Mapping the Reporting Cycle
A disclosure lead pins a single sheet of paper to the wall before the AI pilot kicks off. It is not a tool list and not a prompt library. It is a map of the reporting cycle, every stage from the first materiality interview to the last assured number, and beside each stage one of three coloured tags: green for AI-ready, amber for AI-assisted-with-verification, red for human-only. The CFO wants to "use AI across the report." The assurance partner wants to know exactly where a machine touched a number that will be assured. This one sheet answers both, and it is the thing every workflow in the rest of the program is built on. Without it, an AI pilot is a scatter of clever tricks. With it, the team knows precisely where speed is safe, where speed needs a checkpoint, and where speed is forbidden because a human must own the judgment.
Why the Map Comes Before the Tools
The instinct on most reporting teams is to start from the tool: a vendor demos an AI feature, someone gets excited, and a pilot is born around whatever the tool happens to do. This is backwards, and in a disclosure context it is dangerous. The report is not a single task that AI either does or does not do. It is a chain of distinct stages, each with its own inputs, its own evidence, its own failure mode, and its own relationship to the external assurer who will read the result. A model that is perfectly safe drafting one stage can be a career-ending liability deciding another. You cannot reason about that one tool at a time. You have to reason about it one stage at a time, against a picture of the whole cycle.
That picture is the map. Mapping the reporting cycle means laying out every stage in sequence and then asking, for each one, a single disciplined question: if AI did this step, what would an assurer need to see, and could the team show it. The answer sorts every stage into one of three categories, and that sorting is the foundation. It tells you where to deploy AI first (the green stages, where the win is large and the assurance risk is small), where to deploy it with a mandatory verification gate (the amber stages, where AI accelerates but a human must check before anything moves on), and where to keep it away from the decision entirely (the red stages, where the judgment is the deliverable and a model cannot own it).
The map is also how you talk to the two people pulling at you. To the CFO who wants AI everywhere, the map is an honest answer that is not a refusal: here is where it goes first, here is the win, here is the sequence. To the assurance partner who is nervous about machines touching assured numbers, the map is a commitment: here is every place AI is involved, here is the verification at each amber stage, and here are the red stages no model will ever decide. A team that walks into the engagement with this map has already answered the question the assurer was going to ask, which is the difference between leading the conversation and being cornered by it.
The Stages of the Reporting Cycle
Before you can tag anything, you have to name the stages honestly, including the unglamorous ones that teams skip on a whiteboard and then scramble to evidence under the engagement. A full corporate sustainability reporting cycle, for a large undertaking still in CSRD scope or a multinational adopting ISSB, runs through six families of work. Each is a place where AI either helps, helps-with-a-check, or must stay out.
Materiality assessment is where the cycle begins. The team gathers stakeholder input and impact and risk evidence, then determines which sustainability matters are material under double materiality, the test that asks both how the company affects people and planet (impact materiality) and how sustainability matters affect the company's value (financial materiality). The output is a defended list of material topics and the IROs (impacts, risks and opportunities) under each, with a documented basis the assurer can test.
Data collection is the gathering of activity data and qualitative evidence across the business and the value chain: utility bills, fuel logs, HR records, supplier responses, policy documents. This is the rawest material, and it is where the largest volume of AI-assisted extraction happens.
The GHG inventory turns activity data into emissions across Scope 1 (direct), Scope 2 (purchased energy), and Scope 3 (the value chain, across 15 GHG Protocol categories and typically around 75% of the footprint). Every line is activity data multiplied by an emission factor, and every factor and every method choice is a disclosure in its own right.
Disclosure drafting is the writing of the narrative and quantitative datapoints against the framework, the ESRS datapoints under CSRD or the IFRS S1 and S2 requirements under ISSB, including the qualitative descriptions of policies, actions, targets, and impacts.
Tagging is the machine-readable layer: applying the digital tags (the structured, taxonomy-based markup) that turn a human-readable disclosure into the digital filing a regulator and a machine can parse. A wrong tag is as much a misstatement as a wrong sentence.
Assurance is the external engagement itself, where an independent assurer tests the disclosure against evidence and issues a conclusion, today most often limited assurance and trending toward reasonable assurance. This stage is not something AI does; it is the lens through which every earlier stage is judged.
The Three Tags and What They Mean
The whole value of the map is in the discipline of the three tags. They are not a vague traffic light. Each carries a precise operating rule.
AI-ready
AI-ready means AI can do the bulk of the work and the residual assurance risk is low, usually because the output is non-numeric, easily checked, or a draft that a human will rewrite anyway. The output still gets reviewed, but the review is light because a mistake here does not silently corrupt an assured figure. Drafting a first version of a supplier questionnaire, summarising a long policy document into themes, producing a first plain-language draft of a narrative section that the disclosure lead will rewrite line by line: these are AI-ready, because the human reshapes the output before it matters and nothing the model produced enters the file as a load-bearing number on its own.
AI-assisted-with-verification
AI-assisted-with-verification is the amber heart of the map, and it covers the most valuable and most dangerous stages. Here AI accelerates real work that produces or touches an assured number, and a defined human verification step is mandatory before the output moves on. The model extracts a figure from an invoice (a human confirms it against the source), suggests an emission factor (a human confirms it in the named database), clusters stakeholder inputs into themes (a human owns the materiality conclusion), drafts a quantitative datapoint (a human checks every figure against the evidence). The rule for every amber stage is identical: the AI may produce the candidate, but a named human verifies it against the source before it becomes part of the disclosure, and the file records that verification. Skip the verification and an amber stage silently becomes a fabrication pipeline.
Human-only
Human-only means the judgment is the deliverable and accountability cannot be delegated to a model. The final materiality determination, the choice of organizational and operational boundary, the decision to call a negative impact material or not, the sign-off on a published figure, the representation made to the assurer: these are human-only not because a model could not generate words about them, but because the company is accountable for them and "the model decided" is never a defense to an assurer or a regulator. AI can inform a human-only decision by supplying inputs and drafts. It cannot make it.
A reporting stage is human-only whenever the deliverable is a judgment the company must answer for. AI can carry the inputs to the door of that judgment, but it can never walk through it, because accountability does not transfer to a model.
A Real Annotated Cycle, Stage by Stage
Here is the map filled in, the way the disclosure lead pinned it to the wall. Read it as the reference every later workflow points back to.
| Stage | What happens | Tag | Why, and the verification if amber |
|---|---|---|---|
| Materiality: gather stakeholder and impact inputs | Collect and cluster hundreds of inputs into candidate themes | AI-assisted-with-verification | AI clusters and themes the inputs fast; a human confirms the clustering did not drop or distort an inconvenient stakeholder, and the source of each input is preserved. |
| Materiality: determine what is material | Decide which topics and IROs are material under double materiality | Human-only | The determination is the company's judgment and the assurer tests its basis. A model cannot own it. |
| Data collection: extract activity data | Pull figures from invoices, bills, fuel logs, supplier files | AI-assisted-with-verification | AI extracts at scale; a human confirms each figure against the source document and preserves the source location on the datapoint. |
| Data collection: define the reporting boundary | Decide organizational and operational boundaries and exclusions | Human-only | An undocumented boundary exclusion is an assurance finding. The boundary is a documented human decision. |
| GHG inventory: select emission factors | Find and apply the conversion factor for each activity | AI-assisted-with-verification | AI shortlists candidates; a human confirms the factor in the named, dated database and records its full provenance. A hallucinated factor is the classic failure here. |
| GHG inventory: choose method and label data | Pick spend-based vs. activity-based; label primary vs. secondary | Human-only | Method choice is itself a disclosure, and the primary vs. secondary label is the distinction the assurer lives by. A human decides and labels. |
| Disclosure drafting: narrative datapoints | Draft the qualitative ESRS or ISSB narrative | AI-assisted-with-verification | AI drafts fast; a human checks every claim and figure against evidence and confirms no impact was softened and no target invented. |
| Disclosure drafting: first plain-language skeleton | Produce a rough first draft of a descriptive section | AI-ready | The disclosure lead will rewrite it; the model's draft is scaffolding, not a load-bearing figure. |
| Tagging: apply digital datapoint tags | Mark up the disclosure for machine-readable filing | AI-assisted-with-verification | AI proposes tags against the taxonomy; a human confirms each tag, because a wrong tag is a misstatement. |
| Sign-off: approve published figures | The named owner signs the disclosure | Human-only | Sign-off is the representation to the assurer and the regulator. It is the human owning the number. |
| Assurance: the external engagement | The assurer tests evidence and issues a conclusion | Human-only | Assurance is the lens, not a task AI performs. It judges every earlier stage. |
Read down the table and a pattern emerges that is the real lesson of the map. The amber stages are where AI earns its keep, and they are also where the discipline has to be ironclad, because every amber stage is one skipped verification away from feeding an unsupported number into an assured disclosure. The red stages are not red because AI is useless there; AI can supply inputs to every one of them. They are red because the output is a judgment the company must answer for. And the green stages are few, precisely because in disclosure almost nothing is consequence-free.
A Worked Example: Two Teams, Two Maps
Two reporting teams at comparable companies both decide to "bring AI into the GHG inventory." Watch how the presence or absence of the map decides their year.
Team A starts from the tool. Their carbon-accounting platform ships an AI feature that suggests emission factors and auto-fills Scope 3 categories from spend data. It is fast and it looks magical, so they switch it on across the inventory. There is no map, so there is no distinction between stages: factor selection, method choice, and primary-secondary labeling all get the same treatment, which is to say no verification gate at all. The AI suggests factors that mostly look right and fills gaps with spend-based estimates that land in the output looking exactly like measured data. The inventory closes in record time. Then the engagement begins. The assurer samples a Scope 3 line, asks for the source of the factor, and gets a number the model produced that lives in no database. They sample a category and find estimates presented as if they were primary activity data, with no method label and no uncertainty. The thread unravels. What was supposed to be a triumph of speed becomes a restatement, and worse, it puts every other number in the file under suspicion, because the assurer now has no reason to trust the team's process anywhere.
Team B starts from the map. Before touching the tool they tag the inventory stages. Factor selection: amber, the AI shortlists but the factor is confirmed in the named database and its provenance recorded. Method choice and primary-secondary labeling: red, a human decides and labels, because each is a disclosure. Activity-data extraction: amber, AI extracts but a human confirms against the source. The same AI feature gets switched on, but only where the map allows it, and every amber stage has its verification baked in. The inventory still closes far faster than the old manual process, because extraction and shortlisting are genuinely accelerated. But every factor traces to a database, every estimate is labeled and disclosed with its method, and the boundary and method choices are documented human calls. When the assurer pulls a thread, it holds: here is the factor, here is the database and version and year, here is what is primary and what is estimated, here is who decided the method. Same tool, same ambition, opposite outcome, and the only difference was that one team had the map and the other had a feature.
The lesson is not that Team A used AI and Team B did not. They used the same AI. The lesson is that AI without a stage-by-stage map applies the same level of trust to every step, and disclosure stages do not deserve the same level of trust. The map is what lets you give a green stage a light touch, an amber stage a hard verification gate, and a red stage a human owner, all in the same workflow. That differentiation is the entire point, and it is invisible to anyone reasoning from the tool instead of from the cycle.
Building and Maintaining Your Own Map
The map is not a one-time poster. It is a living control document, and building it well is a skill in itself. Start by writing out your actual cycle, not the idealized one, including the boundary decisions, the method choices, and the sign-offs that whiteboards tend to omit. For each stage, ask the disciplined question: if AI did this, what would the assurer need to see, and can we show it. If the answer is "a light review suffices and nothing load-bearing depends on the raw output," it is green. If the answer is "AI helps a lot but a human must verify the output against a source before it moves on," it is amber, and you write down what that verification is and who does it. If the answer is "this is a judgment the company must answer for," it is red.
Then keep it current. Frameworks shift: CSRD survived the Omnibus as Directive (EU) 2026/470 and narrowed the population, EFRAG's simplified ESRS draft is still in flight, ISSB issued targeted amendments to IFRS S2, and CBAM's definitive phase is live. Each change can move a stage's tag or add a stage. A new AI capability can turn a red stage amber if and only if a real verification step makes the output checkable, never just because the tool got more confident. And the map is the artifact you hand the assurer at the start of the engagement, the document that says: here is our cycle, here is where AI is involved, here is the verification at every amber stage, here are the human-only judgments. That single sheet does more to build assurer trust than any demo of the tool, because it proves the team thought about the assurance risk before the model touched a number, not after.
Key Takeaways
- Map the reporting cycle before you choose any tool: materiality, data collection, GHG inventory, disclosure drafting, tagging, and assurance are distinct stages with distinct failure modes, and AI's safety differs at each one.
- Tag every stage AI-ready, AI-assisted-with-verification, or human-only. The tag is an operating rule, not a label: green gets a light touch, amber gets a mandatory verification gate, red gets a human owner.
- Amber stages are where AI earns its keep and where discipline must be ironclad, because every amber stage is one skipped verification away from feeding an unsupported number into an assured disclosure.
- A stage is human-only whenever the deliverable is a judgment the company must answer for: the materiality determination, the boundary, the method choice, the primary-secondary label, the sign-off. AI can supply inputs but cannot own the call.
- Assurance is not a stage AI performs; it is the lens through which every earlier stage is judged. Tag each stage by asking what the assurer would need to see and whether you could show it.
- Starting from the tool applies the same trust to every step; disclosure stages do not deserve the same trust. The map is what lets one workflow give different stages different levels of scrutiny.
- The same AI feature can produce a triumph or a restatement depending only on whether a stage-by-stage map governs where it is allowed and where verification is mandatory.
- The map is a living control document and the first thing you hand the assurer: here is our cycle, here is where AI is involved, here is the verification at every amber stage, here are the human-only judgments. It builds trust before a model touches a number.
Skill.re