How to Stifle Open Source Without Banning It
Benedikt Langer
6 Min. Read The sharpest argument against China’s top open AI comes from a man at OpenAI. Dean Ball, ...
8 min. read
In many companies, sustainability reporting is treated as a tedious obligation: a document produced by the legal department, signed off by the auditor, and read by nobody else. That view is becoming expensive. Companies that treat ESG data as a mere compliance checkbox miss the fact that the same figures influence capital costs, supplier status, and talent acquisition. The EU has significantly streamlined reporting requirements, but the strategic value of the data remains. The topic is moving out of the compliance corner and onto the executive agenda.
Key Takeaways
Related:Technical Debt Belongs on the Board Agenda/Raw Materials Policy Is Becoming Tech Policy
What is the CSRD? The Corporate Sustainability Reporting Directive is the EU regulation governing sustainability reporting. It requires companies to disclose their environmental and social impacts, along with associated risks, in a standardised format. Unlike earlier frameworks, it demands audited, comparable data under fixed standards – the ESRS – rather than voluntary self-reporting.
The instinct to dismiss all this as bureaucracy is understandable, but it carries a price tag. Banks and investors have long been using ESG data for risk assessment. Weak or absent reporting translates into higher capital costs, reduced access to sustainability-linked loans, and fewer opportunities to issue green bonds. Research, conversely, points to a correlation between strong ESG ratings and lower financing costs. The figures in the report don’t just end up in the archive – they surface in the credit conversation.
The second lever sits in the supply chain. Large clients are required to demonstrate the sustainability of their suppliers and pass that pressure downstream. Mid-market companies that can provide solid ESG data become preferred suppliers, while competitors without that data are disqualified from tenders. The reporting obligation thus becomes a sales argument – one that genuinely counts in the customer’s procurement process.
In early 2026, the EU’s Omnibus Package noticeably reduced reporting burdens. The number of mandatory data points was cut dramatically, and the circle of companies subject to reporting requirements was narrowed. Reading this as an all-clear misses the point of the reform entirely.
What was reduced is the workload, not the strategic substance. The core principle of double materiality remains intact: companies must still disclose how sustainability issues affect their business and how their business affects the environment and society. It is precisely these two perspectives that make ESG data meaningful to investors and customers. The simplification strips out data collection with low decision value while preserving everything that touches financing, risk, and customer requirements. That makes delegation harder to justify.
To turn a compliance obligation into a lever, it helps to look soberly at where ESG data actually moves money. Three impact channels come up again and again.
| Impact Channel | Treated as Obligation | Used as Lever |
|---|---|---|
| Cost of Capital | Risk discount from thin data | Better terms, green financing |
| Supply Chain | Exclusion from tenders | Preferred supplier status |
| Talent | Interchangeable employer | Competitive edge in a tight labor market |
The difference lies in how the data is used. Companies that merely collect ESG figures satisfy the audit. Those that deploy them in credit negotiations, tender submissions, and recruiting turn the same obligation into a hard business case.
What separates effective CSR from pure symbolism is rarely the budget – it’s the honesty of the data and how it’s used. The following patterns determine which direction a company takes.
The difference is a matter of attitude. Companies that treat CSR as a symbol risk not only missing out on competitive advantages – they also invite accusations of greenwashing, which cost more than honest gaps ever would. Those who treat it as an instrument turn a compliance obligation into an argument for banks, customers, and job candidates alike. The data has to be collected either way. Whether it sits in an archive or works in the market is a decision made at board level.
The 2026 Omnibus Package significantly reduces the number of mandatory data points and narrows the circle of companies subject to reporting requirements. The administrative burden drops noticeably as a result. The core principle of double materiality remains intact, however, which means the strategic value of the data is preserved.
Double materiality requires two lines of sight. First, how sustainability issues affect the company financially; second, how the company’s own activities impact the environment and society. Both dimensions must be reported when they are material. It is precisely this dual perspective that makes the data meaningful to investors.
Banks and investors factor ESG risks into lending and investment decisions. Weak or absent reporting leads to risk discounts and reduced access to sustainability-linked financing. Solid, audited ESG data, by contrast, can improve financing terms. That puts reporting data squarely in the conversation with your bank or investors – not just in the annual report.
Because large corporate buyers must demonstrate the sustainability of their supply chains and pass that requirement down the line. Suppliers with robust ESG data become preferred vendors; those without are increasingly excluded from tenders. Reporting obligations thus translate into a concrete competitive advantage in B2B procurement.
A role close to the business, with a mandate at board level – not a pure compliance function buried in the legal department. Only then do ESG data flow into financing, sales, and talent strategy. If the topic remains an archive of box-ticking, the strategic value is lost even though the effort is incurred regardless.
Read more on Digital Chiefs
Digital ChiefsWho Really Owns AI Operations: Three DeterminationsDigital ChiefsAI on the board: Who decides, who is liable?Digital ChiefsCSRD Audit: Where the IT Data Chain BreaksMore from the MBF Media Network
cloudmagazinCloud Sovereignty in Practice mybusinessfutureEU AI Act for SMEs: Provider or Deployer? securitytodayBackup That Survives a Ransomware AttackImage credit: Cover image AI-generated (June 2026), C2PA certificate embedded in image