ESG management for enterprises, funds and financial institutions

Most organisations discover what ESG management is at the worst possible moment: three weeks before a deadline, when someone asks where a number came from and nobody can say.

That question is the whole subject. Reporting is what leaves the organisation. Management is what lets you answer for it afterwards.

Request a demo

ESG stands for environmental, social and governance, and almost everyone knows that much. The more useful thing to understand is why each pillar behaves differently once you try to measure it.

Environmental

The most measurable pillar and the most argued about. Emissions, energy, water, waste, materials. The numbers exist, but so do six defensible ways to calculate them, and the one you pick in year one is the one you are stuck explaining in year four.

Social

Harder for a different reason. Workforce, health and safety, human rights, communities, suppliers. Much of it sits outside your finance systems, and a good deal of it sits outside your organisation entirely, in the hands of people who have no obligation to give it to you.

Governance

The pillar that decides whether the other two can be believed. Board oversight, ethics, remuneration, controls. It is also the pillar auditors look at first, because it tells them how much to trust everything else.

What has changed in the past few years is not the vocabulary. It is the standard of proof. ESG began as a screening language for investors. It is now assessed by people who apply the evidence standards of financial reporting to it.

In Japan, sustainability disclosures sit inside the annual securities report and carry the same legal weight as the financial statements. In Australia, the sustainability report goes to the corporate regulator with a directors’ declaration attached. You can no longer answer the question with a definition. You have to answer it with a record.

What ESG management actually is

ESG management is the internal control system used to define, collect, verify, consolidate and release environmental, social and governance data.

The part that matters more is that it has an order to it, and most organisations build it backwards.

We describe it in five layers. We put governance at the bottom because that is where it belongs structurally, even though it is almost always the last thing anyone gets to. Teams start at the top, with the disclosure, because that is where the deadline lives. Then they do the whole thing again the following year, because nothing underneath it was ever built.

5
Disclosure

How does it leave the organisation?

Without it: every framework becomes its own manual project

4
Consolidation

How do entities roll up?

Without it: double counting, or a subsidiary quietly missing

3
Collection

Where does the raw input come from?

Without it: numbers nobody can trace back

2
Definition

How exactly is it calculated?

Without it: two sites reporting the same metric differently

1
Governance

Who is accountable for this number?

Without it: nobody signs off, so nobody checks

A quick diagnostic

Look at layer two. Ask two entities in your group how they calculate the same indicator. If the answers differ and neither is written down anywhere, you have a definition problem, and it will surface as a consolidation problem later.

The terms people mix up

TermWhat it refers to
ESG managementThe control system that produces the data
ESG reportingWhat you publish from it
ESG strategyWhat you have committed to achieving
ESG ratingsWhat third parties calculate about you, mostly from what you have already published
CSRAn earlier, largely narrative practice. ESG is measured, comparable and increasingly assured. The two are not the same activity wearing different clothes

Why this matters

Companies that built their ESG strategy strictly around the initial 2024 CSRD drafts spent subsequent years constantly redesigning them.

Consider what actually happened. The European Union narrowed its reporting scope substantially and then cut its own disclosure standards by more than sixty per cent. The United States moved to withdraw a federal climate rule it had already adopted, while California carried on regardless. Japan took a published standard and turned it into binding law. Australia moved a second wave of companies into scope. More than thirty jurisdictions adopted a common global baseline for the first time.

Four directions of travel, across four major reporting regimes, in just a few years.

Now consider what did not change. Every one of those regimes still wants to know your emissions, your workforce data, your supply chain exposure and how your board oversees the lot. Every one still expects you to be able to show your working. The organisations that came through this period without drama were not the ones who guessed the politics correctly. They were the ones who had built a system, adjusted their scope, and carried on.

Consider how rapidly the regulatory landscape shifts across key jurisdictions:

EU

Narrowed reporting scope & cut standards by over 60%.

US & California

Federal rule withdrawn, local mandates continued.

Japan & Australia

Turned guidelines into binding law and expanded company scope.

Where disclosure is actually required

Global regulatory convergence is accelerating. Requirements differ in scope across regions but share common characteristics: standardisation, traceability, and accountability.

What follows is a snapshot, verified against primary and official sources on 7 August 2026. Treat it as a map rather than advice, and check the row that applies to you against the regulator before you act on it. These things move.

The European position settled in 2026 after two years of genuine uncertainty, and it settled smaller than anyone expected in 2024.

InstrumentWhere it stands
CSRD, as amended by Omnibus I
Directive (EU) 2026/470
In force 18 March 2026. Applies where an undertaking exceeds both €450 million net turnover and an average of 1,000 employees. Both thresholds, not either. Listed SMEs are out of mandatory scope entirely. Transposition by 19 March 2027, reporting for financial years beginning on or after 1 January 2027
ESRS (2026)Delegated act adopted 3 July 2026. The Commission reports mandatory datapoints down by over 60%, total datapoints by over 70%, and reporting costs expected to fall by over 30% per company. The sector-specific standards mandate was deleted. Currently under a two-month scrutiny period, extendable by two more. Applies from FY2027, early application allowed for FY2026. Double materiality is unchanged
Voluntary Standard
formerly VSME
Adopted the same day under new Article 29ca, based on Commission Recommendation (EU) 2025/1710. Gives companies outside mandatory scope a standard way to answer requests
Value chain capProtected undertakings, meaning those at or below 1,000 employees in a reporter’s value chain, may decline requests exceeding the Voluntary Standard. Contract terms saying otherwise are not binding. Reporters may rely on a supplier’s own declaration of size
AssuranceThe move to reasonable assurance was dropped. Limited assurance only, with the standards themselves now due by 1 July 2027 rather than 1 October 2026
CSDDD, as amendedThresholds up to 5,000 employees and €1.5 billion. Application from 26 July 2029. The climate transition plan obligation was repealed, and the EU-wide civil liability regime removed, replaced by a maximum penalty of 3% of net worldwide turnover
Third-country groupsThreshold raised from €150 million to €450 million EU turnover, with an EU subsidiary or branch above €200 million
SFDR and EU TaxonomyBoth in force. Financial market participants continue to report Principal Adverse Impact indicators. SFDR reform is under discussion

New Articles 29e and 29f require the Commission to build a reporting portal and to report by 19 March 2028 on technological solutions for collecting, processing and exchanging sustainability data automatically, naming harmonised digital formats, minimum interoperability requirements and common data exchange infrastructure. European law has started specifying the plumbing, not just the output.

The American picture is the most confusing one to explain to a board, because the federal and state positions are moving in opposite directions.

JurisdictionWhere it stands
United States, federalThe climate rules the SEC adopted in March 2024 never took effect. The Commission proposed full rescission on 29 May 2026, Release 33-11421, File S7-2026-19, and the status on sec.gov is still “Proposed Rule”. Note what this does not mean: materiality-based disclosure obligations and the Commission’s 2010 climate guidance are untouched and still apply
CaliforniaSB 253 covers US-organised entities above $1 billion revenue doing business in California, requiring annual Scope 1 and 2 disclosure. CARB set the first deadline at 10 August 2026, withdrew the regulation from OAL on 24 June, and on 27 July proposed moving it to 10 November, with comments closing 11 August. SB 261, covering entities above $500 million, is enjoined by the Ninth Circuit, though CARB’s voluntary docket stays open to 31 December 2026
CanadaCSDS 1 and CSDS 2 have been available since December 2024 and remain voluntary. The Canadian Securities Administrators paused mandatory rulemaking on 23 April 2025. Federally regulated financial institutions are on a separate track under OSFI Guideline B-15

If you take one thing from this section, take this: a US company with no federal obligation may still be reporting in California, and almost certainly is answering European or Japanese customers who do have one.

This is the region most European companies underestimate, and it is where the clearest movement towards mandatory, assured reporting has happened.

JurisdictionWhere it stands
JapanSSBJ Standards issued March 2025. The FSA amended the Cabinet Office Ordinance in February 2026, making them legally mandatory for TSE Prime Market issuers through the annual securities report. Phased by average market capitalisation: ¥3 trillion and above from the year ending 31 March 2027, ¥1 trillion from 2028, ¥500 billion from 2029. Below that is still under consideration. Assurance follows a year behind each tier
AustraliaLegislated into the Corporations Act 2001 through the Treasury Laws Amendment Act 2024, applying AASB S2. Group 1 from financial years commencing on or after 1 January 2025. Group 2 from 1 July 2026, which is now live. Group 3 from 1 July 2027. The report goes to ASIC with a directors’ declaration, and limited assurance applies from the first period
Hong KongHKEX Part D of the ESG Reporting Code, aligned to IFRS S2, effective for financial years from 1 January 2025. Main Board issuers on comply-or-explain from FY2025, but LargeCap Index constituents fully mandatory from FY2026, Scope 3 included. GEM voluntary. The government roadmap targets full HKFRS S1 and S2 adoption by 2028
SingaporeISSB-informed rather than directly adopted, delivered through SFRS(I) S1 and S2 and the SGX Listing Rules. All listed issuers report Scope 1 and 2 from FY2025, and STI constituents add Scope 3 from FY2026. ACRA and SGX RegCo revised the roadmap in August 2025, pushing large non-listed companies, above S$1 billion revenue and S$500 million assets, out to FY2030

GRI remains the most widely used voluntary standard for impact reporting. SASB’s industry metrics are now maintained under the ISSB. TCFD’s recommendations live on inside IFRS S2, UK SRS S2 and HKEX Part D, which is why you still see the four-pillar structure everywhere.

JurisdictionWhere it stands
IFRS S1 and IFRS S2
ISSB, 2023
The global baseline. 39 jurisdictions using or moving towards adoption. Financial materiality only
GRI StandardsWidely used worldwide for impact reporting. Voluntary
SASB StandardsIndustry-specific metrics, maintained under the ISSB
TCFDRecommendations incorporated into IFRS S2, UK SRS S2 and HKEX Part D
United KingdomUK SRS S1 and S2, the UK-endorsed versions of IFRS S1 and S2, were published on 25 February 2026 and are available for voluntary use. The FCA consulted through CP26/5, which closed on 20 March 2026, proposing mandatory reporting for certain listing categories for accounting periods beginning on or after 1 January 2027. A policy statement is expected in autumn 2026. Application to private companies is being handled separately under the Modernising Corporate Reporting programme

Your head office address does not decide this

Companies get captured through subsidiaries, branches, listings and turnover generated inside a jurisdiction. Under the amended CSRD, a third-country group is in scope at €450 million EU turnover with an EU subsidiary or branch above €200 million. Work it out entity by entity.

There are two materiality models in play, not one

The value chain cap is narrower than most commentary suggests

This one is worth reading twice. The cap applies only to information gathering for the purpose of CSRD sustainability reporting. It does not touch due diligence obligations under Union law, and it does not touch requests made for risk management, procurement or any other purpose. A supplier who is protected for one purpose can still be asked for exactly the same data for another. We have seen this misread in both directions already.

Assess your readiness

Even where ESG disclosure is not legally mandatory, structured ESG management provides strategic and financial value.

Capital access

Banks, private equity funds and institutional investors increasingly require ESG due diligence. Structured ESG data improves transparency and financing conditions.

Risk mitigation

Climate transition risk, supply chain disruption, labour compliance and governance failures create financial exposure. System-based ESG management reduces unmanaged risk.

Operational efficiency

Monitoring energy, emissions, waste and workforce metrics enables cost optimisation and performance benchmarking.

Long-term strategy

ESG management integrates sustainability objectives into measurable KPIs with board-level accountability.

Generation Impact Global provides a structured ESG and impact data management and regulatory reporting platform for enterprises, funds and financial institutions.

Governed data collection

  • Role-based access control (Super Admin, Admin, Entity Users)
  • Pre-built regulatory-aligned questionnaires
  • Customisable data fields
  • Validation rules and logic checks
  • Centralised document repository
  • Complete audit logs

Data inputs are permission-controlled and traceable.

Multi-tier consolidation

  • Supports complex structures:
    • Group → Holding → Fund → Portfolio Company
    • Consolidation at any level
    • Prevention of double counting
    • Automatic recalculation of KPIs
  • This is critical for:
    • SFDR Principal Adverse Impact monitoring
    • ESRS group reporting
    • Cross-border financial structures

Regulatory mapping engine

  • Each KPI can be mapped to:
    • ESRS disclosure requirements
    • SFDR PAI indicators
    • EU Taxonomy alignment criteria
    • GRI disclosures
    • IFRS S1 and IFRS S2
  • Structured data can be transformed into disclosure-ready outputs without manual reconciliation.

KPI logic and methodology control

  • Configurable formulas
  • Intensity metrics (e.g., emissions per revenue, per FTE)
  • Threshold monitoring (e.g., Do No Significant Harm limits)
  • Methodology version control
  • Distinction between reported and inferred data
  • Consistency across reporting periods is preserved.

Audit and supervisory readiness

  • The system records:
    • User activity
    • Submission timestamps
    • Approval and review workflows
    • Supporting evidence attachments
  • This supports regulatory supervision, external assurance and internal audit processes.

ESG risk management means identifying, measuring and monitoring the sustainability exposures that can affect your financial position, your operations or your licence to operate. Four categories behave differently enough to be worth separating.

Transition risk

Policy, technology and market shifts. Carbon pricing, product bans, procurement standards.

Physical risk

Acute events and chronic conditions, reaching your suppliers’ sites as well as your own.

Value chain risk

Forced labour, deforestation, sanctions exposure and single-source dependency.

Governance and conduct risk

The internal one: weak oversight, misstatement, greenwashing exposure, control failure.

Most ESG risk registers we see are perfectly sensible documents that do nothing, and the reason is always the same. They are maintained separately from the reporting data. A risk you cannot quantify cannot be monitored, and a risk quantified on a spreadsheet cannot be evidenced when someone asks. The register only starts working when it draws on the same indicators, the same entities and the same evidence as your disclosures.

The stakes here have risen quietly. In Australia, misleading climate statements carry penalties under the Corporations Act and directors can be personally liable. The distance between a risk register and a legal exposure is shorter than it was.

A question we get often: our rating went down, what happened?

Usually nothing happened. ESG ratings are produced by third parties using different methodologies, weightings and materiality assumptions, which is why the same company can hold very different scores from different agencies. Three things are worth understanding before you spend money on improving one.

Ratings are built from what you have already published

Where your disclosure has gaps, most providers estimate, and estimates tend to be conservative.

Consistency is scored in its own right

A figure that moves between publications without explanation is penalised, even when the new figure is more accurate.

Scores are not comparable across providers

Each one only means something relative to its own scale and peer group.

Which leads to the useful conclusion. Improving a rating is rarely a communications exercise. It comes from closing disclosure gaps, applying methodology consistently across periods, and being able to explain a restatement when you make one. All three are management outputs.

In our experience ESG management fails on ownership far more often than on technology. Here is a workable allocation.

Board or supervisory body

Approving the sustainability statement and overseeing material risks. In several jurisdictions this now carries a formal declaration

Finance

Consolidation logic, restatement policy, the reporting calendar

Sustainability or ESG lead

Methodology, materiality, framework mapping

Operations and site managers

Primary data entry and the evidence behind it

Risk and compliance

The risk register and the regulatory scope assessment

IT and information security

Access control, retention, system integrity

Internal audit or external assurance

Testing the controls, not the narrative

We should be fair to spreadsheets. They are not the wrong tool because they are unsophisticated. Plenty of excellent ESG work has been done in them. They are the wrong tool at scale because they have no concept of permission, version or evidence, and those three things are exactly what assurance tests.

Data entry

Methodology

Evidence

Consolidation

Double counting

Change history

Reuse across frameworks

Assurance

The threshold arrives at one of four moments, and you will recognise yours: a second reporting framework, a second legal entity, the first assurance requirement, or the first restatement nobody can explain.

The principle behind our platform is simple to state and quite hard to build. Collect a datapoint once, with its evidence attached, and map it outward to every framework that needs it.

VitAI

Icon representing QB-EDGE, a tool for creating and managing questionnaires by Generation Impact Global

QB-EDGE

QB-EDGE
Icon representing the Utility Management Tool for tracking consumption by Generation Impact Global

UtilityIQ

Utilityiq

Double Materiality Assessment

Double Materiality Double Materiality ESRS Compliance Guide
Icon representing the Due Diligence Tool for sustainability assessment by Generation Impact Global

Supply chain and due diligence

Powered by Morpheus.Network, extending visibility past your legal entity boundary into supplier data and logistics records.

TCFD

Icon representing the SDG Mapper for analyzing sustainable development content by Generation Impact Global

SDG Mapper

SDG Mapper SDG Mapper
Cross-framework interoperability

This order is deliberate. Each step depends on the one before it, and skipping ahead is the most expensive mistake we see.

Confirm scope first

Which entities, which jurisdictions, which obligations, which period. Do it entity by entity, not at group level.

Run materiality before anything else

Decide what matters and write down why. Everything downstream inherits from this.

Fix definitions before you collect a single figure

Calculation, unit, boundary, source, for every indicator. This is the step everyone wants to skip and the one that causes the most rework.

Assign one named owner per indicator, per entity

Not a department. A person.

Collect with evidence attached at the point of entry

Going back for it later costs several times more.

Set consolidation rules once

Hierarchy and elimination logic, agreed and documented.

Then map to frameworks

One dataset, mapped outward to each standard that asks.

Build for assurance from the first cycle

Even if nobody is assuring you yet. Retrofitting an audit trail is the most expensive thing on this list.

Build the system, not the report

We work with enterprises, financial institutions, SMEs and marketplaces across jurisdictions. If any of the above sounds like where you are, we are happy to talk it through.

What is ESG management?

Is ESG management mandatory?

What is the difference between ESG management and ESG reporting?

What software is used for ESG management?

  • Structured data collection
  • Multi-entity consolidation
  • KPI calculation engines
  • Regulatory mapping
  • Audit-ready documentation

The rules are being relaxed. Do we still need this?

Did the 2026 simplification make reporting easier?

What is the value chain cap?

What is double materiality?

Will better management improve our rating?

How long does this take?

Subscribe to our Newsletter!

The latest news and events related to impact, risk, and sustainability around the world.

Privacy policy provides additional information on how your data is processed.