ESG software vs spreadsheets and consultants: A readiness check
The same package caps penalties for non-compliance at 3% of a company’s net turnover.

In July 2026, the Commission adopted revised ESRS that cut mandatory data points by 60% and total data points by more than 70%, on top of removing roughly 90% of companies from CSRD’s original scope and 70% from CSDDD’s. The Commission expects the combined changes to cut reporting costs by around 30% per company.
CBAM went through its own simplification in October 2025, introducing a de minimis threshold that exempts importers bringing in 50 tonnes or less of covered goods a year.

None of this makes ESG data easier to ignore. It makes it harder to manage with whatever got a company through 2023 and 2024, because the rules it was built around have changed shape twice since, and the Commission has signaled it will keep revising as implementation continues.
And it isn’t only an EU compliance problem. Investors keep sending CDP questionnaires, large customers keep sending their own supplier sustainability assessments, and voluntary commitments to bodies like the Science Based Targets initiative carry their own data and verification demands. A system built to survive one filing tends to buckle the moment a second, unrelated request for the same underlying data arrives in a different format.
Falling out of mandatory scope doesn’t mean falling out of the conversation, either. The Commission’s Omnibus package also introduced a voluntary reporting standard for companies below the CSRD thresholds, specifically because narrowing CSRD’s scope alone would not stop larger customers from pulling value chain data out of smaller suppliers.
CSRD-covered companies are now capped in what they can request from those suppliers, but the requests themselves have not gone away. If a company supplies, sells to, or is financed by an organization still in scope, it is still inside the data chain. It is just managing that chain with less certainty about what “enough” looks like.
So the honest question for any sustainability team right now isn’t whether Excel, a consultant, an ERP module, a niche point tool, or a general-purpose AI chatbot got them through last year’s report. It’s whether that setup can absorb the next reset without anyone finding out where it breaks, in front of an auditor, a board, or a customer’s due diligence questionnaire.
Five tests for a system, not a stopgap
Beyond the basics that should be a given, strong security, a usable interface, a reputable vendor, here is what actually separates a system built for this from one that is quietly held together by a person, a habit, or a spreadsheet tab nobody wants to touch.

1. Ownership: Who actually runs the process
Ask what happens the day the person who built the spreadsheet, managed the consultant relationship, or configured the ERP module leaves the company.
In spreadsheets and manual processes, ownership usually sits with one or two people who understand the macros, the tab structure, and which version is the real one. When they go, so does most of the working knowledge of how the number was actually produced.
With consultants, ownership sits outside the company by design. A consultant is a resource brought in to run a process, not a system the organization owns, so when the engagement ends, the process it depended on often ends with it.
In general ERP and GRC platforms with an ESG add-on, ownership formally sits with IT, but the configuration was usually done once by a systems integrator and rarely revisited as ESRS or CSDDD requirements shift. That leaves a gap between whoever administers the platform and whoever actually understands what the current rules require of it.
Niche point solutions give real ownership, but a narrow one: whoever runs the carbon accounting tool owns the carbon data, not the double materiality assessment, not the sustainability statement, and not the connections between them. General-purpose AI tools flip the ownership question again: someone can ask a chatbot to draft a disclosure or model a data point, but nothing about who asked, what version answered, or what data it saw lives anywhere the organization actually owns.
An enterprise-ready system keeps ownership inside the sustainability team itself, with configuration the team can change without booking a consultant or an integrator every time a threshold or a data point requirement moves.and an accurate figure shows up as real euros per ton.
Auditability: Can every figure be traced back to its source
CSRD still requires assurance on sustainability statements for the companies that remain in scope, and narrowing that scope has concentrated the requirement on larger, more visible companies rather than removed it. An auditor does not want a verbal explanation of how a number came together. They want to follow it back through every hand it passed through, with a date and an owner attached at each step.
Spreadsheets fail this structurally: formulas get overwritten, tabs get duplicated “just in case,” and version history depends on someone remembering to save a dated copy before making changes.
Consultant-built models fail it a different way: the logic can be entirely sound, but it lives in one firm’s working papers, and sometimes only in a consultant’s head, especially once a follow-up question comes up that the original documentation never anticipated. None of that transfers into a system the company can hand over on short notice.
General ERP and GRC platforms often have strong audit trails for financial data, but the ESG fields added later frequently don’t carry the same rigor. Niche tools are strong within their own scope and weak at the seams, and the seam where carbon data has to reconcile with a DMA or a sustainability statement is exactly where traceability tends to disappear.
General-purpose AI tools add a newer version of the same problem: an assistant can produce a fluent, confident answer with no record of which data it drew on, and once several agents hand a task between each other without logging each step, the calculation lineage breaks somewhere an auditor cannot follow it back.
Data quality: What catches an error before it becomes a disclosure
KPMG’s 2024 survey of ESG organizations found that 47% of companies still manage their ESG data in spreadsheets, and, more tellingly, 83% believe they are already ahead of their peers on ESG reporting.
Those two figures sitting next to each other describe the real risk. A manual process doesn’t just introduce errors, it hides how many exist, right up until an auditor, a regulator, or a customer’s due diligence team finds one.
Built-in thresholds, validation rules, and automatic flagging of outliers are what catch a misplaced decimal or a double-counted emissions figure before it reaches a sustainability statement. Spreadsheets and consultant workbooks have none of this by default; whatever checks exist were built by hand and tend to degrade as the model grows.
ERP and GRC add-ons inherit strong validation for financial data but rarely extend it to ESG-specific metrics like scope 3 emissions or DMA outputs. Niche tools validate well inside their niche and stop at its border.
General-purpose AI tools introduce a failure mode of their own: they produce a fluent, confident answer whether or not the underlying data supports it, and without training specific to Scope 3 categories, EU Taxonomy criteria, or ESRS disclosure requirements, a hallucinated figure can look identical to a correct one until someone checks.
Workflows: can the organization actually collaborate on this
CSRD’s narrower scope means the companies that remain in scope are, on average, larger and more complex, with more subsidiaries, more business units, and more people who need to input, review, and sign off data before it reaches group level. A workflow gap that was survivable at a smaller scale becomes a genuine bottleneck at this one.
Spreadsheets don’t have real review hierarchies, version control, or a way to request and track data between business units; most of that gets rebuilt over email every reporting cycle. Consultants can run a workflow, but that means the workflow lives with them, not with the organization, which is the ownership problem again in a different shape.
ERP and GRC systems generally have workflow and approval logic, but it was built for financial or risk processes, and retrofitting it for a double materiality assessment or ESRS disclosure requirements is exactly the difficult, costly configuration work that shows up in every honest account of that category.
Carbon data exposes the same gap from another angle: activity data comes from facilities, fleet, procurement, and logistics teams that were never part of the original approval chain, so routing it through a workflow built for financial sign-off means bolting on custom steps every time an emission factor or calculation methodology changes. Niche tools rarely have any cross-functional workflow at all; they were built for one team, not a group structure.
Executive visibility: does leadership see exposure before it becomes a headline
The KPMG finding cuts both ways. If leadership believes the company is ahead of peers while the underlying data sits in spreadsheets nobody outside the sustainability team can see, that isn’t confidence, it’s a blind spot with good posture.
Boards are asking sharper questions now because the penalties are sharper too: CS3D’s amending directive sets that 3% of global turnover cap for non-compliance, and CSRD penalties are set at the national level on top of that, with Germany’s transposition allowing fines of up to €10 million or a percentage of group turnover and France’s including personal fines for individual directors. That isn’t a number a board wants to discover applies to them after the fact.
Real-time dashboards, forecasting, and benchmarking are what let an executive team see exposure before a report is due, rather than read about it inside the report itself.
Spreadsheets and consultant relationships report backward, summarizing what already happened. ERP and GRC add-ons often have strong executive dashboards for the functions they were originally built for, and thin, static ones for the ESG module added afterward. Niche tools can show excellent detail on their one metric and very little about how it rolls up into the company’s overall exposure.
The diagnostic
The original ESRS buyer’s guide included a two tier checklist for evaluating new software: essential prerequisites, and what it called significant value adds. That checklist was written for a different moment, evaluating something not yet bought. Turned around, the same structure works as an audit of what an organization already has.

Start with the quick version. Answer plainly, and count one point for every question where the honest answer is no.
- Could someone other than the person who built the current process explain, unassisted, how a disclosed figure was calculated
- Could the organization produce a full audit trail, source, date, owner, version, for any single ESG figure in under an hour
- Does the process flag data quality issues automatically, rather than relying on someone happening to notice
- Can one business unit request and receive data from another inside the system itself, without an email chain
- Can leadership see current ESG exposure and progress on a dashboard today, without waiting for the next reporting cycle
Ownership
Baseline: your own team can change a data point, a threshold, or an entity structure in the system today, without booking a consultant or an integrator to do it.
What separates a stopgap from a platform: the system is maintained by people who track ESRS and CSDDD changes for a living, and it can grow as the organization’s sustainability ambitions grow, rather than needing to be replaced when they do.
Auditability
Baseline: every disclosed figure is audit ready with full traceability today, source, date, owner, version, without anyone reconstructing it by hand before the audit.
What separates a stopgap from a platform: quality assurance is built into the system and maintained continuously, rather than checked once at setup and left alone.
Data quality
Baseline: built in thresholds catch data quality issues automatically, and files can be imported without manual reformatting or copy and paste.
What separates a stopgap from a platform: double materiality assessment outputs map automatically to the relevant disclosures, rather than someone connecting the two by hand every cycle.
Workflows
Baseline: review and approval workflows are transparent and collaborative across business units, matched to the organization’s actual reporting hierarchy, and integrations run through an API layer rather than a CSV someone exports and re-uploads.
What separates a stopgap from a platform: the system handles a genuinely complex, multi-entity group structure, and interoperates with adjacent standards and solutions, carbon accounting, EU Taxonomy, rather than requiring a second tool that doesn’t talk to the first.
Executive visibility
Baseline: dashboards and visualizations update in real time, and forecasting and benchmarking live inside the platform rather than in a deck someone assembles before a board meeting.
What separates a stopgap from a platform: data can be sliced and analyzed at a granular level without a request to IT or a consultant, and benchmarking runs on validated internal and external data sets rather than an estimate.
A dimension missing more than one or two baseline items is the one most likely to fail first when the rules move again. The value add items matter less as boxes to check and more as a measure of how much room a team has ahead of the next reset, which, on current form, is not likely to be far off.
The job hasn’t changed, even though the rules have
Fewer companies now fall under CSRD and CSDDD, and the ones that remain report on fewer data points. That is a genuine simplification and it is worth taking at face value. But it doesn’t remove the underlying job: owning the data rather than renting someone else’s understanding of it, being able to prove where every figure came from, catching errors before they become disclosures, running the process across a real organization instead of through a single spreadsheet owner, and giving leadership a clear view of exposure before it becomes a board question.
A platform built specifically for that job, rather than adapted from a spreadsheet, a consulting engagement, an ERP module, or a single-purpose tool, is what lets a sustainability team meet the next regulatory reset as a configuration change instead of a rebuild.
Access one-pager