When an assurance provider tests a product carbon footprint, the questions are concrete. Where did each emission factor come from, which database, which version, retrieved when? Which of your data is primary and which is secondary, and why? Which global warming potential (GWP) values did you apply, from which IPCC report? How did you split shared emissions across products? And can you re-run last year's calculation and get last year's result?
A carbon number survives third-party scrutiny when every one of those questions resolves to a document. It gets qualified, or quietly walked back, when the answer lives in someone's memory or a spreadsheet tab named final_v3_FIXED.
Below is the checklist assurers actually work from, and what being ready looks like for each item. None of it requires particular software. All of it requires discipline.
Why the audit is evidence-shaped
If your company reports under the EU's CSRD, the climate disclosures (ESRS E1) that your product footprints feed into must be checked by an independent assurance provider. As of mid-2026, the requirement is limited assurance, and under the Omnibus revisions to CSRD the previously planned escalation to reasonable assurance has been dropped. Limited assurance is the standing bar. Still mapping whether CSRD applies to you? See our guide to what CSRD and ESRS E1 mean for physical-product brands.
Don't read "limited" as "light." A limited-assurance conclusion is worded more cautiously than a financial audit opinion, but the fieldwork is real. Assurers sample disclosed figures, trace them to source, test calculation logic, and probe whether your methodology matches what you claim. The IAASB's sustainability assurance standard, ISSA 5000, effective for reporting periods beginning on or after 15 December 2026, makes the expectation explicit: sustainability information, greenhouse gas figures included, has to be auditable and supported by evidence.
Scrutiny also seems to improve the work, not just police it. Research covered by MIT Sloan found companies using third-party auditors initially report roughly 14% higher emissions than those that don't, then go on to make deeper reductions. Verified numbers start out less flattering and end up more real.
The assurer's checklist, item by item
1. Can every emission factor be traced to its source?
The first sampling exercise in almost any product-footprint review: pick a handful of emission factors and ask where they came from. The expected answer, per factor: source database or publication, version or vintage, the specific dataset or factor name, retrieval date, and any adjustments made along the way, such as unit conversions, proxies for a missing geography, or cut-off assumptions.
ISO 14067, the product carbon footprint standard, requires secondary data, which is what most emission factors are, to be justified and referenced, and the study to be documented transparently enough to be reproducible. In practice, "we used an ecoinvent factor" is not an answer. "Cotton fibre, global average, ecoinvent 3.10, dataset X, accessed 2026-03, adapted this way" is. Databases update and factors change between versions, which is exactly why the version matters.
The version matters more than teams expect. Factor databases revise annually, and a factor that moves between versions changes your result with no change to your product. When a reviewer asks why this year's footprint differs from last year's, the only good answer separates your product changed from the factor changed, and you can only give it if versions were recorded at calculation time. Retro-fitting version numbers a year later is guesswork.
The common failure mode is a modeling spreadsheet with factor values pasted in as bare numbers, provenance long gone. If your factors live anywhere without a source column, start there.
2. Primary versus secondary data, and can you defend the split?
ISO 14067 builds on the LCA standards (ISO 14040/14044) and sets a clear expectation: use primary, site-specific data for the processes you control and for the significant contributors, and lean on secondary data only where primary collection isn't practicable, with the choice justified.
Assurers ask three things here:
- Which numbers are measured and which are modeled? A clean inventory tags every activity-data point as primary (metered electricity, actual freight manifests, supplier-specific figures) or secondary (industry averages, database defaults). Tag it in the model itself, not in a side document.
- Why is secondary data acceptable where you used it? "The supplier wouldn't share" is a legitimate justification if it's written down. Silence is not.
- How did you assess data quality? Time, geography, and technology representativeness are the usual axes. You don't need an elaborate scoring apparatus. You need a consistent, written assessment.
Tagging inputs in the model has a second payoff: you can state your primary-data share plainly, a number assurers increasingly ask for, and your data-improvement roadmap writes itself, because the highest-impact secondary inputs are next quarter's supplier-engagement list.
Supplier PCFs deserve a special note. They are the best data you can get for purchased goods, but they import someone else's methodology. Keep the supplier's document, its stated standard and system boundary, and its verification status. An assurer will ask whether you reviewed it or accepted it on faith.
3. Which GWP values, from which vintage?
Every non-CO₂ gas is converted to CO₂e using a GWP value, and those values shift with each IPCC assessment report. The major frameworks, including the GHG Protocol, ESRS E1, CDP, and SBTi, expect 100-year GWP values, with the latest IPCC assessment (currently AR6) as the reference. AR6 also publishes values with and without climate-carbon feedbacks; corporate reporting uses the "without" set (fossil methane 29.8, biogenic methane 27.9, N₂O 273).
The trap assurers keep finding is mixed vintages: a utility factor set built on one assessment report, an LCA database on another, and a reporting tool applying a third, all inside a single footprint. Worse, many published factors arrive pre-converted to CO₂e with a GWP vintage baked in invisibly. Declare one GWP set for the reporting period, know which of your factors embed a different one, and document the exceptions.
4. Allocation: why this method, and is it consistent?
Wherever a process serves more than one output, such as a production line running four SKUs, a truck carrying mixed freight, or a plant producing co-products, you had to split the emissions somehow. That split is a judgment call, and judgment calls are what reviewers probe.
ISO 14067, through the ISO 14044 rules it builds on, and the GHG Protocol Product Standard describe the same broad hierarchy: avoid allocation where you can by subdividing processes, then prefer physical relationships, then other relationships such as economic value. What the assurer wants to see is not that you picked the one "right" method, since several are often defensible, but that you documented why, applied it consistently across products and periods, and can show the sensitivity where the choice materially moves the number.
An allocation change between reporting periods without a documented reason reads, to a reviewer, like number-shopping. Even when it isn't.
5. Can you reproduce the number?
The sharpest question in the whole review: re-run last year's footprint with last year's data and last year's factors. Do you get last year's result?
If your factors have since been overwritten by a database update, your activity data was corrected in place, or your methodology changed without a change log, the answer is no. And every claim built on that historical number, whether a reduction trajectory, a product label, or a customer disclosure, is now standing on air.
Reproducibility means versioning three things per reporting period: the activity data as used, the factor set as applied, and the methodology as written. When any of them changes, keep the old lineage alongside the new. The common failure is the "final" spreadsheet that has been edited in place for months, because overwritten cells are deleted evidence. This is the one item that can't be retrofitted during audit week. It either exists or it doesn't.
6. Does the trail reach actual source documents?
Activity data is a claim about the physical world, and assurers test it by sampling down to source evidence: purchase orders, shipping manifests, utility bills and invoices, meter readings, bills of materials, supplier PCF reports, certificates.
The test isn't only whether those documents exist. It's how fast you can produce them. Pick one disclosed number and walk it backwards: result, calculation, activity data, document. If that walk takes three weeks and four inboxes, you have an evidence-retrieval problem, and during fieldwork that is an evidence problem.
Freeze the methodology in writing
Allocation between co-products, recycled-content treatment, the GWP time horizon, cut-off thresholds: ISO 14067 gives you defined options, and an auditor will accept any of them applied consistently. What fails review is inconsistency, such as one allocation basis in materials and another in freight, chosen ad hoc and documented nowhere.
Write a short methodology note per footprint. A page is enough: the standard applied, system boundary, allocation rules, GWP set and vintage, cut-off criteria, and known exclusions with their justification. Every future question about the number starts here, and most of them end here too.
The evidence-readiness checklist
Run this on yourself before the assurer does. It works with any tooling. A well-kept folder structure and disciplined spreadsheets can pass it; scattered files cannot.
- Every emission factor carries source, database version, dataset name, retrieval date, and adjustments
- Every use of secondary data has a one-line written justification
- Every primary data point maps to a source document (PO, manifest, bill, meter export) retrievable in minutes
- Supplier PCFs are stored with their methodology, boundary, and verification status
- One declared GWP vintage for the period, with embedded-CO₂e exceptions listed
- Allocation methods documented with rationale, applied consistently across SKUs and years
- A frozen per-period snapshot: activity data plus factor set plus methodology version
- A change log for every methodology or factor-set change between periods
- A dry run completed: three SKUs traced from disclosed number to source documents, timed
- A named owner for each data domain (energy, freight, materials, suppliers)
If you can check all ten, the audit becomes a demonstration instead of an excavation.
The twenty-minute version
Before anyone external looks at the footprint, walk it yourself. Pick five activity numbers at random and trace each to its document. Pick five factors and confirm database, version, and rationale are recorded. Rerun the calculation from stored inputs and confirm it reproduces the reported total.
Teams that do this find the same thing every time. The gaps are almost never in the chemistry or the math. They're in the plumbing: an untagged estimate, a factor with no version, a spreadsheet that can't reproduce March.
A note on tooling
Everything above can be done with folders and discipline. What software changes is the marginal cost of that discipline. It stops scaling somewhere between ten SKUs and a full catalog, where the document links, factor versions, and calculation history become their own data-management problem. Systems designed as evidence ledgers, where every number is bound to its source document, factor version, and calculation lineage, make the ten boxes above a byproduct of normal work instead of a pre-audit scramble. That evidence-ledger idea is the premise CarbonSKU is built around, and it's the property worth testing in any PCF software that claims to be audit-ready.
Whichever way you go, remember what's actually under review. The assurer doesn't audit your intentions, your dashboard, or your methodology deck. They audit the trail. Build the trail first.