For two decades, the Australian-listed company’s finance function has run a recognisable controls stack over the financial statements. Journal authorities, sub-ledger reconciliations, segregation of duties, IT general controls, a documented month-end close, internal audit testing, and an external audit opinion at the end of it. It is the architecture that lets a CFO sign the directors’ declaration without flinching. Climate disclosure under AASB S2 now sits within the same annual report, under the same Chapter 2M of the Corporations Act, with the same directors’ sign-off and the same independent assurance regime under AASB S2000. The financial reporting perimeter has expanded. The controls discipline that defines that perimeter has not yet expanded with it.
This is the piece for the CFO who has read the regulatory primer, accepted that climate data has moved inside the audited perimeter, and now wants the operational answer: what does climate disclosure financial reporting controls actually look like in a finance function? The argument is that you do not need a new control philosophy. You need to extend the one you already run. A controls library that names the risks, a three-line of defence model that assigns the ownership, IT general controls that protect the data path, a month-end close cycle that produces evidence as it runs, and segregation of duties that an auditor can test. Each of these has a financial reporting analogue. Each of them needs a climate equivalent, and needs it before reasonable assurance starts testing operating effectiveness rather than the existence of a policy. Our piece on the limited-to-reasonable assurance roadmap traced the timeline. This piece traces the controls.

A controls library is the document the auditor asks for first. It lists every risk the finance function has identified, the control that mitigates it, the owner of that control, how often it operates, and the evidence the control produces. For the general ledger, the library is a comfortable artefact: most ASX-listed resource companies have one, refined across many cycles. For climate data, the library is often missing, partial, or held in the head of an external consultant.
The starter template is not exotic. It mirrors the structure of the financial reporting controls library and applies it to the assertions an auditor will test under ASSA 5000. Completeness: Every emissions source within the reporting boundary is captured. Accuracy: each figure is calculated against the correct emission factor and methodology. Cut-off: emissions are recognised in the period in which the underlying activity occurred. Existence: the activity data ties to a real primary instrument, the fuel invoice, the haulage record, the shipping manifest, and the electricity meter read. Classification: emissions are coded to the correct scope and category, including the GHG Protocol Scope 3 categories carried through in AASB S2. Presentation and disclosure: the figure that lands in the annual report is the figure produced by the system, with no untraceable adjustments in between.
For each assertion, the library names the risk in plain language, the control that addresses it, whether the control is preventive or detective, manual or automated, the frequency at which it operates, the owner, and the evidence it produces. The evidence is the part that matters under assurance. A control without evidence is a policy. A control with evidence is testable. The library for climate data should produce the same monthly log, exception report, and reviewer sign-off file that the controls over revenue or inventory produce today.
Two practical notes. First, the library is not built once. It is reviewed at the same cadence as the financial controls library and follows the same change-management process. New emission sources, new Scope 3 categories, and methodology updates flow through the library before they hit a disclosure. Second, the library should be owned by finance, not by group sustainability. The controls are now financial reporting controls. The owner of the financial reporting controls library also owns this one.
The three lines of defence model is the governance framework that most Australian-listed companies already apply to financial and operational risks. Line one owns the risk and the day-to-day control. Line two designs the framework, monitors compliance, and challenges line one. Line three, internal audit, provides independent assurance to the audit committee. The model translates to climate data with very little adjustment, and the translation is worth doing explicitly because the current state in many resource companies has all three lines collapsed into one team, or worse, into one external consultant.
Line one for climate data sits with the operations that generate the data. The site that records the fuel burn, the haulage team that logs the kilometres, the procurement team that captures the supplier invoices that drive category 1 Scope 3, and the energy team that reconciles the meter reads. These owners apply the day-to-day controls: data is entered at source, validated against tolerances, and signed off by the operator who knows the activity. This is the same first-line discipline a mine site applies to volumetric production data that ultimately feeds revenue.
Line two sits jointly within finance and group sustainability. Finance owns the controls framework, the methodology change log, the reconciliation to the financial ledger where one exists, and the interface to external assurance. Group sustainability owns the technical methodology, the boundary decisions, and the engagement with operational sites. The joint-ownership pattern is the one we see working in practice. Putting climate controls only in sustainability removes the controls discipline that finance brings. Putting them only in finance removes the methodology expertise that sustainability brings. The audit partner wants to see both in the room.
Line three is the internal audit. Internal audit tests the design and operating effectiveness of the climate controls in the same way it tests the controls over revenue or inventory. It reports to the audit committee and is separate from group sustainability. The scope, the testing plan, and the findings flow through the same audit committee papers that already cover the financial controls universe. Note that ASSA 5000 prohibits direct assistance by internal auditors on the external assurance engagement. The two roles must stay distinct, and that distinction is easier to maintain when the internal audit’s own work is documented at the same rigour as the rest of its portfolio.
The board and the audit committee form the governing body that sits above all three lines. ASIC Regulatory Guide 280 is explicit that directors need reasonable grounds for the sustainability disclosures they sign, and that reliance on experts, internal or external, does not absolve directors of the need to make an independent assessment. The three lines of defence model is the machinery that produces those reasonable grounds. Without it, the directors are relying on a single team’s representation, which is the exposure ASIC has flagged.
Climate data lives in systems. Once it lives in systems, the same IT general controls (ITGCs) that the auditor tests over the general ledger apply to it. Change management, access management, security, and operations. The four control families that finance teams know from Sarbanes-Oxley (SOX)-style work and from the equivalent ASX-listed controls discipline applied to financial systems are the ones that an external assurance team will test over the climate data path.
Design effectiveness asks one question: if every control operated as designed, would the assertion be met? The assurance team reads the controls library, the system documentation, and the access matrices, and forms a view. Design effectiveness can be achieved relatively quickly if the controls library is well drafted and the systems are configured to support it. Many resource-sector finance teams will reach design effectiveness on climate ITGCs in their first reasonable assurance year.
Operating effectiveness is the harder bar. It asks whether the control actually ran in every period, for every transaction in scope, and produced the evidence the design specified. Operating effectiveness cannot be created retrospectively. A year-end project cannot demonstrate that a monthly reconciliation ran twelve times if there are no monthly reconciliation files. This is the single most important reason climate controls cannot wait until the reasonable assurance year to be implemented. The evidence needs to exist for the period that is being assured.
The practical ITGC list for climate data is short and familiar. Change management: who can change an emission factor, a methodology rule, a boundary parameter, or an allocation key, and is that change logged, reviewed, and approved before it affects a calculation. Access management: who can read, edit, or approve climate data, with role-based access, periodic recertification, and removal on role change. Security: data is held in a system that is patched, monitored, and backed up, with logging that survives the period under assurance. Operations: scheduled jobs run on a defined cadence, failures are detected and remediated, and the schedule itself is documented. None of this is new to a CFO. The point is that it now applies to a data domain that, in most resource companies, has not yet had it.
The month-end close is the single most powerful integration point for a CFO. It is the rhythm the finance function already runs to, the calendar against which internal audit already tests, and the cadence at which operating effectiveness can be demonstrated. Bringing climate data into that rhythm turns a year-end consultant project into a financial reporting process.
A workable pattern looks like this. By the defined business day of the close, primary activity data has been captured at source for every site within the reporting boundary: fuel, electricity, haulage kilometres, supplier spend in scope, refrigerant losses, and other inputs required by the methodology. By the next business day, first-line reconciliations are complete, with exceptions logged and a documented sign-off. By the day after that, the calculation engine has applied the current emission factors, allocation rules, and methodology version, and produced the period’s emissions figures with a clear audit trail to the inputs. The figures are reviewed against tolerances and against prior periods, with explanations of significant movements. A month-end package is produced that mirrors the management accounts package: figures, commentary, exceptions, and outstanding items.
The integration matters for three reasons. First, evidence is created as the close runs, not assembled later. Twelve monthly reconciliation files demonstrate twelve operating control instances. One annual reconciliation file does not. Second, methodology changes are caught and managed during the year, not in the final weeks before assurance, when the change is either rejected by the assurance team or accepted with a qualification. Third, the figures are usable for decisions during the year: capital allocation, project approval, sustainability-linked loan KPI tracking, and the board paper. Annual data has very little decision value. Monthly data starts to behave like the rest of the management information set.
Australian resource companies that already report under the National Greenhouse and Energy Reporting (NGER) scheme run an annualised compliance process tied to the 1 July to 30 June reporting year. The AASB S2 close is a different beast. It is a monthly process that feeds into an annual disclosure, with the same calendar discipline as the management accounts and the same evidentiary standard as the audited financial statements. Companies that try to bolt AASB S2 onto the existing NGER annualised workflow will find it cannot carry the load. The workflow needs to be closed.
Segregation of duties is the single control failure auditors raise most often in climate workbooks today, and it is also the easiest to remediate once the data has moved into a controlled system. The principle is unchanged from financial controls. The person who enters the data cannot also approve it. The person who approves the calculation cannot also change the methodology. The person who signs off the disclosure has independent visibility of the controls that produced it. No single individual can originate, approve, and disclose the same figure.
The pattern that works in resource sector finance functions is a four-role split, mirrored from financial reporting. Originator: the site or operational team that captures the primary activity data. Preparer: the group sustainability or finance analyst who applies the methodology and produces the calculated emissions figure. Reviewer: a finance manager who reviews the calculation, the exceptions, and the tie back to the source. Approver: the group financial controller or equivalent, who signs off the period figure into the disclosure pipeline. Methodology changes are a separate workflow that involves group sustainability, the audit committee, where necessary, and an independent review before the change is released to production.
Two failure modes deserve a name. The first is the single-consultant pattern. The same external firm captures the data, applies the methodology, prepares the calculation, drafts the disclosure language, and advises the audit committee on the result. No segregation exists. Auditors are increasingly explicit that this pattern is not acceptable under reasonable assurance. The second is the sustainability-only pattern. A single internal team owns the data, the methodology, the approval, and the disclosure, with finance receiving the result for inclusion in the annual report. Internal concentration is no safer than external concentration. The remediation in both cases is to split the four roles across at least two functions and three people, and to document the split in the controls library.
Once segregation is in place, the question becomes system-level. Can the platform that holds the climate data enforce the role split, or does it rely on convention? Auditors will test the enforcement. A system that permits the originator to approve as well, even if policy says otherwise, will be treated as a control gap. Our piece on audit-ready emissions data infrastructure covers the system-level architecture in more detail. The controls library names the role split. The system has to enforce it.
Pull the five sections together, and the picture is a finance function that treats climate disclosure as one more reporting stream, not a parallel project. The controls library names the climate risks and controls alongside revenue, inventory, and tax. The three lines of defence model assigns ownership across operations, finance, and internal audit, with the audit committee above. ITGCs over the climate data path are tested for design and operating effectiveness on the same calendar as financial systems. The month-end close produces evidence as it runs. Segregation of duties is enforced by the system, not by convention. None of this is exotic. All of it is recognisable to a 30-year CFO. The novelty is the data domain, not the discipline.
The question of cost is reasonable to raise. Building controls discipline for a new data domain is not free. The honest read is that the cost is roughly the cost a finance function would incur to add a new statutory reporting stream, with the bulk of the work concentrated in the first cycle and the run-rate cost dropping thereafter. The alternative cost of obtaining reasonable assurance without these controls is harder to predict and tends to be higher. Our piece on the cost model walks through the numbers. The argument here is the operating one: if the controls are absent when assurance moves up, the gap is visible to the audit partner before it is visible anywhere else.
Climate disclosure has been brought inside the financial reporting perimeter by AASB S2 and ASSA 5000. The controls that define that perimeter need to be brought with it. The work is unglamorous, and that is the point. It is the same controls that work the finance function has always done, applied to a new data domain that capital markets and regulators now treat with the same seriousness as the rest of the audited file. The CFO who builds these controls in cycle one runs cycle two without remediation. The CFO who defers them runs cycle two from inside an assurance finding.
If a walk-through of how the climate disclosure controls library, the three lines of defence assignments, and the month-end integration look on a real resource-sector implementation would be useful, we are happy to share the SCIAR Emissions platform pattern and how it ties into the existing finance close. Our framework piece for the CFO climate disclosure programme covers how this controls layer sits alongside regulation, infrastructure, capital markets, and cost within a single mental model.
Nick Ogle has over 30 years of experience in Enterprise IT, spanning engineering, sales, and marketing roles across Australia, the USA, and APJ for various IT vendors.
Nick is passionate about Entrepreneurship and Software innovation that drives positive change. Currently, he is the Sales & Marketing Manager at SCIAR Systems, a Newcastle-based SaaS startup, where he helps commercialise its groundbreaking Bulk Commodity Logistics & Emissions Certification solutions.