Navigating regulatory complexity with ESG regulatory intelligence
To navigate this growing complexity, organizations are increasingly turning to structured regulatory intelligence solutions such as EY’s ESG Regulatory Radar. These tools provide a consolidated view of ESG regulations across sectors, geographies and time horizons, helping organizations anticipate upcoming requirements and understand their impact in a more systematic way. By mapping more than 40 key regulations across multiple industrial sectors and grouping them into clear time horizons, the ESG Regulatory Radar supports companies in prioritizing actions, aligning compliance efforts and identifying overlaps or synergies across regulatory frameworks. This enables a shift from reactive compliance to forward-looking decision-making.
Beyond visibility, regulatory intelligence also supports stronger integration between legal requirements and business processes. By linking regulatory obligations to internal policies, controls and data points, organizations can improve traceability, enhance risk management and strengthen audit readiness. In this context, ESG regulatory intelligence becomes not only a compliance enabler, but a key component of a broader, data-driven ESG strategy.
Today’s reality: manual ESG processes in a digital world
Despite rising expectations, many organizations still operate with “old‑school” ESG processes. This was clearly confirmed by the live pulse survey conducted during the event.
42% of participants indicated that they still primarily rely on local files, emails, and manual consolidation in spreadsheets, while another 42% reported having only partial automation and BI dashboards with inconsistent coverage. Only 15% of respondents use more advanced solutions (centralized platforms or digital systems), and none reported having a fully integrated and controlled ESG system in place.
These results strongly align with the challenges raised in the discussions, where participants consistently pointed to:
- Heavy reliance on spreadsheets and local data files
- Manual, decentralized data collection across entities
- Limited system integration and automation
- Inconsistent definitions, ownership and controls
As a result, teams spend disproportionate effort on getting data “right,” leaving little time to analyze trends, benchmark performance, or generate insights. This gap between effort and insight was a recurring concern during discussions.
The second pulse survey further highlighted the nature of these challenges. “Data quality” clearly emerged as the dominant concern, closely linked to issues such as data availability, completeness, accuracy, and inconsistency. Participants also emphasized internal controls, traceability, and the lack of a single source of truth. Operational constraints were equally visible, with “time-consuming processes,” “manual management,” and “resource constraints” frequently mentioned.
Overall, the discussions confirmed that ESG data is sourced across multiple functions, systems, and geographies, leading to inconsistencies and limited traceability. Inputs from third parties often lack structure and auditability, and the absence of standardized templates, access controls, and formal control processes makes reporting resource-intensive and difficult to manage, especially for first-time or expanded disclosures.
ESG digitalization starts with clarity - not tools
A common misconception is that ESG digital transformation is primarily a tool‑selection exercise. In practice, successful ESG digitalization is process‑driven, not tool‑driven.
During the event, EY presented a high‑level view of the ESG technology landscape, highlighting how different tools address specific needs across the ESG data chain:
- Integrated platforms embed ESG into core business systems
- Sustainability & EHS tools support data collection and management
- Carbon solutions focus on emissions calculation and scenario analysis
- Reporting tools ensure compliant, audit-ready disclosures
- Sensoring solutions provide real-time operational data
Rather than promoting specific tools, the discussion focused on the importance of a fit‑for‑purpose approach. The key challenge is not to find a single, all‑encompassing solution, but to understand an organization’s specific needs, maturity level and regulatory exposure to select and combine the most relevant tools into a coherent ESG ecosystem.
The ability to benchmark and align available solutions with these criteria emerged as a critical starting point, one that many organizations still struggle to structure internally. In this context, having access to an objective market overview and informed recommendations, based on a broad view of solutions, can significantly support more confident and efficient decision-making.
Several participants also reflected on internal developments. While custom-built solutions can be appealing for targeted use cases, they often prove resource-intensive and difficult to maintain over time, especially as methodologies, regulatory requirements and reporting standards continue to evolve. In addition, ensuring alignment with existing systems such as ERP, HR and operational data systems is critical. Change management frequently acts as a barrier, meaning solutions that build on already familiar tools and processes tend to be more easily adopted and sustained.
Audit readiness starts with governance, systems and controls
As ESG reporting becomes increasingly data-driven, the reliability of underlying systems and technology is moving into the spotlight. Many organizations focus on defining ESG metrics and collecting data, but audit readiness starts much earlier: with governance, systems, and controls.
From an IT auditor’s perspective, the question is not only whether ESG data is accurate, but also whether the systems that process, transform, and report that data can be trusted. Automation does not eliminate risk; it merely shifts it from manual activities to technology-enabled processes.
The first step is therefore to understand the end-to-end ESG reporting landscape. Organizations should map their ESG data flows, identify data sources and systems, interfaces, and overall dependencies across the reporting chain. This provides visibility over where data originates, how it is processed, and where risks to completeness, accuracy, and timeliness may arise.
Once these flows are understood, appropriate governance and controls can be designed. Discussions with companies embarking on their ESG journey often revolve around similar questions: How can we ensure the completeness and integrity of ESG data? How do we manage access rights to critical reporting systems? How are changes governed and documented? And how can we demonstrate robust traceability in increasingly automated environments?
This is where IT General Controls (ITGCs) and IT Application Controls (ITACs) become essential. Strong ITGCs around access management, change management, and IT operations provide the foundation for reliable ESG reporting. At the same time, ITACs help ensure that key automated calculations, data validations, interfaces, and reporting processes operate as intended.
In practice, access management, change management, and system monitoring are often among the weakest areas, even within organizations that have invested significantly in ESG tooling. As regulatory scrutiny and assurance requirements increase, these weaknesses can quickly become obstacles to achieving audit readiness.
Ultimately, strong ESG digital foundations are not simply a matter of efficiency. They are a prerequisite for reliable reporting, successful assurance, stakeholder trust, and regulatory confidence. Organizations that invest early in governance, data flows, ITGCs, and ITACs will be far better positioned to meet both compliance expectations and broader sustainability ambitions.