Socious
Compliance

SSBJ Third-Party Assurance: Why FY2028 Is Really FY2027

Socious
SSBJ Third-Party Assurance: Why FY2028 Is Really FY2027

Japan’s Financial Services Agency has now put a specific fiscal year on mandatory third-party assurance for SSBJ disclosures, tiered by market capitalisation. On paper, the gap between disclosure and assurance looks like a free year. It isn’t, and it doesn’t cover what most people assume it covers.

The tiers, as published

The FSA’s roadmap, finalised in its April 2026 report, sets three tiers by average market capitalisation, each with its own disclosure start and its own assurance start one fiscal year later (Linklaters’ analysis of the FSA roadmap; primary source: FSA, “Japanese Roadmap on Sustainability Disclosure and Assurance,” April 2026):

TierMarket capFirst mandatory disclosureFirst mandatory assurance
1¥3 trillion+FY ending March 2027FY ending March 2028
2¥1–3 trillionFY ending March 2028FY ending March 2029
3¥500 billion–1 trillionFY ending March 2029FY ending March 2030

Roughly 1,500–1,600 companies sit on the Tokyo Stock Exchange Prime Market that these tiers ultimately sweep in. Tier 1 is the group to watch first, because it sets the pattern everyone below it inherits.

What “assurance” actually checks in year one

The gap between disclosure and assurance invites an obvious misreading: that a company gets a full year to report before anyone independent looks at the numbers. That is not quite what the roadmap says. Per Linklaters’ reading of the FSA’s April 2026 report, the first two years of mandatory limited assurance cover disclosures on governance, risk management, and Scope 1 and 2 greenhouse gas emissions — not the full statement. Strategy narrative, metrics and targets beyond Scope 1–2, and Scope 3 sit outside the initial assurance boundary. Expansion is under regulatory consideration, with no date attached yet.

That has a practical consequence most compliance timelines miss. A Tier 1 company can be fully compliant with its FY2028 assurance obligation while its Scope 3 estimate, its climate scenario analysis, and its transition plan have never been examined by anyone outside the company. The parts of the statement most likely to hide a defensible-but-wrong number are, for now, the parts nobody outside is required to check.

The standard the assurance runs on

The FSA has stated its intent to build Japan’s domestic assurance framework around the IAASB’s International Standard on Sustainability Assurance 5000 — the first comprehensive global standard written specifically for sustainability assurance, applicable to both limited and reasonable engagements. The IAASB approved ISSA 5000 in September 2024. Formal publication followed that November, after certification by the Public Interest Oversight Board. It takes effect 15 December 2026, with early adoption encouraged (IAASB).

Line that date up against the tiers above. ISSA 5000 becomes effective three and a half months before Tier 1’s first mandatory disclosure date, and a full fifteen months before Tier 1’s first mandatory assurance date. The standard a Japanese assurance provider applies in FY2028 is brand-new by the time it gets used at scale. It arrives into a market that is short on people qualified to apply it.

The capacity constraint arrives before the deadline does

The FSA’s own monitoring documents describe a profession bracing for volume. Japan’s Big Four affiliates are hiring specifically against the April 2027 mandate. Sustainability specialists at those firms expect it to raise Big Four audit workload by 15% to 20% in the initial phase. The same reporting names the constraint behind that number: “a limited pool of qualified CPAs” (Bloomberg Tax).

Every Tier 1 company’s FY2028 assurance engagement lands in the same eighteen-month window as every other Tier 1 company’s. All of them are competing for a pool of qualified providers that the market itself says is not big enough yet. A company that starts talking to an assurance provider in FY2028, when the obligation begins, is starting at the moment demand peaks. A company that starts in FY2026, while disclosure is still voluntary for it, is negotiating before the queue forms.

Why the “free” year is actually the setup year

FY2027 is not a dry run that assurance ignores. It is the year that produces the governance records, risk-management documentation, and Scope 1–2 emissions data the FY2028 assurance engagement will test. An auditor examining a FY2028 disclosure does not start from FY2028. They ask where each number came from, and the answer traces back through the systems and controls a company had running in FY2027, often earlier. Assurance-readiness is a property of the disclosure year’s infrastructure. It is not something bolted on once assurance itself becomes mandatory.

The scoped assurance boundary compounds this. Governance, risk management, and Scope 1–2 are examined first, so they need a defensible audit trail first: who entered a figure, from what source, on what date, under whose sign-off. A company that treats FY2027 as “disclosure only, assurance is next year’s problem” builds that first year’s governance and Scope 1–2 data without the trail an assurance engagement will ask for. It then inherits a remediation project in exactly the window the audit firms describe as capacity-constrained.

What audit-ready looks like before assurance is mandatory

Three things are worth having in place before, not after, the assurance clock starts. Every input to the governance, risk-management, and Scope 1–2 disclosures needs a record of who entered it, when, and from what source — captured at the point of entry, not reconstructed later from emails and spreadsheets. Emissions factors, their sources, and any changes to the calculation method need a paper trail an assurance provider can follow without asking the finance team to explain a formula from memory. And a preliminary conversation with an assurance provider in FY2026 or FY2027, even an informal one, costs less of their time than joining the queue once the whole tier is compulsory at once.

None of this requires waiting for the assurance boundary to expand to the full statement. Scope 3, strategy narrative, and the rest of the disclosure will eventually face the scrutiny the roadmap hasn’t dated yet. Building the provenance habit on the narrower initial scope is the cheapest place to learn it.

Where Socious Report fits

Socious Report captures provenance and calculation logic automatically at the point of entry — source, date, and sign-off attached to each figure as it’s created — across the governance, risk-management, and emissions disclosures SSBJ’s first assurance wave will examine. The record is structured for direct review by an assurance provider, not reconstructed after the fact.

If you want a read on where your organisation stands today, the free SSBJ Readiness Check scores preparedness across seven axes, assurance readiness included, in about three minutes.