The audit trail behind your climate numbers: what an assurance provider actually tests
Your assurance provider picks one number out of your climate disclosure — say the Scope 2 figure — and asks where it came from. You have about ninety seconds before the silence becomes the answer.
Most first-cycle teams can produce the number. Fewer can produce the invoice behind it. Fewer still can show who approved it, or explain why it moved between the September draft and the March filing.
That gap is where first cycles go wrong. Not the calculation — the record around it.
Key points
- An assurance provider tests four things behind any figure: the source, the sign-off, the change history, and whether you can reproduce it.
- The trail has to be a by-product of how you worked during the cycle. Assembled afterwards, it does not hold.
- A spreadsheet handles the arithmetic. It cannot show approval or what a value was before someone overwrote it.
- The most common failure is not a missing document. It is a figure that changed and nobody recorded why.
What "audit trail" means when an assurer says it
The phrase gets used loosely. Inside an assurance engagement it means something specific: a recorded path from a source document to a published figure, where each step was written down at the time it happened.
That last part carries the weight. A trail assembled in February, describing decisions made the previous June, is a reconstruction. Your assurer will treat it as one.
IFRS S2 tells you what to disclose. It does not tell you how to keep the record behind it. That is left to you, and it is the part an assurer spends their time on.
The four tests
Different firms use different working papers, but the questions converge. Four of them, applied to whichever figures they sample.
Test 1: can you produce the source document
Someone asks for the evidence behind your electricity consumption. The good answer is a file: the utility invoices for the period, or the meter export, or the landlord's apportionment statement.
The weak answer is a summary tab in a workbook that says 4,796.3 with no indication of where the underlying kWh came from.
What makes this harder than it sounds is coverage. One invoice is easy. Fourteen sites across three countries, where two use a landlord estimate and one changed supplier mid-year, is where teams start reaching for "we'll find it".
Keep the file, and keep it attached to the figure rather than in a shared drive folder someone will reorganise in November.
Test 2: can you show who reviewed and who approved
This is the test most first cycles fail, and it surprises people, because the review genuinely happened. Someone did check it. The problem is that the checking left no trace.
An email saying "looks fine to me" is better than nothing and worse than a record. It is not attached to the figure, it does not say which version was being looked at, and in eleven months nobody will find it.
What an assurer wants is unglamorous: a named person, a role, a timestamp, and a clear statement of what was approved. If your governance disclosure says the audit committee oversees climate reporting, they will ask to see the minutes where that happened.
What a sign-off record has to contain to be worth anything is covered in more depth in what auditors actually check in a first-cycle IFRS S2 review.
Test 3: can you show what changed, and why
Figures move between draft and final. That is normal. A supplier issues a credit note, a factor gets updated, someone spots a double-count in the Q3 data.
What matters is whether the movement is visible.
If your Scope 2 figure was 4,812.6 in the September board pack and 4,796.3 in the published report, your assurer will find both and ask about the difference. A good answer names the credit note and points at the record of the change. A poor answer is that the workbook was updated and the earlier version is gone.
This is the specific thing a spreadsheet cannot do. Overwrite a cell and the previous value does not exist anywhere. Not hidden, not archived — gone.
An append-only record solves this by construction rather than by policy. Entries can be added. They cannot be edited or deleted, including by the people who run the system. You can test that claim on our own log rather than take it on trust.
Test 4: can you reproduce the figure from what you kept
The fourth test is the one that catches teams who passed the first three.
Take the published number. Using only what you retained — not what is in anyone's head — rebuild it. Same inputs, same factors, same boundary, same answer.
The usual failure is the emission factor. You applied a grid factor in October. The publisher updated it in January. Nobody wrote down which version you used, and the two produce different numbers.
That one question — could you reproduce this figure in eighteen months? — decides more first-cycle findings than any other on this list.
A worked example: one Scope 2 figure, end to end
Illustrative, but the shape is real.
A group reports 4,796.3 tCO2e of location-based Scope 2 for FY2025. Behind it:
- Twelve monthly electricity invoices, uploaded as one PDF on 5 February, hashed at upload so the file can be shown to be unchanged since.
- A stated method — location-based, operational control boundary — and a named factor source with its publication year.
- A review on 20 February by the group reporting manager, with a note: recalculated against invoices, factor vintage confirmed.
- A restatement on 24 February from 4,812.6 to 4,796.3, against a December credit note, with the previous value retained.
- Approval on 2 March by the person with authority to approve it, recorded against that version.
Every one of those is a boring administrative act. Together they answer all four tests without anyone doing archaeology.
Notice what is absent: nobody wrote a memo explaining the trail. The trail is the residue of doing the work.
What a weak trail looks like in practice
It rarely looks like negligence. It looks like a busy team.
A workbook called Emissions_FY25_v7_FINAL_updated.xlsx. A figure that three people touched. An approval that happened verbally in a meeting that was minuted as "sustainability update". Source files in a folder, but not linked to the numbers they support.
Each of those is defensible on its own. Stacked, they mean the answer to "who approved this and when" is a conversation rather than a record.
Where preparers usually lose the trail
Three places, consistently.
The handoff. Site data arrives by email from an operations manager. It gets typed into the group workbook. The email is the only evidence, and it lives in one person's mailbox.
The late correction. Something changes in the final fortnight. Under time pressure the workbook gets updated and the record does not.
The departure. The analyst who built the model leaves in June. What they knew was never written down, because they were there.
Notice that none of these is a technology problem in the first instance. They are all points where a piece of knowledge existed only in transit.
There is a fourth, quieter one: the figure nobody owns. Group consolidates numbers from six subsidiaries. Two of them submit a total with no workings. The group team accepts it, because chasing it would cost a week and the number looks reasonable against last year.
That figure will be sampled eventually. When it is, the answer to "who prepared this" is a company rather than a person, and the answer to "on what basis" is nothing. Group reporting teams tend to assume the subsidiary holds the evidence. Frequently the subsidiary assumes the same about group.
What to fix first
If you are mid-cycle and cannot rebuild everything, the order that recovers the most ground:
First, attach source documents to figures rather than storing them alongside. A file in a folder is not evidence for a specific number until something connects them.
Second, record approvals as records. Named person, timestamp, what was approved. This costs almost nothing and closes the test most teams fail.
Third, stop overwriting. When a figure changes, keep the old value. If you are staying in a spreadsheet, that means a change log carrying the previous value, maintained by discipline rather than by the tool.
The opinion, since this piece has one: the audit trail is not a deliverable you produce for the assurer. It is a by-product of working in a way that records itself. Teams that treat it as a deliverable spend the last six weeks of the cycle reconstructing, and reconstruction is exactly what an assurer is trained to spot.
How much of this you need depends on whether your engagement is limited or reasonable assurance — the depth of testing differs sharply between the two. The assurance standard itself, ISSA 5000, applies to engagements on sustainability information for periods beginning on or after 15 December 2026, with early application permitted.
Common questions
What is an audit trail for emissions data?
It is the recorded path from a source document to a published figure: the invoice or meter reading the number came from, the person who entered it, the person who reviewed it, the person who approved it, and any change made along the way. Each step carries a timestamp recorded when it happened rather than assembled afterwards. That timing distinction is what separates a trail from a reconstruction.
What evidence does an assurance provider ask for behind a climate figure?
Four things, for any figure they select: the source document, the record of who reviewed and approved it, the history of any changes with the previous value retained, and enough retained detail to rebuild the number independently. A gap in any one of the four is a finding. In practice they will not ask for all four in those words — they will ask for a document, then ask who checked it, then ask why it differs from the draft they were sent in September.
Does a spreadsheet give you an audit trail?
It gives you the calculation, which is usually correct. What it cannot give you is who approved the figure, when a value changed and what it was before, because a cell overwrite leaves no record. The arithmetic is rarely the problem. The absence of approval and change history is. A spreadsheet can be part of a controlled process, but only if something outside it holds the approvals and the change log.
What happens if a figure changes after it has been reviewed?
A change after review is normal and expected. What matters is that the previous value, the new value, the person who made the change and the reason are all retained. An unexplained movement between draft and final invites the assurer to test far more of your population than they otherwise would, because they no longer have a basis for trusting the ones they have not looked at.
Where do you stand against IFRS S2?
A free 6-minute diagnostic scores your readiness across all four pillars and sends a 12-page gap report naming what is missing.
Run the free diagnostic →