CSRD
September 16, 2026

ESG data collection: where does that number come from?

Jens Verhiest
COO

Key takeaways

  • ESG data collection is the work of connecting every sustainability number to where it is reported, with three things attached: its scope, its data owner and its source.
  • Scope means the part of the company a number belongs to. A legal entity, a site, a country, a business unit.
  • Pulling numbers out of documents is standard across ESG tools. The harder part is having a process that supports collection, consolidation and verification.
  • Three things make a number defensible: a clear reporting scope, a named data owner, and a recorded source.
  • The revised ESRS, adopted by the European Commission on 3 July 2026, cut mandatory data points by over 60% and total data points by more than 70%. Fewer data points does not mean fewer places to collect them from.
  • A process built on these three things is what turns the second reporting year into less work than the first.

‍

I recently spoke with Marieke*, who leads sustainability at a large public infrastructure operator. She described the moment her CEO asked whether a figure in the report was right. She knew she had checked it. What she could not do was say where it came from. So she went back through file versions looking for the source she had used months earlier, and that search cost her more time than producing the number in the first place.

Nothing in that story is about extraction. The number existed. Somebody had verified it. The problem was that the verification was never written down anywhere.

That is what ESG data collection actually consists of, and it is the part most guides skip.

(*) Names in this article are fictional. The situations are real, taken from conversations with companies working on their sustainability reporting.

What is ESG data collection, and why is it the part that breaks?

ESG data collection is the process of gathering each sustainability data point from wherever it is held, and recording three things alongside it: which part of the company it belongs to, who is accountable for it, and which document it came from. A data point here just means one number or one answer you have to report, such as total electricity used in 2026.

Extraction is close to solved. Most ESG platforms will read a utility bill, an HR export or a previous report and give you back a value. Extraction does not tell you which of your companies that value belongs to, whether it was measured the same way as at your site in Asia, who is accountable for it, or which document it came from when an auditor asks next spring.

Collecting data without a process behind it is faster in the short term. The limits show up when you need to pass an audit, or when you have to collect everything again next year.

Where is the sustainability data actually held?

In most companies, sustainability data sits in systems that were chosen for other reasons: an ERP per site, HR software per country, invoices in accounts payable, certificates on a shared drive. The challenge is reaching twenty separate places by a fixed deadline, using a process you can repeat next year.

Three situations from recent conversations.

Paul works at a workwear manufacturer with 20+ companies across Europe, Africa and Asia. IT has been decentralised there for years, and every site runs its own ERP. There is no shared export, so each company is a separate manual job, repeated for every one of them.

Tom works at a logistics business with 20+ sites in several countries. Getting consistent data from everywhere is already the challenge, before anything is done with it. His team had bought a collection tool, found it did not fit how they work, and went back to Excel.

And back to Marieke at the infrastructure operator, whose honest description of her process was small Excel files, small checklists and emails going around.

What this costs you

What fragmented data collection costs you

"Where does this number come from?"

Most companies have one clearly accountable person or team for the final ESG report. The same is rarely true of the individual numbers inside it. Those come from different people in different parts of the company, each responsible for their own piece, and often nobody has said so out loud.

Bart, head of sustainability at a heavy lifting contractor working worldwide, described his process as a mixture of bottom-up submissions and then him taking all of it and trying to put it together.

For Paul at the workwear manufacturer, checking a number means emailing whoever sent it to ask whether it is correct, and then waiting. His own summary was that he wastes a lot of time doing that.

Hanne works at a financial services company where HR data was the hardest category to collect, because that department was the least experienced at gathering data. Her team also re-enters figures by hand into their parent company's reporting system, which as she put it leaves room for human error.

None of this is a motivation problem. It is what happens when a number has someone asking for it and nobody accountable for it.

Can you trace it back to its original source?

Traceability means every reported number can be traced back to the document it came from, the person who checked it, and the date that happened. Sustainability reports need limited assurance, which is the lighter of the two levels of external checking. In practice, an auditor picks a sample of numbers and asks for exactly that evidence. The record has to be created when you collect the number, because it cannot be reconstructed from memory a year later.

Michel, at a listed investment company in the first CSRD reporting wave, described collecting the data points as the hardest part of the whole exercise, because everything was manual and no number carried its own history.

There is a simple test. Give a colleague view-only access to your reported numbers, and ask them to follow one number back to the document it came from without your help. If they cannot, the trail does not exist yet, whatever the spreadsheet says.

Three things that make a sustainability number usable

A sustainability number becomes usable when three things are attached to it: the part of the company it belongs to, the person accountable for it, and the document it came from. These three decisions hold regardless of which tool you use. They are cheap to make before collection and expensive to make halfway through.

  1. Set your reporting scope, and define what each number means.
  2. Give every data point a named data owner.
  3. Record the source of every number, for every part of the company, every year.

Karomia builds its data collection around these three, with the scope and the definitions set before any document goes in. The order matters more than the tooling.

1. Set your reporting scope, and define what each number means

Decide which parts of the company report separately, then write down for each data point what it means, which unit it uses and which period it covers, before anyone collects anything.

Your financial accounts are a starting point and not an answer. The list of companies in your accounts was drawn up for accounting reasons, and sustainability data does not always sit at that level. Emissions attach to sites. Headcount attaches to whoever employs the people. Energy contracts attach to whoever signed them.

A workable definition contains five things: what is included, the unit, the period, what is explicitly left out, and the calculation method where one applies. "Headcount" on its own is not a definition. Headcount at year end, average full-time equivalent over twelve months, and headcount including agency workers are three different numbers. A company with twenty reporting units will produce all three unless it says which one it wants.

The revised ESRS make this worth doing early. You can now rule a topic out through a high-level review, instead of building a full inventory first, and then collect in depth only on the topics that remain. Doing that safely means your scope and your definitions have to be right before the review, not after it.

This is also where the choice between one report for the whole company and separate reports per part gets made in practice. We have written separately about choosing a consolidated ESG report or entity-level reporting.

Karomia data collection screen showing a company split into reporting scopes for ESG data collection

How do you collect ESG data from suppliers?

Send structured requests limited to what you are allowed to ask for, and keep the answers as data points rather than as attachments. The Commission's revised package introduces a value chain cap. Companies covered by the CSRD, the EU law requiring sustainability reporting, cannot ask companies in their supply chain for more information than the voluntary standard for smaller companies covers (European Commission, 3 July 2026). Emissions are treated as an exception.

The practical consequence is that your supplier questionnaire should be built to the voluntary standard rather than to your own wish list. A short request that suppliers can actually answer returns more usable data than a long one they ignore.

2. Give every data point a named data owner

Assign a named data owner to each data point, for each part of the company. Give them the field to fill and the record to sign off. Checking then happens in one place, instead of in an email thread asking whether a figure is right.

Data ownership usually falls out naturally once you look at where the data comes from. Energy and water sit with facilities or site management. Headcount and staff turnover sit with HR, per country. Spend sits with procurement. Fleet sits with whoever runs the fleet. The sustainability lead owns the report and the definitions, not the individual numbers.

The reason this works is timing, not motivation. Twenty data owners filling twenty fields work at the same time. One person chasing twenty inboxes works through them one after another, and the second one is what makes March unpleasant.

When the honest answer is that nobody owns a data point yet, name someone anyway and record it as a gap. A gap with a name on it gets closed. A gap without one gets discovered at the deadline.

Assigning a data owner to each ESG data point for one part of the company

3. Record the original source of every number, for every part of the company, every year

Record the source document, the data owner and the date at the moment the number is entered. That one record is what answers both the CEO question and the auditor's sample.

A complete record holds:

  • the number, with its unit and period
  • the part of the company it belongs to
  • the source document, down to the page or line
  • who entered it, and who checked it
  • the date it was checked
  • the calculation method and factor, where the number is calculated rather than read

This has to happen at collection time because the question always arrives later. Nobody asks where a figure came from in the week you produce it. They ask during the audit, or in a board meeting, or when this year's number moves and somebody wants to know why.

Tracing a consolidated ESG number back to the submissions and sources behind it

What ESG data collection looks like in year two

In the second year the structure already exists. Your scope is set, your data owners are named, and last year's source sits next to this year's field. The work shifts from building a process to updating numbers and explaining what changed. That is the point where collection stops being the biggest item in your reporting calendar.

The revised ESRS make this more valuable. The Commission expects reporting costs to fall by over 30% per company under the revised standards, and the cut in data points is significant. Neither of those savings reaches a company that rebuilds its collection process from zero every year. More on what changed in the revised ESRS.

What this does not fix

Structure makes a number traceable, consistently defined and attached to a person. It does not make a badly measured number a good one. If a meter is misread at source, or a supplier estimates instead of measuring, a clean collection process will deliver that number faster, with a name on it and a document behind it. It will still be wrong.

What the structure does is make the error findable. An untraceable wrong number and an untraceable right number look identical. That is the honest limit, and it is worth saying before you assume any system removes the need to look at your own data.

What to do next

Start with your scope, because everything else hangs off it. Write definitions for the data points you already know matter to you, before the next collection round rather than during it. Name a data owner for each one, including the ones nobody currently owns. None of this requires a purchase decision, and doing it first makes any later tooling decision cheaper.

Frequently asked questions

What is ESG data collection?
ESG data collection is the process of gathering each sustainability number from the system or document that holds it, and recording it together with the part of the company it belongs to, the person accountable for it, and its source. It covers environmental, social and governance data across everywhere you report from.

Who is responsible for collecting ESG data in a company?
Accountability works best when it is split. The sustainability lead owns the report, the definitions and the deadline. Each individual data point is owned by whoever produces it: facilities for energy, HR for workforce figures, procurement for spend. One person owning every number does not survive the second year.

How do you collect ESG data from several companies in the same organisation?
Set your reporting scope first, then write one definition per data point that applies everywhere, then let each part of the company fill in and check its own figures against that definition. Collecting first and sorting out definitions afterwards is what produces three versions of headcount and a week of email.

What ESG data do you need to collect under the revised ESRS?
The revised ESRS, adopted by the European Commission on 3 July 2026, reduce mandatory data points by over 60% and total data points by more than 70%. The topics themselves are unchanged. The rules apply to companies with more than 1,000 employees and more than €450m turnover, for financial years starting 1 January 2027.

Do you need software for ESG data collection, or is a spreadsheet enough?
A spreadsheet works while one person can hold the whole picture in their head. What changes that is the number of places reporting separately, and whether an auditor checks the result. Company size matters less. Once several teams submit separately, the traceability record is the part a spreadsheet cannot carry from one year to the next.

Sign up for our newsletter

Receive updates and best practices on all things ESG reporting each month.

Read More

CSRD
Here

How sustainability data collection finally works

The hardest part of a group ESRS report is not writing it. It is getting the numbers out of 32 entities in four languages. Here is how Karomia collects and consolidates them.

View
View
Here

How climate risk assessments finally scale

Until now you could have depth on five sites or a colour on five thousand. Not both. Here is how Karomia produces site-level physical climate risk assessments at scale, with the evidence attached.

View
View
Here

The underestimated cost of the energy crisis

Gas prices up 85% in Belgium. Do you know what the Middle East energy crisis costs your business? Calculate your fossil fuel exposure and run your own energy cost scenarios.

View
View