CBAMReturn

The CBAM account

A system of record for your CBAM year, not another spreadsheet.

The free tools on this site answer a question and forget your data. The account is where the year actually gets done: the ledger that is re-tested monthly, the evidence an inspector will ask for, the people who need to see it, and a record of everything that happened. Free founding access now; £149/month from January 2027.

Organisation

One organisation, the right people, the right permissions

Finance, ops and your customs broker all need the same numbers. An organisation holds the ledgers, records and history; people join it by email invitation with a role.

  • Owner, editor and viewer roles — viewers see everything and change nothing
  • Invitations by email, seven-day expiry, withdrawable; the last owner can never be removed
  • Brokers run each client as its own workspace and switch between them — client staff can be invited in as viewers of their own data only

Position

One statutory test on the whole organisation, not on a file

Save each customs export as it arrives (CSV or Excel, any broker's layout; we ask once about unfamiliar columns and remember the answer). Every file joins one consolidated position, de-duplicated by customs reference, priced with every usable supplier declaration in your vault, and re-tested on the 1st of every month.

  • The rolling 12-month test and the 30-day forward test, on the legal entity as the Act requires
  • Disregard lines the rules let you disregard (returned goods, temporary admission, undischarged special procedures), correct codes, all audited
  • Return preview shaped per the made regulations: per 8-digit code, weight, relief, place of origin, with what is still missing flagged
  • Declarant-versus-importer check on every line, because the liable person is the importer of record

Suppliers

A register, a portal, a verifier record and the relief you are owed

Every supplier named across every ledger, once. Send each a private upload link (reminders at 7, 14 and 21 days), record who verified their data and under what accreditation, and enter any overseas carbon price the installation bore so relief is applied per line and capped at the charge.

  • Files are checked on upload; usable ones land in your vault against the right line and move the status
  • Relief workspace covers HMRC's sixteen recognised schemes, with the evidence document attached
  • A needs-attention list on the account home, and the same list by email every Monday

Records vault

The evidence, kept with the numbers, provably unchanged

HMRC expects records kept for six years. Every invoice, customs declaration, supplier emissions file and verification report goes in against the supplier line it supports, and is checksummed on the way in.

  • SHA-256 recorded at upload — recompute over the file six years later to prove integrity
  • Completeness view per supplier line: what is on file, what an inspector would still ask for
  • PDF, CSV, Excel, Word, XML, JSON, images and email files; 25 MB each

Supplier portal

Suppliers upload to you, and the file is checked before you ever see it

One private link per supplier line. The supplier downloads the template, uploads the completed file, and the parser judges it on the spot: a usable file lands in your vault against that line, moves the chase status and emails you; an unusable one tells the supplier exactly what to fix.

  • Links last 60 days and can be emailed from the account or pasted into your own message
  • Verified declarations are recognised and marked as such; unverified data is accepted and flagged for chasing
  • Every upload, usable or not, is in the audit trail

Threshold monitor

Told before you cross the line, not after

Every save, re-run and monthly run classifies each ledger against the £50,000 threshold. When a ledger moves into approaching (80%) or triggered, owners and editors get one email saying what it means and what to do; the audit trail records it.

  • Peak rolling covered value and percentage of threshold on every ledger
  • Registration deadline computed the moment a trigger date appears

Portfolio and statement

Every organisation on one screen; a dated statement for anyone who asks

Brokers see every client's threshold position, indicative liability, supplier-data coverage and records on file in one table. Any owner can print a dated position statement for the board, the auditor or the bank.

  • Portfolio rows are strictly scoped by membership
  • The statement is recorded in the audit trail each time it is generated

Audit trail

Who did what, when — append-only

Every sign-in, save, re-run, upload, download, role change and export is written to an audit log the organisation can read and export. Nothing in it can be edited.

  • Actor, action, target, IP and timestamp on every entry
  • Readable in the account by every member; included in the export

Export

Everything you hold, in one zip, any day

Owners can download the whole organisation: every ledger with its latest report, supplier statuses, every vault document with its checksum, the member list and the audit log. No notice, no ticket, no lock-in.

  • A manifest ties every file to its SHA-256
  • The export itself is audited

Security

Two-step verification and control over signed-in devices

A leaked password or a forwarded sign-in email should not be enough on its own. Turn on an authenticator app and every new device must pass it; see each signed-in device and sign any of them out — or all of them at once.

  • TOTP with any authenticator app (Google, Microsoft, 1Password, Authy) plus one-time recovery codes
  • Device list with IP and last-seen; per-device sign-out; sign out everywhere
  • Sign-in by password or by emailed link; passwords are optional and bcrypt-hashed

How it is run

  • Engine and site are gated by automated tests on every change — 96 engine tests, 30 unit tests, and a 150-check end-to-end suite that drives sign-in, roles, ledgers, the position, suppliers, the vault, export, sessions and two-step verification against a real database and engine
  • A read-only partner API (position and portfolio) with per-organisation keys; a public security page and security.txt
  • Nightly backups of the accounts database and the records vault; a pre-deploy dump before every release; restore rehearsed
  • Uptime checked every five minutes; application errors captured and reviewed weekly
  • Rules watch: eight primary sources fingerprinted twice a week; every figure on the site traces to a dated source

What is deliberately not here yet

The return itself waits for HMRC to publish the filing format; the return preview, registration pack and relief working are computed today and will be filed from here when it does. Passkeys, automatic ingestion of customs entries from your broker's platform, and card billing (from January 2027) are next and are being shaped with founding partners this autumn. We would rather you know that than discover it.

Questions, or something you need that is not listed: hello@cbamreturn.co.uk.