The assurance provider arrives. They ask for the inventory, the supporting bills, the emission factors you used, and evidence of who approved what.
What they receive is a spreadsheet, a folder of scanned PDFs, and a promise that the numbers reconcile.
Then the questions start, and every one of them costs a day.
- Assurance providers are not checking your arithmetic. They are checking whether each figure has a history.
- A control that happened but was not recorded is indistinguishable from one that never happened.
- Read-only access to the live system replaces export packs and week-long document archaeology.
- Inviting the assurance provider in early turns future findings into current work items.
What that week actually looks like
"Where did the 3,454 tonnes of Scope 2 come from?"
Someone opens the spreadsheet. It is a total. Beneath it, twelve monthly figures. Beneath those, nothing — the bills are in a shared drive, organised by whoever filed them, named by whatever the utility called the download.
"Which emission factor produced that?"
A different tab, maintained by a different person, updated at some point during the year. Whether the December figure used the same factor as the January one is genuinely unclear, because the tab has one value in it and no history.
"Who approved these?"
Nobody wrote it down. The sustainability lead compiled it, the manager looked at it, and the approval was a reply in a thread that has since been archived.
"This site's refrigerant line is zero. Is that right?"
Long pause.
Read-only access changes the shape of the engagement
Our answer is unglamorous: give the assurance provider an account in the live system.
Not an export. Not a report pack assembled for them. A seat in the same application the preparation team works in, with fourteen permissions, every one of them read.
They can see activity records and the full calculation trace behind each one. The source documents — the actual bills. Emission factors and warming potentials, with their source, their version, and whether anyone has verified them. The assumption register. The audit trail of who entered, who reviewed, who approved, and when. The boundary: which entities are in, on which consolidation approach. And the reports, which they can export.
What they cannot do is create, edit, approve or delete anything. The people being audited remain the only people who can change what is being audited.
Why the trail matters more than the total
An assurance provider is not really checking your arithmetic. Arithmetic is the easy part and they assume the software does it.
They are checking whether the number has a defensible history. Where did the activity data come from, was the factor appropriate, was there a control between someone typing a figure and that figure entering a published total, and can you show it.
That last clause does the work. A control that happened but was not recorded is, from the outside, indistinguishable from a control that did not happen.
So the trail is not a feature we added for auditors. It is a consequence of how the data moves. Nothing enters the inventory without passing through draft, reviewed and approved, with a name and a timestamp at each step. Reopening an approved record requires a written reason. When someone signs off a period, the figures they signed against are frozen alongside the signature, so a later restatement does not quietly rewrite what was attested to.
The auditor gets that history because it exists, not because we generated a package for them.
The specific things they find fastest
Three questions that used to take days now take a click, and it is worth being concrete about which:
"Show me the bill behind this." Every activity record that came from a document links to it. The auditor opens the November TNB invoice and reads the kilowatt-hours themselves.
"What did you estimate?" Data quality is declared per record — measured, calculated, estimated or proxy — and aggregated into the report. The auditor does not have to ask which figures are soft. The inventory already says, and the assumption register says why.
"Where is your judgement recorded?" Where a fallback factor was used, where a grid region was ambiguous, where a global warming potential has not been verified against its published table — those carry a caveat on the figure and follow it into the report. The uncertain parts are labelled by the system rather than defended in a meeting.
What this does not fix
It does not make an incomplete inventory complete. If your Scope 3 covers two categories, the auditor will see two categories, faster than before.
It does not replace the assurance work. They still test samples, still challenge boundaries, still form their own view.
And it does not help if the underlying discipline is absent. A system full of records approved by the same person who entered them, with no evidence attached, is a tidier version of the same problem. The tooling makes a good process visible. It does not manufacture one.
The part nobody expects
The most common reaction from preparation teams is not relief about the audit. It is discomfort during the year.
Giving an outside party a live view means the gaps are visible before you have finished explaining them. The refrigerant line that is still zero in October. The four suppliers who never replied. The eleven records sitting unapproved since June.
That discomfort is the point. Every one of those was going to be a finding. Seeing them in October means they are work items. Seeing them in March means they are findings, and a finding costs an order of magnitude more to resolve than a task.
The teams who take to this fastest tend to be the ones who invite the assurance provider in early and deliberately, rather than at the end when the position is fixed.
