ISSB, CSRD, ESRS, SSBJ, GRI, TCFD, TNFD, CDP. The frameworks arrive faster than most teams can absorb them. This guide sorts out which one asks what, how single and double materiality differ, why the EU regime reaches non-EU companies, and what to build first if you are starting now.
Six sections, from first principles to assurance
What sustainability disclosure actually is
Not a report for its own sake. It is the mechanism that lets capital, customers and regulators compare companies on non-financial performance.
Sustainability disclosure means publishing information about how a company affects, and is affected by, environmental and social factors — in a form that can be compared with other companies. Over the past decade it has moved from voluntary reporting to a mandatory filing obligation in an increasing number of jurisdictions.
That shift changes what “good” looks like. A voluntary report could be a narrative. A filing has to be specific, sourced, internally consistent, and capable of surviving assurance. In practice this means the disclosure team needs the same controls the finance team has: defined data owners, documented methods, and an audit trail.
The distinction that resolves most confusion: separate what is required of you by law from what is requested of you by others — customers, investors, rating agencies. They demand different things, on different timetables, and conflating them is the usual reason disclosure programmes feel unmanageable.
The standards map
The frameworks look like a crowded field. They are not competing for the same job.
The useful way to hold this: ISSB is the investor-facing baseline, ESRS adds impact-side reporting for the EU, GRI remains the stakeholder-facing standard, and TCFD is the four-pillar structure that the others inherited. A company reporting under ISSB or SSBJ is not choosing against GRI — most large companies publish against more than one, from a single set of underlying data.
Materiality: single and double
This is the decision that determines everything you write. It is also where two regimes genuinely differ.
Single (financial) materiality asks: which sustainability matters could affect the company’s cash flows, access to finance or cost of capital? That is the ISSB question.
Double materiality asks that question and a second one: how does the company affect people and the environment, regardless of financial consequence? That is the CSRD/ESRS question, and it is why an EU-scope report is broader than an ISSB-only report.
Practically, run one assessment that captures both directions and then filter for each audience. Running two separate exercises produces two different lists of priorities, which is difficult to defend to either audience. Whichever route you take, record the evidence — stakeholder input, thresholds, and why topics were excluded. The exclusions get challenged more often than the inclusions.
The EU regime, and why it reaches Japanese and US companies
CSRD applies by size and market presence, not by nationality — which is how a non-EU parent ends up in scope.
The Corporate Sustainability Reporting Directive requires in-scope companies to report under the ESRS, with assurance. Non-EU groups can be pulled in through large EU subsidiaries or EU turnover thresholds, which is why companies with no EU listing still find themselves preparing ESRS data points.
The picture is moving. The Omnibus simplification package has reopened scope, timing and data-point volume, and companies should expect the detail to keep changing. The stable planning assumption is not a specific deadline but the direction: fewer companies in the earliest waves, but no reversal of the underlying requirement. Alongside it, the Corporate Sustainability Due Diligence Directive addresses conduct rather than reporting — it asks what you did about the risks, not only what you disclosed.
For suppliers to EU customers there is a second-order effect that arrives sooner than any legal obligation: in-scope customers need value-chain data, so they ask you for it.
Climate, nature, and the ratings that read your report
Climate disclosure is the most developed area; nature is following the same template; ratings sit on top of whatever you publish.
For climate, IFRS S2 carries the TCFD four-pillar structure — governance, strategy, risk management, metrics and targets — and adds specific requirements including Scope 1, 2 and 3 emissions and, where used, scenario analysis. A transition plan is increasingly the part readers examine most closely: not the target, but the route to it.
For nature, the TNFD recommendations follow a deliberately similar four-pillar shape, with the LEAP approach (Locate, Evaluate, Assess, Prepare) as the assessment method. Anyone who has implemented TCFD will recognise the architecture, which is the point.
Then there are the intermediaries. CDP collects climate, water and forests data through an annual questionnaire and scores responses; unlike public-information ratings, not responding produces no score at all. Rating agencies such as MSCI, FTSE Russell and Sustainalytics score you from what you publish, mostly relative to your sector — which means standing still while peers improve shows up as a downgrade.
Assurance, and where to start
Assurance is arriving. Building for it from the beginning is much cheaper than retrofitting it.
Limited assurance over sustainability information is already required in parts of the EU regime, and the international standard ISSA 5000 gives assurance providers a common basis. The direction is towards broader scope and, eventually, reasonable assurance. What that demands of you is unglamorous: traceable data, retained evidence, documented methods, and a named owner for each metric.
If you are early, the sequence that wastes least effort is:
- Materiality first. Until topics are agreed, nothing else can be scoped.
- Then GHG accounting. Scope 1 and 2 properly, Scope 3 estimated. Almost every framework needs these numbers.
- Then the reporting vehicle. Decide what goes in the statutory filing and what goes in the voluntary report, and keep them consistent.
- Then the questionnaires. CDP and customer requests are much easier once the first three exist.
The two foundations — an agreed materiality list and a working emissions inventory — survive changes in standards. Work sequenced around a specific regulation’s deadline usually does not.
What disclosure leads ask in the first month
Which standard do we have to follow?
Start from your legal obligations rather than from the frameworks. A Japanese listed company begins with securities reporting and the SSBJ standards; a company with substantial EU operations must check CSRD scope; GRI is voluntary and serves a stakeholder audience. Most large groups end up reporting against more than one, from a single underlying dataset.
We are not in scope for CSRD. Can we ignore it?
Not entirely. Customers who are in scope need value-chain data, and they will ask you for it as a commercial requirement long before any law applies to you. Treating that request as a procurement matter rather than a compliance matter is usually the faster route to a workable answer.
Is a sustainability report the same as the disclosure in our annual filing?
No. A statutory filing has prescribed content and timing and carries legal liability; a sustainability or integrated report is voluntary, broader in audience and freer in form. The requirement that catches people out is consistency: where the two describe the same topic, they must not disagree.
Do we need third-party assurance yet?
It is not universally mandatory, but the scope is widening and limited assurance already applies in parts of the EU regime. The practical answer is to operate as if assurance were coming — keep evidence, document methods, name an owner per metric. Retrofitting an audit trail costs far more than maintaining one.