Standing Up the ISSB and CBAM Reporting Programs
A multinational's reporting lead has three obligations landing in the same year and a CFO who assumes they are three separate projects. The company files climate disclosure under ISSB standards adopted in several of its operating jurisdictions, it imports steel and aluminium into the European Union and so must declare embedded emissions under CBAM, and it already runs a CSRD program. The instinct is to build three teams, three spreadsheets, three sets of numbers. That instinct is expensive and, worse, dangerous: when the same physical tonne of emissions is counted one way for ISSB and a different way for CBAM, an assurer or a customs authority will find the discrepancy and ask which number is wrong. The strategist's move is the opposite of three projects. It is one fact base feeding multiple obligations, with shared controls and divergent outputs. This lesson builds the ISSB and CBAM programs off the same evidence base.
One Fact Base, Many Obligations
The central idea of this lesson is the most leverage a reporting strategist has: build the evidence once, disclose it many ways. A fact base is the governed set of underlying data the company holds about its emissions and activities: the activity data, the emission factors with their provenance, the supplier responses tagged primary or secondary, the boundaries, and the calculations. The fact base is framework-neutral. A tonne of CO2 equivalent from a steel purchase is the same physical fact whether ISSB, CBAM, or CSRD asks about it. What differs is the question each framework asks, the boundary each draws, and the form each output takes.
This matters because the alternative, building a separate dataset per framework, guarantees the failure mode that ends careers in disclosure: the same underlying reality reported as two different numbers with no reconciliation. When that happens, neither number is trustworthy, because the existence of a contradiction proves at least one is wrong and the assurer cannot tell which. A single governed fact base, by contrast, gives you one source of truth that each framework draws from, so that any difference between an ISSB figure and a CBAM figure is an explainable consequence of different boundaries and definitions, not an unexplained discrepancy. The discipline is: shared controls on the inputs, divergent outputs by design, and every difference documented.
There is a second, quieter benefit that a strategist should make explicit to a CFO weighing the cost of building the fact base. Collecting value-chain emissions data is the single most expensive and slowest part of sustainability reporting, dominated by the supplier-data bottleneck that the whole industry struggles with. If that data is collected three times, once for each framework, the company pays the cost three times and creates three chances for the numbers to diverge. Collected once into a governed fact base, the cost is paid once and the data is consistent by construction. So the single fact base is not only the more defensible architecture; it is the cheaper one, which is the rare case where the compliance-driven choice and the cost-driven choice point the same way.
The same tonne reported two different ways is not two disclosures. It is one contradiction, and a contradiction proves at least one number is wrong before anyone has even checked the evidence.
The ISSB Program: IFRS S1 and S2 Across Many Jurisdictions
The ISSB, the International Sustainability Standards Board, issues the IFRS Sustainability Disclosure Standards. IFRS S1 sets the general requirements for disclosing sustainability-related financial information, and IFRS S2 is the climate-specific standard built around governance, strategy, risk management, and metrics and targets. As of the start of 2026 these standards are adopted or planned across more than 30 jurisdictions representing over half of global GDP, with roughly 21 jurisdictions having adopted and around 16 more planning. In December 2025 the ISSB issued targeted amendments to IFRS S2 to ease implementation. The strategic significance is that ISSB is converging, not collapsing: a growing share of the world's economy is moving toward one baseline, which is exactly what makes a single fact base valuable.
An ISSB program is jurisdiction-aware. Because adoption happens jurisdiction by jurisdiction, the same company can face IFRS S1 and S2 as adopted with local modifications in several places at once. The program therefore needs a jurisdiction matrix: which entities report under which jurisdiction's adoption of ISSB, with which local amendments, on which timeline. The fact base feeds all of them. The climate metrics that IFRS S2 requires, including the GHG inventory across Scope 1, 2, and 3, are drawn from the same governed emissions data the CSRD and CBAM programs use, so the company computes its footprint once and presents it in the form each jurisdiction's ISSB adoption requires.
The AI leverage here is in mapping and drafting. A model can help map the fact base to the IFRS S1 and S2 disclosure structure, draft the governance and strategy narrative datapoints, and flag where a jurisdiction's local amendment changes a requirement. But the same cardinal rule applies: every metric traces to the fact base, every narrative claim traces to evidence, and a model that "helpfully" reconciles two jurisdictions' figures by averaging them has just manufactured a number that exists in no fact base and will fail assurance.
The CBAM Program: Embedded Emissions in the Definitive Phase
CBAM, the EU Carbon Border Adjustment Mechanism, entered its definitive phase on 1 January 2026. It puts a carbon price on the emissions embedded in certain goods imported into the EU, so that imports face a comparable carbon cost to EU production. The covered goods are cement, iron and steel, aluminium, fertilisers, hydrogen, and electricity. The mechanism runs on a few defined concepts a strategist must hold precisely. Embedded emissions are the emissions released in producing the imported good. The authorised declarant is the party authorised to import covered goods and responsible for the CBAM obligations; authorised-declarant applications were due 31 March 2026, and more than 12,000 authorisation applications were filed by early January 2026. Certificate surrender, the act of surrendering CBAM certificates to cover the embedded emissions of the prior year's imports, begins in 2027. A 50-tonne annual de minimis threshold exempts most small importers.
The pivotal judgment in CBAM is actual values versus default values. The declarant can report the actual embedded emissions of the specific goods, supported by data from the producer, or use default values where actuals are not available. Actuals are usually lower and always more defensible, but they require real production data from the supplier, which is the same value-chain data bottleneck the rest of sustainability reporting fights. This is precisely where the fact base earns its keep: the supplier emissions data the CBAM declarant needs for actual values overlaps heavily with the Scope 3 supplier data the CSRD and ISSB programs already collect. Collect it once, tagged with provenance, and feed both the CBAM declaration and the Scope 3 inventory.
The CBAM failure mode is specific and customs-tested. A declarant who reports actual values must be able to show the data behind them; a declarant who quietly uses a default value but presents it as an actual, or who lets an AI tool "estimate" an actual that has no producer data behind it, is misstating the exact line a customs authority will test at certificate surrender. AI can accelerate the CBAM declaration by parsing producer data, mapping it to the declaration structure, and computing embedded emissions, but it must never invent an actual value, and the declaration must always be explicit about which figures are actuals and which are defaults.
Shared Controls, Divergent Outputs
The architecture that makes this work is shared controls over inputs and divergent outputs by design. The shared controls live on the fact base: one provenance standard for emission factors, one primary-versus-secondary labeling rule, one boundary documentation discipline, one approval process. Every framework draws from inputs that passed the same controls, so a factor accepted for the CBAM declaration is the same factor, with the same provenance, that appears in the ISSB metrics. This is what makes cross-framework consistency a property of the system rather than a manual reconciliation done late at night.
The outputs diverge because the frameworks genuinely differ, and a strategist must be precise about how. CBAM cares about the embedded emissions of specific covered goods crossing the EU border; ISSB cares about the company's climate-related financial disclosure across its whole footprint; CSRD cares about double materiality across all ESG topics. The boundaries differ, the scopes differ, the units of account differ. So the same fact base produces a CBAM declaration scoped to covered imports, an ISSB climate disclosure scoped to the reporting entity, and a CSRD sustainability statement scoped to double materiality, each correct on its own terms. The strategist's job is to document, in the basis of preparation, exactly why a number that appears in two outputs may legitimately differ between them, so that a difference is an explained design choice and never an unexplained contradiction.
The Cross-Framework Mapping Register
The practical artifact that holds this together is a cross-framework mapping register: a table that records, for each material data element in the fact base, which frameworks consume it, with which boundary, in which output, and where any framework-specific transformation is documented. When an assurer or a customs authority asks why the steel-related emissions in the CBAM declaration differ from the steel-related emissions in the ISSB Scope 3 figure, the register and the basis of preparation answer in one place: different boundary, different scope of goods, same underlying fact base, difference documented. AI can help build and maintain this register by mapping fact-base elements to framework requirements, but the register is a control, and a mapping a model proposes is checked by a human before it governs a disclosed number.
The register earns its keep precisely at the moments a reporting function fears most: the year-end crunch and the unexpected query. Without it, a question about why two numbers differ triggers a frantic reconstruction across teams who each remember their own corner of the work, and the reconstruction itself, done late and under pressure, is the thing an assurer trusts least. With the register, the difference was documented at the moment it was designed, so the answer is retrieved, not rebuilt. This is the same principle that runs through the entire program: provenance and reconciliation captured at the moment of creation are defensible, while provenance reconstructed after the fact is suspect. The register is the cross-framework expression of that principle.
One Governance Spine Across Three Programs
A strategist running ISSB, CBAM, and CSRD off one fact base should resist the urge to build three governance structures to match the three frameworks. The frameworks differ in their outputs, but the governance over the inputs should be unified, because the inputs are shared. One steering group owns the fact base and its controls. One provenance standard governs every factor. One approval process gates what enters. The framework-specific work, the ISSB jurisdiction matrix, the CBAM declarant obligations, the CSRD datapoint inventory, sits as specialized layers on top of a common foundation, each with its own owners but drawing from the same governed base. This is what keeps the programs from diverging operationally even as their outputs diverge by design. Three governance silos would re-create, at the management level, exactly the fragmentation that the single fact base exists to prevent at the data level.
The CBAM program adds one governance element the others do not require so sharply: the authorised-declarant obligation is a legal status with named accountability and hard deadlines tied to certificate surrender. The strategist treats the declarant role as a governed position with a clear owner, a calendar anchored to the surrender timeline, and a direct line into the shared fact base for the producer data that supports actual values. Because that producer data overlaps with the Scope 3 supplier data the CSRD and ISSB programs already chase, the declarant is not a separate data-collection effort but a specialized consumer of a collection effort the company is already funding. Seeing it that way is the difference between three competing data programs and one program serving three obligations.
Worked Example: One Steel Purchase, Two Frameworks
Trace a single fact through both programs. The company imports 10,000 tonnes of steel from a supplier in a third country. The fact base holds the activity data, 10,000 tonnes of a specified steel product, and the supplier's reported production emissions data, tagged primary because the supplier provided it, with its provenance recorded. Watch the wrong way first. A CBAM analyst, racing the surrender preparation, asks an AI tool to "give me the embedded emissions for our steel imports." The model returns a clean figure. Nobody notices it silently used a default value because the supplier data was in a different file, and the declaration presents it as an actual. Separately, an ISSB analyst asks a different tool for the Scope 3 figure for the same steel, which uses the supplier's primary data. Now two outputs carry two different emissions numbers for the same steel, one from a default and one from primary data, with no documented reason. A customs authority and an assurer both have a thread to pull.
Now the right way. Both analysts draw from the one governed fact base. The supplier's primary production data is the source for the CBAM actual value, so the declaration reports an actual, explicitly labeled, with the producer data behind it, and it is more defensible and likely lower than the default. The same supplier primary data feeds the ISSB Scope 3 line. Where the CBAM boundary, embedded emissions of the specific imported good, differs from the ISSB boundary, the company's broader Scope 3 accounting, the cross-framework mapping register records the difference and the basis of preparation explains it. The two outputs may still show different numbers, because they answer different questions about different boundaries, but every difference is documented and reconstructable. The fact was collected once. The provenance was preserved. The CBAM actual was never invented. And the contradiction that would have failed both an assurance engagement and a customs check never existed, because there was only ever one fact base.
Key Takeaways
- Build one governed fact base and disclose it many ways: the same physical tonne of emissions is the same fact whether ISSB, CBAM, or CSRD asks, so a separate dataset per framework manufactures contradictions that fail assurance.
- ISSB IFRS S1 and S2 are adopted or planned across more than 30 jurisdictions representing over half of global GDP, with about 21 adopted and 16 planning as of the start of 2026, and targeted IFRS S2 amendments issued in December 2025 to ease implementation.
- An ISSB program is jurisdiction-aware: a jurisdiction matrix tracks which entities report under which jurisdiction's adoption with which local amendments, all fed by the same fact base.
- CBAM's definitive phase went live 1 January 2026 over cement, iron and steel, aluminium, fertilisers, hydrogen, and electricity; authorised-declarant applications were due 31 March 2026, certificate surrender begins in 2027, and a 50-tonne de minimis threshold exempts most small importers.
- The pivotal CBAM judgment is actual values versus default values: actuals are more defensible and usually lower but require real producer data, which overlaps with the Scope 3 supplier data the other programs already collect.
- The architecture is shared controls on inputs and divergent outputs by design: one provenance standard, one primary-versus-secondary rule, one boundary discipline, feeding outputs that differ because the frameworks genuinely differ.
- A cross-framework mapping register and the basis of preparation document why a number may legitimately differ between two outputs, turning every difference into an explained design choice rather than an unexplained contradiction.
- AI accelerates mapping, drafting, and computation across all three programs, but it must never invent a CBAM actual value, never reconcile two jurisdictions by averaging, and every disclosed figure must trace to the one fact base.
- Unify the governance over inputs even though the outputs diverge: one steering group, one provenance standard, and one approval process feed framework-specific layers, so the programs never fragment at the management level the way the single fact base prevents at the data level.
Skill.re