Articles & Analysis

You Don’t Edit the Books During a Financial Audit. Now Your Carbon Model Can’t Be Edited Either.

CarbonSig

You don't edit the books during a financial audit. Now your carbon model can't be edited either — Registered Flow by CarbonSig

Until this release, a carbon model in CarbonSig stayed editable. You could refine inputs while a verifier was reviewing the same numbers. That’s fine during modeling. It is a liability the moment a verifier, customer, or regulator opens the file.1

Registered Flow draws the line. When your model is ready, you register it — and the data freezes into an immutable, hash-stamped snapshot. From that point, the only paths forward are Self Attested (you stand behind the numbers), Pending Verification (a third-party reviews the locked record), or Verified (the verifier signs off). No one can edit the books while the auditor is reviewing them. Carbon data now follows the same rule.

What Registered Flow does

Registration introduces a clear separation between modeling and verification. When you register a model, three things happen at once:

  • Locks the snapshot. The model becomes a hash-stamped immutable record. Inputs, allocations, emission factors, methodology — all frozen.
  • Unlocks the lifecycle. Only registered models can enter the verification workflow or have a Carbon Receipt (CAP) issued against them.
  • Backs the receipt. A CAP from a registered model carries an audit-grade record back to the underlying activity data, traceable to the moment of registration.

“You would not let someone edit the books during a financial audit. Carbon data deserves the same discipline.”

Audit-control parity: finance has had Drafted, Locked, Reviewed, Signed since 1934 (5/5 controls). Carbon, until Registered Flow, sat at 2/5. Registered Flow brings change control, version freeze, and attestation chain to carbon.
Five states, one gate. Modeling is the only state where the data is editable. Registration is the gate that locks the snapshot and opens the verification lifecycle.

The lifecycle

Once registered, the model enters a defined lifecycle:

  • Self Attested — the default state after registration. You can issue a Carbon Receipt (CAP) immediately, or request third-party verification.
  • Pending Verification — you have requested third-party verification. The locked record is what the verifier reviews.
  • Verified — the verifier has issued an opinion. The CAP from this point forward carries the verifier’s signature alongside the registration hash.

All verification actions now live in the Registered tab. The previous verification controls inside Outputs have been removed. One place for everything verification-related.

Same audit lifecycle, different domain: Drafted to Locked to Reviewed to Signed. Finance has had 5/5 controls since 1934; carbon, until Registered Flow, was at 2/5.

Why this matters

Carbon data that can change after submission is a liability. Registered Flow makes your data audit-ready by default. When a verifier, a customer, or a regulator looks at your carbon numbers, they see exactly what you intended to submit — frozen in time, traceable, and tamper-proof.

This is the foundation for scalable verification. Not just for today’s compliance requirements (CBAM, CSRD, the upcoming UK CBAM in January 2027), but for the verifier roles, third-party engagements, and multi-party review workflows coming next in the Victory Arc.

Sources & method: Audit-discipline parallel mirrors SOX 404, ISAE 3410 assurance over GHG statements, COSO 2013, ISO 14067, and GHG Protocol Product Standard. Hash-stamping uses SHA-256 fingerprint of the registered model state, verifiable internally. Third-party verifiers must be accredited under ISO 14065 or recognised under the EU CBAM verifier framework (Implementing Regulation (EU) 2023/1773).

Articles & Analysis

Keep reading

More from CarbonSig.

All resources

Ready to put a number behind the argument?

Bring a product and how you make it. We will model it with you and show you what a third-party verifier would ask for.