consust blog: Decentralized Data Collection and Consolidation

Published:

Last updated:

Reading time:

7–11 minutes

Decentralized Data Collection and Consolidation: How to Turn 40 Companies Into a Verifiable Figure

The effort involved in sustainability reporting does not arise where most companies expect it to. It is not the writing that takes time, but rather the process of gathering data from plants, subsidiaries, the HR department, and procurement to arrive at the consolidated group figure. It is along this path that errors arise, which are later flagged during the audit. This article describes what information each figure must include, the role that approvals and internal controls play, and what auditors actually look for.

As of September 2026. The information refers to the revised European Sustainability Reporting Standards (ESRS) set forth in the delegated act of July 3, 2026. The objection period for the Parliament and the Council expired on September 3, 2026, with no objections raised; the content of the standards is therefore finalized. Publication in the Official Journal and entry into force are still pending; until then, Delegated Regulation (EU) 2023/2772 remains in effect. Our overview of the CSRD reporting process shows where data collection stands in the overall process.

The ESRS do not specify a survey organization, but require traceability

There are no specific requirements regarding how you must collect data. However, you are required to disclose how you do it. In the ESRS Set (2026), the GOV-4 disclosure in ESRS 2 requires the following information: the scope, key characteristics, and components of the risk management and control processes for reporting.

The related application requirement specifies what this entails: the completeness and integrity of the data, as well as the accuracy of the estimates, must be considered as risks in the reporting process. In addition, there is a qualitative requirement from the appendix to ESRS 1: Accuracy requires that the company has established appropriate processes and internal controls to prevent material errors.

The scope of consolidation serves as the frame of reference for each individual survey

The sustainability statement follows the scope of consolidation used in the consolidated financial statements. In an analysis by DRSC and Deloitte of 77 reports from German index-listed companies for the 2024 fiscal year, 94% of the reports were consistent with this approach. The remaining 6% provided reasons for the discrepancy, such as subsidiaries that are not operational, a sale during the fiscal year, or the inclusion of companies that are financially immaterial but have a significant impact.

This has three implications for the data collection process: The list of entities included is determined before the first data request. Any deviation from the scope of the consolidated financial statements is justified and documented. And a rule must be established for additions and disposals during the year before the data is collected, not afterward.

Auditors examine this specifically. The guidelines issued by the Committee of European Auditing Oversight Bodies on September 30, 2024, explicitly address the question of whether the materiality analysis covers all consolidated entities.

Six pieces of information for each value determine whether it can be verified later

A number without context is worthless in reporting because no one can judge whether it meets the requirement. That is why six pieces of information must be included with each value at the time of data entry, not added later:

  • Definition — what exactly is being measured, as defined in the standard.
  • Unit — including the conversion factor, if the supplying unit uses a different measurement system.
  • Consolidation scope — the companies and locations to which the value applies.
  • Reporting Period — Reporting Date or Period, with a rule for non-standard fiscal years.
  • Source — The system, document, or process from which the value is derived.
  • Person in charge — by name, not as a department.

The revised standards require precisely this. The general disclosure requirement for metrics mandates that, for each metric, the calculation method and the sources used be disclosed; in the case of estimates, the estimation method, along with key assumptions and limitations, must also be disclosed. For metrics from the value chain, the following must also be disclosed: the use of indirect sources or approximate values, and the planned measures to improve data quality.

Ensure data quality during data entry, not afterward. The appendix to ESRS 1 requires that estimates, approximations, and forecasts be clearly identifiable as such. Primary data, secondary data, and estimated values must therefore be distinguishable during the data collection phase. This cannot be reconstructed retroactively, and the audit specifically addresses this point.

Secondary data is expressly permitted. For value chain information, the ESRS allow estimates based on indirect sources, sector averages, samples, market and peer group data, or expenditure-based methods. This flexibility comes at a cost: it must be disclosed.

Approvals and the dual-control principle are not required, but they are the most effective tool

Neither the ESRS nor the CEAOB guidelines nor the German Commercial Code recognize the “four-eyes principle” as a term or prescribe a specific approval process. It is a matter of policy, not a requirement. In projects, however, it is still the measure with the best cost-benefit ratio because it catches the most common type of error: the plausible-looking incorrect value.

The professional framework for this is in place. The COSO Supplement on Sustainability Reporting dated March 30, 2023, applies the five components and 17 principles of the COSO framework to sustainability reporting. In Practice Guidance 4/2023, the Institute of Public Auditors has applied the principles for auditing the internal control system to the control system for preparing the sustainability report, structured according to the COSO components, including control activities.

An approval process that has proven effective in practice consists of four steps:

To be recorded by the person with the relevant expertise. The person who operates the facility or maintains the headcount records enters the value.

Technical approval by the supplying unit. A second person from the same unit confirms the plausibility and scope. This is the actual check, because that’s where the expertise lies.

Central consistency check. Year-over-year comparison, comparison to benchmarks, outliers. Anomalies are addressed by asking a question, not by making a correction.

Approval of the consolidated figure. It is only here that the value to be included in the report is generated.

The second reason for documented approvals stems from the qualitative requirements of the ESRS: Verifiability is achieved, among other things, by having information reviewed and approved by the management and supervisory bodies. This applies at the board level, but follows the same logic as the approval process in the chain below it.

What examiners look for—and what they definitely don’t have to look for

In a limited assurance engagement, auditors gain an understanding of the entity, its environment, and the internal control system relevant to the reporting. Test audits and functional audits are not required, but may be performed if they appear to be effective.

Two points in the guidelines are particularly relevant to decentralized data collection. First, auditors assess whether the described process matches the one actually followed. A procedural description included in the report but implemented differently in three national subsidiaries stands out precisely here. Second, auditors assess the systems you use to gather information from the value chain and evaluate their reliability. However, external confirmation of this data by your business partners is not required in every case.

Our article on auditing sustainability reporting describes in detail what this entails: The audit focuses on the source of the data, not on the text.

Collect data once for all frameworks, not once per report

The same metric is requested multiple times in many companies: for the sustainability report, for a customer survey, for a rating, for the EU taxonomy, and for the environmental statement of an EMAS site. If these requests are handled separately, differing values result for the same set of facts, and when in doubt, no one knows which one is correct.

The solution is a catalog of data points that serves as the sole basis from which individual reports are generated as analyses. Our article on the interoperability of sustainability standards describes the official mappings between the frameworks and where they end. In short: Granularity and scope can be reconciled, but different definitions cannot. That is why each value must be accompanied by the definition under which it was collected.

Context: According to PwC’s Global Sustainability Reporting Survey 2025, published on October 27, 2025, which surveyed 496 decision-makers in 40 countries—including 109 in Germany—77% of German companies use a central database, and 66% use reporting software. Fifty-two percent cite early data validation as a key success factor.

What You Should Determine Before the First Round of Data Collection

Specify the list of units included and explain any deviations. It serves as the reference point for every key figure, and changing it later will require reworking all the values.

Define each data point before you query it. The query must include a definition, unit, scope, and an example. Without these, the results will be values that cannot be compared.

Make data quality a required field. Primary data, secondary data, and estimates are options for data collection, not for the December survey.

Incorporate at least one technical approval step within the supplying unit. It catches more errors than any centralized validity check because that’s where the expertise lies.

Log every change after approval. In an audit, the first question that arises whenever a value stands out is: Who changed what, when, and for what reason?

Decentralized data collection without Excel queries, using CONSUST

The difference between a verifiable consolidated figure and one that requires explanation lies in the metadata and the approval chain, not in the number itself. Our FramesCube software manages the data collection across all companies and locations: data points with definitions, units, and scope; responsibilities and deadlines for each unit; approval levels with logs; and a consolidation process in which every conversion remains traceable. The technical assessment of a figure remains the responsibility of the relevant personnel, and the audit trail is generated as the process unfolds.

Our overview of ESG frameworks shows how the same dataset can be used for other frameworks. Contact us for a no-obligation discussion about your data collection structure.

This article presents a professional assessment based on the sources cited, as of September 2026, and is not a substitute for a legal review in individual cases.

More Articles

Scroll to Top