Building an ESG Framework That Survives Contact With the Data
Sustainability programmes almost never fail at the policy layer. Policies are quick to write and easy to approve. They fail at the data layer, months later, when somebody asks where a number came from and the honest answer involves a spreadsheet nobody owns. Build in the other order.
- Materiality, done so that it holds up
- The data layer, and why it comes before the narrative
- Integrating into governance and risk rather than alongside them
- What a realistic first year looks like
A process, not a matrix
A materiality assessment decides what the programme is about. Done badly it is a workshop that produces a two-by-two chart nobody revisits. Done properly it is a documented process that can be shown to a verifier, a board or an investor.
1. Identify stakeholders, specifically
Not 'employees, customers, communities'. Which employees, which customers, which communities, and why those. A generic list produces generic findings.
2. Build the issue universe from outside in
Sector guidance, peer reporting, the mandated disclosure format, customer questionnaires you have actually received, and the risks already on your risk register. The last of those is the most-skipped and the most useful.
3. Engage, and record it
Interviews, surveys, or structured consultation, with who was asked, when, and what they said. The record is what makes the conclusion defensible a year later.
4. Assess on two axes, and say which two
Impact on the business, and the business's impact on the outside world, are different questions. Many frameworks now ask for both. Be explicit about which you have assessed.
5. Conclude, and revisit on a stated cycle
A material issue set that has not changed in three years is either a very stable business or an assessment nobody has revisited.
Where programmes actually fail
For each metric you intend to report, five things have to be true before the number is worth anything. Establishing them is unglamorous and it is the majority of the work in a first year.
A named owner
A person, in a function, whose job description includes producing this figure. Not the sustainability team, who in most organisations are collecting rather than producing.
A defined source system
Which system, which report, which extract. If the answer is a spreadsheet, the spreadsheet needs an owner, version control and a documented input.
A written methodology
Including the boundary, the conversion factors, the denominator for any intensity figure, and the treatment of estimates. Two people should be able to compute the same answer from it.
A control
Review, approval and segregation on the same footing as a financial number. This is the step that turns reported data into assurable data.
A reconciliation
To something already reported elsewhere. Revenue to the financial statements, headcount to payroll, payables days to the ledger. Where the two disagree, find out why before publishing either.
An audit trail
Retained for long enough that somebody can trace the figure back a year later. Most first-year data cannot survive this test, which is why the second report is usually better than the first.
Integrated, not parallel
The most common structural mistake is to run sustainability as a separate programme with its own governance, its own risk list and its own reporting line. It produces duplication, and it produces a set of risks the board sees separately from the risks it actually manages.
The listing regulations give a natural home. Regulation 21 requires the top one thousand listed entities by market capitalisation to constitute a risk management committee with at least three members, a majority of whom must be members of the board, including at least one independent director, and chaired by a board member; senior executives may also serve. It must meet at least twice in each financial year, with no more than 210 days between consecutive meetings, a limit raised from 180 days by the amendment regulations notified on 17 May 2024. Part D of Schedule II requires the committee to formulate and oversee a risk management policy identifying internal and external risks including, expressly, sustainability risks and particularly environmental, social and governance risks. That is the only place in Indian listed-company law where sustainability risk oversight is an express committee mandate, and it should be where the work lands.
The rest follows: sustainability risks on the same risk register with the same rating scale, sustainability controls in the same controls framework, and sustainability data subject to the same internal audit coverage. Our governance, risk and internal control pages deal with the machinery this plugs into.
What to attempt and what to defer
| Do in year one | Defer to year two |
|---|---|
| A documented materiality assessment | Target setting beyond what you can measure |
| Data ownership and methodology for every metric you will report | Value chain data collection, unless a customer requires it |
| A baseline, honestly stated, including the gaps | External assurance, unless it is mandatory for you |
| Governance integration and board or committee oversight | Ratings agency engagement and index submissions |
| Controls over the data | A public commitment with a date attached to it |
The single most damaging thing a first-year programme can do is publish a target it has no means of measuring progress against. It is far better to publish a baseline with the gaps acknowledged.
Where to go next
Environmental, Social, and Governance
Back to the main page: what we do, how an engagement is structured, and how to reach us.
Business Responsibility and Sustainability Reporting: Who Reports, What, and From When
The reporting obligation, how the top one thousand population is actually determined since the 2024 change, the nine core attributes subject to verification, and the glide path year by year.
Getting the Core Verified: Assurance, Assessment and the Independence Bar
The 2025 change from reasonable assurance to assurance or assessment, who may provide it, the conflict rules that decide which firm can do what, and the standards an engagement is conducted under.
Environmental Compliance: Producer Responsibility, Carbon Credits and Energy
The compliance obligations underneath the reporting: extended producer responsibility across plastic, electronic and battery waste, the carbon credit trading scheme, and the energy efficiency regime it sits alongside.
Reporting Beyond India: ISSB, CSRD, CBAM and What Buyers Are Asking
The international sustainability standards and India's position on them, the European reporting directive after it was cut back, the carbon border mechanism now in its definitive phase, and why the real pressure on Indian exporters comes through contracts rather than regulators.
Send an enquiry
If you have a report and cannot easily say where three of its numbers came from, that is the place to start, and it is a contained piece of work.
Position as at 17 September 2026. Reviewed every six months.
This page is general information, not professional advice. Sustainability regulation is the fastest-moving area on this website and the one where published material ages worst. The securities regulator has softened its assurance requirement, made value chain reporting voluntary and redefined who counts as a value chain partner, all since 2024. The European Union has cut back the scope of its reporting directive and pushed out its dates. The climate disclosure task force was disbanded in 2023. Any advice in this area needs a date on it. Take professional advice before acting on anything on this page. We are happy to be that adviser, but we do not act on a web page, ours or anyone else's, without one.