Engaging Suppliers as Data Partners
It is late February and your Scope 3 inventory is a wall of blanks. Purchased goods and services, the biggest category you have, is a spreadsheet with a thousand supplier rows and primary data from maybe forty of them. The annual email went out in January: a generic questionnaire, a two-week deadline, a threat about "reporting requirements." Most suppliers ignored it. Some replied with a PDF nobody can parse. Your carbon accountant is staring at the gap, and the tempting fix is one keystroke away: let the AI fill the empty rows with industry averages and call it done. That single move is how a program that is 75% of your footprint quietly becomes 75% unassurable. This lesson is about the other path: treating suppliers not as a once-a-year data-extraction target but as data partners inside a standing workflow, so the number you file is one an assurer can trace and a supplier can improve.
The Goldmine and the Danger: Why Scope 3 Runs Through Your Suppliers
Scope 3 emissions, the indirect emissions across your value chain, average roughly 75% of a company's total footprint and span the fifteen categories of the GHG Protocol Corporate Value Chain Standard. For most companies the single largest slice is category 1, purchased goods and services, and that slice is made almost entirely of other people's data. Your suppliers are therefore both the goldmine and the danger. They hold the primary data that would make your largest category defensible, and they are also the reason it is so often built on estimates that will not survive assurance. There is no version of a credible Scope 3 inventory that routes around your suppliers, because the emissions are theirs before they are yours.
The barrier is measured, not anecdotal, and it is worth teaching as a number to verify rather than repeat. The Sphera 2025 Scope 3 Report found that 62% of reporters cite internal data quality and 79% cite supplier-data availability as their top barriers to Scope 3. Read the 79% carefully. It does not say suppliers refuse to help. It says the data is not available in a usable form, which is a workflow failure as much as a supplier failure. When you verify that figure, look at how the question was framed, what population was surveyed, and what "availability" meant, because the barrier a number describes tells you where to aim the fix. The fix implied by 79% is not "chase harder." It is "build a relationship that makes primary data flow."
Why does this matter so much more than internal Scope 1 and 2? Because Scope 1 and 2 are yours to measure directly: your fuel, your electricity, your meters. Scope 3 is a data-supply-chain problem layered on top of your physical supply chain, and every weak link is a place where an estimate substitutes for a measurement. When the largest part of your footprint depends on data you do not own, the discipline that governs how you get that data, label it, and improve it becomes the whole game.
The stakes have also risen. Assurance is no longer optional at the top of the market: 73% of large global companies now obtain external assurance on at least some sustainability disclosures, up from 51% in 2019, and emissions are the most-assured category of all. Most engagements are limited assurance today, trending toward reasonable assurance, which is a higher bar. Under CSRD after the Omnibus, the largest undertakings remain in scope, and for them a failed Scope 3 disclosure is a board-level event, not a footnote. The reader who files this number should assume every supplier row will one day be sampled by an assurer who has been burned before by a beautiful report built on numbers no one could reconstruct. That assumption, applied early, is what separates a program that survives assurance from one that scrambles through it.
The Annual Scramble Versus the Standing Relationship
Most Scope 3 data collection is run as an annual scramble: a questionnaire fired into the void in the first quarter, a scramble to chase non-responders, and a deadline that forces the gap-filling shortcut. The scramble fails for a structural reason. It treats the supplier as a data source to be extracted from once a year, under time pressure, with no reason to invest effort and no feedback on whether their last submission was any good. A supplier who gets a cold questionnaire with a threat attached, and never hears back about what happened to their numbers, learns that the exercise is a compliance ritual, and responds accordingly, if at all.
The alternative is to treat the value chain as part of the workflow, not an afterthought: a standing Scope 3 relationship rather than a yearly campaign. In a standing relationship the supplier is onboarded as a data partner, has a persistent channel through which data flows, receives feedback on the quality of what they send, and has a reason to improve over time. The reporting cycle stops being a cliff and becomes a checkpoint on a continuous process. This is not softer or slower. It is the only version that produces primary data at the scale Scope 3 demands, because primary data is a habit you build with a partner, not a file you pull from a stranger.
Suppliers are not a data source you extract from once a year. They are data partners you onboard, incentivize, and improve. The 79% supplier-data barrier is broken by a relationship, not a reminder email.
Onboarding a Supplier as a Data Relationship
The word onboarding is deliberate. You already onboard suppliers commercially: contracts, payment terms, quality expectations, delivery standards. Data is now one of those standards, and it deserves the same deliberate front-loaded effort. Onboarding a supplier as a data partner means, at the start of the relationship, establishing what data you need, in what form, at what cadence, with what quality expectation, and through what channel, so that data provision is a known term of the relationship rather than an annual ambush.
What Onboarding Establishes
Good data onboarding sets four things before the first reporting cycle. First, the data specification: exactly which activity data you need (energy consumed, mass of material, distance shipped, units produced) and in what units, because activity-based data is what lets you move off spend-based estimates. Second, the quality expectation: whether you are asking for measured primary data, a supplier-specific calculation, or an acknowledged estimate, and what evidence backs each. Third, the cadence and channel: how often data flows and through what mechanism, so it is not reinvented each year. Fourth, the provenance requirement: that every datapoint arrives with its source, method, and date attached, because a number without provenance is a number your assurer cannot use.
Onboarding is also where you set expectations honestly. A small supplier with no carbon accounting capability cannot produce measured primary data in year one, and pretending otherwise produces fake precision. The honest onboarding conversation places that supplier in a starting tier, agrees an estimate is acceptable for now, labels it as such, and sets a path to improve. That honesty is what makes the relationship real, and it is what keeps the estimate labeled as an estimate instead of laundered into your measured-data column.
Tiering the Supplier Base
No company can onboard a thousand suppliers to the same depth, and the discipline is not to try. Tier the base by materiality and by data maturity. A small number of suppliers usually drive the majority of the category's emissions, and those are the ones worth the deepest relationship, the capability support, and the push toward measured primary data. The long tail of small, immaterial suppliers can sit on labeled secondary estimates for now, with the effort concentrated where it moves the footprint. Tiering is what makes the standing relationship affordable: it lets you spend real onboarding effort where it changes the number and accept honest, labeled estimates where it does not. The mistake is the inverse of the gap-filling shortcut: exhausting the team chasing primary data from suppliers too small to matter while the material ones stay on spend-based guesses.
Incentives and Feedback Loops: Why Suppliers Actually Improve
A request is not an incentive. The reason 79% of reporters hit a supplier-data wall is that the standard approach gives the supplier a demand with no reason to meet it and no signal about whether they met it last time. Two mechanisms turn a reluctant data source into an improving data partner: incentives to provide primary data, and feedback loops that show suppliers how to get better.
Incentives for Primary Data
Suppliers respond to reasons that touch their own interests. Effective incentives include making data quality a factor in procurement decisions and scorecards, so that a supplier who provides good primary data wins preference over one who sends a spend-based guess; recognizing that a supplier's own customers increasingly ask them the same questions, so the primary data they build for you serves their whole disclosure obligation; and, at the mature end, capacity support, where a large buyer helps key suppliers build the measurement capability that produces primary data. The through-line is that you are asking a supplier to invest effort, and investment follows incentive. A questionnaire with a deadline is a demand. A relationship where good data earns preference and support is an incentive. The most durable incentive of all is that the buyer treats the supplier as a partner in a shared problem rather than a delinquent to be dunned, because a partner who feels the effort is valued keeps investing, while a data source who feels squeezed does the minimum and moves on.
Data-Quality Feedback Loops
The single most neglected mechanism in Scope 3 collection is the feedback loop. In the annual scramble, data flows one way: the supplier sends a number into a void and never learns whether it was usable, whether it was implausible, whether it improved on last year, or how it compares to peers. A feedback loop closes that gap. It tells the supplier that the spend-based figure they sent could become an activity-based figure if they provided energy consumption; that their number jumped 40% year over year and needs explanation; that a measured figure would move them into a preferred tier. Over successive cycles, a supplier who receives this feedback climbs the data-quality ladder, from spend-based estimate, to supplier-specific calculation, to measured primary data. The feedback loop is the machinery of improvement, and without it the same weak data recurs every year because nobody ever told the supplier what "better" looks like.
Where AI Accelerates Collection Without Laundering Estimates
AI is genuinely powerful in supplier data collection, and it is also where the most dangerous shortcut lives. The discipline is to let AI accelerate the human work of collection while never letting it manufacture the data itself. Three uses are legitimate and one is fatal.
Drafting, Triage, and Parsing
AI genuinely speeds the mechanical parts of collection. It can draft tailored supplier outreach and questionnaires at scale, personalized to a supplier's sector and prior submissions instead of one cold generic form. It can triage the flood of inbound responses, flagging which submissions are complete, which are implausible, which contradict last year, and which need a human follow-up, so your team spends its hours on the responses that matter. It can parse the messy formats suppliers actually send, extracting activity data from an invoice, a utility bill, a PDF, or a spreadsheet that would otherwise be manually re-keyed. Every one of these compresses the labor of collection without touching the truth of the data, because in each case the AI is moving or reading a supplier-provided number, not inventing one.
The Fatal Shortcut: Filling Gaps With Averages
The fatal use is letting AI fill the empty supplier rows with a plausible industry average and dropping it into the same field as supplier-reported data. It is fatal for a precise reason: it launders an estimate into the appearance of a measurement. The output looks clean and confident, indistinguishable from a real supplier figure, and that indistinguishability is exactly the problem. An estimate has different reliability, different uncertainty, and different assurance treatment than a measured number, and when the two look identical in the file, the assurer can no longer tell what is real. The moment an assurer discovers one industry-average estimate sitting in the measured-data column, he assumes there are more, and the doubt spreads to every figure in the category. AI does not cause this failure. Using AI without labels causes it.
The line is simple to state and easy to violate under deadline: AI may accelerate how fast supplier data reaches a human decision, but it may never substitute an estimate for the missing data and present it as measured. Defensible estimation is legitimate and often necessary; the GHG Protocol expects it where primary data does not exist. What is not legitimate is the estimate that hides. The difference between a defensible estimate and a laundered one is not the number. It is the label.
Primary Versus Secondary Data, and Provenance on Every Datapoint
The whole discipline reduces to a labeling and provenance regime that an assurer can test. Primary data is supplier-specific data measured or calculated at the source: the supplier's actual energy consumption, their own product-level emissions, their measured activity. Secondary data is everything else: industry averages, database emission factors, spend-based approximations that use an economic proxy rather than the supplier's real activity. A defensible Scope 3 inventory does not require that everything be primary. It requires that everything be honestly labeled as what it is, so the reader and the assurer know the reliability of each figure.
Two method families sit under these labels and must never be confused. Spend-based methods multiply money spent by an emission factor per unit of currency, a rough approximation useful for coverage but weak in accuracy. Activity-based methods multiply physical activity (kilowatt-hours, tonnes, kilometers) by an activity-specific emission factor, far more accurate and far closer to primary. The whole point of the feedback loop and the incentives is to migrate suppliers up this ladder, from spend-based secondary toward activity-based primary. And every emission factor used, whether primary or secondary, carries its own provenance: the source, the version, the date, the geography. A hallucinated emission factor, a plausible number with no source, is the classic AI failure that ends the conversation with an assurer.
Provenance is the connective tissue. Every supplier datapoint that enters your inventory should carry, at the moment it enters, a record of where it came from (this supplier, this invoice, this database), how it was derived (measured, calculated, spend-based estimate), who decided to accept it, and what emission factor was applied with what source. Provenance captured at the point of entry is cheap. Provenance reconstructed under an assurer's deadline is expensive, and often impossible. The cardinal rule of the program applies to every one of these datapoints: AI assists, the human decides, the file proves it.
A Worked Example: One Supplier Row, Two Ways
Take a single row in your purchased-goods category: a mid-sized components supplier who did not respond to the annual questionnaire. Watch the row produced two ways.
In the trust-destroying version, it is the last week before the reporting deadline. The analyst, facing hundreds of blank rows, asks the AI to estimate emissions for every non-responder using industry averages. For this supplier the model returns a confident figure derived from a sector benchmark it names vaguely, and the analyst pastes it into the reporting platform in the same column that holds actual supplier-reported figures, with no note distinguishing it. The inventory now looks complete and precise. But the number is a secondary estimate wearing the clothes of a primary measurement. Months later the assurer samples this supplier, asks for the basis, and finds an unsourced industry average sitting in the measured-data field. He does not just flag the row. He expands the sample, raises the assessed risk for the entire purchased-goods category, and the engagement scoped as limited assurance becomes a scramble over how many other rows were filled the same way. The shortcut that saved a week produced a finding and a possible restatement.
In the trust-building version, the same supplier is a data partner onboarded the prior year. Because a standing relationship exists, the AI drafts a tailored follow-up referencing last year's submission, and the supplier returns a utility bill and a production figure. The AI parses the bill, extracts kilowatt-hours and units produced, and proposes an activity-based calculation, but it is required to return the named, dated emission factor from the approved library and to label the result as an activity-based figure derived from supplier-provided primary data. The analyst reviews the extraction against the source bill, confirms the method, notes the small remaining estimate in the calculation, and signs off. For the genuine non-responders who sent nothing, the AI produces a spend-based estimate that is explicitly labeled secondary and spend-based, with its factor source, so it never masquerades as measured. The record captures, for every row, the source, the method, the reviewer, the factor, and the label, at the moment of entry. When the assurer samples this supplier, he receives the utility bill, the extraction, the human decision, the factor source, and a label that says exactly what the number is. He tests it, finds it reconstructable and honestly labeled, and files it as well-controlled. Same footprint gap, opposite outcome. The difference was not the AI. It was the relationship, the labels, and the file.
Key Takeaways
- Scope 3 averages about 75% of the total footprint across the fifteen GHG Protocol categories, and most of it is other people's data, so suppliers are both the goldmine and the danger. There is no credible Scope 3 inventory that routes around them.
- Treat the 79% supplier-data-availability barrier from the Sphera 2025 Scope 3 Report as a number to verify, and read what it implies: the data is not available in usable form, which is a workflow failure fixed by a relationship, not by chasing harder.
- Replace the annual scramble with a standing Scope 3 relationship. Onboard suppliers as data partners with a clear data specification, quality expectation, cadence, channel, and provenance requirement set before the first cycle.
- A request is not an incentive. Suppliers improve when good primary data earns procurement preference, serves their own disclosure obligations, and is supported with capability building, and when a feedback loop tells them how to climb from spend-based to activity-based to measured.
- AI legitimately accelerates collection by drafting tailored outreach, triaging inbound responses, and parsing messy formats. It moves and reads supplier data faster; it must never invent the data itself.
- The fatal shortcut is letting AI fill gaps with industry averages that sit in the same field as measured data. A supplier-reported figure and an estimate cannot look identical in the file, or the assurer can no longer tell what is real.
- Label everything honestly: primary versus secondary, activity-based versus spend-based, with the emission factor's source, version, and date. Defensible estimation is expected where primary data does not exist; the difference between a defensible estimate and a laundered one is the label.
- Capture provenance on every supplier datapoint at the moment of entry, not under an assurer's deadline. The cardinal rule holds for each row: AI assists, the human decides, the file proves it.
Skill.re