ArchitectureSustainability

An audit-ready ESG data management architecture, layer by layer

An audit-ready ESG data management architecture lets anyone trace a disclosed number back to its source document, the emission factor and method applied, and the person who approved it. It has six layers: source systems, ingestion with human review, a versioned factor and methodology library, a calculation engine, lineage and controls, and reporting outputs. Spreadsheets fail assurance not because they are wrong but because they cannot prove they are right.

Reviewed 7 min read

On this page
  1. Why spreadsheet-based sustainability reporting breaks under assurance
  2. Six layers of an assurable sustainability data platform
  3. What each layer must do to survive testing
  4. Internal controls over sustainability reporting to put in place
  5. Tracing one disclosed emissions figure back to its invoice
  6. Specialist ESG software, an extended ERP or a custom data platform
  7. Picking a route for the sustainability data stack
  8. Ledger anchoring for evidence shared with third parties
  9. Questions and answers
  10. Sources

Why spreadsheet-based sustainability reporting breaks under assurance

Under the CSRD, the assurance opinion covers compliance with the reporting standards, the process used to identify the information reported and the digital mark-up of the sustainability statement3. That is a test of the system, not only of the totals. A workbook passed between teams struggles with all three: links break silently, factors are overwritten without a record, and nobody can show which version of a supplier file fed last year's Scope 3 figure.

Assurance standards make the same demand from a different direction. The IAASB's ISSA 5000 applies to sustainability assurance engagements for periods beginning on or after 15 December 20261, and ISAE 3410 already sets requirements for limited and reasonable assurance on greenhouse gas statements2. Both expect evidence that data is complete, accurate and produced under controls, which is an architecture question before it is an audit question.

Six layers of an assurable sustainability data platform

Reporting outputs01Lineage and controls02Calculation engine03Factor and method library04Ingestion and review05Source systems06
  1. Reporting outputs

    Sustainability statement, tagged electronic filing, questionnaires and management dashboards from one dataset.

  2. Lineage and controls

    Lineage graph, immutable audit log, reconciliations, approvals and change management.

  3. Calculation engine

    Deterministic, versioned calculations from activity data and factors to reported metrics.

  4. Factor and method library

    Emission factors, conversion rates and methodology choices, each versioned with source and approver.

  5. Ingestion and review

    Connectors, document extraction, validation rules and human review queues for exceptions.

  6. Source systems

    ERP, procurement, utility bills, meters, fleet and travel data, HR systems and supplier submissions.

Conceptual reference architecture for sustainability reporting data, with outputs at the top and source systems at the base. Layers describe duties, not a product or a live deployment.

What each layer must do to survive testing

Ingestion. Prefer system connectors to file uploads, and keep the original file or record alongside every extracted value. AI-assisted extraction from invoices and utility bills, of the kind described in our invoice processing use case, saves effort but should route low-confidence fields, unusual units and out-of-range values to a reviewer, whose decision is logged. Validation rules catch the classic errors: duplicate bills, overlapping periods, kWh read as MWh.

Factor and methodology library. Store every emission factor with its publisher, edition, geography, unit and validity period, and never edit a factor in place: add a new version and record who approved the change and why. Methodology choices, such as market-based versus location-based Scope 2 or the method used for each Scope 3 category, belong in the same library. The Scope 3 calculation guide explains how those choices are made.

Calculation, lineage and outputs. Calculations should be deterministic and re-runnable: the same inputs and versions always give the same result, so a prior year can be reproduced after factors change. The lineage graph links each reported value to calculation, factor version, activity record and source document. Outputs draw from one governed dataset, which matters because the CSRD requires the sustainability statement to be marked up in the European single electronic format3. ColdAI's sustainability work pairs advisory with technology-powered measurement and automated data collection5, drawing on the data platform engineering of its technology capability6.

Internal controls over sustainability reporting to put in place

These mirror familiar financial controls and serve the GHG Protocol's accounting principles of relevance, completeness, consistency, transparency and accuracy4.

0 of 8 checked

Tracing one disclosed emissions figure back to its invoice

select metriclineage referencefactor versionfactor and approvalactivity recordsdocuments and reviewrecalculatematch and evidence01Assurer02Reporting layer03Calculationengine04Factor library05Evidence store
  1. Assurer

    Selects a reported value to test.

  2. Reporting layer

    Holds the disclosed metric and its lineage reference.

  3. Calculation engine

    Re-runs the calculation for the selected version.

  4. Factor library

    Returns the factor version and its approval.

  5. Evidence store

    Holds the activity record, source document and reviewer decision.

  1. Assurer to Reporting layerselect metric
  2. Reporting layer to Calculation enginelineage reference
  3. Calculation engine to Factor libraryfactor version
  4. Factor library to Calculation enginefactor and approval
  5. Calculation engine to Evidence storeactivity records
  6. Evidence store to Calculation enginedocuments and review
  7. Calculation engine to Calculation enginerecalculate
  8. Calculation engine to Assurermatch and evidence
Conceptual walkthrough of a lineage test. It illustrates the evidence an assurer typically asks for; it does not describe a specific product or engagement.

Specialist ESG software, an extended ERP or a custom data platform

CriterionSpecialist ESG softwareExtend ERP or EPMCustom build on your data platform
Time to first reportUsually quickest, with standard templatesModerate; depends on vendor modulesSlowest; everything is designed
Fit with unusual operationsLimited to the vendor's data modelGood for data already in the ERPHighest; modeled on your processes
Controls and audit trailBuilt in, but check export of logsInherits existing financial controlsOnly as good as what you build
Factor and method governanceVendor-curated libraries, sometimes opaqueOften thin; may need an add-onFully transparent; you maintain it
Exit and lock-inCheck data and lineage export termsTied to the ERP roadmapLowest lock-in, highest maintenance

Many organizations combine routes: a specialist tool for calculation and reporting fed by the existing data platform, which keeps raw data and lineage under their own control.

Picking a route for the sustainability data stack

  • If

    Most activity data already sits in one ERP and operations are conventional.

    Then

    Extend the ERP or EPM first and add a specialist module only for gaps such as Scope 3 or factor management.

    Existing financial controls and owners carry over, which assurers recognize.

  • If

    Data is spread across many systems, sites and acquisitions.

    Then

    Land raw data on your own data platform with lineage, and choose calculation software that can read from it.

    Keeping the evidence layer in-house avoids rebuilding lineage if you change vendors.

  • If

    You need reporting this cycle and have little engineering capacity.

    Then

    Buy specialist software, but negotiate full export of data, factors and audit logs before signing.

    Speed matters now, and export rights keep later options open.

  • If

    Your methods are distinctive, for example product-level footprints or sector-specific calculations.

    Then

    Build the calculation layer yourself on a governed platform and buy components such as factor databases.

    Off-the-shelf models tend to force workarounds that weaken the audit trail.

Ledger anchoring for evidence shared with third parties

Questions and answers

Can we start small instead of building the full architecture at once?

Yes. Begin with the metrics most likely to be tested, usually energy use plus direct and purchased-energy emissions, and implement the factor library, lineage and review queue for those first. Add Scope 3 categories and social metrics in later cycles, reusing the same pattern rather than creating a parallel spreadsheet process.

Who should own sustainability data: finance or the sustainability team?

Split it. The sustainability team owns methods, factors and interpretation; finance or the controller owns the control framework, reconciliations and close calendar; operational functions own source data. Writing that split into a responsibility matrix prevents the common gap where everyone assumes someone else approved a number.

How should estimates be handled in an assurable system?

Treat estimates as first-class data. Flag every estimated value, record the method and inputs, and track the share of each metric that is estimated so you can show it falling over time. Assurers accept reasoned estimates; they object to estimates that are invisible or inconsistent between periods.

Does AI-assisted extraction create problems for assurance?

Not if it is controlled. Keep the source document, the extracted values, the model's confidence and the reviewer's decision together, set thresholds for mandatory review, and sample high-confidence extractions periodically. The assurer then tests a documented control, not an opaque model.

Sources

  1. Understanding International Standard on Sustainability Assurance 5000 — International Auditing and Assurance Standards Board · checked 10 October 2026
  2. IAASB releases new global standard on assurance on greenhouse gas statements (ISAE 3410) — International Auditing and Assurance Standards Board · checked 10 October 2026
  3. Directive (EU) 2022/2464 as regards corporate sustainability reporting (CSRD) — EUR-Lex · checked 10 October 2026
  4. GHG Protocol Corporate Accounting and Reporting Standard — GHG Protocol · checked 10 October 2026
  5. Sustainability: measurement and reporting approach — ColdAI
  6. Technology: data platform design and engineering — ColdAI

More in Sustainability

Back to Sustainability

Next step

Send us your current reporting workbook map for an architecture review

Describe where each reported metric comes from today, including spreadsheets and manual steps. We will mark the points an assurer is likely to challenge and outline which layer to fix first.

Review your ESG data flow