We were recently invited to demonstrate our ESG reporting platform to a UK-headquartered multinational manufacturer. The questionnaire asked about features, architecture and deployment. It asked nothing about governance, data, obligations or assurance.
The group runs sustainability reporting from the UK, with data collected from manufacturing, assembly and distribution sites across Europe, Asia and the Middle East. The pre-qualification questionnaire was thorough on functionality. What it left out raised a red flag for our team: nothing on how the programme is governed today, how data is collected at each site, which local and international frameworks apply to which entities, or who assures the numbers.
It is one of the most common patterns we see, and it is worth unpacking, because choosing software before answering those questions is not a technology decision. It is a risk decision, and usually an unexamined one.
Two of the largest recent studies, Deloitte's 2024 Sustainability Action Report and KPMG's 2025 ESG Assurance Maturity Index (1,320 senior executives and board members), point in the same direction.
| Finding | Figure | Source | What it means for software buyers |
|---|---|---|---|
| Data quality is the top ESG data challenge | 57% (88% in their top three) | Deloitte 2024 | A platform cannot fix data that nobody owns or controls |
| Documentation and sign-off is a top challenge | 81% | Deloitte 2024 | Assurers test evidence and approvals, not dashboards |
| Preparing for reasonable assurance, versus having finished evaluating what it takes | 78% preparing, 13% finished | Deloitte 2024 | Most buyers will choose software before they know what assurance will demand |
| Organisations at an early or mid stage of ESG maturity | 76% | KPMG 2025 | Few are ready to configure a platform well today |
| ESG targets fully operationalised, with monitoring and incentives | 5% | KPMG 2025 | The gap is governance and operating model, not tooling |
| Leaders whose boards actively identify ESG risks and opportunities | 95% | KPMG 2025 | Leaders put oversight in place at the top |
| Leaders using ESG platforms and dashboards | 50% and 53% (up 30 and 27 points in three years) | KPMG 2025 | Technology scales strong governance; it does not replace it |
Read together, the findings tell a consistent story. The bottleneck is governance, process and evidence, and the organisations getting value from ESG technology are the ones pairing it with board-level oversight. Software on its own does not close the gap.
A dashboard on top of an undocumented spreadsheet process doesn't pass assurance. It reaches the same failure faster, and at greater cost.
A platform can only be configured once someone has decided which topics are material, where the reporting boundary sits, how operational and financial control apply across manufacturing and distribution entities, who owns each metric at each site, and which emission factors and estimation methods are used. If those decisions have not been made, the vendor's default settings end up making them, and the organisation inherits choices it cannot explain.
A single group report does not show that each legal entity meets its own obligations. For a footprint spanning the UK, the EU, Malaysia and the UAE, the obligations look like this:
| Jurisdiction | Requirement | Key threshold or date | Why it matters for a group reporter |
|---|---|---|---|
| UK | SECR today; UK Sustainability Reporting Standards (IFRS S1/S2 based) | Mandatory UK SRS climate reporting proposed for listed companies from January 2027 | The group report must satisfy UK rules and whatever its listing status requires |
| EU | CSRD and ESRS, narrowed by the Omnibus | 1,000+ employees and €450m+ turnover; next wave reports on 2027 data | EU subsidiaries or the group may be in scope, and CBAM or EUDR can apply depending on products and imports |
| Malaysia | NSRF (IFRS S1/S2), with Bursa Malaysia listing requirements | Large non-listed companies (RM2bn+ revenue) from FY2027; Scope 1 and 2 assurance under ISSA 5000 from 2028 for the largest listed issuers, after a one-year deferral in September 2026 | Local entities carry their own reporting and assurance duties, not just group data feeds |
| UAE | Federal Decree-Law No. 11 of 2024 on climate change | Greenhouse gas measurement and reporting, with a compliance deadline of 30 May 2026 | Distribution entities have direct obligations, whatever the group reports |
Status as at October 2026.
None of this can be judged from a feature checklist, and a questionnaire that does not ask about it cannot tell you whether any platform will meet it.
Assurance providers look at controls, data lineage, evidence and review. A well-designed dashboard sitting on top of an undocumented spreadsheet process does not pass assurance.
For a premium manufacturer, figures that cannot be traced to source become a liability the moment they appear in an annual report, a customer questionnaire or a tender response. The rules and standards below explain why evidence, rather than software, is now what gets tested.
| Rule or standard | What it requires | In force from | What it means in practice |
|---|---|---|---|
| COSO internal control over sustainability reporting | Applies the 17 internal control principles used for financial reporting to sustainability data | March 2023 | Sustainability data should be managed with the same rigour as financial data |
| IAASB ISSA 5000 | A global standard for limited and reasonable sustainability assurance, under any reporting framework | Periods from 15 December 2026 | Assurers will test controls, lineage and evidence, not the tool |
| FCA anti-greenwashing rule | Sustainability claims by authorised firms must be fair, clear, not misleading and capable of substantiation | 31 May 2024 | Sets the UK benchmark for evidencing any sustainability claim |
| CMA powers under the DMCC Act | Direct fines of up to 10% of global turnover for misleading consumer claims, including environmental ones, without going to court | 6 April 2025 | An untraceable figure in marketing or tenders becomes a legal exposure |
When requirements surface only after go-live, platforms get reconfigured or replaced, consultants are brought back in, and the reporting cycle slips. The cost of skipping discovery does not disappear; it arrives later.
COSO's guidance, Achieving Effective Internal Control over Sustainability Reporting, gives the right mental model: manage sustainability data with the same rigour as financial data. That leads to a clear sequence.
For a group like the one that approached us, we would expect the highest risks to sit in Scope 3 and supplier data, in consolidation between manufacturing and distribution entities, where emissions are easily double counted or lost at handover, in estimates standing in for missing site data, and in manual spreadsheet transfers into the group team.
The demo will show you dashboards. These questions show you whether the numbers will survive assurance. Ask them of every vendor, and ask whether your own process can answer them yet.
We never decline the demo. We change the conversation around it.
Software matters, and the right platform makes good governance scalable and repeatable. But the organisations getting the most from ESG technology are the ones that decided what good looked like before they bought it.
Sources: Deloitte, 2024 Sustainability Action Report; KPMG, 2025 ESG Assurance Maturity Index; COSO, Achieving Effective Internal Control over Sustainability Reporting (2023); IAASB, ISSA 5000; FCA FG24/3; CMA powers under the DMCC Act; FCA UK SRS proposals; EU Council Omnibus sign-off (February 2026); Securities Commission Malaysia (NSRF and the September 2026 assurance deferral); UAE Federal Decree-Law No. 11 of 2024.