AI for ESG & Sustainability Reporting
Proficient · M17 · lesson 17 of 24 · queued
Preview — browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll →
Persona Engineering: Reasoning Like an Assurer
📖
now learning

Persona Engineering: Reasoning Like an Assurer

15 min

A disclosure lead has a clean draft of an ESRS climate narrative, written in twenty seconds by an AI, and it reads beautifully. Then she changes one thing about how she prompts the model. She stops asking it to write the disclosure, and starts asking it to review the disclosure the way the assurance partner will. The fluent paragraph comes back covered in the model's own red ink: three claims with no evidence, one number that cannot be traced, and a target the company never actually set. Same model. Different persona. The second one did her job for her.

The Reader You Should Be Writing For

Every sentence in a sustainability disclosure has two readers. The first is the public: investors, customers, NGOs, the people the report is nominally for. The second reader is the one who decides whether the first reader ever sees a clean opinion: the external assurer, the auditor running a limited or reasonable assurance engagement who reads every number and every claim and asks, line by line, whether the file supports it. With 73% of large global companies now obtaining external assurance on at least some sustainability disclosures, the assurer is not a hypothetical. The assurer is the gatekeeper, and the assurer reads everything.

Here is the mistake almost everyone makes with AI in disclosure. They prompt the model to write for the first reader. "Draft an ESRS narrative on our climate transition plan." The model obliges, and it is very good at writing for the public: confident, smooth, persuasive. That is exactly the problem. A model optimised to sound convincing to a general reader produces prose that glides over the questions the second reader will stop on. It writes "we have significantly reduced emissions" because that reads well, not because a measured, traced, comparable figure supports it.

Persona engineering is the technique of changing who the model is reasoning as. Instead of letting it default to a fluent drafter writing for the public, you instruct it to reason as the assurer who will read the file. You turn the model into a pre-assurance reviewer. The same model that wrote the soft claim can, given the assurer's persona, find the soft claim, because the persona changes what it is looking for. It stops trying to be convincing and starts trying to be unconvinced.

Notice why this is not the same as asking the model to "double-check" its work. A model asked to check its own draft, still wearing the drafter's persona, tends to confirm what it wrote, because its objective has not changed: it is still trying to produce a good disclosure, and a good disclosure looks finished. The shift that matters is adversarial. The reviewer must want a different outcome from the writer. An assurer is not trying to help you publish; an assurer is trying to find the thing that should stop you publishing. By installing that opposing motivation, you get a genuine second opinion instead of a flattering echo. The cheapest way to find the claim that fails assurance is to ask a reader whose entire job is to find it, and the assurer persona is how you summon that reader on demand.

Three Questions the Assurer Always Asks

To make a model reason like an assurer, you have to know how an assurer actually reasons, and it reduces to a small set of relentless questions. An assurer is professionally skeptical: their default is not to believe a claim until the evidence compels it. Three questions carry most of the weight, and they are the spine of the persona you will build.

Would this survive limited assurance?

This is the framing question. Limited assurance, the most common level today, is a "nothing came to our attention" conclusion: the assurer performs procedures sufficient to say they found nothing suggesting the disclosure is materially misstated. It is a lower bar than reasonable assurance, but it is still a bar, and it still means someone tested your claims. Asking "would this survive limited assurance" forces the model to read each statement as something that will be tested, not merely published. A claim that would draw a question, a request for evidence, or a qualification does not survive, and the model flags it.

What evidence supports this?

This is the demand that breaks soft claims. For every figure and every assertion, the assurer asks what in the file supports it, and "the AI estimated it" is not evidence, nor is "it is generally true," nor is "it reads well." A measured emission figure is supported by activity data, a factor with provenance, and a calculation. A narrative claim like "we engaged our key suppliers" is supported by records of the engagement. When the model reasons as the assurer, it interrogates each claim for its specific support and marks the ones that have none. This is where the AI catches its own fabrications: the target nobody set, the factor with no source, the softened impact.

An assurer does not test every claim equally. They triage, hunting for the weakest link, the claim most likely to be wrong, least supported, and most material if it fails. A skilled assurer reads a disclosure and instantly senses where the chain is thinnest: the Scope 3 category built on the least supplier data, the number that jumped without explanation, the qualitative claim that is doing the most reputational work with the least backing. Asking the model to find the weakest link turns it from a proofreader into a risk-sensor. It tells you where to spend your remaining time before the assurer spends theirs.

The assurer's job is not to believe you. It is to find out whether your file makes them. Prompt the model to be that reader, and it stops defending the draft and starts attacking it.

Building the Assurer Persona Into the Prompt

A persona is not a costume you mention in passing. "Act like an auditor" produces a model that adds the word "audit" to fluent prose. A working assurer persona is a precise instruction set that fixes the role, the standard of skepticism, the questions to apply, and the output format, so the model produces findings, not reassurance. Here is the shape of one.

You are an external sustainability assurance provider performing a limited assurance engagement on the disclosure below. You are professionally skeptical: you do not accept a claim until the evidence compels it. For every figure and every qualitative claim, ask three questions: would this survive limited assurance, what specific evidence in the file would support it, and is this the weakest link. Output a numbered list of findings. For each finding, quote the exact claim, state what evidence would be required, state whether that evidence is present or absent, and rate the risk. Do not rewrite the disclosure. Do not reassure me. Flag every claim you could not tie to evidence, including any number, target, or comparison you cannot trace.

Read what that prompt refuses to let the model do. It does not let the model rewrite the text into something smoother, which is the model's instinct and the last thing you want from a reviewer. It does not let the model reassure you, the second most useless thing a reviewer can do. It forces the model to name the evidence each claim would need and to state plainly whether that evidence exists, which is precisely the assurer's discipline. And it forces a finding on every untraceable claim, so a confident sentence with nothing behind it gets caught rather than waved through because it sounded fine.

Why the Persona Changes the Output, Not Just the Tone

It is fair to be skeptical that a persona does anything real. Does telling a model it is an assurer actually change what it finds, or just how it phrases things? In practice it changes what it finds, because the persona changes the objective the model optimises for. A drafting persona optimises for a fluent, complete-sounding disclosure, so it smooths over gaps. An assurer persona optimises for finding unsupported claims, so it seeks out gaps. The same underlying capability, pointed at the opposite goal, surfaces the opposite things. You are not making the model smarter. You are aiming it at your weaknesses instead of away from them.

Output Format Is Part of the Persona

The persona is not finished when you have set the role and the questions. How you force the model to report its findings is as load-bearing as the skepticism itself, because a finding you cannot act on is a finding wasted. A vague "tell me what is wrong" produces a paragraph of soft hedging. A structured demand, quote the claim, name the evidence required, state present or absent, rate the risk, produces a worklist you can hand to the team and tick off. The format does two things at once. It makes the review reconstructable, so a colleague can see exactly which claim each finding attaches to, and it forces the model to commit, claim by claim, rather than offer general impressions. An assurer does not say "the climate section feels thin." They write a specific point against a specific claim with a specific evidence request. Make the model do the same.

The risk rating matters more than it looks. By asking the model to rate each finding, you get an implicit triage, which is the weakest-link question operationalised. The high-risk findings are where you spend your scarce time first, and they tend to cluster exactly where the real assurer will concentrate: the material number with thin support, the qualitative claim doing heavy reputational work, the comparison that cannot be traced. A flat list of forty equally weighted nitpicks is almost as useless as no list. A ranked list tells you where the engagement will actually go.

A Worked Example: Two Personas, One Paragraph

Watch a single paragraph go through both personas. A disclosure lead needs an ESRS climate narrative sentence and uses AI for the draft. The drafting persona produces this:

"In line with our commitment to net zero, we significantly reduced our greenhouse gas emissions this year through an ambitious decarbonisation programme, and we engaged closely with our key suppliers to cut value-chain emissions across the board."

To the public, that is a fine sentence. Now run the exact same sentence through the assurer persona, and watch the model turn on its own output:

  1. "In line with our commitment to net zero." Finding: the claim implies a formal net-zero commitment. Evidence required: a board-approved target with a baseline year and scope. Status: not provided in the file. Risk: high. This is a stated commitment that, if not formally set, is a target the company never made, the classic fabrication failure mode. Weakest-link candidate.
  2. "Significantly reduced our greenhouse gas emissions." Finding: "significantly" is a quantitative claim with no quantity. Evidence required: the current and prior-period figures, the percentage change, and the boundary, all comparable. Status: no figure cited. Risk: high. An assurer cannot test "significantly" without a number, and an unsupported comparative is a misstatement risk.
  3. "Ambitious decarbonisation programme." Finding: "ambitious" is an unsupported value judgment. Evidence required: the programme's actual measures and quantified targets. Status: absent. Risk: medium. Greenwashing-adjacent language an assurer will ask you to substantiate or remove.
  4. "Engaged closely with our key suppliers." Finding: a qualitative activity claim. Evidence required: records of supplier engagement, which suppliers, when, what was requested. Status: not referenced. Risk: medium. Testable only against an evidence trail that the narrative does not point to.
  5. "Across the board." Finding: an absoluteness claim implying complete coverage. Evidence required: coverage data showing the engagement actually spanned the value chain. Status: almost certainly unsupportable given the 79% supplier-data barrier. Risk: high. Overstatement.

One pleasant sentence became five findings, three of them high risk, before the assurance partner ever saw it. The disclosure lead now knows exactly what to fix: pin the net-zero claim to the actual board decision or soften it, replace "significantly" with the traced figure or cut it, substantiate or remove "ambitious," link the supplier claim to the engagement records, and delete or qualify "across the board." The paragraph that survives that rewrite is one the real assurer will not stop on. The model did the first pass of the assurer's job, which is exactly the point.

What the Persona Cannot Do

Be clear-eyed about the limit, because over-trusting the persona is its own failure. The model reasoning as an assurer is not an assurer. It cannot perform the real engagement, it has no independence, and its findings are suggestions to a human, not an opinion. It can also miss things a real assurer would catch, or flag things that are genuinely fine, so its output is a worklist, not a verdict. The value is in the direction: it points the human's attention at the weak claims early and cheaply, so the human walks into the real engagement having already fixed what a skeptical reader would have found. Used that way, the persona compresses the painful late-stage assurance findings into an early, private, fixable review. Used as a substitute for the real assurer, it is just another fluent voice telling you what you want to hear.

There is also a subtler trap. Because the assurer persona is so good at producing findings, it can produce findings even where none should exist, manufacturing doubt about a claim that is in fact fully supported, simply because you told it to be skeptical. Treat a flagged claim as a question to answer, not a defect to assume. When the model says "this number has no evidence in the file," the right response is to check whether the evidence exists, not to delete the number. Sometimes the evidence is there and the model simply could not see it because you did not give it the file. The persona is a prompt to verify, in both directions: verify the claims it flags, and verify that its flags are warranted.

Where This Fits the Iron Rule

The whole technique is an expression of the program's iron rule: every figure you publish must trace to evidence, and "the AI estimated it" is not evidence. The assurer persona is simply that rule turned into a reviewer. It asks of every claim the exact question the rule demands, what evidence supports this, and it refuses to let a confident sentence pass as its own justification. That is why the persona belongs at the end of an AI-assisted drafting workflow, not the start. You let one persona draft fast, then you turn a second, adversarial persona on the draft to find what the first one glossed. Speed from the drafter, defensibility from the assurer, and the human deciding what to do with the findings. The same discipline that makes the output traceable is what makes it assurable, and the persona is how you apply that discipline before the real assurer applies it for you.

Key Takeaways

  • Every disclosure sentence has two readers: the public, and the external assurer who decides whether the public sees a clean opinion. Most AI prompting writes for the first reader and ignores the second.
  • Persona engineering changes who the model reasons as. Instructing it to reason as the assurer who will read the file turns a fluent drafter into a pre-assurance reviewer that attacks the draft instead of defending it.
  • The assurer persona reduces to three relentless questions: would this survive limited assurance, what specific evidence supports this, and what is the weakest link.
  • A working persona is a precise instruction set, not a costume. It fixes the role and skepticism, forbids the model from rewriting or reassuring, and forces a finding on every claim that cannot be tied to evidence.
  • The persona changes what the model finds, not just how it phrases things, because it changes the objective: a drafting persona smooths over gaps, an assurer persona seeks them out.
  • In the worked example, one pleasant sentence became five findings, catching a target the company never set, an unsupported "significantly," and an overstated "across the board" before the real assurer saw any of it.
  • The persona is a worklist, not a verdict. The model is not an assurer: it has no independence, can miss real issues, and can flag fine ones. Its findings are suggestions to a human.
  • Used well, the persona compresses the expensive, late, public assurance findings into an early, private, cheap review, so the human enters the real engagement having already fixed what a skeptical reader would have caught.