There is a finding in the emissions verification research that tends to make sustainability teams uncomfortable when they first encounter it. Research from MIT Sloan School of Management, drawing on data from Clarity AI covering 30,000 of the world's largest companies, found that companies verifying their greenhouse gas (GHG) emissions through third-party auditors initially report 13.5% higher carbon emissions and 9.5% higher carbon intensity than peers who do not externally verify their data. The instinct is to read that as a bad outcome. It is the opposite. Companies relying on unverified internal figures are, in the words of the researchers, reporting lower but unreliable emissions. The ones with auditors are reporting what is actually there.

The same research found that companies submitting to independent verification ultimately make more emissions reductions over time than those that skip it. The audit does not inflate the number permanently. It corrects it — and then gives companies an accurate baseline to reduce from. Florian Berg, research scientist at MIT Sloan, put the point plainly: setting targets is marketing. Getting third-party assurance reveals intent.

Where the Data Problems Actually Come From

The gap between audited and unaudited emissions figures is not primarily about fraud. It is about the structural weaknesses that accumulate in emissions inventories built without external scrutiny. Smaller companies that forgo verification tend to use more favorable assumptions, including projections of future reductions that have not yet occurred. Estimation methods vary significantly across facilities and reporting periods. Emission factors get applied to the wrong activity data. Boundary definitions shift from year to year without documentation. None of these problems show up as obvious errors in an internal review. They surface when an auditor builds an independent inventory management plan and traces every figure back to its source.

The EU's EHS enforcement record provides a parallel data point. Internal audit findings that contradict public environmental disclosures are showing up in enforcement records with increasing frequency. The German prosecutor/regulatory enforcement matter into DWS, Deutsche Bank's asset management arm, began with marketing materials about sustainability integration. The UK's Competition and Markets Authority published supply chain liability guidance in January 2026 that explicitly extends exposure to claims made about supplier environmental performance, not just a company's own operations.

Why the Assurance Gap Is Becoming a Compliance Risk, Not Just a Credibility Risk

For most of the past decade, the decision to seek third-party GHG assurance was voluntary and largely driven by reputational considerations. That calculus is shifting in multiple jurisdictions simultaneously. While the EU’s Corporate Sustainability Reporting Directive (CSRD) mandates third-party assurance starting with first-wave large public-interest entities in 2025 (on FY2024 data), US regulations are moving in a similar direction. California’s SB 253 follows a comparable phased approach: Scope 1 and 2 reporting begins on August 10, 2026, followed by Scope 3 in 2027. Third-party assurance for SB 253 will gradually phase from limited to reasonable assurance. However, because the California Air Resources Board (CARB) implementation rules are still evolving and subject to shifting timelines, organizations should monitor official CARB updates for exact final compliance requirements.  Australia's mandatory climate disclosure framework, which began phasing in for large entities in 2025, includes assurance requirements on a defined timeline.

Companies operating across these jurisdictions face a compounding problem. The assurance standards are not uniform. What satisfies a limited assurance engagement under one framework may not meet the reasonable assurance standard another regulator expects. An auditor reviewing a company's GHG inventory under CSRD's European Sustainability Reporting Standards (ESRS) is applying a different standard than one conducting a verification under ISO 14064-3. The underlying data architecture has to be capable of supporting multiple assurance frameworks, not just the one the sustainability team originally built for.

What EHS and Sustainability Leaders Are Getting Wrong About Audit Readiness

The most common misconception about GHG audit readiness is that it is primarily a documentation problem. Teams spend considerable effort compiling records, formatting data, and preparing explanations for their methodology choices. What auditors consistently find is that the documentation problem is downstream of a data collection problem. Emission factors sourced from outdated national databases. Activity data pulled from billing systems not designed to track the variables an auditor needs. Facility-level boundaries that were set years ago and never updated as operations changed. Correction of these problems after an audit notice arrives is significantly more expensive and disruptive than building accurate systems before the assurance engagement begins.

Organizations that can produce a traceable protocol, documented escalation paths, and evidence that internal findings were acted on are in a materially different position than those that cannot, regardless of what the final emissions number says. The regulatory enforcement cycle is tightening. EHS teams that are waiting for a mandate before investing in audit-ready data systems are already behind the curve in jurisdictions where assurance is now required, not aspirational.