
ESG data processes: collection, roles and data quality
More than one place in the company needs ESG data today: the sustainability statement, internal steering, supervisory reporting, and the requests that come in from banks, investors and major customers. In many companies a separate collection route has grown up for each of these purposes, built on spreadsheets and email requests. Documents that show the same metric then diverge from one another, and the work starts from scratch every year. A reliable data process sets out, for every metric, which source it comes from and who owns it. On top of that comes a reasoned statement about its quality.
Where the pressure comes from
Credit institutions: Under CRR III, the ESG disclosures required by Article 449a apply to all CRR institutions. On 22 June 2026 the EBA published the final draft implementing technical standards amending Implementing Regulation (EU) 2024/3172, now with the Commission for adoption. They follow a tiered approach of core requirements and supplements: large institutions report 37 per cent fewer datapoints than today, other institutions 17 per cent fewer, and small and non-complex institutions 84 per cent fewer than large banks. The first reference date is 31 December 2026, and 31 December 2027 for small and non-complex institutions. In parallel, the EBA is building an ESG supervisory reporting framework for all CRR institutions on the basis of Article 430(7) CRR, intended to replace the ad hoc data collections used so far. The first reporting reference date is 31 December 2027.
Insurers: For insurers the data converges in the ORSA and the Solvency and Financial Condition Report. The amended Solvency II Directive, which applies from 30 January 2027, adds the climate scenario analysis under Article 45a and the sustainability risk plan, whose quantifiable targets are disclosed annually. Both draw on the same data as the accounting for insured emissions.
Asset managers: For asset managers the data feeds disclosure under the Sustainable Finance Disclosure Regulation (SFDR), and the principal adverse impact indicators in particular. The entity-level statement covers four reference dates in the calendar year and has to be published by 30 June of the following year. The expectation is the same as in banking: every published figure has to be traceable back to its source.
Companies in the real economy: The revised ESRS, adopted by the Commission on 3 July 2026, cut the number of mandatory datapoints by more than 60 per cent. They apply for financial years beginning on or after 1 January 2027, with an option to apply them for 2026. Companies already collecting data are therefore adjusting their processes to a markedly different scope, while also testing their existing double materiality assessment against the new requirements.
Companies outside the reporting scope have had the Voluntary Standard, the successor to the VSME, since the same date. Under the value chain cap, companies in scope may as a rule ask counterparties with fewer than 1,000 employees only for what that standard covers. For data requests along the supply chain it therefore becomes the format that matters.
The bottleneck sits with your counterparties. Following the revision of the CSRD, only companies with more than 1,000 employees and more than EUR 450 million in turnover report as a matter of obligation. For much of your lending, investment or supplier base there will be no audited primary data, and that will not change. Estimation methods and proxies therefore remain part of the process, and you need to be able to justify and document them.
Common weaknesses
The causes rarely lie in the technology. More often there is no clear ownership, because the business function, controlling and the sustainability team each contribute a piece of the metric and nobody stands behind the result. Proxies are used without anyone writing them down, and a year later no one can say what a figure rests on. Reporting and internal steering also tend to work with different reference dates or consolidation scopes.
Our services
-
Deriving the data requirement: We work backwards from the metric. For every reporting, supervisory and steering figure we identify the raw data it needs and bring the requirements together into a single collection exercise.
-
Target processes and role model: We map the collection processes end to end and assign responsibility for each step through a clear RACI matrix. Roles carry the responsibility rather than departments, and sign-offs sit where decisions are actually made.
-
Data quality and estimation methods: We set quality criteria for each datapoint, classify financed and insured emissions along the PCAF data quality scores, and determine which estimation approach is acceptable for which data situation and how it is to be documented.
-
External data sources and supplier requests: We select data providers and test coverage and methodology against your own portfolio. Data collection from suppliers and investees is aligned with the Voluntary Standard, so that the information stays reusable for both sides.
-
Implementation in your systems: We support the selection and rollout of an ESG data platform, from requirements gathering through mapping the target processes in the system to handover into operations.
-
Audit-ready documentation: We record assumptions, sources and methodological decisions so that internal audit, your external auditor and your supervisor can follow the path from the raw data source to the published figure.
Contact us
Whether this is your first collection exercise, the move to the revised ESRS or the replacement of a patchwork of spreadsheets, we will work out with you where your data processes stand and which step makes sense next.
