ESRS S3 Affected Communities: A Practitioner's Guide to Disclosure and Due Diligence

The EU's sustainability reporting framework has always treated communities as more than a footnote. ESRS S3 - Affected Communities - gives that commitment a precise legal shape: structured disclosure requirements, a clear scope, and an explicit link to human-rights due diligence that runs all the way through to the Corporate Sustainability Due Diligence Directive (CSDDD).
This guide is the third in our series on the CSRD social standards. If you have already read our guides on ESRS S1 Own Workforce and ESRS S2 Workers in the Value Chain, you will find S3 follows the same logical structure - but with a materially different subject matter and some unique obligations, particularly around Indigenous Peoples' rights.
What is ESRS S3 - and how does it differ from S1 and S2?
ESRS S3 is the topical standard covering a company's impacts, risks, and opportunities related to affected communities - those beyond the company's own workforce who may be impacted by its operations, supply chain, or products.
The distinction from S1 and S2 is important and deliberate:
- S1 (Own Workforce) covers people the company employs or engages directly - employees, contractors, agency workers.
- S2 (Workers in the Value Chain) covers workers employed by suppliers, customers, and other business partners - people in a labour relationship, just not with the reporting company.
- S3 (Affected Communities) covers everyone else: the people who live near a mine, downstream from a factory, adjacent to a plantation, or in a region where a company's security arrangements operate. They are not workers. They are neighbours, residents, rights-holders.
This distinction matters for scoping. A company can have no material S1 or S2 issues and still face significant S3 exposure - particularly if it operates in extractive industries, agriculture, infrastructure, or any sector with a large physical footprint.
Who counts as an "affected community"?
The standard is deliberately broad. Affected communities include:
- Communities living or working around operating sites, factories, or other physical operations - including those affected indirectly, for example by downstream water pollution
- Communities along the value chain affected by the operations of suppliers or other business partners
- Communities affected by the transition to a low-carbon economy, where a company's decarbonisation activities (such as mine closures or land-use changes) alter local livelihoods
The three sub-topics of ESRS S3 are: communities' economic, social and cultural rights (including land-related impacts, security-related impacts, adequate housing, food, water and sanitation); communities' civil and political rights (including freedom of expression, freedom of assembly, and impacts on human rights defenders); and the particular rights of Indigenous Peoples (including free, prior and informed consent, self-determination, and cultural rights).
The double materiality gate
Like every topical ESRS standard, S3 is subject to the double materiality assessment (DMA). A company only reports under S3 if the topic is material - either because the company has actual or potential impacts on communities (impact materiality), or because community-related issues create financial risks or opportunities for the business (financial materiality), or both.
When is S3 likely to be material?
The standard does not prescribe a sector list, but the indicators are well understood. Key triggers include:
- Operations in or near indigenous territories, protected areas, or conflict-affected regions
- Large-scale land use, extractive operations, or intensive water use
- Significant supply chain exposure in countries with high community conflict risk
- Security arrangements - private or public - that could affect community safety
- Previous grievances, incidents, or litigation involving community impacts
The financial materiality angle is equally concrete. If communities resist a company's presence or object to its local practices, this can create costly delays and affect the ability to secure future land concessions or permits. If a business model relies on intensive water extraction that affects community access to water, the result can be boycotts, complaints, and lawsuits.
The revised ESRS and a more top-down DMA
On 3 July 2026, the European Commission formally adopted the Delegated Act revising the ESRS as part of the Omnibus I simplification package, cutting mandatory datapoints by more than 60% and total datapoints by more than 70% relative to the first-generation standards. The revised ESRS apply from financial year 2027, with voluntary early adoption available for FY2026.
One practical effect for S3: many datapoints that were previously mandatory are now conditional on the DMA outcome. The revised framework also introduces greater flexibility for a top-down DMA approach. However, because impacts on communities and on nature are inherently location-specific, a purely top-down assessment will rarely be sufficient for S3. Proximity of business locations to Indigenous Peoples and local communities requires a bottom-up, site-level lens to fully meet the spirit of the regulation.
Timing check. Wave 1 reporters (large listed companies, FY2024) are unaffected by the revised ESRS. Wave 2 reporters — companies with more than 1,000 employees and more than €450 million net turnover — first report in 2028 for FY2027, and must apply the revised ESRS. Most former Wave 3 SMEs are now out of mandatory CSRD scope entirely under the Omnibus I thresholds.
The five disclosure requirements
Once S3 is material, the standard requires five categories of disclosure. The revised ESRS has streamlined the datapoints, but the logical architecture - policies, engagement, grievances, actions, targets - remains intact.
S3-1 - Policies related to affected communities
The company must describe its policies for managing material impacts, risks, and opportunities related to affected communities. This includes stating whether policies cover specific communities (for example, a community of Indigenous Peoples near a particular site) or all affected communities as a class.
Critically, S3-1 requires the company to describe its human rights policy commitments relevant to affected communities - including processes and mechanisms to monitor compliance with the UN Guiding Principles on Business and Human Rights (UNGPs), the ILO Declaration on Fundamental Principles and Rights at Work, and the OECD Guidelines for Multinational Enterprises.
Where Indigenous Peoples are among the affected communities, the company must disclose any particular policy provisions for preventing and addressing impacts on them - including the process to obtain free, prior and informed consent (FPIC).
S3-2 - Processes for engaging with affected communities
This disclosure covers the company's general approach to engagement: who is engaged, at what stage of the due diligence process, how often, and through what mechanisms. The standard asks companies to disclose the due diligence stage at which engagement occurs - whether in early planning, impact assessment, action, or effectiveness evaluation - and whether engagement is regular or project-specific.
Where affected communities are Indigenous Peoples, the company must also disclose how it takes into account and ensures respect for their right to free, prior and informed consent with regard to: (i) their cultural, intellectual, religious and spiritual property; (ii) activities affecting their lands and territories; and (iii) legislative or administrative measures that affect them. It must also disclose whether Indigenous Peoples have been consulted on the mode and parameters of engagement itself - including the agenda, nature, and timing.
S3-3 - Channels to raise concerns and remediation
S3-3 requires the company to describe the channels available to affected communities to bring concerns or needs directly to its attention and have them addressed. This is the grievance mechanism disclosure - and it is one of the most operationally demanding requirements in the standard.
The disclosure should cover:
- What channels exist (hotlines, community liaison officers, online portals, third-party mechanisms)
- Whether those channels are accessible to communities who may have limited literacy, internet access, or language capability
- How the company tracks and responds to concerns raised
- What remediation processes are in place when negative impacts are confirmed
The revised ESRS simplifies this disclosure for companies without formal programmes, but the underlying obligation - to have accessible, functioning channels - remains.
S3-4 - Taking action on material impacts and effectiveness
The company must disclose how it addresses material impacts on affected communities and manages related risks and opportunities. The objective is to describe actions taken to prevent, mitigate, and remediate negative impacts, and to achieve positive impacts where possible.
Required disclosures include: actions taken, planned, or underway (including remedy); initiatives to deliver positive impacts; and methods for tracking effectiveness. Where negative impacts affecting communities are linked to entities or operations outside the company's direct control, the company may also disclose whether and how it uses leverage in its business relationships - including commercial leverage - to manage those impacts.
S3-5 - Targets related to affected communities
Where the company has set targets related to affected communities, it must disclose them. Targets should be specific enough to track progress - for example, a commitment to employ a defined percentage of community members at a local site by a given year, or to resolve a defined proportion of community grievances within a set timeframe. The standard allows for short-, medium-, and long-term targets covering the same policy commitment.
The CSDDD link: parallel obligations, not duplicates
ESRS S3 and the Corporate Sustainability Due Diligence Directive (CSDDD, also written CS3D) are closely related but legally distinct. Understanding the relationship prevents both under-preparation and double-counting of effort.
What the CSDDD requires
The CSDDD obliges large companies to identify, prevent, mitigate, and account for adverse human rights and environmental impacts in their own operations, subsidiaries, and chains of activities. It entered into force in July 2024 and was substantially amended by the Omnibus I Directive (EU) 2026/470, which was published in the Official Journal on 26 February 2026 and entered into force on 18 March 2026.
After the Omnibus I amendments, the CSDDD applies to EU companies with more than 5,000 employees and over €1.5 billion net worldwide turnover, and to non-EU companies generating more than €1.5 billion net turnover within the EU - with phased application for smaller thresholds. The core due diligence obligation - risk-based human rights and environmental due diligence - was not removed by Omnibus I, even as scope thresholds were raised significantly.
Member States must transpose the amended CSDDD into national law by 26 July 2028, with due diligence obligations applying to in-scope companies from 26 July 2029.
How S3 and CSDDD reinforce each other
The two frameworks are designed to be complementary:
| Dimension | ESRS S3 | CSDDD |
|---|---|---|
| Legal instrument | Reporting standard (CSRD) | Due diligence directive |
| Primary obligation | Disclose impacts, policies, processes, actions, targets | Identify, prevent, mitigate, and remedy adverse impacts |
| Scope | All CSRD-in-scope companies where S3 is material | Companies above CSDDD thresholds |
| Community focus | Explicit - dedicated standard | Implicit - part of broader human rights scope |
| Grievance mechanisms | Disclosure of channels (S3-3) | Operational requirement to establish and maintain mechanisms |
| FPIC | Disclosure of approach (S3-2) | Operational requirement where applicable |
In practice, the due diligence work done to meet CSDDD obligations - stakeholder mapping, impact identification, grievance mechanism operation - generates much of the evidence needed for S3 disclosures. The S3 disclosure, in turn, provides the external accountability layer that makes CSDDD compliance visible to investors and other stakeholders.
The key distinction: CSDDD requires companies to act; ESRS S3 requires companies to report on how they act. A company that has robust CSDDD processes but poor S3 disclosures will fail on transparency. A company with polished S3 disclosures but no underlying due diligence processes will fail on substance - and, once CSDDD applies, on legality.
Practical get-ready checklist
Whether you are a Wave 1 reporter refining your S3 disclosures or a Wave 2 reporter building your approach from scratch, the following steps apply.
Identify all operating sites, facilities, and significant supplier locations. For each, assess proximity to residential communities, indigenous territories, protected areas, and conflict-affected regions. This is the foundation of your impact materiality assessment for S3 — and it cannot be done from a spreadsheet alone. Site-level data is essential.
Using the three S3 sub-topics as a lens — economic/social/cultural rights, civil and political rights, Indigenous Peoples' rights — identify where your operations or value chain create the most severe potential impacts. Severity is assessed by scale, scope, and irremediability. Prioritise the most salient risks for deeper assessment and action.
Document how your company currently engages with affected communities: who leads it, at what project stages, through what channels, and with what frequency. Identify gaps — particularly for communities that may be harder to reach (remote, low-literacy, non-digital). Where Indigenous Peoples are involved, assess whether your engagement approach meets FPIC requirements.
Review whether existing channels (hotlines, community liaison roles, online portals) are genuinely accessible to affected communities — not just to employees. Check whether concerns raised are tracked, responded to within a defined timeframe, and escalated appropriately. Document the number and nature of concerns received and how they were resolved.
If your company is in CSDDD scope (or preparing for it), map your due diligence process steps to the S3 disclosure requirements. The impact identification work feeds S3-1 and S3-4; the stakeholder engagement process feeds S3-2; the grievance mechanism feeds S3-3. Avoid building parallel processes — one integrated workflow should serve both obligations.
S3-4 and S3-5 require evidence of effectiveness — which means you need a system of record. Log community engagements (date, community, topic, outcome), grievances received (date, nature, status, resolution), and actions taken. This data underpins both your S3 disclosures and your CSDDD due diligence documentation.
Frequently asked questions
Does every CSRD reporter need to complete S3 disclosures?
No. ESRS S3 is a topical standard — it only applies if your double materiality assessment concludes that affected communities are a material topic for your company. If the DMA finds S3 non-material, you are not required to report under it, but you should document your reasoning clearly, as auditors and investors will scrutinise that conclusion.
What is the difference between S3 and S2 when it comes to supply chain communities?
S2 covers workers in the value chain — people in a labour relationship with a supplier or other business partner. S3 covers communities affected by those same supply chain activities — people who live near a supplier's factory, downstream from its effluent, or on land that a supplier has acquired. The same supply chain operation can trigger both S2 (for the workers) and S3 (for the surrounding community).
What does free, prior and informed consent (FPIC) actually require in practice?
FPIC is a right of Indigenous Peoples, recognised in the UN Declaration on the Rights of Indigenous Peoples and ILO Convention 169. In the S3 context, it means that before a company takes actions affecting indigenous lands, territories, resources, or cultural property, it must seek consent through a process that is: free (no coercion or manipulation), prior (before the activity begins, not after), and informed (based on full disclosure of the nature, scope, and impacts of the proposed activity). FPIC is not simply consultation — it requires genuine consent, which can be withheld.
How does the revised ESRS (adopted July 2026) change S3 specifically?
The revised ESRS, adopted on 3 July 2026 and applying from FY2027, simplifies S3 by making many datapoints conditional on the DMA outcome rather than mandatory. The number of mandatory datapoints across all ESRS has been cut by more than 60%. For S3, this means companies without material community impacts face a lighter disclosure burden. However, the core structure — policies, engagement, grievances, actions, targets — and the FPIC requirements for Indigenous Peoples remain substantively intact.
My company is not in CSDDD scope. Does S3 still apply?
Yes, if your company is in CSRD scope and S3 is material, you must report under S3 regardless of CSDDD scope. The CSDDD and CSRD are separate legal instruments with different thresholds. After the Omnibus I amendments, the CSDDD applies to companies with more than 5,000 employees and €1.5 billion turnover, while the CSRD (Wave 2) applies to companies with more than 1,000 employees and €450 million turnover. Many CSRD reporters will be in S3 scope without being in CSDDD scope.
What is the most common gap companies find when preparing for S3?
The most common gap is the absence of a structured system for tracking community engagement and grievances. Companies often have informal processes — a community liaison officer who keeps notes, a local manager who handles complaints — but no centralised log that can generate the evidence needed for S3-3, S3-4, and S3-5 disclosures. Building that system of record early is the single most impactful preparation step.
The bottom line
ESRS S3 is not a box-ticking exercise for companies with a physical footprint. It is a structured framework for understanding and disclosing how your operations and value chain affect the people who live alongside them - and for demonstrating that you have the policies, engagement processes, and grievance channels to manage those impacts responsibly.
The revised ESRS, adopted in July 2026, has reduced the datapoint burden. But it has not reduced the underlying expectation: that companies with material community impacts will have genuine, documented, and effective approaches to managing them. The CSDDD, for those in scope, adds a legal obligation to act - not just to report.
The most practical starting point is not the disclosure template. It is the community engagement log and the grievance register. If those are structured, current, and complete, the S3 disclosures largely write themselves.
Related reading

ESRS E3 Explained: A Practitioner's Guide to Water and Marine Resources Reporting
A plain-English guide to ESRS E3 - what it covers, how double materiality screens it in, the five disclosure requirements, and how to get your data ready for FY2027.

ESRS E2 Pollution: A Practitioner's Guide to Disclosure Under the Revised CSRD
A plain-English guide to ESRS E2 Pollution: what it covers, how double materiality determines whether it applies, every disclosure requirement explained, and a practical data-readiness checklist.

CSDDD After Omnibus I: A Plain-English Guide for Legal, Compliance and Sustainability Teams (2026)
The Corporate Sustainability Due Diligence Directive (CSDDD/CS3D) was substantially amended by Omnibus I in February 2026. Here is what in-scope companies need to know now.