BRSR and ESG Internal Audit Checklist: Controls, Evidence and FY 2026-27 Readiness
BRSR and ESG internal audit reviews whether sustainability disclosures are supported by reliable source data, clear owners, consistent calculation methods, documented controls and evidence strong enough for management, the Audit Committee and external assessment or assurance providers. For FY 2026-27, this matters because SEBI's BRSR Core glide path reaches the top 1000 listed entities, and the current SEBI wording requires assessment or assurance of BRSR Core disclosures.
The internal audit role is not to sign the BRSR assurance report. The role is to test readiness: whether the company can produce complete, accurate and consistent ESG data before year-end pressure begins.
BRSR internal audit checklist
| Area | Internal audit test |
|---|---|
| Governance | Check Board/committee oversight, ESG owner, reporting calendar and approval workflow |
| Applicability | Confirm listed-entity status, market-cap rank, BRSR Core phase and value-chain expectations |
| Metric ownership | Map every BRSR Core data point to a process owner and source system |
| Source data | Test meter readings, payroll exports, safety logs, waste records, invoices and system reports |
| Calculation logic | Review formulas, assumptions, conversion factors, boundaries and prior-year consistency |
| Data controls | Test maker-checker review, change logs, reconciliations and exception sign-off |
| Evidence file | Verify whether each KPI has retained support, not only a final number |
| Site coverage | Check whether factories, branches, warehouses and offices are included or validly excluded |
| Value chain | Review supplier/customer data process where applicable or voluntarily reported |
| Assessment / assurance readiness | Identify gaps that would block external assessment or assurance, or require management representation |
The checklist should be tailored to the sector. A manufacturer has different ESG evidence risk from a software company, hospital, logistics business or NBFC.
Why internal audit should start before year-end
ESG data is not produced by one department. It sits across EHS, HR, finance, procurement, legal, facilities, plant operations, security, payroll, contractors and vendors. Waiting until annual-report drafting starts creates predictable gaps:
- Missing meter readings
- Manual spreadsheets with no preparer/reviewer trail
- Contractor worker data not reconciled
- Waste vendor certificates not retained
- Incident logs not tied to reported safety numbers
- GHG emission factors changed without approval
- Site-level exclusions not documented
- Prior-year methodology not followed consistently
Internal audit can reduce this risk by testing the ESG data process during the year, not after disclosure numbers are already final.
BRSR Core evidence areas
SEBI's BRSR Core framework covers a smaller externally assessed or assured subset within the wider BRSR. Internal audit should focus on evidence quality for that subset first.
| ESG area | Evidence examples |
|---|---|
| Greenhouse gas emissions | Fuel invoices, electricity bills, meter readings, emission factors, calculation workbook and turnover reconciliation |
| Water | Municipal bills, borewell logs, tanker invoices, recycling records, ETP/STP records and permissions |
| Waste | Hazardous waste manifests, recycler certificates, disposal invoices, EPR records and waste registers |
| Energy | Electricity bills, renewable-energy certificates, captive generation records, conversion factors and plant logs |
| Employee wellbeing | HR master, payroll, benefits records, training logs, health/safety records and worker registers |
| Gender diversity | HR/payroll data by category, Board/KMP records, contractor workforce data and reconciliation |
| Safety | Incident register, near-miss log, lost-time injury records, investigation files and corrective action |
| Complaints and grievances | Customer, employee, investor and value-chain grievance logs with closure ageing |
| Business conduct | Anti-corruption policy, training, complaints, disciplinary actions and governance records |
The evidence file should show source, preparer, reviewer, period, entity/site coverage and calculation logic.
Internal controls over ESG data
ESG reporting should be controlled like management reporting. Internal audit should test:
- Data owner assigned for each metric
- Source system or source record identified
- Reporting boundary defined
- Calculation method documented
- Changes approved and logged
- Supporting documents retained
- Review performed before consolidation
- Exceptions and estimates disclosed
- Prior-period comparability checked
- Assurance-provider PBC list mapped
The biggest control weakness is often not the final formula. It is the lack of ownership over source data.
ESG data request list
Use this PBC list as a starting point:
- BRSR and BRSR Core applicability assessment
- ESG governance charter, committee minutes and owner RACI
- BRSR data point owner list
- Site/entity coverage map
- Source-system list and data extraction owners
- GHG calculation workbook and emission-factor support
- Electricity, fuel, water, waste and renewable-energy support
- HR master, worker register, safety incident log and training records
- Grievance registers and closure ageing
- Supplier/value-chain data request templates
- Prior-year BRSR and methodology note
- Assurance-provider PBC list and unresolved queries
- Management representation draft and disclosure-control sign-off
Common ESG internal audit observations
| Observation theme | Why it matters |
|---|---|
| No data owner for selected BRSR Core KPIs | Creates accountability gap and late evidence collection |
| Manual spreadsheet with no review trail | Weakens reliability and increases error risk |
| Site exclusions not documented | May understate environmental or safety metrics |
| Emission factors not locked | Reduces comparability and assurance confidence |
| Contractor worker data missing | Distorts safety, wellbeing and workforce disclosures |
| Waste certificate gaps | Weakens recycling/recovery and disposal support |
| Grievance closure ageing not tracked | Makes stakeholder complaint reporting incomplete |
| Value-chain process undefined | Creates FY 2026-27 reporting and assurance pressure |
Good observations should name the affected KPI, source record, control gap, risk, owner and remediation date.
How this connects to BRSR assessment or assurance
BRSR Core assessment or assurance is a separate external process. Internal audit does not replace the independent assessment or assurance provider. But internal audit can make that process smoother by:
- Testing whether source evidence exists before the assurance visit
- Reconciling ESG data to finance, HR and operations systems
- Checking whether estimates and exclusions are documented
- Reviewing whether prior-year methods are consistently applied
- Tracking unresolved PBC requests and management responses
- Reporting readiness gaps to the Audit Committee
This is especially important for companies entering the top-1000 BRSR Core assessment-or-assurance perimeter in FY 2026-27.
BRSR and ESG internal audit FAQ
What is BRSR internal audit?
BRSR internal audit is an internal review of ESG reporting governance, source data, controls, calculations, evidence files, owner accountability and assurance readiness. It helps management identify disclosure risks before annual-report and assurance deadlines.
Is internal audit responsible for BRSR Core assessment or assurance?
No. BRSR Core assessment or assurance is performed by an external provider. Internal audit can test readiness, evidence quality and control gaps, but it should not present itself as the independent assessor or assurer unless separately appointed and independent under the applicable rules.
What should internal audit test first for BRSR Core?
Start with ownership, source systems, site coverage and evidence for the BRSR Core KPIs. Then test calculation logic, review controls, change logs, prior-year consistency and unresolved assessment-or-assurance provider queries.
Why is FY 2026-27 important for BRSR Core?
SEBI's current BRSR Core glide path makes assessment or assurance applicable to the top 1000 listed entities by FY 2026-27. That expands the number of companies needing externally reviewable ESG data and controls.
Can ESG data be monitored continuously?
Some ESG data can be monitored monthly or quarterly, such as energy use, water, waste, safety incidents, grievances and contractor headcount. Internal audit should define source reports, owners, cadence, thresholds and evidence retention before using dashboards.
Related CORAA resources
- BRSR Core Assurance Playbook
- Internal Audit Data Governance and Master Data Controls
- Internal Audit Source Data Readiness
- Internal Audit Dashboard KPIs
- Internal Audit Programme Generator
- Internal Audit Evidence Escalation Tracker
Sources
- SEBI Circular dated 12 July 2023, BRSR Core framework and original glide path
- SEBI Circular dated 28 March 2025, assessment or assurance framework update
- SEBI, Business Responsibility and Sustainability Reporting
- ICAI, Sustainability Reporting Standards Board
- ICAI Internal Audit Standards Board, Compendium of Standards on Internal Audit
- International Auditing and Assurance Standards Board, ISSA 5000