Every resource sector finance team in Australia is running its emissions numbers through the same tool it reaches for whenever something has not yet been properly systematised: the spreadsheet. Site teams populate workbooks, group sustainability rolls them up, an external consultant is engaged at year-end to handle the difficult Scope 3 categories, and a number of items land in the annual report. Initially, that process was good enough, because the output was a narrative paragraph and a published figure that nobody audited closely. That world has gone. Under AASB S2, climate-related financial disclosures now sit within the audited annual report, are tested by the same external auditor, against the same materiality framework, and carry the same director liability. The workbook that once produced a comfortable narrative is now producing an audited financial disclosure. It was never built for that job.
This is the piece for the CFO who already knows the regulatory primer and wants the operational consequence stated plainly. The argument is short. Spreadsheet-based emissions reporting is the next financial reporting control failure waiting to happen, and the proportionate response is audit-ready data infrastructure, not more consultants, more headcount, or another year of patching the workbook. What follows names the specific control failures an auditor will flag, explains why the year-end rebuild model collapses as the assurance bar rises, describes what audit-ready emissions data infrastructure actually looks like, and maps the controls and traceability you already run for financial reporting onto the climate file. None of this is unfamiliar territory for a finance function. It is the discipline you already apply to the general ledger, applied to a dataset that has not yet earned it.

Why does the spreadsheet fail an audit that the general ledger passes every year? Not because spreadsheets are inherently unsound, but because the control environment around them is absent. When an auditor brings Scope 3 into scope for testing, they apply the same lens they apply to any financial dataset: who entered this, who reviewed it, who could change it, and can you prove the number traces back to a source? Climate workbooks built in the narrative era answer none of those questions well. Five failures recur across the sector, and an Excel emissions reporting risk audit will surface most of them on the first pass.
The dominant operating model in the sector is the year-end rebuild. For most of the year, the emissions data is dormant. Then, in the weeks before the annual report, a consultant is engaged to assemble the numbers, reconcile what is reconcilable, apply the methodology, and produce a defensible figure in time for sign-off. It is expensive and compressed, and it has worked because limited assurance requires the provider only to conclude that nothing has come to their attention suggesting the information is materially misstated. That is a low bar. A capable consultant can clear it once a year.
Reasonable assurance is a different standard. Under ASSA 5000, the new Australian standard on sustainability assurance, and the phased timeline in its companion ASSA 5010, assurance over climate disclosures steps up from limited to reasonable across the coming reporting cycles. Reasonable assurance requires the provider to obtain sufficient appropriate evidence to express a positive opinion, the same level of assurance that an auditor gives over the financial statements. That changes what gets tested. The provider is no longer scanning for obvious problems. They are testing the design and operating effectiveness of the controls that produced the number, across the whole period, not at a single point in time.
A year-end rebuild has no operating effectiveness to test, because the controls did not operate during the year. They were assembled at the end of it. You cannot demonstrate that a control ran monthly when the process ran once. The consultant model is, by construction, a point-in-time reconstruction, and reasonable assurance is, by construction, a test of a process that operated continuously. The two are incompatible. This is the structural reason the current model has a finite lifespan, and why adding consultant hours does not fix it. More hours rebuild the number faster. They do not create a control that operates when it is supposed to.
The cost trajectory makes the same point from the other direction. Each cycle demands more Scope 3 categories, greater granularity, more assurance hours, and greater methodological rigour than the one before. Most companies have met that by adding consultant spend and headcount, which absorbs one or two cycles and then runs out of road. Our cost benchmark piece models that curve in detail. The short version: the function ends up consuming more resources each year to produce a number that is still not built to pass the assurance standard arriving behind it.
So what is the alternative, and is it proportionate? The phrase “emissions data infrastructure audit-ready” sounds like an invitation to a multi-year systems programme, and CFOs are right to be sceptical of such programmes. The proportionate version is narrower and more familiar than it sounds. It is the same architecture you already trust for financial data, applied to emissions data. It has three layers.
The first layer is primary data capture at the source. The inputs for the Scope 1, 2 and 3 calculations already exist in systems the finance function knows: the fuel and energy ledgers, the haulage and rail records, the port and shipping data, and the procurement and offtake records. NGER reporting already draws on most of the Scope 1 and 2 inputs. Audit-ready infrastructure pulls these into a structured pipeline rather than re-keying them into a workbook. Removing the manual re-entry removes the largest single source of the control failures named above.
The second layer is an auditable calculation engine. The methodology, the emission factors, the allocation rules, and the boundary decisions sit in a documented, version-controlled system rather than in formulas only one person understands or in a consultant’s files. The calculation follows the GHG Protocol Corporate Standard, the sector already uses for NGER, but it runs inside the company’s own controlled environment, where every factor and rule is recorded, and every change is logged. The methodology becomes a company asset, evidenced by the company’s own records.
The third layer is independent certification. This is the part that separates credible emissions data from merely tidy emissions data. Data without independent verification is treated by capital markets, regulators, and end-buyers as a starting point for due diligence, not as a credible endpoint. Pairing real-time data infrastructure with recognised third-party certification is what earns the disclosure its credibility premium. It is the difference between telling the audit partner your number is right and showing them that an independent body has verified it.
This is the architecture SCIAR Systems and EarthCheck were built to deliver together: a real-time emissions data platform connected to an internationally recognised certification regime. We are direct about why the two belong in the same sentence. Data infrastructure without certification is unverifiable. Certification without a data infrastructure has nothing current to certify. The combination is what moves the climate file from a year-end reconstruction to a controlled, certified, continuously available dataset that an auditor can test the way they test the ledger. The table below sets the two models side by side.
| Dimension | Narrative-era spreadsheet model | Audit-ready data infrastructure |
|---|---|---|
| Data capture | Manual re-entry into workbooks at year-end | Structured pipeline from source systems, captured continuously |
| Calculation | Formulas and overrides only one person understands | Documented, version-controlled engine with logged changes |
| Methodology | Held in a consultant's working papers | Held in the company's own controls library |
| Controls testing | No operating effectiveness to test | Controls that operate across the full reporting period |
| Traceability | Number cannot be tied back to the primary instrument | Footnote traces to fuel invoice, rail record, meter, manifest |
| Assurance fit | Clears limited assurance, fails reasonable assurance | Built for reasonable assurance from the first cycle |
| Cost trajectory | Rises each cycle with no ceiling | Fixed infrastructure that scales with the assurance bar |
If the language of the previous section felt familiar, that is the point. The controls an auditor expects for climate data are the same as those finance teams have applied to financial systems for two decades. The most useful mental model is the IT general control, or ITGC.
Under Sarbanes-Oxley (SOX) in the United States, and the equivalent controls discipline that Australian-listed companies apply to their financial systems, ITGCs are the general controls over the IT environment that financial data passes through: access controls over who can read and change data, change-management controls over how the system itself is modified, and operations controls over how data moves and is backed up. They are the foundation that makes every control inside the application trustworthy. If anyone can change the system, nothing inside it can be relied on.
Climate data now needs the same general controls. Who can edit an emission factor? Who can change a methodology rule? Is that change logged, reviewed, and approved? Can a site user alter a primary figure after it has been locked for the period? In a spreadsheet, the honest answer to most of these is that there is no control at all. In an audit-ready infrastructure, the answer is the same answer you already give for the general ledger. The controls library you apply to climate disclosure, the subject of our piece on climate disclosure financial reporting controls, is not a new invention. It is the existing ITGC discipline extended to a new dataset.
This is why the conversation about controls is more reassuring than it first appears. You do not need to learn a new control philosophy for climate. The philosophy is already in place for financial reporting. What is missing is its application to a dataset that grew up outside the finance function. Closing that gap is an extension of known Practise, not a leap into the unknown.
The single test that pulls all of this together is traceability. Can you start at the disclosed Scope 3 figure in the annual report and trace it, step by step, back to the primary instrument that originated it? The fuel invoice. The rail consignment note. The bill of lading. The electricity meter read. If the answer is yes, the disclosure is audit-ready. If the answer involves a consultant’s spreadsheet, an emailed workbook, or a step no one can fully reconstruct, it is not.
Traceability is the property an auditor is really testing when they ask their questions. Completeness, accuracy, and the reasonable basis that the directors’ declaration requires all reduce to whether the number traces cleanly to the source. ASIC’s Regulatory Guide 280 is explicit that directors are expected to ensure that appropriate systems, internal controls, and oversight underpin the disclosures they sign. A traceable chain is the evidence that those systems exist. An untraceable number is the evidence that they do not.
In the narrative era, traceability did not matter because no one followed the chain. The disclosed number was the end of the conversation. In the evidence era, the chain is the conversation. The disclosed number is only as good as the path back to the instrument that created it, and that path either lives in a controlled system or it does not. This single thread runs through every other facet of the CFO’s climate problem, from assurance to capital markets to cost, which is why we treat traceable, certified data infrastructure as the one underlying solution rather than four separate ones. Our framework piece draws that whole map together.
It is worth being candid about the stakes, because the instinct of a 30-year CFO is to treat unsourced reassurance as a cost. A qualified or modified assurance opinion on a climate disclosure is no longer a remote scenario. It is the predictable outcome of testing a spreadsheet process against a reasonable assurance standard. The restatement risk, the directors and officers insurance renewal questions, the institutional investor who asks how you know and does not get an answer in the room: these are the consequences of carrying the narrative-era process one cycle too long.
But the same fact pattern reads the other way for the company that moves first. The CFO who runs the first mandatory cycle on audit-ready infrastructure does not spend the second cycle remediating a finding. She signs the assurance engagement letter, knowing the evidence base will hold. She answers the investor’s question in the room. She walks into the sustainability-linked loan negotiation with data her relationship banks can assure, and prices her debt accordingly. The infrastructure that protects against downside risk is the same infrastructure that earns upside. That is the through-line of the SCIAR thesis. The work you do to avoid the control failure is the work that creates the advantage.
The financial cost of building it in the first cycle, against building it in the second after an assurance finding, is broadly similar. The reputational and capital-markets cost is not. Spreadsheet emissions reporting is the next audit risk on your register. Audit-ready data infrastructure is the proportionate answer. The choice is not whether to close the gap; the reporting calendar has already made that decision. The choice is whether to close it before the auditor does it for you.
If a walkthrough of what audit-ready emissions data infrastructure looks like in practice would be useful, we are happy to show you the SCIAR Emissions platform and how EarthCheck certification connects to it. There is no urgency in the invitation. The urgency, such as it is, sits in the reporting calendar, not in this conversation.
In the evidence era, the number is only as good as the path back to the instrument that produced it.
Nick Ogle has over 30 years of experience in Enterprise IT, spanning engineering, sales, and marketing roles across Australia, the USA, and APJ for various IT vendors.
Nick is passionate about Entrepreneurship and Software innovation that drives positive change. Currently, he is the Sales & Marketing Manager at SCIAR Systems, a Newcastle-based SaaS startup, where he is helping to commercialise its groundbreaking Bulk Commodity Logistics & Emissions Certification solutions.