ESG management for enterprises, funds and financial institutions
Most organisations discover what ESG management is at the worst possible moment: three weeks before a deadline, when someone asks where a number came from and nobody can say.
That question is the whole subject. Reporting is what leaves the organisation. Management is what lets you answer for it afterwards.
Request a demo





Start with what the letters actually ask of you
ESG stands for environmental, social and governance, and almost everyone knows that much. The more useful thing to understand is why each pillar behaves differently once you try to measure it.
Environmental
The most measurable pillar and the most argued about. Emissions, energy, water, waste, materials. The numbers exist, but so do six defensible ways to calculate them, and the one you pick in year one is the one you are stuck explaining in year four.
Social
Harder for a different reason. Workforce, health and safety, human rights, communities, suppliers. Much of it sits outside your finance systems, and a good deal of it sits outside your organisation entirely, in the hands of people who have no obligation to give it to you.
Governance
The pillar that decides whether the other two can be believed. Board oversight, ethics, remuneration, controls. It is also the pillar auditors look at first, because it tells them how much to trust everything else.
What has changed in the past few years is not the vocabulary. It is the standard of proof. ESG began as a screening language for investors. It is now assessed by people who apply the evidence standards of financial reporting to it.
In Japan, sustainability disclosures sit inside the annual securities report and carry the same legal weight as the financial statements. In Australia, the sustainability report goes to the corporate regulator with a directors’ declaration attached. You can no longer answer the question with a definition. You have to answer it with a record.






Structured definition of ESG management
What ESG management actually is
ESG management is the internal control system used to define, collect, verify, consolidate and release environmental, social and governance data.
The part that matters more is that it has an order to it, and most organisations build it backwards.
We describe it in five layers. We put governance at the bottom because that is where it belongs structurally, even though it is almost always the last thing anyone gets to. Teams start at the top, with the disclosure, because that is where the deadline lives. Then they do the whole thing again the following year, because nothing underneath it was ever built.
How does it leave the organisation?
Without it: every framework becomes its own manual project
How do entities roll up?
Without it: double counting, or a subsidiary quietly missing
Where does the raw input come from?
Without it: numbers nobody can trace back
How exactly is it calculated?
Without it: two sites reporting the same metric differently
Who is accountable for this number?
Without it: nobody signs off, so nobody checks
A quick diagnostic
Look at layer two. Ask two entities in your group how they calculate the same indicator. If the answers differ and neither is written down anywhere, you have a definition problem, and it will surface as a consolidation problem later.
The terms people mix up
| Term | What it refers to |
|---|---|
| ESG management | The control system that produces the data |
| ESG reporting | What you publish from it |
| ESG strategy | What you have committed to achieving |
| ESG ratings | What third parties calculate about you, mostly from what you have already published |
| CSR | An earlier, largely narrative practice. ESG is measured, comparable and increasingly assured. The two are not the same activity wearing different clothes |
ESG Management System vs. Evolving Regulations (CSRD, ISSB)
Why this matters
Companies that built their ESG strategy strictly around the initial 2024 CSRD drafts spent subsequent years constantly redesigning them.
Consider what actually happened. The European Union narrowed its reporting scope substantially and then cut its own disclosure standards by more than sixty per cent. The United States moved to withdraw a federal climate rule it had already adopted, while California carried on regardless. Japan took a published standard and turned it into binding law. Australia moved a second wave of companies into scope. More than thirty jurisdictions adopted a common global baseline for the first time.
Four directions of travel, across four major reporting regimes, in just a few years.
Now consider what did not change. Every one of those regimes still wants to know your emissions, your workforce data, your supply chain exposure and how your board oversees the lot. Every one still expects you to be able to show your working. The organisations that came through this period without drama were not the ones who guessed the politics correctly. They were the ones who had built a system, adjusted their scope, and carried on.
Consider how rapidly the regulatory landscape shifts across key jurisdictions:
EU
Narrowed reporting scope & cut standards by over 60%.
US & California
Federal rule withdrawn, local mandates continued.
Japan & Australia
Turned guidelines into binding law and expanded company scope.
Regulations change. The underlying data needs (emissions, supply chain risk, board oversight) do not.
The disclosure obligation is variable; the control system is not.
Regulatory landscape by jurisdiction
Where disclosure is actually required
Global regulatory convergence is accelerating. Requirements differ in scope across regions but share common characteristics: standardisation, traceability, and accountability.
What follows is a snapshot, verified against primary and official sources on 7 August 2026. Treat it as a map rather than advice, and check the row that applies to you against the regulator before you act on it. These things move.
Europe
The European position settled in 2026 after two years of genuine uncertainty, and it settled smaller than anyone expected in 2024.
| Instrument | Where it stands |
|---|---|
| CSRD, as amended by Omnibus I Directive (EU) 2026/470 | In force 18 March 2026. Applies where an undertaking exceeds both €450 million net turnover and an average of 1,000 employees. Both thresholds, not either. Listed SMEs are out of mandatory scope entirely. Transposition by 19 March 2027, reporting for financial years beginning on or after 1 January 2027 |
| ESRS (2026) | Delegated act adopted 3 July 2026. The Commission reports mandatory datapoints down by over 60%, total datapoints by over 70%, and reporting costs expected to fall by over 30% per company. The sector-specific standards mandate was deleted. Currently under a two-month scrutiny period, extendable by two more. Applies from FY2027, early application allowed for FY2026. Double materiality is unchanged |
| Voluntary Standard formerly VSME | Adopted the same day under new Article 29ca, based on Commission Recommendation (EU) 2025/1710. Gives companies outside mandatory scope a standard way to answer requests |
| Value chain cap | Protected undertakings, meaning those at or below 1,000 employees in a reporter’s value chain, may decline requests exceeding the Voluntary Standard. Contract terms saying otherwise are not binding. Reporters may rely on a supplier’s own declaration of size |
| Assurance | The move to reasonable assurance was dropped. Limited assurance only, with the standards themselves now due by 1 July 2027 rather than 1 October 2026 |
| CSDDD, as amended | Thresholds up to 5,000 employees and €1.5 billion. Application from 26 July 2029. The climate transition plan obligation was repealed, and the EU-wide civil liability regime removed, replaced by a maximum penalty of 3% of net worldwide turnover |
| Third-country groups | Threshold raised from €150 million to €450 million EU turnover, with an EU subsidiary or branch above €200 million |
| SFDR and EU Taxonomy | Both in force. Financial market participants continue to report Principal Adverse Impact indicators. SFDR reform is under discussion |
The provision nobody is talking about
New Articles 29e and 29f require the Commission to build a reporting portal and to report by 19 March 2028 on technological solutions for collecting, processing and exchanging sustainability data automatically, naming harmonised digital formats, minimum interoperability requirements and common data exchange infrastructure. European law has started specifying the plumbing, not just the output.
United States
The American picture is the most confusing one to explain to a board, because the federal and state positions are moving in opposite directions.
| Jurisdiction | Where it stands |
|---|---|
| United States, federal | The climate rules the SEC adopted in March 2024 never took effect. The Commission proposed full rescission on 29 May 2026, Release 33-11421, File S7-2026-19, and the status on sec.gov is still “Proposed Rule”. Note what this does not mean: materiality-based disclosure obligations and the Commission’s 2010 climate guidance are untouched and still apply |
| California | SB 253 covers US-organised entities above $1 billion revenue doing business in California, requiring annual Scope 1 and 2 disclosure. CARB set the first deadline at 10 August 2026, withdrew the regulation from OAL on 24 June, and on 27 July proposed moving it to 10 November, with comments closing 11 August. SB 261, covering entities above $500 million, is enjoined by the Ninth Circuit, though CARB’s voluntary docket stays open to 31 December 2026 |
| Canada | CSDS 1 and CSDS 2 have been available since December 2024 and remain voluntary. The Canadian Securities Administrators paused mandatory rulemaking on 23 April 2025. Federally regulated financial institutions are on a separate track under OSFI Guideline B-15 |
If you take one thing from this section, take this: a US company with no federal obligation may still be reporting in California, and almost certainly is answering European or Japanese customers who do have one.
Asia-Pacific
This is the region most European companies underestimate, and it is where the clearest movement towards mandatory, assured reporting has happened.
| Jurisdiction | Where it stands |
|---|---|
| Japan | SSBJ Standards issued March 2025. The FSA amended the Cabinet Office Ordinance in February 2026, making them legally mandatory for TSE Prime Market issuers through the annual securities report. Phased by average market capitalisation: ¥3 trillion and above from the year ending 31 March 2027, ¥1 trillion from 2028, ¥500 billion from 2029. Below that is still under consideration. Assurance follows a year behind each tier |
| Australia | Legislated into the Corporations Act 2001 through the Treasury Laws Amendment Act 2024, applying AASB S2. Group 1 from financial years commencing on or after 1 January 2025. Group 2 from 1 July 2026, which is now live. Group 3 from 1 July 2027. The report goes to ASIC with a directors’ declaration, and limited assurance applies from the first period |
| Hong Kong | HKEX Part D of the ESG Reporting Code, aligned to IFRS S2, effective for financial years from 1 January 2025. Main Board issuers on comply-or-explain from FY2025, but LargeCap Index constituents fully mandatory from FY2026, Scope 3 included. GEM voluntary. The government roadmap targets full HKFRS S1 and S2 adoption by 2028 |
| Singapore | ISSB-informed rather than directly adopted, delivered through SFRS(I) S1 and S2 and the SGX Listing Rules. All listed issuers report Scope 1 and 2 from FY2025, and STI constituents add Scope 3 from FY2026. ACRA and SGX RegCo revised the roadmap in August 2025, pushing large non-listed companies, above S$1 billion revenue and S$500 million assets, out to FY2030 |
Global baseline standards
The IFRS Foundation reports that 39 jurisdictions have decided to use, or are taking steps to introduce, ISSB Standards or standards based on them, covering around 60% of global GDP and over 40% of global market capitalisation. IFRS S1 and S2 apply financial materiality only, which is the main structural difference from the European approach.
GRI remains the most widely used voluntary standard for impact reporting. SASB’s industry metrics are now maintained under the ISSB. TCFD’s recommendations live on inside IFRS S2, UK SRS S2 and HKEX Part D, which is why you still see the four-pillar structure everywhere.
| Jurisdiction | Where it stands |
|---|---|
| IFRS S1 and IFRS S2 ISSB, 2023 | The global baseline. 39 jurisdictions using or moving towards adoption. Financial materiality only |
| GRI Standards | Widely used worldwide for impact reporting. Voluntary |
| SASB Standards | Industry-specific metrics, maintained under the ISSB |
| TCFD | Recommendations incorporated into IFRS S2, UK SRS S2 and HKEX Part D |
| United Kingdom | UK SRS S1 and S2, the UK-endorsed versions of IFRS S1 and S2, were published on 25 February 2026 and are available for voluntary use. The FCA consulted through CP26/5, which closed on 20 March 2026, proposing mandatory reporting for certain listing categories for accounting periods beginning on or after 1 January 2027. A policy statement is expected in autumn 2026. Application to private companies is being handled separately under the Modernising Corporate Reporting programme |
Three things worth knowing before you assess your own scope
Your head office address does not decide this
Companies get captured through subsidiaries, branches, listings and turnover generated inside a jurisdiction. Under the amended CSRD, a third-country group is in scope at €450 million EU turnover with an EU subsidiary or branch above €200 million. Work it out entity by entity.
There are two materiality models in play, not one
Europe requires double materiality, meaning both how sustainability affects you financially and how you affect people and the environment. The ISSB baseline requires only the first. If you operate under both, you need one dataset that can support two assessments. Running two processes is how teams end up with two sets of numbers.
The value chain cap is narrower than most commentary suggests
This one is worth reading twice. The cap applies only to information gathering for the purpose of CSRD sustainability reporting. It does not touch due diligence obligations under Union law, and it does not touch requests made for risk management, procurement or any other purpose. A supplier who is protected for one purpose can still be asked for exactly the same data for another. We have seen this misread in both directions already.
Why ESG management is necessary
Even where ESG disclosure is not legally mandatory, structured ESG management provides strategic and financial value.
Capital access
Banks, private equity funds and institutional investors increasingly require ESG due diligence. Structured ESG data improves transparency and financing conditions.
Risk mitigation
Climate transition risk, supply chain disruption, labour compliance and governance failures create financial exposure. System-based ESG management reduces unmanaged risk.
Operational efficiency
Monitoring energy, emissions, waste and workforce metrics enables cost optimisation and performance benchmarking.
Long-term strategy
ESG management integrates sustainability objectives into measurable KPIs with board-level accountability.
How Generation Impact Global enables ESG management
Generation Impact Global provides a structured ESG and impact data management and regulatory reporting platform for enterprises, funds and financial institutions.
Governed data collection
- Role-based access control (Super Admin, Admin, Entity Users)
- Pre-built regulatory-aligned questionnaires
- Customisable data fields
- Validation rules and logic checks
- Centralised document repository
- Complete audit logs
Data inputs are permission-controlled and traceable.








Multi-tier consolidation
- Supports complex structures:
- Group → Holding → Fund → Portfolio Company
- Consolidation at any level
- Prevention of double counting
- Automatic recalculation of KPIs
- This is critical for:
- SFDR Principal Adverse Impact monitoring
- ESRS group reporting
- Cross-border financial structures
Regulatory mapping engine
- Each KPI can be mapped to:
- ESRS disclosure requirements
- SFDR PAI indicators
- EU Taxonomy alignment criteria
- GRI disclosures
- IFRS S1 and IFRS S2
- Structured data can be transformed into disclosure-ready outputs without manual reconciliation.








KPI logic and methodology control
- Configurable formulas
- Intensity metrics (e.g., emissions per revenue, per FTE)
- Threshold monitoring (e.g., Do No Significant Harm limits)
- Methodology version control
- Distinction between reported and inferred data
- Consistency across reporting periods is preserved.
Audit and supervisory readiness
- The system records:
- User activity
- Submission timestamps
- Approval and review workflows
- Supporting evidence attachments
- This supports regulatory supervision, external assurance and internal audit processes.




ESG risk, and why registers usually fail
ESG risk management means identifying, measuring and monitoring the sustainability exposures that can affect your financial position, your operations or your licence to operate. Four categories behave differently enough to be worth separating.
Transition risk
Policy, technology and market shifts. Carbon pricing, product bans, procurement standards.
Physical risk
Acute events and chronic conditions, reaching your suppliers’ sites as well as your own.
Value chain risk
Forced labour, deforestation, sanctions exposure and single-source dependency.
Governance and conduct risk
The internal one: weak oversight, misstatement, greenwashing exposure, control failure.
Most ESG risk registers we see are perfectly sensible documents that do nothing, and the reason is always the same. They are maintained separately from the reporting data. A risk you cannot quantify cannot be monitored, and a risk quantified on a spreadsheet cannot be evidenced when someone asks. The register only starts working when it draws on the same indicators, the same entities and the same evidence as your disclosures.
The stakes here have risen quietly. In Australia, misleading climate statements carry penalties under the Corporations Act and directors can be personally liable. The distance between a risk register and a legal exposure is shorter than it was.
What ratings actually measure
A question we get often: our rating went down, what happened?
Usually nothing happened. ESG ratings are produced by third parties using different methodologies, weightings and materiality assumptions, which is why the same company can hold very different scores from different agencies. Three things are worth understanding before you spend money on improving one.
Ratings are built from what you have already published
Where your disclosure has gaps, most providers estimate, and estimates tend to be conservative.
Consistency is scored in its own right
A figure that moves between publications without explanation is penalised, even when the new figure is more accurate.
Scores are not comparable across providers
Each one only means something relative to its own scale and peer group.
Which leads to the useful conclusion. Improving a rating is rarely a communications exercise. It comes from closing disclosure gaps, applying methodology consistently across periods, and being able to explain a restatement when you make one. All three are management outputs.
ESG Data Ownership: Streamlining Cross-Functional Collaboration
In our experience ESG management fails on ownership far more often than on technology. Here is a workable allocation.
Role
What they own
Board or supervisory body
Approving the sustainability statement and overseeing material risks. In several jurisdictions this now carries a formal declaration
Finance
Consolidation logic, restatement policy, the reporting calendar
Sustainability or ESG lead
Methodology, materiality, framework mapping
Operations and site managers
Primary data entry and the evidence behind it
Risk and compliance
The risk register and the regulatory scope assessment
IT and information security
Access control, retention, system integrity
Internal audit or external assurance
Testing the controls, not the narrative
There is a simple test. If one person holds four of these, you do not have a control system. You have a bottleneck with a job title.
When spreadsheets stop being enough
We should be fair to spreadsheets. They are not the wrong tool because they are unsophisticated. Plenty of excellent ESG work has been done in them. They are the wrong tool at scale because they have no concept of permission, version or evidence, and those three things are exactly what assurance tests.
What you need
In a spreadsheet
In a managed system
Data entry
Anyone with the file
Role-based permissions by entity
Methodology
A formula copied between tabs
Version-controlled calculation logic
Evidence
Somewhere else, if anywhere
Attached to the datapoint
Consolidation
Manual, redone every cycle
Rules-based across the hierarchy
Double counting
Risk of double counting
Prevented by hierarchy rules
Change history
Overwritten
Timestamped and attributable
Reuse across frameworks
Rebuilt each time
One dataset, mapped outward
Assurance
Reconstructed afterwards
Available on request
The threshold arrives at one of four moments, and you will recognise yours: a second reporting framework, a second legal entity, the first assurance requirement, or the first restatement nobody can explain.
How we approach it
The principle behind our platform is simple to state and quite hard to build. Collect a datapoint once, with its evidence attached, and map it outward to every framework that needs it.
Structure, permission and evidence
Underneath all of it sits the structure: group, holding, fund and portfolio company hierarchies, consolidation at any level, rules that stop double counting before it happens. Access is role-based. Every submission, approval and amendment is timestamped and attributable. Evidence attaches to the datapoint rather than living in a folder somebody has to go and find.
We are ISO 27001 certified, hold a GRI licence, and are members of Swiss Sustainable Finance, the Swiss Association for Standardization and Eurosif, and a Friend of EFRAG.
Cross-framework interoperabilityIf you are starting from scratch
This order is deliberate. Each step depends on the one before it, and skipping ahead is the most expensive mistake we see.
01
Confirm scope first
Which entities, which jurisdictions, which obligations, which period. Do it entity by entity, not at group level.
02
Run materiality before anything else
Decide what matters and write down why. Everything downstream inherits from this.
03
Fix definitions before you collect a single figure
Calculation, unit, boundary, source, for every indicator. This is the step everyone wants to skip and the one that causes the most rework.
04
Assign one named owner per indicator, per entity
Not a department. A person.
05
Collect with evidence attached at the point of entry
Going back for it later costs several times more.
06
Set consolidation rules once
Hierarchy and elimination logic, agreed and documented.
07
Then map to frameworks
One dataset, mapped outward to each standard that asks.
08
Build for assurance from the first cycle
Even if nobody is assuring you yet. Retrofitting an audit trail is the most expensive thing on this list.
Build the system, not the report
We work with enterprises, financial institutions, SMEs and marketplaces across jurisdictions. If any of the above sounds like where you are, we are happy to talk it through.
Frequently Asked Questions
What is ESG management?
ESG management is the internal control system you use to define, collect, verify, consolidate and disclose environmental, social and governance data. It covers accountability, methodology, evidence, approval and framework mapping.
Is ESG management mandatory?
Disclosure is, in a lot of places now. In the EU you need to exceed both 1,000 employees and €450 million net turnover to fall within the amended CSRD. Japan has made ISSB-based disclosure legally binding for its largest Prime Market issuers, and Australia has done the same through the Corporations Act. The IFRS Foundation counts 39 jurisdictions using or moving towards ISSB Standards. Management itself is never mandatory. It is just what makes the mandatory part survivable.
What is the difference between ESG management and ESG reporting?
ESG management refers to the internal data governance and control system.
ESG reporting refers to the external disclosures derived from that system.
You can complete a report by hand once. Management is what makes it repeatable, comparable and auditable.
What software is used for ESG management?
ESG management software typically provides:
- Structured data collection
- Multi-entity consolidation
- KPI calculation engines
- Regulatory mapping
- Audit-ready documentation
Generation Impact Global provides an ESG and impact data management and regulatory reporting platform for enterprises, funds and financial institutions operating across jurisdictions.
The rules are being relaxed. Do we still need this?
Scope narrowed in some places and widened in others. Europe lowered its assurance ceiling to limited assurance and cut its datapoint count by more than sixty per cent, while Japan and Australia went the other way and introduced binding requirements with assurance attached. What did not change anywhere is the evidence requirement. Fewer datapoints is not less rigour on the ones that remain.
Did the 2026 simplification make reporting easier?
Lighter, not simpler. There is less to disclose. Double materiality, the assessment methodology and the traceability expectation are all unchanged. The voluminous part got smaller. The difficult part did not.
What is the value chain cap?
A statutory limit on what a CSRD reporter can ask of a smaller supplier. Companies at or below 1,000 employees outside mandatory scope can decline requests that go beyond the Voluntary Standard, and contract terms saying otherwise are not binding. It applies to CSRD reporting only, not to due diligence or other purposes.
What is double materiality?
Assessing both how sustainability matters affect you financially and how you affect people and the environment. Europe requires both. The ISSB baseline requires only the financial view.
Will better management improve our rating?
Usually, yes, but indirectly. Ratings are built from published data, and providers estimate where you have gaps. Closing gaps and applying methodology consistently is what moves the number. Describing the same results differently is not.
How long does this take?
One entity, one framework, and you can reach a controlled process inside a single reporting cycle. A multi-entity group across several frameworks should plan for two, with materiality, definitions and hierarchy settled before the first collection round.






