Join our Newsletter — 33% off our NHI Course

Why do AI systems create assurance risk in CSRD reporting when they aggregate ESG data?

AI creates assurance risk because it can obscure how a disclosed metric was produced. Auditors need to trace the calculation path, confirm the underlying data is reliable, and see that validation and approval controls operated during the period. If lineage, version history, or test evidence is missing, the organisation may not be able to defend its disclosures.

Why AI-Driven ESG Aggregation Creates Assurance Friction

CSRD reporting depends on being able to show how a figure was built, not just that the final number looks reasonable. When AI aggregates ESG data, it can combine source records, infer missing values, normalise categories, and draft disclosures in ways that are efficient but hard to explain line by line. That creates assurance risk because auditors need a defensible trail from source to disclosure, including who approved the logic and whether the model output was reviewed against policy and evidence. This is especially important where sustainability data comes from many systems, entities, or manually entered inputs that are already uneven in quality.

AI also changes the control question from “was the number produced?” to “can the organisation prove how it was produced at the time it was reported?” If the workflow does not preserve lineage, model version, prompt or rule changes, and validation evidence, the report may be operationally useful but weak under assurance. A practical reference point is the NIST Cybersecurity Framework 2.0, which emphasises governed, traceable security and risk management across systems that handle material business information. In practice, assurance gaps usually surface after the disclosure is already circulated, when the evidence needed to reconstruct the calculation path is incomplete.

The challenge is not that AI is inherently unsuitable for CSRD work; it is that automated synthesis can outrun the organisation’s ability to explain and verify the result. Where data quality is mixed, the AI layer can hide uncertainty instead of exposing it. That is why disclosure teams need controls that preserve provenance, not just productivity.

How AI Changes the Control Model for ESG Data

AI-assisted ESG aggregation often sits between source systems and the published report. It may collect energy, workforce, emissions, or supplier data, reconcile duplicates, map fields to a reporting taxonomy, and produce the narrative used in the filing. Each of those steps can be legitimate, but each also introduces a point where assurance evidence can be lost unless the process is designed to retain it.

The main control issue is traceability. Auditors and internal reviewers need to know which source records fed the metric, what transformation rules were used, which model or workflow version ran, whether exceptions were flagged, and who approved the final output. If the AI is allowed to infer missing values or convert inconsistent labels without storing the rationale, the organisation may end up with a figure that is operationally consistent but not auditable. The same problem appears when the model is updated during the reporting period and the output changes without a versioned comparison.

Practically, this means the reporting process should preserve a chain of evidence across three layers:

  • source evidence, including original records and their timestamps
  • transformation evidence, including mapping rules, validation checks, and exception handling
  • approval evidence, including human review, sign-off, and any overrides

AI governance guidance from NIST AI RMF is useful here because it frames reliability, accountability, and traceability as operational requirements rather than abstract principles. For organisations building structured AI controls, the OWASP NHI Top 10 also highlights why machine credentials and workflow access must be tightly governed when automated systems move data across reporting environments. Where machine access is poorly scoped, the reporting chain can be altered without leaving a clear accountability trail. If you want a practical primer on the governance implications of identity and access in automated workflows, see Top 10 NHI Issues and NIST Cybersecurity Framework 2.0.

These controls tend to break down when ESG data is stitched together from spreadsheets, shared drives, and ad hoc model outputs because the organisation cannot reconstruct the exact reporting path after the fact.

Where Assurance Breaks Down in Practice

Tighter automation can improve consistency, but it also increases the risk that unresolved data quality issues are carried forward at scale. The difficult cases are usually not simple calculation errors. They are situations where the AI has made a judgement call that looks plausible, such as mapping one business unit’s category to another, smoothing a missing value, or merging duplicate supplier records without preserving the exception logic.

Current guidance suggests several edge cases deserve special attention. First, if the organisation uses an AI system to draft narrative disclosures from structured inputs, the narrative itself becomes part of the assurance surface and should be reviewed like a controlled reporting artifact. Second, if data is aggregated across subsidiaries or jurisdictions, the reporting team needs to confirm that local source definitions still match the consolidated metric after normalisation. Third, if the model is retrained or the rules are tuned late in the reporting cycle, the organisation may lose comparability with earlier working papers unless the prior version is retained.

One NHIMG research point underscores why this matters operationally: the Ultimate Guide to NHIs — Key Research and Survey Results reports that 72% of organisations have experienced or suspect they have experienced a breach of non-human identities. That statistic is not about CSRD itself, but it is relevant because AI reporting workflows often depend on machine identities, tokens, and service access to move data between systems. Where those access paths are weak, assurance risk and security risk reinforce each other rather than staying separate.

In practice, the hardest failures are not the ones that produce obvious nonsense; they are the ones that produce a polished disclosure with incomplete evidence behind it.

Risk and Threat Considerations

AI-aggregated ESG reporting creates a material assurance and integrity risk because the organisation may be unable to demonstrate that the disclosed metric was faithfully derived from source evidence. The exposure is greatest where AI systems infer, normalise, or reconcile data without preserving a defensible audit trail, because the final number can look stable while the underlying basis remains unverified.

Failure mechanism: The risk materialises when lineage, version history, validation output, or approval evidence is missing or overwritten, making it impossible to reconstruct the calculation path. If automated workflows have excessive access or weak change control, they can also move, transform, or approve reporting data without clear attribution.

Impact: The organisation may fail assurance review, be forced to restate disclosures, or lose confidence in the reliability of its ESG reporting. In more complex environments, the same weakness can also expose broader control failures in data governance and machine access management.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST AI RMF, CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST AI RMF GOVERN — Govern AI aggregation needs accountable, traceable governance over reporting decisions.
MAP — Map CSRD aggregation risk depends on understanding where AI touches data and decisions.
MEASURE — Measure Assurance depends on testing reliability, traceability, and control effectiveness.
Recommendation — Define AI reporting accountability and retain evidence for model-driven ESG outputs. Map AI use cases, inputs, outputs, and failure points in ESG reporting workflows. Measure traceability and validation quality for AI-produced disclosure figures.
CIS Controls v8 6 — Access Control Management AI reporting workflows rely on governed access to source data and reporting systems.
8 — Audit Log Management Auditors need logs showing how ESG data was transformed and approved.
Recommendation — Restrict and review access paths used by AI reporting and aggregation jobs. Preserve logs and change records for AI-driven ESG calculations and approvals.
OWASP Non-Human Identity Top 10 NHI-03 — Secrets and Credential Management Automated reporting often depends on machine credentials that must be controlled.
NHI-05 — Workload Identity and Access AI systems acting on reporting data need bounded non-human access and attribution.
Recommendation — Rotate and scope machine credentials used by AI ESG pipelines. Bind AI reporting actions to workload identity with least-privilege access.
NIST CSF 2.0 GV.OV — Oversight CSRD assurance needs oversight of reporting controls and evidence quality.
PR.DS — Data Security ESG source data and derived outputs must stay protected and verifiable.
Recommendation — Set oversight checkpoints for AI-assisted ESG disclosures and evidence retention. Protect ESG source data and derived reports against unauthorised alteration.

Practitioner Guidance

What to prioritise: Treat lineage and version control as first-class assurance controls, not technical extras. If an AI step influences a disclosed metric, require a record of source inputs, transformation logic, model version, and the reviewer who accepted the output.

Decision rule: If a disclosure cannot be reconstructed from retained evidence, do not rely on the AI output as an assurance-ready figure. Use it only as a draft until the calculation path, exception handling, and approval trail are complete.

What to verify: Confirm that the reporting process can answer three questions without manual reconstruction: what data entered, what the AI changed or inferred, and who approved the result. If any one of those answers depends on memory or ad hoc files, the control design is too weak for assurance.

Practitioner takeaway: The core issue is not whether AI helps prepare ESG reporting; it is whether the organisation can still prove the report’s origin, logic, and approval after automation has done its work.