←
AI for ESG & Sustainability Reporting
Strategic · M15 · lesson 15 of 23 · queued
Preview — browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll →
Operationalizing CSRD and ESRS After the Omnibus
📖
now learning

Operationalizing CSRD and ESRS After the Omnibus

15 min

It is the spring of 2026 and a chief sustainability officer is standing in front of a board that has read exactly one thing about the Omnibus: that Brussels "simplified" sustainability reporting. The implied question hanging in the room is whether the whole CSRD program can be quietly wound down. The honest answer is the opposite. The company has more than 1,000 employees and more than EUR 450 million in turnover, which means it sits squarely inside the narrowed population that Directive (EU) 2026/470 kept in scope. The reporting did not go away. It got concentrated onto the largest undertakings, where a failed disclosure is a board-level event, and onto a smaller club of filers who now have nowhere to hide in the crowd. This lesson is about turning that scope rule into a running operating program: governance, a calendar, named owners, a datapoint inventory, and a basis of preparation that an external assurer can read.

What the Omnibus Actually Changed, and What It Did Not

The single most expensive mistake a reporting function can make in 2026 is to treat the Omnibus as a reprieve. It was not. The Corporate Sustainability Reporting Directive, the CSRD, survived the simplification package. Directive (EU) 2026/470, published on 26 February 2026 and in force from 18 March 2026, did three things that matter to an operating program. It narrowed the population so that large undertakings stay in scope only when they exceed both thresholds, more than 1,000 employees and more than EUR 450 million in turnover. It exempted listed small and medium enterprises that the original directive would have pulled in. And it set member-state transposition for 19 March 2027, which is the date by which national law gives the directive teeth in each jurisdiction.

Read those three changes together and the strategic picture is clear. The companies left in scope are the biggest ones, the ones with the most complex value chains, the most assets, and the most exposure if a number is wrong. EFRAG, the body that drafts the European Sustainability Reporting Standards (the ESRS, the detailed standards that say what a CSRD report must contain), released a simplified ESRS draft on 3 December 2025 that aims to cut the datapoint burden, and that draft is still in flight as of mid-2026. So a reporting lead is operating against a moving target: a confirmed scope rule, a confirmed transposition clock, and a standard whose final datapoint set is not yet frozen. The correct posture is not to wait for certainty. It is to build a program flexible enough to absorb the final ESRS without rebuilding from scratch.

Never tell your board the Omnibus killed CSRD. It did not. It raised the stakes per filer and shrank the group of filers who absorb scrutiny together. If anything, the case for a disciplined, assurance-ready operating program is stronger now than it was before the simplification, because the regulator's attention is concentrated on a smaller, larger, better-resourced population that is expected to get it right.

From a Scope Rule to an Operating Program

A scope rule tells you that you must report. It tells you nothing about how to run the machine that produces the report year after year. The leap from "we are in scope" to "we have a program" is the leap from a one-off project staffed by heroics to a repeatable operating capability with governance, ownership, and a calendar. The reason this matters for an AI-literate strategist is simple: AI multiplies whatever it is pointed at. Point it at a chaotic, ad hoc reporting process and it produces fast chaos with no audit trail. Point it at a governed program with named owners and a documented basis of preparation, and it accelerates a process that stays defensible.

An operating program has five load-bearing parts, and the rest of this lesson builds each in turn: a governance structure that says who decides; a reporting calendar that works backwards from the filing and assurance dates; named ownership for every section of the report; an ESRS datapoint inventory that is the program's spine; and a basis of preparation that documents the rules everyone followed. Miss any one of these and the program reverts to heroics. Build all five and you have something an external assurer can engage with rather than excavate.

Governance: Who Decides, and Who Signs

Governance answers a deceptively simple question: when a judgment call arises, who makes it, and whose signature stands behind the published number? In a CSRD program the answer cannot be "the analyst who happened to be in the spreadsheet." It has to be a named structure. At the top sits accountability that reaches the board, because under CSRD the sustainability statement is part of the management report and carries the weight of a regulated disclosure. Below that sits a reporting steering group, typically the chief sustainability officer, the controller or finance lead who co-owns non-financial reporting, legal, and an assurance liaison who manages the relationship with the external assurer. Below that sit the section owners who produce the datapoints. The cardinal rule of the whole program, that disclosure accountability stays human and "the model recommended it" is never a defense, lives in this structure. AI assists, a named human decides, and the governance log proves who decided what.

The Calendar: Working Backwards From Assurance

Most reporting calendars are built forwards, from when data becomes available, and they fail for the same reason: they treat assurance as a step at the end rather than a constraint that shapes the whole year. Build the calendar backwards instead. Start from the date the assured sustainability statement must be filed under your jurisdiction's transposed law. Work back to when the external assurer needs a substantially complete draft to test, because a limited-assurance engagement still requires the assurer to perform walkthroughs and inquiries on a real file, not a placeholder. Work back further to when each datapoint must be final, then to when its underlying activity data and emission factors must be locked, then to when supplier data collection must begin to have any chance of arriving. The assurer's walkthrough date, not the filing date, is the real deadline, and a calendar that does not name it will discover the gap in the worst possible month.

The backwards calendar also exposes the single most common scheduling error in a CSRD program: assuming that supplier data, the input that gates the largest part of a Scope 3 inventory and therefore much of the climate disclosure, will arrive on the same timeline as internal data. It will not. Supplier responses are slow, partial, and frequently late, and the company controls none of that. So a calendar built backwards forces the uncomfortable but essential decision early: if primary supplier data cannot realistically arrive in time for a given category, the program decides in advance how that category will be estimated, labels the estimate, and documents the method in the basis of preparation, rather than discovering a hole in the final weeks and being tempted to let an AI tool quietly fill it with an average. The calendar is not just a schedule; it is the mechanism that converts a future data gap into a planned, disclosed estimation decision instead of a last-minute fabrication.

Named Ownership: Every Section Has a Human Behind It

The third part of the program is the one most often left implicit, and the assurer notices implicit ownership immediately. Every section of the report, and ideally every material datapoint, has a named owner who is accountable for producing it, evidencing it, and standing behind it. Ownership is not the same as authorship; an analyst may draft a section and an AI tool may accelerate the drafting, but the owner is the named human who confirms the section is complete, consistent, and traceable to evidence before it advances. Ownership is what makes the program survivable when a person changes roles mid-cycle, and it is what lets the reporting lead answer the assurer's first organizational question, who is responsible for this number, without hesitation. A program where ownership is clear can absorb staff turnover, parallel workstreams, and AI assistance without losing the thread; a program where ownership is vague cannot, because no one can say who checked what.

The ESRS Datapoint Inventory: The Spine of the Program

If governance is the skeleton and the calendar is the heartbeat, the ESRS datapoint inventory is the spine. An ESRS datapoint is a single, defined unit of disclosure the standard requires: a specific number, a specific narrative element, or a specific qualitative statement, each with an identifier, a place in a standard such as E1 for climate or S1 for own workforce, and a defined meaning. The full ESRS set runs to many hundreds of datapoints across environment, social, and governance topics, which is precisely why EFRAG's simplification effort focuses on cutting the count. The inventory is the master register of which datapoints apply to your company, who owns each one, what evidence supports it, and what its current status is.

The inventory begins with materiality. CSRD runs on double materiality: a topic is reportable if it is material from an impact perspective, meaning the company's effect on people and the environment, or from a financial perspective, meaning the effect of sustainability matters on the company's own value, or both. The double-materiality assessment determines which ESRS topical standards, and therefore which datapoints, are in scope for your company. That assessment is itself an assurable artifact with its own documented basis, which is why a strategist treats the datapoint inventory as flowing directly from a defensible materiality conclusion rather than from a guess about which standards "feel" relevant.

For each in-scope datapoint, the inventory records a small set of fields that turn it from an entry in a standard into a managed obligation: the datapoint identifier and standard reference; whether it is quantitative or narrative; the named owner; the source of evidence; the method or basis where the datapoint is computed or estimated; whether the figure is primary or secondary data; its assurance status; and its current state, from not started through drafted, evidenced, reviewed, and signed off. This is where AI is genuinely load-bearing. A model can help map your prior disclosures and source systems to the ESRS datapoint structure, propose which datapoints likely apply given your materiality conclusion, and draft narrative datapoints at speed. But the inventory is the control that keeps that speed honest, because every AI-drafted datapoint enters the register in "drafted" status and cannot advance to "signed off" until a named human has checked it against the evidence.

A datapoint with no named owner is not a smaller report. It is the line the assurer will pull first, because an obligation that belongs to everyone belongs to no one.

Why the Inventory Tames AI Rather Than the Reverse

It is worth dwelling on why the datapoint inventory, a piece of administrative plumbing, is the thing that makes AI safe in a CSRD program. The temptation a strategist faces is to point AI at the whole report and ask for a draft, because the model can produce one and it will look complete. The inventory blocks that temptation structurally. Because every datapoint exists as a tracked obligation with an owner, an evidence requirement, and a status, an AI-drafted paragraph cannot simply become the disclosure. It enters as a draft attached to a specific datapoint, and it sits in "drafted" status until the owner has checked the claim against evidence and moved it to "evidenced." The model accelerates the production of the draft, but the inventory ensures the draft is checked before it counts. This is the operational form of the program's iron rule: every figure must trace to evidence, and the inventory is what makes that rule enforceable across hundreds of datapoints rather than a slogan.

The inventory also gives the strategist a live picture of program risk that a finished-looking draft would hide. At any moment, the register shows how many datapoints are evidenced, how many are still drafted, how many rest on estimates, and how many lack an owner. That picture is the early warning system. A report that looks 90% drafted but only 40% evidenced is a report in trouble, and only the inventory reveals it. An AI-generated draft, by contrast, looks finished at 100% and evidenced at zero, which is precisely the illusion the inventory is built to dispel.

The Basis of Preparation: The Rulebook Everyone Follows

The basis of preparation is the document that tells a reader, including the assurer, exactly how the numbers in the report were made. It is the single most underrated artifact in a reporting program and the first one a strategist should insist on. It states the reporting boundary, the consolidation approach, the standards applied, the emission factor sources and versions used, the estimation methods and where they were used, the treatment of primary versus secondary data, the restatement policy, and the cut-off and approval rules. Where a number rests on a judgment, the basis of preparation records the judgment and its rationale. Where a figure is estimated rather than measured, the basis says so, names the method, and states the uncertainty.

The reason the basis of preparation matters so much in an AI-assisted program is that AI's failure modes are precisely the things a good basis of preparation makes visible. A hallucinated emission factor, a plausible but invented number with no source, cannot survive a basis of preparation that requires every factor to name its database and version. An estimate dressed up as measured activity data cannot survive a basis that requires primary and secondary data to be labeled differently. A boundary exclusion the model quietly assumed cannot survive a basis that lists every exclusion with its reason. The basis of preparation is, in effect, the written form of the program's discipline, and it is the document that lets the same team produce the report faster and defend it better, because the rules are written down once and applied consistently rather than reinvented per number.

Worked Example: Standing Up the Program in One Quarter

Consider a manufacturer with 4,200 employees and EUR 1.1 billion in turnover, clearly in scope, that has reported voluntarily before but never under assurance. The new strategist has one quarter to convert a loose sustainability report into an operating program. Watch the wrong way first. The team opens the ESRS, sees hundreds of datapoints, and asks an AI tool to "draft our CSRD report." The model returns a fluent, complete-looking document in an afternoon. It reads beautifully. It also contains a climate target the company never formally set, three emission factors with no source, and a narrative that softens a known negative impact in the supply chain. Every one of those is an assurance finding, and the team would not know which until the assurer pulled the thread.

Now the right way. The strategist starts with governance: a steering group is named, accountability is mapped to the board, and an assurance liaison is appointed. Next the calendar is built backwards from the assurer's walkthrough date, which lands four months before filing, which means datapoints must be final two months before that, which means supplier data collection has to start immediately. Then the materiality assessment is run and documented, producing a defensible set of in-scope topical standards. From that, the datapoint inventory is built: each applicable datapoint gets an identifier, an owner, an evidence source, and a status of "not started." Only then does AI enter, and it enters as an accelerator inside the controls. The model helps map source systems to datapoints and drafts narrative datapoints, every one landing in "drafted" status. The basis of preparation is written in parallel, fixing the factor sources, the estimation methods, and the primary-versus-secondary labeling rules.

By quarter end the manufacturer does not have a finished report. It has something far more valuable: a program. Every datapoint has an owner and a status. Every number that exists traces to evidence. The basis of preparation states the rules. And when the assurer arrives, the conversation is about testing a governed file rather than excavating an ungoverned one. The AI-drafted target that nobody set never reached the inventory, because a narrative datapoint cannot advance past "drafted" without an owner confirming the target exists in board minutes. The speed was captured. The misstatement was caught at the door.

Key Takeaways

  • The Omnibus narrowed the population but did not kill CSRD: Directive (EU) 2026/470, in force 18 March 2026, keeps large undertakings in scope when they exceed both more than 1,000 employees and more than EUR 450 million turnover, with member-state transposition due 19 March 2027.
  • The companies left in scope are the largest, where a failed disclosure is a board-level event, so the case for a disciplined operating program is stronger after simplification, not weaker.
  • An operating program has five load-bearing parts: governance that names who decides and signs, a calendar built backwards from the assurer's walkthrough, named ownership for every section, an ESRS datapoint inventory, and a basis of preparation.
  • The ESRS datapoint inventory is the spine: it flows from a documented double-materiality conclusion, and each in-scope datapoint carries an owner, evidence, method, primary-or-secondary label, and a status that advances only on human sign-off.
  • Build the calendar backwards from assurance, because the assurer's walkthrough date, not the filing date, is the real deadline that determines when supplier data collection must begin.
  • The basis of preparation is the written form of the program's discipline; it makes AI's failure modes visible by requiring sourced factors, labeled estimates, and listed exclusions.
  • AI multiplies whatever it is pointed at: inside a governed program it accelerates defensible work, but pointed at "draft our CSRD report" it produces fast, fluent misstatements.
  • The cardinal rule holds at program scale: disclosure accountability stays human, "the model recommended it" is never a defense, and the governance log proves who decided what.