Your ESG Data Needs the Same Controls as Financial Data

Your ESG Data Needs the Same Controls as Financial Data

ESG Data & Governance
ESG Data GovernanceESG Data Controls,ESG AssuranceESG ReportingData IntegrityInternal ControlsMaker-Checker-Approver
PS Team

PS Team

August 18, 2026

Why maker-checker-approver workflows matter for reliable, assurance-ready ESG reporting

Your finance team would never let one person enter a number, verify it, and approve it alone.

So why does ESG data often work that way?

An analyst collects an electricity consumption figure. Someone applies an emission factor. The number lands in a spreadsheet, and months later it appears in a BRSR disclosure.

Who checked the source?

Who verified the calculation?

Who approved the final number?

And if someone revises it three months later, can you say who changed it, when, and why?

For many organisations, the honest answer is still unclear.

That is a data-control problem, not simply a reporting problem.

As ESG disclosures become more structured and BRSR Core information moves through independent assessment or assurance, accurate numbers are no longer enough. Companies also need confidence in how those numbers were produced.

That is where financial-grade controls become relevant.

The control principle finance has used for years

The maker-checker-approver model is not an ESG invention. It is a practical application of a much older internal-control principle: segregation of duties.

The idea is simple. No single person should control an important process from beginning to end.

In practice, three responsibilities are separated.

  • The maker enters the data and provides the supporting evidence.
  • The checker reviews the evidence, methodology, calculations, and completeness.
  • The approver takes ownership of the final number before it moves into reporting.

The value comes from that separation.

The person entering the number is not the only person deciding whether it is correct. This creates accountability and a clear record of how the number moved through the organisation.

Why ESG data is harder to control than it looks

ESG data often has more points of failure than the final disclosure makes visible.

Consider a single electricity consumption figure. Before it reaches your BRSR, it typically passes through a chain like this:

Utility invoice → Meter reading → Unit conversion → Emission factor → Calculation → Consolidation → BRSR disclosure

An error at any point can distort the final number.

One invoice might use kWh while another uses MWh. A meter reading might be missing for a month. The wrong emission factor might be selected. A facility might report data twice. A spreadsheet formula might be overwritten. A revised figure might replace the original with no change record. Supporting evidence might exist only in someone's inbox.

Here is the difficult part:

The final number can still look completely reasonable.

Bad ESG data does not always look bad.

That is exactly why it needs controls, not only a final sanity check.

The problem gets harder as you scale

A single facility can often manage ESG data with a simple review process.

A large organisation faces a much bigger challenge.

Data arrives from:

  • Plants
  • Offices
  • EHS teams
  • Finance
  • HR
  • Procurement
  • Operations
  • Suppliers
  • Multiple business units

A single figure may need to move through several layers before it becomes part of a corporate disclosure:

Site → Business Unit → Corporate ESG Team → Final Approval

At each stage, someone needs to know:

  • Where did the number come from?
  • Who checked it?
  • What evidence supports it?
  • What changed?
  • Is it ready for reporting?

This is where spreadsheets and email-based approvals start to break down.

A single checker also becomes difficult to manage when data needs review across multiple sites, teams, and business units.

BRSR Core raises the stakes on traceability

SEBI introduced BRSR Core with defined ESG KPIs and a framework for independent assurance. The framework has since evolved, and SEBI now provides flexibility around assessment or assurance for BRSR Core.

SEBI's Industry Standards on Reporting of BRSR Core further reinforce the importance of structured and consistent reporting.

The terminology is important, but the underlying process matters more.

When an external party reviews your disclosures, the final number is only part of what they need to understand.

You also need to demonstrate how the number was produced.

That means having:

  • Defined ownership
  • Supporting evidence
  • Consistent methodology
  • Review controls
  • Approval controls
  • A change history
  • A traceable process from source to disclosure

SEBI does not prescribe a specific maker-checker-approver workflow.

But segregation of duties and structured approval are practical ways to strengthen data quality, accountability, and traceability.

Test it: Is your ESG data assurance-ready?

Run your process through these seven questions.

  1. Can you trace every reported ESG figure back to its source evidence?
  2. Does someone independent review the data before it is approved?
  3. Is the person entering the data different from the person approving it?
  4. Can you see who changed a number after it was submitted?
  5. Do you know when that change happened?
  6. Can you reproduce the calculation behind the reported number?
  7. Can you show the complete review history if an auditor or assurance provider asks?

Mostly "yes" means your control environment is moving in the right direction.

Several "no"s point to a data-control gap. That requires a different fix than simply double-checking the final output.

Why one checker is often not enough

A basic maker-checker process works well for a simple organisation.

A company with multiple facilities needs more.

Each site might submit electricity, fuel, water, and waste data. The business unit reviews the consolidated figures. The central ESG team performs another review. A final approver signs off the disclosure.

The workflow might look like this:

Data Entry → Site Review → Business Unit Review → ESG Review → Final Approval

The exact structure depends on the organisation.

What matters is that the workflow follows the organisation rather than forcing every company into the same rigid two-step approval.

What good ESG data governance looks like

A strong ESG data process should answer five questions almost instantly:

Who entered the data?

Who checked it?

Who approved it?

What evidence supports it?

What changed?

If answering any of these means digging through emails, spreadsheets, and shared folders, the process is already generating unnecessary risk.

In a controlled workflow, the audit trail is built as the data moves.

It becomes part of the reporting process instead of a document you have to reconstruct after the reporting cycle closes.

How Karbon helps

This is where the right technology earns its place.

Karbon provides a configurable maker-checker-approver workflow for ESG data, supporting up to 10 levels of review.

You define the structure to match your organisation.

For example:

Facility Team → Facility Reviewer → Business Unit Reviewer → ESG Team → Corporate Approver

Each stage has a defined responsibility.

The workflow records the actions taken during the process, including data entry, review, approval, and changes.

This moves your team from:

"Someone checked the number."

to:

"Here is who checked it, what they reviewed, when they reviewed it, and how the number moved through approval."

The difference matters when your data needs to stand up to internal review, management scrutiny, or external assessment and assurance.

From ESG reporting to ESG data governance

The goal is not to pile on approvals.

It is to build the right controls around the numbers that matter.

A controlled ESG workflow makes it easier to:

  • Assign responsibility
  • Separate data entry from approval
  • Validate source evidence
  • Standardise review
  • Track changes
  • Maintain a traceable audit trail

That is the shift from ESG reporting to ESG data governance.

And as ESG information faces greater scrutiny, having strong controls around the data becomes increasingly important.

The question worth asking your ESG team

Don't ask:

"Are our ESG numbers correct?"

Ask:

"Can we prove how our ESG numbers became correct?"

That is the stronger question.

Reliable ESG reporting is not only about producing the right number.

It is about knowing where the number came from, who reviewed it, who approved it, and what changed along the way.

Karbon helps you build those controls into your ESG workflow.

If you want to see what an assurance-ready ESG data workflow looks like in practice, explore Karbon

Book a demo

Share This Piece

We are eager to hear from you and partner for a sustainable future!

Get in touch

Image
.
Planet Sustech Logo

Global sustainability transformation company partnering for a balanced planet.

Planet Sustech Logologo

All materials ©Planet Sustech 2026 All Rights Reserved