Skip to the answer

Disclosure GuidesPillar guides, articles, FAQ and expert notes

Level 2 · Explainer·UAE FDL 11 / 2024 · Disclosure guides

Internal Controls for UAE MRV: source completeness, reconciliations, factors, estimates, approvals, audit trails, cybersecurity and internal audit

Show control objectives by data stream and assertion.

Who this is for A 6-minute read for reporting teams working through Building the greenhouse gas inventory, and for reviewers testing whether the evidence behind it holds.

Published passport

Current as at 11 August 2026
RK Reviewed by Dr Ross KurinkoLinkedIn Strategic ESG Advisor · IFRS S1 & S2 / GRI / ESRS expert GRI Certified Global Trainer · PhD, University of Cambridge · ESG-AI expert 15+ years on FTSE 100 & Fortune Global 500 disclosures Canary Wharf, London LRA educational guidance · Not issued or endorsed by MOCCAE

Edition written against

LEGAL STATUS CARD: Federal Decree-Law No. 11 of 2024 is in force. Its Article 18 one-year …

Published

12 Aug 2026

Knowledge Hub guide

Last reviewed

11 Aug 2026

Short answer

The answer, before the reasoning

A defensible UAE MRV process needs controls over the whole data lineage: source completeness, accurate units and factors, period cut-off, estimates, formula changes, independent review, locked submission versions, retained evidence and access security. Article 6 sets the reporting, retention and verification framework but does not prescribe this full company control matrix.

The detailed controls below are implementation practice designed to make the legal output reliable and inspection-ready.

From legal obligation to control objective

The law establishes the output and accountability framework: designated sources measure emissions regularly, prepare an inventory, report on required forms, reduce emissions, retain records and support authority verification. It does not provide a line-by-line corporate control manual. Management therefore needs to translate the obligation into control objectives that can be tested.

In practice

Assertion Control question
Completeness Have all entities, facilities, accounts, equipment and emission sources been captured for the period?
Accuracy Are units, quantities, factors, formulas and GWP values correct and independently challenged?
Cut-off and classification Are consumption, delivery, leakage and estimate periods correctly assigned, with source type and boundary treatment documented?
Approval and audit trail Can a reviewer identify the preparer, reviewer, change, evidence and final approved version?
Security and availability Can the company prevent unauthorised change and recover the evidence throughout the retention period?

In practice

Control matrix by data stream

Data stream Key reconciliations Accuracy tests — Approval / trail
Fuel and fleet Supplier invoices to ledger, tank movement and fleet records. Litres, density, calorific value, duplicates and source classification. — Data owner + finance/facilities reviewer.
Electricity and cooling All accounts, sites, meters, landlord statements and accrued missing bills. kWh, tariff mapping, location/market treatment and period cut-off. — Finance + sustainability review.
Refrigerants Equipment register, initial charge, top-ups, recovery and disposal. Gas type, quantity, leakage event date and mass-balance reasonableness. — Facilities + technical reviewer.
Factors and GWP Approved register to calculations. Units, geography, technology, year, source and effective date. — Method owner + change approval.
Estimates and formulas Missing-data log to calculated totals. Coverage, reasonableness, formula tests, sensitivity and uncertainty. — Independent reviewer + sign-off.
Submission and access Final totals to approved workbook and attachments. Locked period, version, export and portal receipt. — Segregated roles + management approval.

Reconciliations that catch the most errors

Entity/facility register to general ledger, utility account list and equipment register.

Fuel supplier totals to accounts payable and inventory movement.

Electricity invoices to meter reads, site opening/closure dates and landlord statements.

Refrigerant purchases and service logs to equipment charge and recovery.

Activity-data subtotals to calculation workbook input ranges.

Factor IDs and versions in the workbook to the approved factor register.

Final emissions by source and gas to the submission form and verifier statement.

Prior-period totals to restatement or methodology-change register.

Factors, estimates and formulas

Factors are master data, not text copied into a formula cell. Each factor needs a stable ID, publisher, edition, geography, technology, numerator/denominator unit, heating-value basis, GWP source and effective period. Changes should trigger an impact assessment and an approved decision on recalculating comparatives.

Estimates should have a reason, coverage period, proxy source, formula, uncertainty or sensitivity, reviewer and remediation date. Formula cells should be protected, tested against known cases and independently recalculated for material sources.

Approval design and segregation of duties

Data owner confirms source completeness and explains anomalies.

Method owner approves factor hierarchy, formulas and departures.

Finance or operational reviewer performs reconciliations.

Sustainability reviewer consolidates and challenges classification and estimates.

Legal reviewer controls claims, authority wording and protected information.

Management approves the final representation and submission package.

System administrator manages access but does not approve the emissions result.

Show data lineage and cross-cutting cyber safeguards.

Cybersecurity guardrails

Cyber controls are not stated as a detailed checklist in Federal Decree-Law No. 11. They are implementation safeguards for the integrity and availability of evidence that the law requires companies to retain and provide. The control design should reflect the company’s risk profile and applicable UAE cyber/privacy requirements.

In practice

Control Purpose Evidence
Role-based access and least privilege Prevent unauthorised viewing or change. Quarterly access review, role matrix and privileged-user log.
Multi-factor authentication Protect privileged and verifier accounts. Configuration and access logs.
Immutable change/approval log Reconstruct who changed factors, formulas, data and status. Timestamped old/new values and approval ticket.
Encryption and secure transfer Protect restricted data in transit and at rest. Configuration, key-management and transfer record.
Backup and disaster recovery Meet five-year availability and recovery expectations. Backup reports and tested recovery results.
Incident response and legal hold Preserve evidence and assess reporting impact. Incident log, preservation notice, root-cause and correction decision.

Internal audit’s role

Internal audit can evaluate whether the control framework is designed appropriately and operated during the reporting period. It can test samples, observe reconciliations, inspect access logs and track remediation. It should not prepare the data it later audits, make management’s legal representation, or present its work as the authority’s verification.

Hypothetical scenario

ILLUSTRATIVE SCENARIO

A group discovers that one facility used a new electricity factor from July, while the workbook applied it for the whole year. The factor register shows no approved effective date. The team freezes the submission, quantifies the impact, corrects the period-specific formula, documents the control failure, considers comparative impact and adds an automated effective-date check. Internal audit later tests the remediation.

Illustrative only. It shows how the decision is made, not wording that can be copied or relied on.

Illustrative control description

“Each material data stream is reconciled to an independent operational or financial population. Emission factors are selected from an approved, version-controlled register. Estimates and formula changes require documented review. The final package is locked after technical, legal and management approval, and the submitted version and receipt are retained with the five-year evidence file.”

Common mistakes

Control descriptions exist but no owner or evidence is assigned.

Finance and sustainability use different site lists.

Factor URLs are stored without downloaded editions.

Formulas are reviewed visually rather than recalculated.

Estimates are overwritten when actual data arrives, losing the original trail.

Administrator access is shared.

The verifier receives a different version from management.

Internal audit tests only the final total, not the source-to-submission lineage.

Backup success is assumed without a restore test.

A late correction is made without assessing the filed report or authority notification.

Rule

MYTH / REALITY

Myth: a verified calculation does not need strong internal controls. Reality: verification is performed on evidence produced by the company. Weak source, access, version and approval controls create findings, rework and inspection risk even when the final number happens to be correct.

Readiness

MRV internal-control checklist

  • • Source population is complete and reconciled.
  • • Data units and cut-off are tested.
  • • Factor register is current and approved.
  • • Formula testing is documented.
  • • Estimates are labelled and challenged.
  • • Changes have old/new values and approval.
  • • Preparer and reviewer duties are separated.
  • • Submission version is locked.
  • • Portal/export receipt is retained.
  • • Role access is reviewed.
  • • Backup recovery is tested.
  • • Internal-audit findings are owned and closed.

Rule

CONTROLLED PRODUCTION RECORD

This section supports CMS publication, technical review, AI/RAG reuse and future updates. It is not intended to appear in the final public web article unless the publisher chooses to expose selected fields.

Perform source-population and data-stream reconciliations: entities, facilities, accounts and equipment to masters; fuel to invoices, ledger and stock; electricity and cooling to meters and accounts; refrigerants to equipment and gas movement; and factors to the approved register. Reconcile final totals to the approved workbook, submission form and receipt, and prior periods to the restatement or methodology-change register.

The audit trail should identify the preparer, reviewer, change, evidence and final approved version for each material data stream. Retain stable source and factor identifiers, calculation inputs and formulas, estimates, approvals, the locked submission, receipt, correction history and access logs.

Use role-based access and least privilege, multi-factor authentication, immutable change and approval logs, encryption and secure transfer, tested backups and recovery, incident response and legal hold. These are implementation safeguards for the integrity and availability of retained evidence, not detailed controls prescribed by the Decree-Law.

Questions

Questions people ask

Which reconciliations should be performed?

Perform source-population and data-stream reconciliations: entities, facilities, accounts and equipment to masters; fuel to invoices, ledger and stock; electricity and cooling to meters and accounts; refrigerants to equipment and gas movement; and factors to the approved register. Reconcile final totals to the approved workbook, submission form and receipt, and prior periods to the restatement or methodology-change register.

How should factor and formula changes be approved?

Each factor needs a stable ID, publisher, edition, geography, technology, numerator/denominator unit, heating-value basis, GWP source and effective period. Changes should trigger an impact assessment and an approved decision on recalculating comparatives. Formula cells should be protected, tested against known cases and independently recalculated for material sources.

What evidence should an audit trail contain?

The audit trail should identify the preparer, reviewer, change, evidence and final approved version for each material data stream. Retain stable source and factor identifiers, calculation inputs and formulas, estimates, approvals, the locked submission, receipt, correction history and access logs.

What is internal audit’s role?

Internal audit can evaluate whether the control framework is designed appropriately and operated during the reporting period. It can test samples, observe reconciliations, inspect access logs and track remediation. It should not prepare the data it later audits, make management’s legal representation, or present its work as the authority’s verification.

Which cybersecurity controls support MRV?

Use role-based access and least privilege, multi-factor authentication, immutable change and approval logs, encryption and secure transfer, tested backups and recovery, incident response and legal hold. These are implementation safeguards for the integrity and availability of retained evidence, not detailed controls prescribed by the Decree-Law.

Sources

Primary sources

Take it with you

The checklists as a working spreadsheet

Every checklist and table on this page, with empty status, owner and evidence columns for your team to fill in and keep.

Download .xlsx

✓ LRA AI Assistant · Human-in-the-loop

Ask about this guide

It answers from this page, and reaches into the linked disclosure cards when your question is about the standard itself. Your first two answers are free without signing in.

Try
2 free answers Automated · the LRA team is one click away

Go deeper · UAE FDL 11 / 2024

UAE Climate Law training

Obligations under Federal Decree-Law 11 of 2024, from inventory to the reduction plan.

Available as Guided Flex, Live Cohort, 1:1 Expert Mentorship or Corporate Programme.

See course formats
/en/knowledge-hub/disclosure-guides/uae/uae-ghg-inventory/internal-controls-for-uae-mrv-source-completeness-reconciliations-fact/