Glossary›Assurance, audit evidence and working papers›Third-party data provider oversight
Glossary term
Cluster A · A47
Tier 1 · differentiator
Third-party data provider oversight
Definition
Third-party data provider oversight is the reporting entity’s responsibility for emissions numbers produced by an outside platform, consultant or data vendor. Outsourcing the calculation does not outsource the accountability. The entity remains responsible for the disclosed figure, and the assurance provider tests the entity’s controls over that provider, not just the output.
On this page
In practice
Almost every Australian reporter uses a third party somewhere: a carbon accounting platform, an ESG consultancy, a travel agency dashboard, an energy retailer’s reporting portal. The mistake is treating the provider’s output as an answer rather than as an input that has to be understood, tested and owned.
The practical test is whether the entity can explain the number without the provider in the room. Which factor set did the platform apply, in which edition. What did it do with a missing month. How did it map a supplier to a sector. What did it assume where activity data was absent. If the answer to any of those is that the platform does it automatically, the entity has not understood its own disclosure, and it is the directors who sign the report, not the vendor.
There is a second, sharper issue specific to consultants. If the same firm builds your emissions model and also assures your report, that is a self-review threat and, for a public interest entity, it is prohibited under APES 110 rather than manageable. Entities sometimes discover this late, after a platform relationship has become entangled with an assurance relationship through a common parent or network firm.
A written agreement helps disproportionately here. What it needs to cover: which factor sets and editions are used and when they are updated; what happens to underlying data and calculation files when the contract ends; the provider’s obligation to support an assurance engagement, including responding directly to the assurer; and whether the provider will make its own methodology documentation available.
What the assurer does with it
The assurer treats the provider as an external information source and tests two separate things. First, the output: they recalculate a sample of the provider’s figures independently, using their own factor lookup, and agree the inputs back to the entity’s own source documents. Second, and less expected, the entity’s oversight: what review did management perform on the provider’s output, who performed it, when, and what did they do about the exceptions they found. A platform figure accepted without review is a control failure even where the figure is correct. They accept a provider’s output supported by documented methodology, a stated factor set and evidence of the entity’s own review. They reject a number the entity cannot explain, a provider that will not release the underlying calculation, a factor set the entity cannot name, and any arrangement where the entity’s only record of its own emissions lives in a system it does not control. Expect a direct question about whether the provider has any relationship with the assurance firm.
Commonly confused with
Assurance. A platform calculating your emissions is not assuring them, and a vendor’s internal “verification” badge is not an assurance conclusion under ASSA 5000. And with an outsourced preparer, which is a different arrangement with the same accountability rule: management makes the judgements.
Timing and relief
None specific. The oversight obligation attaches from the first reporting period, for Scope 1 and Scope 2 figures produced by a platform, and extends to the Scope 3 categories as they come into scope from the second.
Sources
1
ASSA 5000 General Requirements for Sustainability Assurance Engagements
AUASB
2
APES 110 Code of Ethics for Professional Accountants (including Independence Standards)
APESB
Review status
Review required
Last reviewed
15 September 2026
Editorial pass, unsigned
Reviewer required
Registered company auditor
Next scheduled review
1 July 2027
Part of
Cluster A, Assurance, audit evidence and working papers
47 terms on what an assurance provider tests, what they accept as evidence, and what a preparer has to be able to produce.
Related terms
The trap when a platform and the assurer share a network
How a provider’s output is weighed as evidence
What you need when the data lives in someone else’s system
Related questions
We already have carbon accounting software. Do we still need help?
−
Possibly, and the honest way to find out takes about twenty minutes. Pick one emission source and ask the software to produce the source document, the activity data, the factor and its edition, the calculation, and the reviewer’s name. Software rarely produces the boundary decision, the basis of preparation, the narrative disclosures or the governance evidence, which are most of AASB S2 by volume.
Should we use a consultant, software, or do it in-house?
+
They solve different parts of the problem and most first-year reporters need more than one. Software produces numbers, consultants produce judgements and documents, and in-house produces control while carrying the risk. The deciding question is which option leaves you holding a complete assurance file at the end.
Do we need to integrate our systems to do this?
+
No. Nothing in AASB S2 or the Australian assurance standards requires system integration. The evidence an assurance practitioner wants already exists in your invoices, meter data, fuel card statements and general ledger, so extracting it once a year is a retrieval task rather than an IT project.
Where this sits commercially
Carbonhalo hands over the calculation files and the methodology, not just a number.
Other terms in this cluster
Third-party data provider oversight