Preprint
Article

This version is not peer-reviewed.

Artificial Intelligence in Sustainability Assurance: Accounting Challenges, Audit Risks and a Conceptual Framework for ESG Verification

A peer-reviewed version of this preprint was published in:
Accounting and Auditing 2026, 2(3), 15. https://doi.org/10.3390/accountaudit2030015

Submitted:

16 July 2026

Posted:

16 July 2026

You are already at the latest version

Abstract
This conceptual article examines how artificial intelligence can support sustainability assurance in the transition from voluntary ESG disclosure to regulated, assurance-oriented sustainability reporting. The study is situated in the context of the Corporate Sustainability Reporting Directive, the European Sustainability Reporting Standards, ISSA 5000 and the EU Artificial Intelligence Act. It argues that AI can strengthen ESG verification by supporting disclosure identification, ESRS mapping, anomaly detection, consistency checks, greenwashing risk screening, external data triangulation and working-paper documentation. At the same time, AI introduces specific assurance risks, including data quality risk, reliability and hallucination risk, explainability risk, bias risk, overreliance risk, documentation risk, confidentiality risk, boundary and materiality risk, and accountability risk. The article develops a Responsible AI-Assisted Sustainability Assurance Framework that integrates ESG data inputs, AI analytical procedures, assurance risk assessment, human professional judgement, validation controls and documented assurance outputs. The central conclusion is that AI should be used as an analytical support layer within a human-in-the-loop assurance process, not as an autonomous source of assurance conclusions.
Keywords: 
;  ;  ;  ;  ;  ;  ;  ;  ;  

1. Introduction

Corporate reporting is entering a new stage in which sustainability information is no longer treated as a voluntary narrative supplement to financial statements, but as a regulated, decision-useful and assurance-oriented component of corporate accountability. In the European Union, this transformation is driven primarily by Directive (EU) 2022/2464, known as the Corporate Sustainability Reporting Directive (CSRD), which amends the Accounting Directive, the Transparency Directive, the Audit Directive and the Audit Regulation in order to strengthen the reporting and assurance of sustainability information [1]. The adoption of the first set of European Sustainability Reporting Standards (ESRS) through Commission Delegated Regulation (EU) 2023/2772 further reinforces this shift by requiring undertakings to disclose sustainability information according to a structured logic covering governance, strategy, impact, risk and opportunity management, and metrics and targets [2].
The growing regulatory importance of sustainability reporting has direct conse-quences for accounting systems and assurance practices. Sustainability information increasingly includes greenhouse gas emissions, energy consumption, water use, waste, biodiversity impacts, workforce indicators, social policies, governance practices, value-chain information, transition plans and forward-looking targets. Unlike traditional financial information, these data are often heterogeneous, partly qualitative, estimated, externally sourced and methodologically uncertain. As a result, the credibility of sustainability reporting depends not only on the presence of disclosures, but also on the quality of the underlying data infrastructure, internal controls, documentation, trace-ability and assurance procedures.
The assurance dimension of this transformation is particularly important. ISSA 5000, General Requirements for Sustainability Assurance Engagements, provides a global principles-based standard intended to strengthen the credibility of sustainability disclosures and support consistent sustainability assurance engagements across different sustainability topics, reporting frameworks and assurance practitioners [3]. However, sustainability assurance is more complex than the audit of financial statements because assurance providers must evaluate non-financial metrics, estimates, scientific assumptions, value-chain data, scenario analysis and narrative explanations.
Previous research has shown that sustainability assurance is shaped by institutional pressures, credibility concerns and the quality of corporate reporting. Simnett, Vanstraelen and Chua demonstrate that the demand for assurance on sustainability reports varies across countries and industries and is associated with credibility-enhancing incentives [4]. Cohen and Simnett identify sustainability assurance as a major research agenda for auditing because it extends assurance beyond traditional financial information [5]. Farooq and de Villiers emphasise the need for further re-search on assurance providers, assurance quality and the sustainability assurance market [6]. Boiral, Heras-Saizarbitoria and Brotherton show that assurance providers face difficulties when sustainability reports contain selective disclosures, unclear boundaries and weak methodological explanations [7].
Artificial intelligence may provide part of the answer to the practical problem of ESG verification. AI-based tools can support sustainability assurance by processing large volumes of structured and unstructured data, identifying sustainability-related disclosures, comparing information across reports, detecting inconsistencies, mapping disclosures to reporting standards and supporting preliminary risk assessment. The broader auditing literature has already recognised that artificial intelligence, data analytics and automation can transform audit evidence collection, audit planning and audit judgement [8,9,10,11].
At the same time, the use of AI in sustainability assurance creates new audit risks. AI tools may produce inaccurate, incomplete or misleading outputs, especially when used on poor-quality or ambiguous ESG data. Many AI systems operate as black boxes, reducing explainability and making it difficult for auditors to document how results were produced. AI-generated outputs may create overreliance risk if assurance providers accept them without sufficient professional scepticism. Regulation (EU) 2024/1689, the EU Artificial Intelligence Act, reflects a broader regulatory movement towards risk-based AI governance, transparency, accountability and human oversight [12].
The aim of this article is to examine the accounting challenges and audit risks as-sociated with the use of artificial intelligence in sustainability assurance and to pro-pose a conceptual framework for responsible AI-assisted ESG verification. The article addresses three research questions: RQ1. How can artificial intelligence support sustainability assurance in the CSRD/ESRS reporting environment? RQ2. What accounting and audit risks arise when AI is used to analyse, verify or support assurance over ESG information? RQ3. What conceptual framework can guide the responsible use of AI in sustainability assurance while preserving audit quality, professional judgement and evidence reliability?
Table 1 provides a concise overview of the key regulatory and professional documents that frame this transition, showing how each instrument increases the need for reliable, traceable and assurance-ready sustainability information.
Figure 1 illustrates how sustainability reports and ESG data are processed by AI-assisted analytical procedures, translated into audit-risk signals, evaluated through human professional judgement, validated and documented, and finally transformed into an assurance conclusion.

2. Sustainability Assurance and the Need for Evidence-Ready ESG Information

2.1. From Sustainability Reporting to Sustainability Assurance

The development of sustainability assurance reflects a broader transformation in corporate reporting. Sustainability information is increasingly expected to perform a function similar to financial reporting: to provide reliable, comparable and decision-useful information for investors, creditors, regulators and other stakeholders. Under the CSRD, sustainability disclosures become part of the regulated corporate reporting and accountability system [1].
The ESRS reinforce this assurance orientation by requiring companies to disclose information on governance, strategy, impact, risk and opportunity management, and metrics and targets. This structure moves sustainability reporting away from broad ESG narratives and towards more systematic, standardised and verifiable information [2]. Sustainability assurance becomes necessary because users need confidence that disclosed data are not merely selective, symbolic or promotional.
Table 2 summarises this transition by distinguishing four stages in the evolution from voluntary ESG disclosure to digitally structured and assurance-oriented sustainability reporting.

2.2. The Nature of Sustainability Assurance

Sustainability assurance differs from the traditional audit of financial statements in several important respects. Financial statement audits are based on relatively mature accounting systems, established recognition and measurement principles, long-standing audit methodologies and well-developed internal control procedures. By contrast, sustainability assurance often concerns information that is partly quantitative, partly qualitative, forward-looking, estimated, value-chain-dependent and based on different scientific, managerial or operational assumptions.
Assurance providers need to evaluate whether reported sustainability information is supported by sufficient appropriate evidence, whether reporting boundaries are clear, whether methodologies are transparent, whether assumptions are reasonable, whether internal controls are adequate and whether disclosures are consistent with the applicable reporting criteria [3,13]. A key issue is that sustainability assurance engagements may cover greenhouse gas emissions, energy consumption, waste, water use, workforce indicators, diversity metrics, human rights policies, anti-corruption procedures, transition plans, biodiversity impacts and value-chain disclosures.
Figure 2 presents sustainability assurance as a credibility mechanism that connects sustainability activities, ESG data collection, internal controls, reporting procedures and the final assurance conclusion.

2.3. Why Evidence-Ready ESG Information Matters

Evidence-ready ESG information may be understood as sustainability information that is sufficiently specific, measurable, documented, traceable and methodologically transparent to support assurance procedures. Information is not assurance-ready simply because it is disclosed. It becomes assurance-ready when an independent practitioner can test it, compare it, recalculate it, trace it to source documents and evaluate it against suitable criteria.
This distinction is important because sustainability reports often contain extensive narrative information. Companies may describe commitments, strategies, values, stakeholder engagement processes and sustainability ambitions. However, such narratives are difficult to assure if they are not linked to measurable indicators, reporting periods, baselines, methodologies and evidence. Hummel and Schlick show that sustainability disclosure quality is more informative when it contains hard quantitative information rather than vague narrative statements [14].
Table 3 identifies the main characteristics of evidence-ready ESG information and contrasts weak narrative disclosures with disclosures that are more suitable for assurance procedures.

2.4. Reporting Quality, Greenwashing and Assurance Risk

The need for evidence-ready ESG information is connected with the risk of greenwashing. Sustainability disclosure can be used to communicate responsible behaviour, but it can also be used symbolically to manage legitimacy and stakeholder perceptions. Deegan argues that social and environmental disclosures may have a legitimising effect, which means that the existence of disclosure does not automatically indicate substantive accountability [15].
If sustainability reports contain selective information, vague claims or unsupported commitments, assurance procedures become more difficult and assurance risk increases. Boiral et al. show that sustainability reports may suffer from selective disclosure, unclear boundaries and insufficient methodological explanations [7]. Sustainability assurance therefore depends on the interaction between reporting quality and audit evidence.

2.5. Accounting Systems as the Foundation of Assurance-Ready ESG Data

Although sustainability reporting is often labelled non-financial reporting, its assurance requires accounting-like discipline. Companies need systems capable of capturing, classifying, aggregating, validating and documenting ESG data. This is particularly important under the CSRD/ESRS framework, where sustainability information must be connected with governance, strategy, impacts, risks, opportunities, policies, actions, targets and metrics [1,2].
Accounting systems traditionally provide audit trails, documentation, internal control, periodisation, consistency and responsibility for reported information. These principles are now increasingly relevant for ESG data. Carbon accounting requires clear organisational boundaries, emission sources, calculation methods and emission factors. Workforce reporting requires consistent definitions, reliable HR data and clear reporting periods. Supply-chain sustainability information requires documentation of data sources, supplier evidence and estimation methods.
Table 4 translates the requirements for evidence-ready ESG information into accounting-system equivalents and shows why sustainability assurance increasingly depends on accounting-like data infrastructure.

2.6. Digital Reporting and Machine-Readable Sustainability Information

The movement towards evidence-ready ESG information is supported by digital reporting. The ESRS XBRL taxonomy enables tagging of sustainability disclosures in machine-readable XBRL format. Digital tagging can improve comparability, accessibility and systematic extraction of sustainability information, but it does not automatically guarantee assurance-ready reporting. If the underlying ESG data are poorly calculated or insufficiently documented, digital tagging may simply make weak information more visible. This is where AI becomes relevant: AI tools can process machine-readable and unstructured sustainability information, identify inconsistencies, compare disclosures and support risk assessment, provided that the underlying information is sufficiently evidence-ready.
Figure 3 illustrates that AI-assisted assurance depends on a sequence of prior conditions: ESG data quality, documentation, traceability and machine-readable reporting. Without these conditions, AI may increase the speed of analysis, but not necessarily the reliability of assurance evidence.

3. Artificial Intelligence in Accounting and Auditing

3.1. From Digital Accounting to AI-Supported Assurance

Artificial intelligence is becoming an important component of the broader digital transformation of accounting and auditing. Enterprise resource planning systems, cloud accounting platforms, robotic process automation, big data analytics and ma-chine-readable reporting have created an environment in which accounting information is generated, stored and analysed in digital form. Vasarhelyi, Kogan and Tuttle argue that big data changes accounting by expanding the sources, volume and analytical potential of accounting-related information [16].
In auditing, this transformation has shifted attention from traditional sample-based testing towards data-driven, analytics-supported and potentially continuous forms of assurance. Appelbaum, Kogan and Vasarhelyi show that big data and analytics create new research and practice needs for modern audit engagements because audit evidence can now include both traditional accounting records and broader forms of structured and unstructured information [8]. AI builds on this development by enabling pattern recognition, classification, prediction, anomaly detection and natural language processing.
Figure 4 illustrates the gradual evolution from digital accounting systems and audit analytics towards AI-supported audit procedures and, ultimately, AI-assisted sustainability assurance.

3.2. Main AI Technologies Relevant to Accounting and Auditing

Artificial intelligence is not a single technology. In accounting and auditing, it includes a group of methods and tools that can support data processing, decision support and assurance procedures. The most relevant technologies include machine learning, natural language processing, expert systems, anomaly detection, robotic process automation, predictive analytics and generative AI. These technologies can improve the scope and efficiency of audit work, but their adoption also changes the nature of auditor judgement [9,10,11].
Table 5 summarises the main AI-related technologies relevant to accounting and auditing and shows how each technology may support both accounting information systems and assurance procedures.

3.3. AI in Accounting Information Systems

Accounting information systems are a natural environment for the application of AI because they contain structured, semi-structured and unstructured data related to transactions, controls, documents, contracts, management reports and external information. AI can automate transaction classification, identify inconsistencies, support reconciliations, detect duplicate entries, extract data from invoices and contracts, and improve internal reporting.
The contribution of AI is not limited to efficiency. It can also support accounting quality by improving data validation, exception reporting and the identification of weak control points. For example, AI-based tools may detect unusual transaction patterns, flag missing or inconsistent documentation, identify duplicate supplier invoices, support automated reconciliations and assist management in monitoring exceptions across large volumes of accounting data. In this sense, AI can strengthen the analytical capacity of accounting information systems and improve the timeliness of internal reporting.
However, the integration of AI into accounting information systems also creates new control and governance challenges. If the underlying accounting data are incomplete, inaccurate or inconsistently classified, AI tools may amplify rather than correct existing weaknesses. Model risk may arise when AI systems produce inappropriate classifications, predictions or risk scores. Explainability risk is also important because accounting decisions must be traceable, justifiable and reviewable. In addition, AI tools may expand the digital attack surface of accounting systems and create cybersecurity and confidentiality risks. Responsibility may also become blurred when automated outputs influence accounting decisions without clear human approval or documentation [12].
Therefore, AI-supported accounting information systems require strong data governance, clear responsibility for automated outputs, documented validation procedures, access controls and integration with internal control mechanisms. AI should not be treated as a substitute for accounting judgement or control discipline, but as an analytical layer that can improve accounting information quality when embedded in a well-governed accounting system.

3.4. AI in External Auditing

External auditing has been one of the most discussed areas for AI application. AI can support audit planning, risk assessment, substantive procedures, analytical procedures, fraud detection, journal entry testing, document review and working-paper preparation. These applications are especially relevant in audit environments characterised by large transaction volumes, complex digital systems and growing expectations for more comprehensive evidence analysis. Gepp et al. review the use of big data techniques in auditing and identify opportunities for applying advanced analytical methods in audit research and practice [17].
AI-based audit tools can extend the scope of audit procedures by processing entire populations of transactions rather than relying only on sample-based testing. They may identify unusual patterns, detect outliers, classify documents, compare information across systems and generate risk signals for further auditor attention. In this way, AI can improve the efficiency and analytical depth of audit engagements. However, these benefits depend on the quality of the input data, the appropriateness of the model and the auditor’s ability to interpret the results in the context of the engagement.
AI does not remove the auditor’s responsibility to obtain sufficient appropriate audit evidence. ISA 315 requires auditors to identify and assess risks of material misstatement, while ISA 500 requires auditors to obtain sufficient appropriate audit evidence [13,18]. Therefore, AI-supported audit procedures should be understood as analytical support mechanisms rather than autonomous sources of audit conclusions. The auditor remains responsible for determining whether AI-generated outputs are relevant, reliable and sufficient for the audit objective.
Figure 5 summarises this logic by presenting AI-supported auditing as a workflow in which client data and documents are processed through AI-based extraction, classification and risk analysis, but the final interpretation remains dependent on auditor judgement, additional procedures and documented evidence.

3.5. AI, Audit Evidence and Professional Judgement

The relationship between AI and audit evidence is one of the most important issues for modern auditing. AI can help auditors obtain, organise and analyse information, but it also raises questions about the reliability, relevance and sufficiency of AI-generated outputs. Sutton, Holt and Arnold argue that AI research remains relevant for accounting because intelligent systems continue to support decision-making even when they are embedded within broader systems rather than presented as stand-alone expert systems [19].
For auditing, this means that AI may become less visible as a separate tool and more embedded within audit platforms, documentation systems and analytical procedures. This creates a new challenge for audit quality: auditors must understand not only the client’s information systems, but also the role that AI tools play in generating audit-relevant outputs. A risk score, anomaly list, document classification or AI-generated summary may support the audit process, but it should not automatically be treated as audit evidence without further evaluation.
Different AI outputs require different forms of auditor response. Anomaly lists should be tested against source records and assessed for false positives. AI-generated summaries should be compared with the original documents to ensure that relevant information has not been omitted or distorted. Risk scores require an assessment of model logic, input data, assumptions and thresholds. Classification results should be validated against predefined criteria, while generated working-paper drafts must be reviewed, corrected and formally approved by the auditor before being included in the audit file.
The central issue is therefore not whether AI can support audit evidence collection, but how auditors evaluate the evidential status of AI-supported outputs. Professional judgement remains essential because audit evidence is not only a matter of volume or automation. It also requires relevance, reliability, sufficiency, appropriateness and connection to the assessed risks. AI can help auditors identify where to look, what to test and which areas may require further attention, but the auditor must decide whether the obtained evidence supports the audit conclusion.
This is particularly important in sustainability assurance, where data may be estimated, qualitative, value-chain-dependent or methodologically uncertain. In such cases, AI may be useful for identifying inconsistencies, missing information or unusual patterns, but it cannot replace professional scepticism, materiality assessment or the evaluation of management assumptions. AI-supported audit evidence must therefore be embedded in a human-in-the-loop process in which the auditor verifies, challenges and documents the use of AI-generated outputs.

3.6. Continuous Auditing and Real-Time Assurance

AI also supports the development of continuous auditing and continuous assurance. Traditional auditing is usually periodic and retrospective, while continuous auditing aims to monitor transactions, controls and risks closer to real time. This development is closely connected with digital accounting systems, automated controls, cloud platforms, data analytics and machine-readable reporting. As organisational data become more integrated and accessible, audit procedures can increasingly move from isolated year-end testing towards more frequent monitoring of risks and exceptions.
For sustainability assurance, this idea is especially promising. ESG data such as energy use, greenhouse gas emissions, waste, water consumption, workforce indicators, occupational health and safety data and supplier-related information may increasingly be collected through digital systems, sensors, enterprise platforms and external databases. AI can support the monitoring of such information by identifying unusual trends, missing values, inconsistent units, unexplained fluctuations or contradictions between narrative disclosures and quantitative indicators.
However, continuous assurance should not be understood as full automation of audit judgement. Real-time or near-real-time monitoring can generate useful alerts, but these alerts still require interpretation. A sudden decrease in emissions, for example, may reflect genuine operational improvement, a methodological change, a boundary adjustment or missing data. Similarly, an unusual workforce indicator may result from organisational restructuring, reporting inconsistency or classification error. AI can identify the signal, but the auditor must evaluate its meaning.
Continuous assurance therefore depends not only on advanced technologies, but also on data quality, control design, system integration, governance and professional oversight. Companies need reliable source systems, clear data ownership, documented methodologies, access controls and audit trails. Assurance providers need procedures for validating AI outputs, documenting their use and deciding when additional evidence is required. Without these conditions, continuous monitoring may increase the speed of analysis without improving the reliability of assurance.
The progression from periodic audit to AI-supported continuous assurance is therefore best understood as a gradual development. Audit practice moves from retrospective testing, through data analytics and automated monitoring, towards more continuous and risk-sensitive assurance. In the context of sustainability reporting, this progression creates the foundation for AI-assisted sustainability assurance, where ESG data, digital reporting, AI analysis and human professional judgement are combined to support more reliable and decision-useful sustainability information.

4. Opportunities of AI-Assisted Sustainability Assurance

4.1. The Emerging Role of AI in Sustainability Assurance

Artificial intelligence creates important opportunities for sustainability assurance because ESG information is usually more dispersed, heterogeneous and text-intensive than traditional financial accounting information. Sustainability assurance engagements may require the examination of annual reports, sustainability reports, non-financial statements, ESRS disclosures, greenhouse gas data, internal policies, supplier information, websites, press releases, regulatory databases and external datasets.
AI can support sustainability assurance by improving the speed, scale and consistency of document analysis, ESG data screening, anomaly detection, disclosure mapping and risk assessment. Li, Kim, Dai and Vasarhelyi specifically propose the use of AI technologies and exogenous data in ESG assurance and argue that AI can enhance the efficiency and effectiveness of ESG assurance by assessing extensive datasets throughout the assurance process [20]. This is particularly relevant in the CSRD/ESRS environment, where assurance providers need to evaluate not only whether sustainability information is disclosed, but also whether it is complete, traceable, consistent and supported by appropriate evidence.
The main contribution of AI is not that it replaces assurance judgement, but that it expands the analytical capacity of the assurance process. AI can help practitioners locate relevant disclosures, compare information across documents, detect unusual patterns, map corporate disclosures to ESRS requirements and identify areas where additional evidence may be required. In this sense, AI functions as an analytical support layer within the broader assurance process.
Figure 6 presents the general workflow of AI-assisted sustainability assurance. It shows that AI can support the transition from ESG reports and internal sustainability data to structured analysis, risk identification and assurance evidence, while the assurance conclusion remains dependent on auditor judgement and validation.

4.2. AI for ESG Disclosure Identification, ESRS Mapping and Evidence Location

One of the most immediate opportunities of AI-assisted sustainability assurance is the identification and location of relevant ESG disclosures. Sustainability information is often distributed across multiple sections of a report and across several corporate documents. Natural language processing, text mining and semantic search can support this task by identifying sustainability-related terms, extracting relevant paragraphs, detecting topic clusters and linking disclosures to specific ESG categories. For assurance purposes, this opportunity is significant because evidence location is a precondition for testing.
AI can also support the mapping of corporate disclosures to regulatory and standard-setting requirements. Under the ESRS, sustainability information is structured around disclosure requirements and topical standards. AI-assisted tools can classify disclosures according to ESRS-related categories, such as governance, strategy, impacts, risks and opportunities, policies, actions, targets and metrics. This can support preliminary gap analysis by identifying missing baselines, targets without measurable indicators, metrics without methodologies or material impacts not connected to policies and actions.
However, AI-supported disclosure mapping should not be treated as a final compliance assessment. ESRS alignment requires contextual interpretation, understanding of double materiality and professional judgement. AI can indicate where disclosures appear to correspond to specific ESRS categories, but assurance providers must validate whether the disclosure is complete, relevant, entity-specific and supported by evidence. Therefore, AI can improve the efficiency of disclosure identification and mapping, but it does not remove the need for professional assessment.

4.3. AI for Anomaly Detection, Consistency Checks and Greenwashing Risk Screening

A second major opportunity concerns anomaly detection and consistency checks. Sustainability reports often contain multi-year data on greenhouse gas emissions, energy consumption, water use, waste, workforce composition, accidents, training hours, diversity indicators and governance practices. AI can analyse these data for unusual changes, missing values, inconsistent units, restatements, unexplained fluctuations or contradictions between narrative and numerical disclosures.
For example, a significant decrease in reported emissions without a clear methodological explanation may indicate an operational improvement, but it may also reflect a boundary change, missing facilities or a change in calculation method. Similarly, a zero-accident rate in a high-risk sector may require additional procedures to assess definitions, reporting completeness and internal incident-reporting controls. AI can identify such unusual patterns, but assurance providers must investigate their meaning and determine whether additional evidence is necessary.
AI can also support greenwashing risk screening. ESG reports often combine hard quantitative indicators with soft narratives about commitments, values and future ambitions. AI can help identify promotional, vague or boilerplate language; compare narrative claims with quantitative indicators; analyse whether commitments are linked to measurable targets and timeframes; and compare corporate disclosures with external information. Nevertheless, AI produces risk flags rather than assurance conclusions. A potential greenwashing signal must be validated through source documents, external evidence and professional judgement.
This use of AI is particularly important because sustainability assurance is not concerned only with the existence of disclosure. It is concerned with whether disclosed information is balanced, evidence-based, methodologically transparent and not misleading. AI can therefore strengthen the risk assessment stage of the engagement by helping practitioners focus on areas where the credibility of sustainability information may be weaker.

4.4. AI for External Data Integration, Audit Planning and Documentation

Sustainability assurance often requires evidence beyond the company’s own report. External data may include industry benchmarks, regulatory databases, emission factor databases, media reports, NGO databases, supplier information, climate datasets and satellite or geospatial data. AI can help integrate and compare these sources with company disclosures, broadening the evidence base and supporting assurance risk assessment [20].
External data triangulation is especially useful when corporate disclosures depend on estimates, value-chain information or claims about environmental and social performance. For instance, AI can compare reported emission factors with recognised databases, identify controversies in media or regulatory sources, detect outliers compared with sector peers or support the review of supplier-related disclosures. However, external data must also be assessed for reliability, relevance and completeness. AI-assisted triangulation should therefore be used as a risk assessment and corroboration tool, not as a substitute for direct assurance evidence.
AI can also improve audit planning and documentation. By identifying high-risk areas, unusual ESG metrics, missing evidence and inconsistent disclosures, AI can help assurance providers prioritise testing and allocate resources more efficiently. Generative AI can support documentation by summarising long reports, preparing preliminary evidence matrices and drafting descriptions of procedures, provided that all outputs are reviewed, corrected and source-linked. More advanced applications may also support continuous monitoring of sustainability data, moving assurance from an annual document-review exercise towards a more dynamic process of monitoring indicators, exceptions and risk signals.
Table 6 summarises the main opportunities of AI-assisted sustainability assurance, the assurance benefit associated with each opportunity and the conditions required for responsible use.
Overall, AI-assisted sustainability assurance offers important opportunities to improve the scope, speed and risk sensitivity of ESG verification. Its greatest value lies in helping assurance providers process complex sustainability information, identify relevant evidence, detect inconsistencies and focus professional attention on higher-risk areas. However, these opportunities depend on data quality, transparent methodologies, source-linked outputs, human validation and robust documentation. AI should therefore be understood as an enabling technology within a controlled assurance methodology, rather than as an autonomous mechanism for producing assurance conclusions.

5. Audit Risks of Using AI in ESG Assurance

5.1. The Risk Paradox of AI-Assisted ESG Assurance

Artificial intelligence can improve the efficiency, coverage and analytical depth of ESG assurance, but it also creates a new category of assurance risks. The central paradox is that AI may help assurance providers process large volumes of ESG information while simultaneously introducing risks related to data quality, reliability, explainability, bias, documentation, professional judgement, confidentiality and accountability. ISSA 5000 places professional judgement, evidence, materiality and assurance risk at the centre of sustainability assurance [3], while the EU AI Act establishes a risk-based framework for AI governance [12].
In sustainability assurance, this paradox is particularly important because ESG information is often heterogeneous, partly qualitative, estimated, forward-looking and dependent on value-chain data. AI can identify patterns, inconsistencies and potential risk signals across large datasets, but the quality of these outputs depends on the quality of the underlying information, the transparency of the model and the way in which assurance practitioners validate the results. Therefore, AI-assisted assurance does not reduce the need for professional scepticism. On the contrary, it increases the need for explicit validation, documentation and governance.
Figure 7 presents the risk paradox of AI-assisted ESG assurance. It shows that AI can increase speed, coverage and analytical capacity, but these benefits must be balanced against risks related to reliability, explainability, bias and overreliance. The figure also highlights the central role of human validation and governance as the mechanism that connects AI-enabled analysis with credible assurance outcomes.

5.2. Data Quality, Reliability and Explainability Risks

The first and most fundamental risk is data quality risk. AI systems depend on the quality of the data they process. If ESG data are incomplete, inconsistent, outdated, biased or poorly documented, AI analysis may produce misleading outputs. This problem is especially relevant in sustainability assurance because ESG data are often collected from different departments, subsidiaries, suppliers, operational systems and external databases. Weak data governance may lead AI tools to identify false anomalies, overlook missing information or treat non-comparable data as comparable.
Data quality risk is closely connected with reliability risk. AI outputs may appear precise and technically sophisticated even when they are based on incomplete or unreliable inputs. In ESG assurance, this may occur when AI tools analyse emissions data without recognising changes in reporting boundaries, when they compare workforce indicators based on different definitions, or when they interpret narrative sustainability claims without sufficient reference to quantitative evidence. In such cases, AI may amplify existing weaknesses in ESG reporting rather than correct them.
Generative AI introduces a further reliability problem: hallucination risk. Generative AI can produce fluent and plausible text, but the output may contain fabricated references, incorrect interpretations, unsupported conclusions or omissions. In ESG assurance, hallucination risk may arise when an AI tool states that a company has an independent sustainability assurance statement although the report contains only a financial audit opinion, or when it incorrectly claims that Scope 3 emissions are disclosed because the report mentions value chain or carbon neutrality. Such outputs may weaken assurance quality if they are incorporated into working papers without verification.
Explainability risk is equally important. Assurance providers need to understand how an AI system produced a risk score, anomaly flag, classification result or summary in order to evaluate its evidential value. If the model operates as a black box, the assurance team may be unable to assess whether the output is reliable, biased, relevant or reproducible. Casper et al. argue that black-box access is insufficient for rigorous AI audits and that transparency regarding access and methods is necessary to interpret audit results [21]. For ESG assurance, this means that AI-supported outputs should be documented, source-linked and sufficiently explainable to allow professional review.

5.3. Bias, Overreliance and Professional Judgement Risks

Bias risk arises when AI systems produce systematically distorted outputs because of biased training data, biased model design, incomplete source documents or inappropriate assumptions. In ESG assurance, a model trained primarily on English-language reports from large multinational companies may underperform when analysing reports from smaller companies, emerging markets or national-language documents. Similarly, a model trained on disclosures from carbon-intensive sectors may classify environmental information differently from a model trained on service-sector reports. Murikah, Nthenge and Musyoka examine bias and ethics in AI systems applied in auditing and emphasise risks related to algorithmic bias, transparency, accountability and fairness [22].
Bias may also arise from disclosure style. AI systems may overrate long, polished and formally structured sustainability narratives even when they are not supported by measurable indicators, methodologies or evidence. Conversely, concise but evidence-rich disclosures may receive lower apparent relevance if the model is overly sensitive to vocabulary or narrative intensity. This is particularly problematic in sustainability assurance because assurance quality depends not on the rhetorical sophistication of disclosures, but on their reliability, completeness, traceability and alignment with reporting criteria.
Another major risk is overreliance on AI outputs. Auditors and assurance providers may become too dependent on AI-generated classifications, summaries, anomaly lists or risk scores. This may weaken professional scepticism, especially when AI outputs appear objective, precise or technically advanced. Brown-Liburd, Issa and Lombardi discuss how big data affects audit judgement and decision-making [11]. Commerford et al. show that auditor reliance on artificial intelligence is influenced by the way auditors interact with AI systems [23]. In ESG assurance, this risk is intensified because sustainability disclosures often include estimates, assumptions, narratives and value-chain information that require contextual interpretation.
Professional judgement therefore remains the central control mechanism in AI-assisted ESG assurance. AI may identify a risk signal, but the assurance provider must determine whether the signal is relevant, material and supported by evidence. An anomaly in reported emissions may indicate an error, a methodological change, a boundary adjustment or a genuine operational improvement. A vague sustainability claim may represent greenwashing, but it may also reflect a disclosure that is supported elsewhere in the report. AI can support the identification of issues, but it cannot replace the professional assessment of meaning, materiality and evidence sufficiency.

5.4. Documentation, Confidentiality, Boundary and Accountability Risks

Documentation risk arises when the use of AI is not adequately recorded in the assurance file. If AI tools are used to identify disclosures, generate summaries, classify ESG information, detect anomalies or produce risk scores, the assurance provider must document the tool used, the purpose of use, the inputs, prompts or parameters, outputs, validation procedures and professional judgement applied. Without such documentation, AI-supported procedures may not be reproducible, reviewable or defensible.
Confidentiality and cybersecurity risks are also significant. ESG assurance may involve sensitive corporate data, supplier information, employee data, internal policies, incident records, audit documentation and unpublished sustainability information. If these data are processed through external AI tools without appropriate controls, the company and assurance provider may face data leakage, confidentiality breaches or privacy concerns. The GDPR is relevant where personal data are processed [24]. Assurance providers therefore need secure tools, access controls, anonymisation procedures and clear policies governing the use of AI in assurance engagements.
Boundary and materiality risk arises when AI analyses ESG disclosures without understanding the reporting boundary or the materiality logic of ESRS. A model may flag an issue as relevant because it appears frequently in a report, even if it is not material for the entity. Conversely, a material issue may be underweighted if it is disclosed briefly or appears in a technical annex. AI tools may also misinterpret group-level and subsidiary-level information, operational and financial boundaries, or changes in consolidation scope. Assurance providers must therefore ensure that AI-supported analysis is aligned with the reporting boundary, double materiality assessment and assurance scope.
Accountability risk arises when responsibility for AI outputs is unclear. If an assurance team relies on AI-generated outputs but no individual is responsible for reviewing and approving them, professional responsibility becomes blurred. This is inconsistent with the logic of assurance, where the practitioner remains responsible for the conclusion. Therefore, AI-assisted ESG assurance requires clear governance arrangements, including approval responsibilities, review procedures, documentation standards and escalation rules.
Table 7 summarises the main audit risks of using AI in ESG assurance and identifies the key controls needed to manage them.

6. A Conceptual Framework for Responsible AI-Assisted Sustainability Assurance

6.1. Rationale and Principles of the Framework

The preceding sections show that AI can substantially support sustainability assurance, but only if its use is embedded in a controlled professional process. The need for such a framework is reinforced by the interaction between CSRD, ESRS, ISSA 5000 and the EU AI Act [1,2,3,12]. The proposed Responsible AI-Assisted Sustainability Assurance Framework connects five core elements: ESG data inputs, AI-supported analytical procedures, assurance risk assessment, human professional judgement and assurance documentation.
The framework is based on the idea that AI should be used as an analytical support layer within sustainability assurance, not as an autonomous source of assurance conclusions. AI can help assurance providers locate disclosures, classify information, detect anomalies, compare documents and identify risk signals. However, the assurance practitioner remains responsible for evaluating relevance, reliability, sufficiency, materiality and the final assurance conclusion.
The framework is grounded in six principles: evidence orientation, human oversight, explainability, proportionality, accountability and data governance. Evidence orientation means that AI outputs must be connected to verifiable evidence. Human oversight means that the assurance practitioner remains responsible for evaluating AI-supported outputs. Explainability means that the assurance team must understand how AI outputs were generated sufficiently to assess their reliability. Proportionality means that AI-related controls should correspond to assurance risk. Accountability means that responsibility remains with the assurance provider. Data governance means that ESG data used by AI tools must be complete, consistent, traceable, secure and authorised.
Table 8 summarises these principles and translates them into practical requirements for ESG assurance engagements.

6.2. Structure of the Responsible AI-Assisted Sustainability Assurance Framework

The Responsible AI-Assisted Sustainability Assurance Framework consists of five interrelated layers. The first layer is the ESG data input layer. It includes public sustainability reports, annual reports, non-financial statements, ESRS disclosures, emissions data, workforce data, governance policies, supplier information, internal control documentation, external databases and media or regulatory sources. ESG information should be classified by source, type, reliability and assurance relevance because AI can process all information, while assurance practitioners must evaluate its evidential value.
The second layer is the AI analytical layer. It includes AI-supported procedures used to process ESG information, such as text extraction, topic classification, ESRS mapping, anomaly detection, consistency checks, greenwashing risk screening, external data matching and draft documentation support. These procedures should be matched to assurance objectives. Natural language processing may be useful for identifying disclosures, anomaly detection for quantitative indicators, semantic search for locating evidence and generative AI for draft summaries that require human review.
The third layer is the assurance risk assessment layer. AI outputs should be converted into assurance-relevant risk signals, not final conclusions. These signals may relate to data completeness, methodological transparency, boundary consistency, unexplained fluctuations, unsupported claims, missing evidence, weak traceability or possible greenwashing. Each AI-generated signal should be evaluated according to assurance relevance, materiality and the need for additional procedures.
The fourth layer is the human judgement and validation layer. This is the core control layer of the framework. It ensures that AI-generated outputs are interpreted through professional scepticism, materiality judgement, assurance standards and knowledge of the entity. The assurance provider must verify AI outputs against original sources, evaluate whether the outputs are relevant to the assurance objective and decide whether further evidence is required.
The fifth layer is the documentation, governance and assurance output layer. It translates AI-assisted procedures and human validation into assurance documentation. Documentation is essential because AI-supported procedures must be reproducible and reviewable. Raji et al. argue that algorithmic auditing should generate documentation across the system lifecycle to support accountability [25]. In ESG assurance, this means that the assurance file should document the AI tool used, the purpose of use, the data analysed, prompts or parameters applied, outputs generated, validation procedures performed, additional evidence obtained and final professional judgement.

6.3. Human Validation and Documentation Controls

Human validation is the central safeguard in responsible AI-assisted sustainability assurance. AI-generated outputs may be useful, but they must be verified before they are incorporated into the assurance file. The framework requires three main validation steps: source verification, relevance assessment and materiality assessment. Source verification means that the AI output must be checked against the original report, dataset or document. Relevance assessment means that the practitioner must determine whether the output is connected to the assurance objective. Materiality assessment means that the practitioner must decide whether the issue is significant in the context of the entity’s sustainability reporting and assurance scope.
Additional procedures may be necessary when AI identifies an anomaly, inconsistency, missing disclosure or potential greenwashing signal. These procedures may include recalculation, inspection of source documents, inquiry of management, reconciliation with internal records, comparison with external data or testing of internal controls. AI can help identify where further attention is needed, but it cannot determine on its own whether sufficient appropriate evidence has been obtained.
Documentation controls are equally important. The assurance file should clearly record how AI was used, which data were analysed, what outputs were generated, how these outputs were validated and how they influenced assurance procedures. Where generative AI is used, the assurance provider should retain prompt logs, output versions, source links and reviewer comments. Where predictive or classification tools are used, the assurance file should include information on model purpose, input data, assumptions, thresholds and limitations.
Governance controls should also define responsibility for approving AI-supported outputs. The use of AI should be subject to review by the engagement team and, where appropriate, by quality control reviewers. Responsibility for the final assurance conclusion must remain with the assurance practitioner. This requirement is essential because AI outputs may inform the engagement, but they cannot assume professional responsibility.

6.4. Operationalisation of the Framework

The framework can be operationalised through a sequence of assurance activities. First, the assurance objective and reporting criteria should be defined. Second, relevant ESG data sources should be identified, including reports, internal datasets, methodologies, supplier data and external evidence. Third, the readiness of these data should be assessed in terms of completeness, consistency, traceability and documentation. Fourth, suitable AI procedures should be selected according to the assurance objective. Fifth, AI-generated risk signals should be produced and reviewed. Sixth, the assurance practitioner should validate the outputs through source checks, relevance assessment and materiality judgement. Seventh, additional assurance procedures should be performed where necessary. Finally, the procedures, evidence, validation steps and conclusions should be documented.
This operational logic positions AI as a controlled analytical layer supporting assurance work. AI is most useful when it helps assurance providers process large volumes of ESG information, identify inconsistencies, locate evidence and prioritise risk areas. However, each AI-supported output must remain subject to professional judgement and documentation. The final assurance conclusion should be based not on AI output alone, but on sufficient appropriate evidence evaluated by the assurance practitioner.
Table 9 presents the control matrix for responsible AI-assisted ESG assurance. It links the main AI-related risks with the control objectives and practical controls required to preserve assurance quality.
Overall, the proposed framework clarifies how AI can be responsibly integrated into sustainability assurance. Its main contribution is to connect technological capability with assurance discipline. AI can improve the scope, speed and analytical depth of ESG verification, but only when it is embedded in a process based on evidence, human oversight, explainability, proportionality, accountability and data governance. Responsible AI-assisted sustainability assurance is therefore not a model of automation, but a model of professionally controlled augmentation.

7. Implications for Accounting Systems, Auditors and Regulators

7.1. Implications for Accounting Systems and ESG Data Governance

The proposed framework has implications that extend beyond the technical use of artificial intelligence. It affects how companies design accounting and ESG data systems, how auditors plan and perform assurance engagements, and how regulators and standard setters define expectations for credible sustainability information. AI-assisted sustainability assurance can improve efficiency, coverage and risk sensitivity only when it is supported by reliable ESG data, documented methodologies, human professional judgement and clear governance.
The first implication concerns accounting and information systems. Sustainability assurance cannot be effective if ESG information is produced only as a late-stage reporting exercise. Companies subject to CSRD/ESRS reporting need internal systems capable of collecting, classifying, validating, aggregating and documenting sustainability data throughout the reporting period. This means that ESG data must increasingly be treated with accounting-like discipline. Data governance should include indicator definitions, source-system mapping, data ownership, version control, access rights, quality checks, approval workflows, documentation rules and retention policies.
This implication is particularly important because AI tools depend on the quality of the data they process. If ESG data are incomplete, inconsistent, poorly documented or collected from fragmented systems, AI may amplify existing weaknesses rather than improve assurance quality. Therefore, companies should not view AI-assisted assurance as a technological shortcut. It requires a reliable ESG data architecture, clear reporting boundaries, methodological documentation, internal controls and audit trails. Carbon accounting, workforce reporting, health and safety indicators, supplier information and governance disclosures must be traceable to source records and supported by consistent calculation methods.
For accounting systems, this development expands the traditional logic of financial reporting into the sustainability domain. The principles of documentation, control, consistency, periodisation, responsibility and auditability become increasingly relevant for ESG information. AI-assisted assurance therefore reinforces the need to integrate sustainability data into accounting information systems, enterprise resource planning systems, environmental management systems, HR platforms and reporting tools. The more sustainability information becomes assurance-oriented, the more it requires accounting-system discipline.

7.2. Implications for Auditors and Assurance Providers

For auditors and assurance providers, the most important implication is that AI should be treated as an assurance-supporting tool, not as an autonomous source of conclusions. AI can identify disclosures, classify ESG topics, map information to ESRS categories, detect anomalies, compare documents, support external data triangulation and prepare preliminary summaries. However, the assurance practitioner remains responsible for professional judgement, materiality assessment, evidence evaluation and the final assurance conclusion [3,13].
This changes the competence profile required from assurance practitioners. ESG assurance already requires knowledge of sustainability reporting standards, double materiality, sustainability indicators, reporting boundaries and assurance methodology. AI-assisted assurance adds further requirements: data analytics literacy, understanding of AI-related limitations, ability to interpret anomaly signals, awareness of bias and explainability risks, and knowledge of confidentiality and cybersecurity issues. Auditors do not need to become software engineers, but they need sufficient technological literacy to challenge AI outputs and assess their evidential value.
AI-assisted sustainability assurance can improve audit quality if it increases coverage, consistency and risk sensitivity. It can help assurance providers examine larger volumes of information, identify inconsistencies across documents and focus attention on areas where assurance risk is higher. However, AI can also reduce audit quality if it weakens professional scepticism. A technically sophisticated AI output may create the impression of objectivity, even when the underlying ESG data are incomplete, the model logic is opaque or the output is not properly validated.
For this reason, assurance providers should adopt a human-in-the-loop approach. AI may generate signals, but auditors must validate sources, assess relevance, evaluate materiality, perform additional procedures and document their conclusions. The assurance file should show how AI was used, what inputs were analysed, what outputs were generated, how those outputs were checked and how they influenced the engagement. This is particularly important where AI is used for ESRS mapping, greenwashing risk screening, anomaly detection or working-paper drafting.

7.3. Implications for Regulators, Standard Setters and Education

For regulators and standard setters, the main implication is that sustainability assurance guidance should address not only ESG reporting content, but also the technologies used to analyse and verify that content. Regulators do not need to prescribe specific AI tools. Instead, they can define expectations for transparency, documentation, validation, human oversight, confidentiality, accountability and independence. This would align sustainability assurance practice with the broader risk-based logic of the EU AI Act [12].
Regulatory guidance should clarify that AI-generated outputs are not automatically sufficient appropriate evidence. They may support risk assessment, evidence location, consistency checks or documentation, but their evidential status depends on source verification, reliability, relevance and professional judgement. Guidance may also be needed on the use of external AI tools, data protection, documentation of prompts and outputs, validation of models, independence risks and third-party technology providers.
Companies subject to CSRD/ESRS reporting should prepare sustainability information as assurance-ready information from the beginning. This means that ESG data should not be assembled only at the end of the reporting period for disclosure purposes. It should be generated, controlled, documented and reviewed throughout the year. Such preparation is also important for AI-assisted assurance, because AI tools can only support assurance effectively when the underlying data are structured, traceable and reliable.
Finally, accounting and auditing education should reflect this transformation. Future accountants and auditors will need interdisciplinary competence that combines sustainability reporting, assurance methodology, accounting information systems, ESG data governance and AI-related risks. Professional education should therefore move beyond general discussions of digital transformation and include practical training on AI-supported evidence analysis, model limitations, documentation, professional scepticism and responsible use of technology in assurance engagements.

8. Conclusions

8.1. Main Findings and Contribution

This article examined the role of artificial intelligence in sustainability assurance and developed a conceptual framework for responsible AI-assisted ESG verification. The starting point of the study is the transformation of sustainability reporting from voluntary ESG disclosure into regulated, assurance-oriented corporate reporting. In the CSRD/ESRS environment, sustainability information is expected to be reliable, comparable, traceable and decision-useful. The analysis shows that sustainability assurance cannot rely only on the existence of ESG disclosures. Assurance requires evidence-ready information: data that are quantified, time-specific, methodologically transparent, traceable, comparable and aligned with recognised reporting criteria.
The article argues that AI can support sustainability assurance in several important ways. AI can help assurance providers locate ESG disclosures, map corporate reports to ESRS-related categories, detect inconsistencies, identify anomalies in sustainability indicators, screen for greenwashing risks, compare disclosures across documents, integrate external data sources and support the preparation of working papers. These opportunities are particularly relevant because sustainability information is often dispersed across annual reports, sustainability reports, non-financial statements, internal datasets, supplier information and external evidence sources.
However, the use of AI also introduces specific audit risks. The most important risks identified in the article are data quality risk, reliability and hallucination risk, explainability risk, bias risk, overreliance risk, documentation risk, confidentiality and cybersecurity risk, boundary and materiality risk, and accountability risk. These risks are intensified by the characteristics of ESG information, which may be qualitative, estimated, forward-looking, value-chain-dependent and methodologically uncertain. Therefore, AI outputs should not be treated as independent assurance conclusions. They should be treated as analytical signals that require professional validation.
The main conceptual contribution of this article is the proposed Responsible AI-Assisted Sustainability Assurance Framework. The framework clarifies that AI should be positioned as a controlled analytical layer within the assurance process. It does not replace the auditor or assurance practitioner; it supports the identification of evidence, the detection of risk signals and the organisation of complex ESG information. The framework connects ESG data inputs, AI analytical procedures, assurance risk assessment, human judgement and documentation into a coherent assurance logic.

8.2. Practical Implications

The practical implications of the study concern companies, auditors, regulators, professional bodies and researchers. For companies, the main implication is that AI-assisted assurance begins with ESG data quality. Companies preparing for CSRD/ESRS reporting should not focus only on producing longer sustainability reports. They need internal ESG data systems that provide traceable, documented and controllable information. ESG data governance, internal controls, source documentation and clear methodologies are necessary preconditions for both credible reporting and AI-assisted assurance.
For auditors and assurance providers, the main implication is that AI use must be governed through methodology. AI can improve the scope and efficiency of assurance procedures, but its outputs must be validated, documented and interpreted through professional judgement. Assurance providers should develop procedures for assessing AI-generated outputs, documenting AI use, preserving professional scepticism and managing confidentiality, bias, explainability and overreliance risks.
For regulators and standard setters, the article suggests that future guidance should address the evidential status of AI outputs, transparency, documentation, validation, confidentiality, independence and accountability in AI-assisted assurance engagements. The challenge is not to regulate specific technologies, but to establish principles for responsible use. For professional bodies and educators, the implication is that assurance practitioners need new competencies that combine ESG reporting, assurance methodology, data analytics and AI governance.
For researchers, AI-assisted sustainability assurance remains an emerging field. Future studies can empirically examine whether AI improves the detection of ESG reporting weaknesses, how auditors respond to AI-generated risk signals, how companies organise ESG data governance, and whether AI-assisted procedures influence assurance quality. Research can also compare different regulatory approaches to AI use in assurance and investigate whether AI helps identify greenwashing risks more effectively than traditional document review.

8.3. Limitations and Final Conclusion

This article has several limitations. First, it is conceptual in nature. It develops a framework for responsible AI-assisted sustainability assurance, but it does not empirically test the framework on actual assurance engagements or corporate reports. Second, the article discusses AI at a general conceptual level and does not compare specific AI tools, software platforms or large language models. Third, the article is primarily framed in the European regulatory context because of the importance of the CSRD, ESRS and EU AI Act. Fourth, it focuses on assurance risks and governance issues rather than on cost-benefit analysis.
Despite these limitations, the article contributes to the growing debate on the future of sustainability assurance. Artificial intelligence has the potential to make ESG verification more systematic, data-driven and risk-sensitive. It can help assurance providers process large reporting packages, identify relevant disclosures, map information to reporting standards, detect anomalies and support documentation. However, AI also creates new risks that must be explicitly managed. Poor data quality, hallucinated outputs, black-box models, biased classifications, weak documentation and excessive reliance on AI can undermine rather than strengthen assurance quality.
The future of AI-assisted sustainability assurance should therefore not be understood as full automation. It should be understood as responsible augmentation. AI can enhance the work of assurance practitioners, but only within a governance framework based on evidence, transparency, professional scepticism, human oversight and accountability. The central conclusion of the article is that AI can support credible sustainability assurance only when it remains embedded in a human-controlled assurance process.

Author Contributions

Conceptualization, R.K.-H. and V.G.; methodology, R.K.-H.; software, R.K.-H.; validation, R.K.-H. and V.G.; formal analysis, R.K.-H.; investigation, R.K.-H. and V.G.; resources, R.K.-H. and V.G.; data curation, R.K.-H.; writing-original draft preparation, R.K.-H. and V.G.; writing-review and editing, R.K.-H. and V.G.; visualization, R.K.-H.; supervision, R.K.-H. and V.G.; project administration, V.G.; funding acquisition, V.G. All authors have read and agreed to the published version of the manuscript.

Funding

This research received no external funding.

Institutional Review Board Statement

Not applicable.

Data Availability Statement

No new data were created or analyzed in this study. Data sharing is not applicable to this article because it is a conceptual study based on publicly available regulatory documents, professional standards and previously published academic literature.

Acknowledgments

During the preparation of this manuscript, the authors used OpenAI ChatGPT for language refinement, structural editing and the development of illustrative figures. The authors have reviewed and edited the output and take full responsibility for the content of this publication.

Conflicts of Interest

The authors declare no conflicts of interest.

References

  1. European Parliament and Council of the European Union. Directive (EU) 2022/2464 of 14 December 2022 amending Regulation (EU) No 537/2014, Directive 2004/109/EC, Directive 2006/43/EC and Directive 2013/34/EU as regards corporate sustainability reporting. Off. J. Eur. Union 2022. [Google Scholar] [CrossRef]
  2. European Commission. Commission Delegated Regulation (EU) 2023/2772 of 31 July 2023 supplementing Directive 2013/34/EU as regards sustainability reporting standards. Off. J. Eur. Union 2023. [Google Scholar] [CrossRef]
  3. International Auditing and Assurance Standards Board. International Standard on Sustainability Assurance 5000, General Requirements for Sustainability Assurance Engagements. IAASB, 2024. [Google Scholar]
  4. Simnett, R.; Vanstraelen, A.; Chua, W.F. Assurance on Sustainability Reports: An International Comparison. Account. Rev. 2009, 84, 937–967. [Google Scholar] [CrossRef]
  5. Cohen, J.R.; Simnett, R. CSR and Assurance Services: A Research Agenda. Audit. A J. Pract. Theory 2015, 34, 59–74. [Google Scholar] [CrossRef]
  6. Farooq, M.B.; de Villiers, C. The Market for Sustainability Assurance Services: A Comprehensive Literature Review and Future Avenues for Research. Pac. Account. Rev. 2017, 29, 79–106. [Google Scholar] [CrossRef]
  7. Boiral, O.; Heras-Saizarbitoria, I.; Brotherton, M.-C. Assessing and Improving the Quality of Sustainability Reports: The Auditors’ Perspective. J. Bus. Ethics 2019, 155, 703–721. [Google Scholar] [CrossRef]
  8. Appelbaum, D.; Kogan, A.; Vasarhelyi, M.A. Big Data and Analytics in the Modern Audit Engagement: Research Needs. Audit. A J. Pract. Theory 2017, 36, 1–27. [Google Scholar] [CrossRef]
  9. Kokina, J.; Davenport, T.H. The Emergence of Artificial Intelligence: How Automation Is Changing Auditing. J. Emerg. Technol. Account. 2017, 14, 115–122. [Google Scholar] [CrossRef]
  10. Issa, H.; Sun, T.; Vasarhelyi, M.A. Research Ideas for Artificial Intelligence in Auditing: The Formalization of Audit and Workforce Supplementation. J. Emerg. Technol. Account. 2016, 13, 1–20. [Google Scholar] [CrossRef]
  11. Brown-Liburd, H.; Issa, H.; Lombardi, D. Behavioral Implications of Big Data’s Impact on Audit Judgment and Decision Making and Future Research Directions. Account. Horiz. 2015, 29, 451–468. [Google Scholar] [CrossRef]
  12. European Parliament and Council of the European Union. Regulation (EU) 2024/1689 of 13 June 2024 laying down harmonised rules on artificial intelligence. Off. J. Eur. Union 2024. [Google Scholar] [CrossRef]
  13. International Auditing and Assurance Standards Board. ISA 500, Audit Evidence. IAASB. [CrossRef]
  14. Hummel, K.; Schlick, C. The Relationship between Sustainability Performance and Sustainability Disclosure: Reconciling Voluntary Disclosure Theory and Legitimacy Theory. J. Account. Public Policy 2016, 35, 455–476. [Google Scholar] [CrossRef]
  15. Deegan, C. Introduction: The Legitimising Effect of Social and Environmental Disclosures—A Theoretical Foundation. Account. Audit. Account. J. 2002, 15, 282–311. [Google Scholar] [CrossRef]
  16. Vasarhelyi, M.A.; Kogan, A.; Tuttle, B.M. Big Data in Accounting: An Overview. Account. Horiz. 2015, 29, 381–396. [Google Scholar] [CrossRef]
  17. Gepp, A.; Linnenluecke, M.K.; O’Neill, T.J.; Smith, T. Big Data Techniques in Auditing Research and Practice: Current Trends and Future Opportunities. J. Account. Lit. 2018, 40, 102–115. [Google Scholar] [CrossRef]
  18. International Auditing and Assurance Standards Board. ISA 315 (Revised 2019), Identifying and Assessing the Risks of Material Misstatement. IAASB, 2019. [Google Scholar]
  19. Sutton, S.G.; Holt, M.; Arnold, V. “The Reports of My Death Are Greatly Exaggerated”—Artificial Intelligence Research in Accounting. Int. J. Account. Inf. Syst. 2016, 22, 60–73. [Google Scholar] [CrossRef]
  20. Li, N.; Kim, M.; Dai, J.; Vasarhelyi, M.A. Using Artificial Intelligence in ESG Assurance. J. Emerg. Technol. Account. 2024, 21, 83–99. [Google Scholar] [CrossRef]
  21. Casper, S.; Ezell, C.; Siegmann, C.; Kolt, N.; Curtis, T.L.; Bucknall, B.; Haupt, A.; Wei, K.; Scheurer, J.; Hobbhahn, M.; et al. Black-Box Access Is Insufficient for Rigorous AI Audits. In Proceedings of the 2024 ACM Conference on Fairness, Accountability, and Transparency, 2024; pp. 2254–2272. [Google Scholar] [CrossRef]
  22. Murikah, W.; Nthenge, J.K.; Musyoka, F.M. Bias and Ethics of AI Systems Applied in Auditing—A Systematic Review. Sci. Afr. 2024, 25, e02281. [Google Scholar] [CrossRef]
  23. Commerford, B.P.; Dennis, S.A.; Joe, J.R.; Ulla, J.W. Control Issues: How Providing Input Affects Auditors’ Reliance on Artificial Intelligence. Contemp. Account. Res. 2024. [Google Scholar] [CrossRef]
  24. European Parliament and Council of the European Union. Regulation (EU) 2016/679 of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data. In Official Journal of the European Union; 2016. [Google Scholar]
  25. Raji, I.D.; Smart, A.; White, R.N.; Mitchell, M.; Gebru, T.; Hutchinson, B.; Smith-Loud, J.; Theron, D.; Barnes, P. Closing the AI Accountability Gap: Defining an End-to-End Framework for Internal Algorithmic Auditing. In Proceedings of the 2020 ACM Conference on Fairness, Accountability, and Transparency, 2020; pp. 33–44. [Google Scholar] [CrossRef]
Figure 1. The role of AI in the sustainability assurance process.
Figure 1. The role of AI in the sustainability assurance process.
Preprints 223533 g001
Figure 2. Sustainability assurance as a credibility mechanism.
Figure 2. Sustainability assurance as a credibility mechanism.
Preprints 223533 g002
Figure 3. Evidence-ready ESG information as a precondition for AI-assisted assurance.
Figure 3. Evidence-ready ESG information as a precondition for AI-assisted assurance.
Preprints 223533 g003
Figure 4. Evolution of technology use in accounting and auditing.
Figure 4. Evolution of technology use in accounting and auditing.
Preprints 223533 g004
Figure 5. AI-supported audit workflow and progression toward continuous assurance.
Figure 5. AI-supported audit workflow and progression toward continuous assurance.
Preprints 223533 g005
Figure 6. AI-assisted sustainability assurance workflow.
Figure 6. AI-assisted sustainability assurance workflow.
Preprints 223533 g006
Figure 7. Risk paradox of AI-assisted ESG assurance.
Figure 7. Risk paradox of AI-assisted ESG assurance.
Preprints 223533 g007
Table 1. Regulatory transition from ESG disclosure to assurance-ready sustainability reporting.
Table 1. Regulatory transition from ESG disclosure to assurance-ready sustainability reporting.
Regulatory document Main relevance for the article Implication for accounting and assurance
Directive (EU) 2022/2464 - CSRD Expands sustainability reporting obligations and embeds sustainability information in corporate reporting Requires more reliable, comparable and assurance-relevant sustainability information
Commission Delegated Regulation (EU) 2023/2772 - ESRS Introduces detailed sustainability disclosure standards Creates demand for structured, traceable and verifiable ESG data
ISSA 5000 Provides global requirements for sustainability assurance engagements Emphasises evidence, professional judgement, materiality and assurance risk
Regulation (EU) 2024/1689 - AI Act Establishes harmonised EU rules for artificial intelligence Raises issues of transparency, accountability, risk management and human oversight
Table 2. Evolution from ESG disclosure to sustainability assurance.
Table 2. Evolution from ESG disclosure to sustainability assurance.
Stage Main characteristic Dominant problem Assurance relevance
Voluntary ESG disclosure
Flexible, narrative and company-specific reporting Selectivity and lack of comparability Limited assurance potential
Framework-based reporting
Use of GRI, integrated reporting or climate-related frameworks Heterogeneous quality and uneven methodology Partial assurance potential
Regulated sustainability reporting
CSRD/ESRS-based reporting logic Need for reliable systems and evidence Strong assurance demand
Digitally structured reporting XBRL-tagged and machine-readable information Need for accurate tagging and traceability Enables analytics-supported assurance
Table 3. Characteristics of evidence-ready ESG information.
Table 3. Characteristics of evidence-ready ESG information.
Characteristic Meaning Example of weak disclosure Example of evidence-ready disclosure
Quantification Information is expressed through measurable indicators We reduced emissions. Scope 1 emissions decreased by 8% to 12,400 tCO₂e.
Time specificity Information is linked to reporting period, baseline or target year We aim to improve energy efficiency. Energy intensity will decrease by 20% by 2030 compared with 2020.
Methodological transparency Methods, assumptions and boundaries are explained Carbon footprint was calculated. Emissions were calculated using the GHG Protocol and location-based emission factors.
Traceability Information can be linked to evidence Isolated narrative claim Cross-reference to tables, internal records or assurance scope.
Comparability Data can be compared over time or across entities One-year isolated disclosure
Three-year data series with consistent units and boundaries.
Criteria alignment Disclosure follows recognised standards General ESG terminology ESRS-based disclosure of policies, actions, targets and metrics.
Table 4. Accounting-system requirements for evidence-ready ESG information.
Table 4. Accounting-system requirements for evidence-ready ESG information.
ESG information requirement Accounting-system equivalent Assurance relevance
Defined ESG indicators Chart of accounts / reporting classifications Enables consistent data capture
Reporting boundaries Consolidation perimeter Clarifies what is included and excluded
Calculation methods Accounting policies and estimates Supports recalculation and review
Data ownership Responsibility centres Improves accountability
Source documentation Audit trail Enables evidence collection
Periodic reporting Accounting periodisation Supports comparability over time
Internal controls Control environment and testing Reduces risk of error or manipulation
Table 5. AI technologies and their accounting/auditing applications.
Table 5. AI technologies and their accounting/auditing applications.
AI-related technology Main function Accounting application Auditing application
Machine learning Pattern recognition and prediction Forecasting, classification, risk scoring Risk assessment, anomaly detection
Natural language processing Analysis of textual data Contract analysis, disclosure review Report analysis, evidence location
Expert systems Rule-based decision support Accounting treatment support Audit planning and compliance checks
Robotic process automation Automation of repetitive tasks Invoice processing, reconciliations Data extraction and routine testing
Anomaly detection Identification of unusual patterns Fraud flags, unusual transactions Journal entry testing and exception analysis
Generative AI Text generation and summarisation Drafting notes, management reporting Working-paper summaries, preliminary analysis
Table 6. Summary of opportunities of AI-assisted sustainability assurance.
Table 6. Summary of opportunities of AI-assisted sustainability assurance.
Opportunity Main assurance benefit Main condition for effective use
ESG disclosure identification Faster and broader document review Reliable text extraction and topic classification
ESRS mapping Better assessment of regulatory alignment Validated ESRS taxonomy and human review
Evidence location More efficient identification of relevant source material Source-linked outputs and traceability
Anomaly detection Identification of unusual ESG patterns High-quality ESG datasets and contextual interpretation
Consistency checks Detection of contradictions across reports, metrics and narratives Reconciliation with original documents and internal records
Greenwashing screening Identification of vague, promotional or unsupported claims Comparison with quantitative and external evidence
External data integration Broader evidence base and improved triangulation Data governance and source reliability assessment
Risk assessment More focused assurance planning Professional judgement and materiality assessment
Documentation support More efficient working-paper preparation Human verification, source links and audit trail
Continuous monitoring Timelier risk identification Integrated ESG data systems and internal controls
Table 7. Integrated AI-assisted ESG assurance risk matrix.
Table 7. Integrated AI-assisted ESG assurance risk matrix.
Risk category Main cause Assurance consequence Key control
Data quality risk Incomplete, inconsistent or poorly documented ESG data Misleading AI outputs Data validation and boundary checks
Reliability and hallucination risk AI errors, fabricated summaries or unsupported outputs False or unsupported assurance conclusions Source verification and output testing
Explainability risk Black-box model logic Weak reviewability and documentation Tool documentation and explainable outputs
Bias risk Biased training data, language or sector assumptions Distorted ESG assessment Bias testing and sector/language validation
Overreliance risk Excessive trust in AI outputs Reduced professional scepticism Human-in-the-loop review
Documentation risk Poor logging of AI procedures Weak audit trail Prompt logs, output archive and validation notes
Confidentiality risk Use of external AI tools for sensitive data Data leakage or privacy breach Secure tools, anonymisation and access controls
Boundary/materiality risk AI ignores reporting scope or ESRS materiality logic Wrong assurance focus ESRS-based boundary and materiality review
Accountability risk Unclear responsibility for AI outputs Weak professional responsibility Clear governance and approval matrix
Table 8. Principles of responsible AI-assisted sustainability assurance.
Table 8. Principles of responsible AI-assisted sustainability assurance.
Principle Meaning in ESG assurance Practical requirement
Evidence orientation AI outputs must be linked to verifiable evidence Source-linked summaries, page references, datasets and audit trails
Human oversight AI supports, but does not replace, professional judgement Mandatory practitioner review and approval
Explainability AI outputs must be understandable and reviewable Tool description, prompts, parameters and validation notes
Proportionality AI controls should reflect assurance risk Stronger controls for risk scoring and anomaly detection
Accountability Assurance responsibility remains with the practitioner Clear responsibility matrix and review procedures
Data governance ESG data must be reliable, secure and traceable Data quality checks, access controls and confidentiality safeguards
Table 9. Control matrix for responsible AI-assisted ESG assurance.
Table 9. Control matrix for responsible AI-assisted ESG assurance.
AI-related risk Control objective Practical control
Data quality risk Ensure reliable inputs Data completeness, boundary and source checks
Hallucination risk Prevent unsupported outputs Source-linked AI outputs and manual verification
Explainability risk Make AI procedures reviewable Tool documentation and model explanation
Bias risk Avoid distorted classifications Sector, language and sample validation
Overreliance risk Preserve professional scepticism Mandatory human review and challenge
Documentation risk Maintain audit trail Prompt logs, output archive and validation notes
Confidentiality risk Protect sensitive data Approved tools, anonymisation and secure environments
Materiality risk Link AI outputs to assurance relevance Practitioner materiality assessment
Accountability risk Preserve professional responsibility Clear approval and responsibility matrix
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content.
Copyright: This open access article is published under a Creative Commons CC BY 4.0 license, which permit the free download, distribution, and reuse, provided that the author and preprint are cited in any reuse.