Short answer
The answer, before the reasoning
Every reported datapoint should have a controlled evidence record showing what was reported, which paragraph or subpoint it relates to, where the source came from, who owns it, which period and boundary it covers, how it was calculated or judged, who reviewed it, whether the evidence is confidential and whether the datapoint is approved for release. The 2026 Voluntary Standard does not prescribe a named “evidence register”, but it requires information to be faithful and verifiable.
A proportionate register is the practical mechanism that allows an SME to demonstrate those qualities without placing confidential working papers in the public report.
A practical guide to building traceable evidence for energy, workforce, policy and other disclosures under the 2026 EU Voluntary Standard.
Technical status
EDUCATIONAL AND LEGAL STATUS
This article explains the Commission-adopted 2026 EU Voluntary Sustainability Reporting Standard. At the source cut-off, Delegated Act C(2026) 5011 was still in the European Parliament and Council scrutiny period and had not yet entered into force through Official Journal publication. The article is educational material, not legal advice, an assurance opinion or a substitute for checking the final OJ text and any contractual information request.
In practice
Article map
| Stage | What the reader will be able to do |
|---|---|
| Answer | Define the minimum evidence record behind each metric and narrative statement. |
| Distinguish | Separate source evidence, calculation evidence, review evidence and publication status. |
| Apply | Populate a proportionate register for energy, workforce and policy disclosures. |
| Protect | Control confidentiality and access without losing traceability. |
| Review | Use the register for internal quality review, assurance readiness and annual roll-forward. |
Why an evidence register matters even in voluntary reporting
“Voluntary” describes whether the undertaking is legally required to use the Standard; it does not mean that reported information can be approximate, unowned or unsupported. Paragraph 11 requires reported information to be relevant, faithful, comparable, understandable and verifiable. B1 also requires an explicit statement of the selected reporting option. Those statements are difficult to support if the organisation cannot trace a number or narrative claim to the underlying record and explain its period, boundary and method.
The public report should not contain every invoice, payroll export or board minute. The evidence register sits behind the report. It provides a controlled index to the evidence, while permissions ensure that sensitive records remain available only to authorised users. This distinction between a public disclosure and its supporting evidence is especially important for workforce, policy, commercial and personal data.
Rule
PRACTICAL PRINCIPLE
A datapoint is not review-ready merely because the number is plausible. It becomes review-ready when the team can reproduce it, identify the boundary, locate the source, explain the method and show who approved its release.
The four evidence layers behind a datapoint
Figure 1. Evidence register anatomy for one controlled datapoint.
In practice
| Evidence layer | Question it answers | Typical records |
|---|---|---|
| Source evidence | Where did the raw fact originate? | Invoice, meter reading, ERP extract, payroll report, policy document, legal register, certification record. |
| Transformation evidence | How did the source become the reported value or wording? | Calculation workbook, conversion factors, estimate model, mapping table, narrative drafting note. |
| Review evidence | Who checked the source, method, boundary and consistency? | Recalculation, reconciliation, reviewer checklist, exception log, management sign-off. |
| Release evidence | What was approved for which output and on what date? | Approved dataset version, publication pack, disclosure location, recipient/output register. |
Minimum evidence-register fields
The register can be maintained in a controlled spreadsheet, database or reporting platform. The technology is less important than the fields and workflow. A small organisation may use one row per datapoint; a more complex group may use separate records for each entity, site or data component and aggregate them into the reported fact.
In practice
| Field group | Field | Purpose |
|---|---|---|
| Record identity | Evidence record ID | Permanent identifier for the evidence record. |
| Record identity | Standard anchor | Module, disclosure, paragraph and subpoint. |
| Record identity | Datapoint label | Controlled name matching the data dictionary. |
| Reported content | Reported value or narrative | The exact approved number, Boolean, list or wording. |
| Reported content | Unit and format | MWh, tCO2e, headcount, FTE, percentage, currency, date or narrative. |
| Time | Reporting period | The period to which the reported information relates. |
| Time | Source cut-off / extraction date | When the underlying source was closed or extracted. |
| Boundary | Reporting basis | Individual or consolidated basis and covered entities. |
| Boundary | Metric-specific perimeter | Sites, operations, employee population or other scope. |
| Source | Source system / document | System name, report, invoice, register, document title and version. |
| Source | Evidence location | Controlled link, file path, document ID or archive reference. |
| Source | Source owner | Person/function accountable for the underlying source. |
| Methodology | Calculation / judgement method | Formula, conversion, aggregation, estimate or narrative judgement. |
| Methodology | Assumptions and limitations | Material assumptions, exclusions, uncertainty and data gaps. |
| Preparation | Preparer and preparation date | Who produced the value and when. |
| Review | Reviewer, date and result | Review performed, exceptions and resolution. |
| Review | Reconciliation / reasonableness check | Comparison with finance, prior year, operational records or external totals. |
| Confidentiality | Classification and access | Public, internal, confidential, personal data, legal privilege or restricted. |
| Release | Release status | Draft, reviewed, approved, withheld, superseded or released. |
| Release | Output and disclosure location | Report section, data pack, portal field or digital element. |
| Versioning | Version and change history | Old/new value, reason, preparer, reviewer and affected outputs. |
| Retention | Retention / disposal rule | How long the record is kept and who authorises disposal. |
Source quality: keep the strongest available evidence, not the largest file
Evidence quality depends on relevance, reliability and traceability. A system-generated extract may be stronger than a manually typed summary, but only if the report parameters and population are retained. An invoice may support purchased energy but not necessarily the energy period if bills straddle year-end. A policy document may prove that a policy exists but not that it has been implemented or effective. The register should therefore identify what each item proves and what it does not prove.
In practice
| Evidence type | What it can support | Common limitation — Useful control |
|---|---|---|
| External source document | Supplier invoice, certification, regulatory filing or external verification. | May cover a different period, entity or boundary. — Record period, account/site and reconciliation to the reporting perimeter. |
| System-generated internal record | Payroll, ERP, meter, incident or waste-system extract. | Query parameters and subsequent edits may be lost. — Retain extraction settings, date, source owner and locked copy. |
| Manual working paper | Calculation, allocation, conversion or estimate. | High risk of formula, copy/paste and version errors. — Formula review, protected cells, change log and independent recalculation. |
| Governance record | Policy approval, target approval, minutes or management representation. | May prove approval but not operation or outcome. — Link separately to implementation and performance evidence. |
| Management explanation | Narrative rationale, judgement or data-gap explanation. | Self-authored and potentially biased. — Challenge against source records, contrary evidence and user needs. |
Example 1: energy consumption under B3
Paragraph 32 requires total energy consumption in MWh for undertakings with more than 10 employees and makes the renewable/non-renewable and electricity/fuels breakdown conditional on the organisation being able to obtain the necessary information. The evidence record must therefore distinguish the required total from the conditional breakdown and show how invoices, meter readings and fuel records were converted and aligned to the reporting period.
In practice
| Register field | Illustrative entry |
|---|---|
| Standard anchor | B3, paragraph 32, first sentence - total energy consumption. |
| Reported value | 1,284 MWh for FY2026. |
| Boundary | Three operating sites controlled by the individual undertaking; employee home energy excluded. |
| Sources | Electricity invoices, gas invoices, bulk fuel delivery log and landlord statement for leased warehouse. |
| Method | Invoice kWh converted to MWh; December estimate for one bill not received by close; landlord allocation based on sub-metered floor. |
| Assumptions / limitations | Estimated December electricity represents 3.1% of total; renewable/non-renewable split unavailable for one landlord supply. |
| Owner / preparer | Facilities Manager / Management Accountant. |
| Review | Reconciled to utility expense accounts and meter totals; estimate challenged against January invoice after year-end. |
| Confidentiality | Invoices internal; supplier account details restricted. |
| Release status | Approved for Option A report v1.0 and bank data pack v1.0. |
Rule
EVIDENCE NUANCE
An invoice is not automatically the reported value. The register must retain the transformation from invoice units and billing dates to the annual MWh total and explain any estimate or allocation.
Example 2: workforce information under B8
B8 requires workforce information such as the number of employees by employment contract and by gender. The evidence record should define whether the organisation reports headcount or full-time equivalents, the measurement date or averaging convention, the treatment of joiners/leavers and the group entities included. Payroll data may contain personal information, so the public datapoint can be supported without exposing names, salary data or individual records to the reporting team.
In practice
| Register field | Illustrative entry |
|---|---|
| Standard anchor | B8, paragraph 40(a)-(b). |
| Reported content | 82 permanent employees, 6 temporary employees; 49 women, 39 men; headcount at 31 December 2026. |
| Boundary | Employees of parent company and two consolidated subsidiaries; agency workers excluded and tracked in a separate internal field. |
| Source | Payroll master report generated 5 January 2027 with query parameters retained. |
| Method | Unique active employee IDs at period end; fixed-term status mapped to temporary; gender category based on payroll master data. |
| Review | Total reconciled to payroll control account, HR leaver/joiner report and B1 employee total. |
| Confidentiality | Underlying payroll extract restricted to HR and finance controller; register stores aggregate evidence reference only. |
| Release status | Approved aggregate values; personal-data source not included in publisher pack. |
Example 3: policy and initiative disclosure under B2
B2 is narrative, but it still needs evidence. If the undertaking states that it has a sustainability policy, future initiative or target, the evidence should show the approved document, scope, version, responsible owner and approval status. A draft document, an informal practice or a proposal in a meeting deck should not be described as an approved policy unless that status is accurate.
Figure 2. Energy, workforce and policy disclosures use different evidence, but a consistent control structure.
In practice
| Register field | Illustrative entry |
|---|---|
| Standard anchor | B2, paragraph 29(b) - policies on sustainability issues. |
| Approved wording | The company has an Environmental Policy covering energy, waste, water and pollution prevention across all operating sites. |
| Source | Environmental Policy EP-04, version 3.0, approved by the Board on 18 June 2026. |
| Boundary | Parent and two subsidiaries; contractors covered only when working on company premises. |
| Method / judgement | Narrative checked against the policy scope; no claim made that the policy is fully effective. |
| Implementation evidence | Site induction records, environmental responsibilities matrix and 2026 action plan. |
| Review | Policy owner confirmed current version; Company Secretary confirmed board approval; reporting reviewer challenged effectiveness wording. |
| Confidentiality / release | Policy public on website; board minutes restricted; approved wording released. |
Ownership: data owner, preparer and reviewer are different roles
In a small organisation, one person may perform more than one role, but the register should still record the role performed. The data owner is accountable for the source process; the preparer transforms it into the reported datapoint; the reviewer challenges the method and evidence; the approver authorises release. Where the same person prepares and reviews a high-risk metric, a compensating management review or independent spot check should be documented.
In practice
| Role | Primary responsibility | Evidence retained |
|---|---|---|
| Data owner | Maintains the source process and confirms population/completeness. | Source-system description, owner confirmation and exception notes. |
| Preparer | Extracts, calculates, documents assumptions and drafts wording. | Working paper, formula, source links and preparation sign-off. |
| Reviewer | Recalculates or challenges method, boundary, consistency and limitations. | Review checklist, comments, exceptions and resolution. |
| Approver | Accepts the residual risk and authorises external release. | Approval record and approved dataset/output version. |
| Publisher / relationship owner | Uses only approved content in the specified output. | Release log and confirmation that no unreviewed edits were introduced. |
Confidentiality should control access, not erase the evidence trail
Some supporting evidence contains personal data, trade secrets, legal advice, supplier pricing or security information. The evidence register should classify access and point to the controlled location without copying sensitive content into the public publication pack. Paragraph 22 permits omission of specific categories of protected information from the report, subject to identifying each omitted datapoint and reassessing the exemption at each reporting date. That reporting exemption is separate from routine evidence-access controls.
In practice
| Classification | Who may access | What the public/reporting pack contains |
|---|---|---|
| Public | Any user. | Public source or direct hyperlink. |
| Internal | Relevant employees and reviewers. | Evidence reference, method and aggregate output. |
| Confidential commercial | Named owner, reviewer and authorised management. | High-level evidence reference and any paragraph 22 decision if the reported datapoint is omitted. |
| Personal data | HR/authorised controller and strictly necessary reviewer. | Aggregate metric, controlled query description and restricted source ID. |
| Legally restricted / privileged | Legal or security-approved users. | Only the authorised statement and a restricted record reference. |
In practice
Review statuses and release gates
| Status | Meaning | May be published? |
|---|---|---|
| Draft | Source or calculation is incomplete; no reviewer conclusion. | No. |
| Prepared | Value and evidence are assembled by the preparer. | No. |
| Reviewed - exceptions open | Review occurred but unresolved issues remain. | Normally no; escalate or qualify scope. |
| Reviewed - ready for approval | Review complete and evidence sufficient for approval. | Not until approved. |
| Approved | Authorised for a specified dataset and output scope. | Yes, for the recorded output/version. |
| Released | Published or sent to a named recipient. | Already released; retain release record. |
| Superseded | Replaced by a later approved version. | No for new use; preserve history. |
| Withheld / restricted | Not released because of scope, confidentiality or unresolved reporting issue. | No. |
A proportionate evidence-register workflow
Create the datapoint list. Start from the selected reporting option and map each paragraph/subpoint, including conditions and voluntary status.
Assign owners. Name the source owner, preparer, reviewer and approver for each datapoint or disclosure group.
Define the evidence expected. State the source, calculation, review and release evidence required before collection begins.
Collect and link. Store controlled evidence references rather than uncontrolled email attachments.
Document methodology and boundaries. Record units, period, perimeter, assumptions, estimates and exclusions.
Review and resolve exceptions. Recalculate, reconcile, challenge contradictory evidence and document the resolution.
Approve a dataset version. Freeze the value/narrative and evidence status before design or external submission.
Record every release. Identify the recipient/output, date, version and any permitted restriction.
Roll forward. Copy the prior-year record, update changed evidence and preserve comparatives and change history.
Hypothetical scenario
ILLUSTRATIVE SCENARIO
Issue. The reporting team enters 1,300 MWh from a facilities summary. The evidence register shows no period, no leased-site treatment and no reviewer. Review. The finance controller traces the summary to invoices and discovers that one invoice covers November-January. A December estimate is prepared, the January portion is removed, and a landlord allocation is separately documented. Outcome. The approved value becomes 1,284 MWh. The register retains the old value, reason for change, calculation, reviewer and outputs affected. Learning point. The review did not merely “check the number”. It tested the reporting period, boundary, transformation and evidence trail.
Illustrative only. It shows how the decision is made, not wording that can be copied or relied on.
In practice
Common evidence failures
| Failure | Symptom | Correction |
|---|---|---|
| Evidence is a folder, not a register | Files exist but cannot be linked to a specific datapoint or version. | Create record IDs and link every released fact to the exact source and working paper. |
| Owner is a department name only | No individual accepts responsibility for completeness or follow-up. | Record role and named accountable owner for the reporting cycle. |
| Method exists only in the preparer’s memory | The figure cannot be reproduced after staff changes. | Document formula, assumptions, factors and source queries. |
| Confidential evidence is copied widely | Payroll or legal records appear in general reporting folders. | Use access-controlled storage and retain only references/aggregates in the publisher pack. |
| Review is recorded as “checked” | No evidence shows what was tested or which exceptions were resolved. | Define review procedures and retain comments, recalculation and resolution. |
| Approved value is overwritten | The organisation cannot identify what was sent to each user. | Use immutable versions and a release log. |
| A policy document supports an effectiveness claim | Existence and approval are confused with implementation or outcome. | Link separate implementation and performance evidence or narrow the wording. |
Readiness
Evidence register checklist
- Every datapoint has a source anchor and controlled record ID.
- Period, extraction date and reporting boundary are explicit.
- Source document/system, version and location are recorded.
- Method, formula, assumptions, estimates and limitations are documented.
- Data owner, preparer, reviewer and approver are identifiable.
- Review procedures and exceptions are evidenced, not merely asserted.
- Confidentiality and access are appropriate to the underlying record.
- Approved value/narrative and release status are controlled.
- Each report, pack or portal response identifies the dataset version used.
- Change history and prior-year evidence are preserved.
Practical conclusion
A proportionate evidence register turns voluntary sustainability reporting from a collection of plausible statements into a repeatable controlled process. It lets an SME respond to reviewers, banks and customers without exposing confidential working papers, and it provides the foundation for comparatives, correction, assurance readiness and efficient annual roll-forward. The strongest register is not the one with the most attachments; it is the one that makes every material datapoint reproducible, reviewable and clearly approved for release.
Questions
Questions people ask
What evidence should sit behind a sustainability datapoint?
Every reported datapoint should have a controlled evidence record showing what was reported, which paragraph or subpoint it relates to, where the source came from, who owns it, which period and boundary it covers, how it was calculated or judged, who reviewed it, whether the evidence is confidential and whether the datapoint is approved for release. The 2026 Voluntary Standard does not prescribe a named “evidence register”, but it requires information to be faithful and verifiable.
What fields belong in an evidence register?
Every reported datapoint should have a controlled evidence record showing what was reported, which paragraph or subpoint it relates to, where the source came from, who owns it, which period and boundary it covers, how it was calculated or judged, who reviewed it, whether the evidence is confidential and whether the datapoint is approved for release. The 2026 Voluntary Standard does not prescribe a named “evidence register”, but it requires information to be faithful and verifiable.
How should confidential evidence be handled?
Some supporting evidence contains personal data, trade secrets, legal advice, supplier pricing or security information. The evidence register should classify access and point to the controlled location without copying sensitive content into the public publication pack.
What evidence supports energy and workforce disclosures?
An invoice may support purchased energy but not necessarily the energy period if bills straddle year-end. The evidence record should define whether the organisation reports headcount or full-time equivalents, the measurement date or averaging convention, the treatment of joiners/leavers and the group entities included. Payroll data may contain personal information, so the public datapoint can be supported without exposing names, salary data or individual records to the reporting team.
Does a policy document prove effectiveness?
An invoice may support purchased energy but not necessarily the energy period if bills straddle year-end. A policy document may prove that a policy exists but not that it has been implemented or effective.
Take it with you
The checklists as a working spreadsheet
Every checklist and table on this page, with empty status, owner and evidence columns for your team to fill in and keep.
✓ LRA AI Assistant · Human-in-the-loop
Ask about this guide
It answers from this page, and reaches into the linked disclosure cards when your question is about the standard itself. Your first two answers are free without signing in.
Go deeper · EU Voluntary Standard 2026
Available as Guided Flex, Live Cohort, 1:1 Expert Mentorship or Corporate Programme.
