A published claim creates an evidence obligation
Sustainability reports combine quantitative metrics, governance statements, targets, policies, case studies and forward-looking claims. Each creates a different evidence need. An electricity figure may require invoices and meter records; a Board oversight statement may require charters, papers and minutes; a training claim may require curriculum, attendance and completion evidence.
Evidence planning should therefore follow the disclosure architecture. The organisation should know which record supports each claim, who owns it, who reviews it and how it is retained.
- Metric source records and calculations
- Policies, approvals and governance minutes
- Risk, scenario and financial-effect workpapers
- Target baselines and performance evidence
- Management review and disclosure sign-offs
Build a controlled evidence vault
Email folders and shared drives may store files, but they rarely provide consistent ownership, confidentiality, review status, retention, integrity and linkage to the underlying data or disclosure. A controlled evidence register should generate a unique identifier and capture category, period, location, owner, reviewer, source and expiry.
Private supporting files should be protected and hashed so the organisation can demonstrate integrity. Archiving should preserve evidential history rather than silently deleting the record.
- Private file storage and access control
- SHA-256 or equivalent integrity metadata
- Primary file and version management
- Reviewer workflow and history
- Retention and expiry monitoring
Test evidence, not merely its existence
A file attached to a record does not automatically make the claim supportable. Reviewers should test whether the evidence covers the correct entity, location and period; agrees to the submitted value; is complete and legible; and was created or approved by an appropriate source.
Exceptions should be returned with clear correction instructions. The owner must be notified, able to open the relevant record directly and resubmit without losing workflow history.
- Existence
- Relevance
- Completeness
- Accuracy
- Authority
- Period and boundary alignment
Use pre-assurance as a management tool
A pre-assurance review selects material disclosures and traces them through source, calculation, control, approval and published narrative. Findings should be risk-rated and assigned to owners with deadlines and closure evidence.
The purpose is broader than passing an assurance engagement. It exposes weaknesses in the organisation’s data and decision systems and creates a prioritised agenda for stronger reporting in future cycles.