OvalEdge Blog: Data Catalog and Metadata Management Tips

What Is ESG Reporting? A Complete Business Guide for 2026

Written by OvalEdge Team | Dec 11, 2025, 8:16:17 AM

ESG reporting enters 2026 under greater pressure to prove that disclosed figures can withstand scrutiny.

According to a 2026 WorldMetrics report, 92% of Fortune 500 companies have set net-zero targets, yet only 22% of companies have their ESG disclosures verified by third parties.

This gap highlights a growing challenge: ambitious ESG commitments are moving faster than the data controls needed to substantiate them. At the same time, regulatory requirements are shifting, with the European Union narrowing CSRD scope, the U.S. federal climate disclosure landscape changing, and California introducing significant reporting obligations.

As assurance expectations increase, organizations need ESG data that is accurate, traceable, and governed from source to disclosure. This guide covers ESG reporting requirements, frameworks, processes, and the data practices needed to build assurance-ready reports in 2026.

What is ESG reporting?

ESG reporting is the practice of disclosing a company’s environmental, social, and governance performance against recognized standards. It gives investors, regulators, lenders, and customers structured, comparable information on areas such as greenhouse gas emissions, energy use, workforce practices, supply chains, board oversight, and executive compensation.

For example, a manufacturer reporting its Scope 1 emissions may need to combine fuel consumption data from facilities, fleet records, and operational systems, calculate emissions using an approved methodology, and retain evidence showing where every figure originated.

That traceability is increasingly important as ESG disclosures face external assurance. Yet the underlying information often sits across HR platforms, ERP systems, procurement tools, facilities systems, and supplier spreadsheets that were never designed for auditable reporting. As a result, organizations often encounter a data quality problem before they encounter a disclosure problem.

ESG reporting vs sustainability reporting vs CSR reporting

CSR, sustainability, and ESG reporting overlap, but they differ in purpose, audience, and level of scrutiny.

CSR reporting typically communicates a company’s social and environmental initiatives to employees and the public, often through narrative reporting with limited standardization.

Sustainability reporting focuses more specifically on a company’s environmental and social impacts and often follows recognized reporting standards.

ESG reporting adds governance and connects environmental and social factors to business risk, performance, and enterprise value. It is generally more standardized and increasingly subject to regulatory requirements and external assurance.

Comparison factor

CSR reporting

Sustainability reporting

ESG reporting

Primary audience

Public, employees

Communities, stakeholders

Investors, regulators, lenders

Standardization

Low

Moderate

High

Core focus

Corporate responsibility

Environmental and social impact

ESG factors, risk, and value

Assurance

Rare

Occasional

Increasingly required

In practice, companies may combine all three in a single report. What matters most is whether the underlying claims and metrics are consistent, traceable, and defensible under external scrutiny.

The three pillars of ESG reporting and what each one measures

Each pillar covers a distinct set of disclosures, and each carries its own measurement problem.

1. Environmental

The environmental pillar is dominated by greenhouse gas accounting, which the Greenhouse Gas Protocol splits into three scopes. Scope 1 covers direct emissions from sources a company owns or controls, such as company vehicles and on-site fuel combustion.

Scope 2 covers indirect emissions from purchased electricity, steam, heating, and cooling. Scope 3 covers everything else in the value chain, including purchased goods, business travel, and the use of sold products.

Scope 1 and Scope 2 are usually calculable from utility bills and fleet records. Scope 3 routinely accounts for the large majority of a company's footprint and depends on data the company does not own, which makes supply chain data quality the binding constraint for most industrial and retail reporters.

The pillar also covers energy consumption and renewable share, water withdrawal and discharge, waste generation and diversion, and biodiversity impact. Production and facilities data feeds most of these figures, which is why governed manufacturing data determines how much of the environmental pillar can be automated.

2. Social

The social pillar covers workforce composition and pay equity, health and safety incident rates, training hours, employee turnover, human rights due diligence across suppliers, and community investment.

Most of these figures sit in human resources and health and safety systems built for operational reporting, which creates definitional conflicts. A single term such as "contractor" can be counted three different ways across three systems, and every one of them is defensible in isolation.

3. Governance

The governance pillar covers board composition and independence, executive compensation structure, anti-corruption policies and incidents, tax transparency, data privacy practices, and business ethics.

Governance disclosures are the most narrative of the three and the easiest to draft, which is why they attract the most scrutiny for gaps between stated policy and observed practice.

Is ESG reporting mandatory? The 2026 regulatory landscape

ESG reporting is mandatory for companies that meet specific jurisdictional thresholds, while others continue to report voluntarily in response to investor, lender, or customer requirements. In 2026, the biggest changes affect the European Union and the United States.

European Union: CSRD now covers fewer companies

The EU significantly narrowed the scope of the Corporate Sustainability Reporting Directive (CSRD) under the Omnibus I package in February 2026.

Companies now in scope include:

  • Large EU companies: More than 1,000 employees and over €450 million in annual turnover.

  • Non-EU companies: More than €450 million in EU revenue with an EU branch or subsidiary generating over €200 million.

  • Listed SMEs: Removed from mandatory CSRD reporting.

The revised rules also maintain limited assurance rather than progressing toward reasonable assurance. First-wave companies continue reporting through 2027, the expanded wave begins in 2028 using fiscal year 2027 data, and qualifying non-EU groups begin in 2029.

United States: no active federal climate disclosure mandate

The federal reporting landscape moved in the opposite direction. The Securities and Exchange Commission (SEC) adopted climate disclosure rules in March 2024 but stayed them during litigation the following month. After ending its defense of the rules in 2025, the SEC proposed rescinding them entirely on May 29, 2026.

As a result, state-level requirements have become more important for companies operating in the United States.

California: SB 253 and SB 261 drive reporting requirements

California has introduced two major climate reporting requirements based primarily on company revenue:

Requirement

Who is covered

What must be reported

SB 253

Companies doing business in California with revenue above $1 billion

Scope 1 and 2 emissions, with Scope 3 and assurance requirements phasing in

SB 261

Companies doing business in California with revenue above $500 million

Biennial climate-related financial risk reports

These requirements can apply regardless of where a company is headquartered, making California relevant to large businesses operating well beyond the state.

Other countries: ISSB adoption is expanding

Australia, Singapore, Hong Kong, Japan, Brazil, and Chile have adopted or are phasing in disclosure requirements aligned with ISSB standards.

For multinational companies, the challenge is increasingly managing overlapping requirements. A company subject to both CSRD and California rules may need to report similar emissions data using different boundaries, assurance requirements, and deadlines.

Maintaining one governed ESG dataset that can support multiple reporting regimes reduces duplication and depends on lineage that holds up under regulatory reporting.

ESG reporting frameworks and standards compared

Frameworks define what a company discloses and how each figure is calculated. The field consolidated significantly, and several names still in wide circulation no longer operate independently.

Framework

What it covers

Status in 2026

Best fit

GRI

Environmental, social, and economic impacts

Voluntary global standard

Broad stakeholder and impact reporting

SASB Standards

Industry-specific, financially material sustainability topics

Voluntary; maintained by the ISSB

Industry-specific investor disclosures

ISSB (IFRS S1 and S2)

Sustainability-related financial risks and climate disclosures

Global baseline; increasingly adopted into regulation

Investor-focused global reporting

ESRS (under CSRD)

Environmental, social, governance, and cross-cutting disclosures

Mandatory for companies in scope of CSRD

EU regulatory reporting

TCFD

Climate-related governance, strategy, risk, and metrics

Disbanded in 2023; incorporated into IFRS S2

Legacy climate reporting reference

Two points matter more than the individual descriptions.

  • First, these frameworks stopped being alternatives to each other. ISSB standards act as the financial baseline, the Global Reporting Initiative covers impact, and the European Sustainability Reporting Standards form the mandatory European overlay referencing both. Most large reporters combine two or three and publish an index mapping every disclosure.

  • Second, the Task Force on Climate-related Financial Disclosures is still cited as a live framework in guidance published this year. It disbanded in 2023, and the ISSB assumed its monitoring role, so reporting "in line with TCFD" in 2026 means reporting against IFRS S2.

The selection question is rarely which framework is best. It is which ones a company is obligated to, which ones its investors and customers ask for, and whether the underlying data can support all of them from one source.

What goes into an ESG report

A complete ESG report follows a recognizable structure regardless of framework.

  • Statement from leadership. A signed letter from the chief executive or board chair, increasingly treated as a governance disclosure in its own right.

  • Materiality assessment. The topics judged material, the method used, and the stakeholders consulted. Under CSRD, this means double materiality, covering both how sustainability issues affect the company and how the company affects people and the environment.

  • Performance data. The quantitative core: emissions by scope, energy, water, waste, workforce metrics, and safety rates, with prior-year comparatives and progress against stated targets.

  • Targets and progress. Baseline year, target year, interim milestones, and candid reporting where targets were missed or restated.

  • Governance disclosures. Board oversight of sustainability, management responsibility, incentive linkage, and policy inventory.

  • Framework index. A mapping table showing where each required disclosure sits, which is what lets an assurance provider navigate the document.

  • Assurance statement. The provider, the scope of what was assured, and the level obtained.

The performance data section is where reports fail. Narrative sections get drafted and approved internally. Quantitative sections must reconcile to source systems, and that reconciliation is what an assurance provider tests.

Much of the supporting evidence sits in policies, contracts, and supplier documents, which is why unstructured data governance surfaces as a problem midway through the first assured cycle.

How to do ESG reporting: A six-step process

Effective ESG reporting requires more than collecting sustainability metrics. Organizations need a repeatable process that connects reporting obligations to material topics, trusted source data, clear ownership, validation, and assurance.

Step 1: Determine obligations and audience

Identify which ESG reporting requirements apply based on revenue, employee count, listing status, and geographic footprint. Then account for voluntary expectations from investors, lenders, customers, and other stakeholders.

Use these requirements to establish the applicable frameworks, disclosure scope, and reporting deadlines.

Business outcomes:

  • Avoid unnecessary reporting effort

  • Reduce regulatory exposure

Step 2: Run a materiality assessment

Determine which ESG topics matter most through stakeholder engagement, peer benchmarking, and risk analysis. For organizations subject to CSRD, this includes double materiality, covering both sustainability-related financial risks and the organization's impacts on people and the environment.

Use the assessment to prioritize the topics and metrics that belong in the report.

Business outcomes:

  • Focus resources on material issues

  • Prioritize decision-relevant ESG data

Step 3: Map each metric to a source system

For every required ESG metric, identify its system of record, data owner, calculation method, and reporting frequency. This process often reveals inconsistent definitions, missing ownership, manual calculations, and data fragmented across HR, ERP, procurement, facilities, and other systems.

Implementation tip: Use OvalEdge’s 170+ pre-built connectors to discover and inventory ESG data across cloud, on-premises, and legacy source systems without building custom integrations.

Business outcomes:

  • Reduce manual data collection

  • Improve metric traceability

Step 4: Establish ownership and controls

Assign a named owner to each ESG metric and define responsibility for collection, review, approval, and changes. Establish controls for calculations, versioning, approvals, and exceptions so every reported figure can be reproduced and explained.

Where multiple teams contribute to the same metric, standardize definitions and calculation rules across the organization.

Business outcomes:

  • Strengthen data accountability

  • Reduce reporting inconsistencies

Step 5: Collect, calculate, and validate

Collect ESG data from approved sources and apply the calculation methods required by the relevant reporting framework. Validate results against prior periods, expected ranges, and supporting records.

Quality checks should flag missing data, duplicates, outliers, inconsistent definitions, and unexpected changes before metrics enter the final disclosure.

Business outcomes:

  • Improve ESG data accuracy

  • Reduce assurance findings

Step 6: Draft, assure, and publish

Combine validated metrics with the required narrative disclosures, complete internal reviews, and submit applicable information for external assurance. Resolve identified issues before publishing the final report according to regulatory and stakeholder deadlines.

Feed assurance findings back into source mapping, controls, ownership, and validation to strengthen future reporting cycles.

Business outcomes:

  • Accelerate assurance and approval

  • Increase stakeholder confidence

Why ESG data quality decides whether a report survives assurance

Assurance tests whether ESG figures can be traced, reproduced, and supported by reliable evidence. Providers typically trace selected metrics back to their source, verify calculations and underlying data, and check whether methodologies have been applied consistently across reporting periods.

Three data quality failures commonly create problems during this process.

1. Inconsistent definitions across systems

Terms such as headcount, contractor, facility, and business unit may be defined differently across HR, ERP, and facilities systems. Combining these sources can produce inconsistent ESG metrics before calculations even begin. Standardized business definitions help ensure every team calculates and reports the same metric consistently.

2. Numbers without a traceable path

If an emissions figure changes, reporting teams need to demonstrate what changed, where the underlying data originated, and how the final value was calculated. Spreadsheet-based processes often make this difficult.

Important note: ESG data can be accurate and still fail assurance if the organization cannot demonstrate its origin, transformations, and calculation history. Automated data lineage creates a traceable path from source systems to reported figures, providing stronger evidence for assurance and restatements.

3. No clear signal of trusted data

Reporting teams may have multiple datasets available without knowing which one has been validated for reporting. Certification based on quality, lineage, ownership, documentation, and governance criteria gives analysts a clear indication of which data is approved for use.

These challenges make ESG assurance a broader data governance concern. Connecting definitions, ownership, quality, certification, and lineage gives reporting teams the trusted data foundation needed to produce ESG disclosures that can withstand external scrutiny.

What to look for in ESG reporting software

ESG tools fall into two categories, and the distinction shows up at renewal. Disclosure platforms manage the reporting workflow: framework templates, questionnaire responses, narrative drafting, and submission. Data platforms manage the layer underneath: where figures originate, whether they are accurate, and whether the path can be reconstructed on demand.

A disclosure platform assumes clean inputs. Where the inputs are the problem, the result is a well-formatted report built on figures nobody can defend.

Criteria worth weighting heavily during evaluation:

  • Source system coverage, including legacy and on-premises platforms holding facilities and manufacturing data.

  • Automated lineage instead of manually maintained documentation, since hand-drawn maps go stale between reporting cycles. Compliance-grade lineage software and column-level lineage are the relevant benchmarks.

  • Continuous quality monitoring rather than a pre-submission check, using rule-based and machine learning anomaly detection across pipeline health, freshness, and schema drift.

  • Audit trail depth, covering who changed what, when, and under which approval.

  • Reusability across regimes, so one governed dataset serves CSRD, California, and investor questionnaires.

Agent-driven automation has made this practical for lean teams. Governance agents handle the heavy lifting with humans in the loop: Sift classifies sensitive and regulated data across connected systems, Litmus recommends quality rules from data profiles, and Notary evaluates assets against certification standards.

For organizations already running governance at scale, ESG becomes another consumer of enterprise governance infrastructure instead of a separate program.

Conclusion

The 2026 rules narrowed who must report and raised what a report has to withstand. Scope shrank in Europe, the federal rule in the United States is being withdrawn, and California, investors, and customers filled the gap. What remains consistent is the need for every disclosed figure to trace back to a system of record with a named owner and documented history.

Strong ESG reporting therefore depends on strong data governance. OvalEdge brings catalog, lineage, glossary, data quality, and access together in one platform, helping ESG, finance, and data teams establish trusted, traceable data for reporting and assurance.

Book a demo to see how OvalEdge can make ESG reporting more defensible under assurance.