Deepa Rao · Chartered Accountant · Sustainability & AI Governance

TRUST + AIRS
Framework

Boardroom Governance for Sustainability Reporting in the Age of Artificial Intelligence

"Governance isn't keeping pace with innovation — that ends here."

Version 2.0 · 2026 · deeparao.uk
Deepa Rao — Sustainability & AI Governance Advisor
Deepa Rao CA · Sustainability & AI Governance
Sustainability Reporting · AI Governance · Board Oversight · CSRD Alignment · ISO 42001 · COSO Framework · Assurance Readiness
01 — The Problem

The Governance Gap Nobody Is Seeing

Directors are being asked to approve disclosures shaped by complex systems they do not govern, with data they have not seen, and logic they cannot fully explain.

Sustainability disclosures are now regulated, investor-scrutinised, and shaped by customer expectations. Simultaneously, AI is transforming how those disclosures are generated — estimating emissions, generating sustainability narratives, and automating reporting pipelines.

Compliance may be ticked. Confidence may still be fragile.

100 First-wave CSRD reporters studied
<20% Provided evidence that mitigation actions were effective
0 Had a dedicated board-level AI disclosure framework

Infographic

Coming Soon

Legacy Oversight Gaps

  • Signs off on final outputs only
  • Relies on "best of our knowledge" caveats
  • Lacks clear accountability across functions
  • Responds after risks surface
  • Treats sustainability and AI as separate problems

What TRUST + AIRS Delivers

  • Governs both data and the AI systems generating disclosures
  • Enables evidence-based, assurance-ready reporting
  • Establishes end-to-end ownership from source to disclosure
  • Detects ESG data issues and AI logic failures early
  • Unifies oversight of sustainability and AI governance
02 — Part I

The TRUST Framework

Board Governance of Sustainability Reporting

The TRUST Framework provides boards with a structured, principle-based approach to oversee how sustainability information is collected, validated, and disclosed. It moves governance beyond surface-level sign-offs into structured oversight of how ESG data is controlled, validated, and trusted across the enterprise.

The TRUST Framework — Board Governance of Sustainability Reporting
T

Transparency

Sustainability data, assumptions, and methodologies must be traceable, explainable, and well-documented — reducing the risk of greenwashing or selective reporting. Every decision-critical metric should have a clear lineage from source to disclosure.

Minimum Controls
  • Data lineage map for top ten decision-critical metrics
  • Assumptions register with owner, basis, and effective dates
  • Change log: who changed what, when, and why
  • AI influence flag on any disclosure touched by models
Board Question "Can we trace exactly where the data came from for each key metric — and produce that trace in under five minutes?"
R

Responsibility

Clear governance roles are essential. Boards must have visibility into who owns each part of the reporting chain — from data capture to disclosure sign-off. Responsibility is visible as named roles, not titles on a slide.

Minimum Controls
  • RACI matrix per reporting use case with named primary and backup owners
  • Delegation register documenting cover arrangements and limits
  • Issue and action tracker with due dates and accountable names
  • Quarterly certification from each owner that controls were performed
Board Question "Who owns this disclosure at each stage? If that person is on leave, who is the backup — and where is the evidence?"
U

Understanding

Boards must invest in their own sustainability literacy — including regulatory developments, data limitations, and the evolving role of technology. Directors should be able to explain the metrics that carry the greatest regulatory or investor risk.

Minimum Controls
  • Quarterly board teach-in on two high-risk metrics with challenge log
  • Short primer on material standards, updated when rules change
  • One-page risk lens per metric showing sensitivity to key assumptions
  • Scenario playbooks directors can walk through in ten minutes
Board Question "Which two metrics would most likely mislead an investor if wrong by ten per cent? What are the top three assumptions behind each?"
S

Security & Sustainability

Reporting systems must be cyber-resilient and appropriately governed. Cyber integrity, data governance, and process sustainability are now board-level concerns. The work must be completable on time, every period, without heroics.

Minimum Controls
  • Access reviews for reporting systems and AI tools with evidence of removal
  • Secure change process for reporting models, rules, prompts, and templates
  • Business continuity plan tested for the reporting calendar
  • Process health metrics: cycle time, rework rate, on-time completion
Board Question "Which users have write access to reporting rules and model prompts today — and when was that list last reviewed?"
T

Trustworthiness

The reporting output must be capable of independent validation. Numbers and narratives must survive re-performance by an internal validator or external assurer. Boards must be confident that what they approve is fair, accurate, and ethically produced — not just technically complete.

Minimum Controls
  • Validation rules at ingestion and consolidation with exception queues and owner sign-off
  • Reconciliations across systems and periods with clear tolerances and explanations for breaks
  • Management review controls with documented review, questions raised, and evidence of follow-up
  • Pre-assurance checklist aligned to attestation standards, including sampling plans and re-performance steps
Board Question "Has any part of this report been independently assured or reviewed — and what was the scope of that assurance?"
02b — TRUST Maturity

How Mature is Your TRUST Governance?

Use this model to assess where your organisation sits today — and where it needs to be.

Level 1
Foundational
Data sources unclear; roles undefined or informal; board receives basic updates only.
Level 2
Emerging
Some documentation; traceability partial; accountability developing but misaligned.
Minimum Target
Level 3
Established
Key sources and roles documented; board engages with reports; controls in place across systems.
Level 4
Embedded
Governance roles, sign-offs, and escalation paths established; digital and sustainability risks addressed jointly.
Level 5
Assurable
End-to-end traceability; internal and external assurance performed; board understands and signs off with confidence.

Aim for Level 3 as a minimum baseline for all material disclosures. Target Level 4 or 5 for disclosures subject to external assurance. Internal Audit can map control coverage to each level.

03 — Part II

The AIRS Framework

Mastering Governance for AI-Powered Disclosures

AI is no longer a future risk. It is already embedded in the sustainability systems companies rely on today. From emissions calculators to supply chain scorers to auto-generated ESG narratives, AI models are quietly shaping the data that boards are asked to sign off on. AIRS exists to close that gap.

The AIRS Framework — Governing AI-Powered Disclosures

The AIRS Framework

Mastering Governance for AI-Powered Disclosures

Bringing Visibility and Discipline to AI-Driven Sustainability Reporting

Accountability & Stewardship

Assign clear ownership of AI tools and govern systems from deployment through retirement.

Integrity

Use bias-tested models to produce explainable, traceable, and audit-ready insights.

Reporting

Apply AIRS to validate the opaque algorithms often used for complex emissions estimations.

Stewardship

Bring structure to opaque AI tools that boards previously could not fully explain.

From Caveats to Confidence

Replace "best of our knowledge" caveats with evidence-based, structural confidence for regulators.

Functional Alignment

Create a shared language between sustainability, audit, risk, compliance, and tech teams.

A

Accountability

Every AI system used in sustainability reporting must have a clearly identified internal owner — even when vendors develop or maintain the models. Ownership means accountability: a named person who can be asked, in a board meeting, to explain what the system does and what controls govern it.

Minimum Controls
  • AI system register listing all tools with named internal owner and governance status
  • Documented use policy including approved use cases and prohibited applications
  • Ethical oversight structure with escalation paths for bias or misuse
  • Board visibility into which AI systems influence material disclosures
Board Question: "Which AI systems influenced the disclosures in this report — and who is the named internal owner of each one?"
I

Integrity

AI tools must operate with fairness, transparency, and consistency — aligned with the company's values, sustainability goals, and regulatory obligations. Integrity means ensuring the model works as intended — both technically and ethically.

Minimum Controls
  • Bias and fairness testing protocol applied at deployment and at each material update
  • Model card for each AI system documenting training data and known limitations
  • Annual impact assessment reviewing model performance and ethical alignment
  • Version control confirming updates are approved, tested, and logged before deployment
Board Question: "Has the AI model used for our Scope 3 emissions been tested for bias or drift since it was deployed — and what were the results?"
R

Reporting

Outputs produced or influenced by AI must be explainable, auditable, and clearly attributed. Boards should not rely on black-box outcomes without oversight. Model logic must be retained, version history tracked, and audit trails maintained — even when the model is vendor-managed.

Minimum Controls
  • Disclosure tagging: each metric or narrative section influenced by AI is flagged
  • Explainability summary for each material AI-influenced disclosure
  • Audit trail covering data inputs, model version, output, and human review
  • Metadata retention policy ensuring records are available for regulatory review
Board Question: "Can you show me which sections or figures in this disclosure were generated or materially influenced by AI?"
S

Stewardship

AI governance must extend across the entire lifecycle of the tool — not just at the point of implementation. When changes occur — updates to model parameters, training data, or vendor ownership — those changes must be assessed and governed for potential impact.

Minimum Controls
  • Lifecycle management policy covering onboarding, monitoring, retraining, and decommissioning
  • Vendor governance protocol with contractual rights to audit and access model documentation
  • Change control process ensuring updates are assessed for impact before release
  • Periodic risk review at least annually covering model drift and regulatory alignment
Board Question: "What happens to our AI governance when a vendor updates their model? Who approves that change before it affects our reporting?"

AIRS Maturity Model

1 Foundational
2 Emerging
3 Established Minimum for AI in Material Disclosures
4 Embedded
5 Assurable
04 — Part III

TRUST + AIRS Together

One Unified Governance Vision

TRUST + AIRS Framework — Governing AI-Powered Sustainability Reporting
The TRUST + AIRS Framework: Unified Governance — Cross-Functional Alignment
TRUST

Governs What is Disclosed

The content, accuracy, and strategic alignment of ESG reporting. Whether data is traceable, owned, validated, and assurance-ready.

+
AIRS

Governs How it is Produced

The AI systems, processes, and controls that generate disclosures. Whether models are owned, tested, explainable, and governed across their lifecycle.

"TRUST + AIRS provide a governance blueprint that enables boards to trust both human and AI-driven sustainability disclosures — by embedding assurance, accountability, and integrity at every stage of reporting."

Regulatory Alignment

TRUST + AIRS complements — it does not replace — existing standards.

Standard What It Covers Where TRUST + AIRS Adds Value
CSRD / ESRS What must be reported on sustainability; double materiality TRUST operationalises board governance; AIRS governs AI tools used in CSRD disclosures
ISSB / IFRS S1 & S2 Climate-related financial disclosure requirements TRUST ensures data is traceable and owned; AIRS governs AI used in climate modelling
COSO Principles-based internal control and ERM TRUST extends COSO principles to non-financial ESG data; AIRS adds AI-specific requirements
ISO 42001 AI management system standard AIRS translates ISO 42001 into board-level governance with disclosure-specific requirements
EU AI Act Risk classification for AI systems in regulated contexts AIRS provides the board-level governance layer above EU AI Act compliance

Five Outcomes of Deploying TRUST + AIRS Together

01

One View of Reporting Integrity

A unified view of ESG disclosures and the AI systems behind them — what is assured, what is validated, and what is vulnerable.

02

Confidence to Approve, Not Just Acknowledge

Move from "best of our knowledge" reliance to real, evidence-based oversight of disclosures.

03

Early Signals, Fewer Surprises

TRUST + AIRS strengthens oversight before risk becomes reputational damage.

04

Alignment Across Functions

A shared language across sustainability, audit, risk, compliance, and technology.

05

Regulatory & Reputational Readiness

Signals to auditors, investors, and stakeholders that the organisation is governance-ready.

05 — In Focus

AI & ESG Governance

A deeper look at the intersection of AI and sustainability governance.

AI & ESG Governance

Deepa Rao explores the convergence of AI and sustainability governance — why boards can no longer treat them as separate concerns, and how the TRUST + AIRS Framework closes the oversight gap.

06 — Resources

Downloads & Resources

Playbook

TRUST Playbook

Practical implementation guide for the TRUST Framework — including board diagnostic questions, control evidence templates, and the maturity assessment tool.

Download →
Playbook

AIRS Playbook

Step-by-step guide for governing AI systems in sustainability reporting — from AI system registration to lifecycle management and board reporting.

Download →
Board Tool

Board One-Pager

A single-page board-ready summary of TRUST + AIRS — designed for inclusion in board packs and audit committee briefings.

Download →
Coming Soon

Diagnostic Self-Assessment Tool

Interactive maturity assessment for boards and management teams — with scored output and prioritised action plan.

V3.0 — In Development
Coming Soon

Sector-Specific Implementation Guides

Tailored TRUST + AIRS implementation guidance for financial services, industrials, technology, and consumer sectors.

V3.0 — In Development

Version Roadmap

V2.0 — Now

Current Release

  • Full TRUST + AIRS framework
  • Maturity models for both frameworks
  • Board diagnostic questions per pillar
  • Illustrative application scenarios
  • Regulatory alignment map
V3.0 — Next

In Development

  • Diagnostic self-assessment tool
  • Board-ready briefing templates
  • Sector-specific implementation guides
  • Real-world pilot case studies
V4.0 — Future

Vision

  • Digital governance features in reporting platforms
  • Real-time board visibility dashboards
  • Academic validation and peer-reviewed publication
  • Global adoption across industries
08 — The Author

Deepa Rao

CA | Sustainability & AI Governance

Deepa Rao is a sustainability and governance practitioner with decades of experience in sustainability reporting, internal controls, assurance, and risk oversight. She currently leads Global Sustainability Governance and Climate Change at a Fortune 200 technology company, working closely with executive teams to strengthen emerging regulations, AI governance, and non-financial disclosures.

A Chartered Accountant by training, Deepa has held key roles at KPMG and PwC, and serves on boards and audit committees across higher education institutions globally. She is a committee member at the British Standards Institution (BSI) for ISO Standards and contributes to global sustainability dialogue through the World Economic Forum, the Institute of Internal Auditors, Workiva, and FinTech Global.

Sustainability Reporting AI Governance Board Advisory Internal Controls CSRD ISO Standards
Deepa Rao
Deepa Rao CA Sustainability & AI Governance
09 — Connect

Let's Talk Governance

For collaboration, early application opportunities, or board-level advisory enquiries.