Operational guide / Updated August 2026 / 8 min read

What a certification auditor samples, and which measurement gaps fail an audit

By Bhavik Modi / CEO & Co-Founder LinkedIn

Instrumentation and process engineering, electrolyser technology and machine learning, with experience at Siemens, L&T, Mitsubishi and Newtrace.

A chain of custody audit is not an assessment of whether a plant is well run. It tests whether every claimed unit of product can be followed back to inputs that met the scheme rules, on evidence that existed at the time. Plants that operate well and record loosely fail it.

CertificationChain of custodyAuditHydrogen

What the audit is actually testing

A chain of custody audit asks a narrow question: for the product you claimed, can you demonstrate that the inputs met the rules, that the quantities reconcile, and that the records supporting both existed at the time rather than being assembled afterwards.

It is not an assessment of whether the plant is well engineered or well operated. Those matter commercially and they are not what is being sampled. A plant that runs beautifully and keeps loose records fails; one that runs adequately and keeps disciplined records passes.

The distinction catches operators out because it is the reverse of most technical reviews they have been through. The auditor is not looking for reasons the plant is good. They are looking for the point at which the paper trail stops.

The measurement layer underneath the scheme rules

Certification schemes and regulatory frameworks differ in what they require and they are revised regularly, so the applicable scheme document and the certification body's guidance for the claim period govern in every case. What is reasonably stable across them is the shape of the measurement layer they all sit on.

Electricity input, measured at a defined boundary, with the attribute of that electricity evidenced by whatever instrument the scheme accepts, whether that is a direct connection, a contract, or a certificate. Production output, measured at a defined boundary, in a unit the scheme recognises. A time basis on which the two are matched, which may be hourly, monthly or something else depending on the framework and the period. And a mass balance that reconciles inputs, outputs, losses and inventory across a defined accounting period.

Every one of those is a metering and data retention question before it is a compliance question, which is why the failures cluster there.

How sampling actually works

An auditor does not reconcile the whole year. They select periods, often deliberately including ones that look irregular, and trace them end to end. A month with an outage, a month with unusual production, and a randomly chosen ordinary month is a typical shape.

For each sampled period, they follow specific quantities from the claim back through the reports to the meter readings, and then ask how those readings were produced, when the meter was last calibrated, and what happened during any gap.

The implication is that annual totals being correct is not the standard. The evidence has to hold for whichever period is chosen, including the awkward ones, and awkward periods are chosen on purpose because that is where reconciliation usually breaks.

The five gaps that fail audits

Time alignment. Electricity metering, production metering and any external record each carry their own clock and their own interval convention. Where a scheme matches input to output on a defined interval, misaligned or drifting clocks make the match unprovable. This is among the least recoverable failures, because the period has closed.

Meter calibration and validity. A meter outside its calibration window during part of the claim period puts that part of the claim at risk regardless of whether the readings look sensible. Calibration certificates, their dates and the treatment of the intervening period are routine audit requests.

Data gaps and substitution. Every plant has outages in its data. What matters is whether the substitution method was defined in advance, applied consistently and documented, or invented afterwards to fill a hole. A documented, conservative substitution rule is usually acceptable; a retrospective estimate usually is not.

Boundary drift. The metering boundary used in the claim has to be the boundary defined in the scheme documentation, and it frequently is not, because plant metering was installed for operational reasons and the boundaries were never reconciled. The same problem shows up in performance guarantees, where the measurement boundary is the most common source of an apparent shortfall.

Retention. Records have to survive for the retention period the scheme sets, which is usually longer than a historian's default configuration. A claim that cannot be re-evidenced during a later surveillance audit is a finding even though it was fine at the time.

Mass balance, and why it is harder than it looks

A mass balance reconciles what went in, what came out, what was lost and what remains in inventory, within a stated tolerance, over a defined accounting period. It sounds like arithmetic and behaves like metrology.

The difficulties are practical. Hydrogen inventory in storage is measured indirectly, through pressure and temperature, so its uncertainty is larger than the meter uncertainty on the flows. Vented, purged and recycled quantities are often not metered at all and are estimated from operating conditions. Compression, drying and purification losses have to be accounted for somewhere, and if they sit in a residual term then the residual absorbs every other error too.

The useful preparation is to run the balance internally, at the period the scheme requires, before the first audit rather than during it. A balance that only closes over a year is usually hiding offsetting errors that a shorter period would expose, and the auditor will pick the shorter period.

What separates a smooth audit from a painful one

A written measurement inventory. Every meter that appears in the claim, its tag, its boundary, its uncertainty class, its calibration status and its retention. This one document answers a large share of the questions asked and its absence signals to the auditor that nobody has thought about the boundary.

A defined substitution procedure, written before it is needed and applied consistently.

Time synchronisation to a common source, documented, across every system that contributes to the claim.

Traceability from claim to reading without a spreadsheet in the middle that nobody can reproduce. Where a figure passes through a manual step, that step becomes the weakest point in the chain and the auditor will find it.

And separation of provenance where possible, so that the records supporting a claim are system-generated rather than compiled by the party making the claim. The same structural point applies to reporting to lenders after commercial operation: nobody is alleging bad faith, but a figure that can be checked is easier to accept than one that has to be trusted.

Where a monitoring layer helps, and where it does not

It helps with the record. Continuous, timestamped, retained data at a defined resolution, with a documented boundary and a reproducible path from measurement to reported figure, is most of what an audit asks for.

It helps with the awkward periods. Outages, transitions and substitutions are where sampling concentrates, and a system that holds plant state alongside the metering makes those periods explainable rather than blank.

It does not certify anything. The scheme sets the rules, the certification body audits against them, and the certificate is theirs to issue. Yunify supports the reporting and holds the record; it has no role in the determination, and any material suggesting otherwise should be read carefully.

Nor does it substitute for reading the scheme document. Requirements differ between frameworks and are revised, sometimes substantially, and the version that applies is the one in force for the claim period.

Questions teams ask

Frequently asked questions

What does a chain of custody auditor actually ask for?

Meter readings behind the claimed quantities, calibration records for those meters, the mass balance for the sampled period, evidence for the electricity attribute, the time basis on which input and output were matched, and the documented procedure for handling data gaps. They then trace specific quantities from the claim back to the readings.

Why do audits sample rather than check everything?

Because tracing every unit is impractical. Periods are selected instead, usually including ones that look irregular, and traced end to end. The consequence is that correct annual totals are not the standard: the evidence has to hold for whichever period is chosen.

What is the most common reason a plant fails?

Time alignment between electricity metering, production metering and any external record. Where the scheme matches input to output on a defined interval, clocks that are unsynchronised or drifting make the match unprovable, and once the claim period has closed it cannot be corrected.

How should data gaps be handled?

With a substitution procedure defined in advance, applied consistently and documented at the time. A conservative documented rule is usually acceptable. An estimate produced afterwards to fill a hole usually is not, because the auditor cannot distinguish it from a convenient number.

How long do certification records need to be kept?

For the retention period the scheme sets, which is generally longer than a historian's default configuration. Surveillance audits revisit earlier claims, so a record that cannot be reproduced later becomes a finding even though the original claim was sound.

Can a monitoring system certify hydrogen?

No. The scheme sets the rules and the certification body audits against them and issues the certificate. A monitoring layer supports the reporting by holding a continuous, traceable record; it has no role in the determination.