Insights · ESG Reporting

Why Buying ESG Software First Is a Risk Decision, Not a Technology One

Published 11 October 2026 · First published by ESG Disclose on LinkedIn, 25 September 2026

We were recently invited to demonstrate our ESG reporting platform to a UK-headquartered multinational manufacturer. The questionnaire asked about features, architecture and deployment. It asked nothing about governance, data, obligations or assurance.

The group runs sustainability reporting from the UK, with data collected from manufacturing, assembly and distribution sites across Europe, Asia and the Middle East. The pre-qualification questionnaire was thorough on functionality. What it left out raised a red flag for our team: nothing on how the programme is governed today, how data is collected at each site, which local and international frameworks apply to which entities, or who assures the numbers.

It is one of the most common patterns we see, and it is worth unpacking, because choosing software before answering those questions is not a technology decision. It is a risk decision, and usually an unexamined one.

The Evidence Says the Problem Isn't the Tool

Two of the largest recent studies, Deloitte's 2024 Sustainability Action Report and KPMG's 2025 ESG Assurance Maturity Index (1,320 senior executives and board members), point in the same direction.

FindingFigureSourceWhat it means for software buyers
Data quality is the top ESG data challenge57% (88% in their top three)Deloitte 2024A platform cannot fix data that nobody owns or controls
Documentation and sign-off is a top challenge81%Deloitte 2024Assurers test evidence and approvals, not dashboards
Preparing for reasonable assurance, versus having finished evaluating what it takes78% preparing, 13% finishedDeloitte 2024Most buyers will choose software before they know what assurance will demand
Organisations at an early or mid stage of ESG maturity76%KPMG 2025Few are ready to configure a platform well today
ESG targets fully operationalised, with monitoring and incentives5%KPMG 2025The gap is governance and operating model, not tooling
Leaders whose boards actively identify ESG risks and opportunities95%KPMG 2025Leaders put oversight in place at the top
Leaders using ESG platforms and dashboards50% and 53% (up 30 and 27 points in three years)KPMG 2025Technology scales strong governance; it does not replace it

Read together, the findings tell a consistent story. The bottleneck is governance, process and evidence, and the organisations getting value from ESG technology are the ones pairing it with board-level oversight. Software on its own does not close the gap.

A dashboard on top of an undocumented spreadsheet process doesn't pass assurance. It reaches the same failure faster, and at greater cost.

Five Reasons a Software-First Approach Goes Wrong

1. It automates a process nobody has defined

A platform can only be configured once someone has decided which topics are material, where the reporting boundary sits, how operational and financial control apply across manufacturing and distribution entities, who owns each metric at each site, and which emission factors and estimation methods are used. If those decisions have not been made, the vendor's default settings end up making them, and the organisation inherits choices it cannot explain.

2. Group reporting is not the same as local compliance

A single group report does not show that each legal entity meets its own obligations. For a footprint spanning the UK, the EU, Malaysia and the UAE, the obligations look like this:

JurisdictionRequirementKey threshold or dateWhy it matters for a group reporter
UKSECR today; UK Sustainability Reporting Standards (IFRS S1/S2 based)Mandatory UK SRS climate reporting proposed for listed companies from January 2027The group report must satisfy UK rules and whatever its listing status requires
EUCSRD and ESRS, narrowed by the Omnibus1,000+ employees and €450m+ turnover; next wave reports on 2027 dataEU subsidiaries or the group may be in scope, and CBAM or EUDR can apply depending on products and imports
MalaysiaNSRF (IFRS S1/S2), with Bursa Malaysia listing requirementsLarge non-listed companies (RM2bn+ revenue) from FY2027; Scope 1 and 2 assurance under ISSA 5000 from 2028 for the largest listed issuers, after a one-year deferral in September 2026Local entities carry their own reporting and assurance duties, not just group data feeds
UAEFederal Decree-Law No. 11 of 2024 on climate changeGreenhouse gas measurement and reporting, with a compliance deadline of 30 May 2026Distribution entities have direct obligations, whatever the group reports

Status as at October 2026.

None of this can be judged from a feature checklist, and a questionnaire that does not ask about it cannot tell you whether any platform will meet it.

3. Assurance tests the process, not the software

Assurance providers look at controls, data lineage, evidence and review. A well-designed dashboard sitting on top of an undocumented spreadsheet process does not pass assurance.

4. Weak data creates legal and reputational exposure

For a premium manufacturer, figures that cannot be traced to source become a liability the moment they appear in an annual report, a customer questionnaire or a tender response. The rules and standards below explain why evidence, rather than software, is now what gets tested.

Rule or standardWhat it requiresIn force fromWhat it means in practice
COSO internal control over sustainability reportingApplies the 17 internal control principles used for financial reporting to sustainability dataMarch 2023Sustainability data should be managed with the same rigour as financial data
IAASB ISSA 5000A global standard for limited and reasonable sustainability assurance, under any reporting frameworkPeriods from 15 December 2026Assurers will test controls, lineage and evidence, not the tool
FCA anti-greenwashing ruleSustainability claims by authorised firms must be fair, clear, not misleading and capable of substantiation31 May 2024Sets the UK benchmark for evidencing any sustainability claim
CMA powers under the DMCC ActDirect fines of up to 10% of global turnover for misleading consumer claims, including environmental ones, without going to court6 April 2025An untraceable figure in marketing or tenders becomes a legal exposure

5. It usually means paying twice

When requirements surface only after go-live, platforms get reconfigured or replaced, consultants are brought back in, and the reporting cycle slips. The cost of skipping discovery does not disappear; it arrives later.

Treat Sustainability Reporting Like Financial Reporting

COSO's guidance, Achieving Effective Internal Control over Sustainability Reporting, gives the right mental model: manage sustainability data with the same rigour as financial data. That leads to a clear sequence.

  1. Governance. Establish board oversight, an accountable executive (increasingly the CFO), and named data owners at every site.
  2. Obligations register. Record which entities must report what, under which framework, by when, and to what level of assurance. It is the first document an assurer will ask for, and the one most groups do not have.
  3. Materiality. Use double materiality for ESRS and financial materiality for ISSB-based standards to decide which data points actually matter.
  4. Current-state data review. For each material metric, document the source system, owner, method, estimates and evidence, and map where the risk sits.
  5. Risk and control matrix. Design controls for completeness, accuracy, cut-off, consolidation and double counting, and for how emission factors are selected.
  6. Assurance readiness. Understand who assures today, test against limited or reasonable assurance, and run a dry run before it counts.
  7. Requirements, then software. Only now define what a platform must do to support those controls, and use it to write the procurement questionnaire.

For a group like the one that approached us, we would expect the highest risks to sit in Scope 3 and supplier data, in consolidation between manufacturing and distribution entities, where emissions are easily double counted or lost at handover, in estimates standing in for missing site data, and in manual spreadsheet transfers into the group team.

Seven Questions to Ask Before You Shortlist

The demo will show you dashboards. These questions show you whether the numbers will survive assurance. Ask them of every vendor, and ask whether your own process can answer them yet.

  1. How does the platform record who owns each metric at each site?
  2. Can an assurer trace a reported figure back to its source evidence?
  3. How are emission factors selected, versioned and approved?
  4. How are entities consolidated without double counting?
  5. Which frameworks does it map for each entity, not just for the group?
  6. What review and sign-off workflow is built in?
  7. What happens to our data and audit trail if we leave?

What We Recommend When a Software Demo Is Requested

We never decline the demo. We change the conversation around it.

  • Ask discovery questions first: how the programme is governed, which entities and frameworks are in scope, how site data is collected, who reviews and assures it, and what went wrong last cycle. How easily a team answers tells you a great deal about its maturity.
  • Show governance, not just features: demonstrate how the platform supports ownership, data lineage, controls and assurance evidence, because that is what the business will be judged on.
  • Start with readiness: a short, structured readiness assessment produces the obligations register, materiality view, risk and control matrix and assurance gaps, plus a requirements specification the organisation can use to assess any vendor, including ours.

Software matters, and the right platform makes good governance scalable and repeatable. But the organisations getting the most from ESG technology are the ones that decided what good looked like before they bought it.

Sources: Deloitte, 2024 Sustainability Action Report; KPMG, 2025 ESG Assurance Maturity Index; COSO, Achieving Effective Internal Control over Sustainability Reporting (2023); IAASB, ISSA 5000; FCA FG24/3; CMA powers under the DMCC Act; FCA UK SRS proposals; EU Council Omnibus sign-off (February 2026); Securities Commission Malaysia (NSRF and the September 2026 assurance deferral); UAE Federal Decree-Law No. 11 of 2024.

Author & ESG / AI Governance Advisor

Across genres and disciplines, the same instrument recurs: a record that survives suppression, a silence that finally speaks, a ledger made to answer for itself. Nadeem Shakoor writes and advises from the conviction that these are not separate practices: they are one discipline, applied at different registers.

— N. Shakoor