Category: CSRD

  • ESRS-40a: CSRD Is Back for Non-EU Parent Companies

    For eighteen months, the message reaching boardrooms in New York, London, Zurich and Singapore has been reassuringly simple: the Omnibus package gutted CSRD, our European subsidiaries fell out of scope, file closed. For the EU entities, broadly true. What it missed is that the obligation did not disappear — it moved up the corporate structure, to the non-EU parent.

    On 23 July 2026, EFRAG published the Exposure Draft of ESRS-40a — the sustainability reporting standard for certain non-EU undertakings — and opened a 100-day consultation running to 31 October 2026. It implements Article 40a of the Accounting Directive, and applies a test with nothing to do with how many people you employ in Europe. If your group sells enough into the EU, you report.


    What ESRS-40a actually is

    Articles 19a and 29a of the Accounting Directive catch EU companies and EU-parented groups. Article 40a is the extraterritorial arm: it catches groups headquartered outside the EU that do significant business inside it. ESRS-40a is the standard telling them what to disclose, and the logic is a level playing field — a US or Japanese group booking hundreds of millions in EU revenue competes with EU companies carrying a full ESRS burden.


    The scope test: run it before you do anything else

    The threshold is two-part, and both parts must be met. A third-country undertaking not listed on an EU regulated market is in scope if it meets:

    • Turnover test. Net turnover in the Union above €450 million in each of the last two consecutive financial years; and
    • Presence test. Either an EU branch with net turnover above €200 million in the preceding financial year, or it is the ultimate parent of EU subsidiaries with net turnover above €200 million in the preceding financial year.

    These behave differently from the tests your European finance team has been applying: no employee headcount criterion, no balance-sheet criterion. It is a revenue test measured at group level on turnover booked in the Union — so a group with modest European operations and a lean legal footprint can still clear the bar on distribution revenue alone.

    Who actually publishes the report

    The parent is the reporting undertaking, but it does not file. The report is published on the parent’s behalf by an EU subsidiary that would itself fall within CSRD scope, or by a large EU branch. That puts a European entity — often one with no sustainability function of its own — on the hook for making a group-level disclosure public. Flag it early to your European legal and finance leads: the people who sign and file are rarely the people who produce the data.


    What you report — and, importantly, what you don’t

    ESRS-40a is deliberately lighter than a full ESRS sustainability statement. The Article 40a report focuses on impacts — the effects of the group’s activities on people and the environment. It generally excludes the risk-and-opportunity architecture Articles 19a and 29a demand: resilience analysis, dependencies, and the financial-materiality half of double materiality sit outside its content.

    For teams that have watched EU peers build scenario analysis and transition plans, that is good news. But narrower is not easier — the hard part of ESRS-40a is not the disclosure list. It is the boundary.


    The “mixed approach” is the fight that decides your cost

    This is the detail that deserves attention during the consultation window. The draft requires a blend of EU-scoped and global-scoped information — some disclosures drawn from the group’s European activities, others from the group as a whole.

    EFRAG’s own Sustainability Reporting Board did not approve this comfortably. It released the Exposure Draft while recording reservations about the mixed approach, and Chair Kerstin Lopatta published a letter setting out those concerns before launch, noting the approach reflects a request from the European Commission. The objection is practical as much as legal: separating EU-related impacts from global ones is difficult, and in places arbitrary.

    For a reporting team, that is not standard-setting politics — it is the single biggest driver of your data-collection cost. A global-scope disclosure can usually be sourced from systems you already run. An EU-scope disclosure means carving European activity out of consolidated data — by site, by entity, by supplier — for metrics your systems were never designed to slice that way. Every requirement landing on the EU-scoped side adds a pipeline you do not have.

    Which is why the consultation matters. Feedback closes 31 October 2026 and EFRAG’s technical advice goes to the Commission in January 2027. After that, the boundary question is settled and you are implementing someone else’s answer.


    The timeline looks distant. It isn’t.

    Reporting becomes mandatory for financial years beginning on or after 1 January 2028, with first reports published in 2029. Three years is comfortable — right up until you work backwards.

    • 2029 — first report published.
    • FY2028 — the reporting year. Data must be complete, consistent and evidenced across twelve months, from day one.
    • FY2027 — the dry run: find the gaps in EU-scoped data and fix them. Anyone through a first ESRS cycle knows this year is not optional.
    • 2026–2027 — scoping, system selection, and getting European entities collecting data in a form that consolidates.

    That leaves roughly eighteen months of genuine slack, not three years — landing on organisations that spent the last year actively de-resourcing European sustainability compliance.


    Why the scope cut makes this more exposing, not less

    EFRAG has estimated that the Omnibus changes cut the number of non-EU companies in scope from roughly 10,000 to around 1,200 — a 90% reduction, reported as relief. Consider it from the other direction: the remaining population is small, large and identifiable. Any regulator, NGO or journalist can assemble a credible list of who should be reporting and check whether they did. In a group of 10,000, a thin disclosure is noise. In a group of 1,200, it is a story.

    This is the same pattern we described when the SEC’s climate rollback failed to free US multinationals: deregulation in one jurisdiction rarely reduces total disclosure obligation for a global group. It relocates it.


    What to do before 31 October

    • Run the test properly. Get an accurate group-level figure for net turnover in the Union for the last two financial years. Not EU-entity revenue — turnover generated in the Union, which can include sales routed through non-EU entities.
    • Identify the filer. Determine which EU subsidiary or branch would carry the publication obligation, and tell them now.
    • Respond to the consultation. If you are in scope, the mixed approach will shape your cost base for a decade. This is the last practical window to influence it.
    • Map EU-scoped data. Take a first pass at which impact metrics you could already report at EU boundary and which need new collection. That gap list is your 2027 project plan.
    • Do not rebuild in a silo. Much of what ESRS-40a asks for overlaps with what you already produce for CDP, ISSB-aligned reporting, or an EU subsidiary’s own CSRD timeline. One data layer with multiple outputs beats a separate European reporting exercise.

    One honest caveat: ESRS-40a is a draft, its content will change before the Commission’s delegated act, and the mixed approach may not survive in its current form. What will not change is the scope test and the FY2028 start date — those sit in the Directive, not the standard. You can wait on the detail. You cannot wait on knowing whether you are in.


    If your group clears the €450 million test, the work starts with knowing what you can already produce at EU boundary. Horizon ESG helps multinational teams collect sustainability data once and report it against multiple frameworks — so a new obligation becomes a mapping exercise, not a new programme. Book a free demo.

  • Data Centres Just Became an ESG Disclosure Risk

    On 14 July 2026, New York became the first US state to slam the brakes on data centre construction. Governor Kathy Hochul signed an executive order barring the Department of Environmental Conservation from issuing discretionary permits for new data centres above 50 MW of power demand for up to a year, while regulators write comprehensive standards from scratch. The trade press read it as an energy-and-AI story. For sustainability teams, it is something else entirely: the moment data centre energy stopped being a line in your Scope 2 footnote and became a strategic disclosure risk your climate reporting has to describe.

    If your business runs a material digital estate — and in 2026 most do — this is the clearest signal yet that compute energy is moving from an efficiency talking point to a permitting, siting, and transition-risk question. The reporting frameworks you already comply with anticipated this. Most disclosures have not caught up.


    What New York actually did

    The order does not ban data centres. It pauses discretionary environmental permitting for the largest facilities — those drawing more than 50 MW, roughly the scale of a hyperscale or large colocation site — for up to twelve months while the state builds a standing regulatory regime. The stated concern is straightforward: surging AI and cloud demand is loading the grid faster than New York can plan for, and the existing permitting process was never designed to weigh that.

    The specifics matter less than the precedent. A US state has now formally treated large-scale compute as an environmental externality worth constraining. That is exactly the kind of policy shift that climate-risk frameworks classify as a transition risk — a change in the regulatory environment that alters the cost, feasibility, or location of your operations. And New York is unlikely to be the last mover; when one jurisdiction sets a template, disclosure-conscious investors start asking every data-centre-intensive issuer the same questions.


    Why this is a disclosure problem, not just an energy one

    Here is the disconnect. Most companies account for data centre electricity as a Scope 2 emissions figure — a number to be measured, reduced, and reported. That framing is correct but incomplete. It captures what your compute emitted last year. It says nothing about whether you can build, power, or expand that compute next year.

    From Scope 2 line item to transition risk

    A permitting moratorium changes the calculus. If a company’s growth assumes new data centre capacity in a jurisdiction that has just paused approvals, that assumption now carries policy risk — potential delay, higher cost, or forced relocation. Under a climate-risk lens, that is a material forward-looking exposure, not a historical emissions total. The same logic extends to grid connection queues, rising industrial power prices, and local opposition, all of which are tightening in the markets where compute demand is highest.

    The physical-risk angle teams forget

    Transition risk is only half the picture. Large data centres are also water-intensive — cooling can consume millions of litres a year — and they concentrate that demand in specific locations. That exposes them to physical climate risk: drought, heat stress, and water-access restrictions that can throttle operations regardless of how clean the power is. A disclosure that reports Scope 2 emissions but ignores where the facilities sit and what they depend on is telling investors half a story.


    What ISSB S2 and ESRS E1 already require

    None of this requires a new rule. The two frameworks most reporters are already inside — IFRS S2 from the ISSB, and ESRS E1 under the CSRD — both demand exactly the forward-looking narrative that data centre exposure calls for.

    • IFRS S2 requires disclosure of the climate-related risks and opportunities that could reasonably affect your prospects, split into transition and physical risk, plus how they feed strategy, financial planning, and resilience under different scenarios. A permitting-constrained compute footprint is a textbook example of what S2 expects you to surface.
    • ESRS E1 requires a transition plan, disclosure of material physical and transition risks, and reporting of energy consumption and mix alongside gross Scopes 1, 2, and 3. The connective tissue between your energy dependency and your strategic resilience is precisely what E1’s risk disclosures are for.

    In other words, the standards already ask the question. New York just made it concrete. For teams still treating climate risk and carbon accounting as separate exercises, this is the argument for joining them up — a theme we explored in our look at how TCFD and CSRD climate disclosure align.


    What a defensible disclosure looks like

    Most current data centre disclosure is boilerplate: an efficiency metric, a PUE figure, maybe a renewable-energy commitment. That is not what a climate-risk framework is asking for. A disclosure that would survive scrutiny does four things:

    • Locates the exposure. Identify where your material compute capacity sits — owned, colocated, or cloud — and flag jurisdictions where permitting, grid access, or water stress is tightening. Generic group-level statements are not enough.
    • Connects energy to strategy. Explain how future capacity needs interact with transition risk. If growth depends on new facilities, say what a permitting delay would mean for the plan.
    • Treats water as a risk, not a footnote. Disclose cooling water dependency in high-stress locations as a physical risk with operational consequences, not just a sustainability metric.
    • Quantifies where it can. Move from “we are committed to efficiency” to ranges, timelines, and scenario-tested impacts. Frameworks reward specificity and penalise vagueness.

    The reporting teams that get ahead of this will not be the ones with the lowest emissions. They will be the ones who can show investors they understand where their digital infrastructure is exposed — and have a credible plan for it. Reliable, location-aware energy and emissions data is the foundation for that; measuring your Scope 1, 2 and 3 footprint accurately is the first step, but connecting it to forward-looking risk is what turns a number into a disclosure.


    Turning compute energy into an audit-ready climate disclosure starts with data you can trust. Horizon ESG helps reporting teams link emissions, energy, and transition-risk narrative in one place — so when the next New York arrives, your disclosure is already ready. Book a free demo to see how.

  • CSRD Value-Chain Cap: What You Can Still Ask Suppliers

    Most of the coverage of the European Commission’s 3 July package led with the same number: a 60% cut in mandatory ESRS datapoints. That is the headline, and it is real. But buried in the second delegated act is a change that will reshape more programmes than the datapoint cut ever will — and almost nobody is briefing their procurement team on it.

    It is called the value-chain cap. In short: from financial year 2027, a CSRD-scope company will no longer be able to require its smaller suppliers to hand over sustainability data beyond a defined ceiling. If your supplier-engagement programme is built on a 200-question ESG questionnaire pushed down the chain, that programme now has a legal boundary running through the middle of it.

    What the Commission adopted on 3 July 2026

    The Commission adopted two delegated acts. The first is the revised set of European Sustainability Reporting Standards — the concrete landing of the Omnibus I simplification agenda. It cuts mandatory datapoints by over 60%, total datapoints by over 70%, and is expected to reduce reporting costs by more than 30% per company.

    The second is the one to read carefully: a Voluntary Sustainability Reporting Standard, built on the VSME, giving companies outside CSRD scope a single proportionate framework to report against. It is voluntary in the sense that no smaller company is obliged to use it. It is emphatically not voluntary in its effect on the companies above them in the chain — because it sets the ceiling.

    Both acts are now in a two-month scrutiny period before the European Parliament and Council, extendable by a further two months. If neither institution objects, they are published in the Official Journal and enter into force. That caveat matters, and we return to it at the end.

    The value-chain cap, precisely

    The cap protects companies with 1,000 employees or fewer that sit in the value chain of a CSRD reporter. Under the Omnibus I Directive, those companies are entitled to decline requests for sustainability information that go beyond what the Voluntary Standard covers. Micro-enterprises of ten employees or fewer get further relief on top. For CSRD-scope companies, the cap bites from financial year 2027.

    Read plainly, that inverts a decade of supplier-engagement practice. The implicit deal until now was that a large buyer could ask its suppliers for whatever its own reporting obligations demanded, and commercial leverage did the rest. From FY2027, the supplier has a statutory answer: no, and here is the standard that says so.

    Three things the cap does not do

    This is where the early commentary is getting it wrong, so it is worth being exact.

    • It caps what you can require, not what you can ask. The Commission has confirmed that a CSRD reporter may still request information beyond the cap — provided it clearly identifies which parts of the request exceed the cap and informs the supplier of their right to refuse. The cap creates a duty of transparency in the ask, not a prohibition on asking.
    • It applies only to CSRD reporting. The cap operates when fulfilling CSRD reporting obligations. It does not govern information you request for other purposes — commercial qualification, contractual assurance, product compliance, or your own risk management.
    • It does not stop a supplier volunteering more. Plenty of smaller suppliers will keep sharing data, because being easy to buy from is a competitive advantage. The cap removes the obligation, not the incentive.

    Together those three points reframe the cap. It is not a wall. It is a consent boundary — and crossing it now requires you to say out loud that you are crossing it.

    Where the cap collides with CSDDD

    Here is the tension nobody has resolved. The Corporate Sustainability Due Diligence Directive still requires in-scope companies to conduct risk-based human rights and environmental due diligence across their chain of activities — an approach Omnibus I preserved rather than narrowing to tier one. You cannot discharge a risk-based due-diligence obligation without information from the chain. Yet the ESRS package has just capped what you may require from a large part of that same chain.

    The reconciliation is in the scoping: the cap is tied to CSRD reporting obligations, and CSDDD due diligence is a separate legal duty. In principle, a due-diligence request is not a CSRD reporting request, and the cap does not extinguish it.

    In practice, that distinction is going to be tested hard — because it is usually the same supplier, receiving the same questionnaire, from the same buyer, in a single email. If your data requests do not distinguish their legal basis, you invite a supplier to refuse the whole thing on cap grounds, including the parts you are entitled to insist on. The operational bar for all of this is still being written: the Commission’s consultation on CSDDD implementation guidelines closes on 24 July 2026, with the guidelines expected in principle by July 2027. If your supplier programme is material to your business, that consultation is a genuine, closing opportunity to shape it.

    What to do in the next 90 days

    FY2027 sounds distant. It is not — supplier programmes have long lead times, and the contracts you sign this year will still be running when the cap bites.

    1. Re-baseline your supplier questionnaire against the Voluntary Standard. Every question you currently push down the chain now sorts into one of two buckets: inside the cap, or outside it. You cannot manage the boundary until you can see it.
    2. Get headcount into your supplier master data. The 1,000-employee line is now a legal boundary, and most procurement systems do not hold supplier headcount at all. This is the least glamorous item on the list and probably the one with the longest lead time.
    3. Redesign the ask, not just the question set. Beyond-cap requests need to be explicitly flagged as such, with the right to refuse stated. Build that into the template now rather than retrofitting it under deadline.
    4. Separate your legal bases. Split CSRD-reporting requests from due-diligence and commercial requests, and label them. This is the single change that most protects your CSDDD position.
    5. Plan for refusal. Assume a meaningful share of smaller suppliers will exercise the cap. That means leaning harder on estimation, sector averages and spend-based proxies for value-chain data — and being able to document why an estimate was used and how it was derived.

    Prepare — but do not decommission

    One final discipline. Both delegated acts are still in scrutiny, and the revised ESRS are set to apply to financial years beginning on or after 1 January 2027, with early application permitted. Nothing is in the Official Journal yet.

    So the correct posture is prepare, don’t freeze — and above all, don’t switch anything off. The most expensive mistake available right now is to read “60% fewer datapoints” as permission to dismantle data pipelines that a scrutiny objection, an early-adoption decision, or an investor’s own SFDR-driven data request could make you rebuild in eighteen months. Simplification is not the same as less work. A 70% datapoint cut creates a migration project before it creates a saving.

    The companies that will handle this well are the ones that can see, in one place, which datapoints they collect, which regime each one serves, and where in the value chain it came from. That is a data-architecture question long before it is a compliance one — and it is exactly what our CSRD readiness checklist is built to help you work through. If you would like to see how Horizon ESG maps a single data foundation across CSRD, CSDDD and the voluntary standard, book a short demo — we will walk your own supplier data through it.

  • Nature Disclosure Is Coming: Get TNFD-Ready by October

    Climate has dominated sustainability disclosure for a decade. Nature is next, and the timetable is now firm. During its June 2026 conference, the IFRS Foundation confirmed that the International Sustainability Standards Board (ISSB) will publish its nature-related disclosure proposals as an exposure draft in October 2026, timed to land ahead of the year’s biodiversity COP. For reporting teams that have spent two years building climate data pipelines, this is the signal to start scoping the next frontier before it becomes mandatory.

    The proposals will take the form of an IFRS Practice Statement rather than a new standalone standard, a route the ISSB agreed in April 2026. That structural choice matters, and it draws heavily on a framework many sustainability teams already recognise: the Taskforce on Nature-related Financial Disclosures (TNFD). Here is what is coming, why it consolidates TNFD as the global baseline, and the practical groundwork worth doing now.

    What the ISSB actually announced

    The October exposure draft will not be a tenth topical standard sitting alongside IFRS S1 and S2. Instead, it will be an IFRS Practice Statement — guidance that helps companies apply the existing ISSB standards, together with the SASB Standards, to nature-related topics. In plain terms, it explains how to surface material nature information using the machinery investors already understand, rather than asking preparers to learn an entirely separate rulebook.

    The scope spans the nature topics that most often drive financial risk: land use, water, pollution, resource use, and biodiversity. These are the areas where dependencies on natural systems — reliable water, healthy soil, stable ecosystems — and impacts on them can translate into cost, disruption, or lost access to markets and finance. And crucially, the ISSB has confirmed the proposals will draw directly on the TNFD framework, giving early TNFD adopters a genuine head start.

    One point deserves emphasis: an exposure draft is a consultation, not a final requirement. The October text will open a comment window before anything is finalised. That is time to prepare, not a reason to wait.

    Why TNFD is becoming the baseline

    TNFD published its final recommendations in September 2023, deliberately mirroring the four-pillar structure — Governance, Strategy, Risk and Impact Management, and Metrics and Targets — that the market already knew from the Task Force on Climate-related Financial Disclosures. That familiarity was the point. Anyone who has produced climate disclosure recognises the shape of a TNFD report immediately.

    The ISSB’s decision to build its nature guidance on TNFD follows the same path climate took. The TCFD recommendations were absorbed into IFRS S2 and the TCFD itself wound down, with its monitoring role passing to the IFRS Foundation. Nature is now travelling that route: a voluntary framework maturing into the reference point for a global, investor-focused standard. For preparers, that convergence is good news — it means the effort you put into TNFD-aligned work is unlikely to be wasted when the ISSB text lands.

    It also connects to obligations some companies already face. Under the CSRD, ESRS E4 requires disclosure on biodiversity and ecosystems where material, so EU-scope reporters are not starting from zero. If you are still mapping what “material” means across environmental and social topics, our guide to double materiality under CSRD is a useful companion, because nature dependencies and impacts sit squarely inside that assessment.

    What nature disclosure asks of you

    Nature reporting differs from climate reporting in one important respect. Greenhouse gases are broadly comparable wherever they are emitted, so a tonne of CO2e is a tonne of CO2e. Nature is local: the same activity can be immaterial at one site and severe at another, depending on the ecosystem around it. That is why TNFD frames the work through its LEAP approach — Locate, Evaluate, Assess, Prepare — which pushes teams to start from where they operate and interface with nature.

    • Locate your interface with nature — the sites, assets, and supply-chain nodes that sit in or near sensitive ecosystems and water-stressed areas.
    • Evaluate your dependencies and impacts at those locations, from water abstraction to land-use change.
    • Assess the resulting risks and opportunities in financial terms your board and investors can act on.
    • Prepare to respond and report, aligning the output with the four disclosure pillars.

    The practical implication is that location-level data — not just enterprise totals — becomes the raw material of a credible nature disclosure. Teams used to reporting a single group emissions figure will need to think at the level of individual sites and suppliers.

    How to get TNFD-ready before October

    You do not need to wait for the exposure draft to make progress. A focused scoping exercise now will make the eventual reporting far less painful:

    • Run a first-pass location screen. Map your operational sites and material suppliers against water stress and biodiversity-sensitivity data to see where nature risk concentrates.
    • Reuse your climate governance. The board oversight and risk processes you built for climate extend naturally to nature; you are adding a topic, not rebuilding the structure.
    • Fold nature into your materiality assessment. Treat dependencies and impacts on nature as candidate material topics in your next review rather than a separate, bolt-on exercise.
    • Audit your data foundations. Location-level, supplier-level detail is harder to assemble than a single carbon figure. Knowing where those gaps are now is worth more than a polished narrative later.
    • Track the convergence. Watch how the ISSB draft aligns with TNFD and ESRS E4 so you build once and disclose against several frameworks.

    Because the ISSB is building on structures the market already uses, the teams that stay closest to their climate disciplines will adapt fastest. If your climate reporting still leans on TCFD-era foundations, our explainer on how TCFD and CSRD align is a helpful reference point for understanding how these frameworks fit together.

    The bottom line

    Nature disclosure is following the same trajectory climate did: a voluntary framework, growing adoption, then absorption into the ISSB baseline. The October exposure draft is the moment that trajectory becomes concrete. Companies that begin locating their nature interface and tightening their data now will meet it as a manageable extension of existing work — not a standing start.

    Horizon ESG helps reporting teams manage climate, CSRD, and emerging nature requirements in one place, so location-level and supplier data feed straight into disclosure rather than living in scattered spreadsheets. Book a short demo to see how we can help you get ahead of the ISSB timeline with clarity.

  • TCFD vs CSRD: What UK Companies Need to Know About Climate Disclosure Alignment

    By Sai Shankar, Guest Author

    For UK companies, climate disclosure now sits at the intersection of two frameworks. TCFD-aligned reporting has been mandatory for large UK companies since April 2022. CSRD, with its European Sustainability Reporting Standards, applies to UK subsidiaries of EU-headquartered groups and to UK-listed companies within the FCA’s aligned disclosure requirements.

    The two frameworks are related, but they are not the same. Treating them interchangeably creates gaps that surface during assurance. Understanding where they align and where they diverge is the starting point for a disclosure programme that satisfies both without duplicating work.

    What TCFD Actually Is

    The Task Force on Climate-related Financial Disclosures published its final recommendations in 2017, structured around four thematic pillars:

    • Governance: the board’s oversight of climate-related risks and opportunities, and management’s role in assessing and managing them
    • Strategy: the actual and potential impact of climate-related risks and opportunities on the business, strategy, and financial planning
    • Risk Management: the processes for identifying, assessing, and managing climate-related risks
    • Metrics and Targets: the metrics and targets used to assess and manage relevant climate-related risks and opportunities, including Scope 1, 2, and where relevant Scope 3 emissions

    The TCFD itself was dissolved in 2023, with its monitoring role transferred to the IFRS Foundation. TCFD’s four-pillar structure was carried directly into IFRS S2 Climate-related Disclosures, which now serves as the international successor standard.

    In the UK, TCFD-aligned reporting has been mandatory since 6 April 2022 for certain categories of large companies, including UK-listed companies, large private companies, and large limited liability partnerships. The requirement sits within the Companies Act framework and forms part of the Strategic Report.

    What CSRD Requires on Climate

    CSRD requires reporting against the European Sustainability Reporting Standards. The climate-related requirements are concentrated in ESRS E1, which is one of the ten topical ESRS and one of the most detailed.

    ESRS E1 covers disclosures across:

    • Transition plan for climate change mitigation
    • Material impacts, risks, and opportunities and their interaction with strategy and business model
    • Policies related to climate change mitigation and adaptation
    • Actions and resources in relation to climate policies
    • Targets related to climate change mitigation and adaptation
    • Energy consumption and mix
    • Gross Scope 1, 2, and 3 emissions and total GHG emissions
    • GHG removals and mitigation projects financed through carbon credits
    • Internal carbon pricing
    • Anticipated financial effects from material physical and transition risks and potential climate-related opportunities

    The structural similarity to TCFD is intentional. The four TCFD pillars are recognisable throughout ESRS E1, and the European Commission has confirmed that CSRD reporting is designed to satisfy TCFD-aligned expectations.

    Where the Two Frameworks Overlap

    The overlap between TCFD and ESRS E1 is substantial. Both require:

    • Board and management oversight of climate matters
    • Description of climate-related risks and opportunities
    • Scenario analysis to assess resilience
    • Metrics and targets, including Scope 1, 2, and material Scope 3 emissions
    • Transition plan disclosure

    For a UK company already producing a TCFD-aligned disclosure, the underlying data and analysis will feed directly into most of the ESRS E1 requirements. The governance narrative, risk identification process, scenario assumptions, and emissions figures are all reusable.

    Where They Diverge

    The differences matter and are the source of most reporting gaps. Four are particularly worth understanding:

    1. Materiality Approach

    TCFD is grounded in financial materiality. It asks how climate-related risks and opportunities affect the business.

    CSRD requires double materiality, which combines financial materiality with impact materiality. The company must disclose not only how climate change affects it, but also how it affects climate change and the wider environment. This significantly expands the scope of what must be reported.

    2. Level of Prescription

    TCFD provides principles-based recommendations. Companies have flexibility in how they interpret and structure their disclosures.

    ESRS E1 is prescriptive. It sets specific datapoints, defined disclosure requirements, and mandatory structures. A TCFD-aligned narrative is a starting point but rarely sufficient to satisfy ESRS E1 datapoint requirements without supplementation.

    3. Assurance

    TCFD disclosures are not subject to a specific assurance requirement in the UK, although they sit within the Strategic Report and are subject to normal audit expectations.

    CSRD requires limited assurance from the outset, moving to reasonable assurance over time. This changes the standard of evidence, documentation, and control that must sit behind the reported numbers.

    4. Scope 3 Treatment

    TCFD recommends Scope 3 disclosure where material. In practice, many UK TCFD disclosures have deferred detailed Scope 3 reporting or have limited it to a small number of categories.

    ESRS E1 requires disclosure of gross Scope 3 emissions across the relevant GHG Protocol categories, with a clear explanation of any category excluded on materiality grounds. The bar for Scope 3 completeness is meaningfully higher.

    The Practical Implication for UK Companies

    For UK companies within scope of both frameworks, the practical question is how to structure the reporting programme to satisfy both without duplication.

    Three principles are useful:

    • Build the data once: structure the underlying data collection to satisfy the more demanding framework (ESRS E1), and derive the TCFD-aligned narrative from the same source
    • Design for assurance from the start: the CSRD assurance requirement effectively sets a documentation standard that TCFD did not require, but that will improve the quality of the TCFD disclosure as a by-product
    • Treat double materiality as the anchoring assessment: conducting the double materiality exercise properly generates the strategic input needed for both frameworks

    A well-designed CSRD programme will produce a defensible TCFD disclosure with limited additional effort. The reverse is rarely true.

    What About IFRS S2?

    IFRS S2, published by the ISSB in 2023, is the international successor to TCFD and forms the basis of the UK’s proposed Sustainability Reporting Standards. The UK Government is expected to endorse UK versions of IFRS S1 and S2, which would in due course replace the current TCFD-aligned disclosure regime.

    For companies currently reporting under TCFD, the transition to UK-endorsed IFRS S2 will be an incremental change rather than a wholesale one. For companies also within CSRD scope, the picture is that both frameworks will continue to apply in parallel, with different materiality approaches and different levels of prescription.

    How Horizon ESG Supports Dual-Track Climate Reporting

    Horizon ESG allows organisations to manage climate disclosure across TCFD, ESRS E1, and IFRS S2 from a single underlying dataset. Teams can:

    • Capture Scope 1, 2, and 3 emissions once and map them to each framework’s specific structure
    • Document governance, strategy, risk management, and metrics narratives with framework tagging
    • Run and store scenario analyses that satisfy both TCFD and ESRS E1 requirements
    • Maintain the double materiality assessment as a live document rather than an annual exercise
    • Generate framework-specific outputs from the same underlying source

    The result is a climate disclosure process that reuses data rather than duplicating it, and that is designed for the assurance standard CSRD demands.

    Getting Started

    If your organisation is producing TCFD disclosures today and preparing for CSRD, this is the right moment to review whether the current data foundation will scale. The answer is often that the underlying methodology is sound but that the documentation and control environment needs strengthening before it will satisfy assurance requirements.

    Book a free ESG reporting software demo to see how Horizon ESG helps teams manage TCFD and CSRD climate disclosure from a single, audit-ready platform.

  • ESRS S1: Reporting on Your Own Workforce Under CSRD

    By Sai Shankar, Guest Author

    The environmental standards under CSRD have attracted the majority of attention so far, and understandably. Carbon accounting is where most organisations start, and ESRS E1 is where most of the technical complexity lives. But for many companies preparing their first sustainability statement, the social standards will be the harder ones to close out.

    ESRS S1, covering own workforce, is the largest and most involved of the four social standards. It touches employment data that sits in HR systems, payroll processes, health and safety records, and diversity monitoring. For companies that have never brought these datasets together for reporting purposes, S1 can be the standard that consumes the most cross-functional time.

    What ESRS S1 Actually Covers

    ESRS S1 addresses the impacts, risks, and opportunities relating to a company’s own workforce. It is structured around four main topics:

    • Working conditions: including secure employment, working time, adequate wages, social dialogue, freedom of association, collective bargaining, work-life balance, and health and safety
    • Equal treatment and opportunities for all: including gender equality and equal pay, training and skills development, employment and inclusion of persons with disabilities, measures against violence and harassment in the workplace, and diversity
    • Other work-related rights: including child labour, forced labour, adequate housing, and privacy
    • Characteristics of the workforce: the demographic breakdown of employees and non-employees, contract types, and geographic distribution

    Crucially, the standard covers not only direct employees but also non-employees in the company’s own workforce. This includes self-employed contractors and workers provided by third-party agencies. The boundary of who counts as own workforce is broader than many organisations initially assume.

    Who ESRS S1 Applies To

    ESRS S1 applies to companies within the scope of CSRD where own workforce topics have been assessed as material through the double materiality assessment. In practice, own workforce impacts and risks are material for almost every company, because employment relationships inherently create actual or potential impacts on workers.

    Materiality determines the specific disclosure requirements that apply, not whether the standard applies at all. Companies concluding that no aspect of ESRS S1 is material should expect that conclusion to face scrutiny during assurance, and they will need to disclose their reasoning.

    The Main Disclosure Requirements

    ESRS S1 includes disclosure requirements covering strategy, policies, actions, targets, and metrics. Some of the most demanding include:

    • Description of the material impacts, risks, and opportunities relating to own workforce and their interaction with strategy and business model
    • Policies related to own workforce, including how the company respects human rights
    • Processes for engaging with own workforce and their representatives
    • Channels for own workforce to raise concerns
    • Actions and resources dedicated to addressing material impacts, risks, and opportunities
    • Targets related to managing material impacts, risks, and opportunities
    • A defined set of workforce characteristics, remuneration, and health and safety metrics

    The metric requirements are where the operational challenge concentrates. They require quantitative data at a level of granularity that many organisations do not currently produce for internal reporting, let alone external disclosure.

    The Quantitative Metrics: Where the Work Sits

    A non-exhaustive summary of the quantitative metrics required under ESRS S1 includes:

    • Workforce characteristics: total number of employees broken down by gender, country, contract type (permanent, temporary), and full-time or part-time status
    • Non-employee workers: the number of non-employees in the company’s own workforce, with a description of the most common types
    • Collective bargaining coverage and social dialogue: the percentage of employees covered by collective bargaining agreements
    • Training and skills development: average training hours per employee, broken down by gender
    • Health and safety: the percentage of workforce covered by the health and safety management system, number of fatalities, recordable work-related accidents and ill health, and days lost
    • Remuneration: the gender pay gap and the ratio of annual total compensation for the highest-paid individual to the median annual total compensation for all other employees
    • Diversity: gender distribution at top management level and age distribution across the workforce
    • Adequate wages: confirmation that all employees are paid at least an adequate wage, benchmarked against applicable reference wages
    • Incidents of discrimination and harassment: including complaints filed, fines, and remediation actions

    Where Organisations Get Stuck

    The most common operational challenges we see with ESRS S1:

    1. Data Ownership Is Fragmented

    Workforce data sits across HR systems, payroll platforms, health and safety records, learning management systems, and diversity monitoring processes. Bringing these together at the level of granularity ESRS S1 requires is a cross-functional exercise that no single team owns by default.

    2. Non-Employees Are Not Systematically Tracked

    Most HR systems are configured for employees. Contractors, agency workers, and self-employed individuals working for the company are often invisible to the core HR data model, yet ESRS S1 requires them to be counted, characterised, and in some cases assessed for exposure to material risks.

    3. Definitions Do Not Match Internal Reporting

    The ESRS definitions of full-time, temporary, and non-employee do not always match how the organisation classifies workers internally. A person recorded as a fixed-term employee for payroll purposes may need to be classified differently under ESRS S1. Building a mapping between internal categories and ESRS categories is a step organisations frequently overlook until data collection is well underway.

    4. Pay Gap Calculations Are Not Straightforward

    Calculating the gender pay gap and the CEO-to-median compensation ratio requires clean, consistent compensation data across the workforce, including bonuses and equity awards where applicable. Many organisations have this data but not in a form that produces a clean, disclosable figure without significant manual reconciliation.

    5. Human Rights Due Diligence Documentation Is Thin

    ESRS S1 assumes that the company has a functioning human rights due diligence process, aligned broadly with the UN Guiding Principles on Business and Human Rights. Where this process exists only informally, the documentation to support the required disclosures typically needs to be built.

    What Assurance Providers Will Look For

    Under CSRD’s limited assurance requirement, an assurance provider will focus on whether the data is complete, whether definitions have been applied consistently, and whether the narrative disclosures are supported by evidence.

    For ESRS S1 specifically, this tends to mean:

    • A clear mapping between the population reported and the underlying HR and payroll data
    • Consistent application of contract type and worker type definitions
    • Documented calculation methodology for pay gap, training hours, and health and safety metrics
    • Evidence of the processes described in the narrative, such as engagement channels and grievance mechanisms
    • A defensible position on the completeness of non-employee data

    The single most common assurance finding on ESRS S1 is inconsistency between how the workforce is defined in the narrative and how it is counted in the metrics. A clear boundary definition, applied consistently, addresses most of the risk.

    How Horizon ESG Supports ESRS S1 Reporting

    Horizon ESG structures ESRS S1 data collection to reduce the cross-functional burden and improve the audit trail. Teams can:

    • Configure ESRS S1 datapoints once and collect against the same structure each reporting cycle
    • Import HR, payroll, and health and safety data through standard file formats
    • Apply and version-control worker classification mappings, so that internal categories map cleanly to ESRS definitions
    • Calculate and store metrics with the underlying data linked, supporting audit reproducibility
    • Document policies, actions, and targets alongside the metrics they support
    • Track incidents and grievances with structured evidence retention

    The result is an ESRS S1 disclosure that is complete, consistent, and defensible under assurance, without requiring the HR and sustainability teams to rebuild the dataset each year.

    A Practical Starting Point

    If ESRS S1 has been deferred while the carbon workstream progresses, this is a good moment to begin the data mapping. The workforce data required is available in most organisations, but assembling it in the form the standard requires takes longer than the reporting timeline usually allows if left too late.

    Book a free ESG software demo to see how Horizon ESG helps teams operationalise ESRS S1 alongside the environmental standards in a single, structured platform.

  • SEC Climate Rollback Won’t Free US Multinationals

    The headlines are tempting: the SEC is moving to scrap the climate-disclosure rules it adopted in 2024, and some commentators have read that as the end of mandatory climate reporting for US companies. For any business with revenue in California or operations in Europe, the opposite is closer to the truth. The federal rule was only ever one of several overlapping regimes — and the others are advancing, not retreating.

    If your reporting plan hinges on the SEC standing down, this is the moment to stress-test it. Below is what is actually happening in Washington, why it changes less than it appears to, and what reporting teams should do while the noise settles.

    What the SEC is actually doing

    On 3 June 2026, the SEC’s proposed rescission of its 2024 climate-related disclosure rules was published in the Federal Register, opening a comment period that runs through 3 August 2026. Two points are easy to miss in the headlines. First, this is a proposal in its comment window, not a settled outcome. Second, the plan is to eliminate the dedicated framework rather than replace it — reverting issuers to principles-based, materiality-focused disclosure under existing securities law. The Commission has pointed to compliance savings of roughly $4.9bn a year.

    Removing a prescriptive rulebook is not the same as removing the obligation to disclose. Material climate risks that affect a reasonable investor’s decision can still require disclosure under long-standing materiality principles. What changes is the how and the how much — not the underlying duty. And for most multinationals, the SEC was never the binding constraint anyway.

    Why “no SEC rule” doesn’t mean “no disclosure”

    Three other regimes keep mandatory climate and greenhouse-gas disclosure firmly alive for US companies of any size that trade across state or national borders. None of them depend on the SEC.

    California: the de facto US standard

    California’s climate-disclosure laws reach far beyond the state’s borders because they apply to companies “doing business in California,” regardless of where they are headquartered. Two statutes matter:

    • SB 253 (Climate Corporate Data Accountability Act) requires companies with total annual revenues above $1bn to report Scope 1, Scope 2 and, in a later phase, Scope 3 greenhouse-gas emissions.
    • SB 261 (Climate-Related Financial Risk Act) requires companies with revenues above $500m to publish a climate-related financial-risk report aligned with the TCFD recommendations.

    Because the revenue thresholds are low relative to the size of a typical multinational, the practical effect is that a large share of US companies that would have reported to the SEC are captured by California instead — and California explicitly requires Scope 3, which the federal approach was always more cautious about. For most large filers, the toughest disclosure bar in the US now sits in Sacramento, not at the SEC.

    The EU: CSRD reaches across the Atlantic

    The EU’s Corporate Sustainability Reporting Directive pulls in non-EU groups through their European operations. A US parent with substantial EU subsidiaries or branches can fall directly within scope, and even companies that sit outside mandatory scope routinely receive value-chain data requests from European customers who need the numbers for their own ESRS reports. The recent “Omnibus” simplification narrowed who must report at the top of the chain, but it did not switch off the demand for emissions and sustainability data flowing down global supply chains.

    In other words, even a US company with no EU listing can find itself assembling ESRS-grade data because a major European buyer asks for it. If you sell into Europe, CSRD is part of your reality whether or not your own name is on a filing.

    The UK: anti-greenwashing and SDR

    For US groups with UK-regulated financial arms, the FCA’s Sustainability Disclosure Requirements regime adds a third layer. Its anti-greenwashing rule applies to all FCA-authorised firms, and from 30 June 2026 the remaining in-scope asset managers above £5bn in assets must publish entity-level disclosures. The throughline is consistent: any claim you make about sustainability has to be substantiated, and the supporting data has to exist.

    Fragmentation, not freedom

    The real consequence of the SEC’s retreat is not less work — it is less harmonisation. A single US-federal climate rule would at least have given multinationals one reference point that broadly tracked the global ISSB and EU baselines. Without it, a company can find itself reconciling California’s emissions thresholds, the EU’s double-materiality model, and the UK’s disclosure expectations, each with its own scope, boundary and timing.

    That is an argument for building disclosure on a single, well-governed dataset rather than chasing each regime with a separate project. The metrics underneath — Scope 1, 2 and 3 emissions, climate risk, governance and targets — overlap heavily. The expensive mistake is collecting them three times.

    What reporting teams should do now

    • Map your real obligations, not the federal one. Test your revenue and operations against California’s SB 253 and SB 261 thresholds and against EU value-chain exposure before assuming the SEC change lets you scale back.
    • Keep your GHG inventory live. Scope 1, 2 and 3 data feeds California, CSRD and customer requests alike, so a robust carbon accounting foundation is the one investment that pays off under every regime.
    • Build once, report many times. Structure your data so a single source can be mapped to multiple frameworks rather than rebuilt for each.
    • Watch the comment window, but don’t wait on it. The SEC proposal closes for comment on 3 August 2026; nothing about that date pauses California or Europe.

    The companies that handle this period well will be the ones that treated the SEC rule as one input among several, not the keystone. The disclosure expectation has not gone away — it has simply spread out, and it now rewards teams with clean, reusable data more than ever.

    Reporting under more than one rulebook? Horizon ESG helps teams collect emissions and sustainability data once and map it to CSRD, California and other frameworks from a single source. See how it works.

  • ESRS 2.0: Should You Early-Adopt for FY2026?

    For two years, CSRD preparers have built data pipelines, mapped value chains, and wrestled with more than a thousand ESRS datapoints. That groundwork is about to shift. The European Commission is expected to adopt a simplified set of European Sustainability Reporting Standards — informally “ESRS 2.0” — by delegated act in late June or early July 2026, following a public consultation that closed on 3 June. EFRAG’s advice cuts mandatory datapoints by roughly 61% and removes voluntary datapoints altogether.

    Crucially, the revised standards allow voluntary early adoption from financial year 2026, becoming mandatory only for financial years beginning on or after 1 January 2027. That leaves teams with a genuine decision to make now: keep building to the old standard, or pivot to the lighter regime a year early? This guide walks through what is changing and how to weigh the choice with clarity rather than guesswork.

    What ESRS 2.0 actually changes

    The revision is a simplification exercise, not a rewrite of the directive. Three changes matter most for reporting teams:

    • A ~61% cut in mandatory datapoints, with all voluntary datapoints removed. The aim is to concentrate disclosure on what is decision-useful and drop the long tail of marginal metrics.
    • A “top-down” approach to materiality. Rather than testing each datapoint from the bottom up, teams start from the sustainability matters that are material to the business and work down to the disclosures that follow — reducing the assessment burden that has dominated first-cycle projects.
    • Fair presentation applied to the statement as a whole, rather than to each individual datapoint. This is a meaningful audit and governance shift: the question becomes whether the report as a whole gives a true and fair view, not whether every line item is independently perfect.

    The companion Voluntary SME standard (VSME) is on the same adoption track. It underpins the “value-chain cap,” which limits what CSRD reporters can demand from counterparties with 1,000 or fewer employees — directly relevant if your Scope 3 and supply-chain data depend on smaller suppliers.

    The timeline you are actually working against

    Two dates frame the decision. After the Commission adopts the delegated act, a scrutiny period of up to four months by the European Parliament and Council must conclude before the standards are published in the Official Journal. So while the substance is effectively settled, formal finality arrives later in 2026. Early adoption applies from FY2026; mandatory application begins for financial years starting on or after 1 January 2027.

    This sits on top of the February 2026 Omnibus changes, which narrowed mandatory scope to companies with more than 1,000 employees and more than €450m turnover. Many mid-caps that were preparing to report are now outside mandatory scope entirely — yet still face value-chain data requests from larger customers. If that is you, the early-adoption question is less “must we?” and more “what is the most efficient basis to respond on?” For the fuller picture, see our CSRD timeline for 2025–2028.

    The case for early-adopting ESRS 2.0 for FY2026

    • You report on the lighter regime sooner. If your first mandatory report is FY2027 anyway, early adoption lets your FY2026 disclosure — voluntary or value-chain-driven — use the reduced datapoint set rather than the legacy one.
    • You avoid building data flows you are about to retire. Continuing to engineer collection for datapoints that the revision deletes is sunk cost. Pausing those builds now protects budget and analyst time.
    • Top-down materiality is cheaper to run. Re-scoping your materiality assessment around the new model can shrink the single most expensive part of a first cycle.
    • You signal maturity. A clean, focused report aligned to the final standards reads better to investors and assurance providers than an over-stuffed one built to a superseded draft.

    The case for waiting

    • The act is not yet final. Until the scrutiny period concludes and the text is published in the Official Journal, detail can still move. Building to a near-final draft carries some rework risk.
    • Mid-cycle re-scoping has its own cost. If you are deep into an old-ESRS data build with assurance lined up, switching frameworks mid-stream can create more disruption than it saves.
    • Comparability gaps. Reporting on a different basis from peers for one year can complicate year-on-year and benchmark comparisons until everyone converges in FY2027.
    • Internal readiness. Top-down materiality is conceptually simpler but demands confident judgement about what is material. Teams that built bottom-up muscle memory may need time to adjust.

    How to decide: a practical filter

    Work through four questions in order:

    1. When is your first mandatory report? If FY2027, early adoption mainly affects voluntary or value-chain disclosure in FY2026 — lower stakes, easier to trial. If you are still in mandatory scope for FY2026, the calculus is sharper.
    2. How far is your data build? Early-stage projects can pivot to the reduced set cheaply. Near-complete builds with assurance booked may be better finished as planned.
    3. How exposed are you to value-chain requests? If larger customers are asking for data, aligning early to the final standards — and the VSME value-chain cap — can simplify what you owe them.
    4. Can your assurance provider support it? Confirm they are comfortable giving assurance on an early-adopted basis before you commit. The new statement-level fair-presentation model is worth discussing with them directly.

    Whichever way you lean, the foundational work does not change: a defensible double materiality assessment still anchors the report, and your underlying data still needs to be traceable and audit-ready. For a fuller walkthrough of the standards themselves, see our complete ESRS reporting guide.

    The bottom line

    ESRS 2.0 is the most consequential operational change for CSRD preparers since the directive itself. For most teams whose first mandatory report is FY2027 — and especially those early in their data build or responding to value-chain requests — early adoption is the more efficient path, provided your assurance provider is on board. Teams deep into a near-complete old-ESRS cycle have a stronger case to finish as planned and converge in FY2027. Either way, decide deliberately now rather than drifting into the deadline.

    Horizon ESG helps reporting teams navigate ESG complexity with clarity — including scoping and collecting against the right datapoint set the first time. If you are weighing your ESRS 2.0 options, see how our CSRD reporting software keeps your data audit-ready whichever basis you report on.

  • CSRD Assurance: What Limited Assurance Means and How to Prepare

    CSRD assurance is the independent verification of a company’s sustainability report by a qualified third party. Under the directive, all in-scope companies must obtain at least limited assurance on their ESRS disclosures, with the EU planning a transition to reasonable assurance by 2028. This requirement applies from your first CSRD reporting year.

    What is CSRD assurance?

    Assurance is not an audit in the traditional financial sense, but it serves a similar purpose: giving stakeholders confidence that the reported information is materially accurate and prepared in accordance with the applicable standards.

    CSRD introduces two levels of assurance. Limited assurance is required initially — this involves the assurance provider reviewing your data, processes, and disclosures to conclude whether anything has come to their attention that causes them to believe the report is materially misstated. It is less intensive than reasonable assurance but still demands structured evidence and documentation.

    Reasonable assurance — the standard applied to financial statements — is planned for introduction by 2028. This requires the assurance provider to obtain sufficient evidence to positively confirm that disclosures are free from material misstatement. The gap between limited and reasonable assurance is significant in terms of evidence requirements, so organisations building their reporting processes now should design for reasonable assurance from the start.

    What do assurance providers actually check?

    Understanding what assurance providers examine helps you build processes that pass scrutiny the first time. Their focus areas typically include:

    Data accuracy and traceability

    Every figure in your sustainability report must be traceable back to its source. The assurance provider will select a sample of disclosed data points and follow the trail from the published number through your calculation methodology to the underlying activity data. If that trail is broken — because data was manually transferred between systems, or because the calculation methodology is undocumented — the finding will be flagged.

    Methodology consistency

    Have you applied the same calculation methodologies consistently across reporting entities, time periods, and data categories? Changes in methodology between years must be disclosed and justified. The assurance provider will check that emission factors, conversion rates, and estimation approaches are applied uniformly and are appropriate for your sector and geography.

    Double materiality process documentation

    Your double materiality assessment determines which ESRS standards you report against. The assurance provider will examine how you identified material topics, what scoring methodology you used, how stakeholder input was incorporated, and whether exclusion decisions are justified. A materiality assessment without documented methodology and evidence will not survive assurance review.

    Governance and internal controls

    Who approved the data? Who reviewed the calculations? What internal controls prevent errors from propagating through the report? The assurance provider expects to see defined roles, approval workflows, and segregation of duties between data entry and data review. This is where governance alignment becomes critical.

    Completeness of ESRS disclosures

    Based on your materiality assessment, certain ESRS standards apply to your organisation. The assurance provider will verify that all required disclosure points under those standards are addressed — either with reported data or with a documented explanation of why a specific disclosure is not applicable. Missing disclosures without explanation will be flagged as findings.

    How to prepare your organisation for assurance

    Build audit trails from day one. Every data entry should be timestamped, attributed to a named user, and linked to source documentation. If you are using audit-ready ESG reporting software, this should be automatic. If you are using spreadsheets, you need a manual logging process — which is why most organisations undergoing CSRD assurance move to dedicated software before their first engagement.

    Document your methodology decisions. For every calculation approach, emission factor selection, and estimation technique, maintain a methodology note explaining what you chose, why you chose it, and what alternatives you considered. This documentation should be prepared as you build your reporting process, not retrospectively assembled before the assurance engagement.

    Maintain evidence for materiality conclusions. Your double materiality assessment should be supported by stakeholder engagement records, scoring matrices, threshold justifications, and minutes from governance meetings where material topics were approved. The assurance provider will ask for this documentation.

    Establish clear data ownership. Every data point in your CSRD report should have a named owner — the person responsible for its accuracy. When the assurance provider queries a figure, you need to know immediately who can provide the explanation and evidence.

    Run an internal dry run. Before engaging your external assurance provider, conduct an internal review that simulates the assurance process. Select a sample of data points, trace them back to source, check methodology consistency, and verify completeness against ESRS requirements. This identifies gaps you can fix before they become formal findings.

    Common assurance pitfalls

    Engaging the assurance provider too late. If your first conversation with the assurance provider is after your report is drafted, you have missed the window for them to review your methodology and data processes. Engage them during the preparation phase — most providers offer pre-assurance advisory services for first-time reporters.

    Assuming limited assurance is easy. Limited assurance is less intensive than reasonable assurance, but it is not a rubber stamp. Providers will still examine your data, test your calculations, and review your governance processes. Organisations that treat limited assurance casually often receive qualified opinions or management letter findings.

    Inconsistent methodology across entities. Multi-site or multi-entity organisations frequently apply different calculation approaches across locations, then struggle to reconcile them at group level. Standardise your methodology before data collection begins.

    Undocumented Scope 3 estimates. Most organisations use estimates for Scope 3 emissions, which is acceptable under both the GHG Protocol and ESRS E1. However, the estimation methodology, data sources, and assumptions must be clearly documented. An undocumented estimate is an unsupported figure.

    No separation between data entry and review. If the same person enters and approves data, you have a governance weakness. Assurance providers expect a review step between data entry and final disclosure, even in small teams.

    The timeline — when to engage your assurance provider

    For a company reporting on FY2025 with a filing date in 2026, a realistic assurance timeline looks like this:

    6-9 months before filing: Initial conversation with the assurance provider. Discuss scope, timeline, fee structure, and their expectations for documentation and access.

    4-6 months before filing: Pre-assurance advisory engagement. The provider reviews your methodology documents, data collection processes, and materiality assessment. You receive early feedback and can address gaps.

    2-3 months before filing: Data collection close. Final figures are calculated and internal review is completed.

    1-2 months before filing: Formal assurance engagement. The provider conducts their review, tests data samples, and issues their assurance opinion.

    How Horizon ESG supports assurance readiness

    Horizon ESG is designed with assurance in mind. Every data entry is automatically timestamped and attributed. Calculation methodologies are documented within the platform. Approval workflows enforce separation between data entry and review. And your assurance provider can be granted read-only access to trace any disclosed figure back to its source data without requiring your team to compile evidence packs manually.

    The result is a reporting process that is assurance-ready by design, not by afterthought. Learn more about how Horizon ESG can support your assurance readiness.

  • CSRD Readiness Checklist: 12 Steps Before Your First Report

    To prepare for CSRD, organisations should follow a structured readiness process: confirm whether they fall in scope, identify their reporting deadline, conduct a double materiality assessment, map their value chain, establish data collection workflows, and secure assurance early. This 12-step CSRD readiness checklist walks you through each stage so you can approach your first report with confidence rather than last-minute scrambling.

    What Is CSRD Readiness?

    CSRD readiness refers to the state of organisational preparedness required to produce a compliant sustainability report under the EU’s Corporate Sustainability Reporting Directive. Unlike previous non-financial reporting requirements, the CSRD demands structured, auditable disclosures aligned with the European Sustainability Reporting Standards (ESRS). That means readiness is not simply about writing a report — it is about building the internal systems, governance structures, and data pipelines that make accurate, verifiable reporting possible.

    A CSRD readiness assessment evaluates where your organisation currently stands against these requirements and identifies the gaps you need to close before your first filing deadline. The earlier you begin this process, the less disruptive it becomes. Companies that treat CSRD preparation as a phased project — rather than a year-end compliance exercise — consistently report smoother outcomes and fewer audit issues.

    The 12-Step CSRD Readiness Checklist

    1. Determine If You Are in Scope

    The CSRD is rolling out in waves. Large public-interest entities (over 500 employees) began reporting in 2025 on FY2024 data. The second wave, covering large companies meeting two of three thresholds — over 250 employees, EUR 50 million turnover, or EUR 25 million in assets — reports in 2026 on FY2025 data. Listed SMEs follow in 2027, with a possible opt-out until 2028. Non-EU companies generating over EUR 150 million in the EU enter scope from 2029. Check the thresholds carefully. Many mid-sized businesses are surprised to find they qualify earlier than expected, particularly subsidiaries of larger groups.

    2. Identify Your Reporting Year and First Filing Deadline

    Once you have confirmed you are in scope, pin down the exact financial year you need to report on and the corresponding filing date. Your CSRD report will be included within your management report, which means the deadline aligns with your annual financial reporting cycle. If you are in the second wave, your first report covers FY2025 data and must be filed in 2026. This distinction matters because data collection needs to begin at the start of the reporting year — not when the report is due. Work backwards from the filing date to build a realistic preparation timeline.

    3. Conduct a Gap Analysis Against ESRS Requirements

    The European Sustainability Reporting Standards comprise 12 standards spanning environmental, social, and governance topics. Each standard contains specific disclosure requirements and data points. A gap analysis maps your current ESG reporting practices against these requirements to identify what you already collect, what you partially cover, and what is entirely missing. Focus on the mandatory cross-cutting standards (ESRS 1 and ESRS 2) first, then move to the topical standards that your double materiality assessment identifies as relevant. This exercise gives you a clear remediation roadmap and helps you prioritise resource allocation.

    4. Complete Your Double Materiality Assessment

    Double materiality is the foundation of your CSRD report. It requires you to assess sustainability topics from two perspectives: financial materiality (how sustainability issues affect your business) and impact materiality (how your business affects people and the environment). This assessment determines which ESRS topical standards you must report on and which you can legitimately exclude. It also shapes your stakeholder engagement strategy. For a detailed walkthrough of the methodology, see our complete guide to double materiality under CSRD. Do not underestimate the time this step requires — most organisations need 8 to 12 weeks to complete it properly.

    5. Map Your Value Chain for Scope 3 Reporting

    ESRS E1 (Climate Change) requires disclosure of Scope 1, 2, and 3 greenhouse gas emissions. Scope 3 — covering indirect emissions across your upstream and downstream value chain — is typically the largest category and the hardest to measure. Begin by mapping your key suppliers, distributors, and end-of-life product impacts. Identify which Scope 3 categories are most material to your business. You will likely need to rely on spend-based estimates initially before transitioning to activity-based data over time. Engaging key suppliers early and establishing data-sharing agreements will improve data quality in subsequent reporting cycles.

    6. Establish Data Collection Processes Across Departments

    CSRD reporting pulls data from across the entire organisation — HR for workforce metrics, procurement for supply chain data, facilities for energy consumption, finance for climate-related financial risks. Identify every data owner and establish clear collection processes, frequencies, and quality standards. Spreadsheets may work for a first cycle, but they introduce error risk and make audit trails difficult. Investing in purpose-built ESG reporting software early reduces manual effort and improves consistency. Define data definitions clearly so that every department reports metrics in the same way.

    7. Assign Internal Ownership and Governance Structure

    CSRD compliance cannot sit with a single sustainability officer. It requires a governance structure with clear accountability at the board level, an executive sponsor, and designated owners for each ESRS topic. Consider establishing a cross-functional CSRD steering committee that includes representatives from finance, legal, operations, HR, and sustainability. Define who signs off on the final report, who is responsible for data quality, and how disputes over materiality or disclosure are resolved. Our guide on CSRD governance alignment provides a practical framework for structuring this effectively.

    8. Select Your Reporting Software Platform

    The complexity and volume of ESRS data points make manual reporting impractical at scale. Evaluate ESG reporting software platforms based on their ESRS alignment, data integration capabilities, audit trail functionality, and XBRL tagging support — since CSRD reports must be digitally tagged in European Single Electronic Format (ESEF). Consider whether the platform supports double materiality workflows, automated data validation, and multi-entity consolidation if you operate across subsidiaries. Select your platform early enough to allow for implementation, data migration, and user training before the reporting year begins.

    9. Build Your Audit Trail from Day One

    CSRD reports are subject to mandatory assurance — initially limited assurance, moving to reasonable assurance over time. Your assurance provider will need to trace every disclosed figure back to its source. This means maintaining documentation of data origins, calculation methodologies, assumptions, estimation techniques, and any manual adjustments. Build this audit trail from the very start of your data collection process, not retrospectively when the auditor arrives. Version control for documents, approval workflows for data submissions, and timestamped records of changes all contribute to a robust audit trail that will make assurance smoother and less costly.

    10. Engage Your Assurance Provider Early

    Do not wait until your report is drafted to approach an assurance provider. Engage them during the preparation phase so they can review your methodology, flag potential issues with data quality or materiality conclusions, and confirm that your processes meet assurance standards. Many audit firms are experiencing significant demand as thousands of companies enter CSRD scope simultaneously, so early engagement also secures capacity. If your financial auditor offers sustainability assurance, there may be efficiencies in using the same firm, but evaluate independence and expertise carefully. A pre-assurance readiness review can save considerable time and cost later.

    11. Train Your Team on ESRS Disclosure Requirements

    CSRD reporting is not just a sustainability team exercise. Finance teams need to understand climate-related financial disclosures. HR must know what workforce data is required and how to report it consistently. Board members need sufficient literacy to oversee and approve the report. Invest in targeted training that is role-specific rather than generic. Focus on the practical mechanics: what data each team needs to provide, in what format, by what deadline, and to what quality standard. Regular briefings throughout the reporting cycle keep teams aligned and reduce the risk of last-minute data gaps or inconsistencies.

    12. Create a Reporting Timeline with Internal Milestones

    Your CSRD preparation needs a detailed project plan with clear milestones, not just a filing deadline. Work backwards from your submission date and build in time for data collection close, internal review cycles, management sign-off, assurance fieldwork, and XBRL tagging. Allow buffer time — first-year reporting always takes longer than expected. Key milestones should include: completion of the double materiality assessment, data collection cut-off dates for each quarter, first draft review, assurance readiness review, board approval, and final submission. Assign owners to each milestone and track progress through regular steering committee meetings.

    Common CSRD Readiness Mistakes

    Even well-resourced organisations stumble during CSRD preparation. These are the mistakes we see most frequently:

    1. Starting too late. Companies that begin their readiness assessment less than 12 months before their filing deadline consistently struggle with data gaps and rushed disclosures. CSRD preparation is a multi-year journey, not a quarter-end sprint.
    2. Treating it as a sustainability-only project. Without buy-in and active participation from finance, legal, HR, and operations, data collection stalls and governance gaps appear during assurance.
    3. Underestimating double materiality. A superficial materiality assessment leads to either over-reporting (wasting resources on immaterial topics) or under-reporting (creating compliance risk). Invest the time to do it properly.
    4. Ignoring the audit trail. Collecting data without documenting sources, methodologies, and assumptions creates enormous problems when assurance providers request evidence. Retrofitting audit trails is far more expensive than building them from the start.
    5. Choosing software too late. Implementing a reporting platform mid-cycle forces dual processes and increases error risk. Select and configure your platform before the reporting year begins.
    6. Neglecting value chain data. Scope 3 and supply chain disclosures require supplier engagement that takes months to establish. Start building those relationships and data-sharing agreements early.

    How Horizon ESG Supports CSRD Preparation

    Horizon ESG provides a structured platform designed to guide organisations through each stage of CSRD compliance. From automated double materiality workflows to ESRS-aligned data collection templates, the platform helps teams move from readiness assessment to published report without relying on disconnected spreadsheets or manual processes.

    Key capabilities include built-in audit trail functionality, cross-departmental data collection with automated validation, Scope 1-3 emissions calculation, and XBRL-ready output. For organisations in the second and third CSRD waves, Horizon ESG offers a phased onboarding approach that aligns platform implementation with your reporting timeline — so you are collecting data in the right format from day one.

    Learn more about how the platform supports your reporting obligations on our CSRD solutions page, or explore our guide to selecting best-practice ESG reporting software.

Book Your Free Demo