Assurance-Readiness Governance at Scale
A sustainability report at enterprise scale is not one document with one author. It is hundreds of numbers and claims produced by dozens of people across business units, geographies, and functions, each working in their own spreadsheet, each making small judgment calls about boundaries and factors and estimates. The danger is not that any single number is wrong. The danger is drift: the climate team sources a factor one way, a regional unit labels an estimate another way, a third group quietly excludes a category, and by the time the report is assembled it rests on a dozen inconsistent bases of preparation that no longer reconcile. An assurer reading it does not find one error; they find that the report has no single, governed footing. This lesson is about holding a consistent, defensible basis of preparation across the whole report, governed at enterprise scale, so that every disclosed number stays reconstructable.
The Scale Problem: Consistency Is the Hard Part
At small scale, assurance readiness is a discipline one team can hold in its head. At enterprise scale it becomes a governance problem, because the same disclosure is produced by many hands who will, left ungoverned, each do things slightly differently. The failure mode is not dramatic. It is a hundred small, reasonable-looking inconsistencies that together make the report indefensible. One unit uses a 2023 emission factor database, another the 2024 version, and the consolidated number mixes them with no note. One team labels a supplier average as secondary data, another presents the same kind of estimate as if it were measured. One geography documents its boundary exclusions, another assumes them silently. Each choice might survive on its own; the inconsistency between them is the assurance finding.
This is why governance at scale is the real subject of an enterprise reporting program. The strategist's job is not to personally produce every number; it is to build the standards, templates, and controls that make every contributor produce numbers the same way, so that consistency is a property of the system rather than a heroic act of reconciliation at the end. AI raises the stakes of this in both directions. Used without enterprise governance, AI lets each team generate inconsistent output faster, multiplying the drift. Used inside enterprise governance, AI can enforce consistency, applying the same factor sources, the same labeling rules, and the same templates across every contributor. The difference is entirely in whether the governance exists.
A report does not fail because one number is wrong. It fails because two numbers were built on different rules, and an assurer cannot trust a footing that shifts from page to page.
The Enterprise Basis of Preparation: One Footing for the Whole Report
The single most important artifact in enterprise assurance readiness is one basis of preparation that governs the entire report. Recall what a basis of preparation is: the document that states exactly how the numbers were made, including the reporting boundary, consolidation approach, standards applied, emission factor sources and versions, estimation methods, the treatment of primary versus secondary data, the restatement policy, and the approval rules. At enterprise scale, the strategic insight is that there must be one of these, applied everywhere, not one per team. The enterprise basis of preparation is the constitution of the report. It fixes, for every contributor, which factor database and version to use, how to label an estimate, how to document a boundary exclusion, and who signs off.
A single enterprise basis of preparation does three things that scattered local ones cannot. It makes the report internally consistent, so the same kind of number is built the same way everywhere and the consolidated figures reconcile. It makes the report reconstructable, because an assurer can read one document and understand the rules behind any number on any page. And it makes AI safe to deploy at scale, because the model can be grounded on one set of rules and one approved factor library rather than improvising per team. The basis of preparation is what turns a federated reporting effort into a single governed disclosure.
Building the Enterprise Basis of Preparation Without Crushing Local Knowledge
A common objection to one enterprise basis of preparation is that local units know their own data best, so central rules will be wrong for their context. The objection misunderstands what the basis of preparation fixes. It does not dictate what a unit's emissions are; it dictates how any unit's emissions must be built and documented. A unit retains full authority over its activity data, its operational realities, and its boundary facts. What it gives up is the freedom to invent its own factor source, its own labeling convention, or its own undocumented exclusion. Local knowledge flows into the inputs; enterprise consistency governs the method. Done well, the basis of preparation is not a straitjacket but a shared language that lets eleven units produce numbers that mean the same thing and can be added together honestly. The strategist builds it collaboratively, drawing the rules from the units that will follow them, which is also how compliance is earned rather than imposed.
Standards and Templates: Making Consistency the Default
A basis of preparation states the rules, but rules stated in a document are not the same as rules followed in practice. The mechanism that makes consistency the default is standardized templates: the structured forms every contributor uses to enter a number, built so that doing it the consistent way is the easy way. A well-designed datapoint template forces the contributor to record the source of the activity data, select the emission factor from the approved library rather than typing one in, mark the data primary or secondary, name the method, and identify the reviewer. The template is the basis of preparation made operational. It does not rely on every contributor having read and remembered the rules; it builds the rules into the act of entering data.
This is also where AI consistency lives or dies at scale. If contributors can ask an open model to "calculate our emissions" and paste the answer into a free-text field, drift is guaranteed. If instead the AI is wired into the template, grounded on the approved factor library and required to return its source for every value, then the same AI assistance produces consistent, traceable output across every contributor. The template channels both human and AI work into the same disciplined shape, which is exactly what makes the consolidated report defensible.
Sign-Offs and the Control Chain
Consistency in how numbers are built must be matched by clarity in who stands behind them. At enterprise scale, sign-off cannot be a single signature at the end; it has to be a chain that mirrors the structure of the organization. Each contributor signs that their datapoints follow the basis of preparation and trace to evidence. Each section owner signs that their section is complete and consistent. The reporting lead signs that the consolidated report is internally coherent. And the accountable executives, typically the chief sustainability officer and the controller, sign the statement that goes to the board and the assurer. The cardinal rule of the program lives in this chain: disclosure accountability stays human, "the model recommended it" is never a defense, and the sign-off chain proves who stood behind every number at every level.
The sign-off chain is also the mechanism that prevents AI from quietly becoming the unaccountable author of the report at scale. Because each level signs that the numbers trace to evidence, an AI-generated figure with no source cannot pass the first signature, let alone reach the board. The chain forces every number, however it was produced, to acquire a human owner who has checked it. This is what lets a strategist tell an assurer that the report, produced with heavy AI assistance across hundreds of contributors, nonetheless has a named human accountable for every figure on every page.
The chain works only if each signature means something specific, so a strategist defines what each level is attesting rather than letting sign-off degrade into a rubber stamp. The contributor is not attesting that the number is beautiful; they are attesting that it follows the basis of preparation and traces to evidence they can produce. The section owner is attesting that the datapoints in their section are internally consistent with each other and with the enterprise rules, which is a different and higher check than the contributor's. The reporting lead is attesting that the sections reconcile into a coherent whole, that a Scope 3 figure in one place agrees with the same figure referenced elsewhere. The executives are attesting to the report as a regulated disclosure they stand behind personally. Each signature catches a different class of error, and the chain is strong because the levels do not duplicate each other; they layer.
The Controls That Keep Every Number Reconstructable
The final layer is the set of standing controls that keep the whole thing reconstructable as it operates. The test of reconstructability is simple and brutal: can someone rebuild any disclosed number from raw evidence without the person who made it in the room? At enterprise scale, three controls keep that test passable. The first is grounding: AI is restricted to the approved factor library and the company's own source data, never the open web, so it answers from the evidence base rather than its imagination. The second is provenance capture at entry: every datapoint records its source, factor, method, and primary-or-secondary label at the moment it is created, never reconstructed later. The third is versioning and restatement control: every change is tracked so that a prior-period figure can be rebuilt and a restatement becomes a governed process rather than a crisis.
These controls are what make the difference between a report that is fast and a report that is fast and defensible. They are also what let AI scale safely, because each control is a guardrail that catches the specific failure mode AI introduces. Grounding catches the hallucinated factor. Provenance capture catches the estimate dressed as measured data. Versioning catches the silent change that would otherwise make a prior number impossible to reconstruct. Together, applied uniformly across every contributor through the enterprise basis of preparation, they make assurance readiness a standing property of the reporting machine rather than a scramble before each engagement.
Monitoring for Drift Before the Assurer Does
The final discipline that separates a governed enterprise program from a hopeful one is monitoring. A strategist does not wait until consolidation to discover whether the controls held; they monitor compliance continuously across contributors as the report is built. The signals are straightforward and they are the same dimensions the controls govern: template compliance, meaning whether contributors are entering data through the structured forms rather than around them; factor-library usage, meaning whether the factors actually used trace to the approved library and version; label completeness, meaning whether every datapoint carries its primary-or-secondary tag; and version consistency, meaning whether any unit has slipped onto a different database version. Each of these can be checked centrally while the cycle runs, and each divergence caught early is a finding prevented. Monitoring turns the standing controls from a static design into a live system, so that drift is detected as it emerges in one unit rather than discovered across all of them at the worst possible moment.
This is the deepest reason governed AI produces a more consistent report at scale rather than a less consistent one. The same instrumentation that grounds the AI and captures provenance also generates the monitoring signal, because every datapoint entered through the template leaves a structured trace of which factor, which source, which label, and which version it used. The act of building the report defensibly is also the act of making it observable. A strategist who has wired the program this way can answer the board's hardest question, how do you know AI has not quietly degraded the report across hundreds of contributors, with evidence rather than faith: here is the compliance picture across every unit, current as of today, showing the controls operating everywhere.
Worked Example: Governing a Multi-Unit Report
Consider a group with eleven business units across six countries, each contributing to the consolidated sustainability statement. Watch the ungoverned version first. Each unit is told to "report your emissions, use AI to speed it up." Eleven teams comply enthusiastically. Unit A grounds its AI on a current factor library; Unit B lets its model pull factors from the open web, including two that are plausible but unsourced. Unit C labels its supplier estimates clearly; Unit D presents the same estimates as measured data. Three units document boundary exclusions; the rest assume them. The consolidated report is assembled, and it looks complete. When the assurer walks three numbers from three different units, they find three different bases of preparation, an unsourced factor, and an undisclosed estimate. The finding is not about one number. It is that the report has no single footing, and the remediation touches all eleven units at once, weeks before filing.
Now the governed version. Before any unit starts, the strategist publishes one enterprise basis of preparation and one set of datapoint templates, with the AI wired to the single approved factor library and required to return a source for every value. Every unit enters data through the same template, so every datapoint arrives with its source, its factor from the approved library, its primary-or-secondary label, its method, and its reviewer. The sign-off chain runs from contributor to section owner to reporting lead to the accountable executives. When the same assurer walks numbers from three different units, they find the same structure every time: same factor sources, same labeling, same documentation, the consolidated figures reconciling because they were built on one footing. The AI did not produce a less consistent report at scale; governed correctly, it produced a more consistent one, because the same rules and the same library reached every contributor automatically. The speed was captured across all eleven units. The drift never happened, because the governance made the consistent way the only way.
Key Takeaways
- At enterprise scale the danger is not one wrong number but drift: a hundred small, reasonable-looking inconsistencies across many contributors that together make the report rest on no single, governed footing.
- Governance, not personal production, is the strategist's job at scale: build the standards, templates, and controls that make every contributor produce numbers the same way, so consistency is a system property rather than a last-minute reconciliation.
- There must be one enterprise basis of preparation governing the whole report, not one per team; it is the constitution that fixes factor sources and versions, labeling rules, boundary documentation, and sign-off for every contributor.
- Standardized datapoint templates make consistency the default by building the basis of preparation into the act of entering data: source recorded, factor chosen from the approved library, data labeled primary or secondary, method named, reviewer identified.
- Sign-off is a chain, not a single signature: contributor, section owner, reporting lead, and accountable executives each sign, so every number acquires a human owner and "the model recommended it" is never a defense.
- Three standing controls keep every number reconstructable: grounding AI on the approved library and own data, capturing provenance at entry, and versioning every change so a restatement is a governed process.
- Each control catches a specific AI failure mode: grounding catches the hallucinated factor, provenance capture catches the laundered estimate, versioning catches the silent change.
- Governed correctly, AI produces a more consistent report at scale, not a less consistent one, because the same rules and the same factor library reach every contributor automatically and the drift never happens.
Skill.re