csrdready Put me on the waitlist

Kennisbank

Who owns the control over a sustainability data point

Behind every figure in a sustainability report stands a control: a rule that determines whether a data point is correct before it moves forward. Someone has to manage that rule. Someone has to check whether the source still lines up, whether the definition still applies, whether the outcome still makes sense. The question "who owns the control" sounds technical, but in practice it is the question that most often goes unanswered.

What a control actually is

A control is not a reporting line and not a checkbox on a checklist. It is the agreement that establishes: this data point comes from that source, is calculated in that way, and is checked by that person or that system before it is considered reliable. Without that agreement, a figure is the outcome of a process that no one can reconstruct.

In practice, controls often arise by accident. Someone in finance puts a formula in a spreadsheet, someone in sustainability adds a value, and after a few reporting cycles no one remembers why the control sits where it does, or who still adjusts it when the source changes. The control exists, but the ownership of it has disappeared along the way.

Why ownership of the control does not arise on its own

For financial figures, the owner of a control is usually clear: a controller, a process owner within finance, an established responsibility. For sustainability data, this is rarely arranged in the same way. The data comes from multiple corners — energy consumption from facilities, workforce figures from HR, supply chain information from procurement — and each corner has its own habits around control, or no habits at all.

That leads to a skewed distribution: a few data points are heavily controlled because they also matter for other purposes, and a large part of the rest runs along without any fixed control. The report shows all of them with the same apparent certainty, while the underlying control varies widely. In a group with multiple entities this difference grows larger: who owns the process underneath in a group with multiple entities is a different question from who owns the control at group level, and both answers can be contradictory without anyone noticing.

What happens when no one owns the control

When no one owns the control, control is replaced by habit. The figure is carried over as it was last year, the formula is copied, the source is assumed to be correct because it was correct last year too. That works until the moment the source changes — a new system, a different supplier, a changed unit of measurement — and no one notices because no one was responsible for noticing.

The consequences are not always visible in the report itself. The report continues to look well put together. The problem lies in what happens when questions are asked: an accountant, a regulator, or an internal auditor asks about the origin of a figure, and there is no answer beyond "that's how it's set up in the system." That is the moment the absence of ownership becomes visible, usually too late to do anything about it for that reporting period. What to do at that moment is a different question — what you do when no one owns it goes into that further — but the core issue arose earlier, when the control was set up.

Assigning the control is not a formality

Assigning a control to an owner is not filling in a name in a sheet. It means that someone has the authority and the knowledge to judge whether a data point is correct, what to do if it is not, and who to inform if the source changes. For groups with multiple entities, an extra layer is added: the same control can be set up differently at entity level than at group level, and who owns the control in a group with multiple entities is then not a single answer but a distribution that can differ per data point.

The division between finance and sustainability also plays a role here. Finance often has the discipline around controls, sustainability often has the knowledge of the source. Both are needed, and neither department can carry the control alone. How that division works in practice depends on how an organization divides ownership between finance and sustainability — a choice that does not come from a template, but from the way the data actually flows through the organization.

Where this leads

The question of who owns the control cannot ultimately be separated from the question of what control a data point actually needs. Some data points require little — a fixed source, a simple calculation rule. Others require a great deal — estimates, assumptions, sensitive calculations that give a different picture with a small change. An organization that does not make that distinction spends equal or too little attention on everything, and that is rarely the right distribution.

Mapping this out — which control belongs to which data point, and who takes it on — is work that precedes every reporting cycle and every discussion about automation. Only once it is clear who owns which control and what part of that control is routine does it become visible which part of that work can be taken over by AI and which part still requires judgment from someone who knows the source and the context. The [work scan from FTE TO AI](/) calculates this per task, based on the work as it is currently done, not on how a reporting system would prefer to see it.

Marvinde assistent van de Data Readiness Scan

Vraag maar waar een datapunt vandaan komt. Dat is meestal de hele vraag.

Answers come from this site’s knowledge base. Not tailored advice, and not a scan of your company.