-quarter agenda

Figure 1 — The non-financial audit committee year, and the standing item that does not exist anywhere.
Q1 — After the reporting cycle
Assurance and certification findings, in full, with management's response and a named owner and date for each remediation item.
The coverage map: which domains of the non-financial audit universe were independently tested in the period, which were not, and who decided.
Reconciliation of the ESG ratings submission to the assured sustainability statement. Where the emissions figures, incident counts or policy descriptions differ, one of the two documents is wrong and one of them has been assured.
Q2 — Plan and independence
Approve the non-financial audit plan for the cycle, including the dependency sequence: certification before verification before assurance.
Approve the audit universe and its risk scoring, and note every domain scored above threshold that is not in the plan, with the reason.
Confirm independence for every provider in the plan, in writing, covering the current and three preceding years, before any engagement letter is signed.
The third item is the one most often deferred, and deferring it is the same as omitting it. Once an engagement is under way the committee's practical options are to accept the conflict or to lose a cycle.
Q3 — Mid-cycle, while the evidence is still live
The double materiality determination: which matters were considered, which were rejected, on what evidence, and who approved. Under ISSA 5000 the practitioner must evaluate whether significant matters were overlooked; this is the committee's opportunity to ask the same question while something can still be done about the answer.
Controls testing status for the current period. Not whether controls are described, but whether they operated and whether anybody tested that they did.
Value chain: which counterparties are protected undertakings under the Omnibus I value chain cap, and what proportion of Scope 3 and supplier social data now rests on estimation rather than corroboration.
WHY Q3 IS THE MEETING THAT MATTERS
Everything discussed in Q1 is history. Everything discussed in Q3 can still be fixed. A committee that reviews the materiality determination only after publication has reviewed a decision, not governed it.
Q4 — Before publication
Connected information: the boundary between the financial statements and the sustainability statement, and who owns it. Climate assumptions in impairment testing against the published transition plan; provisions against disclosed incidents; consolidation boundaries.
Narrative substantiation: every assertion of progress, leadership or improvement in the sustainability statement, and the evidence for it. Narrative is within assurance scope and is the raw material of green claims enforcement.
Estimates and omissions to be disclosed: which figures are estimates and of what character, which value chain data could not be corroborated, and where the assurance scope ended.
3. Standing items, every meeting
Changes to the non-financial audit universe. New obligations acquired since the last meeting: a customer contract containing a supply chain warranty, a lending facility with a sustainability-linked ratchet, a public net-zero commitment made in a press release. Each adds an assertion the organisation must be able to evidence. A new obligation that has not reached the map is a control failure, not an administrative oversight.
Any provider engaged since the last meeting, and its independence status. Including providers engaged by other budget holders through other procurement channels, which is how the advisory-assurance conflict enters the organisation unobserved.
Remediation status of open findings. With named individual owners and dates. A finding whose owner is a department is a finding nobody is remediating.
Public non-financial commitments made since the last meeting, and who approved them. Targets, claims, labels, statements in investor communications. These are assertions with legal consequence, and in most organisations they are approved by nobody in this room.
4. The private session
The audit committee's private session with the external financial auditor — management excluded, minuted separately, held at every meeting — is one of the oldest and most effective governance controls in existence. It works because it creates a channel through which an auditor can say something they would not say in front of the CFO, and because the CFO knows the channel exists.
Almost no audit committee holds an equivalent session with its sustainability assurance provider, its GHG verifier, or its certification body. The engagement is procured by management, reported by management, and presented by management, and the only person in the room who examined the evidence is not in the room.
Establish the session. Ask one question.
"What would you have raised if your scope had been wider?"
Then be quiet. In a limited assurance engagement the practitioner is not required to test the operating effectiveness of controls, and is therefore in possession of a great deal of information about which controls they chose not to test, and why.
None of it appears in the conclusion. All of it is available on request, to somebody with the standing to ask, in a room without management.
Three supplementary questions, for the same session.
Who determined the scope of this engagement, and did you have the mandate to challenge it?
Was there any point in the engagement at which you were asked, formally or informally, to reconsider a finding?
If you had been engaged to provide reasonable assurance rather than limited assurance, what would you have needed that this organisation does not currently have?
The most valuable information about an assurance engagement is held by the practitioner, is not in the report, and has never been requested.
5. The competence requirement
An audit committee that does not understand financial accounting cannot oversee a financial audit. The principle carries across without modification, and it is uncomfortable, because it implies that a committee overseeing sustainability assurance must understand something about sustainability assurance.
It does not require that directors become sustainability experts. It requires sufficient literacy to ask the questions in this paper and to recognise an evasive answer. Concretely, the committee should collectively be able to state:
A director should be able to say | Because |
|---|---|
What a limited assurance conclusion does and does not cover | It is a negative conclusion on a bounded scope, and in a limited engagement the practitioner is not required to test whether controls operated |
The difference between certification, verification and assurance | They are governed by different accreditation regimes, answer different questions, and confer different credibility. A certificate is not an assurance opinion. |
What double materiality is, and that its determination is within assurance scope | Under ISSA 5000 the practitioner must evaluate whether significant matters were overlooked by the entity's own assessment |
Which of the organisation's non-financial obligations were independently tested this year | This is the coverage question, and it is the diagnostic for whether a function exists |
What the Omnibus I directive changed for this organisation | Scope, the permanence of limited assurance, and the value chain cap on evidence |
A REASONABLE STANDARD
At least one member of the audit committee should have direct experience of a non-financial assurance or certification engagement, in the same way that at least one member is expected to have recent and relevant financial experience. Most boards do not have such a person, and most have never noticed.
6. What a good non-financial audit committee paper looks like
One paper, each cycle, replacing at least three existing ones. Six sections, none longer than a page.
The universe and its coverage: one page, colour-coded, showing what was tested, what was not, and when each was last examined.
Findings and remediation: open items, named owners, dates, and the items whose dates have moved more than once.
The plan: next cycle's sequence, with the dependency visible, and the domains scored above threshold that are not in it.
Independence: every provider, its accreditation, its advisory relationship with the group, and the advisory-to-assurance fee ratio.
New obligations: everything added to the universe since the last paper, and how it was discovered.
The connected-information boundary: the matters on which the financial auditor and the assurance provider both touched, and who owns the reconciliation.
If the paper cannot be written, the function described in Paper 1 of this series does not exist. That is a finding, and the first meeting at which it is stated is the first meeting of the function.
Questions this paper answers
Should non-financial assurance sit with the audit committee or the sustainability committee?
The audit committee. A sustainability committee is composed of directors selected for their commitment to the sustainability agenda, and its natural relationship with the sustainability function is supportive — the right composition for overseeing strategy and performance, and the wrong composition for determining whether the function's assertions can be evidenced. The sustainability committee should own strategy, targets and performance. The audit committee should own the materiality determination, the assurance plan, provider independence, internal controls over sustainability reporting, assurance findings, and connected information.
What is the private session, and why does it matter?
A meeting between the audit committee and the external auditor with management excluded, minuted separately. It is standard practice in financial audit and has been for decades, because it creates a channel through which the auditor can say something they would not say in front of the CFO. Almost no audit committee holds an equivalent session with its sustainability assurance provider, GHG verifier or certification body — so the only person in the room who examined the evidence is not in the room.
What single question should an audit committee ask its assurance provider in private?
What would you have raised if your scope had been wider? In a limited assurance engagement the practitioner is not required to test the operating effectiveness of controls, and is therefore in possession of substantial information about which controls they chose not to test and why. None of it appears in the conclusion. All of it is available on request, to somebody with the standing to ask.
When should the materiality determination be reviewed?
Mid-cycle, while the evidence supporting it is still obtainable. Under ISSA 5000 the practitioner must evaluate whether significant sustainability matters were overlooked by the entity's own assessment. A committee that reviews the determination only after publication has reviewed a decision rather than governed it.
When should provider independence be confirmed?
At plan approval, in writing, covering the current and three preceding years, before any engagement letter is signed. Once an engagement is under way the committee's practical options are to accept the conflict or to lose a cycle. The confirmation should also capture providers engaged by other budget holders through other procurement channels, which is how the advisory-assurance conflict typically enters an organisation unobserved.
What should appear on every audit committee agenda covering non-financial matters?
Four standing items. Changes to the non-financial audit universe — new contracts, covenants, certificates and public commitments acquired since the last meeting. Any provider engaged since the last meeting, and its independence status. Remediation status of open findings, with named individual owners and dates. And every public non-financial commitment made since the last meeting, together with who approved it.
What competence does non-financial oversight require?
Not sustainability expertise, but sufficient literacy to ask the right questions and recognise an evasive answer. The committee should collectively be able to state what a limited assurance conclusion does and does not cover; the difference between certification, verification and assurance; what double materiality is and that its determination is within assurance scope; which of the organisation's non-financial obligations were independently tested this year; and what the Omnibus I directive changed for this organisation.
References and sources
IAASB, ISSA 5000, General Requirements for Sustainability Assurance Engagements; effective for periods beginning on or after 15 December 2026. Requires the practitioner to evaluate the entity's materiality process where the applicable framework requires double materiality.
IESBA, International Ethics Standards for Sustainability Assurance (including International Independence Standards), issued January 2025; generally effective from 15 December 2026.
Directive (EU) 2026/470 (the Omnibus I directive), in force 18 March 2026 — narrowing CSRD scope, confirming limited assurance as the permanent requirement, and introducing the value chain cap.
Regulation (EU) No 537/2014 on statutory audit of public-interest entities, and Directive 2006/43/EC as amended — the audit committee's relationship with the statutory auditor, including the additional report to the audit committee.
ISO/IEC 17021-1:2015 and ISO/IEC 17029:2019 — impartiality requirements for certification bodies and validation and verification bodies.
Speeki, The Non-Financial Audit Function (Series 1, Paper 01); The Plan That Survives the Deadline (Series 1, Paper 02); The Non-Financial Audit Universe (Series 1, Paper 03); Can They Afford to Fail You? (Series 1, Paper 04), July 2026.
About Speeki
Speeki is an accredited ESG assurance and certification body operating in more than 100 countries. Speeki provides management system certification, verification and validation, and sustainability assurance. Speeki does not provide consulting services. Its independence is structural.
For current details of Speeki's accreditations and their scope, please refer to speeki.com.
© 2026 Speeki. This paper is provided for general information and does not constitute legal, accounting or assurance advice.