The assurance-procedure gap in CBAM and CSRD emissions verification

The assurance-procedure gap in CBAM and CSRD emissions verification
Here's the issue: third-party auditors reviewing Carbon Border Adjustment Mechanism (CBAM) filings and Corporate Sustainability Reporting Directive (CSRD) disclosures in 2026 report the same surprise. Clients arrive with emissions totals, line-item calculations, and methodology documentation. The auditor asks for the evidence lineage—the document trail linking each calculation back to source invoices, utility bills, and bills of material—and discovers it does not exist in a form that supports systematic testing. The engagement that looked straightforward becomes a six-week evidence-reconstruction exercise, and the assurance fee doubles.
However, emissions verification consists of two things: emissions totals and assurance procedures. Emissions totals are the numbers your internal team calculated. Assurance procedures are the steps an independent auditor must perform to form an opinion on those numbers under International Standard on Sustainability Assurance (ISSA) 5000, ISO 14064-3, or ISAE 3410.
Emissions totals on their own have no value to an auditor. Assurance procedures—evidence lineage, population completeness, reproducibility, and methodology documentation—are what the auditor is actually testing, verifying, and paying for.
While internal calculation has become cheaper through software automation, assurance procedures have become more expensive. If your evidence lineage requires manual reconstruction, the cost of assurance procedures might outpace the entire savings of automated calculation. A 2026 limited assurance engagement that should cost 40,000 euros and take eight weeks can escalate to 90,000 euros and fourteen weeks when documentation gaps force the auditor to perform substantive testing on a sample that was supposed to be pre-verified.
How do you solve this? I think the answer lies in treating assurance procedures as a design constraint from day one, not a post-calculation audit step. The operators we work with build evidence lineage during data collection—linking each calculation to its source document at ingestion time—so that when the auditor requests the trail, it exists as a queryable artifact. For now, that approach remains rare. Most teams still calculate first and reconstruct evidence later, which is why assurance-procedure gaps remain the primary driver of fee escalation in 2026.
The shape of the argument, visualised below.
What ISSA 5000 actually requires from evidence trails
ISSA 5000, the new global standard for sustainability assurance effective December 15, 2026, specifies that the practitioner must obtain sufficient appropriate evidence to reduce assurance engagement risk to an acceptably low level. The IAASB defines sufficient as the quantity of evidence and appropriate as the quality—relevance and reliability. For GHG emissions, that translates to four concrete requirements: evidence must be traceable to source documents, calculations must be reproducible by a third party, the methodology must be documented and consistent, and the population of transactions must be complete.[1]
The International Auditing and Assurance Standards Board (IAASB) FAQ from January 2025 clarifies that reasonable assurance involves more comprehensive testing of controls, data, and evidence, closer to a financial audit in rigour, while limited assurance is substantially lower but still enhances user confidence.[2] The gap is one of depth, not kind. Both levels require an audit trail. The difference is how much of the population the auditor samples and how deeply they test controls.
For third-party auditors, this means every emissions figure must be backed by a document, every calculation must include the formula and assumptions, and every boundary decision must be justified in writing. If your CBAM filing reports 450 tonnes of embedded emissions for a steel shipment, the auditor will ask for the utility bills, production logs, and allocation methodology that produced that number. If your CSRD disclosure reports 12,000 tonnes of Scope 3 Category 1 emissions, the auditor will ask for supplier-specific data or proxy documentation for every line item, not just a sample.
The four pillars auditors now demand
Auditors working under ISSA 5000 and ISO 14064-3 evaluate emissions data against four criteria, in order:
| Pillar | What it means | What the auditor tests |
|---|---|---|
| Evidence lineage | Every number traces back to a source document | Can you produce the invoice, utility bill, or bill of material for each calculation? Is the chain of custody clear? |
| Deterministic calculation | Every calculation is reproducible | If the auditor re-runs your formula with your inputs, does it yield the same result? Are assumptions documented? |
| Reproducibility | A third party can verify your work without your help | Can another auditor, two years later, reproduce your 2026 filing from your records alone? |
| Population completeness | All transactions in scope are included | Did you account for every shipment, every facility, every supplier in the reporting boundary? How do you know? |
The Commonwealth Climate Law Initiative's March 2026 director guidance frames the board-level questions plainly: what is our reporting, controls, and assurance plan for fiscal years 2025 and 2026; which disclosures rely on estimates or proxies, and what processes are in place to ensure their consistency and explainability; and which EU or US entity will own governance, data collection, and assurance mobilization internally.[3]
For CBAM, the European Commission expects actual installation values, not default values, by the end of the transitional period. For CSRD, ESRS E1 requires Scope 1, 2, and 3 disclosures with data quality splits by category. Both regimes assume the evidence exists before the auditor requests it.
Why sampling breaks at Scope 3 scale
Traditional assurance relies on sampling: the auditor selects a representative subset of transactions, tests them, and extrapolates confidence to the full population. For Scope 1 and 2 emissions, where the population might be 50 facilities and 600 utility bills, sampling works. For Scope 3 Category 1 procurement, where the population might be 5,000 suppliers and 80,000 invoices, sampling becomes impractical.
ISAE 3410, the predecessor standard to ISSA 5000, notes that the practitioner must obtain evidence over the completeness of the population before selecting a sample.[4] If you cannot prove that your 80,000 invoices represent all procurement transactions in scope, the auditor cannot form an opinion, even on the sample. The assurance engagement stalls at population definition.
Cross Country Consulting's 2026 readiness brief observes that limited assurance typically involves targeted procedures such as analytical reviews, interviews, and selective testing to determine whether anything suggests the information is materially misstated.[5] The word "suggests" is key. Limited assurance does not require the auditor to verify every transaction, but it does require them to confirm that the population you tested is the population you should have tested. If your procurement team cannot produce a complete list of suppliers, the auditor cannot sign off, even under limited assurance.
For operators, this creates a new workflow requirement: before you calculate Scope 3 emissions, you must define and document the full population of suppliers, shipments, or transactions in scope. That documentation—typically a supplier master file, a shipment log, or a procurement extract—becomes the first thing the auditor requests. If it does not exist, the engagement timeline extends by four to six weeks while you reconstruct it.
The methodology documentation gap
Emissions calculations rely on three inputs: activity data, emissions factors, and allocation rules. Of the three, emissions factors are the most frequent source of audit challenges. The IAASB FAQ from January 2025 confirms that methodological choices—every emissions factor, every boundary decision, every proxy estimate—are the primary subject of scrutiny during assurance.[6]
For CBAM filings, this means documenting why you selected the GaBi emissions factor for hot-rolled steel instead of the Ecoinvent factor, or why you allocated emissions by mass instead of by economic value. For CSRD Scope 3, this means documenting why you used supplier-specific data for 60% of Category 1 emissions and industry averages for the remaining 40%, and how you determined which suppliers fell into which bucket.
Brightest's GHG audit readiness guide notes that a first-time limited assurance engagement typically takes 8 to 14 weeks from kickoff to signed statement, assuming your Inventory Management Plan (IMP) and activity data are well-organised, but that documentation gaps—missing emissions factor rationale, incomplete boundary definitions, data provenance issues—typically extend that timeline by 4 to 6 weeks.[7] The cost and timeline overruns in first-time assurance engagements are rarely in the audit itself. They are in the scramble to produce records that should have existed before the auditor arrived.
For third-party auditors, the documentation test is simple: can a different auditor, working from your records two years from now, reproduce your 2026 calculation and arrive at the same result? If the answer is no, your methodology documentation is incomplete.
What California SB 253 adds to the picture
California's Senate Bill 253 imposes the same limited-to-reasonable assurance ramp as CSRD, but with a tighter timeline. Entities reporting under SB 253 must disclose Scope 1 and 2 emissions with limited assurance starting in 2026, and Scope 3 emissions with limited assurance starting in 2027. The California Air Resources Board (CARB) clarified in March 2026 that it will exercise enforcement discretion for first-year reporting, meaning companies may submit Scope 1 and 2 data based on information they already had when the enforcement notice was issued, even if that data has not undergone limited assurance.[8]
The enforcement discretion window closes in 2027. After that, SB 253 filers face the same evidence-lineage requirements as CSRD reporters: every number must trace to a source document, every calculation must be reproducible, and every boundary decision must be documented. For US firms with EU operations, this creates a dual-compliance scenario where the same emissions inventory must satisfy both CARB and ESRS E1.
The practical implication: if your 2026 SB 253 filing uses estimates or proxies, you must document them now, because the auditor reviewing your 2027 filing will test them for consistency. Year-over-year comparability—one of the four pillars—requires that the methodology you use in 2026 can be applied in 2027 without restatement.
How to build assurance procedures into data collection
The operators who pass first-time assurance engagements without timeline or fee escalation follow a common pattern: they design their data collection workflow around the auditor's evidence requirements, not their internal calculation needs. That means three structural changes:
-
Evidence-first ingestion: Every data point—utility bill, supplier invoice, production log—is captured as a source document at ingestion time, with a unique identifier that links to the calculation it supports. If the auditor asks for the evidence behind a specific line item, you retrieve it by ID, not by reconstructing the calculation.
-
Deterministic calculation layers: Every emissions factor, allocation rule, and conversion factor is stored as a versioned parameter, not a hardcoded value. If the auditor questions why you used 2.5 kg CO2e per kg of steel, you show them the versioned record that documents the source, the date of selection, and the rationale.
-
Population completeness checks: Before you calculate, you define the full population of transactions in scope and store it as a reference file. If the auditor asks how you know you captured all suppliers or all shipments, you show them the population definition, the extraction query, and the completeness test you ran before calculation.
These changes are not expensive, but they require a shift in sequencing: you build the audit trail during data collection, not after calculation. The teams we work with report that this front-loading saves 20 to 30 hours per quarter during ongoing assurance cycles, because the auditor's evidence requests become a query, not a research project.
How Emission3 fits
Emission3 is built on the assumption that assurance procedures are a design constraint, not an afterthought. Every calculation in the platform links back to a source document—an invoice PDF, a utility bill scan, a bill of material export—stored with metadata that records the ingestion date, the user who uploaded it, and the calculation it supports. When an auditor requests evidence for a specific line item, you export an evidence pack that includes the source document, the calculation lineage, and the versioned parameters (emissions factors, allocation rules, conversion factors) that produced the result.
For CBAM filings, that means exporting installation-level evidence packs that CBAM registries and auditors can verify without requesting additional documents. For CSRD Scope 3, that means exporting supplier-level evidence packs that demonstrate population completeness and proxy documentation for every category. For SB 253, that means exporting facility-level evidence packs that satisfy CARB's methodology documentation requirements and support year-over-year comparability.
The evidence-lineage artifact Emission3 generates is designed to be auditor-readable: a PDF report that includes the source document thumbnails, the calculation formulas, and the methodology notes, organized by line item. Third-party auditors using Emission3 exports report that the evidence request phase of an engagement shortens from three weeks to three days, because the documentation exists in the format they need to test.
If you are preparing for a 2026 CBAM verification or a 2027 CSRD limited assurance engagement, book a CBAM readiness call. We will map your supplier population, identify documentation gaps, and build the evidence lineage before the auditor requests it.
The board-level framing for assurance investment
For audit committees and CFOs, the assurance-procedure gap is not a technical problem—it is a cost and liability question. The Commonwealth Climate Law Initiative's director guidance asks boards to approve three decisions before the 2026 reporting cycle begins: the assurance standard (ISSA 5000, ISO 14064-3, or ISAE 3410), the reporting boundary (which entities and facilities fall in scope), and the internal owner of data collection and assurance mobilization.[3]
Each decision has a fee implication. Choosing reasonable assurance instead of limited assurance doubles the audit fee, because the auditor must test controls and evidence at a financial-audit level of rigour. Expanding the reporting boundary to include joint ventures or non-consolidated entities increases the population the auditor must verify, which extends the timeline. Assigning data collection to a decentralized team without audit-ready controls guarantees that the auditor will request evidence that does not exist, triggering reconstruction costs.
The strategic question for boards is simple: do we build audit-ready controls in 2026, or do we pay for evidence reconstruction every year from 2027 onward? The operators who answer that question early—by treating assurance procedures as a design constraint during data collection—report that their first-time limited assurance engagements cost 40,000 to 60,000 euros and take eight to ten weeks. The operators who defer the question until the auditor requests evidence report that the same engagements cost 80,000 to 120,000 euros and take fourteen to eighteen weeks.
The difference is not in the audit itself. It is in whether the evidence existed before the auditor arrived.
References & Sources
External Sources
- [1]IAASB Approved Standard: International Standard on Sustainability Assurance (ISSA) 5000
PwC summary of ISSA 5000 requirements for sufficient and appropriate evidence in sustainability assurance engagements.
- [2]ISSA 5000 Explained: How to Prepare for Mandatory Sustainability Assurance in 2026
Spectreco analysis of limited vs. reasonable assurance under ISSA 5000, with IAASB FAQ citations from January 2025.
- [3]GHG Assurance Under SB 253 and CSRD: What Every CSO Must Know Before 2027
ASUENE deep dive on board-level governance questions for SB 253 and CSRD assurance readiness, citing Commonwealth Climate Law Initiative March 2026 director guidance.
- [4]Assurance on a Greenhouse Gas Statement (ISAE 3410, to be withdrawn Dec. 15, 2026)
IAASB project page for ISAE 3410, the predecessor standard to ISSA 5000, withdrawn December 15, 2026.
- [5]2026 Limited ESG Assurance Readiness: Now's the Time
Cross Country Consulting readiness brief on limited assurance procedures and CARB enforcement discretion for SB 253.
- [6]GHG Assurance: ISO 14064-3 Audit Requirements Explained
Brightest audit readiness guide explaining the cost and timeline implications of documentation gaps in first-time limited assurance engagements.
Related Content
- [7]Audit-ready exports in Emission3
The evidence-lineage artifact Emission3 generates for third-party auditors and CBAM registries.
- [8]Book a CBAM readiness call
Start with a readiness conversation: we map suppliers, identify documentation gaps, and build evidence lineage before the auditor requests it.