ArchitectureSustainability
An audit-ready ESG data management architecture, layer by layer
An audit-ready ESG data management architecture lets anyone trace a disclosed number back to its source document, the emission factor and method applied, and the person who approved it. It has six layers: source systems, ingestion with human review, a versioned factor and methodology library, a calculation engine, lineage and controls, and reporting outputs. Spreadsheets fail assurance not because they are wrong but because they cannot prove they are right.
On this page
- Why spreadsheet-based sustainability reporting breaks under assurance
- Six layers of an assurable sustainability data platform
- What each layer must do to survive testing
- Internal controls over sustainability reporting to put in place
- Tracing one disclosed emissions figure back to its invoice
- Specialist ESG software, an extended ERP or a custom data platform
- Picking a route for the sustainability data stack
- Ledger anchoring for evidence shared with third parties
- Questions and answers
- Sources
Why spreadsheet-based sustainability reporting breaks under assurance
Under the CSRD, the assurance opinion covers compliance with the reporting standards, the process used to identify the information reported and the digital mark-up of the sustainability statement3. That is a test of the system, not only of the totals. A workbook passed between teams struggles with all three: links break silently, factors are overwritten without a record, and nobody can show which version of a supplier file fed last year's Scope 3 figure.
Assurance standards make the same demand from a different direction. The IAASB's ISSA 5000 applies to sustainability assurance engagements for periods beginning on or after 15 December 20261, and ISAE 3410 already sets requirements for limited and reasonable assurance on greenhouse gas statements2. Both expect evidence that data is complete, accurate and produced under controls, which is an architecture question before it is an audit question.
Six layers of an assurable sustainability data platform
- Reporting outputs
Sustainability statement, tagged electronic filing, questionnaires and management dashboards from one dataset.
- Lineage and controls
Lineage graph, immutable audit log, reconciliations, approvals and change management.
- Calculation engine
Deterministic, versioned calculations from activity data and factors to reported metrics.
- Factor and method library
Emission factors, conversion rates and methodology choices, each versioned with source and approver.
- Ingestion and review
Connectors, document extraction, validation rules and human review queues for exceptions.
- Source systems
ERP, procurement, utility bills, meters, fleet and travel data, HR systems and supplier submissions.
What each layer must do to survive testing
Ingestion. Prefer system connectors to file uploads, and keep the original file or record alongside every extracted value. AI-assisted extraction from invoices and utility bills, of the kind described in our invoice processing use case, saves effort but should route low-confidence fields, unusual units and out-of-range values to a reviewer, whose decision is logged. Validation rules catch the classic errors: duplicate bills, overlapping periods, kWh read as MWh.
Factor and methodology library. Store every emission factor with its publisher, edition, geography, unit and validity period, and never edit a factor in place: add a new version and record who approved the change and why. Methodology choices, such as market-based versus location-based Scope 2 or the method used for each Scope 3 category, belong in the same library. The Scope 3 calculation guide explains how those choices are made.
Calculation, lineage and outputs. Calculations should be deterministic and re-runnable: the same inputs and versions always give the same result, so a prior year can be reproduced after factors change. The lineage graph links each reported value to calculation, factor version, activity record and source document. Outputs draw from one governed dataset, which matters because the CSRD requires the sustainability statement to be marked up in the European single electronic format3. ColdAI's sustainability work pairs advisory with technology-powered measurement and automated data collection5, drawing on the data platform engineering of its technology capability6.
Internal controls over sustainability reporting to put in place
These mirror familiar financial controls and serve the GHG Protocol's accounting principles of relevance, completeness, consistency, transparency and accuracy4.
Tracing one disclosed emissions figure back to its invoice
- Assurer
Selects a reported value to test.
- Reporting layer
Holds the disclosed metric and its lineage reference.
- Calculation engine
Re-runs the calculation for the selected version.
- Factor library
Returns the factor version and its approval.
- Evidence store
Holds the activity record, source document and reviewer decision.
Specialist ESG software, an extended ERP or a custom data platform
| Criterion | Specialist ESG software | Extend ERP or EPM | Custom build on your data platform |
|---|---|---|---|
| Time to first report | Usually quickest, with standard templates | Moderate; depends on vendor modules | Slowest; everything is designed |
| Fit with unusual operations | Limited to the vendor's data model | Good for data already in the ERP | Highest; modeled on your processes |
| Controls and audit trail | Built in, but check export of logs | Inherits existing financial controls | Only as good as what you build |
| Factor and method governance | Vendor-curated libraries, sometimes opaque | Often thin; may need an add-on | Fully transparent; you maintain it |
| Exit and lock-in | Check data and lineage export terms | Tied to the ERP roadmap | Lowest lock-in, highest maintenance |
Many organizations combine routes: a specialist tool for calculation and reporting fed by the existing data platform, which keeps raw data and lineage under their own control.
Picking a route for the sustainability data stack
- If
Most activity data already sits in one ERP and operations are conventional.
ThenExtend the ERP or EPM first and add a specialist module only for gaps such as Scope 3 or factor management.
Existing financial controls and owners carry over, which assurers recognize.
- If
Data is spread across many systems, sites and acquisitions.
ThenLand raw data on your own data platform with lineage, and choose calculation software that can read from it.
Keeping the evidence layer in-house avoids rebuilding lineage if you change vendors.
- If
You need reporting this cycle and have little engineering capacity.
ThenBuy specialist software, but negotiate full export of data, factors and audit logs before signing.
Speed matters now, and export rights keep later options open.
- If
Your methods are distinctive, for example product-level footprints or sector-specific calculations.
ThenBuild the calculation layer yourself on a governed platform and buy components such as factor databases.
Off-the-shelf models tend to force workarounds that weaken the audit trail.
Questions and answers
Can we start small instead of building the full architecture at once?
Yes. Begin with the metrics most likely to be tested, usually energy use plus direct and purchased-energy emissions, and implement the factor library, lineage and review queue for those first. Add Scope 3 categories and social metrics in later cycles, reusing the same pattern rather than creating a parallel spreadsheet process.
Who should own sustainability data: finance or the sustainability team?
Split it. The sustainability team owns methods, factors and interpretation; finance or the controller owns the control framework, reconciliations and close calendar; operational functions own source data. Writing that split into a responsibility matrix prevents the common gap where everyone assumes someone else approved a number.
How should estimates be handled in an assurable system?
Treat estimates as first-class data. Flag every estimated value, record the method and inputs, and track the share of each metric that is estimated so you can show it falling over time. Assurers accept reasoned estimates; they object to estimates that are invisible or inconsistent between periods.
Does AI-assisted extraction create problems for assurance?
Not if it is controlled. Keep the source document, the extracted values, the model's confidence and the reviewer's decision together, set thresholds for mandatory review, and sample high-confidence extractions periodically. The assurer then tests a documented control, not an opaque model.
Sources
- Understanding International Standard on Sustainability Assurance 5000 — International Auditing and Assurance Standards Board · checked 10 October 2026
- IAASB releases new global standard on assurance on greenhouse gas statements (ISAE 3410) — International Auditing and Assurance Standards Board · checked 10 October 2026
- Directive (EU) 2022/2464 as regards corporate sustainability reporting (CSRD) — EUR-Lex · checked 10 October 2026
- GHG Protocol Corporate Accounting and Reporting Standard — GHG Protocol · checked 10 October 2026
- Sustainability: measurement and reporting approach — ColdAI
- Technology: data platform design and engineering — ColdAI