Logotipo Datanet iot

ESG Compliance in 2026: What Survives an Audit

Goldman Sachs paid $4 million because one of their ESG-labeled funds had no written research policies for over a year. DWS paid EUR 25 million because “ESG is in our DNA” didn’t match what prosecutors found inside the company. Both organizations had frameworks. Both published reports. What neither had was an evidence chain connecting public claims to internal decisions.

That gap is the real test of ESG compliance. Not which acronym you adopt. Not how polished the sustainability PDF looks. Whether every material ESG statement your company makes can answer six questions: what was claimed, for which boundary and period, using which method, supported by which evidence, approved by whom, and updated how when better data arrived.

I run growth at an IoT company. My day-to-day is asset trackers, environmental sensors, and operational data flowing from ports, warehouses, and freight operators. ESG compliance entered my work not through regulation, but through customers asking: “Can your tracking data feed our sustainability reports?” The answer depends entirely on the evidence architecture underneath. That’s what this guide unpacks.

What ESG Compliance Means in Practice

ESG stands for environmental, social, and governance. The term describes three categories of non-financial factors that affect a company’s risk profile, stakeholder relationships, and long-term viability.

Compliance means meeting the specific obligations attached to those factors. Here’s where most guides lead people astray: there is no single “ESG law.” The obligations come from a portfolio of sources.

  • Securities regulations (CSRD in the EU, state-level rules in the US)
  • Supply-chain due diligence directives (EU CSDDD)
  • Anti-greenwashing rules (UK FCA)
  • Lender covenants and insurance sustainability requirements
  • Customer questionnaires that are contractually binding
  • Voluntary commitments that become auditable once you publish them

A freight operator running containers between Rotterdam and Long Beach could face CSRD reporting in Europe, California Scope 1-2-3 emissions disclosure, customer ESG questionnaires from major retailers, and lender sustainability covenants. All simultaneously. All with different scopes, timelines, and definitions of what counts as “material.”

The financial stakes are real, if volatile. Global sustainable funds held over $3.9 trillion in assets at the end of 2025, despite recording $84 billion in net outflows that year. By Q2 2026, inflows returned at an estimated $3.7 billion. Capital that considers ESG factors hasn’t disappeared. It’s gotten more selective. Sloppy ESG claims now lose capital faster than having no ESG program at all.

ESG compliance is therefore not a single checkbox. It’s a control architecture that maps each obligation to data, owners, evidence, and review cycles.

Close up of a technician inspecting monitoring equipment on a pipe to ensure strict esg compliance standards.

The Regulatory Landscape in 2026

The regulatory picture has fractured along geographic lines, and 2026 is the year that fracture became impossible to manage with a single global policy.

European Union. The Corporate Sustainability Reporting Directive (CSRD) requires large and listed companies to report sustainability risks, opportunities, and impacts under the European Sustainability Reporting Standards (ESRS). The EU has introduced simplification proposals and a “stop-the-clock” measure, but the core obligation stands. The Corporate Sustainability Due Diligence Directive (CSDDD) targets very large companies (5,000+ employees, EUR 1.5 billion+ worldwide turnover) with obligations beginning in 2028. And the EU ESG Ratings Regulation applies from July 2, 2026, requiring transparency and integrity from rating providers.

United States (federal). The SEC proposed rescinding its climate-disclosure rules entirely in May 2026, concluding they exceeded statutory authority. The rules had been stayed since April 2024. Federal retreat does not mean US companies are off the hook.

United States (state). California’s SB253 applies to US entities doing business in California with over $1 billion in revenue, requiring annual Scope 1, 2, and 3 disclosures. SB261 requires biennial climate-related financial risk reports from companies with over $500 million in revenue. These laws create binding obligations regardless of federal direction.

Global convergence. Thirty-six jurisdictions had adopted, used, or were finalizing use of the ISSB Sustainability Disclosure Standards by June 2025. ISSB is becoming the common investor-oriented baseline, even as local rules diverge in scope and ambition.

Jurisdiction Key regulation Who it covers Status in 2026
EU CSRD / ESRS Large and listed companies Active (with simplification proposals)
EU CSDDD 5,000+ employees, EUR 1.5B+ turnover Transposition by 2026; obligations from 2028
EU ESG Ratings Regulation Rating providers operating in the EU Applies from July 2, 2026
US (federal) SEC climate rules Public companies Proposed rescission (May 2026)
US (California) SB253 $1B+ revenue, doing business in CA Active; Scope 1, 2, and 3 reporting
US (California) SB261 $500M+ revenue, doing business in CA Active; biennial climate risk reports
UK FCA anti-greenwashing rule Authorized financial firms Active since May 2024
Global ISSB (IFRS S1/S2) Varies by adopting jurisdiction 36 jurisdictions adopting or finalizing

The practical takeaway: size your compliance program around the strictest jurisdiction you operate in, not the loosest. The SEC may be stepping back. California, the EU, your customers, and your lenders are not.

Frameworks, Standards, and Laws Are Not the Same Thing

The ESG acronym soup confuses even experienced compliance teams. Here’s the hierarchy that actually matters.

Laws tell you what you must disclose. CSRD, SB253, CSDDD: these are legal instruments with penalties. You don’t choose them. They choose you, based on your size, jurisdiction, and activities.

Standards tell you how to measure and report. ESRS (mandated under CSRD), ISSB/IFRS S1 and S2 (global, investor-focused), and SASB (industry-specific) define the data fields, boundaries, and metrics. Standards translate legal requirements into operational instructions.

Frameworks tell you what to think about. GRI provides a stakeholder-impact lens. The former TCFD (now folded into ISSB) provided a climate-risk structure. Frameworks shape the narrative and scope of your reporting.

Category Examples Function Binding?
Laws CSRD, SB253, SB261, CSDDD Define who reports and the consequences of not reporting Yes, if you meet thresholds
Standards ESRS, ISSB (S1/S2), SASB Define what to measure and how When referenced by law, or voluntary
Frameworks GRI, TCFD (legacy) Structure thinking and stakeholder scope Voluntary, or incorporated into standards

The GRI and IFRS Foundation collaboration is working to optimize interoperability between their standards. GRI serves a broader stakeholder and impact audience; ISSB focuses on investors. A multinational company covered by CSRD needs both perspectives, because ESRS demands double materiality: report how sustainability issues affect the business and how the business affects people and the environment.

The efficient approach: build one governed data inventory, then map disclosures to each standard and jurisdiction. Collect data once. Publish to many audiences.

The Evidence Problem Most Companies Ignore

Here’s the uncomfortable truth about ESG compliance: most failures are not framework failures. They’re evidence failures.

A company picks ESRS. Assigns a sustainability team. Publishes a report. And then an auditor, regulator, or investigative journalist asks: where did this number come from? Who approved the boundary? What methodology produced the Scope 3 estimate? When was it last reviewed?

Silence.

A working ESG compliance architecture has four layers:

  1. Legal layer. Identify every entity, jurisdiction, threshold, and relationship that triggers a reporting obligation.
  2. Standards layer. Select the standards that translate each obligation into specific data fields, calculation methods, and boundaries.
  3. Control layer. Assign owners to every metric. Build approval workflows. Reconcile inputs. Preserve evidence. Track changes. This is where most programs fall apart.
  4. Assurance layer. Test whether reported numbers and public claims can survive independent review.

The control layer deserves emphasis because this is where ESG data must be treated like financial data. Every number needs an owner, a boundary, a method, an evidence file, a reviewer, and a version history. The IAASB published ISSA 5000 in November 2024, a sustainability assurance standard designed for any topic and framework. As external assurance becomes the norm, last-minute spreadsheet assembly won’t survive the review.

KPMG’s 2024 survey of 5,800 companies found that 95% of the world’s 250 largest published carbon-reduction targets and 82% included sustainability information in annual reports. Targets are no longer scarce. Evidence that holds up under scrutiny is.

Scope 3: where evidence gets hardest

The GHG Protocol Scope 3 Standard covers 15 categories of upstream and downstream value-chain emissions. For most companies, Scope 3 represents the majority of their carbon footprint and the weakest link in their evidence chain.

Four calculation methods exist, and they’re not interchangeable:

Method Input Strength Risk
Spend-based Money spent × category emissions factor Broad coverage when physical data is unavailable Sensitive to price swings and category mapping errors
Activity-based Physical quantities (energy, freight, materials) Tied to actual operations Requires detailed, continuous data from operations
Supplier-specific Primary emissions data from individual suppliers Most accurate for known relationships Requires supplier capability, time, and coordination
Hybrid Best available combination of the above Practical path from rough estimates to real data Method changes create false trend signals if undisclosed

The shift from spend-based estimates to activity-based or supplier-specific data is where physical measurement infrastructure becomes critical. If you’re tracking container movements, fuel consumption, asset utilization, or environmental conditions across your supply chain, that operational data is also Scope 3 data. Companies doing this well don’t treat sustainability reporting and operations data as separate streams. They feed from the same source.

When ESG Claims Fail: Lessons from Goldman and DWS

The two highest-profile ESG enforcement actions follow the same pattern: marketing language outran evidence.

Goldman Sachs Asset Management (2022). The SEC found that one ESG-labeled product had no written research policies from April 2017 through June 2018. When policies were eventually created, they weren’t followed consistently. Questionnaires were sometimes completed after investment decisions had already been made. Personnel sometimes relied on outdated research. Meanwhile, GSAM shared descriptions of its ESG process with investors as though it were operating. Penalty: $4 million.

DWS (2025). German prosecutors fined DWS EUR 25 million after concluding that public statements about the company’s ESG leadership did not correspond to internal reality. This followed a separate 2023 US settlement of $25 million for ESG misstatements and other violations. DWS said it subsequently improved internal documentation and controls.

Three lessons carry beyond financial services:

  • A policy is not a control until decisions and communications actually follow it. Goldman had the policy on paper. The investments didn’t follow the paper.
  • Broad claims create a large evidence population. “ESG is in our DNA” means every product screen, exclusion rule, portfolio holding, training record, and public statement must agree. DWS couldn’t show they did.
  • Compliance review should test the strongest reasonable interpretation of a public statement, not the most forgiving one. What would a skeptical regulator read into this sentence?

These are not outliers. A 2026 Conference Board survey found that nearly half of respondents had already experienced ESG backlash, and 61% expected it to persist or intensify over the next two years. The right response to backlash is not dropping the ESG label while keeping vague claims. It’s making every claim narrower as evidence becomes less certain.

From Spreadsheets to Evidence Chains

When I talk to operations leaders, the ESG compliance conversation usually begins the same way: “We have the data somewhere. We just can’t connect it to the report.”

That gap explains why ESG reporting software is forecast to grow by $2.08 billion between 2026 and 2030. But software is infrastructure, not a substitute for judgment. A platform can provide data lineage, calculation workflows, audit trails, and multi-framework publishing. It cannot decide the correct reporting boundary, validate an unsupported Scope 3 estimate, or make a misleading claim compliant by formatting it into a dashboard.

The technology stack that matters for ESG compliance has three functional layers:

Physical data capture. IoT sensors, asset trackers, energy meters, and environmental monitors generate the raw operational data that feeds carbon calculations, resource efficiency metrics, and environmental impact assessments. A temperature sensor on a refrigerated container. A GPS tracker on a reusable logistics asset. A water-quality monitor at a port facility. This is where ESG numbers originate.

Data management and calculation. Platforms that ingest operational data, apply emissions factors, enforce boundaries, preserve methodology records, and maintain audit trails. This is where spend-based estimates gradually get replaced by activity-based measurements as physical data becomes available.

Reporting and assurance. Tools that map governed data to specific standards (ESRS, ISSB, GRI), generate disclosures, support reviewer workflows, and preserve version history for auditors.

AI is accelerating the middle layer. Automated emissions-factor mapping, anomaly detection, document classification, and report drafting are already in production. The prudent model is human-supervised automation: AI handles the repetitive mapping and flagging, accountable people approve boundaries, estimates, claims, and exceptions.

Walmart’s Project Gigaton illustrates the principle at scale. More than 5,900 suppliers signed up to report on projects covering energy efficiency, packaging redesign, and emissions reduction. The mechanism is operational data flowing upward from supply-chain activity into a structured disclosure framework. Same principle applies to any company managing physical assets across multiple sites and geographies.

Building ESG Compliance That Holds

A dual-track model works for most organizations.

Track 1: Mandatory compliance. Maintain a jurisdiction matrix. Identify thresholds. Map each legal obligation to a data owner, calculation method, evidence standard, and review cycle. Monitor legal changes (the EU is simplifying, the SEC is retreating, California is advancing). This track is defensive. It keeps you out of enforcement actions.

Track 2: Strategic credibility. Maintain one governed ESG data layer. Distinguish investor information (ISSB) from impact information (GRI) and jurisdiction-specific requirements (ESRS). Use GHG Protocol methods for value-chain accounting. Subject every public claim to both legal and operational review. This track is offensive. It builds trust with the investors, customers, and partners who are getting more selective, not less.

Five practical steps to get started:

  1. Map your obligations entity by entity. Not “we think CSRD applies” but “here is the threshold analysis for each legal entity in each jurisdiction.”
  2. Audit your data sources. Where does each ESG metric originate? A utility bill, a supplier survey, an IoT sensor, a manual estimate? Document the source, frequency, and quality of every input.
  3. Assign metric owners. Every number in your sustainability report needs a named person responsible for its accuracy, methodology, and update cycle.
  4. Build for assurance from day one. If you can’t show an auditor the trail from source data to published number, you’re building on sand.
  5. Invest in the physical data layer. The move from spend-based estimates to activity-based measurements depends on sensors, trackers, and monitors generating real operational data. This is the foundation that separates companies surviving audits from companies hoping no one checks.

Keep ESG ratings in perspective. MIT Sloan’s Aggregate Confusion Project found an average correlation of just 0.54 among prominent ESG ratings agencies. Ratings are signals. Use them as one input to materiality and risk analysis, not as proof of compliance.

If your ESG data chain starts at the physical layer (asset utilization, environmental conditions, supply-chain operations) that’s exactly where we work at Datanet. Our environmental tracking devices and asset tracking solutions generate the operational data that feeds ESG reporting systems. Not the whole compliance stack, but the foundation layer everything else depends on. If that’s a gap in your evidence architecture, reach out: info@datanetiot.com.

Wide view of a sustainable industrial plant with solar panels and green spaces showing esg compliance in action.

Frequently Asked Questions

Is ESG compliance mandatory?

It depends on your jurisdiction, size, and activities. There is no single global ESG law. Mandatory obligations come from specific regimes like CSRD (EU), SB253 (California), anti-greenwashing rules (UK FCA), and due diligence directives. Voluntary targets and customer questionnaires can also become contractually binding once published. Start by mapping which laws apply to each entity you operate.

What happened to the SEC climate disclosure rules?

The SEC stayed the rules in April 2024 and proposed rescinding them entirely in May 2026, concluding they exceeded statutory authority. This does not eliminate US climate reporting obligations. California’s SB253 and SB261 still apply to qualifying companies, and customers, lenders, and exchanges may impose their own requirements independently.

What is the difference between ISSB, ESRS, and GRI?

ISSB (IFRS S1/S2) focuses on investor-relevant sustainability information. GRI addresses broader stakeholder impacts. ESRS is the EU-specific standard mandated by CSRD, requiring double materiality: how sustainability issues affect the business, and how the business affects people and the environment. Most multinationals operating across jurisdictions need all three, built from a shared data layer.

How should a company start calculating Scope 3 emissions?

Use the GHG Protocol Scope 3 Standard, which covers 15 upstream and downstream categories. Start with the most decision-relevant categories for your business. Document boundaries, choose between spend-based, activity-based, supplier-specific, or hybrid methods, and disclose estimation uncertainty. The long-term objective is replacing financial estimates with physical measurement data.

Are ESG ratings proof of compliance?

No. Ratings from agencies like MSCI and Sustainalytics measure risk exposure or management quality using proprietary methodologies. MIT Sloan found only 0.54 average correlation among major raters. Ratings are analytical products, not legal certifications. They’re useful as benchmarks and investor signals, but they cannot substitute for meeting specific regulatory requirements.

Does ESG compliance require specific software?

No regulation names a specific vendor. Software becomes practically necessary when the number of entities, data sources, frameworks, suppliers, and evidence files exceeds what manual processes can reliably control. Choose platforms for audit trails, calculation transparency, approval workflows, and version history, not for polished dashboards alone.


2 Responses

Leave a Reply

Your email address will not be published. Required fields are marked *

Other related articles

Your Cart