Assurance is not the same as calculation

A company can build a technically sound Scope 3 inventory and still fail assurance, because assurance is a separate discipline from measurement. An assurance provider is not there to recalculate your emissions from scratch. They are there to test whether your process for arriving at the number is reliable enough that an outside party can put their name behind a stated level of confidence. That distinction matters more in Scope 3 than anywhere else in the inventory, because Scope 3 is built on estimates, proxies, and third-party data rather than metered fuel and utility bills.

Limited assurance vs reasonable assurance

The two assurance levels sit on a spectrum of how much work the provider does and how strongly they can conclude.

Limited assurance is the lighter-touch engagement. The provider runs analytical review, asks management questions, checks that data flows in a plausible and consistent way, and looks for anything that contradicts the reported figures. The resulting statement is phrased negatively: nothing has come to the provider's attention that suggests the disclosure is materially misstated. It is a check for red flags, not a full verification.

Reasonable assurance is closer to a financial audit. The provider gathers enough evidence to make a positive statement: in their opinion, the disclosure is fairly stated, in all material respects. That requires more substantive testing — sampling underlying records, tracing data back to source, testing controls over how the data was collected and consolidated, and forming an independent view rather than just checking for inconsistency. It costs more, takes longer, and demands far more from the company's internal documentation.

Most regulatory regimes start companies at limited assurance and step up to reasonable assurance over time. California's SB 253 is built this way, with phased assurance requirements that tighten as the program matures. India's BRSR Core disclosures follow a similar phased logic, with assurance requirements expanding to more KPIs and more companies over time rather than applying at full strength from day one. The pattern reflects a practical reality: neither companies nor assurance providers can jump straight to reasonable assurance on data that has never been externally tested before.

What an assurance provider actually tests

Regardless of the level, the work generally breaks into three areas.

Methodology. The provider checks whether the calculation approach matches a recognised standard — the GHG Protocol Corporate Value Chain (Scope 3) Standard, in most cases — and whether the boundary decisions are defensible. Did the company correctly identify which of the fifteen Scope 3 categories are relevant to its business? Are exclusions justified and disclosed, or quietly dropped? Is the same methodology applied consistently year over year, so trend data means something?

Data lineage. This is the traceability test: can the company show where a number came from, step by step, from source document to final reported figure? For a category like Purchased Goods & Services, that means tracing spend data or activity data back to the procurement or ERP system, showing how emission factors were selected and applied, and showing that consolidation across business units or subsidiaries didn't introduce double-counting or gaps. Weak lineage is the single most common reason a Scope 3 disclosure fails to progress from limited to reasonable assurance readiness.

Calculation accuracy. This is closer to what most people picture as an audit — recalculating a sample of figures, checking emission factor sources are current and correctly applied, checking unit conversions, and confirming that formulas in spreadsheets or software tools do what they're supposed to do. Errors here are usually mechanical rather than conceptual, but they compound across thousands of line items in a large Scope 3 inventory.

Why Scope 3 resists high assurance more than Scope 1 and 2

Scope 1 and Scope 2 data mostly trace back to primary, verifiable sources: metered fuel consumption, utility invoices, grid emission factors published by regulators. The data lineage is short and the underlying activity data is usually within the company's direct control.

Scope 3 breaks that model in several ways. Much of the data originates outside the reporting company entirely — supplier-reported figures, industry averages, spend-based estimates using economic input-output factors. The GHG Protocol's own data quality hierarchy, running from spend-based estimates at the weak end through average-data and hybrid methods to supplier-specific primary data at the strong end, exists precisely because most companies start at the weak end and improve over time. An assurance provider testing a spend-based estimate for Purchased Goods & Services is not verifying emissions; they are verifying that a proxy calculation was applied correctly to unverifiable underlying assumptions. That ceiling limits how strong an assurance conclusion can honestly be, no matter how rigorous the testing.

Categories like Use of Sold Products or Investments compound the problem further, since they depend on assumptions about downstream behaviour or third-party operations that the reporting company has no direct visibility into or control over. A reasonable assurance opinion on those categories is a much heavier lift than one on Scope 1 fuel combustion, and in practice many companies and their assurance providers treat certain Scope 3 categories as limited-assurance-only for the foreseeable future, even where the regulation calls for reasonable assurance elsewhere in the disclosure.

What this means for reporting teams

The practical implication is to build data lineage before assurance deadlines force the issue. Documenting where every input comes from, standardising emission factor selection, and moving priority categories up the data quality hierarchy toward supplier-specific data all make the difference between a smooth limited-assurance engagement and a drawn-out one full of caveats and scope limitations. Assurance readiness is really inventory-management discipline wearing an auditor's hat — the earlier that discipline is built in, the less painful the transition to higher assurance levels becomes as regulatory requirements tighten.