Maker/checker for ESG data: approvals that survive an audit
Governance5 min read
The weakest link in ESG data is often not the calculation — it's the control around it. When a figure is entered by one person and never independently checked, you're trusting a single point of judgment. Maker/checker is the control that removes that weakness, and it's one of the first things an assuror looks for.
What maker/checker actually means
Two roles, kept separate. The maker enters the record; a different checker reviews and approves it. The person who enters a figure is never the only person who stands behind it. On approval, the record locks — no more silent edits.
- The maker can't approve their own work.
- Approved records lock — any change requires a new, logged action.
- Every approved record names its approver.
Why separation of duties matters here
Segregation of duties is a basic financial control, and ESG data deserves the same. It catches the ordinary errors — a mistyped reading, the wrong factor — and it removes the “one person's word” problem. Accountability stops being implied and becomes recorded: the figure carries the names of who entered it and who signed it off.
The audit trail behind it
Approvals only count if they're recorded. An immutable audit log — who entered, who approved, what changed and when — is what turns “trust me” into “here's the evidence.” When an assuror asks whether a number was reviewed and whether it has been altered since, that log is the answer.
Where teams get it wrong
The common failure modes are quiet ones: approvals done informally over email, with no record and no lock; the same person entering and approving; or a sign-off that doesn't actually prevent later edits. If the workflow doesn't lock the record and log the approval, it's theatre — it looks like a control without being one.
What good looks like
A figure is entered under a named identity, submitted, reviewed by a second person, and approved — at which point it locks, and nothing reaches a report unreviewed. That's the standard an assuror expects, and it's the difference between a number you hope is right and one you can defend.
This is exactly how Approvals work in Susmatic ESG: maker/checker with record locking and an immutable audit log, so nothing reaches a report without a second set of eyes.