The Compliance Gap Fixes Agent: Suggested Remediations Before the Auditor Sees the Issue
Compliance gaps are the boring, repetitive quality-control failures that end up on assurance management letters. A background agent that runs continuously against the emission ledger and proposes typed remediations closes most of them before the auditor arrives.
The findings on an ASSA 5010 management letter are almost never the exciting ones. Not a scandalous methodology choice or a philosophical debate about operational control. A REC retirement without a certificate ID. A methane emission factor stamped with an AR6 GWP when the report is a NGER submission. An orphan record that survived a business unit merger. A Scope 2 factor pulled from a superseded NGA edition six months after the workbook was updated.
Boring stuff. And that is the point. Boring stuff is what fails assurance walk-through, because the auditor's tests are designed to catch exactly the errors that are easy to miss when you are looking at 40,000 rows of ledger.
The Compliance Gap Fixes agent is a background job we built to close that class of finding at the systems layer instead of at the walk-through table. It runs continuously against the emission ledger. It matches records against typed gap patterns. It proposes a specific remediation. And it hands that remediation to a human to accept or reject.
It does not replace an external assurer. It is the internal quality-control loop that means the assurer opens the file and finds fewer things to write down.
What we mean by "compliance gap" in this context
A compliance gap is not the same thing as an anomaly. An anomaly is a data point that looks wrong: a fuel invoice ten times the site average, a period-over-period spike that has no supporting activity change, a duplicate meter read. Anomalies are described elsewhere in the five-rule anomaly detection walkthrough.
A compliance gap is a record that will not survive a specific assurance test even if the underlying number is right. The agent watches for five recurring patterns.
Missing source documents. An emission record without a linked source document fails any traceability test. The auditor asks to see the underlying utility bill, fuel docket or REC retirement certificate, and there is nothing to open. This is the single most common finding in Year 1 limited assurance engagements, and mechanical to detect.
Emission factor version drift. The record uses a NGA factor from an edition that was superseded before the reporting period closed. The number is not wrong exactly; it is just not the number the auditor will map to the current workbook. In construction and property portfolios where the same factor is applied thousands of times, one stale factor multiplies fast.
Unresolvable variance. A NGER draft and its matching AASB S2 disclosure show more than a 5% variance on the same scope for the same period. This is the three-question test an assurance provider will run. If a spreadsheet cannot explain it, it becomes a finding.
Methodology label inconsistency. A record is tagged as NGER Method 2 but has no laboratory analysis attached. Or a record is tagged Method 1 but carries a custom uncertainty override. The auditor's substantive test is looking for the methodology stack, not just the number, and a mismatched label is a red flag.
Orphan records. An emission record whose business unit was merged, whose material was superseded, whose reporting period was closed and reopened. These are the ledger equivalent of a broken foreign key. They do not roll up cleanly into any framework report and they cannot be traced back to a source system.
Each pattern has a defined remediation. Attach a document. Re-price the factor at the correct vintage. Reconcile the variance with a written explanation and journal. Add the missing methodology attachment. Reparent the orphan or archive it with a reason code. The agent's job is to find every instance and propose the specific fix, ranked by the exposure it removes.
How the agent runs continuously against the ledger
The agent is not a nightly batch. It runs on every write to the emission ledger.
The ledger publishes an event on every insert, update, restate and reopen. The Compliance Gap Fixes runtime subscribes to those events, applies the five pattern checks against the affected record, and if any pattern matches, writes a suggested remediation into a queue.
For patterns that require cross-record context (factor version drift across a whole portfolio, unresolvable variance between two framework reports, orphan detection after a business unit merge), the agent also runs a scheduled scan. High-priority checks run daily. Medium-priority checks weekly. Lower-priority checks monthly. The cadence mirrors the way we built the twelve compliance monitoring agents that ship alongside it.
Every run is logged. The activity log records what the agent looked at, what it found, what it proposed, and what mode it was running in. That log is one of the artefacts the auditor sees inside the Auditor Workspace. It is also how we prove to a management letter reviewer that a class of issue was checked continuously across the reporting period, not just once at year-end.
Autonomy is controlled by a mode setting. Shadow means the agent looks and logs but never proposes. Co-pilot means it proposes and a human decides. Trusted means it can apply a narrow set of pre-approved remediations without waiting for a human: factor re-pricing at a known vintage, document reattachment where the file already exists in the OneDrive or SharePoint source folder, that kind of thing. Most organisations run in co-pilot mode for the first reporting cycle and graduate individual patterns to trusted once the internal audit function is comfortable with the record.
The suggested-remediation lifecycle
Every gap the agent finds becomes a first-class remediation object with its own state machine.
Detected. The agent has flagged a record against one of the five patterns. The remediation is a hypothesis at this stage. It carries the record ID, the pattern that matched, the evidence the agent used, and a confidence score. Nothing has changed in the ledger.
Proposed. The agent has generated a specific fix. For a missing-source-document gap, the proposal is a document ID to link, drawn from the folder-per-project OneDrive or SharePoint sync where an invoice already exists but was not attached. For a factor drift gap, the proposal is the correct vintage and the recalculated emission value. For a variance gap, the proposal is a reconciling journal entry with an explanation drawn from prior similar resolutions. Each proposal is a diff against the current record, not a rewrite.
Accepted. A human reviewer, typically the sustainability lead or the finance controller who owns the ledger, has clicked accept. Accepting is itself a logged event with the reviewer's user ID.
Applied. The remediation has been written to the ledger. The audit trail records the before-state, the after-state, the reviewer, the agent that proposed the change, and the pattern that triggered it. Every applied remediation is retained for seven years under the same policy that governs the rest of the ledger, described in the version control and seven-year retention model.
Superseded. A proposal that was never accepted, or was accepted but later invalidated by a data change, moves to superseded. It is not deleted. Auditors sometimes ask what an agent proposed that a human did not act on, and being able to answer that is part of the control narrative.
We deliberately did not build an auto-close state. If a reviewer never touches a proposal, it stays in the queue with an ageing indicator. Silence is not resolution.
Integration with the Auditor Workspace
The point of the Auditor Workspace is to hand an external assurance provider a read-only view of the working papers without pulling them into your production environment. The ASSA 5010 walk-through we wrote up earlier covers the mechanics. The Compliance Gap Fixes agent plugs into that workspace as a first-class evidence stream.
Specifically, the auditor sees three things about compliance gaps.
They see the register of every gap the agent detected across the reporting period, whether it was resolved or superseded. This is the closed-loop evidence that internal quality control was active, not dormant. If the agent detected fifty missing-document gaps in September and the register shows all fifty were remediated with linked evidence by October, that is exactly the kind of continuous control auditors look for under reasonable assurance.
They see the applied remediations attached to the specific ledger records they are testing. When an auditor pulls a sample of 30 diesel records and one of them was corrected by the agent, they can see the before-state, the after-state, the reviewer and the pattern. There is no separate spreadsheet to reconcile.
They see the mode history: when the agent was in shadow, co-pilot or trusted mode, and which patterns were graduated to trusted with which board or committee approval. Trust graduation is itself a governance disclosure item under AASB S2 paragraph 6 and the auditor will ask about it. Having the log available means the answer is not a slide deck.
None of this is an assurance opinion. The agent does not sign a report. It just makes the auditor's substantive tests cheaper to satisfy.
Integration with the Anomaly Detection queue
Compliance gaps and anomalies share an investigation surface, deliberately.
An anomaly is a suspicious value. A compliance gap is a structural weakness. In practice they overlap. A record with a missing source document is a compliance gap, but if the value is also three standard deviations from the site average, it is an anomaly too. Investigating both separately would waste reviewer time and create duplicate audit trails.
So both flow through the same investigation queue. Each item carries its detection reason, priority, evidence, proposed remediation and status. A reviewer working the queue does not need to know which runtime raised the flag. They just need to accept, reject, or escalate.
Where the two systems differ is in the proposal. Anomaly detection tends to propose an investigation ("compare against Q2 activity data"). Compliance gap fixes tend to propose a specific data change ("relink invoice ID 0f28…, re-price at NGA 2025 edition"). Both are logged the same way, but the reviewer's action is different.
Grouping matters. If the compliance gap agent finds 200 records that all use a superseded NGA factor from the 2024 edition, we do not create 200 investigation items. We create one. The remediation is bulk. Reprice all 200 at the current vintage, log the recalculation, and record who approved the bulk change. Alert fatigue is the enemy of any control system, and grouping is what keeps this one usable.
Where consultants fit into the flow
If a consulting practice is running the ASRS engagement, the Compliance Gap Fixes agent changes their working pattern. Not their role.
The traditional flow was that the consultant reviewed the client's spreadsheet, wrote a management letter of findings back to the sustainability team, waited for the client to remediate manually, then re-reviewed. That is a slow loop. It burns hours on the boring findings (factor drift, missing documents) that carry no analytical value.
With the agent running against the ledger continuously, the boring findings are already remediated by the time the consultant reviews. What lands on their desk is the harder subset: the methodology calls, the boundary decisions, the transition plan credibility questions. That is where consulting judgement actually earns its fee.
Practices that adopt the agent early tend to reposition the engagement letter around reasonable assurance readiness and Scope 3 methodology work, rather than data hygiene. The consultant is not competing with the agent. The agent is doing the consultant's least-billable work.
What the agent explicitly does not do
The name is "suggested remediations" for a reason. Everything about the agent is designed to keep a human in the loop for the decisions that matter.
It does not auto-remediate outside a narrow trusted mode. Even in trusted mode, the patterns eligible for auto-apply are the low-judgement ones: factor re-pricing where the target vintage is unambiguous, document relinking where the file is already resident in a project source folder. Anything that requires interpretation (reconciling a variance, choosing between two candidate factors, deciding whether an orphan record should be reparented or archived) always requires a human accept.
It does not replace external assurance. Nothing the agent proposes carries the weight of an ISAE 3410 opinion. When the auditor signs off, they sign off on the ledger and the controls, including the agent as one of those controls. The attestation record is stored separately and belongs to the auditor.
It does not rewrite a locked reporting period silently. Once a period is locked and a NGER submission or an AASB S2 disclosure has been generated against it, the agent's proposals against records in that period route through the restatement workflow, not the standard accept-and-apply path. Restatement is a governance action with its own approval chain.
And it does not judge Scope 3 methodology choices. Scope 3 boundary questions (where a spend-based estimate is legitimate, where an activity-based method is required, whether a category applies at all) are not compliance gaps in the technical sense. They are strategic decisions that need to be made by a human accountable to the board. The agent will flag missing source documents on Scope 3 records the same as it does for Scope 1 and 2, but it will not tell you your Category 11 boundary is wrong.
Honest admission: the hardest pattern to detect reliably is methodology label inconsistency. A record can be tagged Method 2 with the correct attachments and still be wrong methodologically. We catch the label-versus-attachment mismatch; we do not catch the deeper question of whether the method is defensible for the activity. That is a limit of what an automated agent can reasonably do, and we would rather say it than pretend otherwise.
FAQ
Does the agent replace an internal audit review?
No. Internal audit reviews the design and operation of controls. The agent is one of the controls being reviewed. It generates the continuous evidence stream that internal audit and external assurance both draw from. It does not form conclusions about control effectiveness.
How does the agent know which NGA factor edition is current?
The material library carries effective-from and superseded-on dates for every published NGA vintage. When a factor is used, the vintage is stamped on the record. The agent compares the stamp against the applicable edition for the reporting period date and proposes re-pricing where they differ.
Can we run the agent in shadow mode indefinitely?
You can, but you probably should not. Shadow mode is useful for the first two or three cycles while an internal audit function is validating what the agent flags. After that, the point of the agent is to close the loop, and shadow mode does not close it. Most sustainability teams graduate to co-pilot within a reporting quarter and to selective trusted mode for low-judgement patterns within a full cycle.
What happens if an agent proposal is later found to be wrong?
Every applied remediation is versioned in the ledger. Rolling back an incorrect proposal is a restatement, and the restatement carries its own approval and audit trail. The original agent proposal is not deleted; it is annotated with the reversal reason. Auditors sometimes explicitly test the rollback path as part of control walk-through, which is why we do not overwrite.
Is the agent module included in the standard Carbonly subscription?
The Compliance Gap Fixes agent ships with the platform. Pricing is per project with a base of $100 per month, and the agent runs across every project in the tenant regardless of tier. For a scoping conversation, hello@carbonly.ai is the right address.
The next reporting cycle will surface the same boring findings unless something in the pipeline changes. A background agent that runs against every write, proposes typed remediations, and hands them to a human to accept is the shape of that change. Book a walk-through against your own ledger before the next lock date.