Why Sustainability Verification Is Turning Auditor Independence into an Institutional Governance Question

MACHINE-READABLE RIGHTS

Snn Owned

AI TRAINING
allowed
RIGHTS BASIS
Original Sustainability News Network English institutional analysis, metadata, structured publication content and controlled publication assets.
Open JSON rights record ↗

Series introduction

Evidence Infrastructure Analysis is an institutional research publication series published by EMJ.LIFE.

The series examines structural developments across global governance, sustainability reporting, interoperability and evidence ecosystems.

Rather than analysing individual regulations, standards or policy positions in isolation, each edition explores what significant institutional developments may reveal about the capabilities required to support trustworthy governance.

This edition examines the 24 August 2026 Multi-State Attorney General Letter addressed to Deloitte, EY, KPMG, PwC and senior officials of the U.S. Securities and Exchange Commission.

The letter raises allegations and questions concerning auditor independence, professional objectivity, materiality, climate-related commitments, commercial incentives and potential conflicts of interest.

This publication does not assess whether those allegations are legally or professionally correct.

Instead, it examines what the existence of such scrutiny may reveal about a broader institutional question:

What makes verification authority legitimate enough for institutions to rely upon it?

Executive Summary

Sustainability assurance is built on a simple institutional proposition.

Information is prepared.

An independent professional examines it.

An assurance conclusion increases confidence in that information.

Institutions then rely upon the result.

But the authority of an assurance provider does not depend on technical competence alone.

It also depends upon something less visible.

Legitimacy.

On 24 August 2026, sixteen U.S. state Attorneys General sent a 38-page letter to the U.S. leadership of Deloitte, EY, KPMG and PwC, as well as senior officials of the Securities and Exchange Commission.

The letter alleges that the Big Four's climate-related commitments may create threats to professional independence, integrity and objectivity.

It also questions whether participation in climate-related initiatives, support for sustainability disclosure frameworks, commercial incentives from assurance services and public statements concerning net-zero objectives can coexist with professional obligations concerning materiality, neutrality and independence.

Those allegations remain allegations.

But institutionally, their existence matters.

They move sustainability assurance into a different stage of governance.

The question is no longer only whether sustainability information can be verified.

It is increasingly whether the institution performing the verification remains sufficiently independent, objective and governable for others to rely upon that verification.

This publication describes that condition as:

Assurance Legitimacy.

Assurance Legitimacy is the institutional condition under which verification authority remains credible not only because the verifier possesses technical competence, but because its independence, professional judgement, incentives and governance remain sufficiently trusted.

This creates a new distinction.

Verification authority answers who may verify.

Assurance legitimacy answers why institutions should continue to trust that authority.

Opening

Verification is designed to create trust.

But verification itself must also be trusted.

This second condition is easy to overlook.

An assurance provider may possess highly trained professionals.

Established methodologies.

Internal quality controls.

Professional licences.

Accreditation.

Global experience.

Yet institutional reliance ultimately depends upon more than competence.

The verifier must also be perceived as independent.

Its judgement must be understood as professional rather than predetermined.

Its incentives must not appear to override objectivity.

Its methodology must remain connected to applicable professional standards.

And the institution relying upon the assurance conclusion must remain confident that the verification process was not shaped by interests external to the engagement itself.

The August 2026 Multi-State Attorney General Letter makes this institutional condition unusually visible.

The letter does not challenge only sustainability disclosure requirements.

It challenges the role of the organisations that increasingly help companies interpret, implement and assure those requirements.

The Big Four are simultaneously:

Auditors.

Assurance providers.

Technical advisers.

Implementation advisers.

Participants in professional and sustainability initiatives.

Contributors to standard-setting consultations.

And commercial providers of sustainability-related services.

The letter argues that some of these roles may create conflicts with professional duties of independence, integrity and objectivity. It specifically questions commitments associated with TCFD, ISSB and the former Net Zero Financial Service Providers Alliance, and asks whether commercial benefits from expanded climate-related reporting create conflicts of interest.

Whether those conclusions are ultimately accepted is a separate legal and professional matter.

The institutional signal appears earlier.

The organisation performing verification can itself become a governance object.

The question therefore evolves.

Not:

"Can this information be independently verified?"

But:

"What keeps the verifier institutionally independent enough for its verification to remain trusted?"

Structural Change / Institutional Friction

Assurance Authority Stops Being Self-Validating

For much of modern reporting, assurance legitimacy has been treated as an established institutional condition.

A recognised accounting firm performs the engagement.

Professional standards govern the work.

Internal quality-control systems oversee execution.

External regulators monitor professional conduct.

The resulting assurance report carries institutional weight.

This architecture assumes that professional authority and institutional legitimacy remain aligned.

The August 2026 letter places pressure directly on that assumption.

Its core argument is not that the Big Four lack technical competence.

Quite the opposite.

Their institutional influence is part of the reason the letter matters.

The document notes their substantial position within public-company auditing and repeatedly frames the firms as powerful intermediaries between reporting requirements, corporate implementation and assurance.

The challenge raised by the Attorneys General concerns something different.

Whether external commitments, commercial incentives or advocacy positions can create actual or perceived threats to the independence that gives assurance its institutional value.

This distinction is fundamental.

A verifier can be technically competent while its institutional legitimacy is questioned.

A methodology can be rigorous while users question whether judgement was sufficiently neutral.

A disclosure can be correctly calculated while the assurance provider's role becomes contested.

The evidence itself may not have changed.

The institutional confidence surrounding its verification can.

This publication describes that condition as:

Assurance Legitimacy Risk

Assurance Legitimacy Risk arises when questions about independence, incentives, governance or professional judgement weaken confidence in the institution responsible for verifying information.

It does not require evidence that verification was incorrect.

It concerns whether institutional users continue to regard the verification authority as sufficiently independent and objective.

This is why independence in appearance matters alongside independence in fact.

The underlying institutional logic becomes:

Technical Competence → Professional Independence → Assurance Conclusion → Institutional Reliance

If confidence in one layer weakens, the reliability of the whole chain can be questioned.

Five-stage path from sustainability claims and verification through auditor independence, institutional recognition and regulatory reliance.
Figure 1. Verification authority requires independence before institutions can rely on it.

Institutional Signal

Independence Is Becoming Part of the Evidence Chain

The letter contains 38 groups of questions.

Many are legal or political in character.

But several reveal something broader about assurance governance.

The Attorneys General ask the Big Four to explain:

How climate-related commitments interact with professional independence.

How materiality decisions are made.

What safeguards exist against conflicts of interest.

Whether engagement teams have raised internal concerns.

How sustainability advisory and audit functions are structurally separated.

Whether potential conflicts have been disclosed to clients.

How much revenue has been generated from sustainability reporting and assurance activities.

And what internal policies or controls govern these relationships.

Viewed collectively, these questions are not simply requests for documents.

They form an institutional test.

Who made the judgement?

Under which professional standard?

Was the judgement independent?

Were competing incentives present?

Were safeguards applied?

Were roles separated?

Was the methodology governed?

Can the decision process be reconstructed?

This moves auditor independence closer to the evidence architecture itself.

Traditionally, verification focuses on the object being assured.

The reported metric.

The underlying calculation.

The evidence supporting the assertion.

The methodology.

The controls.

The conclusion.

The August 2026 letter introduces another evidential object:

The verifier's own governance.

Once verification authority itself becomes subject to scrutiny, the evidence chain expands.

It is no longer sufficient to demonstrate:

Why the disclosed information should be trusted.

Institutions may increasingly also need to understand:

Why the organisation providing assurance should be trusted to reach that conclusion independently.

This is a major structural shift.

Materiality Makes the Conflict More Visible

One of the letter's principal arguments concerns materiality.

The Attorneys General contrast U.S. financial-reporting and auditing concepts of materiality with their interpretation of climate-related disclosure frameworks and the ISSB Standards.

They argue that different approaches to materiality may create tensions with professional audit obligations.

Whether that comparison is technically correct in every respect is outside the scope of this publication.

But the institutional issue it exposes is important.

Materiality is not merely a measurement rule.

It is a governance decision.

It determines which information becomes institutionally significant enough to enter reporting, assurance and decision-making systems.

Different frameworks may apply different reporting objectives, user perspectives, time horizons and materiality concepts.

The resulting information may therefore move through multiple institutional interpretations before reaching an assurance conclusion.

This creates another governance question:

Who governs the translation between different materiality regimes?

The answer cannot depend upon the verifier alone.

Nor can it depend solely upon management.

Standards.

Regulators.

Professional guidance.

Management judgement.

Audit methodology.

Assurance procedures.

All participate.

Materiality therefore becomes part of the broader legitimacy architecture.

Five-stage path from a sustainability claim through verifier independence, governance controls and regulatory scrutiny to institutional legitimacy.
Figure 2. Assurance legitimacy emerges when verifier governance withstands scrutiny.

Pre-Disclosure Evidence Infrastructure Perspective

Viewed through a Pre-Disclosure Evidence Infrastructure perspective, the August 2026 letter reveals that an evidence system cannot treat verification as the final institutional layer.

Verification itself requires governance.

This extends the evidence chain.

A sustainability disclosure begins with operational reality.

Operational activities generate information.

Methodologies transform information into reported measures.

Management determines relevance and materiality.

Controls govern preparation.

Assurance providers evaluate selected assertions.

Institutions then rely upon the resulting report.

But every one of those stages introduces another question.

Who controlled the information?

Who selected the methodology?

Who made the materiality judgement?

Who performed the verification?

What professional authority supported that verification?

What incentives surrounded the verifier?

What safeguards preserved independence?

What evidence demonstrates that those safeguards operated?

This is why Assurance Legitimacy is not merely a professional-ethics issue.

It becomes an evidence-governance issue.

A mature evidence infrastructure therefore needs to preserve not only evidence about the reported assertion.

It may also need to preserve evidence about the governance of the verification process itself.

This can include:

Role identity

Who prepared, reviewed and verified the information.

Responsibility separation

Which actors controlled management, advisory, audit and assurance functions.

Methodology governance

Which professional and reporting standards governed the engagement.

Conflict governance

Which actual or potential conflicts were identified and how they were addressed.

Judgement traceability

How significant decisions concerning scope, materiality and evidence sufficiency were reached.

Assurance provenance

Which team, methodology, scope and professional authority produced the assurance conclusion.

Together, these conditions form an additional institutional layer.

Not simply:

Evidence of the disclosure.

But:

Evidence of the legitimacy of the verification process.

This is the deeper transition revealed by the letter.

From Independence to Evidence Provenance

Professional independence has historically been treated primarily as an ethical and regulatory condition.

Pre-Disclosure Evidence Infrastructure suggests another interpretation.

Independence also affects evidence provenance.

If an institution relies upon an assured disclosure, it is relying on more than the reported number.

It is relying upon a chain.

The operating evidence.

The methodology.

Management judgement.

Internal controls.

Verifier competence.

Verifier independence.

Assurance procedures.

And institutional recognition of the conclusion.

If one of those relationships becomes opaque, confidence can weaken even if the underlying number does not change.

This suggests that future assurance systems may increasingly need to make the governance surrounding verification more observable.

Not by exposing confidential audit files.

Not by eliminating professional judgement.

And not by treating every perceived conflict as proof of compromised independence.

But by strengthening institutional clarity around:

Who verified.

Under what authority.

Using which standard.

Within which scope.

With which safeguards.

And under which governance boundary.

This is a form of assurance provenance.

Closing Reflection

The August 2026 Multi-State Attorney General Letter is politically contentious.

Its allegations may be challenged.

Its interpretation of climate disclosure frameworks may be disputed.

The Big Four may reject its conclusions.

Regulators and professional bodies may reach different views.

None of that diminishes the institutional significance of the event.

Because the deeper development has already occurred.

Sustainability assurance itself has become an object of institutional scrutiny.

The verifier is no longer invisible.

Its commitments matter.

Its incentives matter.

Its professional boundaries matter.

Its materiality judgements matter.

Its governance matters.

And its legitimacy can be questioned independently from the technical accuracy of the underlying information.

This moves the assurance discussion beyond:

"Was the information verified?"

Toward:

"Was the authority performing that verification institutionally legitimate, independent and sufficiently governed?"

That distinction may become increasingly important as sustainability information moves closer to:

Capital allocation.

Regulation.

Procurement.

Taxation.

Market access.

Corporate liability.

And public policy.

Evidence Infrastructure Analysis · 012 examined the authority to verify.

This edition asks what must come next.

What makes verification authority legitimate enough to support institutional reliance?

The answer may increasingly depend upon a second evidence layer.

Not evidence about the disclosure.

But evidence about the governance of the verifier.

Verification creates confidence.

Assurance Legitimacy determines whether that confidence can endure.

Official Sources

This analysis is based on one primary institutional source:

Multi-State Attorney General Letter to Deloitte LLP, Ernst & Young LLP, KPMG LLP, PricewaterhouseCoopers LLP and senior officials of the U.S. Securities and Exchange Commission, dated 24 August 2026.

The 38-page letter is signed by sixteen state Attorneys General and contains allegations and questions concerning auditor independence, materiality, integrity, objectivity, conflicts of interest, climate-related commitments, professional safeguards and sustainability-related commercial incentives.

This publication does not independently conclude that Deloitte, EY, KPMG or PwC violated professional, contractual, state or federal requirements.

The allegations, legal interpretations and characterisations contained in the source document remain those of its signatories unless independently established elsewhere.

The concepts of Assurance Legitimacy, Assurance Legitimacy Risk, Assurance Provenance and the interpretation of verifier governance as part of a Pre-Disclosure Evidence Infrastructure are analytical constructs developed by EMJ.LIFE.

This publication represents an independent institutional analysis and does not imply endorsement of the allegations by EMJ.LIFE or participation, review, approval or endorsement by the Attorneys General, the SEC, Deloitte, EY, KPMG, PwC, the IFRS Foundation or any other institution.

Primary official source: Multi-State Attorney General Letter, 24 August 2026

OFFICIAL ANALYSIS SOURCES

Sources informing this publication

Multi-State Attorney General Letter to the Big Four accounting firms and senior SEC officials

Office of the Nebraska Attorney General and fifteen co-signatory state Attorneys General

Primary institutional source · Official multi-state letter · source-link-only · AI training not-allowedOpen official source ↗
Analytical boundary

Evidence Infrastructure terminology and conclusions are independent institutional interpretations. They do not imply participation, endorsement or adopted positions by the institutions cited above.

Disclosure

The 24 August 2026 letter contains allegations and legal interpretations by its sixteen state Attorney General signatories. This publication does not independently conclude that Deloitte, EY, KPMG or PwC violated professional, contractual, state or federal requirements. Assurance Legitimacy, Assurance Legitimacy Risk, Assurance Provenance and the Pre-Disclosure Evidence Infrastructure interpretation are independent EMJ.LIFE analytical constructs. Citation does not imply participation, review, approval, endorsement or institutional affiliation by the Attorneys General, the SEC, Deloitte, EY, KPMG, PwC, the IFRS Foundation or any other institution.

Evidence Infrastructure AnalysisOpen source registry ↗