Skip to main content

Organizing (IT) control and strengthening assurance in ESG reporting

Europe’s sustainability rulebook continues to evolve with the European Sustainability Reporting Standards (ESRS) “Omnibus” adjustments. Timelines are shifting, scope changes are on the table, and targeted relief measures have been introduced. One thing hasn’t changed: companies within the scope of the Corporate Sustainability Reporting Directive (CSRD) still need decision-grade Environmental, Social and Governance (ESG) data that management can steer on and auditors can attest to.

Why does this matter now? The Omnibus creates breathing room to strengthen ESG reporting processes and implement (IT) controls that support high‑quality data. KPMG research shows that 88% of organizations are continuing their ESG programs, using the additional time to strengthen data foundations, automate reporting, and make assurance a natural outcome of good design.

This article explains how to organize IT governance and controls to achieve decision-grade and assurance-ready ESG reporting by design. The operating principle is clear: treat ESG like finance, with reliable data, robust IT controls, and an architecture that can scale with ambition.

Introduction

Even as policy evolves, the direction of travel is clear: boards, investors, supervising bodies, customers, and other stakeholders expect reliable, auditable ESG information that supports day-to-day decision‑making and enables organizations to measure performance against their long‑term ambitions. Early CSRD reporters confirm that momentum. In the Netherlands, KPMG analyzed 26 first-wave sustainability statements to see how companies are applying the ESRS and how reporting practices are maturing. The findings highlight the need for stronger methods and integration with financials, and they expose a growing dependency on technology and data.

As with financial reporting, data reliability is non-negotiable. That requires disciplined IT controls to ensure complete, accurate, and timely internal and external data. Without this control framework, ESG disclosures remain exposed to errors and inconsistencies. With it, processes become manageable and stakeholders – internal and external – gain confidence. Our review therefore concludes that boards must use the time provided by the Omnibus to address three critical shifts related to IT governance and data. In the sections that follow, we unpack these shifts in more detail, showing what they mean in practice, why they matter, and how organizations can move from intention to execution.

ESG & IT assurance – three shifts to act on now

1. From compliance-first to ambition-led

The initial CSRD wave prioritized “getting compliant” through transparent and verifiable reporting. Improvement in data management and control automation often followed later. With more room on the timeline provided by the Omnibus, organizations should start from ambition and focus on (IT) governance from the outset. This includes clarifying why each topic matters to value creation, setting targets that truly steer behavior, and implementing monitoring and (IT) governance mechanisms to track progress continuously.

In this way, disclosers are generated from the same trusted datasets management already uses to run the day-to-day business, and controls are embedded in the operating model. As a result, assurance is no longer simply a year-end outcome of the CSRD audit,1 but a natural consequence of the way the organization has set up structured (IT) governance around ESG reporting.

2. Rethinking the tech journey

Many ESG programs were expected to evolve from minimal compliance to a transitional state and only later to a highly automated future state. With the additional time provided by the Omnibus, organizations are advised to design the highly automated architecture now and aim for the future state from the beginning. This also relates to the first shift: start from ambition. Specifically, the tech journey plays an important role. Figure 1 illustrates this journey: from minimal compliance (manual reporting) through a transitional state (partially automated) to a future state (fully automated ESG workflow).

C-2026-5-Jong-1-klein

Figure 1. IT Architecture scenarios for ESG reporting. [Click on the image for a larger image]

The four clusters outlined in our previous Compact article on mastering data & technology for CSRD ([Hure24]) form the building blocks for this progression towards future-state IT architecture:

  1. End-to-end ESG platform. In the future-state architecture, workflows, CSRD reporting processes, and strategic analysis should reinforce one another. This requires a clearly defined workflow from data intake to reports and dashboards, driven by reporting requirements. Internal and external data sources must be assessed and integrated into a single, consistent reporting process, supported by a governance structure that steers workflows and reporting and helps strengthen assurance. Together, these processes are embedded in the technological backbone, forming an end-to-end ESG platform.
  2. Data governance complements the end-to-end ESG platform by ensuring data accuracy, security, and traceability beyond the technological enablement of data capture. Organizations must define robust processes for data collection, storage, cataloging, and protection to support reliable ESG reporting. In the future state, governance will become increasingly automated and embedded within IT controls, enabling consistent enforcement across workflows. This evolution is critical to maintaining data integrity and auditability, particularly as ESG reporting expands in scope and complexity, making manual governance checks neither sustainable nor scalable.
  3. Metric calculation is a core component of the end-to-end ESG platform, carried out through ESG tooling integrated with core systems. Mature calculation tooling ensures transparency, repeatability, and compliance, reducing reporting risk and building confidence in disclosed figures as ESG requirements continue to evolve.
  4. Integration with core systems evolves the end-to-end ESG platform from standalone data collection to embedded business steering. In the current state, ESG data is often captured in separate tools, disconnected from ERP, HR, procurement, and supply-chain systems. In the future state, ESG is fully connected to core systems. This integration reduces manual effort, strengthens controls, and embeds ESG considerations into day-to-day business decisions, delivering significant efficiency and cost benefits.

Whereas the previous four points focus on the internal technology journey, external dependencies are also an integral part of ESG technology design. Designing the future state architecture goes beyond internal systems and requires actively managing external data providers and SaaS tools as part of the broader ecosystem. An increasing share of ESG metrics relies on data and logic that resides outside the corporate boundary, such as supplier footprints, market emission factors, sector benchmarks, financed emissions models, and reporting platforms. Assurance therefore hinges on questions such as whether external data is accurate, complete, and reproducible after updates, and whether movements between reporting periods can be clearly explained. These external inputs must be treated as extensions of the organization’s own control environment to safeguard decision quality and auditability.

This starts with defining what good data means upfront through clear data dictionaries and intake checks, and aligning provider assurances, such as SOC reports and bridge letters, with the reporting timetable. Critical outputs should be periodically back-tested to validate stability and accuracy. At the same time, operational robustness is required, including reliable APIs, accessible data lineage, role-based access, and complete audit trails, supported by service level agreements, security certifications, and a realistic exit strategy to manage concentration risk. Together, these expectations reflect the control map described earlier, applying data and technology controls end-to-end to ensure ESG metrics remain repeatable, explainable, and auditable, even when key inputs originate from external providers.

As with internal capabilities, maturity evolves over time: in the minimal compliance state, external data is often accepted without validation; in the transition state, intake checks and provider assurance are aligned to reporting cycles; and in the future state, integration is automated through APIs, version control, and direct embedding in assurance processes. As data flows and external dependencies continue to grow in complexity, the guidance in the next section becomes essential for managing that complexity effectively.

3. Sustainable (IT) control

As the ESG technology journey described in the previous chapter evolves into an increasingly interconnected landscape of systems and dependencies, sustainable IT control becomes essential to ensure that this landscape remains reliable and auditable. As organizations move from minimal compliance, through the transition state, toward a fully automated ESG workflow, data flows expand, system interactions multiply, and reliance on both internal and external technologies increases. In this context, IT controls are not an afterthought but a structural requirement to ensure that reported ESG outcomes can be trusted.

Sustainable IT control focuses specifically on the technical backbone that captures, processes, calculates, and reports ESG information. These controls are directly linked to the future state architecture described earlier and are designed to safeguard both the integrity of ESG data and the resilience of the technology that processes it. Two types of IT controls are central to this foundation.

Data controls ensure completeness, accuracy, timeliness, lineage, and end-to-end reconciliation from source data to reported KPIs. They validate calculations analytically, make methodologies and assumptions transparent, and ensure that exceptions are logged, investigated, and resolved. These controls address fundamental questions such as whether data quality is sufficient and how organizations can demonstrate that ESG calculations are correct and consistently applied.

Technology controls safeguard the systems and applications that process ESG data. They include applying general IT controls and application controls across ESG tools, data platforms, and cloud environments. This covers controlled changes to calculation logic, enforced role-based access, security and resilience measures, and assurance over hosted and outsourced services, such as through SOC reports. Together, these controls ensure that the ESG technology landscape remains secure, stable, and auditable as reporting requirements and dependencies continue to grow.

C-2026-5-Jong-2-klein

Figure 2. Control points in ESG reporting. [Click on the image for a larger image]

Additionally, it is important to design controls end-to-end. The overview in Figure 2 represents the full ESG reporting value stream, starting with business processes and applications that generate ESG-relevant data. These processes and applications form the foundation of ESG reporting, as disclosures ultimately reflect operational reality (point 3 in Figure 2).

ESG-specific applications sit on top of these standard business processes and applications to automate reporting requirements and connect with the broader IT infrastructure. This layer manages data input and output, linking ESG platforms with enterprise systems. In the previous chapter, this is reflected in the integration with core systems building block.

The next element in the value stream, shown in point 5 of Figure 2, relates to governance and risk management within the organization. At this level, organizations define their risk appetite, establish governance structures, and identify and assess risks across their operations and information landscape. ESG reporting does not reside outside this framework; it is embedded within it, as one of the domains affected by broader organizational risks related to data, processes, systems, and decision‑making. Internal (IT) controls are a direct outcome of this risk management process: they translate governance decisions and risk assessments into concrete measures. Comparable to financial reporting, these controls support data quality, integrity, compliance, and auditability, ensuring that ESG information is produced in a controlled and reliable manner as part of the organization’s overall control environment.

The next element in the value stream, shown in point 5 of Figure 2, relates to governance and risk management. As organizations increasingly rely on ESG information for decision‑making and external reporting, they must first identify and assess risks across the ESG reporting chain – ranging from data availability and quality issues to system dependencies and third‑party reliance. Internal (IT) controls are a direct outcome of this risk management process: they operationalize governance decisions by addressing identified risks and translating them into concrete measures. Comparable to financial reporting, these controls support data quality, integrity, compliance, and auditability across the end‑to‑end ESG reporting process.

Finally, the illustration extends beyond the organization to the broader ESG value stream, as outlined in points 6 and 7, where one organization’s output becomes another’s input. This interconnectedness means that controls cannot stop at internal systems but must extend to external data providers and downstream partners.

Summary and key takeaways

ESG reporting is no longer primarily a matter of policy design or disclosure intent. As regulatory expectations change and reporting scopes expand, the real challenge lies in execution. Gaps between ambition, data, technology, and control create tangible risk: without a well‑designed IT control environment, ESG reporting remains fragmented, difficult to explain, and hard to audit. Decision‑grade data, clear ownership, and auditable processes are no longer optional; they are the minimum standard.

This is why organizations must act decisively on the shifts outlined in this article. ESG reporting needs to be organized and controlled with the same rigor as financial reporting, supported by an end‑to‑end ESG platform and a control environment that spans internal systems and external dependencies. Leading organizations start by defining their target-state architecture, then embed sustainable IT controls across data, applications, and integrations, including third‑party data providers and SaaS solutions. When controls are designed into the system rather than added at the end, assurance becomes a natural outcome. The result is ESG reporting that management can rely on, auditors can stand behind, and stakeholders can trust.

What to do next?

Use the extra time to strengthen assurance by organizing and tightening your IT controls for ESG reporting. Align ESG strategy, governance, and delivery so ambition, roles, and decision rights reinforce one another. Make thoughtful decisions. Design an ESG architecture – data, controls, and workflows – that prioritizes internal performance steering and scales with ambition. Manage your data and providers. Map your value chain, scrutinize assurance reports, and be explicit about responsibilities for third-party inputs and tools. Remember the clock. For many tier-2 reporters, there are roughly 10 months to go.

Notes

  1. For a discussion on limited versus reasonable assurance over ESG, see [Morr24].

References

[Hure24] Hurenkamp, I., Jong, N. de, Toledo, P. van, & Veld, M. op het (2024). CSRD: mastering data & technology: How to collect, manage and process data for a solid CSRD reporting. Compact 2024/2. Retrieved from: https://www.compact.nl/articles/csrd-mastering-data-technology/

[Morr24] Morris, N. (2024, 28 February). Limited vs reasonable assurance over ESG. KPMG. Retrieved from: https://kpmg.com/xx/en/our-insights/esg/limited-vs-reasonable-assurance-over-esg.html