Are We Getting Value Out Of Non-financial Assurance?
By Paul Davies; COO and Principal, Banarra, and Lead Certified Sustainability Assurance Practitioner
Non-financial report assurance has become commoditised as a product. Increasingly we find that assurance contracts are being won on considerations of cost rather their ability to add value to the business. Recently I was told by the CEO of a large multinational that they like their assurance “simple”, and were not necessarily looking beyond the assurance statement for any value to be added from the process – a view I found both surprising and somewhat troubling. And this is not just because assurance can be an expensive proposition for reporters in terms of the visible up-front fees. It is also the time and resource investment required by the business to undergo assurance, a cost often difficult to calculate or hidden from view and therefore not considered in assessing the return on investment.
Assurance has the potential to significantly enhance business practices, not just around organisational accountability, but more broadly around improving performance, reputation and processes. The information gleaned from assurance can be used to build reader’s confidence in the report, build stakeholder confidence in the organisation, identify improvement opportunities in reporting processes (resulting in better and more efficient future reporting), and encourage change within the business around systems and management. Yet many published assurance statements, on closer examination, appear to add relatively little value to the business, the report, or the reader.
There are also assured reports out there that are poorly written, weak on material data, or generally fail to meet the requirements of the reporting frameworks they purport to align with – thus draining stakeholders’ confidence in the value of assurance itself. The reasons for this are varied. Some assurers are applying more of a “data verification” approach to their assurance these days, in many instances to keep costs down and because of their more traditional auditing (“check the numbers”) background. Yet taking such an approach only provides confidence that the data in the report is “right”. The significant added benefit of assurance over verification is determining whether the “right data” is in the report, which requires an assessment of the company’s approach to stakeholder engagement, its application of materiality, and its capabilities around responsiveness. Yet these aspects are often overlooked or paid lip service to in many assurance statements.
Boosting the value of non-financial assurance
Assurance is a tripartite arrangement between the reporter, the assurer, and the user of the report. The assurer’s primary role is to help bridge the divide between the reporter and the report user in terms of facilitating credibility for the report content and, by extension, trust in the reporter.
Report users often complain that assurance statements are inaccessible, uninformative or inconclusive as an enabler of confidence building, and thus decision-making, for readers. Assurance statements need to walk a fine line between being comprehensive accounts of what was done by the assurer, yet remaining accessible to an often wide range of stakeholders with different needs and quite different levels of knowledge. For this reason they are not easy to craft, even though their basic content is defined by the various assurance standards. Although they should always render an opinion on the report, the basis for reaching that opinion is often lost in the minutiae of detail, or else simply not evident in the statement.
Our experience as assurance providers over the past decade tells us that reporters themselves are not asking or demanding enough of assurers in terms of questioning their approach or the value being added through assurance. Reporters could be better informed about the process and its purpose, so as to be able to articulate why they need assurance and what they expect from it – in other words, “smarten up”. They should choose assurance providers based on reputation or previous user recommendations, rather than on “lowest price wins”.
Reporters should clearly communicate their expectations of the selected assurer in terms of the business outcomes and benefits sought from the process, how it fits with their business strategy or corporate ethos, and then ask how the assurer will take account of those expectations in their approach. Assurers can also do much more to understand the reporter’s needs and expectations and be prepared to question them and be clear about what can and cannot be delivered though their proposed approach or the reporter’s available budget. They should advise the reporter on the appropriate level of assurance relative to the reporter’s needs, context, maturity and risks. Their assurance focus should be on the reporter’s most material data, or those with the highest risks or greatest complexity.
Reporters should also be able to independently compare and evaluate the strengths and weaknesses of the proposed assurance provider and approach. Assurers must have a demonstrable capability to write stakeholder-relevant assurance statements that are accessible to the reporter’s key audiences. Reviewing an assurer’s past statements for their other clients (these are all public and available) is a useful way of assessing what the assurer’s approach is and what they are capable of in terms of communicating the assurance outcomes to your stakeholders.
Finally, beyond the assurance statement, the assurance provider should be able to deliver meaningful recommendations to the reporter’s leadership team or senior management that enhance the organisation’s accountability, management or performance. Some assurers will say that’s not the goal of assurance; that its primary focus should be on establishing confidence in the report data and narrative. That’s fine if that’s all you want out of the process. However, the work and effort needed to deliver the assurance statement simultaneously unpacks much about the underlying systems and processes that generate data, monitor performance, set targets and performance indicators, and manage risk. It begs to be used.
Upgrading non-financial assurance standards
Since 2003, non-financial assurance has been largely performed against either Accountability’s AA1000 Assurance Standard (AA1000) or against the International Standard on Assurance Engagements other Than Audits or Reviews of Historical Financial Information (ISAE3000) or, in some cases, both. ISAE3000, derived from the accounting discipline, has been the usual choice of the ‘Big 4’ in providing non-financial assurance (last year these firms provided two thirds of the non-financial assurance delivered to the market). AA1000, a less pedantic, more principles-based framework is often the preferred choice of the smaller, specialist assurance providers.
It is now the fifth birthday of the last iteration of the AA1000 assurance standards. ISAE 3000 is even older, at ten years since its last revision. Assurance standards have a habit of aging quickly in a rapidly evolving discipline such as non-financial reporting (noting that GRI’s G4 has just been delivered in May and that IIRC’s Integrated Reporting framework will be on the shelves come December).
Whilst an update of the ISAE3000 standard is reportedly on the cards for this year, it is difficult to determine exactly where it is at. The revision process began in 2009, and the last ISAE 3000 consultation draft was issued in 2011, yet the website of IFAC/IAASB is not particularly enlightening as to where things are now at in terms of its delivery. Similarly, the review of AA1000 series by the UK-based AccountAbility seems to have stalled. There is nothing on AccountAbility’s website that indicates things are moving forward (even though their revision was on the agenda of the AA1000 Standards Board at their January 2013 meeting). It would be both helpful and reassuring if IFAC/IAASB and AccountAbility clearly signalled their intentions to the market around delivering the next generation of these important standards, so they don’t wilt on the vine.
What about assurance of emerging accountability mechanisms, such as integrated reporting?
Having recently sat on the International Integrated Reporting Council (IIRC) Technical Collaboration Group (TCG) on Assurance, I found a lot of good thinking being done around potential criteria for assuring integrated reports. Yet I couldn’t help wondering at the end if we had truly addressed the most important element of the process – that is, the fundamental intent of providing sufficient confidence that claims made in integrated reports around value creation by the business were real and evidence-based.
The integrated reporting framework to be delivered in December is a principles-based approach rather than a prescriptive formula for reporting. It will need an assurance approach that reflects this fundamental characteristic. It will need trained auditors who can apply their knowledge and experience to examine not only the fundamental assertions being made, but the assessment of value transformations between different assets of the organisations (referred to in the framework as ‘capitals’). It will not be a ‘tick and flick’ auditing exercise. The very nature of integrated reporting makes company directors highly nervous about what they are prepared to sign their name to, so any assurance will not just have to satisfy external stakeholders’ (i.e. investors’) expectations, but sufficiently and successfully bridge the gap between principles and pragmatism to satisfy internal stakeholders too.
It will be interesting to watch how this evolves, as assurance offers the very confidence-building tool that company directors need to get comfortable with integrated reports. This is particularly relevant given a recent UN Global Compact study[1] which noted that one of its most alarming findings was that “company directors are still largely ignorant about what sustainability actually means and why it is important for the triple bottom line”.
Assurance has the potential to deliver so much more than just an assurance statement. In addition to building external trust and transparency, it underpins internal confidence and capability through its ability to identify barriers and shortcomings in processes, systems and outputs, which then becomes the basis for their improvement. Both these attributes together more than justify the investment, but fully realising their potential has significant obligations on all parties involved.
[1] www.unglobalcompact.org/AboutTheGC/global_corporate_sustainability_report.html