
You have sat through the demo. Somewhere around slide four the words “audit-ready” appeared, and nobody in the room could have told you what they meant. Every sustainability platform now makes the same claim, which means the claim itself carries no information.
If you run finance, you already know what the phrase should mean, because it is the standard your own numbers are held to: a controls environment that an auditor can test, not a spreadsheet that happens to be tidy. This piece applies that standard to sustainability data: the six things an assurance provider actually examines, and the one demo request that tells you in under a minute whether “audit-ready” is a capability or a slide.
Assurance is a controls problem, and that makes it yours
The shift that matters is not a new disclosure standard. It is that sustainability figures are now being tested the way financial figures are. Limited assurance is already live for the largest CSRD reporters, and ISSA 5000, the IAASB’s sustainability assurance standard, applies to engagements covering periods beginning on or after 15 December 2026. In the UK, lenders and listed customers are asking for evidence behind supplier numbers whether or not any regulation requires it.
What an assurance provider does with your sustainability report is worth being precise about. They do not recalculate your totals. They test whether the process that produced the totals is documented, controlled and reproducible: where each number came from, who touched it, what method was applied, and whether the same inputs would give the same answer again. That is an audit of controls, and controls are the discipline finance already owns. We covered the engagement itself in our earlier piece on what limited assurance involves and how to prepare; this post is about what the platform underneath it has to do.
The six tests an assurance provider actually runs
Use these as a checklist. A platform that fails two or three will still produce a report, but the assurance fee rises to cover the extra sampling, and the gaps are found on your time rather than the vendor’s.
1. Evidence attached at datapoint level, not in a folder
The auditor picks a number, say Scope 2 electricity for one site, and asks to see the invoice, the meter reading or the utility export behind it. The test passes if that source is attached to that datapoint, with the extracted value visible against the document. It fails if the answer is a shared drive called “Evidence FY2025” containing 400 PDFs. Vouching a figure to its source should take seconds, not a search.
2. An immutable change history
Every figure needs a record of who changed it, when, from what value to what value, and why. A “last modified” timestamp is not a change history. Neither is a log that an administrator can edit or clear. Ask to see the history of a figure that was corrected mid-year and check that the original value is still visible alongside the correction and the reason given for it.
3. A prior period reproduced on the methodology that applied then
This is the test most platforms fail quietly. Emission factors are updated every year. If the platform overwrites the old factor with the new one, last year’s published total can no longer be regenerated, and a restatement query from your auditor turns into an argument you cannot win. The control you want is versioned factors and closed periods: ask the vendor to regenerate FY2024 as it was reported, on the FY2024 factor set, while FY2025 runs on the current one.
4. Methodology and factor versions recorded with the figure
Which factor set was used (the DEFRA year, the grid factor source, the database version), which organisational boundary, which allocation rule for shared sites. These need to sit on the datapoint, captured at the moment of calculation, not in a methodology document written afterwards from memory. When the auditor asks “why does this factor differ from the one in the note”, the answer should be on screen.
5. Segregation of duties enforced by the system
Preparer, reviewer and approver should be different people, and the platform should refuse to let the person who entered a figure sign it off. A policy that says this is nice; a system that enforces it is a control. Sign-off should be recorded with the name, the date and what was approved, exactly as you would expect for a journal above the approval threshold.
6. Estimates labelled as estimates
Assurance providers do not object to estimates. Spend-based proxies and modelled figures are normal in Scope 3. What they object to is an estimate presented with the same confidence as a meter reading. Every figure should carry its data quality (measured, spend-based, modelled) and the report should show the aggregate uncertainty that results. This is also where built-in intelligence earns its place, provided it is bound to evidence: in Horizon ESG, anything Nova drafts or estimates is labelled as such, carries its sources and factor versions, and waits for a named human to approve it in the same audit trail as a manual entry. An estimate nobody can distinguish from a measurement is a finding waiting to happen.
The one request that settles it
Checklists can be rehearsed. So once the vendor has finished, make this request, in these words:
“Trace a published figure back to its source document, live, without preparation.”
Pick the figure yourself. A pass looks like this: the presenter clicks the total, the calculation opens showing activity data and the factor with its version, the source file is one click further, the change log and the approver’s name are visible, and the whole thing takes under a minute. A fail sounds like “we would need to set that up”, “let me show you the evidence folder”, or a quiet switch to a spreadsheet. You will know which you have seen, and so will your auditor.
What this does to cost
Two costs move when the six tests are met. The assurance fee falls, because the provider samples less when lineage is visible and can rely on system controls rather than substantive testing. And the internal cost becomes predictable, because year two is the same process as year one instead of a fresh reconstruction. The platform fee is a line item; the reconstruction is what quietly eats a quarter of someone’s year. If you are comparing vendors on this, our comparison of ESG reporting platforms on audit trail and lineage sets out where each one, including ours, is stronger and weaker.
Twelve months ahead: what to have in place
- Agree the boundary and the factor sets for the period now, and record them where the calculation happens.
- Close prior periods so that FY2024 and FY2025 can be regenerated as published.
- Assign preparer and approver roles per datapoint group and let the system enforce them.
- Attach source documents as data is entered, not in the month before fieldwork.
- Run the trace test internally on ten figures picked at random. If any fail, that is your remediation list.
One last point. The numbers your sustainability officer sends to customers and lenders in questionnaires need to match the numbers you publish. Produced from different sources, they diverge, and a customer noticing is the worst way to find out. Our piece on answering customer and lender data requests covers that side; one evidenced dataset feeding both is what closes the gap.
If you want to see the six tests against real data, Horizon ESG for finance teams is built around datapoint lineage, enforced approval and versioned factors. Book a short demo, pick a figure, and make the request above. We would rather you asked it of us first.



