Verification Readiness & Engagements
Run a verification round as a managed engagement: freeze the data set with a SHA-256 hash, invite the verifier, resolve findings and issue the statement.
Request a demoThird-party verification is where an inventory is tested against ISO 14064-3 and the TGO guideline. CarbonBiz treats it as a structured process rather than a folder of spreadsheets. Each activity carries a verification status that moves from unverified through under review to verified or rejected, separate from its ISO 14064-3 assurance level (internal review, third-party limited or third-party reasonable). Editing a verified activity's amount or factor automatically returns it to unverified, and every transition is written to the audit log.
An engagement bundles one verification round: organization, reporting year, scope and target assurance level. A readiness gate checks that the scope has data, that internal review is at least 80 percent complete and that every Scope 1 activity has evidence attached before submission is allowed. On submission the App freezes the data set as a snapshot with a SHA-256 hash and an attachment manifest, and soft-locks the activities so they cannot change while under review. Once the round concludes as verified, the data is hard-locked permanently.
External verifiers are invited by email with a single-use link and receive a read-only account scoped to that engagement only. They raise findings classified as non-conformity, clarification request or observation, each tied to a clause and severity with an append-only response thread; approval is blocked while material non-conformities remain open. Because the verifier drives the review, the organization cannot approve its own round. The signed verification statement is uploaded to close the engagement, and the verified activities are stamped with the resulting assurance level. An IMP data-room export bundles evidence, factor traceability and audit trail for the verifier, and immutable audit logs record every create, update, delete, import and export across the App.
What you can do
- Verification state machine per activity, separate from ISO 14064-3 assurance level
- Engagement with readiness gate, snapshot and SHA-256 hash, soft-lock then permanent hard-lock
- External verifier invitation with single-use link and engagement-scoped read-only account
- Findings (NCR / CL / OBS) with clause, severity and append-only thread
- Verification statement upload, assurance stamp, IMP data-room export and immutable audit log
Standards referenced
- ISO-14064-3 · ISO 14064-3:2019 (opens in a new tab)
- ISO-14064-1 · ISO 14064-1:2018 (opens in a new tab)
- TGO-CFO-04 · TGO CFO Requirements, Version 04