Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

ICSR explained

ICSR: The Complete Guide to Internal Control over Sustainability

ICSR — internal control over sustainability reporting — is COSO’s answer to a question that arrived with mandatory ESG disclosure: how does an organisation get the same confidence in its emissions, workforce and supply-chain numbers that it has in its financial statements? The answer COSO gave in March 2023, in the supplemental guidance Achieving Effective Internal Control over Sustainability Reporting, is that it does not need a new framework. The 2013 Internal Control — Integrated Framework, with its five components and 17 principles, was written for any objective, and the guidance walks each principle through what it means when the reported information is a tonne of CO₂e rather than a dollar of revenue. The guidance is non-authoritative and says so, but it has become the reference point regulators, assurance providers and boards use, because it is the only mainstream framework treatment of the subject. This guide sets out what ICSR is, why sustainability data breaks the controls built for financial data, the 17 principles as the guidance interprets them, the ten takeaways COSO closes with, and a build sequence that moves an organisation from “annual and manual” reporting to controls an assurance provider can rely on.

ICSR: the 17 COSO principles applied to sustainability information
Control environment (1–5) · Risk assessment (6–9) · Control activities (10–12) · Information and communication (13–15) · Monitoring activities (16–17) — the 2013 framework, interpreted for ESG data by COSO’s March 2023 guidance.

What ICSR is

Element Detail
The guidance Achieving Effective Internal Control over Sustainability Reporting (ICSR): Building Trust and Confidence through the COSO Internal Control — Integrated Framework, released 30 March 2023
Status Non-authoritative and interpretative — ‘it expresses only the interpretations, opinions, and perspectives of the authors on how the COSO Internal Control — Integrated Framework may apply’
The framework applied ICIF-2013: five components, 17 principles, points of focus — the same framework used for SOX 404 assessments of internal control over financial reporting
Scope of ‘sustainability’ Sustainable business information broadly: external and internal, financial and nonfinancial, compliance reporting — not only the external ESG report
Authors Robert Herz (former FASB chair), Robert Hirth (former COSO chair), Douglas Hileman, Shari Littan, Brad Monterio, Jeffrey Thomson
Why it matters ISSB standards, the EU CSRD and assurance requirements moving from limited to reasonable assurance all presume controls over the reported data; the guidance is how the controls are framed

Why sustainability data defeats financial controls

Financial reporting controls sit on a ledger: every transaction has a document, a double entry, a reconciliation and a chart of accounts that has existed for a century. Sustainability data has none of that by default. The guidance’s comparison of conventional financial reporting with sustainable business information is the reason ICSR is a project rather than an extension, and the differences drive the control design.

Characteristic Financial reporting Sustainability reporting Control consequence
Source of the data Accounting systems, ledgers, invoices Meters, utility bills, HR systems, supplier surveys, engineering estimates, spreadsheets Completeness and accuracy controls at the source, not the consolidation
Units and conversions Currency kWh, litres, tonnes, headcount, converted with emission factors and assumptions Factor libraries and conversion logic under change control
Ownership Finance Operations, EHS, HR, procurement, sustainability team Cross-functional roles and a single accountable owner
Estimation Bounded by GAAP Pervasive — Scope 3, allocations, extrapolations Methodology documents, estimate governance, disclosure of uncertainty
Boundary The consolidated entity Operational or financial control, equity share, value chain A boundary decision recorded and applied consistently
Systems ERP with ITGCs Spreadsheets and point tools ITGCs over tools nobody thought of as systems
Maturity Decades of standards, audit and enforcement Standards still converging; assurance moving from limited to reasonable Principle 9 — change — is permanent

The 17 principles as ICSR interprets them

Component Principle What it means for sustainability reporting
Control environment 1 Integrity and ethical values Tone from the top on honest sustainability claims; greenwashing treated as the reporting fraud it is
2 Board oversight A board or committee with sustainability competence, overseeing reporting as it oversees financial reporting
3 Structures, authority, responsibility Named ownership of each metric; the Three Lines Model applied to sustainability
4 Competence People who understand both the subject (GHG accounting, human capital) and controls
5 Accountability Incentives tied to sustainability targets carry the same risk of manipulation as financial bonuses — and the same accountability
Risk assessment 6 Suitable objectives Which standards, which metrics, which boundary, which users — specified before controls are designed
7 Risks to objectives Where each metric can be wrong: source, conversion, estimation, aggregation, presentation
8 Fraud risk Incentives to overstate progress or understate emissions; management override of sustainability data
9 Significant change New standards, new regulations, new assurance levels, acquisitions — continuous
Control activities 10 Control activities Reconciliations, reviews, cut-off, completeness checks designed for each data flow
11 General controls over technology Access, change and operations controls over the spreadsheets and ESG platforms — ITGCs the guidance says not to forget
12 Policies and procedures A sustainability reporting manual: methodologies, factors, boundaries, roles, calendar
Information and communication 13 Relevant information Data quality at source; data lineage from meter to disclosure
14 Internal communication Reporting lines, escalation, the disclosure committee’s remit extended
15 External communication Consistent messages across the ESG report, the annual report, regulatory filings and marketing
Monitoring 16 Evaluations Internal audit coverage of sustainability reporting; internal assurance before external assurance
17 Deficiencies Deficiencies evaluated, reported and remediated — with a severity scale the organisation defines, since no regulator has

Our guide to the COSO 17 principles covers the framework the interpretation sits on; ESG reporting covers the standards the objectives in principle 6 are set against.

COSO’s ten takeaways

The guidance closes with ten takeaways. Condensed: (1) commit to effective internal control over sustainability matters and get involved; (2) the end game is the 17 principles present and functioning over key sustainability activities and reporting — start now, leverage financial-reporting controls, do not forget ITGCs, and use the framework beyond reporting; (3) settle structures, roles and responsibilities, using the Three Lines Model; (4) learn the subject; (5) use COSO’s other materials, including ERM and ESG; (6) internal assurance and confidence must exist before external assurance — use internal audit; (7) ESG reporting is not an “annual and manual” activity — make it automated, efficient and continuous; (8) monitoring activities are key in a fast-moving area; (9) COSO is for all organisations, not only listed companies; (10) form a cross-functional team of sustainability and controls experts. The sixth and seventh are the ones that separate organisations with controls from organisations with a report.

Building ICSR: a sequence

  1. Inventory the disclosures and their data flows. Every metric in the report, traced back to its sources, conversions, estimates and owners. The map is the risk assessment’s input and most organisations have never drawn it.
  2. Set objectives and boundary (principle 6). Which standard, which metrics, which consolidation boundary, which assurance level is the target — reasonable assurance changes the control design.
  3. Risk-assess metric by metric (principles 7 and 8). Where can it be wrong, and who has an incentive to make it wrong.
  4. Design controls at the source and the conversion (principle 10). Completeness of sites and meters; accuracy of readings; factor and methodology change control; reconciliation of totals; review at a precision that would catch a material error.
  5. Bring the tools under ITGCs (principle 11). The spreadsheet that computes Scope 1 is a financial-reporting-grade system now.
  6. Write the manual (principle 12) and put internal audit on the calendar (principle 16) before the assurance provider arrives.
  7. Define deficiency severity (principle 17). Borrow the ICFR scale — deficiency, significant deficiency, material weakness — with materiality defined for each metric.

Our guide to ESG governance covers the board and committee structure principles 2 and 3 expect.

Frequently asked questions

What does ICSR stand for?
Internal control over sustainability reporting — the application of the COSO Internal Control — Integrated Framework (2013) to sustainability and ESG information, set out in COSO’s March 2023 supplemental guidance, Achieving Effective Internal Control over Sustainability Reporting.

Is ICSR a new framework?
No. It is the 2013 framework — five components, 17 principles — interpreted for sustainability information. COSO’s position is that the framework was always designed for any objective and that most, if not all, of the 17 principles apply to sustainability comparably to financial reporting.

Is the ICSR guidance mandatory?
No. It is non-authoritative and interpretative by its own description. It matters because regulators and assurance providers assessing controls over sustainability data have no other mainstream framework treatment to point to.

How does ICSR relate to SOX 404?
SOX 404 covers internal control over financial reporting. Sustainability disclosures are largely outside it unless they appear in the financial statements, but the same framework, the same deficiency concepts and often the same people are used for both, which is why COSO built ICSR on ICIF-2013.

Where should an organisation start?
With a data-flow inventory of every disclosed metric, then objectives and boundary, then a metric-by-metric risk assessment. COSO’s own advice is to start using the framework now rather than waiting for regulation, to leverage existing financial-reporting controls, and to get internal assurance before external.

Where this leaves you

Treat ICSR as the same discipline applied to different data: map every sustainability metric to its sources, set the objectives and boundary, assess where each number can be wrong and who would want it to be, put controls at the source and the conversion, bring the spreadsheets under ITGCs, and let internal audit test it before the assurance provider does. The 17 principles have not changed; the ledger has.

References

More on COSO

The 17-principle control matrix, the sustainability data-flow inventory, the metric risk assessment workbook, the reporting manual template and the deficiency evaluation worksheet are in the COSO ERM & Internal Control Toolkit, or start with the free templates.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.