Skip to main content
Version: Work in Progress
UNTP Public Review
Public review has now closed. The UNTP team is working through the review comments and expects to release UNTP version 1.0.

Chain of Custody and Mass Balance

info

Please note that this specification is suitable for pre-production pilot implementations.

Overview​

Chain of custody refers to the documented, end-to-end record of how a product or material moves and is transformed from origin to final use. Its purpose is to provide traceability and integrity, proving where something came from, what happened to it, and who was responsible at each step.

Six models are in common use. The definitions below follow the ISEAL Chain of Custody Models and Definitions Guidance v2 (2025), which describes them in terms of certified material specifically. ISO 22095:2020 defines an equivalent generic set, without the reference to certification.

ModelPhysical mixingWhat the output claim rests on
Identity PreservationNone. Single source, kept separate throughoutThe specific source itself. The strongest link between product and claim
SegregationCertified material from several sources may be combined, never with non-certifiedThe output being wholly certified, though individual origin is not preserved
Controlled BlendingCertified and non-certified mixed in a known, fixed proportionThat proportion, tracked through production, so the output carries a known percentage
Mass BalanceCertified and non-certified mixed freelyAdministrative reconciliation: certified volume in against volume sold as certified out
Controlled Mass BalanceAs mass balance, but every input must meet a baseline requirementThe baseline applying to all material, with the additional attribute reconciled by volume
Book and ClaimPhysical product and claim fully decoupledCredits traded independently of the goods. The weakest physical link

Under Controlled Mass Balance all inputs must satisfy a minimum set of requirements, and volumes meeting further criteria are tracked as in mass balance. Non-conforming material is excluded at the input boundary rather than accounted for. See Two different frauds.

This page covers the volume accounting that underpins the middle four models, and mass balance in particular, since that is where UNTP's material accounting does the most work. Book and Claim is covered in a separate page.

The model is a property of the claim, not the process​

A chain of custody model applies to a claimed attribute, not to a facility or a process. One facility, one production run and one set of traceability events may support claims under different models at the same time.

A fabric manufacturer runs a segregated line for certified organic cotton. The organic claim rests on segregation, because organic and conventional cotton never meet. The same manufacturer claims water use, carbon intensity and country of origin, and the bales feeding that segregated line come from farms with different water footprints, energy mixes and origins. Those claims rest on mass balance.

Where a claim rests on a chain of custody model, that model MUST be stated. Claim.chainOfCustodyMethod carries it in a Digital Product Passport or Digital Facility Record, and ConformityAssessment.chainOfCustodyMethod in a Digital Conformity Credential, taking one of the six values above. A claim that rests on no such model omits the property. It is not carried on Criterion, nor on a Digital Corporate Record claim.

A traceability event does not carry the model, because one event serves claims under several. Nor can the model be fully derived from events: a reader can often tell from the graph whether inputs for a given attribute were separated or mixed, but the allocation rule applied at a transformation — first-in-first-out, last-in-first-out, proportional mix — is not recoverable from quantities, and affects how a mass balance resolves downstream. UNTP does not yet specify it.

Volume reconciliation and mass balance are not the same thing​

Volume reconciliation is the check that what a facility says came out is consistent with what went in, allowing for waste, losses and stock movements. It requires quantities of claimed material in, quantities of claimed material out, and an allowance for waste.

Volume reconciliation applies to every model except Book and Claim. A mill that receives 40 tonnes of certified cotton and sells 60 tonnes of certified fabric has failed segregation as surely as it would have failed mass balance. Controlled blending reconciles against its declared ratio.

Mass balance is narrower: the model in which physically mixed material is reconciled administratively, so that the volume sold as certified does not exceed the certified volume acquired.

Proving the absence of undeclared material is a separate and harder problem, and it is the one that requires comprehensive facility-level disclosure. See Privacy-Preserving Verification.

Two different frauds​

Two distinct failures require different controls.

Volume inflation is selling more material as conforming than the conforming inputs support. All material in the chain is eligible; the quantities do not add up. Volume reconciliation detects it, because the volumes are declared.

Contamination and substitution is the introduction of non-eligible material into a chain that claims conformity. The material is not declared, so no ledger fails to balance. Detection depends on input and output thresholds, yield plausibility, and physical testing of composition.

The two are separable in documentary practice. In textiles a test report establishes what material physically is, measured by a laboratory, while a transaction certificate attests a standard claim over a certified volume. A test report reading "100% cotton" is silent on whether that cotton is organic. A divergence between measured and declared composition indicates substitution; a certificate covering more volume than was acquired indicates inflation.

Every chain of custody model MUST prevent non-eligible material entering, independently of how it accounts for volumes. Controlled Mass Balance enforces this at the input boundary.

Challenges​

The transparency graphs page describes how data in UNTP credentials can be assembled to construct a verifiable digital twin of a supply chain — linking products to the facilities that made them and, via traceability events, to the upstream materials used in manufacturing. However, it does not address how to verify that the sustainability claims on output products are actually supported by the input materials and production processes. That is the domain of volume reconciliation, whichever chain of custody model a given claim rests on.

Are Output Claims Matched by Inputs?​

Consider these concrete scenarios:

  • Organic cotton fabric — A buyer purchases certified organic and fair-work cotton fabric from a weaver. The weaver can show evidence of some upstream purchases of certified raw cotton. But how can the buyer be sure that the fabric does not include mixed non-compliant cotton? If the weaver buys 40% certified organic cotton and 60% conventional, only 40% of output fabric should carry the organic claim.
  • Low-carbon steel — A buyer of low-carbon steel products needs confidence that the claimed emissions intensity is matched by purchases of low-emissions ore by the refiner. If the refiner blends ore from multiple sources with different carbon footprints, the output emissions claim must reflect the weighted average of actual inputs, not a cherry-picked best case.
  • Certified mineral sourcing — A copper smelter claims that its refined copper comes from 100% certified mines. But does the smelter actually source sufficient certified copper concentrate to back that claim across all its output, or is it re-using certificates from a small certified supply to cover a much larger uncertified volume?

More generally, the challenge is to verify that the totality of output performance claims from a facility are matched by input material and production process performance metrics. Volume inflation happens when an actor buys small quantities of high-integrity inputs and claims much larger volumes of conforming output. Without material accounting it is undetectable, and it is the failure mode reconciliation exists to catch.

Commercial Confidentiality​

Reconciling the volumes of claimed material is not, on its own, demanding: it needs quantities in, quantities out, and an allowance for waste. The demanding case is proving that nothing undeclared entered the chain, and for that a buyer would need visibility of all facility inputs, outputs and production processes, including supply volumetrics, yield rates and stock levels. That data is almost always commercially sensitive. Facilities will not publish their production volumes, supplier relationships or material accounting ledgers for competitors to see.

This creates a tension. Detecting contamination benefits from comprehensive facility-level data, and that data is too commercially sensitive to share openly. Any viable solution must resolve it, enabling trustworthy verification without requiring public disclosure of commercial secrets.

Solution​

UNTP addresses the reconciliation challenge through facility-level material accounting anchored in the same credentials used for transparency graphs, combined with privacy-preserving audit mechanisms that resolve the confidentiality tension.

Facility-Level Material Accounting​

UNTP material accounting follows the same fundamental logic as financial accounting:

Financial AccountingUNTP Material Accounting
Chart of accountsDigital Product Passports (DPPs) describe characteristics and intensity metrics of identified input and output materials
Balance sheetStock at a point in time, derived from the running total of recorded flows and verified against physical count
Ledger transactionsDTEs with bizStep "shipping" or "transformation" account for input/output flows and production runs
Audited accountsDigital Conformity Credentials (DCCs) carry independently audited conformance and verified intensity metrics
Facility conformityDigital Facility Records (DFRs) carry facility-level conformity claims, certifications, and quality metrics

The core principle is conservation:

Opening stock
+ inbound flows
- outbound flows
± production transformations
= closing stock

This applies to mass, volume, or count and forms the foundation for all higher-level sustainability claims. Just as double-entry accounting makes financial fraud difficult by requiring transactions to balance, material accounting makes greenwashing difficult by requiring physical quantities to reconcile.

The accounting analogy may imply an accuracy that exists in financial accounting but does not in material accounting, and even less in impact accounting. Material stocks and flows must allow for waste and losses, and emissions intensity calculations must allow for inaccuracies in reported intensities. UNTP allows for claims and assessments to report metrics together with an estimate of accuracy.

Supporting All Production Models​

Industrial processes fall into three broad categories, each producing a different but conceptually equivalent type of production record:

  • Discrete Manufacturing produces individually serialised items (vehicles, machinery, electronics). The canonical record is the as-built record documenting actual components and processes for a specific serialised product.
  • Batch Manufacturing processes identified inputs to produce identified outputs via discrete production batches (food processing, chemicals, refining). The canonical record is the batch record.
  • Continuous Production produces a stream of output materials from a continuous stream of inputs (mining, oil production, bulk chemicals). The boundary is typically a time period, and the canonical record is the production run record.

All three record types are specialisations of a production record and differ only in how boundaries are defined (serial number, batch ID, or time window). All are represented as transformation event DTEs with quantity inputs and outputs.

Separating Facts from Policy Claims​

This approach separates underlying material accounting (facts about what physically happened) from policy-driven claims (assertions about sustainability attributes). This separation allows the same material accounting facts to support different chain of custody assessments. For example, when a facility records input material identity and quantity for every production run, the same records support:

  • Segregated chain of custody — if all inputs for a given run meet the policy criteria claimed for the output
  • Mass balance chain of custody — if the average of all inputs to multiple production runs matches the average of all outputs over a given period

The same separation facilitates multiple impact assessments from the same data. For example, given a shipment of 100 tonnes of copper ore with a DPP stating 2 tCO₂e/tonne ore and 25% copper concentration, the emissions intensity per tonne of contained copper is 2 ÷ 0.25 = 8 tCO₂e/tonne Cu.

Aligning with Natural Industrial Processes​

UNTP does not require facilities to change their manufacturing processes or record-keeping systems. No UNTP credential should carry information not reasonably available in production management systems at the time of issue:

  • Material flows between facilities are recorded using shipping manifests — logistics-level flow records that production management systems already create.
  • Production runs record consumption of inputs and creation of outputs — data that all production management systems maintain.
  • Facility stocks are the running balance of recorded flows, which a facility verifies against a physical count on its own cycle.
  • Product records define characteristics and intensity metrics of identified material types.

UNTP credentials map naturally to these records: DTEs carry flow information as shipping and transformation events, DPPs carry material characteristics and intensity metrics, and DFRs carry facility-level material usage and conformity claims.

Privacy-Preserving Verification​

Most facilities will not publish their internal production stocks and flows, and genuine commercial confidentiality should not become a way to hide non-compliant behaviour. A facility shares its material accounting with at least one trusted independent party, not with everyone, and the verifier receives an attestation rather than the private books.

That is one of three patterns for reaching a conclusion without publishing the evidence behind it, set out with their mechanisms, requirements and limits in Privacy-Preserving Verification. The degrees of assessor access relevant here — sample-based, continuous, and one-up-one-down — are described there.

How Credentials Work Together​

The diagram shows an overview of credential flows for a refiner facility seeking to provide chain of custody compliance assurance to its customers without revealing commercial sensitivities.

chain of custody with UNTP

Process flow:

  1. A supplier facility (e.g., a mine-site) ships material with a shipping manifest (DTE) listing material identifiers and quantities. The mine has also issued a DPP for each material and may include conformity assessments (DCCs). Following the UNTP identity resolver standard, the DPPs and DCCs are discoverable from material identifiers in the shipping manifest.
  2. The refiner receives the inbound shipment. The inbound material may be mixed with other supplies of different qualities. The facility performs production runs and records quantities of input materials consumed and output materials produced as transformation event DTEs.
  3. An external auditor (which, if all source data is digital, could be an algorithmic service) receives all stock and flow data (DTEs), pulls the DPPs for each identified material, verifies material accounting (balancing material mass), calculates impacts (e.g., emissions intensity), and issues DCCs at product and facility level.
  4. The facility issues DPPs with declared product characteristics and intensity metrics and DFRs with facility-level conformity claims. The facility adds the DCCs from the independent auditor as verifiable support. A shipment of refined product is prepared for a customer with a shipping manifest listing identifiers and quantities.
  5. The customer receives the shipment and can pull DPPs, DCCs, and DFRs that provide verifiable confidence in the qualities claimed — without needing to see the facility's internal production data. The receiving facility is now in the same position as step 1, and the process repeats.

Criterion alignment: Each assessment criterion in DPPs and DFRs has a unique criterion.id. When an auditor issues a DCC, the DCC's assessment criteria reference these same IDs, creating a verifiable link between facility claims and auditor verification.

Fraud Resistance​

The countermeasures below address volume inflation, which is the failure that reconciliation can detect. Contamination and substitution need the additional controls described under Two different frauds. Fraud in chain of custody claims will disadvantage legitimate actors and lead to a collapse in trust. When there is material value (higher prices or reduced taxes) attached to performance claims, there will be incentives to make fraudulent claims.

If all stocks and flows are digitally signed by responsible parties, time-ordered and immutable, and counterparty-anchored (suppliers sign outbound, receivers sign inbound), then volume assurance becomes an algorithmic audit problem rather than requiring constant physical site inspections. An independent audit service can collect stock positions, gather all signed inbound and outbound flows, collect production records, apply conservation rules, and check for temporal consistency, counterparty consistency, impossible negative balances, and outputs exceeding possible inputs.

Two of those preconditions have to be supplied by the design rather than assumed.

Every transfer should be attested by both parties. This is the cheapest control in the stack and the one the rest depends on. Unless the buyer signs for what it received, a facility can understate its inputs and reconcile perfectly against the understatement. Where the supplier signs the outbound transfer and the buyer signs the inbound one, both referencing a common shipment identifier and quantity, the input total is fixed by a party other than the one claiming against it, and unilateral fabrication becomes impossible: a falsified transfer then needs a colluding counterparty whose own books must still reconcile with its own customers.

A shipment identifier carrying enough entropy, or hashed under a salt the two parties agree between themselves, doubles as a shared edge token. Two independently published records become joinable by any party holding both and by no party holding neither, with no registry and no authority involved. That is the linkability a masked supplier list cannot deliver, scoped to the parties who already know each other.

A signed record is not necessarily the only record. A signature proves that a record was issued by a given party and not altered since. It does not prove that the party has not issued a contradictory record to someone else, which is what random sample-based audit rests on. See how much the auditor needs to see.

Key fraud countermeasures include:

  • Multi-party reconciliation — Collusion is easiest pairwise but becomes fragile when third parties are involved. If A and B collude, they must ensure downstream buyer C's records also reconcile, scaling collusion to many actors.
  • Time-based plausibility constraints — Material moves and transforms at finite rates. Fabricated flows often violate equipment capacity, transport time, or yield constraints.
  • Statistical anomaly detection — Analysis of yield variance vs peers, suspiciously consistent loss rates, perfect reconciliation over long periods (real operations have noise), and sudden step changes aligned across facilities.
  • Independent anchoring points — Transport operators signing manifests, weighbridge operators issuing signed weights, port intake records, and utility-based production constraints all break closed-loop fabrication.
  • Randomised physical audits — Algorithmic audit runs continuously; facilities are randomly selected for spot checks weighted by anomaly scores. This is exactly how tax audits work.
  • Liability and counterparty risk linkage — Audit failures propagate risk flags to connected parties; certifications or market access can be suspended.

The goal is not to make collusion impossible but to make it expensive, risky, fragile, and commercially dangerous. This is the same standard financial systems operate under.

One failure mode needs no collusion at all. If a thousand facilities each over-claim by two per cent, every facility passes its own audit and every bilateral reconciliation succeeds, because each set of books balances internally. Nothing in the list above sees it.

Aggregate reconciliation does. Where quantities recorded under a scheme are totalled by commodity and period, those totals can be compared against independently produced figures: national production and trade statistics, customs data, commodity study group series, geological survey output. Recorded volume exceeding known production is detectable without auditing any participant, and it is hard to defeat for a reason that has nothing to do with cryptography, since defeating it would mean corrupting statistics produced by a different institution for an unrelated purpose.

The check is one-sided. The ceiling holds at any level of adoption, because an over-claim is an over-claim however little else has been recorded. The converse inference, that recorded volume approaching production implies completeness, holds only once coverage is representative. That asymmetry is why coverage is better pursued by saturating one commodity in one jurisdiction than by spreading thinly across many.

Report coverage rather than implying completeness. A claim that reports only the material it could trace reads as though it traced everything. The honest form states the proportion of input mass with conserved and audited provenance, against the proportions that are declared but unaudited, and undeclared.

It is also the more useful form. A reachability flag at twelve per cent coverage reports "no", which gives the holder nothing to act on. A coverage figure reports twelve per cent traced and names the unaccounted remainder as the next target, improves with every additional participating facility, and has no level below which it stops meaning anything. Carrying that figure on the claim is a credential change rather than a guidance point, and is tracked in issue #853.

Examples​

The examples below are excerpts from the published v0.8.0 sample credentials. Follow the link on each example for the whole credential.

They trace one copper supply chain:

  • Copper Mine (did:web:sample-mine.example.com) — produces copper ore concentrate in Zambia
  • Refinery (did:web:sample-refinery.example.com) — smelts and refines to LME Grade A copper cathode in Japan
  • Battery Factory (did:web:sample-battery.example.com) — manufactures battery components in Germany

Example 1: DPP for Input Ore​

Purpose: Identity and characteristics (accounting analogy: chart of accounts)

A DPP identifies a product or material and declares intrinsic properties and performance claims. It does not assert quantity or location, so the same DPP is referenced from many shipments and production records.

Excerpted from DigitalProductPassport_instance.json.

{
"type": [
"DigitalProductPassport",
"VerifiableCredential"
],
"@context": [
"https://www.w3.org/ns/credentials/v2",
"https://vocabulary.uncefact.org/untp/0.8.0/context/"
],
"id": "https://credentials.sample-mine.example.com/dpp/cu-conc-2025",
"issuer": {
"type": [
"CredentialIssuer"
],
"id": "did:web:sample-mine.example.com",
"name": "Sample Copper Mine Pty Ltd"
},
"validFrom": "2025-03-01T00:00:00Z",
"credentialSubject": {
"type": [
"Product"
],
"id": "https://id.sample-mine.example.com/product/cu-conc-2025",
"name": "Copper Concentrate (Cu 30%)",
"idScheme": {
"type": [
"IdentifierScheme"
],
"id": "https://id.sample-mine.example.com",
"name": "Sample Product Identifier Scheme"
},
"productCategory": [
{
"type": [
"Classification"
],
"code": "14110",
"name": "Copper ores and concentrates",
"definition": "Copper ores and concentrates obtained from mining operations.",
"idScheme": {
"type": [
"IdentifierScheme"
],
"id": "https://unstats.un.org/unsd/classifications/Econ/cpc/",
"name": "UN Central Product Classification (CPC)"
}
}
],
"idGranularity": "model",
"performanceClaim": [
{
"type": [
"Claim"
],
"id": "https://sample-mine.example.com/claims/product-carbon-2025",
"name": "Product Carbon Footprint — Copper Concentrate",
"chainOfCustodyMethod": "identity-preservation",
"conformityTopic": [
{
"type": [
"ConformityTopic"
],
"id": "https://test.uncefact.org/vocabulary/conformity-topics/greenhouse-gas-emissions",
"name": "Greenhouse Gas Emissions"
}
],
"claimedPerformance": [
{
"metric": {
"type": [
"PerformanceMetric"
],
"id": "https://vocabulary.uncefact.org/performance-metrics/product-carbon-footprint",
"name": "Product Carbon Footprint"
},
"measure": {
"value": 2.1,
"unit": "KGM"
}
}
]
}
]
}
}

Key observations: The credentialSubject is a Product (not a wrapper). Uses performanceClaim with claimedPerformance containing metric references from the UNTP performance metrics vocabulary. Declares intensities, not absolute quantities.

Example 2: DFR for Facility Conformity​

Purpose: Facility-level certifications, material usage, and performance claims (accounting analogy: corporate certifications)

A DFR identifies a facility and declares certifications, material usage and performance claims. The materialUsage property records aggregate material consumption over a reporting period, which is the facility-level balance-sheet data that reconciliation works from.

Excerpted from DigitalFacilityRecord_smelter_instance.json.

{
"type": [
"DigitalFacilityRecord",
"VerifiableCredential"
],
"id": "https://credentials.sample-refinery.example.com/dfr/smelter-002",
"issuer": {
"type": [
"CredentialIssuer"
],
"id": "did:web:sample-refinery.example.com",
"name": "Sample Copper Refinery Co. Ltd"
},
"credentialSubject": {
"type": [
"Facility"
],
"id": "https://facility-register.example.com/fac-002",
"name": "Sample Copper Refinery",
"materialUsage": {
"applicablePeriod": {
"startDate": "2024-01-01",
"endDate": "2024-12-31",
"periodInformation": "Calendar year 2024 reporting period."
},
"materialConsumed": [
{
"name": "Copper concentrate",
"originCountry": {
"countryCode": "ZM",
"countryName": "Zambia"
},
"massFraction": 0.85,
"mass": {
"value": 420000000,
"unit": "KGM"
}
},
{
"name": "Coke (reducing agent)",
"originCountry": {
"countryCode": "AU",
"countryName": "Australia"
},
"massFraction": 0.1,
"mass": {
"value": 50000000,
"unit": "KGM"
}
}
]
},
"performanceClaim": [
{
"type": [
"Claim"
],
"id": "https://sample-refinery.example.com/claims/recycled-2024",
"name": "Recycled Content",
"chainOfCustodyMethod": "mass-balance",
"conformityTopic": [
{
"type": [
"ConformityTopic"
],
"id": "https://test.uncefact.org/vocabulary/conformity-topics/recycled-material-integration",
"name": "Recycled Material Integration"
}
],
"claimedPerformance": [
{
"metric": {
"type": [
"PerformanceMetric"
],
"id": "https://vocabulary.uncefact.org/performance-metrics/recycled-content-percentage",
"name": "Recycled Content Percentage"
},
"measure": {
"value": 12,
"unit": "P1"
}
}
]
}
]
}
}

Key observations: The credentialSubject is a Facility directly. Uses materialUsage to report aggregate material consumption for the reporting period. Uses performanceClaim with claimedPerformance for facility-level metrics. The relatedDocument array (not shown) links to the Copper Mark DCC.

Example 3: DTE Move Event (Shipping)​

Purpose: Material flows between facilities (accounting analogy: ledger transactions)

An EPCIS ObjectEvent records the physical movement of material between facilities. epcList identifies what moved, sourceList and destinationList where it moved between, and bizStep what the movement was.

Excerpted from DigitalTraceabilityEvent_container_leaves_refinery_instance.json.

{
"type": [
"DigitalTraceabilityEvent",
"VerifiableCredential"
],
"id": "https://credentials.sample-refinery.example.com/dte/ship-container-2025-0322",
"issuer": {
"type": [
"CredentialIssuer"
],
"id": "did:web:sample-refinery.example.com",
"name": "Sample Copper Refinery Co. Ltd"
},
"credentialSubject": [
{
"type": "ObjectEvent",
"eventID": "https://sample-refinery.example.com/events/ship-container-2025-0322",
"eventTime": "2025-03-22T14:00:00Z",
"action": "OBSERVE",
"bizStep": "departing",
"epcList": [
"urn:carrier:sea-freight:container:SFCU3054383"
],
"sourceList": [
{
"type": "location",
"source": "https://facility-register.example.com/fac-002"
},
{
"type": "possessing_party",
"source": "did:web:sample-refinery.example.com"
}
],
"destinationList": [
{
"type": "location",
"destination": "https://facility-register.example.com/fac-003"
},
{
"type": "possessing_party",
"destination": "did:web:sample-battery.example.com"
}
]
}
]
}

Key observations: credentialSubject is an array, so one credential may carry several events. action: "OBSERVE" says the event observes existing objects rather than creating or destroying them. The counterparty issues its own arrival event, and reconciliation uses both.

Example 4: DTE Make Event (Production Run)​

Purpose: Material transformation (accounting analogy: ledger transactions)

An EPCIS TransformationEvent records a production process that consumes inputs and creates outputs. inputQuantityList and outputQuantityList carry the quantities on which all reconciliation depends.

Excerpted from DigitalTraceabilityEvent_concentrate_smelted_into_anodes_instance.json.

{
"type": [
"DigitalTraceabilityEvent",
"VerifiableCredential"
],
"id": "https://credentials.sample-refinery.example.com/dte/smelt-anodes-2025-0305",
"issuer": {
"type": [
"CredentialIssuer"
],
"id": "did:web:sample-refinery.example.com",
"name": "Sample Copper Refinery Co. Ltd"
},
"credentialSubject": [
{
"type": "TransformationEvent",
"eventID": "https://sample-refinery.example.com/events/smelt-anodes-2025-0305",
"eventTime": "2025-03-05T06:00:00Z",
"bizStep": "creating_class_instance",
"bizLocation": {
"id": "https://facility-register.example.com/fac-002"
},
"inputQuantityList": [
{
"epcClass": "https://id.sample-mine.example.com/product/cu-conc-2025/batch/2025-Q1-4501",
"quantity": 30000,
"uom": "KGM"
},
{
"epcClass": "https://id.sample-refinery.example.com/product/cu-scrap-2025/batch/2025-Q1-0301",
"quantity": 1200,
"uom": "KGM"
}
],
"outputQuantityList": [
{
"epcClass": "https://id.sample-refinery.example.com/product/cu-anode-2025/batch/2025-Q1-0805",
"quantity": 10100,
"uom": "KGM"
}
]
}
]
}

Key observations: The balance holds on contained metal, not gross mass. 30,000 kg of concentrate at roughly 30% copper gives about 9,000 kg contained, plus 1,200 kg of scrap, against 10,100 kg of anodes out. The remainder is slag and process loss.

An auditor checking this needs the grade of each input, which comes from the input product's DPP rather than from the event.

Example 5: DCC for Independent Mass Balance Assurance​

Purpose: Verified conformance and assessed performance metrics (accounting analogy: audited accounts)

The DCC is issued by an independent auditor after verifying the facility's material accounting. It communicates assessed conformance and performance metrics WITHOUT revealing commercially sensitive stock and flow data.

Excerpted from ConformityCredential_smelter_instance.json.

{
"type": [
"DigitalConformityCredential",
"VerifiableCredential"
],
"id": "https://credentials.sample-cab.example.com/dcc/smelter-002",
"issuer": {
"type": [
"CredentialIssuer"
],
"id": "did:web:sample-cab.example.com",
"name": "Sample Conformity Assessment Body"
},
"credentialSubject": {
"type": [
"ConformityAttestation"
],
"id": "https://coppermark-cab.example.com/attestation/CM-SG-2025-002",
"assessorLevel": "third-party",
"assessmentLevel": "authority-derived",
"attestationType": "certification",
"conformityAssessment": [
{
"type": [
"ConformityAssessment"
],
"id": "https://coppermark-cab.example.com/assessment/CM-SG-2025-002-GHG",
"name": "GHG Emissions Assessment (Criteria 26, 27)",
"conformance": true,
"assessmentDate": "2025-01-12",
"chainOfCustodyMethod": "mass-balance",
"conformityTopic": [
{
"type": [
"ConformityTopic"
],
"id": "https://test.uncefact.org/vocabulary/conformity-topics/greenhouse-gas-emissions",
"name": "Greenhouse Gas Emissions"
}
],
"assessedFacility": [
{
"facility": {
"type": [
"Facility"
],
"id": "https://facility-register.example.com/fac-002",
"name": "Sample Copper Refinery",
"registeredId": "fac-002"
},
"idVerifiedByCAB": true
}
],
"assessedPerformance": [
{
"metric": {
"type": [
"PerformanceMetric"
],
"id": "https://vocabulary.uncefact.org/performance-metrics/scope-1-ghg-emissions",
"name": "Scope 1 GHG Emissions"
},
"measure": {
"value": 120000,
"unit": "TNE"
}
}
]
}
]
}
}

Key observations:

  • Uses ConformityAttestation as the credential subject (not Attestation)
  • Uses conformityAssessment array (not assessment)
  • Uses assessedPerformance with metric references from the UNTP performance metrics vocabulary (not declaredValue/assessmentCriteria)
  • assessmentLevel is authority-derived, and the authorisation chain links to the scheme authority whose endorsementType is authority-benchmark
  • Each assessment has assessedFacility with idVerifiedByCAB: true confirming the auditor verified facility identity
  • Hides commercially sensitive information (stock levels, flow quantities, supplier identities) while providing verified performance metrics
  • Downstream buyers can use the conformityTopic and assessedPerformance to match against corresponding performanceClaim entries in DPPs and DFRs