Security a bank can grade for itself.
A disclosure carries someone's signature, so the system behind it has to stand up to procurement. Here is how access, approval and evidence are controlled — laid out plainly for your own security team to assess, without badges we haven't earned.
The controls procurement will ask about.
Role-based access control
People see and do only what their role allows. Who can enter, who can approve and who can only read are separate permissions, set per workspace.
MFA & SSO
Multi-factor authentication on sign-in, and single sign-on so access follows your existing identity provider and joiner-mover-leaver process.
Immutable audit log
Every material action is recorded — who entered a figure, who approved it, what changed and when. The log is append-only, so the history can't be quietly rewritten.
Traceable to source
Each number ties back to the document it came from, the emission factor applied and the person who signed it off — the full chain, reviewable on demand.
Tenant isolation
Each organisation's data is kept in its own isolated tenant. One customer's records are never visible to another.
Data residency
Where your data lives matters to a GCC regulator, so residency is scoped with you at onboarding rather than assumed — raise your jurisdiction's requirements and we'll walk through them.
Approval and evidence, enforced by the system — not by convention.
Defensibility isn't a policy document; it's built into how a record moves. Nothing reaches a report without passing through it.
- Step 1
Entered
A maker creates the record under a named identity.
- Step 2
Submitted
Sent for review — the maker can't approve their own work.
- Step 3
Reviewed
A checker verifies the figure and its source document.
- Step 4
Approved & locked
The record locks, naming its approver. Nothing else changes it.
Standards: support, not a certificate.
Susmatic ESG helps your teams report against GRI, ISSB/IFRS S1 & S2 and CBB guidelines, and appends a framework index to reports. That is support for your reporting — it is not a certification, not a compliance guarantee, and not a substitute for your own auditor's opinion.
The evidence an auditor asks for, already in place.
Access, approvals and an immutable audit trail aren't a policy you promise — they're how a record moves, so a review finds the chain intact.
Hand this to your security team.
Book a demo and we'll walk your security and procurement reviewers through access, approvals and the audit trail — with your questions in hand.