Home/ Review Process/ Regulatory Context
Regulatory context

Regulation is becoming a data-evidence problem.

A regulatory position increasingly depends on information generated by other organisations, at other times, for other purposes. That changes what a file has to be able to show.

ReferenceWEETRA Regulatory Series N°001
Current applicationCBAM
ExtensionDPP · EUDR · research

Compliance increasingly depends on data the declarant did not generate

The organisation that files a regulatory declaration is often not the organisation that produced the information behind it. A regulatory position may rest on information generated by

  • Suppliers
  • Producers
  • Installations
  • Logistics actors
  • Certification or assurance systems where relevant
  • Commercial systems
  • Regulatory registries
  • Other organisations in the value chain.
How can a later reviewer reconstruct why a particular regulatory value was relied upon?

From documents to regulatory-data chains

Collecting documents was, for a long time, a sufficient description of compliance work. It is becoming less sufficient, not because documents matter less, but because the regulatory question has moved.

The question is increasingly about relationships between things a document mentions rather than about the document itself. Stated as a progression, the material passes through several states before it reaches a regulatory use

Documents remain important evidence carriers. What has changed is that the data and relationships represented across those documents increasingly need to be connected, validated within scope, and reconstructed later.

Six structural pressures

These pressures recur across regulatory-data regimes, though not every regime applies each of them identically or to the same degree.

01

Multi-organisation data

The organisation making the regulatory declaration often depends on data generated elsewhere, by parties it does not control.

02

Granularity

A regulatory value may need to relate to a specific product, installation, batch, period or supplier rather than only to an annual corporate total.

03

Provenance

The existence of a value does not establish where it came from, or whether the source is capable of supporting the use being made of it.

04

Versioning

Supplier files, methodologies, calculations and declarations can change. A later reviewer needs to know which state was relied upon.

05

Assurance and verification interfaces

Independent verification or assurance may apply to parts of the information chain without removing the need to connect that information to the final regulatory position.

06

Ex-post reconstructibility

The file may need to be understood months or years after the underlying information was first assembled, by someone who was not there.

The declared value is only the end of the chain

Depending on the regime, a regulatory system may ultimately require a value such as embedded emissions, a product characteristic, origin-related information, due-diligence information, identifier-linked product data or carbon-price information.

Whatever the field, it is the endpoint. Behind it may sit a sequence that had to hold

The final value may be simple.

The evidentiary history behind it may not be.

Identifiers and relationships

When data crosses organisational boundaries, a reviewer needs to know what each piece of information actually refers to. That is less trivial than it sounds. The same number can be correct for one object and meaningless for another.

Depending on the regime, the relationships at stake may involve

  • Product
  • Batch or item
  • Supplier
  • Operator
  • Installation
  • Facility
  • Shipment
  • Declaration
  • Reporting period
  • Evidence object
  • Registry record.

A data value detached from the object and the period it describes can become difficult to use reliably, even when the value itself is accurate. What is at stake is not the arithmetic but the reference.

Data presence is not evidentiary sufficiency

A field can be complete while the evidence behind it remains weak. A file may contain

  • A number with no clear provenance
  • A source that establishes one fact but not another
  • Competing values for the same regulatory fact
  • An outdated version
  • A verified dataset whose connection to the final declared object remains unclear
  • A supplier assertion without the supporting relationship the relevant claim requires.

Data completeness is not evidentiary sufficiency.

A complete field can still rest on nothing in particular.

Explore the Review Approach

CBAM, the current operational application

CBAM is the current operational application of the WEETRA review approach, and it illustrates the broader problem concretely rather than theoretically.

A CBAM position can depend on relationships involving

  • Imported goods
  • Producer
  • Installation
  • Reporting period
  • Embedded-emissions information
  • Precursors where relevant
  • Verification documentation where applicable
  • Carbon-price evidence where relevant
  • The documentary records tying those elements together.

That density is the point. CBAM is a working example of regulatory-data evidence moving through multiple organisations and documentary layers before it reaches a single declared field.

Explore CBAM

Research and future extension

The same evidentiary questions appear in other regulatory-data systems. The institute studies them as review extension. None of the following is an operational Determination service.

DPP

Digital Product Passport

Raises review questions around product identity, model, batch and item relationships where applicable, persistent links between data and product, provenance, access and update relationships, versioning, and responsibility for data supplied by multiple actors.

EUDR

EUDR evidence chains

Raises questions around supplier and source relationships, origin and provenance, geospatial or source-linked information where applicable, due-diligence evidence, data moving through multiple actors, and later reconstructibility.

OTHER

Other regulatory-data systems

The same evidentiary questions may arise wherever a final regulatory position depends on information generated across an upstream chain. Traceability, product information, sustainability data, customs-related evidence, assurance, provenance and supplier declarations.

Current operational application: CBAM. DPP and EUDR are maintained as research and planned review extensions for future controlled deployment.

Why auditability matters

A regulatory file is not only used at the moment it is prepared. Its working life is longer than the moment of filing, and usually less controlled.

The same file may later be

  • Reviewed internally
  • Examined by an adviser
  • Independently verified where applicable
  • Challenged
  • Corrected
  • Resubmitted
  • Examined by an authority
  • Compared against a later version.

Each of those readings asks a version of the same question. The ability to reconstruct

  • What was known
  • What was relied upon
  • Which version
  • Which source
  • Which limitations
  • Which remediation
  • Which reviewed state

Explore Documented Evidentiary Due Diligence

Where WEETRA fits

WEETRA develops review standards for the evidentiary layer of regulatory data. Its concern is the space between raw document collection and the final regulatory position.

That space includes

  • Evidence structuring
  • Provenance
  • Fact relationships
  • Contradictions
  • Source limitations
  • Professional judgement
  • Reconstructibility
  • Controlled Determination.

Explore the Institute

Current application and review extension

The distinction matters and is stated plainly rather than left to inference.

Current operational application

Where the review approach is applied today to defined evidentiary files, under a mandate, with agreed Review Levels and a bounded Determination.

  • CBAM.

Research and future extension

Where the same evidentiary principles are being studied, without an operational Determination service.

  • Digital Product Passport requirements
  • EUDR evidence chains
  • EU Customs Reform
  • Other regulatory-data and traceability regimes.
Institutional boundary

WEETRA’s Determination complements these roles by documenting what the reviewed evidence supports within the agreed mandate. Accredited verification, where required, remains the independent statutory function of the verifier. Mandate & Responsibilities

Let's get to work

Prepare the evidence before the data is challenged.