The CBAM Declaration Workflow
It is late January 2026 and a trade-compliance specialist at an EU importer is staring at a shipment of hot-rolled steel coil from a mill three time zones away. The definitive phase of the Carbon Border Adjustment Mechanism went live on the first of the month. Her company is now an authorised declarant, and the carbon embedded in that coil is no longer a footnote, it is a quantity she will have to declare, defend, and eventually pay for in surrendered certificates. The supplier has sent a spreadsheet of emissions figures. Some of them look too round to be real. This lesson is about building the declaration that survives the moment someone official asks her to prove them.
What CBAM Actually Asks of You
The Carbon Border Adjustment Mechanism is the EU's tool for pricing the carbon embedded in imports of certain carbon-intensive goods, so that an importer of high-carbon steel faces a cost comparable to a producer inside the EU emissions trading system. The definitive phase went live on 1 January 2026. Authorised-declarant applications were due 31 March 2026, and more than 12,000 were filed by early January. The first surrender of CBAM certificates falls in 2027. The covered goods are cement, iron and steel, aluminium, fertilisers, hydrogen, and electricity. A 50-tonne annual de minimis threshold exempts most small importers, so the people doing this work are importing at scale.
Two terms anchor everything. An authorised declarant is the importer, or its representative, that has been granted authorisation to bring covered goods into the EU customs territory and is the party legally responsible for the CBAM declaration. Why you care: the obligation and the liability sit with the declarant, not with the foreign producer who actually made the steel, and not with any software you bought to help. Embedded emissions are the greenhouse gas emissions released during the production of the imported good, expressed per tonne of product, covering the direct emissions of making it and, for some goods, specified indirect emissions from the electricity consumed. Why you care: embedded emissions are the quantity the whole mechanism turns on, and getting them wrong in either direction is a problem, understatement is a compliance exposure, overstatement is money paid for carbon you did not import.
So the CBAM declaration is not an ESG narrative. It is a quantitative customs filing, read by a customs and competent authority that can ask for the basis of every figure. The discipline is the same as the rest of this program, every number traces to evidence, but the evidence here lives mostly in another company, in another country, in a producer's installation you do not control.
That last point is what makes CBAM feel different from an internal GHG inventory, and it is worth dwelling on. When you build your own Scope 1 inventory, the evidence is yours: your meters, your bills, your sites, all reachable. When you declare embedded emissions for imported steel, the evidence sits inside a mill you have never visited, run by a company whose incentives are not yours, in a jurisdiction whose verification ecosystem you do not control. You remain fully accountable for figures generated by people you cannot direct. This asymmetry, total accountability over data you do not own, is the defining tension of the CBAM declarant's job, and the workflow exists to manage it: to turn data you cannot control into figures you can defend, or to fall back, deliberately and on the record, to a default when you cannot.
Actual Values Versus Default Values
The single most important mechanic to get right is the difference between actual values and default values, because it determines both your exposure and your evidence burden. Actual values are embedded-emissions figures calculated from the real, verified production data of the specific installation that made your goods. Default values are fallback figures published by the Commission, used when actual data is not available, and they are deliberately conservative, generally set so that relying on them is not advantageous compared with obtaining real data.
Read that last point carefully, because it shapes the whole workflow. Defaults are designed to be a worse deal than the truth. If your supplier is a relatively clean producer, declaring on defaults means surrendering certificates for carbon the steel never embedded, a direct cost. If your supplier is dirtier than the default assumes, the default may understate, but you cannot rely on that to your advantage, and the rules push you toward actual values precisely so the mechanism prices real carbon. The practical consequence: actual values usually save money but require verified supplier data; default values require almost no supplier engagement but tend to cost more and still must be applied correctly to the right good and route.
A default value is the price of not knowing. Sometimes that price is worth paying, but you must choose it deliberately and record why, not slide into it because the supplier never answered the email.
This is exactly where an AI tool tempts you into the failure mode that fails review. Asked to draft a declaration, a model can produce a tidy table of embedded emissions per good. But if the model silently fills missing actuals with a number that is neither a verified actual nor a properly applied published default, you now have a third category: a plausible figure with no standing under the rules. A customs authority does not have a column for that. Every emissions figure in the declaration must be clearly one thing: an actual value backed by verified production data, or a published default value correctly applied. There is no defensible middle.
Supplier-Data Verification, the Hard Center
If you choose actual values, the declaration stands or falls on supplier data you did not generate. This is the hardest part of the workflow and the part AI can genuinely accelerate, as long as it accelerates collection and structuring, never the trust decision.
The supplier sends production data: output volumes, fuel and energy consumption, process emissions, and the installation-level embedded-emissions figures derived from them, ideally accompanied by verification from a recognised body. AI is useful here in the same way it is useful with any messy inbound document. It can parse a producer's report into structured fields, line up the figures against the good and the CN code, flag internal inconsistencies, and surface the gaps where a number is missing or a unit looks wrong. It can draft the follow-up questions to the supplier when the data does not reconcile.
What AI must not do is decide that an unverified, implausible, or absent figure is good enough. The verification questions are human and unavoidable. Does the embedded-emissions figure come from the actual installation that produced these specific goods, or a corporate average smuggled in as installation data? Is there third-party verification, and from whom? Do the production volumes and energy inputs reconcile to the claimed emissions, or is the figure suspiciously round and unsupported? Where the answer is no, the correct move is not to let the model invent a bridge, it is to either obtain better data or fall back to the correct default value and record that you did so. A supplier figure that cannot be traced and verified is not an actual value, no matter how precise it looks.
The reconciliation check deserves a closer look, because it is the most powerful test you have and the one AI is genuinely good at supporting. Embedded emissions are not a free-standing number; they are produced by a calculation from production volume, energy and fuel consumption, and process chemistry. That means the figure has to be internally consistent with the inputs the supplier also reports. If a mill claims a certain embedded-emissions intensity but the energy consumption it lists could not physically produce that intensity, the figure does not reconcile, and the discrepancy is a red flag no matter how official the document looks. A model can run this consistency check across many supplier reports quickly, surfacing the lines where the arithmetic does not hold together. What it cannot do is decide what the discrepancy means or whether to accept the figure anyway. It flags; you judge; the file records the judgment.
Build the supplier relationship with this in mind. The cleanest path to defensible actual values is to make installation-level data, with recognised third-party verification, a contractual expectation of your suppliers of covered goods, delivered on a schedule that lands before your declaration deadline. A declarant who only starts chasing emissions data after the steel arrives is structurally late and will end up defaulting lines they could have substantiated. A declarant who has written the data requirement into the purchase relationship is collecting verifiable actuals as a matter of course. AI helps draft, send, and triage those data requests at scale, but the strategic move, making the data a term of doing business, is a procurement decision the practitioner has to drive.
The Too-Round Number
Return to the steel coil. The supplier's spreadsheet lists embedded emissions of exactly 2.0 tonnes CO2e per tonne of steel, flat, for every product. Real installation data is almost never that clean. The figure may be a genuine rounded actual, or it may be a default the supplier copied, or it may be an internal guess. The workflow does not let the precision lull you. You ask for the underlying production and energy data, the installation identity, and the verification. If it arrives and reconciles, it is an actual value with a trail. If it does not, you do not declare 2.0 as an actual; you use the correct published default and note that actual data was unavailable. The discipline is identical to verifying any AI output: a number with a confident look and no traceable basis is not evidence.
Building the Declarant File
The declaration that survives review is backed by a declarant file: the assembled evidence that lets the competent authority, and your own future self, reconstruct every figure. Think of it as the basis-of-preparation for the customs filing.
For each line, the file should carry the good and its CN code, the quantity imported, the installation and producer identity, whether the figure is an actual or a default, and the supporting evidence behind that choice. For an actual value, that means the supplier's production data, the embedded-emissions calculation, and the verification documentation, with each emissions figure tied back to its source. For a default value, it means the specific published default applied, the good and route it applies to, and a note of why actual data was not used. Across the whole declaration it should record who prepared it, who reviewed it, and who, as the authorised declarant or its representative, signed it.
AI assembles and cross-checks this file efficiently. It can verify that every declared good has an emissions basis, that actuals are flagged separately from defaults, that quantities reconcile to customs entries, and that no line carries an unsupported figure. But the authorised declarant is accountable for the filing. The obligation does not transfer to the supplier whose data you used, nor to the platform that structured it. When the competent authority asks how you arrived at a figure, the only acceptable answer is the file, not the assertion that a tool produced it.
Design the file so it is reconstructable per line and per period, not as one undifferentiated archive. The authority's questions are specific: they ask about a particular good, on a particular declaration, and they expect you to open that exact line and walk it back to evidence. A file organised so that each declared line carries its own basis, evidence, and the people who handled it answers that question directly. A file that is a shared drive of supplier emails and spreadsheets, with the connection between any given figure and its support living only in someone's recollection, does not. The difference is the same one that separates a reconstructable disclosure from an asserted one everywhere else in this program: structured, per-figure evidence versus a pile you have to excavate under pressure.
Keep one more discipline in view: periods and restatements. CBAM is a recurring obligation, and a supplier's installation data, the methods, the verification, can change from one period to the next. The file has to be period-specific, so that the basis for a figure declared in one period is preserved as it was, even after the underlying data is updated for the next. When a figure is corrected after filing, perhaps a verification document turns out to be invalid, the workflow recomputes the line, records the correction and its cause, and reassesses the certificate-surrender consequence, rather than quietly overwriting the old number. A declarant who can show, for any line in any period, exactly what was declared and on what basis, and how any correction was handled, has a file that survives not just the first review but every review after it.
A Worked Example: The Steel Coil, Declared Two Ways
The importer brings in 5,000 tonnes of hot-rolled steel coil from a single overseas mill. Watch the declaration built badly, then well.
Built badly. Under deadline pressure, an analyst feeds the supplier spreadsheet to a general model and asks it to produce the embedded-emissions table. The supplier's flat 2.0 figure goes in as an actual value. For two products where the supplier sent nothing, the model fills the cells with a plausible 1.8, interpolated from the others. The table looks complete and is filed. Later the competent authority asks for the basis. The 2.0 cannot be tied to any verified installation data; it was a number on a spreadsheet. The 1.8 is worse, it is neither an actual nor a published default, it is a model interpolation with no standing. The declaration unwinds. The importer faces correction, scrutiny on every other line, and the prospect of certificate exposure recalculated upward.
Built well. The same analyst uses AI to parse the supplier data into structured fields and immediately flags that the 2.0 figure lacks underlying production data and that two products are missing entirely. Those flags become supplier requests. The mill returns verified installation data for three of the five products: production volumes, energy inputs, process emissions, and third-party verification that reconcile to embedded-emissions figures of 2.13, 1.96, and 2.34 tonnes CO2e per tonne. Those three are declared as actual values, each tied to its evidence. For the two products the mill could not substantiate, the analyst applies the correct published default value and records that actual data was unavailable. The declarant file carries, per line, the CN code, quantity, installation identity, actual-or-default flag, and the supporting evidence. When the authority asks for the basis of the 2.34, the analyst opens the file: supplier production data, the calculation, the verification, the reviewer, the signer. The figure holds.
Same shipment, same deadline. One declaration is a liability; the other is a customs filing that does exactly what CBAM asks, prices the carbon actually embedded in the goods, with every figure traceable to evidence.
The Cost Axis Nobody Mentions in the AI Demo
It is worth naming the financial logic explicitly, because it is what makes the verification discipline pay rather than just protect. The AI vendor demo sells speed: a declaration assembled in minutes. But CBAM is one of the rare disclosure regimes where rigor and cost point the same way. Defaults are deliberately conservative, which for a cleaner-than-average supplier means they overstate, and overstatement is money, certificates surrendered for carbon that was never embedded. So for your cleaner suppliers, the work of obtaining and verifying actual values is not a compliance tax, it directly lowers the certificates you surrender. The verification effort that makes a figure defensible is the same effort that makes it cheaper. A team that defaults everything to save time is, for its clean suppliers, choosing to pay more.
This reframes the AI question. The right use of AI in a CBAM workflow is not "generate the declaration faster," it is "make it feasible to pursue verified actuals at scale," by drafting and triaging supplier requests, structuring inbound data, running reconciliation checks, and surfacing exactly which lines have verifiable actuals worth the human effort and which should be defaulted deliberately. Used that way, AI expands how much of your declaration you can put on accurate, cheaper actual values within the deadline, while the human keeps the trust decision and the file. That is the dual win this program looks for: the move that lowers cost and the move that strengthens defensibility are the same move, getting real, verified data and recording it.
Key Takeaways
- CBAM's definitive phase is live as of 1 January 2026, with authorised-declarant applications due 31 March 2026 and first certificate surrender in 2027. The covered goods are cement, iron and steel, aluminium, fertilisers, hydrogen, and electricity, with a 50-tonne de minimis threshold.
- The authorised declarant carries the obligation and the liability. It does not transfer to the foreign producer whose data you use, nor to the software that structures your filing.
- Embedded emissions are the quantity the mechanism turns on. Every emissions figure in the declaration must be clearly one of two things: an actual value backed by verified production data, or a published default correctly applied. A model-invented figure in between has no standing.
- Default values are deliberately conservative and generally a worse deal than the truth, so choosing them is a deliberate, recorded decision, the price of not knowing, not a place you drift into when the supplier goes quiet.
- Actual values usually save money but require verified supplier data tied to the specific installation. The trust decision on that data is human and unavoidable; AI accelerates collection and structuring, never the decision that an unverified figure is good enough.
- A supplier figure that is suspiciously round or unsupported is not an actual value. Demand the underlying production and energy data, the installation identity, and the verification, or fall back to the correct default and record why.
- The declarant file is the basis-of-preparation for the filing: per line, the good and CN code, quantity, installation, actual-or-default flag, and the supporting evidence, plus who prepared, reviewed, and signed it.
- When the competent authority asks how you arrived at a figure, the only acceptable answer is the file. "A tool produced it" is not evidence, exactly as "the AI estimated it" is never evidence anywhere in disclosure.
Skill.re