The audit-grade terminology gap in CSRD and CBAM compliance documentation

Emission 3 Team
The audit-grade terminology gap in CSRD and CBAM compliance documentation

The audit-grade terminology gap in CSRD and CBAM compliance documentation

Here's the issue: compliance officers preparing for CSRD limited assurance or CBAM quarterly filings often assume that "audit-ready" means having the emissions totals calculated correctly. They budget for data collection tools, scope category mapping, and reporting templates. The first year feels manageable. But when the auditor arrives in Q2 2026 and asks for the evidence lineage behind each number, or when the CBAM verifier requests reproducible calculation logic for embedded emissions, teams discover they have been optimizing for the wrong deliverable. The cost of retrofitting audit-grade documentation mid-engagement can exceed the original software budget by a factor of three.

However, audit-grade compliance consists of two things: the emissions total and the evidence lineage that supports it.

The emissions total on its own has no audit value. The evidence lineage—the chain from source document through calculation logic to disclosure—is what the auditor is actually paying for, because it is what they stake their professional liability on. A CSRD auditor signing a limited assurance opinion under ISSA 5000 is confirming that nothing came to their attention suggesting material misstatement. That confirmation rests entirely on whether the preparer's controls and documentation allow the auditor to replay the calculation independently. If the lineage is missing, the auditor cannot issue the opinion, no matter how accurate the total appears.

While emissions calculation tools have become cheaper and faster, audit-grade evidence assembly has become more expensive and manual. A mid-sized industrial exporter filing CBAM reports for the first time in 2026 might spend €15,000 on a scope mapping consultant and €8,000 on a carbon accounting platform, but then face a €42,000 verification bill because the verifier spent 60 hours reconstructing the calculation lineage from invoices, utility bills, and supplier attestations that were never structured for audit replay. The ratio of evidence assembly to calculation cost has inverted. If compliance teams continue to budget for totals instead of lineage, the 2026 assurance season will systematically undershoot by 40-60%.

How do you solve this? I think you start by learning the vocabulary auditors use when they assess evidence quality, not the vocabulary software vendors use when they describe their features. The terms below are what a CSRD auditor or CBAM verifier will say out loud in the first 30 minutes of an engagement. If a compliance officer cannot define these terms before the auditor arrives, the engagement will begin with a two-hour tutorial billed at the auditor's hourly rate, and the clock starts running before any evidence is reviewed.

The shape of the argument, visualised below.

The 12 terms auditors use to assess CSRD and CBAM evidence quality

Below are the terms a compliance officer will hear in the first audit cycle, defined in plain English, with a worked example and the source regulation. These are not aspirational concepts. They are the vocabulary auditors use to explain why a filing passed or failed.

1. Limited assurance

Definition: A level of assurance where the auditor conducts a review sufficient to conclude that nothing has come to their attention to suggest the reported information is materially misstated. The opinion is phrased in a negative form: "we are not aware of any material modifications that should be made." It is less rigorous than reasonable assurance but still requires structured evidence and internal controls.

Worked example: A CSRD wave-2 filer reports 12,450 tonnes CO₂e in Scope 1 and 2 emissions for FY 2025, filed in 2026. The auditor samples 30% of the emission sources, interviews the data owners, reviews the calculation methodology, and tests the internal controls over data collection. If no red flags emerge, the auditor issues a limited assurance opinion. The auditor does not verify every invoice or meter reading—only enough to form a negative conclusion.

Source regulation: CSRD Article 34, as amended by the Omnibus Directive (EU) 2025/794, confirmed that limited assurance is mandatory for all in-scope companies, with no automatic transition to reasonable assurance. The European Commission will adopt limited assurance standards by 1 July 2027.[1]

2. Reasonable assurance

Definition: A level of assurance where the auditor conducts procedures sufficient to form a positive opinion: "in our opinion, the reported information is fairly stated in all material respects." It requires comprehensive testing of controls, data, and evidence, comparable to a financial audit. The auditor verifies the population completeness and reproducibility of every material assertion.

Worked example: A California registrant subject to SB 253 reports 8,320 tonnes CO₂e in Scope 1 and 2 emissions for 2029, requiring reasonable assurance from 2030. The auditor tests 100% of material emission sources, reperforms the calculations independently, confirms the source documents are authentic, and evaluates whether the company's internal controls are sufficient to prevent and detect misstatements. The auditor's opinion is phrased positively, and the engagement typically costs 2-3 times the limited assurance equivalent.[2]

Source regulation: California SB 253 Section 38532(b)(2) requires reasonable assurance on Scope 1 and 2 emissions starting with reports filed in 2030. ISSA 5000, released in January 2025, provides the global standard for both limited and reasonable assurance on sustainability information.[3]

3. Evidence lineage

Definition: The documented chain linking a reported emissions figure back to the underlying source documents (invoices, utility bills, supplier attestations) through every calculation step and assumption. An auditor should be able to start with the disclosed total and trace backward to the original evidence without requiring the preparer's interpretation.

Worked example: A CBAM filer reports 2.4 tonnes CO₂e per tonne of hot-rolled steel in their Q1 2026 report. The evidence lineage consists of: the electricity invoices from the mill (kWh consumed), the grid emission factor from the national registry (kgCO₂e per kWh), the natural gas purchase receipts (cubic meters), the combustion factor from ISO 14064-1 Annex C, the production log (tonnes of steel output), and the calculation spreadsheet showing the division. The verifier reperforms the calculation using only these documents and confirms the 2.4 figure. That is evidence lineage.

Source regulation: CBAM Implementing Regulation (EU) 2023/1773 Article 7 requires that embedded emissions are calculated based on "direct measurements" with "verifiable and transparent" methodology. The regulation does not use the phrase "evidence lineage," but Article 7(4) requires that the calculation method be "reproducible."[4]

4. Reproducibility

Definition: The property that an independent third party (an auditor or regulator) can reperform the calculation using only the documented inputs and methodology and arrive at the same result. Reproducibility eliminates reliance on the preparer's judgment or institutional knowledge. It is the foundational test of audit-grade documentation.

Worked example: A CSRD filer reports 450 tonnes CO₂e from business travel in their 2026 filing. The auditor is given the travel booking confirmations, the distance calculations, and the DEFRA emission factors used. The auditor reperforms the calculation in a separate spreadsheet: 120 short-haul flights × 0.15 tonnes per flight + 30 long-haul flights × 0.8 tonnes per flight + 80,000 km rail × 0.041 kg per km = 450.28 tonnes. The 0.28 rounding difference is immaterial. The calculation is reproducible. If the auditor had to ask the preparer "how did you classify this flight as long-haul?" the calculation would not be reproducible.

Source regulation: ISSA 5000 paragraph A77 states that "the practitioner considers whether the measurement or evaluation of the underlying subject matter is reproducible." It is a core criterion for assurance over quantitative information.[5]

5. Population completeness

Definition: Assurance that all items within a defined scope have been identified and included in the calculation. An auditor testing population completeness is asking: "how do you know you didn't miss anything?" For emissions inventories, this means all emission sources, all facilities, all transactions, and all suppliers within the reporting boundary are accounted for.

Worked example: A CSRD filer reports Scope 3 Category 1 emissions from 85 suppliers representing 95% of procurement spend. The auditor asks for the full supplier list and the FY 2025 accounts payable ledger. The auditor sorts the ledger by spend, identifies the top 100 suppliers, and confirms that the 85 reported suppliers match the top 95% by spend. The auditor then asks how the company confirmed that no significant suppliers were omitted from the ledger—perhaps a subsidiary's procurement was excluded. The auditor is testing population completeness. If the company cannot demonstrate that the ledger captures all procurement, the population is incomplete.

Source regulation: ISSA 5000 paragraph A105 requires the auditor to obtain evidence about the completeness of the underlying subject matter, including consideration of "whether all relevant sources have been identified." For CSRD, ESRS E1 paragraph 44 requires disclosure of the "boundary" and any exclusions.[6]

6. Executive officer statement

Definition: A signed declaration by a named executive officer (CEO, CFO, or equivalent) attesting that the reported information is accurate and complete to the best of their knowledge. Under SB 253 and SB 261, the executive officer's signature carries personal liability if the statement is later found to be materially false or misleading. It is not a ceremonial signature—it is a legal attestation.

Worked example: A California registrant files its SB 253 Scope 1 and 2 disclosure in 2027. The CFO signs the executive officer statement, declaring that the 6,200 tonnes CO₂e reported is accurate and that the company's internal controls are sufficient to support the figure. In 2028, the auditor identifies a 15% undercount due to a missing facility. The CFO is personally liable for the misstatement under California Corporations Code Section 25540, which imposes penalties for false filings. The executive officer statement is what makes SB 253 compliance a board-level concern, not a sustainability-team concern.

Source regulation: California SB 253 Section 38532(d) requires that the disclosure include a statement signed by an executive officer "attesting to the accuracy of the report." SB 261 Section 38533(c) imposes the same requirement for climate-related financial risk disclosures.[7]

7. Reasonable assurance engagement

Definition: The formal assurance process conducted under ISSA 5000 or equivalent standards where the auditor gathers sufficient appropriate evidence to form a positive opinion on the subject matter. It includes engagement planning, risk assessment, testing of controls, substantive testing of data, and evaluation of the presentation and disclosure. The auditor's report is addressed to the intended users and states whether the reported information is fairly presented in all material respects.

Worked example: A CSRD filer voluntarily elects reasonable assurance on its 2027 ESRS E1 disclosure (the EU does not mandate reasonable assurance, but the company seeks it for investor credibility). The auditor plans the engagement in Q4 2027, conducts interim testing of controls in Q1 2028, performs year-end substantive testing in Q2 2028, and issues the opinion in Q3 2028. The engagement includes testing 100% of Scope 1 and 2 sources, confirming the accuracy of emission factors, reperforming the calculations, and evaluating the adequacy of disclosures under ESRS E1. The auditor's opinion states: "In our opinion, the greenhouse gas emissions disclosed in the 2027 sustainability statement are fairly presented, in all material respects, in accordance with ESRS E1." The cost is approximately €350,000, compared to €140,000 for limited assurance.

Source regulation: ISSA 5000 paragraph 46 defines the objective of a reasonable assurance engagement: "to obtain reasonable assurance about whether the sustainability information is free from material misstatement." The EU's October 2028 assessment will determine whether reasonable assurance becomes mandatory for CSRD.[8]

8. Audit trail

Definition: The sequential record of transactions, calculations, and approvals that links a reported figure back to its source. In sustainability reporting, the audit trail includes the original invoice or meter reading, the data entry log, the calculation spreadsheet, the review and approval record, and the final disclosure. An effective audit trail allows an auditor to trace forward from the source document to the disclosure or backward from the disclosure to the source document without gaps.

Worked example: A CBAM filer reports 1.2 tonnes CO₂e embedded in 10 tonnes of aluminium ingots exported to Germany in Q2 2026. The audit trail consists of: the smelter's electricity bill (45,000 kWh consumed), the grid factor (0.6 kgCO₂e per kWh), the production log (10 tonnes output), the calculation (45,000 × 0.6 ÷ 10 ÷ 1000 = 2.7 tonnes per tonne, multiplied by 10 tonnes = 27 tonnes total, wait—this does not match 1.2 tonnes). The auditor identifies a missing step: the filer applied a correction factor for recycled content. The audit trail must include that factor and the source document justifying it. Without the complete trail, the 1.2 figure is not verifiable.

Source regulation: CBAM Regulation (EU) 2023/956 Article 35 requires that the authorized CBAM declarant maintains records sufficient to demonstrate compliance for at least four years. The term "audit trail" is not defined in the regulation, but Article 35(1)(b) requires records of "the calculation of embedded emissions."[4]

9. Safe harbor

Definition: A regulatory provision that protects a disclosing entity from liability if they made a good-faith effort to comply with the reporting requirements and disclosed the limitations of their data. In sustainability reporting, safe harbor often applies to forward-looking statements or estimates where precise data is unavailable, provided the limitations are clearly stated. It does not protect against knowing misstatements or negligence.

Worked example: A CSRD filer cannot obtain primary data from 40% of its Scope 3 Category 1 suppliers by the 2026 filing deadline. The company estimates emissions using spend-based factors and discloses in the ESRS E1 narrative: "Emissions for 40% of suppliers are estimated using industry-average factors due to supplier engagement limitations. The company is implementing a supplier data collection program and expects primary data coverage to exceed 80% by 2027." The disclosure includes the uncertainty range (±30%). This disclosure may qualify for safe harbor treatment under ESRS E1 paragraph 72, which allows phased improvements in data quality, provided the limitations are disclosed. If the company had used the estimates without disclosing the limitation, safe harbor would not apply.

Source regulation: ESRS 1 paragraph 126 states that when data is unavailable, the undertaking may use "estimates or approximations" but must disclose the fact and the reason. This is not labeled "safe harbor," but it functions as one by allowing incomplete data if the incompleteness is transparent.[1]

10. Methodological documentation

Definition: The written record of the calculation methodology, including the emission factors, allocation rules, boundary definitions, and assumptions used to calculate reported emissions. Methodological documentation is separate from the evidence lineage—it describes how the calculation was performed, not the source documents themselves. An auditor uses the methodological documentation to evaluate whether the approach is consistent with the reporting standard (ESRS, GHG Protocol, ISO 14064-1) and applied consistently across reporting periods.

Worked example: A CBAM filer produces cement and reports embedded emissions using the "mass balance" method under CBAM Annex IV. The methodological documentation includes: the boundary definition (clinker production only, excluding downstream grinding), the emission factor for limestone calcination (0.525 tonnes CO₂ per tonne CaCO₃), the fuel combustion factors (from ISO 14064-1 Annex C), the allocation rule (no allocation because cement is the only output), and the justification for excluding waste heat recovery (immaterial, <1% of total). The verifier reviews this documentation before testing the data. If the methodology is inconsistent with CBAM Annex IV, the verifier will issue a qualified opinion, even if the data itself is accurate.

Source regulation: CBAM Implementing Regulation (EU) 2023/1773 Article 7(1) requires that the calculation method follows Annex IV and be "documented in a verifiable manner." ESRS E1 paragraph 51 requires disclosure of the "methodologies and significant assumptions" used to calculate emissions.[6]

11. Internal control system

Definition: The policies, procedures, and activities designed to ensure that data is complete, accurate, and reliable. In sustainability reporting, an internal control system includes data ownership assignments, review and approval workflows, segregation of duties, reconciliation procedures, and documentation requirements. Auditors evaluate the design and operating effectiveness of internal controls as part of both limited and reasonable assurance engagements.

Worked example: A CSRD filer establishes an internal control system for Scope 1 and 2 data collection: each facility manager is responsible for submitting utility bills and fuel receipts by the 10th of each month; the central sustainability team reviews the submissions for completeness and accuracy; a finance team member reconciles the reported energy consumption against the general ledger; the CFO approves the final emissions total before disclosure. The auditor tests this system by selecting three months, confirming that the bills were submitted on time, that the reconciliation was performed, and that discrepancies were investigated. If the system is operating effectively, the auditor places reliance on it and reduces substantive testing. If the system is weak (e.g., no reconciliation, no approval), the auditor must test 100% of the population.

Source regulation: ISSA 5000 paragraph A84 requires the auditor to "obtain an understanding of internal control relevant to the engagement." ESRS 1 paragraph 131 requires that the undertaking establish "policies and processes" to ensure data quality, though it does not mandate a formal control system.[5][1]

12. Data quality assessment

Definition: The evaluation of whether the reported data meets the qualitative characteristics required by the reporting standard: relevance, faithful representation, completeness, neutrality, accuracy, comparability, verifiability, understandability, and timeliness. In CSRD reporting under ESRS 1, data quality is assessed against the five-tier hierarchy: measured, calculated, estimated, industry average, or extrapolated. Auditors use data quality assessments to determine the level of assurance they can provide and whether additional evidence is needed.

Worked example: A CSRD filer reports Scope 3 Category 11 (use of sold products) emissions for 500 different SKUs. The data quality assessment shows: 20% of SKUs have measured product energy consumption data from field studies (Tier 1), 50% have calculated emissions based on product specifications and usage assumptions (Tier 2), and 30% are estimated using industry averages (Tier 4). The filer discloses this breakdown in the ESRS E1 narrative and notes that Tier 1 coverage increased from 10% in 2025 to 20% in 2026. The auditor evaluates whether the Tier 4 estimates are reasonable and whether the disclosure adequately describes the limitations.

Source regulation: ESRS 1 paragraph 34 defines the qualitative characteristics of sustainability information. ESRS E1 paragraph 72 describes the data quality hierarchy and requires disclosure of the proportion of emissions data derived from primary sources versus estimates.[1][6]

How Emission3 fits

Emission3 positions CBAM and CSRD compliance as an audit-grade evidence assembly problem, not a carbon accounting problem. Our compliance infrastructure treats every emissions figure as a future audit artifact, meaning the calculation logic is reproducible from source documents without requiring the preparer's interpretation. For compliance officers preparing for the first CSRD limited assurance engagement in 2026, this means:

  1. Evidence lineage is built at ingestion, not assembly. When a utility bill or supplier invoice is uploaded, Emission3 extracts the line items, links them to the calculation logic, and creates the audit trail automatically. The auditor can request the lineage for any reported figure and receive a PDF evidence pack that includes the source document, the calculation steps, and the final total.

  2. Reproducibility is enforced by the calculation layer. Emission3's deterministic LLM layer applies the emission factors, allocation rules, and boundary definitions transparently, so the auditor can replay the calculation independently. If the auditor questions an assumption, the system can rerun the calculation with the auditor's factor and show the sensitivity.

  3. Population completeness is testable. Emission3 ingests the full accounts payable ledger, the full utility account portfolio, and the full supplier list, so the auditor can confirm that no sources were omitted. The system flags any gaps (e.g., a facility with no utility bills in Q3) before the audit begins.

  4. Methodological documentation is version-controlled. The calculation methodology is documented in the system, and any changes (e.g., switching from spend-based to activity-based factors for Category 1) are logged with a timestamp and justification. The auditor can review the methodology history and confirm consistency across periods.

For CBAM filers, the same infrastructure applies: the embedded emissions calculation is reproducible from the electricity invoices, the production logs, and the emission factors, with the full evidence pack exportable for the verifier. The difference between Emission3 and a generic carbon accounting platform is that Emission3 is built for the auditor's workflow, not the sustainability team's workflow. The output is not a dashboard—it is an assurance-ready evidence file.

If your team is preparing for a CSRD limited assurance engagement or a CBAM verification in 2026, the question is not "do we have the emissions total calculated?" The question is "can an auditor reproduce our calculation without asking us for help?" That is the audit-grade terminology gap. If you are not sure, book a CBAM readiness call and we will walk through the 12 terms above with your filing in hand.[9]

The 2026 assurance season will be a vocabulary test

The compliance officers who succeed in 2026 will not be the ones with the most sophisticated carbon accounting platforms. They will be the ones who can speak the auditor's language before the engagement begins. The 12 terms above are not aspirational. They are the words the auditor will use in the first meeting, and if the compliance officer cannot define them, the auditor will spend the first billable hours teaching them. That tutorial is expensive.

The path forward is to learn the vocabulary now, map it to your current evidence assembly process, and identify the gaps before the auditor does. The companies that treat 2026 as a learning year will face a scramble in 2027. The companies that treat 2026 as the year they build audit-grade infrastructure will find that 2027 is a repeat engagement with known costs. The terminology gap is closable, but it requires treating the auditor as the primary user of the compliance system, not a downstream reviewer of the sustainability report.

If you are preparing for your first CSRD or CBAM filing and want to close the terminology gap before the auditor arrives, book a CBAM readiness call. We will map your suppliers, gaps, and implementation timeline, and walk through the 12 terms above with your filing in hand.[9]

References & Sources

External Sources

  1. [1]
    CSRD Audit & Assurance: How to Prepare for Compliance

    EFRAG guidance on CSRD assurance standards and the October 2026 deadline for limited assurance procedures.

  2. [2]
    Do You Need Reasonable Assurance for Sustainability Data? - ESG Simplified

    Comparison of limited and reasonable assurance costs and procedures under ISSA 5000.

  3. [3]
    ISSA 5000 Explained: How to Prepare for Mandatory Sustainability Assurance in 2026

    IAASB guidance on ISSA 5000 application to CSRD and California SB 253 reasonable assurance.

  4. [4]
    CSRD reporting: a complete guide for EU companies in 2026

    CBAM Implementing Regulation (EU) 2023/1773 Article 7 requirements for reproducible calculation methodology.

  5. [5]
    How to Prepare for a CSRD Audit: A Step-by-Step Guide

    ISSA 5000 paragraph A77 on reproducibility and internal control evaluation.

  6. [6]
    CSRD Audit: What Companies should Know Now

    ESRS E1 paragraph 44 and 51 requirements for boundary disclosure and methodological documentation.

  7. [7]
    The executive-liability cost cascade in CSRD limited-to-reasonable assurance transitions

    California SB 253 executive officer statement requirements and personal liability under Corporations Code Section 25540.

  8. [8]
    CSRD Assurance | Limited and Reasonable Assurance Engagement

    EU October 2028 assessment timeline for reasonable assurance feasibility under CSRD.

Related Content

  1. [9]
    Book a CBAM readiness call

    All customers start with a readiness call: we map suppliers, gaps, and implementation, no anonymous self-serve onboarding.

  2. [10]
    Audit-ready exports in Emission3

    For auditors and CFOs, shows the evidence lineage artifact and deterministic calculation replay.

Need help operationalizing this for your organization?

Book a CBAM readiness call: we map suppliers, reporting gaps, and a practical workflow using the same infrastructure we deploy for EU registry outputs.