The 2026 CSRD Assurance Opinion: Where Auditors Ask Where Your AI-Generated Metrics Came From
The first CSRD limited-assurance opinions are being signed in 2026, and auditors want to know which system every figure came from. AI-assisted ESG reporting needs versioned sources and a clean audit trail.
By The Rexfin team
A sustainability controller at a Wave 1 manufacturer told me her assurance team spent nearly an hour on a single number: Scope 3 emissions from purchased goods. Not arguing the methodology. Arguing where the figure came from. Which source system, which extraction, which version of the supplier dataset, who touched it after the model produced it. The number was probably right. She just couldn’t prove how it got onto the page.
That conversation is now happening at every company that has to file a sustainability statement, and it is the conversation that decides whether the assurance opinion gets signed.
What changed for 2026
Wave 1 companies, the large public-interest entities already inside the Corporate Sustainability Reporting Directive, are publishing fiscal-year 2025 sustainability statements in 2026, and those statements carry a limited-assurance opinion. The EU’s Omnibus simplification package trimmed scope and pushed deadlines for later waves, but it did not let Wave 1 off the hook, and it kept assurance in place. It also removed the planned escalation from limited to reasonable assurance, so limited assurance stays the standard indefinitely. The assurance work itself is converging on the IAASB’s ISSA 5000 framework, the international standard built specifically for sustainability information.
“Limited” is doing a lot of misleading work in that phrase. A limited-assurance engagement is lighter than a full financial audit in the level of comfort it expresses, but the assurance provider still has to design procedures, test how numbers were produced, and decide whether anything makes the statement materially misstated. And the procedure that trips up AI-assisted reporting is the most basic one: trace this figure back to its source.
Why AI makes the provenance question harder, not easier
Plenty of ESG teams now lean on AI to pull numbers out of utility invoices, supplier questionnaires, ERP exports, and last year’s spreadsheets, then to summarize and assemble disclosures. The output reads cleanly. The problem is what sits underneath it.
A language model that reads a PDF energy bill and reports a consumption figure has, in most setups, left no durable record of which line on which document it read, what it did to that value, or whether the document it read is the same version the auditor will be handed three months later. The figure exists. The chain of custody does not. When an assurance provider asks “show me the source for this number,” a screenshot of a chatbot answer is not a source. It is a claim about a claim.
There are three specific failure points auditors probe:
- The source moved. The supplier resubmitted data, the ERP was re-extracted, someone corrected a unit error. The AI answered against version one; the report shows version three; nobody can say which version the disclosed figure reflects.
- The math is opaque. An emissions factor was applied, currencies were converted, a partial year was annualized. If the calculation lived inside the model’s reasoning rather than an explicit, inspectable step, it cannot be re-run and confirmed.
- The edit is invisible. A human nudged a number after the model produced it. Sensible, maybe. But with no timestamped log of who changed what and when, the assurance team treats the whole figure as unverifiable.
Each of these is survivable for one metric. Across a few hundred ESRS datapoints, they compound into an opinion the auditor cannot comfortably sign.
What “auditable” actually requires
Strip away the ESG-specific vocabulary and assurance providers are asking for the same four things any controller would ask of a closing process: data lineage, governance, documentation, and consistency. For AI-assisted figures, that translates into concrete mechanics.
Versioned sources. Every input, the invoice, the export, the questionnaire, has to be captured as a fixed, identifiable version at the moment a figure is derived from it. When the source changes, that is a new version, and the disclosed number is bound to the one it was actually built on. This is the same discipline the German GoBD regime has demanded of financial records for years, now arriving in sustainability data.
Reproducible calculations. The step that turns kilowatt-hours into tonnes of CO2, or local-currency spend into a comparable base, has to be an explicit operation that runs the same way every time, not a one-off inference buried in a prompt. Give the auditor the inputs and they should land on the identical output.
A complete audit trail. Source version, calculation performed, the figure produced, and every subsequent edit, all timestamped, all attributable. This is the artifact that converts “trust us” into “here, check it.” We have written more on what a real audit trail for AI in finance has to contain, and the requirements are not negotiable for assurance work.
Where the deterministic engine matters
This is the distinction we keep coming back to at Rexfin, because it is the one that separates an AI demo from something an assurance team will accept. The language model is excellent at finding the right number and understanding what is being asked. It is the wrong tool for computing the number.
Rexfin connects to the systems your data already lives in, accounting platforms, ERPs, warehouses, or uploaded statements and disclosures, and builds one reconciled model that ties out to the underlying records. When a figure is needed, the AI retrieves it; a separate, deterministic calculation engine does the arithmetic, the same way every time. Every result traces back to a versioned source and the exact operation that produced it. The model never quietly does math in its head and hands you a confident guess. That architecture is the whole point of running the math through a deterministic engine instead of the LLM, and it is what makes a disclosed figure defensible rather than merely plausible.
It is worth being honest about the limits. None of this judges whether your emissions methodology is sound or your materiality assessment is complete; those are decisions your team owns. What the architecture guarantees is narrower and, for an assurance opinion, more useful: that whatever number you disclose can be traced, reproduced, and shown to be unchanged since it was produced.
The takeaway
The 2026 assurance season is the first real test of whether AI-assisted sustainability reporting can survive scrutiny. The companies that pass will not be the ones with the most impressive AI. They will be the ones who can answer “where did this number come from” without flinching, for every figure on the page, on the first ask. If your current ESG tooling produces clean answers but no chain of custody, you have a 2026 problem that no amount of methodology work will fix.
If you want to see what versioned sources, a deterministic calculation engine, and a cell-to-source audit trail look like against your own numbers, book a demo and bring the figure your auditor is most likely to question.
Part of AI in Finance, Audit-Proof: GoBD- and AI-Act-Defensible Models With Traceable Numbers