Don't audit the data point; audit the process

Howden manages Scope 3 PG&S emissions across 55 countries with DitchCarbon.
.webp)
We do not taste test every biscuit that rolls off a factory line to decide whether it is safe. Food companies run system-level controls instead, HACCP and ISO 22000, designed to prevent problems in the first place, then sample and monitor where it matters most.
Scope 3 assurance works the same way. Rather than chasing third-party verification of every data point, focus assurance on the calculation process and the controls around it, then test the most material and highest-risk items. Risk-based procedures under ISO 14064-3 and CSRD's phased assurance model already assume you will.
Why does the food safety analogy hold up?
- Food safety is process-based. HACCP identifies hazards, sets critical control points and monitors them with corrective actions. It is a preventive system, not a test-every-item regime. ISO 22000 wraps that thinking into a management system across the food chain.
- Sustainability assurance is system first too. ISO 14064-3 sets out how an independent verifier validates or verifies a GHG statement, using professional judgement, documented evidence and a risk-based plan that normally includes sampling. CSRD starts at limited assurance and moves on from there.
Food companies do not test every unit for safety, and no sustainability team can verify every Scope 3 data point. Build the system, sample where the uncertainty is highest, and save the deep dives for the items that change the total.
What does "audit the process" mean for Scope 3?
1) Documented, versioned methodology. Your calculation engine, factor lineage and category logic are reproducible and version controlled. An independent verification, ISO 14064-3 for example, says what was verified and when.
2) A risk-based assurance plan. Set materiality thresholds and name the places where the evidence is weakest, usually purchased goods hotspots and figures supplied by the organisations themselves. Sample at those points rather than everywhere. Limited assurance is designed to work this way, and assurance standards such as ISAE 3000 describe how.
3) Controls at the critical points. Borrow the HACCP idea and set critical control points at data ingestion, factor selection and transformation logic. Monitor them with alerts and audit trails rather than re-verifying every number.
4) Clear scope statements. When you obtain external assurance, check what the statement actually covers: the software or the methodology as well as the corporate inventory, the level (limited or reasonable), and the version or date it applies to. Under CSRD, limited assurance is the starting point and reasonable assurance follows later.
What does verification of a calculation process look like in practice?
It looks like a document your auditor can read. DitchCarbon provides verified emissions data for over 2 million organisations, so procurement, sustainability and finance teams can measure and act on supply chain and portfolio emissions from one source. The evidence behind the calculation sits in four places, and all of it downloads from our trust centre.
- The calculator. The DitchCarbon Portal calculator holds a Verification Opinion Declaration to ISO 14064-3 at limited assurance, plus UL Solutions' Sustainability Information Calculator Verification, renewed annually. That is verification of the software and the methodology, not of a corporate inventory, which is the distinction this article turns on.
- The emission factors. Globus Thenken independently assessed the industry emission factor methodology behind spend-based Scope 3 categories 1 and 2, purchased goods and services and capital goods, in August 2025. That is an independent assessment rather than an audit, and the report says so.
- The numbers. Every figure carries its source and change history. Entity resolution runs against DUNS, LEI and ISIN identifiers, coverage gaps are shown rather than hidden, and an independent recalculation of a 10% sample kept every deviation inside a 1% tolerance. The approach has been assessed as compliant with the GHG Protocol Scope 3 Standard and ISO 14064-1:2018.
- What happened downstream. DitchCarbon data has been used in emissions reports that were subsequently assured by ten different third-party assurance providers, including Big Four firms. Ten separate reviewers, each applying their own scrutiny to the same data.
DitchCarbon is the only specialist Scope 3 tool with third-party assurance of its calculation methodology. Judge that for yourself: Who's really verified? A reality check on carbon software assurance lists every vendor we checked, verified or not, with the verifier and the evidence in each case.
Whether a particular report passes assurance is your own auditor's determination. What a vendor can give you is evidence that stands up to their questions.
When should you go deep on an individual data point?
- High-impact categories, where a handful of organisations drive most of the footprint.
- Outliers that materially swing the total or contradict a benchmark.
- New methods and major updates: a new factor set, changed allocation rules, a wider product scope.
These are the critical points, in HACCP terms. They earn more testing because the risk and the impact are both higher.
A practical five-step playbook
- Map materiality across the Scope 3 categories and rank them by impact and uncertainty.
- Lock the methodology: versioned documentation, factor sources, allocation rules.
- Design the assurance plan for limited assurance. Say what will be sampled, why, and how the evidence is retained.
- Instrument controls at the ingestion, factor and logic points, and keep the audit trails.
- Engage an independent verifier for the software or methodology as well as the corporate inventory, and keep the statement, with its version and date, in the audit file.
Procurement tip: if a vendor says its data is audit-ready, ask for the public assurance statement, and check that it names the methodology, the verifier, the assurance level and the effective date. Audit-ready with nothing behind it is marketing. Audit-ready plus an ISO 14064-3 verification is something a third-party auditor can follow. The wider question is worth asking too: how easily could another third party audit the numbers you are about to publish?
Resources
- Codex Alimentarius, General Principles of Food Hygiene, HACCP annex
- ISO 22000, food safety management systems, overview
- ISO 14064-3:2019, verification and validation of greenhouse gas statements, overview
- CSRD, European Commission overview
- CEAOB guidelines on limited assurance for sustainability reporting (PDF)
- ISAE 3000 (revised), IAASB
- ISAE 3410 withdrawal, IAASB, effective for periods beginning on or after 15 December 2026
Last reviewed 29 July 2026.
See how your own numbers would hold up
Send us the supplier or portfolio list you have to report on and we will show you the coverage, the source behind each figure and where the gaps are, so you get numbers you can defend within 2 weeks. If you would rather start with the detail, read the calculation methodology.
If you are the one being asked for emissions data, by a customer or by an investor, claim your company profile and publish your figures with their sources attached, once, instead of filling in the same survey again.
Recent posts
Join the industry leaders and solve your Scope 3 emissions data challenge
See how DitchCarbon can transform your sustainability journey with auditable insights and verified data.

