

Sep 27, 2026 · 15 min read
Governance
Impact reporting must be traceable, controlled, and board-reviewed: scope, data, controls, remediation, repeat.
If an impact claim cannot be traced to source records, tested controls, and board review, I would not treat it as ready for public use. That is the core point. This article shows a five-part cycle: set scope, check data, test controls, route findings, and review results at the board level.
In plain terms, I see three big problems firms run into:
Claims that do not trace back to source files
Metric definitions that shift between teams or reports
Weak ownership over data, methods, fixes, and approvals
The article’s answer is simple and strict:
Define what is in scope and what is out
Match the depth of review to risk and use
Trace each material figure to source evidence
Test approvals, timing, accuracy, and role separation
Classify issues and track them to closure
Put the board or committee into the review cycle each reporting round
A few points stand out. Annual disclosure plus periodic outside verification is becoming standard practice in impact management. The article also draws a hard line between facts, estimates, and forecasts. That matters because a number like 12,500 metric tons means little if no one can show the method, source data, approval trail, and any changes made along the way.
For me, the main lesson is clear: impact reporting is not just a writing task. It is a system of data, controls, evidence, issue tracking, and oversight. If one link fails, the claim weakens fast.
Below, I condense the article into the main actions you need to understand before putting impact results in front of investors, committees, or the public.
5-Step Impact Assurance Cycle for Investment Operations
Testing without a written scope undercuts credibility. A scope statement agreed on before fieldwork starts keeps the review within clear bounds and makes impact claims testable, not just neatly described. Once that boundary is set, the team can test data and controls against it.
The scope memo should spell out the subject, boundary, period, criteria, data sources, and intended users. If the boundary is vague, claims become hard to verify. Say plainly whether assurance covers the full investment platform or only selected funds, and whether the review addresses reported impact results or the processes that produced them. Any exclusions should be documented with a clear reason and disclosed to intended users.
To set the boundary, start with an inventory of investment vehicles and classify them by assets under management, strategy, geography, impact goals, data availability, and materiality. Include entities that matter to aggregate impact claims, even when a third party manages them. For instance, if a firm reports portfolio-wide emissions reductions, it should state whether the calculation includes minority investments and co-investments.
Across the investment lifecycle, the scope should follow the full path where relevant: strategy and fund design, origination, due diligence, investment approval, impact target-setting, portfolio monitoring, engagement, exit decisions, and post-exit impact considerations. It also helps to separate process, output, outcome, and attribution claims. Those categories are not interchangeable, and blending them creates gaps that are tough to fix later.
Impact themes should cover both intended outcomes and material harms. Leaving harms out weakens the claim. The scope should define metric terms, baseline year, target year, attribution method, and any thresholds that apply. Assurance needs to cover both favorable outcomes and material harm - a fund that leaves negative impacts outside scope produces decision-grade reporting that is incomplete by design. Before fieldwork begins, build a scope-to-evidence matrix with one row for each material claim, showing the source record, responsible owner, expected control, testing procedure, and treatment of missing or estimated data.
With the scope set, the next step is deciding how much assurance the claim needs.
Not every metric or fund calls for the same level of scrutiny. The right depth depends on the risk of misstatement, how the information will be used, and whether it feeds high-stakes decisions such as fundraising, compensation, or regulatory reporting. In many cases, a staged approach works well: limited assurance for broad portfolio reporting or early-stage systems, then deeper or reasonable assurance for high-risk funds, incentive-linked metrics, or public commitments.
| Area | Limited Assurance | Reasonable Assurance |
|---|---|---|
| Testing depth | Inquiry, analytical review, walkthroughs, and targeted testing | More extensive substantive testing, control testing, recalculation, corroboration, and sampling |
| Evidence required | Sufficient to support a negative-form conclusion | Sufficient to reduce assurance risk to an acceptably low level |
| Direct verification | Selected source tracing and plausibility checks | Broader source tracing, independent recalculation, confirmations, and site or portfolio-company procedures where relevant |
| Control evaluation | Understand and assess key controls, with selective testing where necessary | Test relevant controls in greater depth and combine control testing with substantive procedures |
| Conclusion style | "Nothing has come to our attention that indicates the information is materially misstated" | "In our opinion, the information is fairly stated, in all material respects, in accordance with the criteria" |
| Suitable use | Early-stage systems, lower-risk disclosures, or periodic review | High-risk or high-materiality claims, investor-facing reporting, regulatory commitments, or board-critical information |
Each assurance level calls for different evidence and procedures, and those procedures should be built around the risks in the engagement.[2][4] When metrics sit at the center of fundraising, carried-interest calculations, covenants, regulatory reporting, public commitments, or board decisions, it may make sense to expand the scope or use a higher assurance level.[1][3] The scope memo should state the assurance level clearly, along with any limits.
After scope is set, the work shifts to tracing data and testing controls.
Once scope and assurance depth are set, the next job is simple to say and harder to do: trace every material metric back to where it came from and test the controls that keep it intact.
Start with the number that appears in the report, then work backward. A reviewer should be able to follow a clean trail through the calculation file, portfolio-company submission, source system, and underlying support. If a portfolio reports 12,500 metric tons of avoided carbon dioxide equivalent, the reviewer should verify the activity data, emissions factor, formula, unit conversion, and management approval using documented evidence only. If that chain breaks even once, the claim is not yet assurable.
Accuracy is only part of the story. Completeness checks matter just as much. Reconcile the reporting population to the investment register so you can spot missing entities, duplicate submissions, or changes in scope. Confirm that every required field is filled in, that reporting periods match, and that the same metric definition is used the same way across portfolios and years.
Formula reviews need close attention. Go through calculation workbooks line by line. Check accuracy, locked cells, linked inputs, rounding logic, and error handling. Reperform material calculations on your own and reconcile totals to approved portfolio schedules. Use one numeric format throughout: $1,250,000, not 1,250,000 or $1,250; write dates as September 27, 2026. Assumptions such as emissions factors, attribution rates, and baseline conditions should be documented, current, approved, and used the same way across the portfolio.
Methodology version control sits right beside this work. Keep a controlled methodology register that records the metric definition, framework or standard used, formula, data sources, effective date, and approving authority. When a method changes, document the reason, the metrics affected, the transition date, and whether earlier periods need restatement. Keep prior versions archived so earlier reports can still be reproduced.
Once the source trail holds up, move to the controls that protect it.
Use inquiry, inspection, observation, sampling, analytical review, and reperformance to test each control. The point is not just to see whether a control exists. You need to know whether it was built to address the risk and whether it actually operated on time, by the right person, with evidence kept. A control that looks fine on paper but was not performed on schedule is not an operating control.
Four areas need direct attention:
Authorization: Check whether metric definitions, assumptions, adjustments, and final disclosures were approved by the people assigned to approve them.
Accuracy: Confirm that calculations, inputs, and reconciliations were reviewed and re-performed where needed.
Timeliness: Verify that portfolio companies submitted data by the deadline, that late submissions were flagged, and that reporting cutoffs were applied the same way each time.
Segregation of duties: Make sure one person cannot enter, change, approve, and publish the same data without an independent review. Access reviews should cover spreadsheet permissions, reporting platforms, and portfolio-company submission portals.
Controls tied to negative impacts need plain, direct testing. Set escalation thresholds before fieldwork begins. That may include a material increase in emissions, injuries, excluded beneficiaries, or signs that an outcome is being double-counted. Then test whether the control catches the issue, records it, assigns an owner, and notifies the proper risk or investment committee before any claim is published. Negative-impact findings should not be buried in aggregate results or offset automatically by positive outcomes.
Map each material risk to the control that prevents, detects, or escalates it.
| Risk | Control Objective | Control Activity | Evidence Retained | Control Owner | Testing Method | Remediation Trigger |
|---|---|---|---|---|---|---|
| Portfolio company omits a required metric | Ensure reporting population is complete | Reconcile portfolio register to submitted files each cycle | Reconciliation, population listing, exception log, reviewer sign-off | Impact data manager | Inspection and reperformance | Any unexplained omission or duplicate |
| Metric calculated using incorrect formula | Ensure reported values are accurate and reproducible | Independently review formulas and reperform material calculations | Versioned workbook, formula review, recalculation evidence | Impact measurement lead | Inspection and reperformance | Formula error or unexplained result |
| Units differ across investments | Ensure comparable units are used | Validate units and approved conversion factors during data intake | Data dictionary, validation report, conversion table | Data quality owner | Inspection and analytical review | Unapproved unit or failed conversion |
| Methodology changes without approval | Ensure methodological changes are controlled | Require documented change request, impact analysis, and approval before implementation | Change request, approval, version history, restatement analysis | Methodology owner | Inquiry, inspection, and reperformance | Unapproved or undocumented change |
| Management review is incomplete or late | Ensure exceptions are identified and resolved before reporting | Require documented review of variances, estimates, and late submissions | Review checklist, comments, approvals, issue log | Portfolio reporting manager | Observation and inspection | Missing, late, or unresolved material exception |
| One person can enter and approve data | Prevent unauthorized changes or self-approval | Separate preparation, review, approval, and publication privileges | Role matrix, access report, approval trail | Systems or compliance owner | Inspection and observation | Conflicting access or self-approval |
| Negative impact is not escalated | Ensure adverse outcomes affect decisions and disclosures | Apply predefined thresholds and escalate material incidents to governance | Incident record, escalation notice, committee minutes | Risk or impact committee chair | Inquiry, inspection, and sampling | Threshold breach without documented escalation |
| Prior-period data cannot be reproduced | Preserve an auditable reporting history | Archive finalized datasets, source evidence, formulas, and methodology versions | Controlled archive, retention log, retrieval test | Records or reporting owner | Inspection and retrieval reperformance | Missing, altered, or unretrievable evidence |
Every finding from control testing should be classified by severity, assigned to an owner, and tracked to closure. Retesting should follow; a simple management statement that the issue was fixed is not enough. Repeated, overdue, or high-severity findings should move up the reporting line to senior management, the relevant committee, and the board where appropriate.
Classify findings, assign owners, and route unresolved issues into formal reporting lines and remediation.
Once a finding hits its remediation trigger, it should move right away. That only works if the reporting chain is already set. People who spot problems need a direct path to the people who can approve fixes, assign budget, and make sure teams follow through.
The IIA's Three Lines Model separates ownership, oversight, and independent review.
Use the Three Lines Model to assign ownership, oversight, and independent review.
| Role | Primary responsibility | Reporting path |
|---|---|---|
| Investment and impact teams - first line | Maintain source records, execute processes, perform routine checks, and own day-to-day controls | Escalate exceptions to the second line |
| Risk, compliance, or impact governance - second line | Set requirements, monitor compliance, challenge assumptions, review exceptions, and coordinate remediation | Receives first-line issues and escalates material issues to executive management |
| Internal audit - third line | Independently assess governance, risk management, data controls, and remediation effectiveness | Reports findings through senior management and the audit or risk committee |
| Executive management | Prioritize findings, approve corrective actions, allocate resources, and accept residual risk | Escalates material issues to the relevant committee or board |
| Audit, risk, or sustainability committee | Oversee the assurance framework, review material findings, challenge management, and monitor overdue remediation | Provides oversight for material issues and escalates as needed to the full board |
In plain terms, escalation should move from the operational owner to the second line, then to executive management, the committee, and, for material issues, the full board. Internal audit should report functionally to the audit or risk committee, not to the managers whose work it reviews. That independence matters.
In practice, the internal-audit charter should give the chief audit executive direct access to the committee chair, the right to attend closed sessions, and unrestricted access to records and personnel. A responsibility matrix should also spell out who owns each control, who reviews it, what evidence must be kept, who receives escalations, and who gives final approval. The board, or the right committee, provides oversight, approves the assurance mandate, and holds management to account for fixing major issues.[6]
Severity should reflect the risk to impact claims, reporting accuracy, compliance, and investor decisions.
| Finding severity | Typical characteristics | Escalation threshold | Response expectation and target timing | Committee or board visibility |
|---|---|---|---|---|
| Minor exception | Isolated deviation, low likelihood of misleading a stakeholder, no evidence of systemic failure, and an effective compensating control | Escalate to the process owner and second-line reviewer; combine recurring exceptions for trend analysis | Correct promptly, typically within 30–60 days; document evidence of completion | Include in periodic management reporting; committee visibility if recurring or overdue |
| Significant deficiency | Repeated or widespread failure, unreliable supporting evidence for a material metric, ineffective review control, or a weakness that could materially affect decisions | Escalate to the responsible executive, risk or compliance leader, and internal audit; assess whether disclosure or metric restatement is needed | Establish a documented remediation plan, interim control, named owner, resources, and target date, typically within 30–90 days | Report to the relevant audit, risk, or sustainability committee at the next scheduled meeting, or sooner if material |
| Critical issue | Suspected intentional misstatement, potential fraud, severe data-integrity failure, inability to support a material impact claim, major legal or regulatory exposure, or failure affecting multiple funds or reporting periods | Immediate escalation to executive management, the committee chair, general counsel or compliance leadership, and internal audit; preserve evidence and restrict unsupported reporting | Triage within 24 to 72 hours, implement interim safeguards immediately, and set a senior-management-approved remediation program; consider investor, regulator, or contractual notification | Prompt board or committee notification, with continuing updates until containment, remediation, and independent validation |
Once severity is set, the next step is closing the issue through remediation. A minor exception may call for a prompt fix and a record showing it was done. A significant deficiency needs more: a written remediation plan, an interim control, a named owner, assigned resources, and a due date. A critical issue needs fast triage, immediate safeguards, and close attention from senior management and the board.
A finding should be closed with evidence, not management assertion. The control owner submits documentation. The second line checks whether the corrective action fixes both the finding and its root cause. Internal audit, or another suitably independent reviewer, should then confirm operating effectiveness when the issue is significant or critical.[7]
New controls should not be marked closed until they have run through a full reporting cycle. If actions go past due, they should stay open and be reported at their original severity, along with the revised due date, the reason for delay, and the interim risk response.
Board oversight should stay fixed on what is still open, what is overdue, and what management has accepted. A board dashboard should show open findings by severity, overdue items, repeat findings, and residual risk accepted by management.
Once findings are logged and fixes are under way, board review answers a simple but hard question: Is the assurance system working as intended? This review should sit inside the normal governance rhythm, not show up once a year as a box-checking exercise. It is a standing control across the investment and reporting cycle.
Each review cycle should rely on the same evidence trail built during testing and remediation. The board, or a designated committee, should confirm that the impact strategy still fits the fund's mandate, investment thesis, theory of change, and stated beneficiary and environmental objectives. The review should also cover material impact risks, target performance, negative-impact events, data-quality exceptions, control-testing results, assurance limits, key judgments, methodology or boundary changes, and the status of corrective actions.[8][5]
Board materials need to draw a sharp line between verified facts, management estimates, and forecasts. Those are different categories, and when they blur together, directors have a harder time judging whether a public claim is backed by the evidence trail. The board should be able to trace any public claim back through the full record: underlying portfolio activity, source records, calculation method, approvals, and the final reporting output. If that trail has gaps, the claim is not ready to publish.[5][10]
Assurance validates reported data and controls; it does not guarantee future impact outcomes.
The best way to keep board review useful is to tie it to a repeatable operating cycle instead of treating it as a one-off event. Use a fixed cycle: plan, operate, test, report, improve, repeat.[8][9][5]
That keeps assurance connected to day-to-day operations, not just annual reporting.
Reliable impact claims rest on clear scope, verified data, tested controls, documented remediation, and board oversight. If one link weakens, the claim weakens with it.
Start with a materiality assessment. That helps you pinpoint the ESG issues that matter most for your sector, your fund goals, and your reporting duties. Once that’s clear, review your sustainability disclosures and flag the quantitative metrics and qualitative statements that may need assurance.
Give priority to data with the highest risk of material misstatement. In most cases, that includes GHG emissions, workforce metrics, and environmental impact data. If the full scope feels too big to tackle at once, take a phased approach. Just make sure you document the reasoning behind your scope choices so the process stays clear and defensible.
An impact claim becomes audit-ready when you treat sustainability data with the same discipline used in financial reporting. That means every figure you report should trace back to source records - things like invoices, meter readings, or survey responses.
Just as important, the process around the data needs to be documented. That includes how the data was collected, how it was checked, who approved it, and which methods or assumptions were used when estimates came into play. Internal controls matter here. Automated range checks and multi-level approvals help keep the data accurate, complete, and consistent.
The board should review impact reporting at least quarterly, with a deeper review annually.
This work should sit on the board’s standing agenda, not show up once a year and then disappear. At each meeting, the audit or ESG committee should look at reporting progress, assurance findings, and new regulatory developments.

FAQ