CSRD first-wave sustainability statements lock for FY 2024 year-end filings
CSRD first wave sustainability statements are due for the largest companies. If you are in scope for 2024 reporting, your sustainability report needs ESRS-compliant disclosures. Double materiality assessment and value chain data collection should be complete.
Accuracy-reviewed by the editorial team
FY 2024 sustainability statements under the Corporate Sustainability Reporting Directive (CSRD) must be approved and published in 2025 with limited assurance and digital tagging. December 2025 is the final checkpoint to lock ESRS disclosures, evidence, and XBRL mapping before board approval. Use this runbook with the pillar hub, the CSRD first-wave readiness guide, and related briefs on ESRS quick fix and CSRD XBRL control build.
Timeline and governance gates
| Period | Action | Evidence |
|---|---|---|
| Dec 2025 | Finalize ESRS datapoints, double materiality, and control testing. | Materiality matrix, disclosure checklist, control test results. |
| Jan–Feb 2026 | Board/AC approval, assurance fieldwork, and XBRL tagging completion. | Board minutes, auditor PBC list, tagging validation logs. |
| By Apr 2026 | Publication with digital package (XHTML + XBRL) and accessibility statement. | Filed report, filing receipt, website publication log. |
Visual — CSRD workback plan
[Publication] ← [Assurance wrap & AC signoff] ← [XBRL tagging QA] ← [Control testing] ← [Data freeze]
Materiality and disclosure coverage
- Double materiality refresh. Update impact and financial materiality assessments with FY 2024 data; evidence stakeholder engagement and thresholds.
- Disclosure mapping. Crosswalk each material topic to ESRS topical standards (E1–E5, S1–S4, G1) and entity-specific disclosures.
- Data lineage. For each metric, document source systems, calculation methods, controls, and owners.
- Assumptions and estimates. Record estimation methods for Scope 3, financed emissions, or biodiversity baselines.
Control testing and assurance readiness
| Area | Control | Test | Owner |
|---|---|---|---|
| GHG inventory | Emission factor governance and change control. | Sample recalculation and factor approval evidence. | Sustainability controller |
| Data collection | Access control and completeness checks for ESG data lake. | User access review; reconciliation to finance/HR systems. | IT + Internal control |
| Forward-looking statements | Review and approval workflow for transition plans and targets. | Disclosure committee minutes and sign-offs. | Legal/Strategy |
| XBRL tagging | Tag-to-source traceability and validation. | Tagging QA logs, validation screenshots. | Reporting |
Data packaging for digital reporting
- Taxonomy selection. Use the final ESRS taxonomy; avoid custom extensions unless required by entity-specific disclosures.
- Tagging quality. Apply anchor tags, dimensionality, and sign conventions; validate with automated tools and manual review.
- Accessibility. Ensure XHTML package meets WCAG 2.1 AA; include language tags, alt text, and keyboard navigation.
- Reproducibility. Store tagging instructions, mapping tables, and validation logs in an evidence repository.
Key metrics to track
| Metric | Target | Purpose |
|---|---|---|
| Control test completion | ≥ 95% by data freeze | Assurance readiness and reliability. |
| XBRL validation errors | 0 blocking errors; < 5 warnings | Digital filing quality. |
| Disclosure completeness | 100% of applicable ESRS datapoints covered | Scope coverage for auditors and regulators. |
| Issue resolution time | < 5 business days | Keeps critical path on schedule. |
Engaging stakeholders
- Audit and assurance. Agree PBC lists, walkthrough dates, and sampling; align on materiality thresholds and narrative review timeline.
- Board and audit committee. Schedule education on ESRS changes, assurance scope, and key judgments; secure sign-off slots.
- Legal and communications. Coordinate forward-looking statements, climate targets, and risk factors to align with securities disclosures.
- IT and data owners. Assign issue-response SLAs for data defects and ensure backup controls for late-breaking fixes.
Risk scenarios and mitigations
- Late Scope 3 data. Mitigate with estimation methodology approval and sensitivity analysis disclosure.
- XBRL mapping errors. Conduct dual control reviews and pre-filing validation; maintain rollback package.
- Control failures. Escalate deficiencies to the audit committee; design and execute compensating controls with evidence.
- Inconsistent narratives. Align sustainability statements with financial filings and risk factors; run red-team review.
Evidence room contents
- Materiality methodology, stakeholder engagement notes, and approval records.
- Data lineage documents, calculation workbooks, and change logs.
- Control test scripts and results; remediation plans.
- XBRL tagging maps, validation screenshots, and filing receipts.
- Board and audit committee minutes, education materials, and sign-offs.
30-day closing checklist
- Freeze KPIs and emission inventories; lock calculation factors.
- Complete control testing and document conclusions for assurance teams.
- Run XBRL validation on full draft; resolve blocking errors.
- Finalize narratives, targets, and risk factors; align with financial statements.
- Populate evidence room and prepare board/audit committee materials.
Disclosure controls and procedures
- Integrate sustainability controls into existing ICFR/ICS frameworks; map responsibilities to control owners.
- Run disclosure committee checkpoints at draft, pre-assurance, and pre-board stages.
- Embed version control for narratives and data tables; lock for changes after data freeze unless approved.
Scenario playbook
| Scenario | Response | Evidence |
|---|---|---|
| Late supplier Scope 3 input | Use approved estimation methodology; disclose limitations and plan for improvement. | Estimation memo, approval record, disclosure note. |
| Control failure identified during testing | Design compensating control, retest, and document in deficiency tracker. | Deficiency log, remediation plan, retest results. |
| XBRL validation errors near filing | Stand up war room; prioritize blocking errors; rerun validations after fixes. | Issue log, validation reports, sign-off notes. |
Communications and change management
- Prepare board and executive FAQs on CSRD scope, assurance, and liability.
- Draft press and investor messaging aligned to risk factors and forward-looking statements.
- Train disclosure owners on plain-language principles and consistency across channels.
Third-party and technology oversight
- Assess ESG software providers for access controls, change management, and uptime SLAs.
- Review auditor independence and scope; clarify reliance on specialists for climate or social metrics.
- Ensure backup calculation paths (for example, spreadsheets with controls) exist if system defects arise.
Post-publication sustainment
- Plan for reasonable-assurance transition; capture lessons learned and control improvements.
- Monitor regulatory updates (for example, ESRS setup Q&As) and integrate into next cycle.
- Update risk registers and strategic plans to reflect disclosed targets and transition pathways.
Internal audit role
- Conduct pre-assurance readiness reviews on governance, data quality, and control design.
- Validate segregation of duties between data preparers, reviewers, and approvers.
- Track remediation and retesting, reporting status to the audit committee.
Data controls by topic
| Topic | Control focus | Example test |
|---|---|---|
| E1 Climate | Activity data completeness, emission factor governance, and scenario consistency. | Reperform Scope 1/2 calculation for selected sites; confirm factor versions. |
| S1 Workforce | HR data access, attrition and pay calculation logic, diversity metrics. | Trace pay gap calculation to payroll and HR master data. |
| G1 Governance | Anti-corruption incidents, board diversity, risk management disclosures. | Verify incident counts against ethics hotline register; reconcile board data to corporate records. |
Assurance coordination
- Share control matrices, walkthrough narratives, and evidence index with assurance providers early.
- Agree sampling approaches for key metrics to avoid late rework.
- Schedule daily stand-ups during fieldwork to clear blockers and document agreed views.
Future-proofing for reasonable assurance
- Enhance automation for data capture (IoT meters, system connectors) to reduce manual collection risk.
- Introduce preventive controls (system validations) alongside detective reconciliations.
- Document model governance for estimates, including assumptions, sensitivity analyzes, and change control.
Data retention and archiving
- Retain working papers, evidence, and tagging files for at least the statutory period aligned to financial reporting.
- Store immutable copies of submitted XHTML/XBRL packages and validator outputs.
- Archive versions of methodologies and assumptions to support future period-over-period comparisons.
People and capacity planning
Map resource needs for reporting, controls testing, tagging, and assurance support. Secure backups for critical roles, and lock calendar time for walkthroughs, board education, and filing rehearsals to keep the critical path intact.
Keep investor-relations and legal teams aligned on timing of sustainability statement publication relative to financial results to manage disclosure consistency.
Continue in the Policy pillar
Return to the hub for curated research and deep-dive guides.
Latest guides
-
Policy Advocacy Roadmap
Coordinate cross-border policy advocacy aligned with EU Better Regulation, U.S. Administrative Procedure Act, Lobbying Disclosure rules, and Canadian transparency requirements.
-
AI Policy Implementation Guide
Coordinate governance, safety, and reporting programmes that meet EU Artificial Intelligence Act timelines and U.S. National AI Initiative Act mandates while sustaining product…
-
Export Controls and Sanctions Policy Guide
Integrate U.S. Export Control Reform Act, International Emergency Economic Powers Act, and EU Dual-Use Regulation requirements into trade compliance, engineering, and supplier…
Further reading
- Directive (EU) 2022/2464 (Corporate Sustainability Reporting Directive) — European Union
- European Commission — Corporate Sustainability Reporting Directive — European Commission
- ISO 31000:2018 — Risk Management Guidelines — International Organization for Standardization
Comments
Community
We publish only high-quality, respectful contributions. Every submission is reviewed for clarity, sourcing, and safety before it appears here.
No approved comments yet. Add the first perspective.