Domain D · Area D-CA2 · Delivery governance, coordination and quality improvement
D.7Define and manage the scope of work for external advisers and service providers
Working Draft version 1.1
Purpose and scope
This unit covers the capability to define, procure, onboard, monitor, challenge and integrate work from external advisers, subject-matter specialists, data and ratings providers, translators, designers, software vendors and other service providers used in sustainability reporting. It includes scope, competence, conflicts, confidentiality, data access, intellectual property, acceptance criteria, change control, review, ownership and service boundaries.
Applied competency statement
Can scope and manage external reporting contributors through clear terms, competence and conflict checks, controlled access, deliverable acceptance criteria, review and integration while preserving management accountability and assurance boundaries.
Boundary and escalation
This unit manages third-party work and does not validate specialist conclusions beyond the practitioner's competence. B.8 owns specialist-evidence integration; F.9 owns the preparation-versus-assurance boundary; procurement, contract, data-protection, cyber-security, intellectual-property, legal and professional-independence conclusions require qualified review.
Key quality risks
Vague scopes or deliverables; provider selection based only on brand or price; undisclosed conflicts; consultants making management decisions; assurance providers participating in preparation beyond permitted boundaries; uncontrolled access to confidential or personal data; unlicensed use of standards or proprietary methodologies; deliverables accepted without evidence or challenge; scope creep; late dependencies; unclear intellectual-property ownership; and third-party conclusions copied into reports without integration or approval.
D.7-K01
Understands common reporting-related providers, including advisers, subject-matter experts, data and ratings providers, software vendors, assurance providers, translators, designers and publication services.
Knowledge Type: Provider and service types · Normative Weight: Core
D.7-K02
Understands reporting questions, deliverables, methods, evidence, assumptions, limitations, timetable, interfaces, acceptance criteria, change control and ownership requirements for third-party work.
Knowledge Type: Scope and acceptance · Normative Weight: Core
D.7-K03
Understands competence, experience, sector and jurisdiction knowledge, capacity, quality history, references, methodology transparency and the limits of credentials or brand reputation.
Knowledge Type: Competence and selection · Normative Weight: Core
D.7-K04
Understands actual, potential and perceived conflicts, management-participation and self-review threats, assurance independence, sponsorship, referral and commercial incentives and possible safeguards.
Knowledge Type: Conflicts and independence · Normative Weight: Core
D.7-K05
Understands confidentiality, privacy, cyber-security, system and data access, retention, cross-border transfer, intellectual property, licensing, translation and permitted-use considerations.
Knowledge Type: Information and rights · Normative Weight: Core
D.7-K06
Understands governance, progress, issue and change management, evidence review, acceptance, remediation, integration, sign-off and retention of third-party contributions.
Knowledge Type: Monitoring and integration · Normative Weight: Core
D.7-S01
Define the reporting need, service boundary, required competence, deliverables, evidence, interfaces and acceptance criteria.
Skill Type: Core applied capability · Observable Output or Result: Terms of reference
D.7-S02
Evaluate competence, capacity, method, conflicts, independence, security, licensing and commercial conditions and establish controlled onboarding.
Skill Type: Selection and onboarding · Observable Output or Result: Terms of reference, selection and onboarding pack
D.7-S03
Monitor milestones, dependencies, scope, changes, data access, assumptions and emerging quality or conflict issues.
Skill Type: Delivery monitoring · Observable Output or Result: Third-party delivery and issue tracker
D.7-S04
Challenge deliverables for completeness, methodology, evidence, limitations and response to the scope and document acceptance, return or remediation.
Skill Type: Review and acceptance · Observable Output or Result: Third-party deliverable and quality-review record
D.7-S05
Integrate accepted work into reporting processes, preserve assumptions and attribution and maintain the evidence, conflict, approval and rights record.
Skill Type: Integration and retention · Observable Output or Result: Third-party evidence, conflict and integration register
D.7-B01
Does not ignore conflicts or independence threats because a provider is commercially important, well known or already engaged.
Behaviour Type: Independence and conflict transparency · Non-compensable Requirement: No
D.7-B02
Does not allow an external provider to assume management accountability or permit internal teams to use the provider's name as a substitute for review.
Behaviour Type: Ownership discipline · Non-compensable Requirement: No
D.7-B03
Does not accept deliverables solely because they were completed on time; acceptance requires the agreed method, evidence, limitations and quality criteria.
Behaviour Type: Evidence-based acceptance · Non-compensable Requirement: No
Typical tasks · 4
D.7-T01
Define the service need, reporting question, competence, scope, deliverables, evidence, timetable, interfaces, rights and acceptance criteria.
Primary Output Link: D.7-O01
D.7-T02
Evaluate candidate competence, capacity, conflicts, independence, security, licensing and commercial conditions and complete onboarding.
Primary Output Link: D.7-O01
D.7-T03
Monitor progress, dependencies, access, assumptions, issues and changes and coordinate internal owner and specialist interfaces.
Primary Output Link: D.7-O02
D.7-T04
Review and accept, return or remediate deliverables and integrate approved work with clear ownership, limitations, evidence and retention.
Primary Output Link: D.7-O03
Expected outputs · 3
Level 1 · Foundation
D.7-L1-01
Can support an established third-party process, maintain onboarding and delivery records and check submitted deliverables against defined scope and acceptance fields.
Indicator Dimension: Task execution
D.7-L1-02
Can identify obvious scope, evidence, access, conflict or boundary issues and escalate them to the accountable owner.
Indicator Dimension: Quality, judgement and accountability
Level 2 · Practitioner
D.7-L2-01
Can independently scope, onboard, monitor and review an external contributor for a moderately complex reporting workstream.
Indicator Dimension: Task execution
D.7-L2-02
Can resolve routine scope and quality issues, document acceptance and limitations and explain conflicts, dependencies and residual risk to management.
Indicator Dimension: Quality, judgement and accountability
Level 3 · Advanced Practitioner
D.7-L3-01
Can design or critically review enterprise governance for external reporting advisers, specialists, vendors and assurance interfaces across complex programmes.
Indicator Dimension: Method design and review
D.7-L3-02
Can resolve significant competence, access, rights and quality failures, identify and escalate independence concerns, challenge provider or management overreach and advise governance bodies on remediation or replacement.
Indicator Dimension: Leadership and governance
Illustrative evidence · 6
D.7-E01
Terms of reference, selection and onboarding pack with competence, conflict, security, rights and acceptance fields.
Evidence Type: Work product
D.7-E02
Third-party deliverable and quality-review record showing scope compliance, challenge, return, remediation and acceptance.
Evidence Type: Work product
D.7-E03
Third-party evidence, conflict and integration register with assumptions, limitations, ownership and approval.
Evidence Type: Work product
D.7-E04
Selection, onboarding, access, issue, change, review and acceptance trail.
Evidence Type: Process evidence
D.7-E05
Documented procurement, legal, privacy, IT, specialist, assurance or management review and the practitioner's response.
Evidence Type: Review evidence
D.7-E06
Observed challenge and acceptance or rejection of a deficient third-party deliverable.
Evidence Type: Observed performance
Assessment · 3
D.7-A-L1
Scope-and-deliverable review, conflict scenario and situational judgement
Completeness of scope; recognition of conflicts and boundaries; deliverable quality and escalation awareness.
D.7-A-L2
Integrated provider-management case and professional memorandum
Selection and onboarding; scope and change control; evidence and access safeguards; deliverable review and integration.
D.7-A-L3
Complex independence and vendor case, portfolio and oral defence
Governance design; competence assessment; identification and escalation of independence concerns; data and IP control; remediation and replacement decisions; oral defence.
| From | To | Type | Rationale |
|---|---|---|---|
| D.7 | B.8 | Method, data and analytical linkage | External specialist evidence must be scoped, reviewed and integrated with assumptions and limitations. |
| D.7 | H.5 | Professional conduct and collaboration linkage | Provider selection and oversight require identification and management of actual, potential and perceived conflicts. |
| D.7 | F.9 | Boundary distinction | Advisory, preparation and independent assurance responsibilities must remain distinct. |
| D.7 | I.8 | Professional conduct and collaboration linkage | External tool and provider access must protect privacy, confidentiality and information security. |
| F.9 | D.7 | Governance and role linkage | External adviser and assurance-provider scopes should preserve management responsibility and service boundaries. |
| H.5 | D.7 | Governance and role linkage | External adviser and service-provider selection and oversight should consider conflicts and commercial incentives. |
| I.1 | D.7 | Digital and technology linkage | Technology providers should be scoped, assessed and monitored through controlled third-party governance. |
| I.8 | D.7 | Governance and role linkage | Vendor, connector and subcontractor data and rights risks should be managed through third-party governance. |
| Role | Target level | Relevance | Evidence expectation |
|---|---|---|---|
| Corporate Sustainability Reporting Practitioner | Foundation | Supporting? | A supervised or defined work sample showing correct application, traceability and recognition of escalation needs. |
| Sustainability Reporting Manager or Lead | Advanced Practitioner | Role-defining? | A complex case or verified portfolio, supplemented by oral or observed defence, demonstrating method design, challenge and governance capability. |
| Sustainability Reporting Adviser or Consultant | Advanced Practitioner | Role-defining? | A complex case or verified portfolio, supplemented by oral or observed defence, demonstrating method design, challenge and governance capability. |
| Sustainability Data, Systems and Controls Specialist | Practitioner | Required? | A case or work sample demonstrating independent performance, documented judgement and a reviewable professional output. |
| Assurance Readiness and Reporting Quality Specialist | Advanced Practitioner | Role-defining? | A complex case or verified portfolio, supplemented by oral or observed defence, demonstrating method design, challenge and governance capability. |
| Investor, Capital Markets and Ratings Disclosure Specialist | Practitioner | Required? | A case or work sample demonstrating independent performance, documented judgement and a reviewable professional output. |