The methodology-drift problem in multi-year Scope 3 assurance

Emission 3 Team
The methodology-drift problem in multi-year Scope 3 assurance

The methodology-drift problem in multi-year Scope 3 assurance

Here's the issue: your Scope 3 inventory looks complete. You have 15 categories mapped, emissions calculated by GHG Protocol methods, and a base year locked. The spreadsheet exports to your CSRD filing. Then your auditor schedules the limited assurance kickoff and asks for your methodology documentation pack. You send the calculation workbook. They come back with a single question: which emission factor database did you use for Category 1 in the base year, and did you use the same version this year? You realise you switched from DEFRA 2024 to ecoinvent 3.10 mid-cycle because a consultant recommended it. The trend you reported is no longer comparable. The assurance timeline just doubled.

However, Scope 3 assurance consists of two things: emissions totals and methodology consistency.

Emissions totals on their own have no value. Methodology consistency is what the auditor is actually verifying. ESRS 1 states that an undertaking must provide restated comparative figures when it has redefined or replaced a metric, identified new information regarding estimated figures from the preceding period, or discovered material prior period errors. [1] Switching emission factor databases mid-process creates both problems simultaneously. The auditor cannot attest to a trend they cannot reproduce.

While emissions calculation has become cheaper through software and API access to factor databases, methodology documentation has become more expensive. If you change your calculation approach between the base year and the reporting year without documenting the change and restating prior periods, the cost of reconciliation and restatement might outpace the time you saved by switching tools. An ESRS E1-compliant methodology note requires you to name the databases used, specify the version and year, and explain any changes with quantified impact. [2] That documentation work is manual, and it scales with the number of methodology changes you made.

How do you solve this? I think the operators we work with lock three things before they start the base year inventory: the emission factor sources they will use, the GHG Protocol calculation approach per category, and the boundary definition for included and excluded entities. They treat those as fixed for the assurance period, typically three years under CSRD's limited-to-reasonable assurance escalation. For now, that discipline is the only way to avoid methodology drift becoming an assurance blocker.

The shape of the argument, visualised below.

Why methodology consistency determines assurance cost

Auditors conducting limited assurance under ISAE 3410 or ISSA 5000 are not verifying that your Scope 3 number is correct. They are verifying that your reported number was calculated using the methodology you documented, applied consistently across periods, and supported by traceable evidence. The distinction matters because the second task is what determines the hour count in your assurance engagement letter.

Consider a three-year assurance cycle under CSRD. Year one is your base year, reported in 2026 for financial year 2025. Year two adds comparative data. Year three triggers the escalation from limited to reasonable assurance under ESRS 1. [3] If you change your emission factor database between year one and year two without restating the base year, the auditor must now:

  1. Verify that the year two calculation is correct under the new methodology.
  2. Assess whether the base year figures would have been materially different under the new methodology.
  3. Determine whether the change constitutes a change in estimate (disclosure only) or a prior period error (restatement required).
  4. Document the quantitative impact of the methodology change on trend claims in your narrative disclosures.

That is four workstreams where you budgeted for one. The marginal cost is not in the calculation software. It is in the auditor's time reconciling two methodologies across two reporting periods.

Methodology elementBase year (2025)Reporting year (2026)Assurance impact if inconsistent
Emission factor databaseDEFRA 2024ecoinvent 3.10Auditor must restate base year or qualify opinion
GHG Protocol approach (Category 1)Average-data methodSupplier-specific methodTrend not comparable without base year adjustment
Boundary (included subsidiaries)12 entities14 entities (2 acquisitions)Organic growth vs. acquisition must be disclosed separately
Data quality split (primary vs. secondary)18% primary31% primaryProgress narrative must reconcile methodology vs. coverage improvement

The table shows four common drift points. The first two require base year restatement. The third requires segment disclosure. The fourth requires narrative reconciliation between methodology improvement and data coverage improvement, a distinction ESRS E1 makes explicit in its data quality disclosure requirements. [2]

The four methodology lock points before base year inventory

The GHG Protocol Corporate Value Chain (Scope 3) Standard defines four calculation approaches: supplier-specific, hybrid, average-data, and spend-based. [4] The choice between them is the most consequential methodology decision you will make, and the one most likely to drift if not locked before the base year.

Here is the decision sequence:

1. Emission factor sources. Name the databases you will use per category and lock the version. If you are using DEFRA for UK activity data, ecoinvent for European supplier data, and EPA USEEIO for US spend-based estimates, document that mapping now. Include the version number and publication year. When the 2027 versions are released mid-cycle, you do not upgrade until the next base year restatement window. Auditors will check whether you used the most current version at the time of calculation. [5] That means the version current at base year lock, not the version current at filing.

2. GHG Protocol calculation approach per category. Specify which of the four approaches you are using for each of the 15 categories and why. If you are using supplier-specific data for your top 20 suppliers in Category 1 and average-data for the rest, document the threshold and the coverage percentage. That split is your baseline. Next year, if you increase supplier-specific coverage to 40 suppliers, the trend improvement is in data quality, not methodology. The auditor can trace that. If instead you switch the remaining suppliers from average-data to spend-based because you lost access to production volume data, that is a methodology change requiring restatement.

3. Reporting boundary. List the entities included in the inventory and the entities excluded with rationale. ESRS E1 requires you to disclose the entities included in your GHG inventory and explain any differences between your GHG boundary and your financial consolidation boundary. [6] If you acquire a new subsidiary mid-cycle, you must disclose whether the emissions increase is organic growth or acquisition-driven. That disclosure is only possible if your base year boundary was documented at the start.

4. Data quality classification. Disclose the proportion of Scope 3 data obtained from suppliers (primary) versus estimated (secondary). ESRS E1 makes this a required disclosure, not an optional one. [5] Lock your primary-vs-secondary split definition before the base year. If you define primary data as "supplier-measured at installation level" in year one, you cannot redefine it as "supplier-reported regardless of measurement basis" in year two without restating the base year classification. The auditor needs a consistent definition to verify your data quality improvement claims.

"ESRS 1 dictates that an undertaking must provide restated comparative figures when it has: redefined or replaced a metric or target, identified new information regarding estimated figures from the preceding period, or discovered 'material prior period errors' (omissions or misstatements from a failure to use reliable information). Switching emission factor databases mid-process creates both problems simultaneously." [1]

The Normative Scope 3 reporting guide synthesises the interaction clearly: treat CSRD as your baseline because ESRS E1 is the most prescriptive on methodology documentation and assurance, then IFRS S2 alignment and California SB 253 compliance follow automatically. [1] An ESRS-compliant methodology note satisfies ISSB and CARB requirements without duplicative filings.

The restatement trigger matrix under ESRS 1

ESRS 1 paragraph 126 defines three restatement triggers: metric redefinition, new information about prior estimates, and material prior period errors. [7] Each has a different documentation and disclosure threshold, but all three create assurance-hour inflation if encountered mid-cycle.

The restatement decision tree works like this:

Change in emission factor version within the same database (e.g., DEFRA 2024 to DEFRA 2025). This is typically a change in estimate, not an error. You disclose the impact quantitatively in the notes but do not restate prior periods unless the impact exceeds materiality (usually 5% of total Scope 3 or 1% of total enterprise emissions). The auditor will verify your materiality calculation and the quantified impact disclosure.

Change in emission factor database (e.g., DEFRA to ecoinvent). This is a methodology change, equivalent to metric redefinition. ESRS 1 requires restatement of all prior periods presented, with disclosure of the reason for the change and its quantitative effect. The auditor must verify both the restated figures and the impact disclosure. If your CSRD report includes two years of comparative data, that is three years of recalculation and verification.

Change in calculation approach (e.g., average-data to spend-based). This is also a methodology change requiring restatement. However, if the change represents a data quality improvement (e.g., moving from spend-based to supplier-specific), ESRS E1 permits you to frame it as progress toward primary data targets rather than an error correction. The auditor will check that your base year used the best available data at the time, meaning the original methodology was not an error. If it was, the restatement is an error correction, not an improvement, and the disclosure language changes.

Change in reporting boundary (acquisition or divestiture). You must disclose the impact separately and restate prior periods for comparability, or provide separate metrics for organic and inorganic growth. CSRD filers typically choose separate disclosure because restatement of acquisition-driven boundary changes is not required under ESRS 1 if the impact is disclosed. [7]

The cost differential is significant. A change in estimate requires two hours of auditor time for impact quantification and disclosure review. A methodology change requiring restatement requires 15-25 hours per year restated: recalculation verification, lineage tracing, and comparative figures testing. Multiply that by three years and you have added 45-75 hours to your engagement, often at short notice when the drift is discovered during fieldwork.

Why data quality improvement is not the same as methodology drift

The single most common point of confusion in Scope 3 assurance is distinguishing between improving data quality and changing methodology. Both involve switching from secondary to primary data sources, but the assurance treatment is completely different.

Data quality improvement: increasing supplier-specific coverage within the same calculation approach. You document in your base year that you are using the supplier-specific method for Category 1 (purchased goods and services), with supplier-measured data for 18% of spend and average-data factors for the remaining 82%. Next year, you increase supplier-specific coverage to 31% of spend. Your calculation approach has not changed—you are still using the supplier-specific method as defined in the GHG Protocol. [4] The improvement is in data coverage, not methodology. ESRS E1 requires you to disclose your primary-vs-secondary split each year, so this improvement is reported in that disclosure line. [5] The auditor verifies the new supplier data, but does not restate the base year because the methodology was consistent.

Methodology drift: switching calculation approach. You document in your base year that you are using average-data for Category 1 because supplier engagement had not yet begun. Next year, you switch to the supplier-specific method because you now have primary data. This is a methodology change under ESRS 1. [7] The auditor must determine whether the base year should be restated to the supplier-specific method (if the data was available but not used), or whether the original average-data approach was appropriate given the information available at the time (in which case no restatement is required, but the methodology change must be disclosed with quantified impact).

The difference is whether your base year methodology was fit-for-purpose given the data available at the time. If it was, improving data quality over subsequent years is expected progress. If it was not—if you had access to supplier data but chose a less accurate method—the base year was an error and must be restated.

This is why methodology lock at base year is critical. You must be able to demonstrate to your auditor that the methodology you chose in the base year was the most accurate method available given the data you had access to. That demonstration requires documentation: the supplier engagement letters you sent, the data requests that went unanswered, the decision log that shows why you used average-data as a fallback. Without that documentation, the auditor cannot distinguish between planned data quality improvement and methodology drift, and will default to the more conservative treatment: restatement.

How Emission3 solves the methodology-lock problem

Emission3 is built on the principle that methodology lock must happen at base year commit, not at filing. The platform enforces three structural constraints:

1. Emission factor freeze per inventory. When you create a base year inventory, you select your emission factor sources (DEFRA, ecoinvent, EPA USEEIO, etc.) and Emission3 locks the version to the publication year of your base year. Subsequent inventories inherit that lock by default. If you want to upgrade to a newer version, Emission3 forces a restatement workflow: it recalculates the base year under the new factors, generates a restatement impact report, and flags whether the change exceeds your materiality threshold. That report is your ESRS 1 paragraph 126 disclosure, pre-built. [8]

2. Calculation approach documentation per category. For each of the 15 Scope 3 categories, you document which GHG Protocol approach you are using (supplier-specific, hybrid, average-data, or spend-based) and the evidence threshold for each. If you are using supplier-specific data for top suppliers and average-data for the rest, you define the spend threshold or supplier count that determines the split. Emission3 tracks that threshold across reporting periods and flags any category where you switched approaches without triggering a restatement review.

3. Primary-vs-secondary data classification. Every emissions line item is tagged as primary (supplier-measured or metered) or secondary (factor-based estimate). That classification feeds directly into your ESRS E1 data quality disclosure. When you increase primary data coverage year-over-year, Emission3 separates the data quality improvement from any methodology changes in the year-over-year variance report your auditor reviews. The distinction is explicit, not inferred.

The result is that your methodology documentation is version-controlled from base year commit. When your auditor asks for your methodology pack, you export a single document that shows: the emission factors used (database, version, publication year), the calculation approach per category (GHG Protocol method, evidence threshold), the reporting boundary (entities included, consolidation approach), and the data quality classification (primary-vs-secondary split). That document is identical in structure across all reporting periods, making the auditor's consistency check mechanical rather than interpretive.

The assurance-timeline consequence of methodology drift

The practical cost of methodology drift is not the recalculation. Modern software can recalculate an entire Scope 3 inventory in seconds. The cost is in the assurance timeline, specifically the lag between when the auditor discovers the drift and when they receive the restated figures and documentation.

A typical CSRD limited assurance engagement runs 8-12 weeks from kickoff to opinion. The first two weeks are planning and methodology review. Weeks 3-6 are evidence requests and testing. Weeks 7-8 are management representation letters and final reviews. If the auditor discovers methodology drift in week four during evidence testing, you have just collapsed your restatement window into the final four weeks of the engagement. Restatement requires:

  • Recalculation of base year emissions under the new methodology (1 week).
  • Auditor verification of the restated figures (1 week).
  • Preparation of the ESRS 1 paragraph 126 disclosure narrative (3 days).
  • Auditor review of the disclosure and impact quantification (2 days).
  • Board or audit committee approval of the restatement (timeline varies, often 1-2 weeks).

You are now in week eight with two weeks of work remaining. The engagement either extends (increasing fees) or you file without an unqualified opinion (increasing regulatory risk). Both are expensive.

The operators we work with avoid this by running a methodology consistency check 90 days before the assurance kickoff. They compare the current year's methodology documentation to the base year's, flag any drift points, and either revert to the base year methodology or commission the restatement work before the auditor arrives. That 90-day buffer is the difference between a clean eight-week engagement and a 12-week engagement with fee overruns.

What this means for you

If you are...Your methodology lock point is...The documentation you need before base year commit is...
A CSRD filer preparing for 2026 limited assuranceFY 2025 close (your base year)Emission factor database and version per category, GHG Protocol calculation approach per category, reporting boundary entity list, primary-vs-secondary data definition
A California SB 253 filer preparing for 2026 limited assuranceFY 2025 close (your base year under SB 253)Same as CSRD; CARB accepts ISSB-aligned disclosures, so ESRS E1 methodology documentation satisfies SB 253 [1]
An SBTi target-setter locking a base year before submissionTwo years before submission maximumGHG Protocol-compliant inventory with documented inclusions, exclusions, and data quality baseline per category [1]
A Scope 3 disclosure preparer not yet under assuranceYour next reporting cycleLock methodology now, even if assurance is two years away; retrofitting methodology documentation after the fact is what creates restatement risk

The common thread is that methodology lock is not a filing task. It is a base year task. If you are preparing your first CSRD filing for FY 2025 (reported in 2026), your methodology lock deadline was December 31, 2025. If you missed it, you are now in restatement risk for 2027 when you add comparative figures.

The path forward: methodology lock before base year inventory

The Scope 3 Standard revisions expected in late 2027 will not relax methodology consistency expectations. [4] The Phase 1 progress update published March 31, 2026 focuses on data quality, boundary setting, and verification disclosure—all of which increase the documentation burden, not reduce it. The revision will likely require explicit disclosure of verification status per category and mandate that companies disclose if their Scope 3 data has undergone independent review. [6] That is methodology lock by another name.

The practical next step for teams preparing for 2026-2028 assurance cycles is to treat methodology documentation as a base year deliverable, not a filing deliverable. Before you close your base year inventory:

  1. Select your emission factor databases and lock the version.
  2. Document your GHG Protocol calculation approach per category.
  3. Define your reporting boundary and your primary-vs-secondary data classification.
  4. Store that documentation in a version-controlled file that your auditor can access across reporting periods.

That discipline is what separates an eight-week assurance engagement from a 12-week engagement with restatement fees. The cost of methodology drift is not in the calculation. It is in the assurance timeline, and the timeline determines the fee.

If you are preparing a Scope 3 inventory for upcoming CSRD, SB 253, or SBTi assurance, book a CBAM readiness call with Emission3. [9] The call is not anonymous self-serve onboarding—it is a 45-minute methodology readiness review where we map your current documentation against the four lock points above and identify which methodology elements carry restatement risk if left undocumented. That review is the first step in an assurance-ready Scope 3 program, and it happens before your base year inventory is committed, not after.

[1] [2] [3] [4] [5] [6] [7] [8] [9]

References & Sources

External Sources

  1. [1]
    Scope 3 Reporting: CSRD & SBTi Requirements (2026)

    ESRS 1 restatement requirements and the base year methodology lock rationale for CSRD and SBTi alignment.

  2. [2]
    Scope 3 Emissions Disclosure Methodology: 2026 Practitioner's Guide

    ESRS E1 methodology documentation requirements including emission factor sources, calculation approaches, and data quality disclosure.

  3. [4]
    Scope 3 Standard Revisions Phase 1 Progress Update

    GHG Protocol's March 2026 update on Scope 3 revisions, focusing on data quality, verification disclosure, and methodology consistency expectations.

  4. [5]
    2025 GHG Emissions Calculation Methodology

    Example of production-grade methodology documentation showing emission factor version lock and calculation approach specification per category.

  5. [6]
    CSRD Reporting Requirements: A Practical Climate & ESRS E1 Guide

    ESRS E1 reporting boundary requirements and the four areas auditors focus on during limited assurance engagements.

  6. [7]
    GHG Protocol Updates 2026: Scope 2 & Scope 3 Accounting Guide

    The shift from spend-based to supplier-specific data and how it intersects with CSRD, IFRS S2, and SBTi data quality expectations.

Related Content

  1. [3]
    The assurance-escalation gap in CSRD limited-to-reasonable disclosure timelines

    The three-year escalation timeline from limited to reasonable assurance under CSRD and how it structures methodology lock windows.

  2. [8]
    Reporting & filings

    Emission3's CSRD, CBAM, and SB 253 filing generation with version-controlled methodology documentation and restatement workflows.

  3. [9]
    Book a CBAM readiness call

    All Emission3 customers start with a readiness call: we map suppliers, methodology gaps, and implementation, no anonymous self-serve onboarding.

Need help operationalizing this for your organization?

Book a CBAM readiness call: we map suppliers, reporting gaps, and a practical workflow using the same infrastructure we deploy for EU registry outputs.