
In brief: Reliable ESG data means another competent person can trace a published figure back to its source, repeat the method and explain changes. Start with definitions, ownership, evidence, calculation controls, review and a correction process.
Sustainability data often crosses procurement, facilities, human resources, finance and suppliers. The risk is not limited to arithmetic errors. Different teams may use inconsistent boundaries, periods or definitions. A proportionate control framework makes these differences visible and allows management to judge whether the data is suitable for disclosure or decisions.
Use a data dictionary as the common language
For each metric define the purpose, boundary, unit, period, formula, exclusions, source, owner and reviewer. Include examples for ambiguous terms. Version the dictionary and record effective dates so historical figures are not silently reinterpreted.
Protect source evidence and data lineage
Link reported values to invoices, system extracts, meter files, supplier returns or approved estimates. Record transformations and aggregation steps. Evidence should be retained in a controlled location with access appropriate to sensitivity and responsibility.
Design checks around the actual error risks
Use input validation, reconciliations, variance analysis, duplicate checks, unit checks and reasonableness thresholds. Manual spreadsheets can be improved with locked formulas, protected reference tables and independent review before a larger system investment is justified.
Correct errors transparently
Define who can change data, how corrections are approved and when prior periods require restatement. The change log should show the old value, new value, reason, impact and reviewer. This protects comparability and prevents quiet overwriting.
A practical implementation sequence
Pilot the control framework on a small set of material metrics. Walk each number from source to disclosure, identify where judgement or manual work occurs, then assign preventive and detective controls. Expand only after the process is usable.
- Create and approve a versioned data dictionary.
- Map every metric to its source and transformation steps.
- Assign preparer and independent reviewer roles.
- Implement unit, variance, duplicate and reconciliation checks.
- Maintain a correction and methodology change log.
For every step, retain the owner, source, reporting period, method, version, reviewer and known limitations. Estimates can be useful during transition, but they should never be presented as measured data.
Decision risks to control
- Relying on one spreadsheet owner’s undocumented knowledge.
- Changing formulas or boundaries without version records.
- Treating external assurance as a substitute for internal controls.
A strong evidence pack includes the data dictionary, source files, calculation workbook, factor register, review sign-off, issue log and correction history. Control performance should be tested, not assumed from the existence of a procedure.
Frequently asked questions
Does reliable data require expensive software?
No. Clear definitions, ownership, protected formulas, evidence and review can materially improve a controlled spreadsheet process.
Who should review ESG data?
Use a reviewer with sufficient knowledge and independence from preparation. Finance, risk or internal audit may support higher-risk metrics.
Should estimates be excluded?
Not necessarily. Estimates should use an approved method, be labelled, reviewed and replaced when better data becomes available.
What happens when an error is found?
Assess materiality, correct through the approved process, retain the change history and update public information where necessary.
Authoritative sources
- IFRS S1 General Requirements for Disclosure of Sustainability-related Financial Information
- HKEX Implementation Guidance for Enhanced Climate-related Disclosures
This article is for general information and education only. It is not legal, investment, financial, assurance, certification, compliance or other professional advice.