An accountant who provides assurance on sustainability data asks a simple question: where does this figure come from, and who can demonstrate that. Many organisations only discover during preparation for an assurance engagement that this question cannot be answered per data point. The figure is in the report, but the path leading to it is recorded nowhere.
Assurance does not ask for a polished report. It asks for a trail: a data point must be traceable back to a source, through recorded steps, with an identifiable owner who can explain how the figure came about. Without that trail, every check becomes a reconstruction after the fact, with the risks that come with it: people who no longer remember why a figure was adjusted, spreadsheets that have been overwritten, a source that can no longer be found.
The question where does a data point already exist seems simple, but it is exactly the question that surfaces during assurance. If the answer differs per system, or if no one is certain, that is not a matter of reporting format. It is a gap in the lineage that an assurance engagement exposes.
There is a tendency to solve this problem with software that generates reports. That changes nothing about the auditability of the underlying figures. A tool that produces tidy output on top of a process without recorded sources and ownership delivers a more convincing report about the same unreliable data. Assurance looks straight through that layer.
Auditability starts with three questions per data point: where does it come from, who is responsible for it, and which rule determines whether the value is correct. These are not questions a reporting tool answers. They are questions an organisation must work out, record and maintain itself.
A data point register with source-to-report lineage answers those three questions, per data point. It shows which part of the data already has a clear source and owner, and which part does not. That distinction is exactly what how many of your data points have a source is about: not an estimate, but a count per data point, with the gaps visible rather than averaged away.
What this does not do: it does not render an assurance judgement, it does not assess materiality, and it does not guarantee approval by an accountant. A register with lineage is preparatory work. It makes visible what is auditable and what is not yet, so that an assurance engagement does not stumble over questions that should have been asked long before. The outcome of that engagement remains with the party providing the assurance.
A data point without an owner is a data point no one can defend when a question arises about it. In practice, ownership changes: people move to different roles, spreadsheets are taken over by a successor who does not know the history. The question who reads your data point register once you are no longer there is therefore not a thought experiment. It is a test of whether the recording is independent of one person, or whether the knowledge disappears the moment that person leaves.
A register that only exists in the controller's head is not a register. Assurance asks for something that remains standing when the composition of the team changes.
Part of the difficulty in assurance preparation comes not from bad data, but from too much data: data points that are collected because they once seemed relevant, without anyone still checking whether that is still the case. The question which data points do you actually need therefore belongs to the same exercise as building lineage. Fewer data points with a watertight trail are more auditable than a long list of which half has never been used.
Spreadsheets often get the blame in this context, but the problem rarely lies in the file format itself. Why spreadsheets are not always the underlying problem is addressed at why spreadsheets are not the problem: a spreadsheet with a recorded source and a designated owner is just as auditable as a system, and a system without that recording is just as vulnerable as a loose spreadsheet.
The effect of a watertight register is felt by an organisation not only during assurance preparation, but in the day-to-day work surrounding reporting: less back-and-forth about where a figure comes from, less time spent reconstructing a path that has already been worked out once. What concretely changes once that structure is in place is described at what changes once the lineage is in place.
This tool is under construction. Those who want to have the scan carried out as soon as it becomes available can sign up for the waiting list.
Working out sources, ownership and quality rules is work that currently often happens manually, per data point, per system. Part of that work can be accelerated with AI, another part cannot, and which part that is differs per organisation and per process. FTE TO AI offers a work scan that calculates per task which part of the work can be taken over by AI, so that it becomes clear where automation gives back time and where the manual work remains.
Vraag maar waar een datapunt vandaan komt. Dat is meestal de hele vraag.
Answers come from this site’s knowledge base. Not tailored advice, and not a scan of your company.