← Back to CSRD Insights
Insights

CSRD Data Collection: A Step-by-Step Playbook for Audit-Ready ESG Data

Generated image

Most companies that have filed their first CSRD report discovered the same uncomfortable truth: the reporting standards were the easy part. The hard part was the plumbing - figuring out where the data actually lives, who owns it, how to collect it consistently, and how to prove to an auditor that the number on the page is the right one.

In Workiva's 2024 ESG Practitioner Survey of more than 2,200 professionals, 83% said that collecting accurate data to meet CSRD requirements would be a challenge for their organisation. That figure is striking because it comes from people who are already working in ESG - not from bystanders. The data process, not the disclosure framework, is where most programmes stall.

This guide focuses entirely on that process layer: how to scope what you need to collect, map it to source systems, build controls that survive an auditor's scrutiny, and decide when spreadsheets stop being good enough. It deliberately does not re-cover iXBRL tagging, limited assurance mechanics, or GHG measurement methodology - those are covered in separate guides on this site. This is about the infrastructure underneath.


Why the data problem is harder than it looks

ESG data for a CSRD report spans 12 ESRS covering environmental, social, and governance topics - and the original framework contained over 1,000 individual datapoints. Even after the revised ESRS adopted on 3 July 2026 cut mandatory datapoints by 61%, the remaining ~320 mandatory disclosures still draw on data from across the entire business.

The structural problem is fragmentation. ESG data typically originates in energy and utility invoices, ERP procurement records, HR systems, travel booking tools, and group consolidation platforms - rarely in a single place. Finance teams know this pattern from financial consolidation, but sustainability data is messier: it often lacks the standardised chart of accounts that makes financial data tractable.

Under CSRD, the sustainability statement is subject to mandatory limited assurance from the first reporting year, meaning ESG data must be as traceable and auditable as financial figures. That is the bar. A spreadsheet that produces the right number but cannot show where the number came from, who approved it, or what methodology was applied will not pass.


Step 1 - Scope your datapoints to material IROs, not the full ESRS list

The single most important efficiency decision you will make is what not to collect. The revised ESRS (2026) reduce mandatory datapoints by over 60% and total datapoints by more than 70% compared to the 2023 standards, and are expected to lower reporting costs by over 30% per company. But even within the remaining mandatory set, many disclosures are only triggered if a topic is material to your company.

Your double materiality assessment (DMA) is therefore the upstream input to your data collection scope. Once you have concluded which impacts, risks, and opportunities (IROs) are material, you can produce a definitive list of the ESRS datapoints that apply to you. Everything else is out of scope - and collecting it anyway wastes resource and creates noise for your assurance provider.

Practical actions:

  • Export the EFRAG datapoint list and filter to mandatory-only disclosures for your material topics.
  • Mark each datapoint as: (a) already collected, (b) collectable from existing systems, or (c) a genuine gap requiring new process.
  • Treat the gap list as your project backlog, not a reason to panic.
lightbulb Tip

The revised ESRS (2026) introduce a more top-down, principles-based materiality approach. If your DMA was completed under the 2023 standards, revisit it before locking your datapoint scope for FY2027 — some previously mandatory disclosures are now conditional on materiality, which may reduce your collection burden materially.


Step 2 - Map every datapoint to a source system and a named data owner

A datapoint without a named owner is a datapoint that will arrive late, inconsistently formatted, and without supporting documentation. Build a data inventory - a simple register that maps each required disclosure to three things: the source system, the data owner (a named person or role), and the collection method.

Example CSRD Data Inventory (extract)
ESRS DatapointSource SystemData OwnerCollection MethodCadence
E1-6 — Scope 1 GHG emissionsERP / fuel recordsFacilities ManagerAutomated ERP extract + emission factorMonthly
E1-6 — Scope 2 GHG emissionsUtility invoicesFinance ControllerInvoice upload + market-based factorMonthly
S1-6 — % employees by genderHRISHR DirectorAutomated HRIS reportQuarterly
S1-9 — Diversity of governance bodiesBoard secretariatCompany SecretaryManual entry with board minutes as evidenceAnnual
G1-1 — Business conduct policiesPolicy registerLegal / ComplianceDocument reference + attestationAnnual
E1-6 — Scope 3 (Cat. 1 purchased goods)Procurement / ERP spend dataProcurement DirectorSpend-based with EEIO factors; supplier-specific where availableAnnual

The data inventory becomes your single source of truth for the programme. It also makes onboarding new team members and briefing your assurance provider dramatically faster.

Key principle: ERP systems are excellent sources for quantitative data - financial metrics, procurement volumes, HR headcount, energy invoices - but rarely capture all ESG data requirements out of the box. Expect to supplement ERP data with manual inputs, particularly for governance disclosures and value-chain data.


Step 3 - Define collection cadence and methodology before the data arrives

One of the most common audit findings is inconsistent methodology between periods. Decide - and document - the following before you collect a single number:

Collection cadence. Not everything needs to be collected monthly. Environmental data (energy, water, waste) benefits from monthly collection so you can catch anomalies early. Workforce metrics can typically be collected quarterly. Governance disclosures are usually annual. Build a reporting calendar that maps each datapoint to a collection trigger date.

Emission factors and calculation rules. For GHG data, specify which emission factor database you are using (e.g., DEFRA, IEA, ecoinvent), which version, and the reference year. Document whether you are using location-based or market-based accounting for Scope 2. These choices must be consistent year-on-year and disclosed in your methodology note.

Estimation policy for gaps. Gaps will exist - particularly in the first reporting cycle. The right response is a documented estimation methodology, not a blank cell. Specify the estimation approach (e.g., extrapolation from a comparable site, spend-based proxy), flag estimated figures clearly in your data register, and set a target to replace estimates with primary data in the next cycle. CSRD auditors treat "we don't have data for this category" as a data gap requiring a documented plan - not as a valid exclusion rationale.


Step 4 - Build controls and an audit trail for limited assurance

This is the step most teams underinvest in, and the one that causes the most pain when the assurance provider arrives. Limited assurance under CSRD requires your auditor to conclude that nothing has come to their attention suggesting the sustainability statement is materially misstated. To reach that conclusion, they will interrogate your data process, not just your outputs.

Assurance providers will ask to see the raw source data (e.g., utility bills, HR system exports), the exact emission factors or calculation methodologies used, and the internal approval workflows for each reported figure. Spreadsheets fail this test structurally: they lack immutable audit trails, are susceptible to formula errors, and offer no reliable change history.

The minimum viable control set for limited assurance:

  • Source documentation: Every reported figure must link to a source document (invoice, system export, signed attestation). Store these in a structured folder or document management system, not in email.
  • Calculation log: Where a raw input is transformed (e.g., kWh × emission factor = tCO₂e), the calculation must be recorded and reproducible. A named cell in a shared spreadsheet is not sufficient - the formula, the factor, and the version must be locked and versioned.
  • Preparer / reviewer segregation: The person who collects a datapoint should not be the sole person who approves it. Build a two-step review into your workflow, mirroring the segregation of duties that applies to financial reporting.
  • Change log: Any correction to a submitted figure must be recorded with a reason, a date, and the identity of the person who made the change.
  • Cut-off documentation: Record when data collection closed for each reporting period. Late data that is estimated and corrected post-publication weakens the audit trail.
star Important

The transition from limited to reasonable assurance (currently expected for larger companies from 2028 onwards) will require significantly more evidence, documentation, and internal control quality. Building robust controls now — even if they feel over-engineered for limited assurance — avoids a costly rebuild in two years.


Step 5 - Decide: spreadsheets vs. dedicated ESG software

This is a genuine decision, not a foregone conclusion. The right answer depends on your organisation's size, data complexity, and assurance ambitions.

When spreadsheets can still work: A company with 2-3 material topics, a single reporting entity, and a small sustainability team can manage CSRD data collection in a well-structured, version-controlled spreadsheet - provided the control disciplines in Step 4 are applied rigorously. The risk is that spreadsheet-based processes are fragile: one formula error, one overwritten cell, and the audit trail breaks.

When dedicated software earns its keep: One sustainability expert estimated it takes around 375 hours to compile data manually for a full CSRD disclosure - and automating reporting processes can reduce that manual effort by up to 70%. For organisations with multiple entities, complex Scope 3 programmes, or imminent reasonable assurance requirements, dedicated ESG data management platforms offer structured data collection, system integrations, workflow controls, and built-in audit trails that spreadsheets cannot replicate. The ESG reporting software market reflects this demand: it is projected to grow from USD 1.29 billion in 2025 to USD 3.92 billion by 2032.

The key capability to evaluate in any platform: does it act as a genuine system of record - connecting source systems such as ERP, procurement, and HR to reporting outputs - or is it primarily a report-formatting tool? The former is what audit-readiness requires.


Step 6 - Close value-chain and Scope 3 data gaps

Value chain integration is cited as the biggest CSRD implementation hurdle by 41.7% of companies, ahead of data gap analysis (29.6%) and assurance readiness (27%). This is not surprising: Scope 3 emissions data lives outside your direct control, scattered across suppliers, logistics partners, and downstream customers.

Scope 3 emissions account for on average over 70% of a company's total carbon footprint - and for many sectors, the figure is closer to 90%. Ignoring them is not an option where ESRS E1 is material.

A practical progression for Scope 3 data quality:

  1. Start with spend-based screening. Use your procurement spend data and environmentally extended input-output (EEIO) emission factors to estimate emissions by category. This gives you full coverage immediately, even if accuracy is limited.
  2. Prioritise material categories for primary data. Focus supplier engagement on the categories that represent the largest share of your estimated footprint - typically purchased goods and services (Category 1) and upstream transportation (Category 4). The GHG Protocol Scope 3 Calculation Guidance recommends focusing primary data collection on the most material categories and suppliers, using estimates to fill remaining gaps.
  3. Engage suppliers with a structured questionnaire. Embed sustainability data requests into your procurement onboarding and annual supplier review processes. Tier your requests: a short self-assessment for all suppliers, a detailed annual survey for high-spend or high-risk suppliers.
  4. Document your data quality split. ESRS E1 requires you to disclose the proportion of Scope 3 data based on primary (supplier-reported) versus secondary (activity-based) sources. Track this split from the start - it is an assurance focus area.
  5. Note the value-chain cap. The revised ESRS (2026) introduce a cap limiting what CSRD reporters can request from value-chain partners with 1,000 employees or fewer. Design your supplier data requests to stay within this boundary.

Readiness checklist: is your data process audit-ready?

Use this checklist before your assurance provider engagement begins. If you cannot answer "yes" to a question, that is a gap to close.

Scoping

  • Double materiality assessment completed and documented
  • Definitive list of in-scope ESRS datapoints derived from DMA output
  • Out-of-scope topics documented with rationale

Data inventory

  • Every in-scope datapoint mapped to a named source system
  • Named data owner assigned to each datapoint
  • Collection method and cadence documented

Methodology

  • Emission factors specified (database, version, reference year)
  • Scope 2 accounting method (location-based / market-based) documented
  • Estimation methodology documented for all gap-filled datapoints
  • Methodology note drafted and reviewed

Controls

  • Source documents stored and linked to reported figures
  • Calculation logs reproducible and version-controlled
  • Preparer / reviewer segregation in place for all material datapoints
  • Change log maintained for all corrections
  • Reporting cut-off date documented

Value chain

  • Scope 3 categories screened using spend-based approach
  • Material categories identified and primary data collection initiated
  • Supplier data quality split (primary vs. secondary) tracked
  • Supplier data requests designed within the ESRS value-chain cap

Systems

  • Decision made on spreadsheet vs. ESG software (and documented)
  • Integration points between source systems and reporting tool defined
  • Audit trail mechanism confirmed with assurance provider

The process is the product

The CSRD disclosure that lands in ESAP next year is only as credible as the process that produced it. Auditors, investors, and increasingly lenders are not just reading the numbers - they are asking how you got them. A well-designed data collection process, with clear ownership, documented methodology, and controls that mirror financial reporting discipline, is what separates a defensible disclosure from a liability.

The good news: the revised ESRS (2026) have materially reduced the datapoint burden. The companies that use that reduction to build a leaner, better-controlled process - rather than simply doing less - will be the ones that find reasonable assurance in 2028 a manageable step rather than a crisis.

Stay ahead of ESRS changes and CSRD implementation guidance. Subscribe to The CSRD Brief - plain-English alerts on what matters, when it matters.