Environmental, Social and Governance (ESG) reporting has moved from voluntary to mandatory across much of Europe, and from a communications exercise to an assured disclosure. Investors use it for due diligence, customers for procurement decisions, and regulators increasingly require it outright.
For an organisation starting from nothing, the framework landscape — GRI, SASB, TCFD, ISSB, CSRD and the ESRS — is genuinely confusing. This guide sets out what each one is for, and a practical order of work.
What ESG Reporting Covers
- Environmental — greenhouse gas emissions, energy, water, waste, pollution, biodiversity, resource use.
- Social — own workforce, workers in the value chain, health and safety, diversity, affected communities, consumers.
- Governance — board structure and oversight, business ethics, anti-corruption, political engagement, payment practices.
The Framework Landscape
The frameworks differ mainly in who they are written for, which is the fastest way to tell them apart:
| Framework | Audience | Nature |
|---|---|---|
| GRI | Multi-stakeholder | Voluntary; impact-oriented; the most widely used globally |
| SASB (now ISSB) | Investors | Industry-specific; financially material topics |
| TCFD | Investors | Climate-specific; four-pillar structure |
| IFRS S1/S2 (ISSB) | Investors | Global baseline; S2 incorporates the TCFD structure |
| ESRS (under CSRD) | Multi-stakeholder | Mandatory for in-scope EU companies; double materiality |
| SFDR | Investors | For financial market participants and products |
Two clarifications that save confusion. TCFD has been disbanded, with monitoring transferred to the ISSB — but its four-pillar structure (governance, strategy, risk management, metrics and targets) survives inside IFRS S2 and the ESRS climate standard, so work done against it is not wasted. And SASB standards continue under ISSB stewardship.
Note also that CSRD scope and timing have been subject to amendment, including the 2025 "omnibus" proposals. Confirm your applicable wave and first reporting year against current national transposition rather than the original directive.
First Steps, in Order
1. Determine Whether You Are In Scope
Before choosing a framework, establish whether reporting is mandatory for you, voluntary, or contractually required by a customer or lender. These lead to very different levels of effort, and organisations regularly over-build for obligations they do not have — or discover late that they do.
Being in a larger company's value chain matters too: their Scope 3 reporting will ask you for data whether or not you report yourself.
2. Run a Materiality Assessment
Identify which topics actually matter. Under CSRD this is a double materiality assessment asking two questions: how sustainability matters affect the company (financial materiality), and how the company affects people and environment (impact materiality). A topic is material if it meets either test.
Both are risk assessments with the structure your enterprise risk process already uses — likelihood against consequence, on defined scales, with thresholds. Running them inside your existing methodology is faster and more defensible than inventing a parallel scoring system you then have to justify to an assurance provider.
Document the whole thing: stakeholder engagement, matters considered, scoring, thresholds, and the resulting material topics. The assessment is itself an auditable artefact.
3. Establish Data Ownership Before Collecting
The usual failure is starting with a data-collection spreadsheet. Assign each metric an owner, a source system, a calculation method and a frequency first. Metrics without an owner do not get collected, and metrics without a documented method cannot be assured.
4. Start With Scope 1 and 2
The GHG Protocol splits emissions into three scopes. Scope 1 (direct, from owned or controlled sources) and Scope 2 (indirect, from purchased energy) are tractable — fuel, refrigerants, and energy bills, with location-based and market-based figures for Scope 2.
Scope 3 — all other value-chain emissions across 15 categories — is where credibility is won or lost, and it depends on data you do not control. Two approaches: spend-based (spend × emission factor: quick, imprecise) and activity-based (physical quantities × factors: better, harder). Start spend-based, identify which categories are material, and migrate those to activity-based over time.
Assurance does not demand perfect data. It demands disclosed method, disclosed factor source and version, and consistency between periods, with restatements visible as restatements. A documented estimate is defensible; a precise-looking number with no provenance is not.
5. Set Targets That Can Be Evidenced
A target needs a baseline year, a defined scope, a mechanism, and interim milestones. "Net zero by 2030" with no baseline and no interim points cannot be tracked, and increasingly attracts greenwashing scrutiny rather than credit.
6. Build the Evidence Trail From the Start
Sustainability data is the least mature data most organisations hold, and it is now subject to assurance. Retrofitting provenance later is far more expensive than capturing it as you go:
- Provenance — for every figure, its source or supplier, submission date, and the request it answers.
- Method and factor version recorded alongside estimates.
- Immutability — submissions versioned, never overwritten.
- Controls over completeness and accuracy, with owners and test results.
- Linkage to the risk register, so a supplier data failure is an assessed risk rather than a red dashboard cell.
Supplier data is the weakest link because it originates outside your control environment — but the machinery that already governs security questionnaires applies to ESG questionnaires unchanged.
7. Report, Then Improve
Publish, obtain assurance where required, and treat the first cycle as a baseline rather than a finished product. First reports are always weaker than third ones; the value is in establishing the data foundations.
Where ESG Meets GRC
The "G" in ESG is governance — the same governance apparatus your compliance function already runs. Climate and social risks belong in the enterprise risk taxonomy. ESRS disclosures need controls with owners and evidence, exactly like ISO 27001. Supplier ESG assessment is third-party risk management with different data fields.
Organisations that recognise this run one system and report against many frameworks. Those that do not maintain parallel worlds and reconcile them by hand — see our guide to GRC and ESG integration.
A dedicated ESG platform built on a GRC foundation keeps materiality, metrics, controls and evidence in one place. See our ESG frameworks coverage or request a demo.