Documentation Standards for Assurance
The carbon accountant who built the whole Scope 3 inventory was on a flight to Singapore when the assurer arrived. Her manager opened the file the assurer asked for, the basis behind the largest emissions figure in the report, and found a spreadsheet with a total, a tab of supplier numbers, and a folder of emails. No statement of how the figure was built. No record of which factors were used or where they came from. No note of the estimates, their methods, or who approved them. The number was probably right. Nobody in the room could prove it, because the only person who could rebuild it was over the Bay of Bengal. The engagement stalled, the finding wrote itself, and the lesson landed hard: a number you cannot reconstruct without the person who made it is not assured, it is merely asserted. This lesson is about the documentation discipline that lets someone rebuild a number without you in the room.
What "Reconstructable" Actually Requires
The whole of assurance documentation collapses to one test: can a competent person, handed only your file and no access to you, rebuild the published number from raw data to final figure and arrive at the same result? That is what reconstructable means, and it is a higher and more specific bar than "we kept the data." A pile of correct inputs is not reconstructable if the path from inputs to output is in your head. The figure on the page is the end of a chain, and reconstructability means the entire chain, every input, every factor, every method, every adjustment, every decision, is visible and re-walkable by a stranger. The flight-to-Singapore failure was not a data failure. The data was all there. It was a reconstructability failure: the path was missing.
This reframes documentation from a clerical afterthought into the actual deliverable. In a regulated, assured disclosure, you are not really producing a number; you are producing a number plus the proof of how it was made, and the proof is what assurance tests. A figure without its reconstruction is, to an assurer, an unsupported assertion, no matter how correct it happens to be, because correctness you cannot demonstrate is indistinguishable from luck. The discipline that follows exists to make every material number re-walkable by someone who was not there, which is the only form of correctness assurance can accept.
The Four Pillars of an Assurance-Grade File
Reconstructability is built from four documentation components that together let a stranger rebuild any number. Each answers a different question the assurer will ask, and a file missing any one has a hole a competent rebuild will fall into.
The Basis-of-Preparation
The first pillar is the basis-of-preparation, the document that states how the disclosure was built: the reporting boundary, the consolidation approach, the standards and frameworks applied, the methods chosen for each category, the emission-factor sources, the estimation approaches, and the key judgments. It is the map of the whole inventory, the thing that tells a stranger what kind of number they are looking at before they trace any single figure. An assurer reads the basis-of-preparation first, because it frames everything: a figure that looks wrong may be right under the stated method, and a figure that looks right may be wrong if the boundary was drawn improperly. Without a basis-of-preparation, every number is unmoored, because the reader does not know the rules under which it was produced. With one, every number has a context that makes it testable.
The Evidence Trail
The second pillar is the evidence trail, the linked chain from each published figure back to its raw source. For a number, this is the activity data tied to its source document, the emission factor tied to its named dated database, and the calculation tied to both. For a qualitative claim, it is the claim tied to its supporting record. The evidence trail is what turns "trust me" into "trace it": the assurer picks a figure, follows the trail, and confirms each step. A trail with a gap, an activity figure with no source, a factor with no database, an estimate with no method, is exactly where the rebuild stops and the finding starts. The evidence trail is the reconstructability of an individual number, where the basis-of-preparation is the reconstructability of the whole.
Version Control
The third pillar is version control, the record of every change to a figure, a method, or a document, with what changed, when, and why. Numbers move during a reporting cycle: a supplier responds late, a factor is revised, an error is corrected, an estimate is replaced with primary data. Without version control, the file shows only the final state and cannot explain how it got there, which is fatal when an assurer asks why this year differs from a draft they saw, or why a figure changed after a particular date, or how a prior-year number can be reconstructed for a restatement. Version control is also what makes a restatement, a correction of a previously published figure, a controlled process rather than a crisis: you can show exactly what the old number was, why it was wrong, and how the new one was derived, because the history is preserved rather than overwritten.
Sign-Offs
The fourth pillar is sign-offs, the record of who reviewed and approved what, and when. Assurance rests on accountability, and accountability has to be attributable: a figure that was prepared, reviewed, and approved by named people at recorded points is a controlled figure, while a figure that simply appeared is an orphan. Sign-offs matter especially where AI was involved, because the cardinal rule is that accountability stays human: the file must show that a named person reviewed the AI-assisted output and approved it, so that "the model produced it" is never the end of the trail. The sign-off is where the human takes ownership on the record, which is what makes the number defensible when someone asks who stands behind it.
A number you can reconstruct without the person who made it is assured. A number only its author can rebuild is merely asserted. The documentation is not the paperwork around the disclosure. It is the proof that the disclosure is true, and it is the deliverable assurance actually tests.
Limited Versus Reasonable Assurance, and What Each Demands of the File
How heavy the documentation must be depends on the level of assurance, and the difference is not cosmetic. Under limited assurance, the most common level today, the assurer performs procedures sufficient to conclude that nothing has come to their attention suggesting the disclosures are materially misstated. This is a negative form of conclusion based on a lighter, more selective set of procedures: they sample, they enquire, they test where risk concentrates. The file must support that sampling, so every material figure needs its basis, its evidence trail, and its sign-off ready, because any of them might be the one they pull.
Under reasonable assurance, the higher level the market is trending toward, the assurer performs more extensive procedures to conclude positively that the disclosures are prepared, in all material respects, in accordance with the criteria. This is a positive conclusion requiring substantially more testing, larger samples, and deeper substantiation, so the documentation demand rises sharply: more figures are traced, the evidence trail is probed harder, the basis-of-preparation is tested against the actual numbers, and gaps that a limited engagement might never sample become near-certain findings under a reasonable one. The practical implication is forward-looking: build the file to reasonable-assurance standard even while your current engagement is limited, because the market is moving toward reasonable assurance, and a file that only survives sampling will not survive substantiation. The cheapest time to build a reconstructable file is while you are making the number, not when the engagement upgrades.
A Worked Example: The Same Number, Documented Two Ways
Take the Scope 3 Category 1 figure from the opening and document it two ways, then run the rebuild test on each. The published figure is 5,760 tonnes CO2e for purchased goods and services, built from five suppliers' primary data and seven estimated suppliers.
Before, the un-reconstructable file. The file is a spreadsheet showing 5,760 tonnes, a tab listing twelve suppliers with a number against each, and a folder of supplier emails. There is no basis-of-preparation, so the reader cannot tell which suppliers were primary and which estimated, what method or factors were used, or how the boundary was drawn. There is no evidence trail, so a number against a supplier cannot be traced to a source. There is no version control, so the late supplier response that changed the total leaves no record. There is no sign-off, so no named person owns the figure or the AI-assisted estimates inside it. When the assurer tries to rebuild 5,760, they cannot get past the first supplier without the author, and the engagement stalls. The number was correct and is indefensible.
After, the reconstructable file. The same figure carries its four pillars. The basis-of-preparation states the boundary, that Category 1 used primary data where available and a spend-based estimate otherwise, the named dated factor sources, and the estimation method with its uncertainty approach. The evidence trail links each of the five primary suppliers to its supplier-reported figure and source, each of the seven estimates to its spend input, named factor, and arithmetic, and the total to the sum. Version control records that one supplier responded on a specific date, replacing an estimate of a stated value with a primary figure, moving the total from a prior value to 5,760, with the reason logged. Sign-offs show the accountant prepared it, a reviewer checked it, and a named owner approved it, including explicit review of the AI-assisted estimates. Now a competent stranger, handed only this file, rebuilds 5,760 from raw data to total without anyone in the room: primary figures from sources, estimates from spend times named factors, the late-response adjustment explained, every step owned. The assurer traces a sample, finds each step supported, and moves on. Same number, same facts, and the difference is a file built to be rebuilt.
That is reconstructability made concrete. The test is brutally simple and worth running on every material figure before filing: hand the file to a colleague who was not involved and ask them to rebuild the number. If they can, it is assured-ready. If they need you, the documentation is not finished, however correct the number is, because the one thing assurance cannot accept is a figure that lives only in its author's head.
Building the File As You Go, Not at Cycle End
The single most common way teams fail this is timing. They write the inventory and the narrative first, treat the documentation as a wrap-up task, and arrive at the assurance window with a fortnight to retrofit a basis-of-preparation, reconstruct evidence trails from memory, and chase sign-offs from people who have moved on to next year's work. The retrofit is slow, error-prone, and frequently impossible, because the knowledge that would have made a figure reconstructable, why this factor, which suppliers were estimated, what the late adjustment was, has already evaporated. The figure that was effortless to document the day it was made becomes a forensic exercise three months later, and sometimes the honest finding of that exercise is that the file cannot actually explain its own number.
The discipline that defeats this is to make documentation a property of producing the number, not a phase after it. The moment a figure is calculated, its basis context is recorded, its evidence trail is linked to source and factor, a version entry is opened, and a sign-off slot is created and filled when reviewed. This costs a little at every step and almost nothing in aggregate, because each figure is documented while its maker still holds the context in their head. It also surfaces gaps early: a figure that cannot be linked to a source the day it is made is a problem you can fix that day, when fixing it is cheap, rather than a hole you discover under the assurer's question, when fixing it is a finding. The file is not a deliverable you assemble at the end. It is a residue the workflow deposits as it runs, if the workflow is built to deposit it.
The Cost Asymmetry That Makes Continuous Documentation Rational
It is worth being explicit about the economics, because the deadline always argues for deferral and the argument is wrong. Documenting a figure at the moment of creation costs minutes, because every input, choice, and source is immediately to hand. Documenting the same figure weeks later costs hours, because the context must be reconstructed, and reconstructing it requires re-finding sources, re-deriving methods, and re-interviewing whoever remembers. And documenting it after the assurer has already flagged its absence costs a finding, a stalled engagement, and a credibility hit, which is a different order of expense entirely. The cost of documentation rises steeply and discontinuously with delay, so the rational moment to do it is always now, at creation, when it is cheapest, even though the deadline pressure of the moment always whispers that you can do it later. Teams that internalise this asymmetry build the file as they go and never face the cliff. Teams that do not face it every cycle.
Common Documentation Failures and How They Read to an Assurer
Reconstructability fails in recognisable, repeatable ways, and naming them lets you catch your own file before the assurer does. Each failure feels minor in the moment and reads as a finding in the engagement, which is exactly the trap.
The orphaned number. A figure appears in the inventory with no trail to a source, no method note, and no sign-off, often because it was pasted in from a side calculation or an AI output and never wired into the file. To the preparer it is just a cell. To the assurer it is a number with no provenance, the single most common and most fatal finding, because an orphaned number is indistinguishable from a fabricated one. The fix is the standing rule that no figure enters the inventory without its trail and its owner attached.
The silent overwrite. A figure is corrected in place during the cycle, the old value gone, no record of the change. The final number may be right, but the file cannot answer why it differs from an earlier draft the assurer saw, and an unexplained change is itself a flag, because the assurer cannot distinguish a legitimate correction from a quiet manipulation. The fix is version control that logs every change rather than overwriting, so the history is preserved and every movement has a reason on the record.
The phantom basis. A basis-of-preparation exists but describes the method the team intended to use, not the one the calculations actually followed, because the basis was written early and the numbers drifted from it without the document being updated. Under reasonable assurance, where the basis is tested against the actual numbers, this mismatch is a systemic finding that can undermine a whole category. The fix is to treat the basis as a living document that is updated whenever a method changes, so the stated rules always describe what was actually done.
The rubber-stamp sign-off. A sign-off exists, but the approver glanced at a total and never examined the figure or its AI-assisted components, so the accountability the sign-off implies is hollow. Assurance tests whether controls operated, and a review that did not review is a control failure regardless of the number being correct. The fix is to make sign-off mean substantive review, with the reviewer confirming they checked the figure against its evidence, especially where AI produced it.
Key Takeaways
- Reconstructable means a competent person, handed only your file and no access to you, can rebuild the published number from raw data to final figure and get the same result; a pile of correct inputs is not reconstructable if the path from inputs to output is in your head.
- Documentation is the actual deliverable, not paperwork: in an assured disclosure you produce a number plus the proof of how it was made, and a figure without its reconstruction is an unsupported assertion no matter how correct it is.
- The basis-of-preparation states how the disclosure was built, the boundary, methods, factor sources, estimation approaches, and key judgments, and it is the map the assurer reads first because it frames whether any figure is right.
- The evidence trail links each published figure back to its raw source, activity data to source document, factor to named dated database, calculation to both, and a gap in the trail is exactly where the rebuild stops and the finding starts.
- Version control records every change with what, when, and why, and it is what makes a restatement a controlled process rather than a crisis, because the old number, its error, and the new derivation are all preserved.
- Sign-offs record who reviewed and approved what and when; they matter especially with AI, because accountability stays human and the file must show a named person reviewed and approved the AI-assisted output so the model is never the end of the trail.
- Limited assurance is a negative conclusion from lighter, selective procedures; reasonable assurance is a positive conclusion from extensive testing, so its documentation demand is far higher, and you should build to the reasonable standard now because the market is trending toward it.
- The rebuild test is the simplest assurance-readiness check: hand the file to a colleague who was not involved and ask them to rebuild the number; if they need you, the documentation is unfinished, because a figure that lives only in its author's head cannot be assured.
Skill.re