Architecture Proof · Claim #3 · Methane MRV

Methane reconciled, then restated, on OSDU

A source-level methane inventory reconciled against a site-level measurement per ISO 25624-1 — verified on a live OSDU platform, then formally restated after the standard's own worked anomaly: an unlit flare caught as a super-emitter.

Site MRV-01 · NorthField gas processing (synthetic) Standard ISO 25624-1:2026 · OGMP 2.0 · EU 2024/1787 Platform cimpl-stack OSDU v0.31.0 Date 08 Sep 2026
DRAFTUNDER REVIEW VERIFIEDSUSPENDEDRESTATED

A five-source bottom-up inventory (156,300 kg CH₄) reconciled within 8.5% of a drone-flux top-down measurement and was verified Gold-Standard. A subsequent re-survey caught an unlit flare at 600 kg/h; instantaneous reconciliation failed at 97%, the plan was suspended, the 72-hour episode was annualized (+27% — above the 5% materiality threshold), and the inventory was formally restated, re-reconciling at 6.8%. Every step ran against real OSDU services with immutable versioning.

12 + 28
methane kinds + OFP domain kinds via the ofp-schema-deploy pipeline
6/6
reconciliation-gate constraints at verification
+27%
restatement — above the 5% materiality threshold
240
OFP records across five data domains, 18/18 FK hops resolved

Lifecycle

The Monitoring Plan state machine, on OSDU record versioning

ISO 25624-1 §5.1 requires a formal Monitoring Plan where verification is needed. Here it is the certifiable wrapper; each transition is a distinct immutable OSDU version.

draftv1 · periodic underReviewv2 · periodic verifiedv3 · gate 6/6 ✓ suspendedv4 · eventDriven restatedv5 · corrective super-emitter ISO 12.3
MethaneMonitoringPlan · osdu:work-product-component--MethaneMonitoringPlan

Bottom-up · ISO Formula (1)

Source-level inventory: E = Σ EFi × Ni × ti

Five representative sources from the ISO Clause 6 taxonomy, each quantified by a method and OGMP level chosen by materiality (§8): material sources at L4, the 2.8% fugitives legitimately on a generic factor at L3.

SourceISO categoryMethodLevelkg CH₄ / yr
Flare stack (98% DRE)flaringdirect measurementL496,000
Intermittent pneumatics ×40ventingPneumaticemission factorL417,520
Compressor rod-packing ×2ventingCompressorReciprocatingdirect measurementL419,200
Engine slip ×3 (CEMS)incompleteCombustiondirect measurementL419,200
Leaking connectors ×25fugitivegeneric EFL34,380
Bottom-up total · 4,376 t CO₂e @ GWP100 = 28156,300
Top-down (ISO Clause 7). Drone flux survey (CRDS): 19.5 kg/h instantaneous → 170,820 kg/yr annualized, with expanded uncertainty U = k·u = 24% (k = 2, ≈95% confidence, §9.5.3).

Reconciliation gate · ISO Clause 11

Six constraints, at verification and on the anomaly

The gate is the SysML methane constraint block, each clause traced to the standard. Verification was issued only because all six held.

ConstraintEvidenceAt verifyOn anomaly
SiteLevelReconciliation (11)|BU−TD|/TD: 8.5% ≤ 20% → 97.1% instantaneousPASSFAIL
GoldStandardCoverage (OGMP 2.0)L4/L5 coverage 97.2% ≥ 95%PASSPASS
MaterialityRigor (8, F.25)material sources at L4+; finding +27% > 5%PASSRESTATE
MethaneLeakDetectionThreshold19.5 kg/h ≥ LoQ 0.5 kg/hPASSPASS
EmissionRateAccuracy (9)flare 3.3% ≤ 10% (L4)PASSPASS
ReportingFrequency (EU 2024/1787)4 quarterly LDAR surveysPASSPASS

Anomaly & restatement · ISO 11.3 · 12.3

The standard's own worked example, reproduced

ISO 25624-1 cites an unlit flare releasing raw gas as the archetypal reconciliation discrepancy. The cascade follows its Figure 1 workflow to a formal restatement.

Super-emitter

Unlit flare (DRE = 0): 600 kg/h raw gas, > 100 kg/h threshold

Re-reconcile · 11.3.1

Instantaneous 17.8 vs 607.5 kg/h — 97% divergence, class C

Plan

verified → suspended; attestation suspended

Annualize · 6.3.4.3

72 h from last credible lit data: +42,336 kg CH₄

Restatement · 12.3

+27% of inventory > 5% materiality → formal restatement

Re-reconciled

198,636 vs 213,156 kg/yr — 6.8% ✓ · plan restated · attestation re-issued

Trust layer

Attestation bound to the plan hash

A VerifiableCredential (issuer did:web:dveracity.com, Ed25519 proof) is bound to the Monitoring Plan's SHA256 and carries the ISO expanded uncertainty as its confidence basis. It tracked the lifecycle exactly: issued → suspended → re-issued on the restated hash — three immutable versions.

OFP data domains · canonical model

The same proof, expressed in the Open Footprint domains

The methane kinds above are dVeracity's SysML view. To make claim #3 an OFP-conformant emissions data flow, the proof was re-expressed across five OFP data domains on the canonical kinds — 28 additional kinds registered through the same OFP→OSDU pipeline as the original load, 240 records forming one connected graph, and the Monitoring Plan versioned once more to point at it.

OFP domainWhat carries the methane storyRecordsKinds
Organizational Structure / Boundaryoperator with an LEI (OrganizationExternalIdentifier), operational-control boundary (OrganizationControl), verifier organization and its lead verifier119
Facility Structuresite → two process units (FacilityStructure), location, one EquipmentInstallation per methane source, compliance requirements for EU 2024/1787 and OGMP 2.03113
RecordingISO Formula (1) as an EmissionCalculationFormula with EF / N / t components; per source a model, three arguments, three argument values, an EmissionStatement and its uncertainty; the top-down and aggregate statements13526
Reportingthe OGMP 2.0 annual EmissionReport, period, reporting boundary, per-standard references (ISO, OGMP, EU), seven statements-per-report with facility allocations, a reasonable-assurance ReportingAssurance218
Data Verificationthe six gate constraints as DataQualityRules in one DataQualityRuleSet; every gate run as DataQuality assessments evaluated against the methane records — verify 100%, anomaly 83.3% (SiteLevelReconciliation = 0), restated 100%; the dVeracity attestation as an OFP VerifiableCredential4211

Resolved by foreign key through the OSDU Search API, 18 of 18 hops.

Chain A · recording

Report ⋈ flare statement → model → ISO Formula (1) → Standard ISO 25624-1

Chain A · structure

statement → activity → process unit → site → operator → LEI · operational control

Chain B · assurance

ReportingAssurance → verifier organization → lead verifier (ISO 14065)

Chain B · verification

rule set → the one DataQuality with score 0 → SiteLevelReconciliation → the evaluated methane record

Loaded the canonical way. The 28 kinds were generated and registered by the repo's ofp-schema-deploy pipeline (generate_domain_schemas.py + register_schemas.sh domains): kind id, group and version are the Hackolade collection's own id — the same field the original mapping took its ids from — e.g. reference-data--DataQualityRule:4.0.0, master-data--OrganizationExternalIdentifier:4.0.0; OFP's transactional-data becomes work-product-component:1.0.0 per the EmissionStatement precedent. One entity with no canonical id in the model (OrganizationPersonAssociation) was skipped rather than invented.

Evidence ledger · portable

What was stored, and where it lives now

Every record and version history was exported from OSDU to JSON committed in this repository — 342 record bodies, 515 version bodies and all 158 schemas — so the proof outlives the environment. The console beside this report replays that bundle.

MethaneSourceInventory6
EmissionQuantification8
MethaneSourceCategory (ISO ref-data)6
MethaneDetectionEvent2
LDARSurveyRecord1
MethaneAlertEvent1
ReconciliationResult2
OGMPReport2
MethaneMonitoringPlan1 (25 vers)
MethaneAttestation1 (14 vers)
OFPAdjustmentRecord1
OFP domain graph (5 domains, 67 kinds)240
Traceability. The seven activity records were generated from the dVeracity SysML v2 model (03_types_items.sysml, x-dve-sysml-source); the three reference-data kinds carry x-dve-clause pointers into ISO 25624-1. Reproducible via run_all.sh; verifiable offline via verify_export.py (23 checks, no network).

Caveats & provenance

  • SyntheticThe site and its numbers are illustrative, chosen to exercise the standard's own worked anomaly — not measured data. The LEI is not a registered identifier.
  • Draft stdISO 25624-1:2026 was read from a supplied draft; clause numbers may shift at publication.
  • ScopeSite-level reconciliation (§11.3.1) only; population reconciliation, the full GUM Type A/B machinery and the 17 per-source methods were deliberately not modeled.
  • RegistryTwo earlier passes registered domain kinds with hand-assigned versions and groups before the pipeline was used; OSDU cannot delete schemas, so 41 orphan kinds remain unused on that stack (listed in ofp-schema-deploy/ORPHANED_KINDS.md; 158 ofp kinds in total). Records on the pipeline kinds are the ones the plan links to.
  • VersionsThe plan accumulated 25 versions and the attestation 14; the proof lifecycle is plan v1–v5 plus the OFP grounding, the rest came from interactive write-action testing. Every version is exported verbatim.
  • VerifiedSchema registration, the lifecycle, the cascade, the OFP graph traversal and the version histories were observed live on the cimpl-stack dev OSDU before it was decommissioned.