Every CFO of an ASX-listed resource company knows the Key Audit Matters section of the auditor’s report. It is the section that identifies the matters of greatest significance to the audit, and for a miner or an upstream producer, the usual residents are familiar: asset impairment, rehabilitation provisions, ore reserve estimates, revenue recognition, and tax. AASB S2 has now placed climate disclosure inside the same annual report, under the same Chapter 2M of the Corporations Act, with the same directors’ sign-off and an independent assurance regime under ASSA 5000. The question is no longer whether Scope 3 sits inside the audited perimeter. It is what happens the year the audit partner decides Scope 3 is significant enough to warrant focused attention. When that happens, the testing depth changes, and the restatement exposure changes with it.
This is the piece for the CFO who has read the regulatory primer, accepted that climate data has moved inside the audited file, and now wants to understand the specific failure mode. What does the auditor actually test when Scope 3 is elevated? Which Scope 3 categories draw that attention first? Where do climate disclosure restatements come from, and what is the underlying control pattern? How do you prepare for the partner’s first walk-through, and what is the difference between a Key Audit Matter and a modified opinion when the two get confused in board conversation?
A note on terminology before going further: a Key Audit Matter is formally a feature of the financial statement auditor’s report, while the AASB S2 disclosures are assured separately under ASSA 5000. The two engagements apply the same risk-based testing logic, and in practice, the audit partner’s elevation of Scope 3 carries across both. Our piece on the limited-to-reasonable assurance roadmap traced the timeline. This piece traces what happens when the spotlight lands on Scope 3.

A Key Audit Matter (KAM) is selected, under Australian Auditing Standard ASA 701, from the matters the auditor communicated to those charged with governance. The auditor focuses on areas of higher assessed risk of material misstatement, areas involving significant judgment, and the effect of significant events or transactions. Scope 3 ticks all three boxes the moment it becomes material. It is large relative to the rest of the emissions inventory; it relies on estimates and third-party data; and it changes year to year as methodologies and supply chains evolve. That combination is exactly what draws an audit partner’s attention.
When Scope 3 is elevated, the procedures move from light-touch to substantive. Under limited assurance, the assurance team performs mainly enquiries and analytical reviews, sufficient to conclude that nothing has come to their attention. Once a matter is treated as a Key Audit Matter, or once the engagement moves toward reasonable assurance under ASSA 5010, the testing becomes detailed and evidence-led. The auditor traces disclosed figures back to primary instruments, recalculates the emissions from activity data and factors, samples supplier records, tests the emission factors and their vintage, evaluates the methodology for consistency with the prior period, and assesses whether the controls over the data path actually operated.
Five things get tested hard. Completeness: Is every emissions source within the declared reporting boundary captured, and is the boundary itself defensible? Accuracy: Is each figure calculated against the correct factor and the correct methodology version? Cut-off: are emissions recognised in the period in which the underlying activity occurred. Existence: Does the activity data tie to a real primary record, the fuel invoice, the haulage log, the shipping manifest, or the supplier statement? Estimation: where a number is an estimate, and most of Scope 3 is, the estimation method is documented, applied consistently, and governed by someone other than the person who produced it. A figure that cannot survive those five questions is the figure that produces a finding.
The practical lesson is that a Key Audit Matter is not a one-year event you survive and forget. It retests the same data path every cycle, and it tests operating effectiveness, not the existence of a policy. A control that ran once at year’s end cannot demonstrate that it ran across the period being assured. That is the difference between passing the testing and arguing with the partner about scope limitations.
The GHG Protocol Corporate Value Chain (Scope 3) Standard splits Scope 3 into fifteen categories. They are not equal. For a resource company, three of them have the size, judgment, and data fragility that make an audit partner reach for the Key Audit Matter pen.
The first is the use of sold products, category 11. For a coal, gas, or oil producer, this is the single largest line in the entire inventory, often an order of magnitude larger than Scope 1 and Scope 2 combined, because it captures the combustion of the product after it leaves the gate. For an iron ore producer, the equivalent pressure point is the processing of sold products (category 10), which captures emissions from turning the ore into steel. Both categories rest on downstream assumptions the reporting entity does not directly control: combustion factors, conversion ratios, and allocation choices. Maximum materiality multiplied by maximum estimation uncertainty is the textbook profile of a Key Audit Matter.
The second is purchased goods and services, category 1. This line is large for any capital-intensive operation, and it is usually built from spend-based estimates rather than primary supplier data. Spend-based estimation is acceptable as a starting point, but it has weak provenance, is sensitive to the chosen emission factor set, and involves allocation judgments that an auditor will probe. As supplier-specific data replaces spend proxies, the figure can move materially, which is precisely the kind of year-on-year volatility that attracts scrutiny.
The third is upstream transportation and distribution (category 4). Haulage, rail, and shipping generate emissions where primary data often exists but sits in fragmented systems: third-party logistics providers, charter records, and port data. The data is real, which raises the auditor’s expectation that it be captured accurately, but it is scattered, which raises the risk that it is incomplete. Categories where good data is theoretically available but operationally fragmented are a common source of findings on completeness.
The common thread across all three is the testing triangle the partner applies: how big is it, how much judgment does it carry, and how solid is the data lineage behind it. A category that scores high on all three is a category that gets named. Knowing which of your categories sit in that zone before the partner does is the difference between a managed conversation and a surprise.
A restatement is the correction of a previously issued figure that is later found to be materially wrong. In financial reporting, it is the outcome a CFO works hardest to avoid because it signals to the market that prior numbers cannot be relied on. A climate disclosure restatement carries the same signal and, increasingly, the same regulatory interest, because the disclosure now sits within the same annual report under the same directors’ declaration.
The control failure pattern behind a climate restatement is recognisable and recurring. The first failure is the emission factor problem: the wrong vintage is applied, or a single factor is applied inconsistently across sites, and there is no reconciliation to catch the discrepancy before the figure is published. The second is the boundary error: an entity, a joint venture, or a source is omitted or double-counted because the reporting boundary is held in someone’s working memory rather than in a controlled register. The third is the methodology change that is never disclosed or managed, so the current-period figure is not comparable to the prior period, and the break only surfaces when the auditor asks why the number moved.
The fourth is the spreadsheet failure: a broken formula, a hard-coded override, a dragged range that stops one row short, with no independent review to detect it. The fifth is the late supplier revision: a third party restates its own data after the disclosure has been signed, and there is no process to assess whether the change is material to the reported figure. Each of these is a control gap, not a sustainability problem. None of them is exotic to a finance function. All of them are the kind of failure that the controls over revenue or inventory were designed decades ago to prevent.
There is one respect in which climate restatement risk runs hotter than financial restatement risk. The data is newer, the controls over it are younger, the estimation base is wider, and the assurance history is thin. A figure with one or two reporting cycles behind it has not been stress-tested the way a revenue number has. ASIC Regulatory Guide 280 is explicit that directors need reasonable grounds for the sustainability information they sign, and that reliance on experts, whether internal or external, does not absolve directors of the need to make an independent assessment. A restatement is the visible evidence that those reasonable grounds were not there. Our piece on climate disclosure financial reporting controls sets out the controls library that closes these gaps, and our piece on audit-ready emissions data infrastructure covers the systems that enforce them.
A walk-through is the procedure in which the auditor takes a single transaction and follows it end-to-end through the process and controls, from the primary record to the disclosed figure. It is how the partner determines whether the data path is a controlled process or an annual reconstruction. For Scope 3, it is usually the first detailed contact between the audit team and the climate data, and it sets the tone for everything that follows.
The artefacts to have ready are the same artefacts a financial controls walk-through would expect, translated to the climate domain. A controls library that names each risk, the control that addresses it, the owner, the frequency, and the evidence it produces. A methodology document under version control, so a change to a factor or a calculation rule is dated, reviewed, and approved before it affects a figure. A reporting-boundary register that lists every entity and source inside the boundary, so completeness is a document rather than a recollection. Data lineage that runs from the primary instrument to the disclosed number with no untraceable adjustments in between. A segregation-of-duties map showing that the person who enters the data is not the person who approves it. And evidence that the controls actually ran across the period: monthly reconciliation files, exception reports, and reviewer sign-offs.
The questions to expect are blunt. Where does this number come from? Who can change it, and is the change logged? How do you know the boundary is complete? What happens when a supplier restates its data after you have closed? How is the estimate governed, and by whom? Companies that already report under the National Greenhouse and Energy Reporting (NGER) scheme sometimes assume that compliance experience answers these questions. It does not. NGER is an annualised compliance lodgement; the walk-through tests a monthly, evidence-producing process held to the standard of the audited financial statements. The two are different animals.
The honest read on the first walk-through is that it quickly exposes whether climate data is a process or a project. A consultant-rebuilt annual workbook fails the walk-through, not because the numbers are necessarily wrong, but because there is no operating evidence that any controls ran during the period. The walk-through is the moment that the gap becomes visible to the partner, and it becomes visible early, before there is time to remediate within the cycle. Our piece on audit-ready emissions data infrastructure covers what a process that passes the walk-through looks like in Practise.
Terminology gets muddled in board conversations, so it is worth being precise. A modified opinion, under ASA 705, is the umbrella term. It has three species: a qualified opinion, which is the ‘except for’ conclusion used when a specific matter is material but not pervasive; an adverse opinion, used when the misstatement is both material and pervasive; and a disclaimer, used when the auditor cannot obtain sufficient evidence to form an opinion at all. ‘Qualified’ is therefore one type of modified opinion, not a synonym for it. For the sustainability assurance engagement under ASSA 5000, the parallel is a modified conclusion, expressed in the negative form under limited assurance and the positive form under reasonable assurance.
A Key Audit Matter is none of these. A Key Audit Matter sits inside a clean opinion. It is the auditor saying this area mattered and here is how we addressed it, while still concluding that the disclosure is not materially misstated. The progression to watch is the one that runs from a Key Audit Matter in year one, where the opinion is clean but the scrutiny is heightened, to a modified conclusion in year two if the remediation does not happen. The Key Audit Matter is the warning. The modification is the consequence.
The cascade is the reason this matters beyond the auditor’s report. A modified conclusion on the climate disclosures does not stay contained on the page. Lenders read it, and a sustainability-linked loan margin can step up when a KPI cannot be assured to the lender’s standard, a point our piece on sustainability-linked loan pricing develops. Rating agencies fold data-quality signals into credit assessments. The board has to address it, and ASIC has signalled that climate disclosures are within its surveillance focus. A restatement that triggers a modification compounds across all of these at once. The exposure is not the paragraph in the report; it is everything the paragraph sets in motion.
Pull the five sections together, and the target state is straightforward to describe, if not trivial to build. Scope 3 can be elevated to a Key Audit Matter and survive the testing, because the data path is controlled end to end, the methodology is documented and version-controlled, the reporting boundary is a maintained register rather than a recollection, segregation of duties is enforced by the system, and operating evidence exists for the whole period rather than the final fortnight. The high-risk categories, use or processing of sold products, purchased goods and services, and upstream transport, have been identified in advance and given the strongest data foundations, because the CFO knew which lines the partner would reach for before the partner reached.
The CFO who reaches that state treats the first Key Audit Matter as a signal, not a verdict. A Key Audit Matter says the auditor is paying close attention to Scope 3. It does not say the disclosure is wrong. The window between the first elevation and a possible modification is the remediation window, and it is wider than it feels if the controls work has been done in advance. The restatement risk that worries Catherine is, underneath, a controls problem and a data-infrastructure problem. It is not a sustainability problem, and it does not get solved by more consultants or another year of workbook patching.
If a walk-through of how the Scope 3 controls map, the boundary register, and the data lineage hold up against a first Key Audit Matter elevation would be useful, we are happy to share the SCIAR Emissions pattern and the readiness diagnostic we use on real resource-sector implementations. Our framework piece for the CFO climate disclosure programme explains how this restatement-risk layer sits alongside regulation, infrastructure, capital markets, and cost within a single mental model.
Nick Ogle has over 30 years of experience in Enterprise IT, spanning engineering, sales, and marketing roles across Australia, the USA, and APJ for various IT vendors.
Nick is passionate about Entrepreneurship and Software innovation that drives positive change. Currently, he is the Sales & Marketing Manager at SCIAR Systems, a Newcastle-based SaaS startup, where he is helping to commercialise its groundbreaking Bulk Commodity Logistics & Emissions Certification solutions.