Tokenisation has been pitched to the voluntary carbon market and the renewable energy certificate market as the answer to a long-standing transparency problem. The pitch is that placing a credit on a ledger fixes the integrity questions that have followed the market since its inception. The pitch is partially correct and partially misleading. Tokenisation fixes the question of what moved, when, between which wallets. It does not fix the questions of what the credit represents, how it was issued, whether it was double counted in a national inventory, or whether the underlying project actually produced the claimed climate benefit.
The International Sustainability Standards Board issued IFRS S2 Climate-related Disclosures in 2023. The standard requires an entity to disclose information that enables users of financial statements to understand the effect of climate-related risks and opportunities on the entity's prospects. Where the entity relies on carbon credits to support a net-zero target, IFRS S2 requires disclosure of the type of credit, the issuance protocol, the registry, the retirement status and the assurance basis. The European Union Corporate Sustainability Reporting Directive and the European Sustainability Reporting Standard E1 on climate change impose substantively similar disclosure obligations on European reporting entities.
Tokenising the credit does not alter the disclosure. A tokenised credit retired against a corporate emissions claim must still be described by the issuance protocol, the registry of origin, the project methodology, the vintage, and the assurance pathway. The token is the wrapper. The disclosure is about the underlying. The control plane above the rail must reconcile every tokenised retirement to the corresponding entry in the originating registry and must capture the assurance evidence that supports the disclosure.
The Integrity Council for the Voluntary Carbon Market published the Core Carbon Principles in 2023 and the Assessment Framework in 2024. The Principles set integrity criteria covering governance, emissions impact, sustainable development, additionality, permanence, robust quantification, no double counting, and effective registry operation. Crediting programmes that meet the Principles can label eligible credits as Core Carbon Principles aligned. The Principles are not certified by the tokenisation rail. The rail can carry the alignment metadata as an attribute on the token, but the institution that relies on the alignment must verify it independently against the Council's published assessments, which are updated periodically.
Double counting is the integrity question that tokenisation has so far failed to resolve. A credit issued under a voluntary methodology may correspond to an emissions reduction that the host country has also counted toward its Nationally Determined Contribution under the Paris Agreement. Article 6 of the Paris Agreement and the associated guidance on Internationally Transferred Mitigation Outcomes establish a corresponding adjustment mechanism intended to prevent this. The mechanism operates at the national-inventory level and is not visible on the tokenisation rail. The corporate buyer that wishes to make a credible claim must demonstrate, in its disclosure, either that a corresponding adjustment was applied or that the credit was issued on a basis that does not require one.
Renewable energy certificates raise a parallel integrity question. A REC represents the environmental attribute of one megawatt-hour of electricity generated from a qualifying renewable source. The certificate is issued by a regional issuing authority, in the United States by entities such as the Western Renewable Energy Generation Information System, the Midwest Renewable Energy Tracking System and the New England Power Pool Generation Information System, in Europe by the Association of Issuing Bodies under the European Energy Certificate System. Tokenising a REC requires the tokenised representation to retire the underlying certificate at the issuing authority, or to bind the issuing authority's record to the token in a manner that cannot produce divergence. Several first-generation tokenised REC programmes have produced tokens that exist alongside the issuing authority's certificate, creating a double-counting exposure that the rail does not detect.
The Securities and Exchange Commission climate disclosure rules adopted in 2024 and currently subject to ongoing litigation require registrants, where they have publicly disclosed climate-related targets that include the use of carbon offsets or RECs, to describe the offsets, the source, the nature and the cost, and to discuss the role they play in meeting the target. Where the registrant's reported financial statements are subject to assurance, the assurance engagement now extends to the existence and authenticity of the offsets relied on. The institutional control plane must produce an audit-ready trail from each tokenised offset retirement to the source registry, the project documentation and the assurance evidence.
The CSRD assurance regime in Europe imposes limited assurance on sustainability reports for the first reporting periods, transitioning to reasonable assurance under standards to be issued by the European Commission. Both engagements will examine the basis for any offset claim. A claim supported only by a transfer record on a tokenisation rail will not satisfy the engagement. The assurer requires the underlying project documentation, the registry confirmation, the corresponding-adjustment evidence where applicable and the methodology validation report. The control plane must assemble this evidence file at the time of retirement, not at the time of the assurance engagement.
Marketing claims based on tokenised offsets are subject to consumer-protection regimes. The United States Federal Trade Commission Green Guides, the United Kingdom Competition and Markets Authority Green Claims Code, the European Union Empowering Consumers for the Green Transition Directive and the Australian Competition and Consumer Commission Greenhouse Gas Emissions Claims Guidance each require environmental claims to be substantiated, specific, and capable of independent verification. A claim that a product is carbon neutral on the basis of tokenised offsets must be supported by an evidence chain that the rail does not provide on its own.
Retirement is the operational pivot point. A credit or certificate that has been retired against a specific claim cannot be reused. The tokenisation rail must enforce a single-retirement semantic equivalent to the single-authoritative-copy semantic in trade finance. Where the rail permits the same underlying credit to be tokenised on multiple chains without coordinated retirement at the originating registry, the integrity exposure is structural and the institution cannot rely on the rail's transfer history to discharge the no-double-counting principle.
The board-level question for an institution that uses tokenised carbon or REC credits to support climate disclosures or marketing claims is whether the institution has stood up a continuous evidence file that, for each retired credit, captures the originating registry record, the project documentation, the methodology, the vintage, the corresponding-adjustment status where applicable, the assurance pathway and the disclosure or claim the credit supports. Where that file is incomplete, the prudent posture is to defer reliance on the credit for any reportable claim.
Cabier Consulting's 2026 brief, Governance Above the Rail, places carbon and REC tokenisation in the under-governed category because the assurance pathway has not kept pace with the settlement mechanics. Provenance is what the rail provides. Assurance is what the institution owes. The two are not the same.
Section. The board questions before going live.
Before the first tokenised carbon and renewable energy certificates transaction settles in production, the institution's audit and risk committees should resolve a defined list of questions, on the record, with named accountability. The first question is whether the legal opinion supporting the use of the tokenisation rail covers every jurisdiction in which the institution will issue, hold, transfer or distribute the instrument, and whether the opinion is current as of the most recent supervisory communication in each jurisdiction. The second question is whether the institution has identified the named senior manager responsible for the programme under the relevant individual-accountability regime, including the United Kingdom Senior Managers and Certification Regime, the Australian Financial Accountability Regime, the Hong Kong Manager-in-Charge regime, the Singapore Senior Managers regime, and any equivalent in the home jurisdiction.
The third question is whether the model inventory has been updated to include every smart contract, oracle and pricing routine that influences a regulated outcome, and whether each new entry has been subject to independent validation under standards equivalent to Federal Reserve SR 11-7 and the Office of the Superintendent of Financial Institutions Guideline E-23. The fourth question is whether the institution has documented, in advance, the supervisory communications it will make in the event of a tokenisation rail outage, a smart-contract incident or an oracle failure, and whether those communications have been pre-cleared with the relevant regulators where pre-clearance is appropriate. The fifth question is whether the institution's professional-indemnity, directors-and-officers and cyber-insurance policies have been updated to reflect the new exposures, and whether the underwriters have been provided with the institutional control documentation.
Section. An operating model for the institution-owned control layer.
A credible above-the-rail control layer for tokenised carbon and renewable energy certificates sits inside the second line of defence, reports through the chief risk officer, and is staffed by a small named team with explicit charters for valuation governance, model risk, regulatory reporting, conflict and incentive surveillance, operational resilience and cross-jurisdictional consistency. The team does not run the rail. It operates a continuous evidence file that consumes events from the rail, reconciles them to the institution's systems of record, and grades the effectiveness of each control on a daily cycle. The grading is not pass or fail. It is a defined scale of effective, degraded and failed, with a stated remediation latency for each grade, and with explicit escalation thresholds to the chief risk officer and the audit committee.
The control layer's outputs are designed to be regulator-readable without bespoke transformation. A single source of truth produces the figures that feed every supervisory return, every internal capital-adequacy assessment, every Pillar 3 disclosure and every public sustainability or operational-resilience statement. The auditor and the supervisor see the same chain of evidence. The institution does not produce one number for the regulator and a different number for the board. The discipline of a single source of truth is the precondition for any defensible cross-jurisdictional posture, and it is the principal operational benefit of building the control layer above the rail rather than inside it.
Section. A twelve-month plan to stand up the layer.
In month one, the institution maps every regulatory obligation that attaches to the tokenised carbon and renewable energy certificates programme across every jurisdiction in scope, and produces a matrix that ties each obligation to a named owner, a control description, an evidence source, an effectiveness-grade definition, and a remediation latency. In months two and three, the institution stands up the evidence vault, ingests live data from the tokenisation rail, the legacy systems of record and the third-party data providers, and reconciles the three on a daily cycle. In months four through six, the institution writes the effectiveness-grade definitions for each control, validates them against historical data, and stress-tests them against scenarios developed in conjunction with internal audit.
In months seven through nine, the institution runs the control layer in parallel with the existing periodic control regime, identifies the divergences, documents the root causes and remediates. In months ten through twelve, the institution retires the periodic regime for the controls now operated continuously, formalises the operating model with the audit committee and the regulator of record, and produces the first regulator-readable evidence file. The plan is paced so that no production volume is committed to the rail in advance of the corresponding control evidence being in place. The discipline is uncomfortable in the early months and unmistakably valuable when the first supervisory examination arrives.
Section. What a regulator-ready evidence file looks like.
The regulator-ready evidence file for the tokenised carbon and renewable energy certificates programme is not a folder of point-in-time reports. It is a continuously assembled, cryptographically anchored record that, on any day a supervisor walks into the institution, can answer five questions without rework. Which obligations attach to this programme in this jurisdiction. Which control discharges each obligation. What grade did each control hold on each day. Where the grade was below effective, what the remediation latency was and whether it was met. Which named individuals were accountable for the obligation, the control and the remediation. A file that cannot answer these five questions on the supervisor's first request will be treated as a control weakness in its own right, irrespective of the substantive quality of the underlying programme.
The Cabier institutional brief, Governance Above the Rail 2026, is the reference architecture this plan implements for the tokenised carbon and renewable energy certificates use case. The brief is written for boards and senior risk committees and is available in full at the Cabier Consulting site. LUMINAIRE will continue to publish under this cluster as the under-governed asset classes evolve and as supervisory expectations are clarified through 2026 and beyond.
