
If you say the directors meet quarterly to discuss climate risks, then you actually have to have that as an agenda item, and it has to be minuted in the board minutes.
"A lot of companies have been surprised at the level of evidence that the auditors are asking for."
René Muller, audit partner, SW Accountants and Advisors
René Muller is an audit partner at SW Accountants and Advisors. She has worked with clients on sustainability reporting for the last four years, on both sides of the line: assurance for audit clients, and consulting work helping companies prepare reports and calculate emissions. She has now been through a full cycle of Group 1 assurance.
So what should Group 2 and Group 3 do differently?
Group 2 reporting began for financial years starting on or after 1 July 2026, and Group 3 follows from 1 July 2027. Six things René would tell a finance leader starting now:
René's summary of what happens when companies do the work properly: "To see that it's not just a compliance obligation, but it's actually a practical tool for helping manage risks has been a really great thing to be part of."
Under the ASRS, climate disclosures sit inside the annual report or sustainability report and are subject to external assurance, phasing in from limited assurance to reasonable assurance in the early years. The governance disclosures are assured in full from the start, which is why evidence has been the pressure point for Group 1.
Group 1 reported for financial years starting on or after 1 January 2025. Group 2 is in its first reporting year now. Group 3 follows from 1 July 2027. René's Group 1 client base spans sectors already some way into a sustainability journey, mining and agribusiness among them, and companies that have never reported on emissions at all.
We asked René what assurance actually tests, where Group 1 came unstuck, and what she would tell a business starting now. Her answers follow.
"We can't just look at the climate risk identification as a standalone item. It forms part of the scenario analysis, and it also forms part of governance and the resilience of the business."
René Muller, audit partner, SW Accountants and Advisors
The risk register is not a deliverable we assess in isolation. It sits inside the scenario analysis, and it sits inside the question of how well governed the business is and how resilient it is to the risks it has identified.
From there we look at the systems, processes and controls behind identifying and documenting climate risks and opportunities. How did the risks get found? Who reviewed them? What happens to them once they are on the register?
Only once we understand that do we turn to what has actually been captured as a climate risk, and what has been reported as material. That last part means we also need to understand your materiality assessment: how you went about it, and what you consider material to the sustainability report. A risk register with no documented method behind it is difficult to assure, however sensible its contents are.
"Anything you put in it has to have some sort of evidence."
René Muller, audit partner, SW Accountants and Advisors
The level of evidence has surprised a lot of companies. The governance section is subject to assurance in full, so anything in it has to have some sort of evidence behind it.
The example I keep coming back to: if you say the directors meet quarterly to discuss climate risks, then you actually have to have that as an agenda item, and it has to be minuted in the board minutes. A statement in the report is not evidence that the meeting happened.
The same applies to capability. Clients often tell us their directors or management have been trained in sustainability reporting, and then there are no training records to support it. The claim is usually true. The evidence is missing, and for assurance purposes that comes to the same thing.
The level of supporting detail has caught some clients out, and they may not have everything evidenced appropriately to pass assurance. That is an expensive position to be in late in the year, because you cannot write minutes retrospectively.
The Corporations Act also requires companies to keep their sustainability records for seven years. So the advice is simple: evidence everything you put in the report, build the audit trail, and keep it for seven years.
"The number one thing I would do is make sure that you have buy-in from everyone across the organisation."
René Muller, audit partner, SW Accountants and Advisors
Directors need to be on the sustainability journey, you need a management team responsible for it, and you need clearly defined roles and responsibilities so everyone knows who owns what.
Then get across your carbon emissions for Scope 1 and 2 reporting. It is actually quite straightforward to do once you know what you are doing, but it can take a while to get there. The boundary assessment takes time and pulling the data together takes time.
It is also a big piece of the reporting that you can knock over early, which frees you up to focus on other areas later in the year. Alongside that, you need a clear project plan, a timetable, and those clearly defined roles and responsibilities.
"Clients kind of have a light bulb moment when they realise just how actually invaluable it is in a practical sense, to know what their climate risks are, to know what their climate opportunities are."
René Muller, audit partner, SW Accountants and Advisors
There is a wide variety of attitudes towards climate reporting. Companies in sectors like mining and agribusiness are already some way into a sustainability journey and understand what is required and why. Companies that have never reported on emissions or sustainability find it a very new area, and there is significant upskilling to do.
What has surprised me most is how those attitudes shift as companies work through identifying their climate risks and testing how resilient the business actually is to them.
Clients have a light bulb moment when they realise how invaluable it is in a practical sense to know what their climate risks are, to know what their climate opportunities are, and to then go and manage or capitalise on them.
To see that it is not just a compliance obligation, but that it is actually a practical tool for helping manage risks, has been a really great thing to be part of.
The remainder of this post is written by the Trace team. René's interview ends above.
In the audit process, two key things are under scrutiny.
The first is completeness. Every disclosure the standard requires, present and addressed. This is what the disclosure checklists exist for, and it is the mechanical half of the job.
The second is traceability, and it is where first-year reporters come unstuck. Every statement in the report needs a path back to a source. The claim about quarterly board discussion traces to an agenda item and a minute. The training claim traces to a training record. The risk register traces to a documented method and the people who applied it. The materiality judgement traces to an assessment someone can explain.
Notice what is not on that list. Nobody is asking whether your modelling is sophisticated or your forecast is correct. A simple method that is documented, consistently applied and understood is worth more under assurance than a complex one nobody can walk through.
Most of the market for ASRS support is newer than the standard itself. If you are choosing a partner or a platform for your first year, these three questions separate them quickly.
1. Have your outputs been through assurance, and what did the assurer say about them?
Not whether their clients passed, but what the auditor said about the work itself. Anyone who has genuinely been through it will have specific feedback to share, and probably a story about what the assurer pushed back on.
2. Have your tools and templates been reviewed by auditors?
Reviewed, not simply used. A provider who has sat down with assurance teams and had their methodology picked apart will produce outputs that survive the same treatment at your place.
3. How does AI work in your product, and can you show me how it reached a conclusion?
This is a traceability question, not a technology question. If a tool produces a risk or a number and nobody can explain how, you have bought something you cannot evidence. Ask to see the working.
If you want to put those questions to us, book a 30 minute ASRS readiness call.
The risk register is never assessed in isolation. Assurers test it through the scenario analysis, the governance arrangements and the resilience of the business. They look at the systems, processes and controls behind how risks were identified and documented, then at what was captured as a risk and what was reported as material, which pulls in your materiality assessment.
Yes, and in full from the first reporting year. That is why evidence has been the pressure point for Group 1 reporters. Every statement in the governance disclosures needs supporting evidence behind it, not just a plausible account of what the business does.
Documentary support for each claim. If the report says directors meet quarterly to discuss climate risk, assurers expect a board agenda item and a minute recording it. If it says directors or management have been trained in sustainability reporting, they expect training records. A true claim with no evidence behind it fails assurance the same way a false one does.
Seven years, under the Corporations Act. That covers the records supporting your sustainability report, not only the report itself. In practice it means building the audit trail as you go, because minutes cannot be written retrospectively and reconstructing evidence for a closed reporting period is either expensive or impossible.
Group 2 applies to financial years beginning on or after 1 July 2026, so those entities are in their first reporting year now. Group 3 follows from 1 July 2027. Group 1 began with financial years starting on or after 1 January 2025.
Trace is a climate reporting platform specialising in ISSB and AASB standards, helping businesses navigate mandatory climate disclosure with clarity and confidence.