Tag: ESG Compliance

  • What Audit-Ready ESG Reporting Actually Means: 6 Tests

    What Audit-Ready ESG Reporting Actually Means: 6 Tests

    Horizon ESG data quality view showing emissions split by measured, spend-based and estimated sources with an aggregate uncertainty range

    You have sat through the demo. Somewhere around slide four the words “audit-ready” appeared, and nobody in the room could have told you what they meant. Every sustainability platform now makes the same claim, which means the claim itself carries no information.

    If you run finance, you already know what the phrase should mean, because it is the standard your own numbers are held to: a controls environment that an auditor can test, not a spreadsheet that happens to be tidy. This piece applies that standard to sustainability data: the six things an assurance provider actually examines, and the one demo request that tells you in under a minute whether “audit-ready” is a capability or a slide.


    Assurance is a controls problem, and that makes it yours

    The shift that matters is not a new disclosure standard. It is that sustainability figures are now being tested the way financial figures are. Limited assurance is already live for the largest CSRD reporters, and ISSA 5000, the IAASB’s sustainability assurance standard, applies to engagements covering periods beginning on or after 15 December 2026. In the UK, lenders and listed customers are asking for evidence behind supplier numbers whether or not any regulation requires it.

    What an assurance provider does with your sustainability report is worth being precise about. They do not recalculate your totals. They test whether the process that produced the totals is documented, controlled and reproducible: where each number came from, who touched it, what method was applied, and whether the same inputs would give the same answer again. That is an audit of controls, and controls are the discipline finance already owns. We covered the engagement itself in our earlier piece on what limited assurance involves and how to prepare; this post is about what the platform underneath it has to do.


    The six tests an assurance provider actually runs

    Use these as a checklist. A platform that fails two or three will still produce a report, but the assurance fee rises to cover the extra sampling, and the gaps are found on your time rather than the vendor’s.

    1. Evidence attached at datapoint level, not in a folder

    The auditor picks a number, say Scope 2 electricity for one site, and asks to see the invoice, the meter reading or the utility export behind it. The test passes if that source is attached to that datapoint, with the extracted value visible against the document. It fails if the answer is a shared drive called “Evidence FY2025” containing 400 PDFs. Vouching a figure to its source should take seconds, not a search.

    2. An immutable change history

    Every figure needs a record of who changed it, when, from what value to what value, and why. A “last modified” timestamp is not a change history. Neither is a log that an administrator can edit or clear. Ask to see the history of a figure that was corrected mid-year and check that the original value is still visible alongside the correction and the reason given for it.

    3. A prior period reproduced on the methodology that applied then

    This is the test most platforms fail quietly. Emission factors are updated every year. If the platform overwrites the old factor with the new one, last year’s published total can no longer be regenerated, and a restatement query from your auditor turns into an argument you cannot win. The control you want is versioned factors and closed periods: ask the vendor to regenerate FY2024 as it was reported, on the FY2024 factor set, while FY2025 runs on the current one.

    4. Methodology and factor versions recorded with the figure

    Which factor set was used (the DEFRA year, the grid factor source, the database version), which organisational boundary, which allocation rule for shared sites. These need to sit on the datapoint, captured at the moment of calculation, not in a methodology document written afterwards from memory. When the auditor asks “why does this factor differ from the one in the note”, the answer should be on screen.

    5. Segregation of duties enforced by the system

    Preparer, reviewer and approver should be different people, and the platform should refuse to let the person who entered a figure sign it off. A policy that says this is nice; a system that enforces it is a control. Sign-off should be recorded with the name, the date and what was approved, exactly as you would expect for a journal above the approval threshold.

    6. Estimates labelled as estimates

    Assurance providers do not object to estimates. Spend-based proxies and modelled figures are normal in Scope 3. What they object to is an estimate presented with the same confidence as a meter reading. Every figure should carry its data quality (measured, spend-based, modelled) and the report should show the aggregate uncertainty that results. This is also where built-in intelligence earns its place, provided it is bound to evidence: in Horizon ESG, anything Nova drafts or estimates is labelled as such, carries its sources and factor versions, and waits for a named human to approve it in the same audit trail as a manual entry. An estimate nobody can distinguish from a measurement is a finding waiting to happen.


    The one request that settles it

    Checklists can be rehearsed. So once the vendor has finished, make this request, in these words:

    “Trace a published figure back to its source document, live, without preparation.”

    Pick the figure yourself. A pass looks like this: the presenter clicks the total, the calculation opens showing activity data and the factor with its version, the source file is one click further, the change log and the approver’s name are visible, and the whole thing takes under a minute. A fail sounds like “we would need to set that up”, “let me show you the evidence folder”, or a quiet switch to a spreadsheet. You will know which you have seen, and so will your auditor.


    What this does to cost

    Two costs move when the six tests are met. The assurance fee falls, because the provider samples less when lineage is visible and can rely on system controls rather than substantive testing. And the internal cost becomes predictable, because year two is the same process as year one instead of a fresh reconstruction. The platform fee is a line item; the reconstruction is what quietly eats a quarter of someone’s year. If you are comparing vendors on this, our comparison of ESG reporting platforms on audit trail and lineage sets out where each one, including ours, is stronger and weaker.


    Twelve months ahead: what to have in place

    • Agree the boundary and the factor sets for the period now, and record them where the calculation happens.
    • Close prior periods so that FY2024 and FY2025 can be regenerated as published.
    • Assign preparer and approver roles per datapoint group and let the system enforce them.
    • Attach source documents as data is entered, not in the month before fieldwork.
    • Run the trace test internally on ten figures picked at random. If any fail, that is your remediation list.

    One last point. The numbers your sustainability officer sends to customers and lenders in questionnaires need to match the numbers you publish. Produced from different sources, they diverge, and a customer noticing is the worst way to find out. Our piece on answering customer and lender data requests covers that side; one evidenced dataset feeding both is what closes the gap.

    If you want to see the six tests against real data, Horizon ESG for finance teams is built around datapoint lineage, enforced approval and versioned factors. Book a short demo, pick a figure, and make the request above. We would rather you asked it of us first.

  • How to Answer Customer and Lender ESG Data Requests

    How to Answer Customer and Lender ESG Data Requests

    One ESG dataset mapped to multiple reporting frameworks and questionnaire formats in Horizon ESG

    Somewhere in your inbox right now there is an ESG questionnaire you have not opened yet. It might be from a customer’s procurement portal, from your bank’s annual credit review, or from an insurer’s renewal pack. Each one uses a different format, asks slightly different versions of the same questions, and lands with a deadline that has nothing to do with any regulation.

    If that describes your week, this piece is for you. It covers why the requests keep multiplying even though the EU just cut its reporting rules back, the legal ceiling on what your customers can now require of you, and how to stop answering every request from scratch.


    Why the requests keep coming when the regulation went away

    On 18 March 2026 the Omnibus I Directive came into force and CSRD shrank dramatically. The threshold is now more than 1,000 employees and more than EUR 450m net turnover, both tests together, which cut the reporting population from roughly 50,000 companies to roughly 5,000 across the EU.

    If your company fell out of scope, you might reasonably have expected the questionnaires to slow down. They have not, and the reason is structural. The 5,000 companies still in scope are the largest buyers, banks and insurers in Europe, and their obligations cover their value chains: your emissions, your energy mix, your workforce data, your policies. Banks need supplier and borrower data for financed emissions. Insurers ask at renewal. Procurement teams have embedded ESG scoring in tender processes that are not going to be unwound because a directive changed.

    The obligation did not disappear. It moved, from the regulator to your customers. And that changes the nature of your deadline: it is a tender date, a contract renewal, a credit review. Nobody in Brussels set it, and nobody in Brussels will extend it.


    The value chain cap: the ceiling on what they can require

    Here is the part most suppliers still have not heard. The same Omnibus package that shrank CSRD also gave you a statutory ceiling. If your company has fewer than 1,000 employees, a CSRD-scope customer cannot require you to provide sustainability information beyond what the voluntary VSME standard covers. The European Commission adopted the VSME-based voluntary standard on 3 July 2026, and for CSRD reporters the cap bites from financial year 2027.

    We unpacked the legal mechanics in our earlier piece on what the value chain cap lets buyers still ask suppliers, written for the company sending the questionnaire. This post is the other side of the conversation: what to do when you are the one receiving it.

    Three things to hold onto. First, the cap limits what a customer can require for their CSRD reporting; it does not stop them asking for more, but they must identify which parts of a request go beyond the cap and tell you that you are entitled to refuse those parts. Second, the cap does not stop you volunteering more if it is commercially worth it. Third, the cap is only useful to you if you actually have a VSME dataset to point at, which is the real work.

    How to invoke it without souring the relationship

    The cap is a boundary, not a weapon, and the tone that works is helpful-with-a-ceiling. Something like:

    “We have fewer than 1,000 employees, so under the Omnibus I value chain cap we maintain our sustainability data against the VSME standard. Our full VSME dataset is attached and covers most of your questionnaire. Could you confirm which of the remaining items you need for purposes other than CSRD reporting, and we will see what we can do?”

    You have answered fast, answered most of it, stated the legal position without threatening anyone, and moved the burden of justifying the excess back to the requester. That is a very different conversation from either silence or a flat refusal.


    One dataset, many formats

    The deeper fix is to stop treating each questionnaire as a document to be written and start treating it as a view of a dataset you already maintain.

    The VSME standard is the natural spine for that dataset, because it is now the reference point for what you can be required to provide. Build it once: energy and emissions, workforce basics, policies, certifications, incidents. Attach the evidence to each datapoint, not to a folder, so that every answer you send out carries its source with it. Then each new request, whatever the format, becomes a mapping exercise rather than a writing exercise.

    The consistency matters as much as the speed. When five people answer five portals from memory and spreadsheets, the same question eventually gets five slightly different answers, and one of them ends up contradicting the number your company published elsewhere. One maintained dataset is what prevents that.

    This is the problem Horizon ESG’s sustainability team workspace is built around: one evidenced dataset, mapped to the frameworks and questionnaire formats you actually get asked for. Nova, the built-in assistant, drafts questionnaire answers from that dataset, with every figure traced to its source and every draft held for your approval before anything leaves the building.


    When a customer asks for more than the cap allows

    It will happen, usually because the person running the portal has never heard of the cap. A short sequence to work through:

    • Check the purpose. The cap governs requests made for CSRD reporting. Data requested for contract qualification, product compliance or the customer’s own risk management sits outside it. Ask which is which; the question itself often shrinks the request.
    • Ask them to flag the excess. A CSRD-scope buyer asking beyond the cap is supposed to identify which items exceed it and tell you they are optional. If they have not, asking them to do so is entirely reasonable.
    • Decide commercially, not defensively. The cap gives you a right to decline, not a duty. If a strategic customer wants two extra datapoints and you can produce them from your dataset in an hour, volunteer them.
    • Counter-offer the dataset. “Here is our complete VSME dataset now; the remaining items would take us six weeks” gives the requester something to bank immediately and usually ends the conversation.

    The commercial cost of answering slowly

    It is tempting to treat questionnaires as overhead to be minimised. The evidence in front of most sustainability officers points the other way: the requests you are receiving are attached to revenue and to the cost of capital. A tender response that misses the portal deadline is a bid not scored. A slow answer to a bank’s ESG review does not usually lose the loan, but sustainability-linked facilities increasingly tie margin to data quality, and “supplier could not evidence their numbers” is a phrase that shows up in credit files.

    Being easy to buy from is the quiet advantage here. The supplier who returns a complete, evidenced, consistent dataset in two days is doing more for renewal season than most marketing budgets.


    One dataset, two audiences

    A last point worth raising internally: the numbers you send to customers and lenders need to match the numbers your finance team publishes. When the two are produced separately, they eventually diverge, and a customer noticing the difference is the worst possible way to find out. If your CFO is starting to ask assurance-flavoured questions about sustainability data, that is the same problem from the other end; our page for finance teams covers that side.

    If your week is currently being eaten by questionnaires, book a short demo and bring your worst one. Answering it from one dataset is the fastest way to see the point.

  • UK SRS S1 and S2: Who Has to Report, and When

    The UK’s sustainability reporting standards have been finished for six months and almost nobody has started. That is not negligence, it is a rational response to an unfinished sentence: the standards exist, but the rule that makes them binding does not. It is expected this autumn.

    Which makes now the useful moment to understand them, rather than the moment after the announcement when every consultant in London is quoting you a readiness assessment.


    Where things actually stand

    The Department for Business and Trade published the final UK SRS S1 and UK SRS S2 on 25 February 2026. They are available for voluntary use by any entity today, and a handful of companies have already adopted them early.

    The binding step sits with the Financial Conduct Authority. Its consultation, CP26/5, ran from 30 January to 20 March 2026 and proposed replacing the current TCFD-aligned listing rules with UK SRS. The FCA has said it aims to publish the final Policy Statement in autumn 2026. As of today it has not.

    Everything below the standards themselves is therefore still a proposal. It is a well-signalled proposal that has already been through consultation, which is not the same thing as a rule.


    The distinction that matters most: this is ISSB, not ESRS

    If your team spent 2024 and 2025 building for CSRD, the single most important thing to understand about UK SRS is that it did not come from the same place.

    UK SRS S1 and S2 are endorsed versions of IFRS S1 and IFRS S2, the ISSB standards, with only limited UK amendments. They are not derived from the ESRS. The practical consequences are real:

    • Materiality is single, not double. ISSB asks what could reasonably be expected to affect an entity’s prospects – cash flows, access to finance, cost of capital. It does not ask you to report impacts on people and planet that are not financially material. Your CSRD double materiality assessment is useful input, but it is not the same assessment.
    • The audience is investors, explicitly and narrowly. That changes the register of the disclosure and often the level of aggregation.
    • There is no ESRS datapoint list to work through. ISSB is principles-based with industry-specific metrics drawn from SASB. Teams used to filling in a defined set of datapoints find this harder, not easier, because judgement is now load-bearing.

    The overlap is nonetheless substantial at the data layer. Emissions are emissions; governance narrative is largely reusable; scenario analysis carries over. It is the framing, materiality boundary and reporting location that differ. We covered the mechanics of that mapping in more detail in our piece on how TCFD and CSRD requirements line up for UK companies.


    Who is in scope

    The FCA’s proposals apply to listed issuers in five UK Listing Rules categories: commercial companies (UKLR 6), secondary listings (UKLR 14), depositary receipts (UKLR 15), non-equity and non-voting equity shares (UKLR 16), and the transition category (UKLR 22).

    That is roughly 515 companies. For context, post-Omnibus CSRD now catches around 5,000 companies across the entire EU, so neither regime is the mass-market obligation the 2023 architecture implied.

    If you are a private UK company, you are not in the FCA’s population. You may still receive UK SRS-shaped questions from listed customers and from lenders, which is a different problem with the same answer.

    The timetable, as proposed

    • UK SRS S2 (climate): accounting periods beginning on or after 1 January 2027. For a December year end, that means the report published in 2028.
    • Scope 3 emissions: a one-year transitional relief, applying on a comply-or-explain basis for periods beginning on or after 1 January 2028.
    • UK SRS S1 (wider sustainability): a two-year relief, comply-or-explain for periods beginning on or after 1 January 2029.

    Read that phasing carefully, because it is the opposite of how most companies sequence their work. Climate lands first and hardest. Scope 3, the hardest data problem in the standard, gets one extra year and then arrives on comply-or-explain, which in practice means “report it or write a paragraph explaining a gap to your investors”. Neither is a reason to defer the work; both are a reason to sequence it properly.


    What happens to your TCFD disclosures

    If you have been reporting under the FCA’s TCFD-aligned rules, you are not starting from zero. IFRS S2 was built on the TCFD’s four pillars, and governance, strategy, risk management, and metrics and targets survive intact as the structure of the disclosure.

    What is genuinely new is the level of specificity:

    • Industry-based metrics. S2 points to SASB-derived metrics for your sector. TCFD left this open; S2 does not.
    • Scope 3 across all fifteen categories, with the measurement approach and inputs disclosed, rather than a partial inventory with a footnote.
    • Connectivity with the financial statements. The assumptions behind your climate disclosure are expected to be consistent with the ones behind your accounts. Asset lives are the classic exposure.
    • Transition plans. The FCA is not proposing to mandate one. It is proposing that you disclose whether you have published one and where it can be found, or why you have not – which is a harder question to answer blandly than it looks.

    The assurance line most readers skipped

    CP26/5 does not mandate third-party assurance. It proposes something quieter: that in-scope companies state in the annual financial report whether they obtained assurance, from whom, over which disclosures, to what level, against which standard, and where the report sits.

    A visible blank is a disclosure in itself. Once one FTSE 250 peer names a provider and a standard, the field fills in fast. Anyone who watched limited assurance arrive in Europe will recognise the shape of it – and the preparation it demands is the same as we set out in our guide to what limited assurance actually tests: documentation, traceability and controls, not recalculated totals.


    SECR has not gone anywhere

    Worth saying plainly, because the UK SRS coverage tends to imply otherwise. Streamlined Energy and Carbon Reporting still applies to all UK quoted companies and to large unquoted companies and LLPs meeting the familiar size test. That population is an order of magnitude larger than the FCA’s 515, and nothing in UK SRS removes the obligation. If you are a large private company, SECR remains your binding UK requirement and UK SRS is, for now, context.


    What to do before the Policy Statement lands

    • Establish whether you are in one of the five UKLR categories. Ten minutes, and it determines everything else.
    • Re-run materiality on a single-materiality basis if your existing assessment was built for CSRD. Do not assume the answer transfers.
    • Baseline Scope 3 now, not in 2028. The relief is on the reporting date, not on the data collection, and purchased goods and services cannot be built in a quarter.
    • Check connectivity between your climate assumptions and the assumptions in your financial statements. Fix the inconsistencies while nobody is examining them.
    • Decide your assurance position early. If you intend to say “assured”, the provider needs to see your controls well before the reporting period, not after it.
    • Read the Policy Statement when it appears and re-check the dates. Consultation feedback moves timetables, and these are still proposals.

    The companies that will find UK SRS straightforward are not the ones with the most disclosure experience – they are the ones that can show where each number came from. Horizon ESG helps UK reporting teams collect data once and keep source, method, factor version and owner attached to every figure, so the same evidence base serves UK SRS, SECR, ISSB and customer data requests without a rebuild each cycle. If you are still choosing a platform, our comparison of eight ESG reporting platforms sets out which ones cover ISSB properly rather than treating it as a CSRD add-on. See how it works for UK reporting, or book a free demo.

  • IFRS’s New Chairs Are Supervisors, Not Accountants

    On 11 August the IFRS Foundation named the two people who will run global corporate reporting for the rest of the decade. Almost nobody in the sustainability press covered it, because governance announcements do not read like news. They are, however, one of the more reliable predictors available: personnel is policy, and the Foundation has just told you a great deal about how IFRS S1 and S2 will be interpreted, pushed and enforced.

    The short version is that the Foundation skipped the accounting bench. Neither appointee comes from technical financial reporting. Both come from financial supervision, which is a different profession with different instincts about what a disclosure is for.


    What was announced

    Steven Maijoor becomes Chair of the IFRS Foundation Trustees from 1 January 2027 on an initial three-year term, succeeding Erkki Liikanen, who has held the role since 2018. Maijoor is currently an Executive Board member and Chair of Supervision at De Nederlandsche Bank and sits on the ECB Supervisory Board. Before that he was Chair of ESMA through the period in which SFDR and the EU Taxonomy were designed.

    Sam Woods becomes Chair of the IASB from 1 October 2026 on a five-year term, succeeding Andreas Barckow, whose term ended in June. Woods was Deputy Governor of the Bank of England and Chief Executive of the Prudential Regulation Authority.

    The two appointments complete the Foundation’s senior slate alongside Emmanuel Faber, who remains ISSB Chair to 31 December 2027, and Laura Forzani, who becomes Managing Director on 1 September 2026.


    Why a supervisor reads a disclosure differently

    A standard-setter’s core question is whether a requirement is conceptually sound and faithfully represents the underlying economics. A supervisor’s core question is narrower and more awkward: can I compare this across forty firms, and does it hold up when I ask the firm to show me where the number came from?

    That difference has consequences. Supervisors are institutionally impatient with disclosures that are technically compliant but not usable. They tend to favour prescription over judgement where judgement produces incomparable results. They ask for the underlying data, not the narrative around it. And they have spent their careers in regimes where the answer “that is our best estimate” is only acceptable if it is accompanied by a documented method, a stated limitation and a trail back to source.

    Put a former ESMA Chair over the Trustees and a former PRA chief executive over the IASB, and the reasonable expectation is that this register becomes the house style of global reporting.


    Four things this makes more likely

    1. Harder pressure on connectivity

    Connectivity, the requirement that sustainability information hangs together with the financial statements rather than sitting beside them, is already in IFRS S1. It has been unevenly applied because it is easy to satisfy in form. Supervisors are unusually good at spotting the gap between a transition plan that assumes an asset is retired in 2030 and a balance sheet that depreciates it to 2045. Expect that inconsistency to be treated as a finding rather than a presentational quirk.

    2. Assurance expectations move ahead of assurance mandates

    In most jurisdictions sustainability assurance is either limited-scope or not yet required. That will not stop the direction of travel. Supervisors do not wait for an assurance mandate to ask evidential questions; they ask them through their existing supervisory relationship, and preparers answer. If your organisation is already working through what limited assurance actually requires, that work now has a second audience beyond the auditor.

    3. Adoption gets negotiated with supervisors, not accounting bodies

    Jurisdictional adoption of ISSB standards has largely been driven through securities regulators and central banks already: the FCA in the UK, the FSA in Japan, ASIC and the AASB in Australia. Two supervisors at the top of the Foundation makes that channel the default rather than the exception. For preparers the practical read is that local implementation detail will increasingly be set by your market regulator, and that is where to watch for the rules that actually bind you.

    4. The evidence bar rises while the scope bar falls

    This is the tension worth internalising. Europe has spent eighteen months narrowing who has to report: the Omnibus cut the CSRD population, the revised ESRS reduced datapoints, and the Taxonomy is being simplified again for FY2027. It is tempting to read that as a general softening. It is not. Fewer companies are being asked to report, and those that do are being asked to prove more. Scope and rigour are moving in opposite directions, and the Foundation just staffed for rigour.


    What this does not change

    Two clarifications, because governance news invites over-reading.

    First, the technical programme is unaffected. Faber remains ISSB Chair through 2027, so the work in flight proceeds on its existing timetable: the targeted IFRS S2 amendments on greenhouse gas measurement are effective for annual periods beginning on or after 1 January 2027 with early application permitted, and the nature-related work continues as a non-mandatory IFRS Practice Statement, with an exposure draft targeted for October 2026. If you are already preparing for nature disclosure, nothing in this announcement moves that date.

    Second, neither appointment changes a single current obligation. Nobody’s filing deadline moved on 11 August. This is a signal about the next three to five years, not a compliance event.


    What a reporting team should actually do about it

    Very little that is new, and quite a lot that is usually deferred. The useful response to a rising evidence bar is not more disclosure. It is better provenance behind the disclosure you already make.

    • Attach evidence at the point of collection, not at audit. Every figure should carry its source document, method, preparer and date without anyone having to reconstruct it in February. Reconstruction is where first assurance cycles overrun.
    • Write down your estimation methods before you need to defend them. Estimates are acceptable; undocumented estimates are not. A supervisor’s objection is almost never to the estimate itself.
    • Reconcile your sustainability assumptions to your financial ones. Asset lives, impairment triggers, provisions, capex commitments. Do the comparison internally before somebody external does it for you.
    • Read your market regulator, not just the standard. If adoption is supervisor-led, the binding detail arrives in a policy statement or a consultation from the FCA, FSA, ASIC or SEC, not from the IFRS Foundation.
    • Stop treating scope relief as workload relief. If simplification has taken pressure off your reporting population, redirect that capacity into data quality rather than banking it.

    The signal underneath the announcement

    For four years the central question in sustainability reporting has been who has to report. Politically that question is closing, and the answer is fewer companies than the 2023 architecture envisaged. The question replacing it is how well, and that is a supervisory question rather than a legislative one. It gets answered slowly, through examinations and findings and comparability reviews, and it does not respond to lobbying in the way scope thresholds do.

    The teams that will find the next few years comfortable are not the ones with the most disclosure. They are the ones that can answer “where did this number come from” in minutes rather than weeks.


    If your emissions and ESRS data live across spreadsheets, inboxes and a consultant’s model, the evidence trail is the thing you do not have. Horizon ESG helps reporting teams collect data once, keep source, method and owner attached to every figure, and report it against CSRD, ISSB and California requirements without rebuilding the inventory each cycle. Book a free demo.

  • SB 253 Deadline: Three Reliefs Buried in CARB’s Redline

    The nearest binding climate-reporting deadline anywhere in the world is not in Brussels. It is 10 November 2026, when the first Scope 1 and Scope 2 disclosures under California’s SB 253 fall due — around fourteen weeks from now. And the document that decides how hard that filing will actually be was published on 27 July, arrived as a redline, and has been read by almost nobody outside the law firms.

    On that date the California Air Resources Board published its modified initial regulation implementing SB 253 and SB 261, and opened a 15-day public comment period closing 11 August 2026. Most coverage led with the deadline deferral — from 10 August to 10 November — already known since June. Further down the text sit three first-year concessions that materially change what an in-scope company has to produce this year, each the kind of provision that vanishes in a press-release summary.


    First, what this document is — and isn’t

    It is a modified text out for comment, not a final rule: it still has to clear the comment period and review by the Office of Administrative Law before it binds. Treat what follows as a strong signal of CARB’s intent rather than settled law — while not planning a fourth-quarter data sprint as though none of it exists.

    The scope test is unchanged: companies with total annual revenue above $1 billion that do business in California. The first report covers FY2025 Scope 1 and Scope 2 emissions, due 10 November 2026.


    Relief one: the 5 December 2024 data cut-off

    For initial reporting only, a company may rely on information it possessed, or was already in the process of collecting, as of 5 December 2024.

    Read that slowly, because it inverts the instinct most teams are acting on. The benchmark for your first California filing is not the best inventory you could assemble by November — it is the inventory your systems were already producing more than eighteen months ago. If utility data for a set of leased sites was never metered separately in 2024, CARB’s text does not require you to reconstruct it now.

    The practical effect is that the sensible first-year project is narrower than most teams have scoped it. Rather than retro-instrumenting every site, the work is to establish what you genuinely held at that date, report on that basis, and document the boundary clearly enough that it survives a later question. That is a governance and evidence exercise more than a measurement one — the same discipline that applies whenever estimated data is good enough to report: state the method, state the limitation, keep the trail.

    What it does not do

    It is explicitly a first-year provision. It does not waive the obligation to file, and it does not carry into the 2027 cycle — by which point the expectation is a properly built inventory. Nor is it self-executing: relying on it means being able to evidence what you held and when. A company that quietly uses the relief without recording why has taken the risk without the protection.


    Relief two: intercompany revenue is out of the $1 billion test

    The modified text clarifies that revenue transmitted between a parent and a subsidiary, or between different parts of the same company, is not counted as revenue when applying the $1 billion threshold.

    This matters more than it sounds. Groups running captive distribution entities, internal manufacturing transfers or centralised procurement can show gross figures well above the threshold that are substantially internal turnover. An entity that looked comfortably in scope may not be in scope at all once genuine third-party revenue is isolated.

    If your scoping decision was made in 2025 on a quick read of group revenue, re-run it before you commit a reporting budget. Threshold questions are cheap to answer now and expensive to answer in November.


    Relief three: one consolidated report for the group

    The modified regulation permits a parent company to submit a consolidated report covering its in-scope subsidiaries, rather than requiring each entity to file separately. Fees are still assessed on a per-company basis, so this is an administrative simplification rather than a financial one.

    The value is in coherence. One filing means one organisational boundary, one consolidation approach, one set of emission factors and one assurance conversation — instead of several subsidiary submissions that anyone can lay side by side and find inconsistent.

    One caveat: the consolidated boundary you use for California should reconcile to the consolidation approach in your GHG inventory and to whatever you publish elsewhere. A boundary chosen for administrative convenience creates a discrepancy you will spend years explaining.


    What the reliefs don’t touch

    Scope 3 arrives in 2027 — but only five categories

    CARB has signalled a phased approach for the 2027 cycle, with initial Scope 3 reporting focused on five commonly reported categories rather than all fifteen: purchased goods and services, fuel- and energy-related activities, waste generated in operations, business travel, and employee commuting, with flexibility around de minimis categories.

    That is a genuine sequencing instruction, and it is unusual to be handed one. Four of the five can be built largely from data your finance and HR systems already hold. The fifth — purchased goods and services — takes a year, because it depends on spend categorisation and supplier engagement rather than a single system. That is your critical path.

    Assurance is coming, on a proposed schedule

    CARB’s proposals introduce limited assurance over Scope 1 and Scope 2 from qualified independent providers, recognising several standards families — AICPA, IAASB and ISO-based frameworks among them — with a move toward reasonable assurance signalled around 2030. The detail is still in play; the direction is not. If you have been through limited assurance under CSRD, you know the real cost is not the auditor’s fee. It is having evidence attached to every number.

    SB 261 is still enjoined — SB 253 is not

    These two laws are routinely discussed together but sit in very different positions. The Ninth Circuit enjoined enforcement of SB 261, the climate-risk reporting law for companies above $500 million in revenue, on 18 November 2025 pending appeal; oral argument was heard on 9 January 2026 and, at the time of writing, no merits decision has been published. SB 253 was not enjoined. Its deadline is live. Anyone who paused California work on the strength of “the courts blocked it” has confused the two.


    Fourteen weeks: a working sequence

    • Re-run the threshold test on third-party revenue only, excluding intercompany turnover, and write down the answer with its basis.
    • Establish your 5 December 2024 position. What Scope 1 and Scope 2 data did you hold, or have in collection, at that date? That list defines the scope of your first report.
    • Decide the filing structure — consolidated at parent level or entity by entity — and check the boundary reconciles to your existing inventory.
    • Comment by 11 August if any of the three provisions is ambiguous for your structure — the last low-cost way to influence the text.
    • Separate the FY2025 filing from the 2027 build. Different projects, different standards of rigour; merging them is how first-year filings become nine-month programmes.
    • Start purchased goods and services now, not in 2027. It is the only one of the five categories that cannot be delivered in a quarter.

    The pattern is familiar. As we argued when the SEC’s climate rollback failed to free US multinationals, federal deregulation has not reduced disclosure obligation — it has moved it to states and to Europe, where the timetables are statutory and the reliefs are technical rather than political.


    If 10 November is on your calendar, the question is not how much data you can gather — it is how much you can evidence. Horizon ESG helps teams collect emissions data once, keep the audit trail attached, and report it against SB 253, CSRD and ISSB without rebuilding the inventory each time. Book a free demo.

  • ESRS-40a: CSRD Is Back for Non-EU Parent Companies

    For eighteen months, the message reaching boardrooms in New York, London, Zurich and Singapore has been reassuringly simple: the Omnibus package gutted CSRD, our European subsidiaries fell out of scope, file closed. For the EU entities, broadly true. What it missed is that the obligation did not disappear — it moved up the corporate structure, to the non-EU parent.

    On 23 July 2026, EFRAG published the Exposure Draft of ESRS-40a — the sustainability reporting standard for certain non-EU undertakings — and opened a 100-day consultation running to 31 October 2026. It implements Article 40a of the Accounting Directive, and applies a test with nothing to do with how many people you employ in Europe. If your group sells enough into the EU, you report.


    What ESRS-40a actually is

    Articles 19a and 29a of the Accounting Directive catch EU companies and EU-parented groups. Article 40a is the extraterritorial arm: it catches groups headquartered outside the EU that do significant business inside it. ESRS-40a is the standard telling them what to disclose, and the logic is a level playing field — a US or Japanese group booking hundreds of millions in EU revenue competes with EU companies carrying a full ESRS burden.


    The scope test: run it before you do anything else

    The threshold is two-part, and both parts must be met. A third-country undertaking not listed on an EU regulated market is in scope if it meets:

    • Turnover test. Net turnover in the Union above €450 million in each of the last two consecutive financial years; and
    • Presence test. Either an EU branch with net turnover above €200 million in the preceding financial year, or it is the ultimate parent of EU subsidiaries with net turnover above €200 million in the preceding financial year.

    These behave differently from the tests your European finance team has been applying: no employee headcount criterion, no balance-sheet criterion. It is a revenue test measured at group level on turnover booked in the Union — so a group with modest European operations and a lean legal footprint can still clear the bar on distribution revenue alone.

    Who actually publishes the report

    The parent is the reporting undertaking, but it does not file. The report is published on the parent’s behalf by an EU subsidiary that would itself fall within CSRD scope, or by a large EU branch. That puts a European entity — often one with no sustainability function of its own — on the hook for making a group-level disclosure public. Flag it early to your European legal and finance leads: the people who sign and file are rarely the people who produce the data.


    What you report — and, importantly, what you don’t

    ESRS-40a is deliberately lighter than a full ESRS sustainability statement. The Article 40a report focuses on impacts — the effects of the group’s activities on people and the environment. It generally excludes the risk-and-opportunity architecture Articles 19a and 29a demand: resilience analysis, dependencies, and the financial-materiality half of double materiality sit outside its content.

    For teams that have watched EU peers build scenario analysis and transition plans, that is good news. But narrower is not easier — the hard part of ESRS-40a is not the disclosure list. It is the boundary.


    The “mixed approach” is the fight that decides your cost

    This is the detail that deserves attention during the consultation window. The draft requires a blend of EU-scoped and global-scoped information — some disclosures drawn from the group’s European activities, others from the group as a whole.

    EFRAG’s own Sustainability Reporting Board did not approve this comfortably. It released the Exposure Draft while recording reservations about the mixed approach, and Chair Kerstin Lopatta published a letter setting out those concerns before launch, noting the approach reflects a request from the European Commission. The objection is practical as much as legal: separating EU-related impacts from global ones is difficult, and in places arbitrary.

    For a reporting team, that is not standard-setting politics — it is the single biggest driver of your data-collection cost. A global-scope disclosure can usually be sourced from systems you already run. An EU-scope disclosure means carving European activity out of consolidated data — by site, by entity, by supplier — for metrics your systems were never designed to slice that way. Every requirement landing on the EU-scoped side adds a pipeline you do not have.

    Which is why the consultation matters. Feedback closes 31 October 2026 and EFRAG’s technical advice goes to the Commission in January 2027. After that, the boundary question is settled and you are implementing someone else’s answer.


    The timeline looks distant. It isn’t.

    Reporting becomes mandatory for financial years beginning on or after 1 January 2028, with first reports published in 2029. Three years is comfortable — right up until you work backwards.

    • 2029 — first report published.
    • FY2028 — the reporting year. Data must be complete, consistent and evidenced across twelve months, from day one.
    • FY2027 — the dry run: find the gaps in EU-scoped data and fix them. Anyone through a first ESRS cycle knows this year is not optional.
    • 2026–2027 — scoping, system selection, and getting European entities collecting data in a form that consolidates.

    That leaves roughly eighteen months of genuine slack, not three years — landing on organisations that spent the last year actively de-resourcing European sustainability compliance.


    Why the scope cut makes this more exposing, not less

    EFRAG has estimated that the Omnibus changes cut the number of non-EU companies in scope from roughly 10,000 to around 1,200 — a 90% reduction, reported as relief. Consider it from the other direction: the remaining population is small, large and identifiable. Any regulator, NGO or journalist can assemble a credible list of who should be reporting and check whether they did. In a group of 10,000, a thin disclosure is noise. In a group of 1,200, it is a story.

    This is the same pattern we described when the SEC’s climate rollback failed to free US multinationals: deregulation in one jurisdiction rarely reduces total disclosure obligation for a global group. It relocates it.


    What to do before 31 October

    • Run the test properly. Get an accurate group-level figure for net turnover in the Union for the last two financial years. Not EU-entity revenue — turnover generated in the Union, which can include sales routed through non-EU entities.
    • Identify the filer. Determine which EU subsidiary or branch would carry the publication obligation, and tell them now.
    • Respond to the consultation. If you are in scope, the mixed approach will shape your cost base for a decade. This is the last practical window to influence it.
    • Map EU-scoped data. Take a first pass at which impact metrics you could already report at EU boundary and which need new collection. That gap list is your 2027 project plan.
    • Do not rebuild in a silo. Much of what ESRS-40a asks for overlaps with what you already produce for CDP, ISSB-aligned reporting, or an EU subsidiary’s own CSRD timeline. One data layer with multiple outputs beats a separate European reporting exercise.

    One honest caveat: ESRS-40a is a draft, its content will change before the Commission’s delegated act, and the mixed approach may not survive in its current form. What will not change is the scope test and the FY2028 start date — those sit in the Directive, not the standard. You can wait on the detail. You cannot wait on knowing whether you are in.


    If your group clears the €450 million test, the work starts with knowing what you can already produce at EU boundary. Horizon ESG helps multinational teams collect sustainability data once and report it against multiple frameworks — so a new obligation becomes a mapping exercise, not a new programme. Book a free demo.

  • Data Centres Just Became an ESG Disclosure Risk

    On 14 July 2026, New York became the first US state to slam the brakes on data centre construction. Governor Kathy Hochul signed an executive order barring the Department of Environmental Conservation from issuing discretionary permits for new data centres above 50 MW of power demand for up to a year, while regulators write comprehensive standards from scratch. The trade press read it as an energy-and-AI story. For sustainability teams, it is something else entirely: the moment data centre energy stopped being a line in your Scope 2 footnote and became a strategic disclosure risk your climate reporting has to describe.

    If your business runs a material digital estate — and in 2026 most do — this is the clearest signal yet that compute energy is moving from an efficiency talking point to a permitting, siting, and transition-risk question. The reporting frameworks you already comply with anticipated this. Most disclosures have not caught up.


    What New York actually did

    The order does not ban data centres. It pauses discretionary environmental permitting for the largest facilities — those drawing more than 50 MW, roughly the scale of a hyperscale or large colocation site — for up to twelve months while the state builds a standing regulatory regime. The stated concern is straightforward: surging AI and cloud demand is loading the grid faster than New York can plan for, and the existing permitting process was never designed to weigh that.

    The specifics matter less than the precedent. A US state has now formally treated large-scale compute as an environmental externality worth constraining. That is exactly the kind of policy shift that climate-risk frameworks classify as a transition risk — a change in the regulatory environment that alters the cost, feasibility, or location of your operations. And New York is unlikely to be the last mover; when one jurisdiction sets a template, disclosure-conscious investors start asking every data-centre-intensive issuer the same questions.


    Why this is a disclosure problem, not just an energy one

    Here is the disconnect. Most companies account for data centre electricity as a Scope 2 emissions figure — a number to be measured, reduced, and reported. That framing is correct but incomplete. It captures what your compute emitted last year. It says nothing about whether you can build, power, or expand that compute next year.

    From Scope 2 line item to transition risk

    A permitting moratorium changes the calculus. If a company’s growth assumes new data centre capacity in a jurisdiction that has just paused approvals, that assumption now carries policy risk — potential delay, higher cost, or forced relocation. Under a climate-risk lens, that is a material forward-looking exposure, not a historical emissions total. The same logic extends to grid connection queues, rising industrial power prices, and local opposition, all of which are tightening in the markets where compute demand is highest.

    The physical-risk angle teams forget

    Transition risk is only half the picture. Large data centres are also water-intensive — cooling can consume millions of litres a year — and they concentrate that demand in specific locations. That exposes them to physical climate risk: drought, heat stress, and water-access restrictions that can throttle operations regardless of how clean the power is. A disclosure that reports Scope 2 emissions but ignores where the facilities sit and what they depend on is telling investors half a story.


    What ISSB S2 and ESRS E1 already require

    None of this requires a new rule. The two frameworks most reporters are already inside — IFRS S2 from the ISSB, and ESRS E1 under the CSRD — both demand exactly the forward-looking narrative that data centre exposure calls for.

    • IFRS S2 requires disclosure of the climate-related risks and opportunities that could reasonably affect your prospects, split into transition and physical risk, plus how they feed strategy, financial planning, and resilience under different scenarios. A permitting-constrained compute footprint is a textbook example of what S2 expects you to surface.
    • ESRS E1 requires a transition plan, disclosure of material physical and transition risks, and reporting of energy consumption and mix alongside gross Scopes 1, 2, and 3. The connective tissue between your energy dependency and your strategic resilience is precisely what E1’s risk disclosures are for.

    In other words, the standards already ask the question. New York just made it concrete. For teams still treating climate risk and carbon accounting as separate exercises, this is the argument for joining them up — a theme we explored in our look at how TCFD and CSRD climate disclosure align.


    What a defensible disclosure looks like

    Most current data centre disclosure is boilerplate: an efficiency metric, a PUE figure, maybe a renewable-energy commitment. That is not what a climate-risk framework is asking for. A disclosure that would survive scrutiny does four things:

    • Locates the exposure. Identify where your material compute capacity sits — owned, colocated, or cloud — and flag jurisdictions where permitting, grid access, or water stress is tightening. Generic group-level statements are not enough.
    • Connects energy to strategy. Explain how future capacity needs interact with transition risk. If growth depends on new facilities, say what a permitting delay would mean for the plan.
    • Treats water as a risk, not a footnote. Disclose cooling water dependency in high-stress locations as a physical risk with operational consequences, not just a sustainability metric.
    • Quantifies where it can. Move from “we are committed to efficiency” to ranges, timelines, and scenario-tested impacts. Frameworks reward specificity and penalise vagueness.

    The reporting teams that get ahead of this will not be the ones with the lowest emissions. They will be the ones who can show investors they understand where their digital infrastructure is exposed — and have a credible plan for it. Reliable, location-aware energy and emissions data is the foundation for that; measuring your Scope 1, 2 and 3 footprint accurately is the first step, but connecting it to forward-looking risk is what turns a number into a disclosure.


    Turning compute energy into an audit-ready climate disclosure starts with data you can trust. Horizon ESG helps reporting teams link emissions, energy, and transition-risk narrative in one place — so when the next New York arrives, your disclosure is already ready. Book a free demo to see how.

  • CSRD Value-Chain Cap: What You Can Still Ask Suppliers

    Most of the coverage of the European Commission’s 3 July package led with the same number: a 60% cut in mandatory ESRS datapoints. That is the headline, and it is real. But buried in the second delegated act is a change that will reshape more programmes than the datapoint cut ever will — and almost nobody is briefing their procurement team on it.

    It is called the value-chain cap. In short: from financial year 2027, a CSRD-scope company will no longer be able to require its smaller suppliers to hand over sustainability data beyond a defined ceiling. If your supplier-engagement programme is built on a 200-question ESG questionnaire pushed down the chain, that programme now has a legal boundary running through the middle of it.

    What the Commission adopted on 3 July 2026

    The Commission adopted two delegated acts. The first is the revised set of European Sustainability Reporting Standards — the concrete landing of the Omnibus I simplification agenda. It cuts mandatory datapoints by over 60%, total datapoints by over 70%, and is expected to reduce reporting costs by more than 30% per company.

    The second is the one to read carefully: a Voluntary Sustainability Reporting Standard, built on the VSME, giving companies outside CSRD scope a single proportionate framework to report against. It is voluntary in the sense that no smaller company is obliged to use it. It is emphatically not voluntary in its effect on the companies above them in the chain — because it sets the ceiling.

    Both acts are now in a two-month scrutiny period before the European Parliament and Council, extendable by a further two months. If neither institution objects, they are published in the Official Journal and enter into force. That caveat matters, and we return to it at the end.

    The value-chain cap, precisely

    The cap protects companies with 1,000 employees or fewer that sit in the value chain of a CSRD reporter. Under the Omnibus I Directive, those companies are entitled to decline requests for sustainability information that go beyond what the Voluntary Standard covers. Micro-enterprises of ten employees or fewer get further relief on top. For CSRD-scope companies, the cap bites from financial year 2027.

    Read plainly, that inverts a decade of supplier-engagement practice. The implicit deal until now was that a large buyer could ask its suppliers for whatever its own reporting obligations demanded, and commercial leverage did the rest. From FY2027, the supplier has a statutory answer: no, and here is the standard that says so.

    Three things the cap does not do

    This is where the early commentary is getting it wrong, so it is worth being exact.

    • It caps what you can require, not what you can ask. The Commission has confirmed that a CSRD reporter may still request information beyond the cap — provided it clearly identifies which parts of the request exceed the cap and informs the supplier of their right to refuse. The cap creates a duty of transparency in the ask, not a prohibition on asking.
    • It applies only to CSRD reporting. The cap operates when fulfilling CSRD reporting obligations. It does not govern information you request for other purposes — commercial qualification, contractual assurance, product compliance, or your own risk management.
    • It does not stop a supplier volunteering more. Plenty of smaller suppliers will keep sharing data, because being easy to buy from is a competitive advantage. The cap removes the obligation, not the incentive.

    Together those three points reframe the cap. It is not a wall. It is a consent boundary — and crossing it now requires you to say out loud that you are crossing it.

    Where the cap collides with CSDDD

    Here is the tension nobody has resolved. The Corporate Sustainability Due Diligence Directive still requires in-scope companies to conduct risk-based human rights and environmental due diligence across their chain of activities — an approach Omnibus I preserved rather than narrowing to tier one. You cannot discharge a risk-based due-diligence obligation without information from the chain. Yet the ESRS package has just capped what you may require from a large part of that same chain.

    The reconciliation is in the scoping: the cap is tied to CSRD reporting obligations, and CSDDD due diligence is a separate legal duty. In principle, a due-diligence request is not a CSRD reporting request, and the cap does not extinguish it.

    In practice, that distinction is going to be tested hard — because it is usually the same supplier, receiving the same questionnaire, from the same buyer, in a single email. If your data requests do not distinguish their legal basis, you invite a supplier to refuse the whole thing on cap grounds, including the parts you are entitled to insist on. The operational bar for all of this is still being written: the Commission’s consultation on CSDDD implementation guidelines closes on 24 July 2026, with the guidelines expected in principle by July 2027. If your supplier programme is material to your business, that consultation is a genuine, closing opportunity to shape it.

    What to do in the next 90 days

    FY2027 sounds distant. It is not — supplier programmes have long lead times, and the contracts you sign this year will still be running when the cap bites.

    1. Re-baseline your supplier questionnaire against the Voluntary Standard. Every question you currently push down the chain now sorts into one of two buckets: inside the cap, or outside it. You cannot manage the boundary until you can see it.
    2. Get headcount into your supplier master data. The 1,000-employee line is now a legal boundary, and most procurement systems do not hold supplier headcount at all. This is the least glamorous item on the list and probably the one with the longest lead time.
    3. Redesign the ask, not just the question set. Beyond-cap requests need to be explicitly flagged as such, with the right to refuse stated. Build that into the template now rather than retrofitting it under deadline.
    4. Separate your legal bases. Split CSRD-reporting requests from due-diligence and commercial requests, and label them. This is the single change that most protects your CSDDD position.
    5. Plan for refusal. Assume a meaningful share of smaller suppliers will exercise the cap. That means leaning harder on estimation, sector averages and spend-based proxies for value-chain data — and being able to document why an estimate was used and how it was derived.

    Prepare — but do not decommission

    One final discipline. Both delegated acts are still in scrutiny, and the revised ESRS are set to apply to financial years beginning on or after 1 January 2027, with early application permitted. Nothing is in the Official Journal yet.

    So the correct posture is prepare, don’t freeze — and above all, don’t switch anything off. The most expensive mistake available right now is to read “60% fewer datapoints” as permission to dismantle data pipelines that a scrutiny objection, an early-adoption decision, or an investor’s own SFDR-driven data request could make you rebuild in eighteen months. Simplification is not the same as less work. A 70% datapoint cut creates a migration project before it creates a saving.

    The companies that will handle this well are the ones that can see, in one place, which datapoints they collect, which regime each one serves, and where in the value chain it came from. That is a data-architecture question long before it is a compliance one — and it is exactly what our CSRD readiness checklist is built to help you work through. If you would like to see how Horizon ESG maps a single data foundation across CSRD, CSDDD and the voluntary standard, book a short demo — we will walk your own supplier data through it.

  • Nature Disclosure Is Coming: Get TNFD-Ready by October

    Climate has dominated sustainability disclosure for a decade. Nature is next, and the timetable is now firm. During its June 2026 conference, the IFRS Foundation confirmed that the International Sustainability Standards Board (ISSB) will publish its nature-related disclosure proposals as an exposure draft in October 2026, timed to land ahead of the year’s biodiversity COP. For reporting teams that have spent two years building climate data pipelines, this is the signal to start scoping the next frontier before it becomes mandatory.

    The proposals will take the form of an IFRS Practice Statement rather than a new standalone standard, a route the ISSB agreed in April 2026. That structural choice matters, and it draws heavily on a framework many sustainability teams already recognise: the Taskforce on Nature-related Financial Disclosures (TNFD). Here is what is coming, why it consolidates TNFD as the global baseline, and the practical groundwork worth doing now.

    What the ISSB actually announced

    The October exposure draft will not be a tenth topical standard sitting alongside IFRS S1 and S2. Instead, it will be an IFRS Practice Statement — guidance that helps companies apply the existing ISSB standards, together with the SASB Standards, to nature-related topics. In plain terms, it explains how to surface material nature information using the machinery investors already understand, rather than asking preparers to learn an entirely separate rulebook.

    The scope spans the nature topics that most often drive financial risk: land use, water, pollution, resource use, and biodiversity. These are the areas where dependencies on natural systems — reliable water, healthy soil, stable ecosystems — and impacts on them can translate into cost, disruption, or lost access to markets and finance. And crucially, the ISSB has confirmed the proposals will draw directly on the TNFD framework, giving early TNFD adopters a genuine head start.

    One point deserves emphasis: an exposure draft is a consultation, not a final requirement. The October text will open a comment window before anything is finalised. That is time to prepare, not a reason to wait.

    Why TNFD is becoming the baseline

    TNFD published its final recommendations in September 2023, deliberately mirroring the four-pillar structure — Governance, Strategy, Risk and Impact Management, and Metrics and Targets — that the market already knew from the Task Force on Climate-related Financial Disclosures. That familiarity was the point. Anyone who has produced climate disclosure recognises the shape of a TNFD report immediately.

    The ISSB’s decision to build its nature guidance on TNFD follows the same path climate took. The TCFD recommendations were absorbed into IFRS S2 and the TCFD itself wound down, with its monitoring role passing to the IFRS Foundation. Nature is now travelling that route: a voluntary framework maturing into the reference point for a global, investor-focused standard. For preparers, that convergence is good news — it means the effort you put into TNFD-aligned work is unlikely to be wasted when the ISSB text lands.

    It also connects to obligations some companies already face. Under the CSRD, ESRS E4 requires disclosure on biodiversity and ecosystems where material, so EU-scope reporters are not starting from zero. If you are still mapping what “material” means across environmental and social topics, our guide to double materiality under CSRD is a useful companion, because nature dependencies and impacts sit squarely inside that assessment.

    What nature disclosure asks of you

    Nature reporting differs from climate reporting in one important respect. Greenhouse gases are broadly comparable wherever they are emitted, so a tonne of CO2e is a tonne of CO2e. Nature is local: the same activity can be immaterial at one site and severe at another, depending on the ecosystem around it. That is why TNFD frames the work through its LEAP approach — Locate, Evaluate, Assess, Prepare — which pushes teams to start from where they operate and interface with nature.

    • Locate your interface with nature — the sites, assets, and supply-chain nodes that sit in or near sensitive ecosystems and water-stressed areas.
    • Evaluate your dependencies and impacts at those locations, from water abstraction to land-use change.
    • Assess the resulting risks and opportunities in financial terms your board and investors can act on.
    • Prepare to respond and report, aligning the output with the four disclosure pillars.

    The practical implication is that location-level data — not just enterprise totals — becomes the raw material of a credible nature disclosure. Teams used to reporting a single group emissions figure will need to think at the level of individual sites and suppliers.

    How to get TNFD-ready before October

    You do not need to wait for the exposure draft to make progress. A focused scoping exercise now will make the eventual reporting far less painful:

    • Run a first-pass location screen. Map your operational sites and material suppliers against water stress and biodiversity-sensitivity data to see where nature risk concentrates.
    • Reuse your climate governance. The board oversight and risk processes you built for climate extend naturally to nature; you are adding a topic, not rebuilding the structure.
    • Fold nature into your materiality assessment. Treat dependencies and impacts on nature as candidate material topics in your next review rather than a separate, bolt-on exercise.
    • Audit your data foundations. Location-level, supplier-level detail is harder to assemble than a single carbon figure. Knowing where those gaps are now is worth more than a polished narrative later.
    • Track the convergence. Watch how the ISSB draft aligns with TNFD and ESRS E4 so you build once and disclose against several frameworks.

    Because the ISSB is building on structures the market already uses, the teams that stay closest to their climate disciplines will adapt fastest. If your climate reporting still leans on TCFD-era foundations, our explainer on how TCFD and CSRD align is a helpful reference point for understanding how these frameworks fit together.

    The bottom line

    Nature disclosure is following the same trajectory climate did: a voluntary framework, growing adoption, then absorption into the ISSB baseline. The October exposure draft is the moment that trajectory becomes concrete. Companies that begin locating their nature interface and tightening their data now will meet it as a manageable extension of existing work — not a standing start.

    Horizon ESG is an audit-ready ESG reporting platform that helps reporting teams manage climate, CSRD, and emerging nature requirements in one place, so location-level and supplier data feed straight into disclosure rather than living in scattered spreadsheets. Book a short demo to see how we can help you get ahead of the ISSB timeline with clarity.

  • SEC Climate Rollback Won’t Free US Multinationals

    The headlines are tempting: the SEC is moving to scrap the climate-disclosure rules it adopted in 2024, and some commentators have read that as the end of mandatory climate reporting for US companies. For any business with revenue in California or operations in Europe, the opposite is closer to the truth. The federal rule was only ever one of several overlapping regimes — and the others are advancing, not retreating.

    If your reporting plan hinges on the SEC standing down, this is the moment to stress-test it. Below is what is actually happening in Washington, why it changes less than it appears to, and what reporting teams should do while the noise settles.

    What the SEC is actually doing

    On 3 June 2026, the SEC’s proposed rescission of its 2024 climate-related disclosure rules was published in the Federal Register, opening a comment period that runs through 3 August 2026. Two points are easy to miss in the headlines. First, this is a proposal in its comment window, not a settled outcome. Second, the plan is to eliminate the dedicated framework rather than replace it — reverting issuers to principles-based, materiality-focused disclosure under existing securities law. The Commission has pointed to compliance savings of roughly $4.9bn a year.

    Removing a prescriptive rulebook is not the same as removing the obligation to disclose. Material climate risks that affect a reasonable investor’s decision can still require disclosure under long-standing materiality principles. What changes is the how and the how much — not the underlying duty. And for most multinationals, the SEC was never the binding constraint anyway.

    Why “no SEC rule” doesn’t mean “no disclosure”

    Three other regimes keep mandatory climate and greenhouse-gas disclosure firmly alive for US companies of any size that trade across state or national borders. None of them depend on the SEC.

    California: the de facto US standard

    California’s climate-disclosure laws reach far beyond the state’s borders because they apply to companies “doing business in California,” regardless of where they are headquartered. Two statutes matter:

    • SB 253 (Climate Corporate Data Accountability Act) requires companies with total annual revenues above $1bn to report Scope 1, Scope 2 and, in a later phase, Scope 3 greenhouse-gas emissions.
    • SB 261 (Climate-Related Financial Risk Act) requires companies with revenues above $500m to publish a climate-related financial-risk report aligned with the TCFD recommendations.

    Because the revenue thresholds are low relative to the size of a typical multinational, the practical effect is that a large share of US companies that would have reported to the SEC are captured by California instead — and California explicitly requires Scope 3, which the federal approach was always more cautious about. For most large filers, the toughest disclosure bar in the US now sits in Sacramento, not at the SEC.

    The EU: CSRD reaches across the Atlantic

    The EU’s Corporate Sustainability Reporting Directive pulls in non-EU groups through their European operations. A US parent with substantial EU subsidiaries or branches can fall directly within scope, and even companies that sit outside mandatory scope routinely receive value-chain data requests from European customers who need the numbers for their own ESRS reports. The recent “Omnibus” simplification narrowed who must report at the top of the chain, but it did not switch off the demand for emissions and sustainability data flowing down global supply chains.

    In other words, even a US company with no EU listing can find itself assembling ESRS-grade data because a major European buyer asks for it. If you sell into Europe, CSRD is part of your reality whether or not your own name is on a filing.

    The UK: anti-greenwashing and SDR

    For US groups with UK-regulated financial arms, the FCA’s Sustainability Disclosure Requirements regime adds a third layer. Its anti-greenwashing rule applies to all FCA-authorised firms, and from 30 June 2026 the remaining in-scope asset managers above £5bn in assets must publish entity-level disclosures. The throughline is consistent: any claim you make about sustainability has to be substantiated, and the supporting data has to exist.

    Fragmentation, not freedom

    The real consequence of the SEC’s retreat is not less work — it is less harmonisation. A single US-federal climate rule would at least have given multinationals one reference point that broadly tracked the global ISSB and EU baselines. Without it, a company can find itself reconciling California’s emissions thresholds, the EU’s double-materiality model, and the UK’s disclosure expectations, each with its own scope, boundary and timing.

    That is an argument for building disclosure on a single, well-governed dataset rather than chasing each regime with a separate project. The metrics underneath — Scope 1, 2 and 3 emissions, climate risk, governance and targets — overlap heavily. The expensive mistake is collecting them three times.

    What reporting teams should do now

    • Map your real obligations, not the federal one. Test your revenue and operations against California’s SB 253 and SB 261 thresholds and against EU value-chain exposure before assuming the SEC change lets you scale back.
    • Keep your GHG inventory live. Scope 1, 2 and 3 data feeds California, CSRD and customer requests alike, so a robust carbon accounting foundation is the one investment that pays off under every regime.
    • Build once, report many times. Structure your data so a single source can be mapped to multiple frameworks rather than rebuilt for each.
    • Watch the comment window, but don’t wait on it. The SEC proposal closes for comment on 3 August 2026; nothing about that date pauses California or Europe.

    The companies that handle this period well will be the ones that treated the SEC rule as one input among several, not the keystone. The disclosure expectation has not gone away — it has simply spread out, and it now rewards teams with clean, reusable data more than ever.

    Reporting under more than one rulebook? Horizon ESG helps teams collect emissions and sustainability data once and map it to CSRD, California and other frameworks from a single source. See how it works.

Book Your Free Demo