β
I recently spoke with Marieke*, who leads sustainability at a large public infrastructure operator. She described the moment her CEO asked whether a figure in the report was right. She knew she had checked it. What she could not do was say where it came from. So she went back through file versions looking for the source she had used months earlier, and that search cost her more time than producing the number in the first place.
Nothing in that story is about extraction. The number existed. Somebody had verified it. The problem was that the verification was never written down anywhere.
That is what ESG data collection actually consists of, and it is the part most guides skip.
(*) Names in this article are fictional. The situations are real, taken from conversations with companies working on their sustainability reporting.
ESG data collection is the process of gathering each sustainability data point from wherever it is held, and recording three things alongside it: which part of the company it belongs to, who is accountable for it, and which document it came from. A data point here just means one number or one answer you have to report, such as total electricity used in 2026.
Extraction is close to solved. Most ESG platforms will read a utility bill, an HR export or a previous report and give you back a value. Extraction does not tell you which of your companies that value belongs to, whether it was measured the same way as at your site in Asia, who is accountable for it, or which document it came from when an auditor asks next spring.
Collecting data without a process behind it is faster in the short term. The limits show up when you need to pass an audit, or when you have to collect everything again next year.
In most companies, sustainability data sits in systems that were chosen for other reasons: an ERP per site, HR software per country, invoices in accounts payable, certificates on a shared drive. The challenge is reaching twenty separate places by a fixed deadline, using a process you can repeat next year.
Three situations from recent conversations.
Paul works at a workwear manufacturer with 20+ companies across Europe, Africa and Asia. IT has been decentralised there for years, and every site runs its own ERP. There is no shared export, so each company is a separate manual job, repeated for every one of them.
Tom works at a logistics business with 20+ sites in several countries. Getting consistent data from everywhere is already the challenge, before anything is done with it. His team had bought a collection tool, found it did not fit how they work, and went back to Excel.
And back to Marieke at the infrastructure operator, whose honest description of her process was small Excel files, small checklists and emails going around.

Most companies have one clearly accountable person or team for the final ESG report. The same is rarely true of the individual numbers inside it. Those come from different people in different parts of the company, each responsible for their own piece, and often nobody has said so out loud.
Bart, head of sustainability at a heavy lifting contractor working worldwide, described his process as a mixture of bottom-up submissions and then him taking all of it and trying to put it together.
For Paul at the workwear manufacturer, checking a number means emailing whoever sent it to ask whether it is correct, and then waiting. His own summary was that he wastes a lot of time doing that.
Hanne works at a financial services company where HR data was the hardest category to collect, because that department was the least experienced at gathering data. Her team also re-enters figures by hand into their parent company's reporting system, which as she put it leaves room for human error.
None of this is a motivation problem. It is what happens when a number has someone asking for it and nobody accountable for it.
Traceability means every reported number can be traced back to the document it came from, the person who checked it, and the date that happened. Sustainability reports need limited assurance, which is the lighter of the two levels of external checking. In practice, an auditor picks a sample of numbers and asks for exactly that evidence. The record has to be created when you collect the number, because it cannot be reconstructed from memory a year later.
Michel, at a listed investment company in the first CSRD reporting wave, described collecting the data points as the hardest part of the whole exercise, because everything was manual and no number carried its own history.
There is a simple test. Give a colleague view-only access to your reported numbers, and ask them to follow one number back to the document it came from without your help. If they cannot, the trail does not exist yet, whatever the spreadsheet says.
A sustainability number becomes usable when three things are attached to it: the part of the company it belongs to, the person accountable for it, and the document it came from. These three decisions hold regardless of which tool you use. They are cheap to make before collection and expensive to make halfway through.
Karomia builds its data collection around these three, with the scope and the definitions set before any document goes in. The order matters more than the tooling.
Decide which parts of the company report separately, then write down for each data point what it means, which unit it uses and which period it covers, before anyone collects anything.
Your financial accounts are a starting point and not an answer. The list of companies in your accounts was drawn up for accounting reasons, and sustainability data does not always sit at that level. Emissions attach to sites. Headcount attaches to whoever employs the people. Energy contracts attach to whoever signed them.
A workable definition contains five things: what is included, the unit, the period, what is explicitly left out, and the calculation method where one applies. "Headcount" on its own is not a definition. Headcount at year end, average full-time equivalent over twelve months, and headcount including agency workers are three different numbers. A company with twenty reporting units will produce all three unless it says which one it wants.
The revised ESRS make this worth doing early. You can now rule a topic out through a high-level review, instead of building a full inventory first, and then collect in depth only on the topics that remain. Doing that safely means your scope and your definitions have to be right before the review, not after it.
This is also where the choice between one report for the whole company and separate reports per part gets made in practice. We have written separately about choosing a consolidated ESG report or entity-level reporting.

Send structured requests limited to what you are allowed to ask for, and keep the answers as data points rather than as attachments. The Commission's revised package introduces a value chain cap. Companies covered by the CSRD, the EU law requiring sustainability reporting, cannot ask companies in their supply chain for more information than the voluntary standard for smaller companies covers (European Commission, 3 July 2026). Emissions are treated as an exception.
The practical consequence is that your supplier questionnaire should be built to the voluntary standard rather than to your own wish list. A short request that suppliers can actually answer returns more usable data than a long one they ignore.
Assign a named data owner to each data point, for each part of the company. Give them the field to fill and the record to sign off. Checking then happens in one place, instead of in an email thread asking whether a figure is right.
Data ownership usually falls out naturally once you look at where the data comes from. Energy and water sit with facilities or site management. Headcount and staff turnover sit with HR, per country. Spend sits with procurement. Fleet sits with whoever runs the fleet. The sustainability lead owns the report and the definitions, not the individual numbers.
The reason this works is timing, not motivation. Twenty data owners filling twenty fields work at the same time. One person chasing twenty inboxes works through them one after another, and the second one is what makes March unpleasant.
When the honest answer is that nobody owns a data point yet, name someone anyway and record it as a gap. A gap with a name on it gets closed. A gap without one gets discovered at the deadline.

Record the source document, the data owner and the date at the moment the number is entered. That one record is what answers both the CEO question and the auditor's sample.
A complete record holds:
This has to happen at collection time because the question always arrives later. Nobody asks where a figure came from in the week you produce it. They ask during the audit, or in a board meeting, or when this year's number moves and somebody wants to know why.

In the second year the structure already exists. Your scope is set, your data owners are named, and last year's source sits next to this year's field. The work shifts from building a process to updating numbers and explaining what changed. That is the point where collection stops being the biggest item in your reporting calendar.
The revised ESRS make this more valuable. The Commission expects reporting costs to fall by over 30% per company under the revised standards, and the cut in data points is significant. Neither of those savings reaches a company that rebuilds its collection process from zero every year. More on what changed in the revised ESRS.
Structure makes a number traceable, consistently defined and attached to a person. It does not make a badly measured number a good one. If a meter is misread at source, or a supplier estimates instead of measuring, a clean collection process will deliver that number faster, with a name on it and a document behind it. It will still be wrong.
What the structure does is make the error findable. An untraceable wrong number and an untraceable right number look identical. That is the honest limit, and it is worth saying before you assume any system removes the need to look at your own data.
Start with your scope, because everything else hangs off it. Write definitions for the data points you already know matter to you, before the next collection round rather than during it. Name a data owner for each one, including the ones nobody currently owns. None of this requires a purchase decision, and doing it first makes any later tooling decision cheaper.
What is ESG data collection?
ESG data collection is the process of gathering each sustainability number from the system or document that holds it, and recording it together with the part of the company it belongs to, the person accountable for it, and its source. It covers environmental, social and governance data across everywhere you report from.
Who is responsible for collecting ESG data in a company?
Accountability works best when it is split. The sustainability lead owns the report, the definitions and the deadline. Each individual data point is owned by whoever produces it: facilities for energy, HR for workforce figures, procurement for spend. One person owning every number does not survive the second year.
How do you collect ESG data from several companies in the same organisation?
Set your reporting scope first, then write one definition per data point that applies everywhere, then let each part of the company fill in and check its own figures against that definition. Collecting first and sorting out definitions afterwards is what produces three versions of headcount and a week of email.
What ESG data do you need to collect under the revised ESRS?
The revised ESRS, adopted by the European Commission on 3 July 2026, reduce mandatory data points by over 60% and total data points by more than 70%. The topics themselves are unchanged. The rules apply to companies with more than 1,000 employees and more than β¬450m turnover, for financial years starting 1 January 2027.
Do you need software for ESG data collection, or is a spreadsheet enough?
A spreadsheet works while one person can hold the whole picture in their head. What changes that is the number of places reporting separately, and whether an auditor checks the result. Company size matters less. Once several teams submit separately, the traceability record is the part a spreadsheet cannot carry from one year to the next.
Receive updates and best practices on all things ESG reporting each month.
Read More