โ†
AI for ESG & Sustainability Reporting
Aware ยท M14 ยท lesson 14 of 19 ยท queued
Preview โ€” browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll โ†’
The Cardinal Rule: No Number Without a Source
๐Ÿ“–
now learning

The Cardinal Rule: No Number Without a Source

15 min

An assurer sits down with your sustainability report and does something deceptively simple: she starts pulling numbers out of it and asking, one at a time, "where did this come from." Not most numbers. Not the big ones. Any number she chooses, in any order she likes. The entire fate of your disclosure rests on a single property of your file: that every figure she points at has an answer waiting underneath it. That property has a name, and it is the rule the whole program rests on.

The Rule, Stated Plainly

Here is the cardinal rule of AI-assisted disclosure, the one principle that, if you internalize nothing else, keeps you out of trouble: no number without a source. Every figure you publish must trace to evidence, the assurer reads everything, and accountability stays with the discloser, never the tool. Compressed to a sentence you can carry into any meeting: AI assists, the human decides, the file proves it.

This is not a productivity tip and it is not a nice-to-have. It is the load-bearing wall of the entire discipline. Every other technique in this program, every verification habit, every labelling convention, every workflow design, exists to serve this one rule. If a number traces to a source, the rest follows. If it does not, nothing else can save it.

No number without a source. Every figure traces to evidence, the assurer reads everything, and accountability never transfers to the tool.

Let us take the rule apart, because each clause carries weight, and then make it concrete with the idea that turns it from a slogan into a working practice: the basis of preparation.

One framing helps before we begin. People often hear "no number without a source" as a constraint, a thing that slows them down and adds work. It is more useful to hear it as a promise the rule makes to you. If you honor it, you are never caught out. There is no figure in your report that can surprise you in front of an assurer, no question you cannot answer, no thread that, when pulled, unravels something. The rule is the difference between a report you have to hope about and a report you can stand on. That is not a constraint. That is the only position from which a disclosure professional can work without fear.

Every Figure Traces to Evidence

The first clause is the literal heart of it. Tracing to evidence means that for any figure in the report, you can produce the thing it rests on: a meter reading, an invoice, a supplier submission, a named and dated emission factor, or a documented and methodical estimate. The figure and its evidence are connected by a path someone else can walk.

Notice the word someone else. The test is not whether you remember where a number came from. It is whether a person who was not in the room, the assurer this year, your successor next year, a regulator in three years, can start at the published figure and arrive at the underlying evidence without your help. That is reconstructability, and it is the real standard. A number you can explain from memory is not traced; a number a stranger can rebuild from your file is.

This is exactly where AI both helps and threatens. AI helps by extracting, drafting, and organizing at speed. AI threatens because it can produce a figure with no path underneath it, a number that exists only because the model generated it. The rule does not care which tool produced the figure. It cares whether the path exists. A figure from a spreadsheet, a figure from a colleague, and a figure from an AI are all judged by the same question: trace it.

Make the test physical. Imagine printing your report, handing it to a competent stranger along with your evidence folder, and leaving the building. For any figure they pick, can they walk from the printed number to the meter reading, the invoice, or the factor database entry that produced it, and arrive at the same value? If yes, that figure is traced. If they reach a point where the only way forward is to phone you, it is not. This is not a metaphor for the assurer; it is very close to what the assurer literally does, except that the assurer is trained, skeptical, and selecting the figures most likely to be weak. Designing for the indifferent stranger is how you pass the hostile expert.

The Assurer Reads Everything

The second clause sets the audience, and it is harsher than most people assume. The assurer is the independent external party who checks your disclosures, and a useful working assumption is that the assurer reads everything and can sample anything. You do not get to choose which numbers get checked. You cannot hide a weak figure in a large table and hope it goes unnoticed. Under a limited assurance engagement (the most common type today, where the assurer does enough work to say nothing has come to their attention suggesting the figures are materially misstated), they already sample across the report. Under reasonable assurance (a higher level, closer to a financial audit, that the market is trending toward), they test more deeply still.

Design for this. If you build your file assuming only the headline numbers will be checked, you are building a trap for yourself, because the one figure you did not support is exactly the one a sampling methodology is designed to find. The discipline is to treat every number as if it will be the one the assurer pulls, because any of them can be. A file built that way has no soft spots. A file built any other way has a soft spot you cannot predict and the assurer's sampling can.

Accountability Stays With the Discloser

The third clause is the one people most want to wish away, and it is the most important. Accountability for the disclosure stays with the company and the people who sign it. It does not transfer to the AI, and it does not transfer to the software vendor. "The model recommended it" is not a defense to an assurer, and it is not a defense to a regulator. Neither is "the platform calculated it." The obligation is yours; the tool is just a tool.

This is liberating once you accept it, because it tells you exactly where to spend your attention. You do not need to understand the model's internals. You need to ensure that every output you adopt, you can stand behind, because you, not the model, are standing behind it. The human in "AI assists, the human decides" is not a formality. It is the legally and professionally accountable party, making a real decision to accept or reject each figure, and leaving a record of having done so.

This is why a named human decision matters so much in the file. It is not bureaucracy. It is the visible point where accountability was exercised: a person looked at this number, judged it supported, and took responsibility for it. An AI cannot do that, because an AI cannot be held responsible. Only a discloser can.

Why the Obligation Cannot Transfer

It is worth dwelling on why this is structurally true and not just a matter of policy. A disclosure is a statement the company makes to the market and to regulators. The law and the assurance standards attach the duty of that statement to the entity making it, the same way a financial statement's accuracy is the company's responsibility even though accountants, software, and spreadsheets all contributed to it. The tool is upstream of the statement; the statement is the company's. Inserting an AI into the production process changes the speed of production. It does not change who is making the claim. When you publish a Scope 3 total, you are asserting it. The model did not assert anything; it produced text. You decided to publish.

For the working professional, this collapses a great deal of anxiety about AI into a single, manageable question. You do not need to certify the model. You do not need to audit its training data or understand its architecture. You need to be able to answer, for every figure you adopt, the assurer's question: where did this come from, and on what basis did you accept it. If you can answer that, the tool's nature is irrelevant. If you cannot, no amount of vendor reassurance about the tool will rescue the number, because the number's defense was always going to be yours to mount.

The Basis of Preparation: Where the Rule Becomes Real

A rule needs a place to live, and in disclosure that place is the basis of preparation: the document that explains how the numbers in your report were arrived at. It states the boundaries you set, the methods you used, the data sources you drew on, the emission factors and where they came from, the estimates you made and how, and the judgments you exercised. It is, in effect, the instruction manual for reconstructing your report.

The basis of preparation is where the cardinal rule stops being abstract. A strong basis of preparation is one in which every figure in the report can be traced through it to its evidence. When an assurer asks "show me the basis," this document, plus the evidence it points to, is the answer. If it is complete, the engagement is a process of confirmation. If it has gaps, every gap is a place the assurer stops and asks a question you may not be able to answer.

This reframes the role of AI beautifully. AI can help you build the basis of preparation faster: drafting method descriptions, organizing source lists, structuring the documentation. What AI cannot do is make a number true that has no evidence underneath it. So the basis of preparation is both the tool that operationalizes the rule and the test of whether you followed it. A report whose basis of preparation reconstructs every number is a report that obeyed "no number without a source." A report whose basis has holes is a report that did not, regardless of how good it looks.

Building the Trail as You Go, Not at the End

The single most common and most expensive mistake is to treat the basis of preparation as a write-up you assemble after the numbers are done, in the week before the assurer arrives. Built that way, it is a reconstruction from memory, and reconstruction from memory is exactly what the rule forbids. By the time you sit down to document where a figure came from, the analyst who produced it may have moved on, the source file may have been overwritten, and the factor may have been one of three the team tried. The trail you write is then a best guess about your own history, and an assurer can usually tell.

The disciplined alternative is to capture provenance and the accepting decision at the moment each figure enters, so the basis of preparation accretes continuously and is simply complete when the report is. This is precisely where AI-assisted workflows earn their place: a tool that tags every extracted figure with its source pointer, and a process that records who reviewed and accepted it, builds the trail as a byproduct of doing the work rather than as a painful afterthought. The speed of AI and the discipline of the rule are not in tension here. The same automation that pulls the kWh figure from the bill can attach the pointer back to that bill, so the figure arrives already traceable.

This is the deeper reason the cardinal rule and AI fit together rather than fight. The thing the rule demands, a path from every number to its evidence, is a structuring problem, and structuring is something software does well. What the rule withholds from the tool, the accountable decision and the truth of the underlying evidence, is exactly what no tool can supply. Keep those two on the right sides of the line and AI becomes the rule's best friend instead of its greatest threat.

Worked Example: Two Files Meet the Same Assurer

Two teams produce the same Scope 2 electricity figure, 12,400 tCO2e, using the same AI tools. The same assurer samples it. Watch the two files diverge. The point of the contrast is uncomfortable: the number is identical, the tooling is identical, and only the discipline differs, yet one team has a clean engagement and the other has a problem.

The File That Cannot Answer

Team A used AI to extract consumption from utility bills and to apply an emission factor, and entered 12,400 tCO2e. When the assurer asks "show me the basis," the team explains it from memory: the AI read the bills and used a standard factor. But the file does not show which bills, the extracted kWh figures carry no pointer back to source documents, and the factor has no named, dated reference. The number is probably right. It is also unreconstructable. The assurer cannot confirm it without redoing the work, the figure cannot be cleanly assured, and the team is now defending a number instead of resting on a file.

The File That Answers Itself

Team B used the identical AI tools, but built the file to the rule. Each kWh figure carries a provenance pointer to a specific utility bill, page, and line. The emission factor is cited to a named, dated source. The basis of preparation describes the boundary, the extraction method, the factor selection, and names the analyst who reviewed and accepted the figure. When the assurer asks "show me the basis," the team hands over the document and the evidence trail, and the assurer reconstructs 12,400 tCO2e from raw bills to published figure without the team in the room. Same number, same tools, opposite engagement. One team defended a memory. The other rested on a file. That difference is the cardinal rule, made concrete.

And notice the second-order effect. Team A is now spending the engagement in defensive conversations, redoing work to satisfy the assurer, and discovering at the worst possible moment that some bills cannot be located. Every hour of that is more expensive and more stressful than the minutes it would have taken to attach a pointer at entry. Team B is spending the engagement watching the assurer confirm what the file already shows. The cardinal rule does not just protect the number. It changes which kind of week you have when the assurer arrives, and it does so without anyone working harder, only more deliberately.

How the Whole Chapter Converges on This Rule

It is worth stepping back to see that this rule is the destination the entire chapter was walking toward. The first lesson showed where AI genuinely helps, and every one of those wins came with a verification obligation, which is just the cardinal rule applied to a specific task. The second lesson named the asymmetry, easy to generate and hard to defend, and showed that an unsupported number is a liability, which is what the cardinal rule exists to prevent. The third lesson catalogued the hallucinations, invented factors, fabricated data, fake targets, softened impacts, and each of those is precisely a number or claim with no source, which the cardinal rule forbids by name.

So the four lessons are not four separate ideas. They are one idea approached from four directions. AI is a powerful assistant whose outputs must be traced to evidence, decided on by an accountable human, and proven in a file an assurer can reconstruct. Master that, and the rest of this program is detail and technique built on a foundation you already trust. Skip it, and every technique downstream is built on sand, because a fast workflow that produces unsupported numbers has only made it easier to fail. The cardinal rule is not the strictest thing you will learn. It is the thing that makes everything else worth learning.

Key Takeaways

  • The cardinal rule is the load-bearing wall of the whole program: no number without a source. Every figure traces to evidence, the assurer reads everything, and accountability stays with the discloser.
  • Carry it as one sentence: AI assists, the human decides, the file proves it.
  • Tracing to evidence means reconstructability: a person who was not in the room can start at the published figure and reach the underlying evidence without your help. A number you can explain from memory is not traced.
  • Assume the assurer reads everything and can sample anything. Build every figure as if it is the one that will be pulled, because under sampling any of them can be.
  • Accountability never transfers to the tool. "The model recommended it" and "the platform calculated it" are not defenses; the obligation is the discloser's and a named human decision is where it is exercised.
  • The basis of preparation is where the rule becomes real: the document that explains boundaries, methods, sources, factors, and estimates so the report can be reconstructed.
  • AI can help build the basis of preparation faster, but it cannot make a number true that has no evidence underneath it. The basis is both the tool for the rule and the test of whether you followed it.
  • Two teams with the same number and the same AI can have opposite engagements: one defends a memory, the other rests on a file. Building to the rule is the entire difference.