Knowledge Base

Audit trail requirements for carbon data

An audit trail is the record of who entered what, from which document, with which factor, and who approved it. The fields to capture and the roles to separate. An audit trail is a design decision made before the first upload, not a report you generate afterwards.

Download the communication guide
Download the communication guide

In short

  • An audit trail is a design decision made before the first upload, not a report you generate afterwards.
  • Seven fields per entry cover almost every question anyone will ask you.
  • Three separated roles do more for credibility than any amount of dashboard polish.

An audit trail for carbon data is the continuous record of who entered each figure, which document it came from, which emission factor was applied and at which version, who reviewed it and when anything changed. Anyone whose numbers leave the building needs one: assured reporters, tender bidders, suppliers answering customer questionnaires. It is not something you produce at year end, because a trail can only record events as they happen. If you are about to start collecting, decide the fields and the roles this week, before the first upload lands.

The distinction that matters: an export is what you hand over, and a trail is what makes the export believable. Plenty of teams have built the first without the second and only found out at the worst moment.

What actually counts as an audit trail here?

Financial audit has a settled answer to this and carbon reporting has borrowed it without always saying so. The test is whether an informed outsider, with no access to the person who did the work, can reconstruct how a reported total was assembled.

That requires three layers.

The entry layer. Every activity record, with its quantity, unit, period, site and entity.

The derivation layer. What turned that activity into an emissions figure: the factor, its value, its unit, its source library and the version of that library, plus any currency or distance conversion in between.

The control layer. Who did it, who checked it, who approved it, what changed afterwards and why.

Most tools do the first layer well. The second and third are where products differ, and where the price difference between a calculator and a reporting platform actually sits.

Which fields belong on every single entry?

Seven. If you capture these, you can answer nearly any question anyone puts to you.

FieldWhy it existsWhat goes wrong without it
Source referencePoints to the uploaded file or documentThe figure was retyped and cannot be substantiated
Quantity and unitThe raw activity as it appeared at sourceUnit confusion, usually litres against kilograms
Period and entityPlaces the entry in a reporting year and a boundaryEntries drift between years at consolidation
Factor identityName, value, unit and source databaseFactor named but the number behind it is unknown
Library versionWhich release of that database was appliedPrior years move silently when the library updates
Conversion appliedCurrency, distance or unit conversion and its basisThe entry does not match the input and nobody can say why
Actor and timestampWho entered, edited or approved, and whenNo segregation of duties, so no control to rely on

The sixth row is worth dwelling on because it is the one buyers least often test. A Hedgehog customer made exactly this point publicly: a Mid-Market reviewer rated us 4 out of 5 on G2 in July 2026 and said they wanted to see the conversion factor applied when an input in USD became an entry in EUR, and which calculator produced a distance figure in their distribution overview. A link to the source, they wrote, would be enough. That is a precise description of what this field is for.

Who needs one, and how strict does it have to be?

Strictness scales with who is going to look at it.

Internal reporting only. A consistent method and a note of your sources is enough. You are managing a number, not defending one.

Customer questionnaires and tenders. You need factor provenance and a stable boundary, because a procurement team can ask you to substantiate a figure and a certifying body certainly will. This is the level most SMEs actually sit at, and most reach it without noticing.

Independent assurance. All three layers, with segregation of duties. Anything less produces findings.

Published claims. The highest bar, and the one most often underestimated. Since 27 September 2026 the Empowering Consumers directive, Directive (EU) 2024/825, has applied through national law across the EU. It does not oblige you to substantiate every claim on request. It prohibits named practices outright, and three of them reach a carbon team. A generic environmental claim is unfair unless you can demonstrate recognised excellent environmental performance relevant to it. A claim that a product is neutral, reduced or positive on greenhouse gases based on offsetting is banned in all circumstances. And a claim about future environmental performance needs clear, objective, publicly available and verifiable commitments set out in a detailed and realistic implementation plan, which is where an inventory with a trail behind it stops being paperwork and starts being the evidence. We keep a working list in the claims checklist.

What happens when the emission factor library updates?

This is the question that separates a real trail from a cosmetic one, and it is the one to ask in a vendor demo.

Databases are revised. If your platform silently applies the new version to a closed year, last year's published figure no longer reconciles to your own system, and any reduction you reported becomes impossible to distinguish from a library change.

There are only two acceptable behaviours, and both must be visible. Either closed periods are locked to the library version they were computed with, or a recalculation is recorded as a restatement with the original preserved alongside it. Ask which one you get, and ask to see it demonstrated on a prior period rather than described.

The same discipline applies to your own factors. If you add a supplier-specific figure, it needs a date, a source and a note of what it replaced, or it becomes an unexplained number in twelve months.

Who should be allowed to change what?

Three roles, minimum, and they should be three different people wherever headcount allows.

Data owner. Enters or uploads for a defined scope, typically a site, an entity or a category. Can edit their own entries until the period is submitted.

Reviewer or auditor. Reads everything, comments, challenges, but cannot change figures. This is the role that makes an internal review meaningful.

Approver or manager. Closes a period, and is the only role that can reopen it. Reopening should always leave a record.

Shared logins destroy all of this. If two people use one account, the timestamp records the account, not the person, and the whole control layer collapses into decoration. This is a policy decision rather than a software feature, and it costs nothing except the discipline to enforce it.

What does Hedgehog record, and where are the gaps?

The platform supports entity management across locations and sites with distinct user roles for data owners, auditors and managers, which is the three-role separation described above. It builds a GHG Protocol inventory, guides you through identifying your data sources, data owners and documents, covers over 20,000 spend-based and activity-based factors, and lets you add organisation-specific or supplier-specific CO2 data of your own. Reporting outputs include the GHG Protocol, PPN 006 and the CO2-Prestatieladder, and named legislation support includes CSRD, SECR and SB253. Free account, no sales call, and Pro from EUR 1,200 per year.

Three limits stated plainly.

Applied conversions are not fully exposed to the user. The July 2026 G2 review quoted above is the source, and it is the most relevant limitation on this page. Ask about it directly if your assurance provider will sample converted entries.

Loading the data is manual and takes real effort. A Small Business reviewer wrote on G2 in August 2026 that once the data is there it works perfectly, and getting it loaded is the challenging part. That loading work is also what builds the trail, which is the honest reframe: the effort is not overhead, it is the evidence.

Product footprints are a service. The platform does organisational footprints. Product-level work, including LCA, EPD, MKI and PCF, is delivered by people and carries its own review record. That is LCA consulting rather than a platform feature.

Where should you start?

Start with the boundary document, not the software. One page naming the entities, the sites, the consolidation approach and the exclusions, dated and signed by someone senior. Almost every trail problem downstream is really a boundary problem upstream.

Then set the three roles before the first upload, because retrofitting segregation of duties onto a year of entries made under one login is not possible. You can only fix it forward.

Then upload from source and keep the file. Every retyped figure is a gap you will be asked about.

If you are still comparing tools against this list, the wider selection criteria are in choosing carbon accounting software. If you want to test the roles and the record on your own data, start with a free account.

Sources: Hedgehog platform and Hedgehog on G2, both read on 27 August 2026. The GHG Protocol Corporate Accounting and Reporting Standard for the inventory requirements. Claims rules from Directive (EU) 2024/825, read against the Official Journal text on 16 September 2026: Article 4 for the 27 September 2026 application date, Annex I points 4a and 4c and Article 6(2)(d) for the prohibited practices. Page verified 16 September 2026.

Facts on this page were last verified on 2026-09-16.

Frequently asked questions

No items found.

Start free version on Hedgehog Carbon Platform

Start your carbon footprint with a free trial on the Hedgehog Carbon Platform

This article is written by:
Joost
Joost
Co-Founder
Send emailLinkedInBook a meeting

Get in touch

Whether you are a large or small business, a start-up or a company with a long history, offering a product, process, or service, we respond swiftly and support you in taking your next step.