Data Integrity and Trust

If the third act of sustainability data is trust, this module is where trust is earned or lost. It treats the integrity of an ESG number as a business question, not a technical one: whether a figure is accurate, complete, consistent and unaltered, and whether anyone can prove it. It shows how bad data, not bad intent, produces false claims that carry real legal and reputational cost, then walks through the everyday controls that let a leader stand behind a figure under audit, investor scrutiny and the EU's Green Claims regime. Security appears throughout, framed plainly as the discipline of keeping numbers honest and provable.

  • data-integrity
  • tamper-evidence
  • attestation
  • greenwashing-risk
  • audit-trail
  • internal-controls
12 min · Core

What Integrity Means for ESG Numbers

Integrity is a plain idea with four parts: a figure is accurate, complete, consistent, and unaltered since it was approved. When all four hold, a number can be trusted; when one fails, the whole figure is suspect. This lesson builds the shared definition the rest of the module depends on and explains why integrity, not effort or good intentions, is the true foundation of trust.

~4 min

By the end you can

  • Define data integrity through its four parts: accuracy, completeness, consistency and being unaltered.
  • Explain why a single failing part makes a whole figure suspect.
  • Distinguish integrity from good intentions and hard work.
  • Explain why integrity is the foundation on which trust in a number rests.

Integrity in plain terms

When an auditor or an investor asks whether they can trust a sustainability figure, they are really asking about its integrity. That word has a precise, practical meaning built from four parts. A figure has integrity when it is accurate (it reflects what actually happened), complete (nothing that should be counted has been left out), consistent (it is calculated the same way across sites and across years, so like is compared with like), and unaltered (no one has quietly changed it since it was approved). Hold all four and the number can be believed. Miss one and the number is in doubt, however sincere the team behind it.

Why one weak link breaks the chain

These four parts are not a menu to pick from; they work together. Imagine an emissions figure that is accurate, complete and consistent, but that someone edited after sign-off without telling anyone. It is now unreliable, because you can no longer be sure the published number is the approved one. Or picture a figure that is unaltered and consistent but missing three of a firm's ten factories. Its completeness has failed, so the total is simply wrong. A single failing part contaminates the whole figure. This is why leaders should treat integrity as a property of the number as a whole, not a box-ticking checklist where three out of four is a pass.

Integrity is not the same as good intentions

A common and costly assumption is that a hard-working, well-meaning team automatically produces figures with integrity. It does not. A team can spend weeks gathering data in good faith and still publish a number that is incomplete because a supplier's data never arrived, or inconsistent because two regions measured the same thing differently. Integrity is about the properties of the data and the process, not the sincerity of the people. This distinction matters because it points to the fix: better systems and controls, not merely more effort or more goodwill.

Why integrity is the foundation of trust

Everything else in this module rests on this idea. Tamper-evidenceA property whereby any change to a figure leaves a visible, undeniable mark, so no alteration can be made silently. It differs from preventing all change, since legitimate corrections still occur., audit trails, attestation and controls are all techniques for protecting and proving the four parts of integrity. Trust is the outcome; integrity is the foundation beneath it. A bank lending against a firm's carbon figures, an auditor giving an opinion, a regulator testing a green claim, all of them are, in the end, testing integrity. Consider a company that states a fifteen per cent cut in emissions. If the figure is accurate, complete, consistent and provably unchanged since approval, the claim stands. If any part is shaky, the claim is a liability waiting to surface. Get integrity right and trust follows; neglect it and no amount of polish will save the number.

A single failing part contaminates the whole figure, however sincere the team.
A single failing part contaminates the whole figure, however sincere the team.

Check your understanding

Answer each from memory. Your results are saved in this browser and count toward your readiness — sign in (account panel above) to keep them across devices.

  1. Which set best describes the four parts of data integrity for an ESG number?

  2. An emissions figure is accurate, complete and consistent, but was edited after sign-off without record. What is true of its integrity?

  3. Why can a sincere, hard-working team still publish a number that lacks integrity?

13 min · Core

Greenwashing by Accident

The word greenwashing suggests deliberate deception, but most of the risk sits elsewhere. Honest firms make false claims because their data is wrong, incomplete or inconsistent. Under the EU's tightening rules on green claims, intent offers little protection: a claim you cannot substantiate is a problem whether or not you meant to mislead. This lesson shows how bad data, not bad faith, becomes real legal and reputational exposure.

~4 min

By the end you can

  • Explain how a false green claim can arise from bad data rather than bad intent.
  • Describe why the EU Green Claims regime focuses on substantiation, not motive.
  • Connect weak data integrity to concrete legal and reputational risk.
  • Recognise substantiation as the practical defence against accidental greenwashing.

The accidental version is the common one

GreenwashingMaking an environmental claim that is false or unsubstantiated. Most risk is accidental, arising from bad data rather than deliberate deception, yet it carries the same exposure. calls to mind a firm knowingly dressing up a dirty product as clean. That deliberate kind exists, but it is not where most companies get caught. The larger danger is greenwashing by accident: an honest business makes a claim it genuinely believes, and the claim turns out to be false because the data underneath it was wrong. A retailer announces its packaging is now thirty per cent recycled, using a supplier figure that was never checked. The real number is twelve per cent. No one lied, yet the public statement is false, and the firm now carries the same exposure as if it had.

How bad data produces a false claim

Trace the path and it is always the four parts of integrity failing. A claim can be false because the data was inaccurate at source, because it was incomplete and left out an inconvenient site or supplier, or because it was inconsistent, mixing two methods so this year is not comparable with last. A carbon-neutral claim built on a footprint that quietly omits value-chain emissions is not a lie told by a person; it is a lie told by a gap in the data. The firm believes its own number because it cannot see the flaw. This is why integrity is a commercial safeguard, not a technical nicety.

Why intent will not save you

The EU is closing the door on the it was an honest mistake defence. Under the developing Green Claims regime and the related rules against misleading environmental marketing, the burden shifts to the company to substantiate a claim with clear evidence before making it. Regulators are asking a simple question: can you prove it? If you cannot, the claim is treated as misleading, and your good intentions are largely beside the point. This is a deliberate design choice, because a consumer misled by an accident is misled just the same. For a leader, it means the old comfort of we meant well is gone.

Real cost, not hypothetical

The consequences are concrete. Regulators can order claims withdrawn, impose fines, and require public correction. Competitors and consumer groups bring complaints. Investors who relied on the figure feel deceived even when no deception was intended, and the reputational damage of a headline about a false green claim lands whether the error was malicious or careless. A firm can lose a hard-won contract because a customer's own auditors cannot verify the sustainability figures it was given. The uncomfortable implication is that weak data integrity is not merely a reporting inconvenience; it is a direct route to legal and reputational harm. SubstantiationBacking a claim with clear, sound, traceable evidence so it can be proved. Under EU rules a claim that cannot be substantiated is treated as misleading., the ability to back every claim with traceable, sound data, is the only real defence, and it is exactly what the rest of this module builds.

Under the EU Green Claims regime intent offers little protection; only substantiation does.
Under the EU Green Claims regime intent offers little protection; only substantiation does.

Check your understanding

Answer each from memory. Your results are saved in this browser and count toward your readiness — sign in (account panel above) to keep them across devices.

  1. What is greenwashing by accident?

  2. Under the EU Green Claims regime, why does honest intent offer little protection?

  3. Which is a concrete consequence a firm can face for an unsubstantiated green claim?

13 min · Core

Tamper-Evidence and Audit Trails

Trust does not come from promising a number was never changed; it comes from being able to show what changed, when, and by whom. This lesson introduces two plain ideas: tamper-evidence, so that any change to a figure leaves a visible mark, and the audit trail, the who-changed-what-and-when record that makes a number's whole life visible. Together they turn an unprovable assurance into demonstrable fact.

~4 min

By the end you can

  • Explain what tamper-evidence means and why it differs from preventing all change.
  • Describe what an audit trail records and why it matters.
  • Explain how visible change history makes a figure defensible under audit.
  • Distinguish a promise that data is unchanged from proof that it is.

Show, do not just say

Ask most firms whether their published emissions figure was altered after approval and the answer is a confident no. Ask them to prove it and the confidence evaporates. That gap between saying and showing is the whole problem this lesson addresses. Trust in a number does not come from an assurance that it was never touched. It comes from being able to demonstrate exactly what happened to it. Two ideas make that possible, and neither requires deep technical knowledge to understand.

Tamper-evidenceA property whereby any change to a figure leaves a visible, undeniable mark, so no alteration can be made silently. It differs from preventing all change, since legitimate corrections still occur.: change leaves a mark

The first idea is tamper-evidence. A figure is tamper-evident when any change to it leaves a visible, undeniable mark, so that no one can quietly alter it without the alteration being seen. This is different from making data impossible to change, which is rarely practical or even desirable, because legitimate corrections happen. The point is not to lock the number in a vault; it is to make sure a change can never be silent. A useful analogy is the tamper-evident seal on a medicine bottle. The seal does not stop you opening the bottle; it makes it impossible to open without leaving proof. Applied to data, tamper-evidence means an unrecorded change is simply not possible.

The audit trail: who, what, when

The second idea is the audit trail, sometimes called an audit log. It is a running record of every meaningful action taken on a figure: who entered it, who changed it, from what value to what value, and at what time. Where tamper-evidence guarantees a change cannot hide, the audit trail is the readable story of every change that legitimately occurred. Picture a single emissions number that was entered by an analyst in March, corrected upward in April when a supplier sent revised data, and approved by the finance director in May. A good audit trail shows all three steps with names and timestamps. Nothing about the number's life is hidden.

Why this is what an auditor wants

Put the two together and a figure becomes defensible. When an external auditor examines a sustainability report, the reassuring answer to how do we know this figure is right is not a verbal promise but the ability to open its history and walk through it. The auditor sees the original entry, the reason for each change, and the sign-off, all timestamped and attributable. A firm that can do this passes scrutiny quickly and cheaply. A firm that cannot faces the auditor's hardest questions and, often, a qualified opinion. The deeper shift is from trust me to see for yourself. In an assured, legally exposed world, only the second one holds, and making changes visible is how an honest number proves it is honest.

Defensibility comes from demonstrable change history, not an unprovable assurance.
Defensibility comes from demonstrable change history, not an unprovable assurance.

Check your understanding

Answer each from memory. Your results are saved in this browser and count toward your readiness — sign in (account panel above) to keep them across devices.

  1. What does it mean for a figure to be tamper-evident?

  2. What does an audit trail record about a sustainability figure?

  3. Why does visible change history make a figure defensible under audit?

12 min · Core

Attestation and Signing

Once a number is trustworthy, the next problem is letting others rely on it without re-checking everything themselves. Attestation is a named party formally standing behind a figure; signing is the tamper-evident mark that ties that person to that exact number at that moment. This lesson explains both as everyday business concepts, not cryptography, and shows how they let trust travel downstream to auditors and investors.

~4 min

By the end you can

  • Define attestation as a named party formally standing behind a figure.
  • Explain what signing adds: binding a specific person to a specific number.
  • Describe how attestation lets downstream users rely on data without re-checking it.
  • Recognise attestation and signing as trust-transfer, not deep cryptography.

The problem attestation solves

Suppose your data now has integrity, and its history is tamper-evident and fully logged. A new question appears: how does an outsider rely on your number without repeating all your work? An investor cannot re-audit every figure in every report they read, and a customer cannot re-measure a supplier's emissions. What they need is someone credible to attest to the figure, to formally state I stand behind this number. AttestationThe act of a named, accountable party formally standing behind a figure so that others can rely on it without repeating all the checking themselves. is the act of a named, accountable party vouching for a figure so that others can rely on it. It converts a number that is merely correct into a number someone has staked their name on.

What signing adds

Attestation needs a mechanism, and that mechanism is signing. To sign a figure is to attach a mark that binds a specific person to a specific number at a specific moment, in a way that cannot be quietly forged or moved to a different number later. In the paper world this was a signature on a report; in a modern data system it is a digital equivalent that ties the sign-off to the exact figure that was approved. The important part for a business leader is not the mathematics underneath but what it guarantees: if the number changes after signing, the signature no longer matches, and the mismatch is visible. SigningAttaching a mark that binds a specific person to a specific figure at a specific moment. If the figure changes after signing, the signature no longer matches and the mismatch is visible. is how an attestation stays honest.

How trust travels downstream

Together, attestation and signing let trust move. Consider the chain a sustainability figure travels. An analyst produces it, a manager reviews it, the finance director attests and signs it, the external auditor relies on that signed figure, and finally an investor relies on the auditor's opinion. At each link, one party trusts the signed work of the one before instead of redoing it. This is why signed, attested data is so valuable: it lets a whole chain of people depend on a number efficiently. Without it, every reader would have to re-verify everything, which is impossible at scale, so in practice they would either trust blindly or not trust at all.

Not cryptography, but accountability

It helps to strip away the mystique. The deep cryptography that makes digital signing work is real, but a leader does not need it to make good decisions here. The idea that matters is accountability: a named person has put their name to this exact figure, and any later change to the figure breaks the link and shows. A supplier who signs the emissions data it sends you is doing something a leader should insist on, because it means that if the figure is later found wrong, there is a clear, accountable origin rather than a shrug. Attestation and signing are, at heart, the machinery that lets a business say who is answerable for a number and prove it has not changed since they answered for it.

Signed, attested data lets a whole chain depend on a number without redoing the work.
Signed, attested data lets a whole chain depend on a number without redoing the work.

Check your understanding

Answer each from memory. Your results are saved in this browser and count toward your readiness — sign in (account panel above) to keep them across devices.

  1. What is attestation of an ESG figure?

  2. What does signing a figure add beyond a verbal assurance?

  3. How does a signed, attested figure help an investor who cannot re-audit everything?

13 min · Core

Controls That Make a Number Defensible

This lesson pulls the module together into a practical minimum. Four everyday controls, validation, approval, versioning and sign-off, are what let a leader stand behind a figure. None is exotic; each is familiar from how finance already handles money. Applied to sustainability data, they turn a fragile number into a defensible one and give every function a shared checklist for what good looks like.

~4 min

By the end you can

  • Name the minimum set of controls that make a sustainability figure defensible.
  • Explain what each control does and the failure it prevents.
  • Relate these controls to the integrity, tamper-evidence and attestation ideas already covered.
  • Explain why these controls let a leader stand behind a number under scrutiny.

Defensibility is built, not declared

A defensible number is one a leader can stand behind when an auditor, investor or regulator pushes back. Defensibility is not a quality you announce; it is the product of a few ordinary controls applied consistently. The good news is that finance has used these controls on money for generations, so none of them is new or exotic. The task is to apply the same discipline to sustainability data. Four controls form the practical minimum, and together they protect the integrity, tamper-evidence and attestation the earlier lessons described.

The four controls

The first is validation: checking data as it enters, so obvious errors are caught early. If a factory reports energy use ten times last year's figure, validation flags it before it poisons the total, protecting accuracy and completeness. The second is approval: a figure moves forward only when a responsible person has reviewed and accepted it, so numbers are not published simply because they exist. The third is versioning: every version of a figure is kept, so you can see what the number was before and after each change, which is the tamper-evidence and audit-trail idea made routine. The fourth is sign-off: a named person formally attests to the final figure, the attestation and signing from the previous lesson, so accountability is fixed. Validation guards the way in, approval guards the way forward, versioning guards the history, and sign-off guards accountability.

How the controls reinforce each other

These four are not independent chores; they compose into a single defensible pipeline. Validation gives you accurate inputs; approval ensures a human judged them sound; versioning preserves the trail of every change; sign-off puts a named party behind the result. Remove any one and a familiar failure returns. Without validation, a wild figure slips through. Without approval, unreviewed numbers reach the report. Without versioning, no one can prove what changed. Without sign-off, no one is accountable when a figure is questioned. Consider a supplier emissions figure that passes validation, is approved by a manager, has every revision versioned, and is signed by the finance director: that number can be defended line by line. The same figure with none of these controls is just an assertion.

The shared checklist

The lasting value of naming these four is that they give every function the same picture of what good looks like. The sustainability lead knows a figure is not done until it is validated, approved, versioned and signed. Finance recognises its own language of controls. IT knows exactly which capabilities the system must support. Procurement knows to ask suppliers for data that can pass validation and be signed. This is the shared vocabulary the course promised, made concrete. A number carried through these four controls is not merely present; it is defensible, and defensibility is what the assured, investor-grade, legally exposed world now demands. Master this and a leader can look an auditor in the eye and say, with evidence, we stand behind this figure.

Remove any one control and a familiar failure returns.
Remove any one control and a familiar failure returns.

Check your understanding

Answer each from memory. Your results are saved in this browser and count toward your readiness — sign in (account panel above) to keep them across devices.

  1. Which four controls form the practical minimum for a defensible sustainability figure?

  2. What failure does versioning specifically prevent?

  3. How do these four controls connect to the earlier ideas in the module?

Flashcards

Recall-first review of the load-bearing facts.

0 reviewed · 8 left

Ready to test yourself?

12 graded questions with real explanations. You commit a confidence before each reveal — that is how you find what you only think you know.

Start practice quiz →
Data Integrity and Trust — Sustainability Data as Infrastructure | Contested Futures Academy · The Contested Futures Institute