CORAA
Blog/Internal Audit

BRSR and ESG Internal Audit Checklist: Controls, Evidence and FY 2026-27 Readiness

A practical BRSR and ESG internal audit checklist for Indian companies: BRSR Core evidence, ESG data controls, owner mapping, source systems, value chain readiness and audit committee reporting.

CCORAA Team31 August 202612 min read

BRSR and ESG Internal Audit Checklist: Controls, Evidence and FY 2026-27 Readiness

BRSR and ESG internal audit reviews whether sustainability disclosures are supported by reliable source data, clear owners, consistent calculation methods, documented controls and evidence strong enough for management, the Audit Committee and external assessment or assurance providers. For FY 2026-27, this matters because SEBI's BRSR Core glide path reaches the top 1000 listed entities, and the current SEBI wording requires assessment or assurance of BRSR Core disclosures.

The internal audit role is not to sign the BRSR assurance report. The role is to test readiness: whether the company can produce complete, accurate and consistent ESG data before year-end pressure begins.

BRSR internal audit checklist

Area Internal audit test
Governance Check Board/committee oversight, ESG owner, reporting calendar and approval workflow
Applicability Confirm listed-entity status, market-cap rank, BRSR Core phase and value-chain expectations
Metric ownership Map every BRSR Core data point to a process owner and source system
Source data Test meter readings, payroll exports, safety logs, waste records, invoices and system reports
Calculation logic Review formulas, assumptions, conversion factors, boundaries and prior-year consistency
Data controls Test maker-checker review, change logs, reconciliations and exception sign-off
Evidence file Verify whether each KPI has retained support, not only a final number
Site coverage Check whether factories, branches, warehouses and offices are included or validly excluded
Value chain Review supplier/customer data process where applicable or voluntarily reported
Assessment / assurance readiness Identify gaps that would block external assessment or assurance, or require management representation

The checklist should be tailored to the sector. A manufacturer has different ESG evidence risk from a software company, hospital, logistics business or NBFC.

Why internal audit should start before year-end

ESG data is not produced by one department. It sits across EHS, HR, finance, procurement, legal, facilities, plant operations, security, payroll, contractors and vendors. Waiting until annual-report drafting starts creates predictable gaps:

  • Missing meter readings
  • Manual spreadsheets with no preparer/reviewer trail
  • Contractor worker data not reconciled
  • Waste vendor certificates not retained
  • Incident logs not tied to reported safety numbers
  • GHG emission factors changed without approval
  • Site-level exclusions not documented
  • Prior-year methodology not followed consistently

Internal audit can reduce this risk by testing the ESG data process during the year, not after disclosure numbers are already final.

BRSR Core evidence areas

SEBI's BRSR Core framework covers a smaller externally assessed or assured subset within the wider BRSR. Internal audit should focus on evidence quality for that subset first.

ESG area Evidence examples
Greenhouse gas emissions Fuel invoices, electricity bills, meter readings, emission factors, calculation workbook and turnover reconciliation
Water Municipal bills, borewell logs, tanker invoices, recycling records, ETP/STP records and permissions
Waste Hazardous waste manifests, recycler certificates, disposal invoices, EPR records and waste registers
Energy Electricity bills, renewable-energy certificates, captive generation records, conversion factors and plant logs
Employee wellbeing HR master, payroll, benefits records, training logs, health/safety records and worker registers
Gender diversity HR/payroll data by category, Board/KMP records, contractor workforce data and reconciliation
Safety Incident register, near-miss log, lost-time injury records, investigation files and corrective action
Complaints and grievances Customer, employee, investor and value-chain grievance logs with closure ageing
Business conduct Anti-corruption policy, training, complaints, disciplinary actions and governance records

The evidence file should show source, preparer, reviewer, period, entity/site coverage and calculation logic.

Internal controls over ESG data

ESG reporting should be controlled like management reporting. Internal audit should test:

  1. Data owner assigned for each metric
  2. Source system or source record identified
  3. Reporting boundary defined
  4. Calculation method documented
  5. Changes approved and logged
  6. Supporting documents retained
  7. Review performed before consolidation
  8. Exceptions and estimates disclosed
  9. Prior-period comparability checked
  10. Assurance-provider PBC list mapped

The biggest control weakness is often not the final formula. It is the lack of ownership over source data.

ESG data request list

Use this PBC list as a starting point:

  • BRSR and BRSR Core applicability assessment
  • ESG governance charter, committee minutes and owner RACI
  • BRSR data point owner list
  • Site/entity coverage map
  • Source-system list and data extraction owners
  • GHG calculation workbook and emission-factor support
  • Electricity, fuel, water, waste and renewable-energy support
  • HR master, worker register, safety incident log and training records
  • Grievance registers and closure ageing
  • Supplier/value-chain data request templates
  • Prior-year BRSR and methodology note
  • Assurance-provider PBC list and unresolved queries
  • Management representation draft and disclosure-control sign-off

Common ESG internal audit observations

Observation theme Why it matters
No data owner for selected BRSR Core KPIs Creates accountability gap and late evidence collection
Manual spreadsheet with no review trail Weakens reliability and increases error risk
Site exclusions not documented May understate environmental or safety metrics
Emission factors not locked Reduces comparability and assurance confidence
Contractor worker data missing Distorts safety, wellbeing and workforce disclosures
Waste certificate gaps Weakens recycling/recovery and disposal support
Grievance closure ageing not tracked Makes stakeholder complaint reporting incomplete
Value-chain process undefined Creates FY 2026-27 reporting and assurance pressure

Good observations should name the affected KPI, source record, control gap, risk, owner and remediation date.

How this connects to BRSR assessment or assurance

BRSR Core assessment or assurance is a separate external process. Internal audit does not replace the independent assessment or assurance provider. But internal audit can make that process smoother by:

  • Testing whether source evidence exists before the assurance visit
  • Reconciling ESG data to finance, HR and operations systems
  • Checking whether estimates and exclusions are documented
  • Reviewing whether prior-year methods are consistently applied
  • Tracking unresolved PBC requests and management responses
  • Reporting readiness gaps to the Audit Committee

This is especially important for companies entering the top-1000 BRSR Core assessment-or-assurance perimeter in FY 2026-27.

BRSR and ESG internal audit FAQ

What is BRSR internal audit?

BRSR internal audit is an internal review of ESG reporting governance, source data, controls, calculations, evidence files, owner accountability and assurance readiness. It helps management identify disclosure risks before annual-report and assurance deadlines.

Is internal audit responsible for BRSR Core assessment or assurance?

No. BRSR Core assessment or assurance is performed by an external provider. Internal audit can test readiness, evidence quality and control gaps, but it should not present itself as the independent assessor or assurer unless separately appointed and independent under the applicable rules.

What should internal audit test first for BRSR Core?

Start with ownership, source systems, site coverage and evidence for the BRSR Core KPIs. Then test calculation logic, review controls, change logs, prior-year consistency and unresolved assessment-or-assurance provider queries.

Why is FY 2026-27 important for BRSR Core?

SEBI's current BRSR Core glide path makes assessment or assurance applicable to the top 1000 listed entities by FY 2026-27. That expands the number of companies needing externally reviewable ESG data and controls.

Can ESG data be monitored continuously?

Some ESG data can be monitored monthly or quarterly, such as energy use, water, waste, safety incidents, grievances and contractor headcount. Internal audit should define source reports, owners, cadence, thresholds and evidence retention before using dashboards.

Sources

Topics
BRSR internal audit checklistESG internal audit checklist IndiaBRSR Core evidenceESG controls internal auditBRSR assurance readiness
Share
← Back to all articles
Keep reading

More in internal audit.

Built for India · DPDPA compliant

Ready to automate your audit work.

See how Coraa reduces audit engagement time by 60%, from ledger scrutiny to working papers, all from one Tally import.

Run one complete audit free