Working Draft — content version 1.4.0 · review package 1.2 · not approved content
SRCF / framework / domain F / F.1
Domain F · Area F-CA1 · Reporting risk, controls, evidence and working papers

F.1Map reporting assertions, risks and control objectives

Working Draft version 1.1

Purpose and scope

This unit covers the capability to understand the end-to-end sustainability reporting process, identify the assertions implicit in reported information and claims, assess the risks that those assertions may not be achieved and translate the risks into clear control objectives, owners and expected evidence. It includes quantitative, qualitative, governance, methodology, boundary, claim, system, publication and change risks.

Applied competency statement
Can map sustainability reporting processes and assertions, identify and assess reporting risks and translate them into proportionate control objectives, ownership and evidence requirements.
Boundary and escalation
This unit establishes reporting risk and control objectives and does not provide internal audit, independent assurance, legal compliance, cyber-security or enterprise-risk opinions. Management owns the reporting risk assessment and control environment; specialist, IT, legal, finance and assurance input may be required for complex assertions and risks.
Key quality risks
Controls selected before the process and assertions are understood; risk registers copied from financial reporting without adaptation; focus only on numerical accuracy while omitting completeness, boundary, methodology, evidence, narrative and claim risks; generic control objectives that cannot be tested; failure to consider estimates, value-chain data, system interfaces, management bias, late changes and publication channels; and residual risks hidden by a large number of low-value controls.
Required knowledge · 6
F.1-K01
Understands end-to-end sustainability reporting processes, including requirements, scope, materiality, data, methodology, estimates, consolidation, drafting, review, approval, publication and correction.
Knowledge Type: Reporting processes · Normative Weight: Core
F.1-K02
Understands assertions such as completeness, existence or occurrence, accuracy, validity, consistency, classification, cut-off, boundary, rights and obligations where relevant, presentation, neutrality, traceability and supportability.
Knowledge Type: Reporting assertions · Normative Weight: Core
F.1-K03
Understands process, data, methodology, judgement, system, fraud, management-bias, legal, confidentiality, publication, change and assurance-readiness risks.
Knowledge Type: Risk identification · Normative Weight: Core
F.1-K04
Understands likelihood, impact, severity, velocity, concentration, detectability, uncertainty, materiality and residual risk and how these dimensions inform control priority.
Knowledge Type: Risk assessment · Normative Weight: Core
F.1-K05
Understands how a control objective states the condition that should be achieved to address a defined reporting risk and how it differs from a control activity.
Knowledge Type: Control objectives · Normative Weight: Core
F.1-K06
Understands ownership, review, approval, evidence, change control and the distinction between management risk assessment, control design, internal audit and independent assurance.
Knowledge Type: Governance and boundary · Normative Weight: Core
Applied skills · 5
F.1-S01
Map the reporting process, decision points, information flows, systems, owners, reviewers and outputs.
Skill Type: Core applied capability · Observable Output or Result: Reporting process map
F.1-S02
Identify the assertions and quality conditions implicit in each material metric, narrative disclosure, methodology, claim and publication step.
Skill Type: Assertion analysis · Observable Output or Result: Assertion inventory
F.1-S03
Identify and assess risks to the assertions using evidence, prior issues, process complexity, judgement, systems, changes and external requirements.
Skill Type: Risk assessment · Observable Output or Result: Reporting process, assertion and risk map
F.1-S04
Translate prioritised risks into clear, testable control objectives with owners, frequency, evidence and expected residual risk.
Skill Type: Control-objective design · Observable Output or Result: Reporting risk and control-objective register
F.1-S05
Map existing and planned controls to risks, identify gaps, duplication and over-control and communicate the residual-risk profile to management.
Skill Type: Coverage and communication · Observable Output or Result: Risk-control matrix and control coverage assessment
Professional behaviours · 3
F.1-B01
Does not understate reporting risks because a process is familiar, previously used or owned by a senior function.
Behaviour Type: Risk realism · Non-compensable Requirement: No
F.1-B02
Prioritises controls according to material reporting risk rather than creating a large checklist of low-value activities.
Behaviour Type: Control proportionality · Non-compensable Requirement: No
F.1-B03
Distinguishes management control assessment from internal audit and independent assurance and escalates specialist risks appropriately.
Behaviour Type: Boundary discipline · Non-compensable Requirement: No
Typical tasks · 4
F.1-T01
Document the reporting process, systems, decisions, inputs, transformations, reviews and outputs.
Primary Output Link: F.1-O01
F.1-T02
Identify the assertions and quality conditions for material data, methods, narrative, claims and publication steps.
Primary Output Link: F.1-O01
F.1-T03
Assess risks using prior findings, changes, complexity, judgement, system and external evidence and prioritise them.
Primary Output Link: F.1-O01
F.1-T04
Define control objectives, map current controls, identify gaps and residual risk and obtain management review.
Primary Output Link: F.1-O03
Expected outputs · 3
F.1-O01
Reporting process, assertion and risk map
Output Type: Professional work product
F.1-O02
Reporting risk and control-objective register
Output Type: Professional work product
F.1-O03
Risk-control matrix and control coverage assessment
Output Type: Professional work product
Proficiency indicators
Level 1 · Foundation
F.1-L1-01
Can document an established process, identify specified assertions and risks and maintain a risk-control matrix using an approved methodology.
Indicator Dimension: Task execution
F.1-L1-02
Can identify obvious missing risks, unsupported control objectives or ownership gaps and escalate matters beyond the assigned method.
Indicator Dimension: Quality, judgement and accountability
Level 2 · Practitioner
F.1-L2-01
Can independently map and assess reporting risks and control objectives for a moderately complex reporting process involving data, judgement, systems and narrative.
Indicator Dimension: Task execution
F.1-L2-02
Can prioritise risks, identify control gaps and duplication and explain the residual-risk profile and evidence needs to management and control owners.
Indicator Dimension: Quality, judgement and accountability
Level 3 · Advanced Practitioner
F.1-L3-01
Can design or critically review enterprise reporting-risk and control-objective methodologies across complex groups, systems, reporting instruments and assurance scopes.
Indicator Dimension: Method design and review
F.1-L3-02
Can challenge incomplete or cosmetic risk assessments, resolve significant coverage gaps and advise governance bodies on residual reporting risk, control priorities and assurance implications.
Indicator Dimension: Leadership and governance
Illustrative evidence · 6
F.1-E01
Reporting process, assertion and risk map linked to material information and publication steps.
Evidence Type: Work product
F.1-E02
Reporting risk and control-objective register with assessment, owner and evidence fields.
Evidence Type: Work product
F.1-E03
Risk-control matrix and control coverage assessment showing gaps, duplication and residual risk.
Evidence Type: Work product
F.1-E04
Prior-issue, change, judgement, system and evidence trail supporting the risk assessment.
Evidence Type: Process evidence
F.1-E05
Documented management, control-owner, IT, legal, finance, specialist or internal-audit review and the practitioner's response.
Evidence Type: Review evidence
F.1-E06
Observed explanation and defence of a reporting-risk and control-priority conclusion.
Evidence Type: Observed performance
Assessment · 3
F.1-A-L1
Process-mapping exercise, risk classification and situational judgement
Process completeness; assertion and risk relevance; control-objective clarity; recognition of gaps and escalation needs.
F.1-A-L2
Integrated reporting-control case and professional memorandum
Risk identification and prioritisation; assertion coverage; control-objective design; residual-risk and management communication.
F.1-A-L3
Complex control-framework case, portfolio and oral defence
Method design; completeness and proportionality; challenge of cosmetic controls; governance advice and oral defence.
Relationships · 10
FromToTypeRationale
C.1F.1Risk and control linkageReporting governance establishes accountability for risk and control objectives.
E.10F.1Risk and control linkageReporting technology and data risks should be reflected in control objectives and risk-control matrices.
F.1C.2Governance and role linkageReporting risk and control ownership should align with the approved responsibility and decision-right architecture.
F.1E.10Risk and control linkageSpreadsheet, system, interface and data-quality risks are inputs to reporting control objectives.
F.1F.2Feeds intoControl objectives are operationalised through specific reporting controls.
F.1F.3Evidence and traceability linkageAssertions and risks determine the evidence required to support reporting conclusions.
F.1H.1Professional conduct and collaboration linkageRisk assessment should consider misleading information, bias and professional-conduct threats.
F.2F.1PrerequisiteControl design should respond to a defined reporting risk and control objective.
F.7F.1Risk and control linkageReadiness assessment should consider the reporting-risk and control-objective profile.
I.7F.1Risk and control linkageAI use-case and model risks should be integrated into reporting risk and control-objective assessments.
Role profiles for this unit
RoleTarget levelRelevanceEvidence expectation
Corporate Sustainability Reporting Practitioner PractitionerRequired?A case or work sample demonstrating independent performance, documented judgement and a reviewable professional output.
Sustainability Reporting Manager or Lead Advanced PractitionerRole-defining?A complex case or verified portfolio, supplemented by oral or observed defence, demonstrating method design, challenge and governance capability.
Sustainability Reporting Adviser or Consultant Advanced PractitionerRole-defining?A complex case or verified portfolio, supplemented by oral or observed defence, demonstrating method design, challenge and governance capability.
Sustainability Data, Systems and Controls Specialist PractitionerRequired?A case or work sample demonstrating independent performance, documented judgement and a reviewable professional output.
Assurance Readiness and Reporting Quality Specialist Advanced PractitionerRole-defining?A complex case or verified portfolio, supplemented by oral or observed defence, demonstrating method design, challenge and governance capability.
Investor, Capital Markets and Ratings Disclosure Specialist PractitionerRequired?A case or work sample demonstrating independent performance, documented judgement and a reviewable professional output.