Field notes

How to Make a PCF Auditable: Traceable Emission Factors, Step by Step

A product carbon footprint is auditable when every number traces to a source. The step-by-step workflow: factors, versions, lineage, and what assurers check.

Guide4 min readUpdated September 2, 2026

A product carbon footprint is auditable when someone who didn't build it can reconstruct it. That's the whole test. Not how sophisticated the model is, not how many decimal places the result carries, whether a reviewer can walk from the final number back to every input, factor, and assumption without asking you to explain anything from memory.

Most PCFs fail that test not because the math is wrong but because the trail is missing. The number was right when it was calculated; twelve months later nobody can show why. Here is the workflow that prevents that, step by step.

Step 1: Make every activity number point at a document

Every quantity in the model, kilograms of fabric, tonne-kilometres of freight, kilowatt-hours of electricity, should reference the document it came from: a purchase order, a shipping manifest, a utility bill, a supplier declaration. Not a spreadsheet cell someone typed, the actual source.

The practical standard: if an auditor picks any activity number at random, you can produce the document behind it in under a minute. If the answer is "that came from an estimate," that's allowed, but the estimate's basis and author need to be written down too. An undocumented estimate and a documented one carry the same value and completely different audit outcomes.

Step 2: Record the factor, the database, and the version

This is the step ISO 14067 is most explicit about: an emission factor must be traceable to its source database and version. "Cotton, 8.3 kg CO₂e/kg" is not a traceable factor. "Cotton fibre, global average, ecoinvent 3.10, dataset X, accessed 2026-03" is.

The version matters more than teams expect. Factor databases revise annually, and a factor that moves between versions changes your result without any change in your product. When a reviewer asks "why does this year's PCF differ from last year's?", the only good answer separates your product changed from the factor changed, and you can only give it if versions were recorded at calculation time. Retro-fitting version numbers a year later is guesswork.

For every factor, capture four things: the database and version, the specific dataset name, the date accessed, and a one-line rationale for why that factor fits that activity (geography, technology, time period). The rationale is what turns a defensible choice into a defended one.

Step 3: Separate primary and secondary data: visibly

ISO 14067 encourages primary (supplier-specific) data where feasible and permits secondary (database) data to fill gaps, provided quality requirements are met. Auditors don't penalize secondary data; they penalize secondary data dressed as primary, and primary data with no evidence behind it.

Tag every input as primary or secondary in the model itself, not in a side document. Two useful disciplines follow automatically: you can state your primary-data share accurately (a number assurers increasingly ask for, and one ESRS E1 asks you to describe), and your data-improvement roadmap writes itself, the highest-impact secondary inputs are next quarter's supplier-engagement list.

Step 4: Make the calculation replayable

An auditable PCF is not a result; it's a pipeline you can rerun. Activity data → emission factor → methodology choice (allocation, cut-off criteria, GWP set) → intermediate result → total. Each step should be recorded so the calculation can be replayed and produce the same number.

The common failure here is the "final" spreadsheet that has been edited in place for months. Overwritten cells are deleted evidence. Whatever tooling you use, the requirement is the same: versions of the calculation are preserved, changes are attributable, and last year's number can still be regenerated from last year's inputs. If a number can't be reproduced, in assurance terms it doesn't exist.

Step 5: Freeze methodology choices in writing

Allocation between co-products, recycled-content treatment, the GWP time horizon, cut-off thresholds, ISO 14067 gives you defined options, and an auditor will accept any of them applied consistently. What fails review is inconsistency: one allocation basis in materials, another in freight, chosen ad hoc and documented nowhere.

Write a short methodology note per PCF (a page is enough): the standard applied, system boundary, allocation rules, GWP set and vintage, cut-off criteria, and known exclusions with their justification. Every future question about the number starts here, and most end here too.

Step 6: Close the loop with a pre-assurance check

Before anyone external looks at the PCF, run the auditor's walk yourself: pick five activity numbers at random and trace each to its document; pick five factors and check database, version, and rationale are recorded; rerun the calculation from stored inputs and confirm it reproduces the reported total. Twenty minutes, and it finds the broken links while they're still cheap to fix.

Teams that do this discover the same thing: the gaps are almost never in the chemistry or the math. They're in the plumbing, an untagged estimate, a factor with no version, a spreadsheet that can't reproduce March.

Where software fits

Everything above can be done manually, and for a handful of hero products it often is. It stops scaling somewhere between ten SKUs and a full catalog, the document links, factor versions, and calculation history become their own data-management problem. That's the problem an evidence-ledger approach exists to solve: platforms like CarbonSKU bind every number to hashed, versioned source documents and keep the calculation lineage replayable by default, so the audit trail is a property of the system rather than a discipline someone has to maintain by hand.

Whether you get there with tooling or process, the destination is the same: a PCF where every number knows where it came from. That's what "auditable" means, and it's decided long before the auditor arrives.