← Back to CSRD Insights
Insights

ESRS S3 Affected Communities: A Practitioner's Guide to Disclosure and Due Diligence

Editorial cover for an ESRS S3 Affected Communities guide. Diagrammatic, typographic corporate-disclosure style in petrol-teal (#0E4D54) and warm amber (#E0A100) on warm off-white (#FAF9F6). Motifs: value-chain and community network nodes, land/water/livelihood icons, engagement and grievance-channel flow, human-rights due-diligence framework. Respectful and abstract - no depictions of specific ethnic groups or identifiable people. Avoid eco-green cliches, leaves, globes-in-hands, and stock office photos.

The EU's sustainability reporting framework has always treated communities as more than a footnote. ESRS S3 - Affected Communities - gives that commitment a precise legal shape: structured disclosure requirements, a clear scope, and an explicit link to human-rights due diligence that runs all the way through to the Corporate Sustainability Due Diligence Directive (CSDDD).

This guide is the third in our series on the CSRD social standards. If you have already read our guides on ESRS S1 Own Workforce and ESRS S2 Workers in the Value Chain, you will find S3 follows the same logical structure - but with a materially different subject matter and some unique obligations, particularly around Indigenous Peoples' rights.


What is ESRS S3 - and how does it differ from S1 and S2?

ESRS S3 is the topical standard covering a company's impacts, risks, and opportunities related to affected communities - those beyond the company's own workforce who may be impacted by its operations, supply chain, or products.

The distinction from S1 and S2 is important and deliberate:

  • S1 (Own Workforce) covers people the company employs or engages directly - employees, contractors, agency workers.
  • S2 (Workers in the Value Chain) covers workers employed by suppliers, customers, and other business partners - people in a labour relationship, just not with the reporting company.
  • S3 (Affected Communities) covers everyone else: the people who live near a mine, downstream from a factory, adjacent to a plantation, or in a region where a company's security arrangements operate. They are not workers. They are neighbours, residents, rights-holders.

This distinction matters for scoping. A company can have no material S1 or S2 issues and still face significant S3 exposure - particularly if it operates in extractive industries, agriculture, infrastructure, or any sector with a large physical footprint.

Who counts as an "affected community"?

The standard is deliberately broad. Affected communities include:

  • Communities living or working around operating sites, factories, or other physical operations - including those affected indirectly, for example by downstream water pollution
  • Communities along the value chain affected by the operations of suppliers or other business partners
  • Communities affected by the transition to a low-carbon economy, where a company's decarbonisation activities (such as mine closures or land-use changes) alter local livelihoods

The three sub-topics of ESRS S3 are: communities' economic, social and cultural rights (including land-related impacts, security-related impacts, adequate housing, food, water and sanitation); communities' civil and political rights (including freedom of expression, freedom of assembly, and impacts on human rights defenders); and the particular rights of Indigenous Peoples (including free, prior and informed consent, self-determination, and cultural rights).


The double materiality gate

Like every topical ESRS standard, S3 is subject to the double materiality assessment (DMA). A company only reports under S3 if the topic is material - either because the company has actual or potential impacts on communities (impact materiality), or because community-related issues create financial risks or opportunities for the business (financial materiality), or both.

When is S3 likely to be material?

The standard does not prescribe a sector list, but the indicators are well understood. Key triggers include:

  • Operations in or near indigenous territories, protected areas, or conflict-affected regions
  • Large-scale land use, extractive operations, or intensive water use
  • Significant supply chain exposure in countries with high community conflict risk
  • Security arrangements - private or public - that could affect community safety
  • Previous grievances, incidents, or litigation involving community impacts

The financial materiality angle is equally concrete. If communities resist a company's presence or object to its local practices, this can create costly delays and affect the ability to secure future land concessions or permits. If a business model relies on intensive water extraction that affects community access to water, the result can be boycotts, complaints, and lawsuits.

The revised ESRS and a more top-down DMA

On 3 July 2026, the European Commission formally adopted the Delegated Act revising the ESRS as part of the Omnibus I simplification package, cutting mandatory datapoints by more than 60% and total datapoints by more than 70% relative to the first-generation standards. The revised ESRS apply from financial year 2027, with voluntary early adoption available for FY2026.

One practical effect for S3: many datapoints that were previously mandatory are now conditional on the DMA outcome. The revised framework also introduces greater flexibility for a top-down DMA approach. However, because impacts on communities and on nature are inherently location-specific, a purely top-down assessment will rarely be sufficient for S3. Proximity of business locations to Indigenous Peoples and local communities requires a bottom-up, site-level lens to fully meet the spirit of the regulation.

star Important

Timing check. Wave 1 reporters (large listed companies, FY2024) are unaffected by the revised ESRS. Wave 2 reporters — companies with more than 1,000 employees and more than €450 million net turnover — first report in 2028 for FY2027, and must apply the revised ESRS. Most former Wave 3 SMEs are now out of mandatory CSRD scope entirely under the Omnibus I thresholds.


The five disclosure requirements

Once S3 is material, the standard requires five categories of disclosure. The revised ESRS has streamlined the datapoints, but the logical architecture - policies, engagement, grievances, actions, targets - remains intact.

S3-1 - Policies related to affected communities

The company must describe its policies for managing material impacts, risks, and opportunities related to affected communities. This includes stating whether policies cover specific communities (for example, a community of Indigenous Peoples near a particular site) or all affected communities as a class.

Critically, S3-1 requires the company to describe its human rights policy commitments relevant to affected communities - including processes and mechanisms to monitor compliance with the UN Guiding Principles on Business and Human Rights (UNGPs), the ILO Declaration on Fundamental Principles and Rights at Work, and the OECD Guidelines for Multinational Enterprises.

Where Indigenous Peoples are among the affected communities, the company must disclose any particular policy provisions for preventing and addressing impacts on them - including the process to obtain free, prior and informed consent (FPIC).

S3-2 - Processes for engaging with affected communities

This disclosure covers the company's general approach to engagement: who is engaged, at what stage of the due diligence process, how often, and through what mechanisms. The standard asks companies to disclose the due diligence stage at which engagement occurs - whether in early planning, impact assessment, action, or effectiveness evaluation - and whether engagement is regular or project-specific.

Where affected communities are Indigenous Peoples, the company must also disclose how it takes into account and ensures respect for their right to free, prior and informed consent with regard to: (i) their cultural, intellectual, religious and spiritual property; (ii) activities affecting their lands and territories; and (iii) legislative or administrative measures that affect them. It must also disclose whether Indigenous Peoples have been consulted on the mode and parameters of engagement itself - including the agenda, nature, and timing.

S3-3 - Channels to raise concerns and remediation

S3-3 requires the company to describe the channels available to affected communities to bring concerns or needs directly to its attention and have them addressed. This is the grievance mechanism disclosure - and it is one of the most operationally demanding requirements in the standard.

The disclosure should cover:

  • What channels exist (hotlines, community liaison officers, online portals, third-party mechanisms)
  • Whether those channels are accessible to communities who may have limited literacy, internet access, or language capability
  • How the company tracks and responds to concerns raised
  • What remediation processes are in place when negative impacts are confirmed

The revised ESRS simplifies this disclosure for companies without formal programmes, but the underlying obligation - to have accessible, functioning channels - remains.

S3-4 - Taking action on material impacts and effectiveness

The company must disclose how it addresses material impacts on affected communities and manages related risks and opportunities. The objective is to describe actions taken to prevent, mitigate, and remediate negative impacts, and to achieve positive impacts where possible.

Required disclosures include: actions taken, planned, or underway (including remedy); initiatives to deliver positive impacts; and methods for tracking effectiveness. Where negative impacts affecting communities are linked to entities or operations outside the company's direct control, the company may also disclose whether and how it uses leverage in its business relationships - including commercial leverage - to manage those impacts.

S3-5 - Targets related to affected communities

Where the company has set targets related to affected communities, it must disclose them. Targets should be specific enough to track progress - for example, a commitment to employ a defined percentage of community members at a local site by a given year, or to resolve a defined proportion of community grievances within a set timeframe. The standard allows for short-, medium-, and long-term targets covering the same policy commitment.


The CSDDD link: parallel obligations, not duplicates

ESRS S3 and the Corporate Sustainability Due Diligence Directive (CSDDD, also written CS3D) are closely related but legally distinct. Understanding the relationship prevents both under-preparation and double-counting of effort.

What the CSDDD requires

The CSDDD obliges large companies to identify, prevent, mitigate, and account for adverse human rights and environmental impacts in their own operations, subsidiaries, and chains of activities. It entered into force in July 2024 and was substantially amended by the Omnibus I Directive (EU) 2026/470, which was published in the Official Journal on 26 February 2026 and entered into force on 18 March 2026.

After the Omnibus I amendments, the CSDDD applies to EU companies with more than 5,000 employees and over €1.5 billion net worldwide turnover, and to non-EU companies generating more than €1.5 billion net turnover within the EU - with phased application for smaller thresholds. The core due diligence obligation - risk-based human rights and environmental due diligence - was not removed by Omnibus I, even as scope thresholds were raised significantly.

Member States must transpose the amended CSDDD into national law by 26 July 2028, with due diligence obligations applying to in-scope companies from 26 July 2029.

How S3 and CSDDD reinforce each other

The two frameworks are designed to be complementary:

Dimension ESRS S3 CSDDD
Legal instrument Reporting standard (CSRD) Due diligence directive
Primary obligation Disclose impacts, policies, processes, actions, targets Identify, prevent, mitigate, and remedy adverse impacts
Scope All CSRD-in-scope companies where S3 is material Companies above CSDDD thresholds
Community focus Explicit - dedicated standard Implicit - part of broader human rights scope
Grievance mechanisms Disclosure of channels (S3-3) Operational requirement to establish and maintain mechanisms
FPIC Disclosure of approach (S3-2) Operational requirement where applicable

In practice, the due diligence work done to meet CSDDD obligations - stakeholder mapping, impact identification, grievance mechanism operation - generates much of the evidence needed for S3 disclosures. The S3 disclosure, in turn, provides the external accountability layer that makes CSDDD compliance visible to investors and other stakeholders.

The key distinction: CSDDD requires companies to act; ESRS S3 requires companies to report on how they act. A company that has robust CSDDD processes but poor S3 disclosures will fail on transparency. A company with polished S3 disclosures but no underlying due diligence processes will fail on substance - and, once CSDDD applies, on legality.


Practical get-ready checklist

Whether you are a Wave 1 reporter refining your S3 disclosures or a Wave 2 reporter building your approach from scratch, the following steps apply.

1
Map your physical footprint and value chain exposure

Identify all operating sites, facilities, and significant supplier locations. For each, assess proximity to residential communities, indigenous territories, protected areas, and conflict-affected regions. This is the foundation of your impact materiality assessment for S3 — and it cannot be done from a spreadsheet alone. Site-level data is essential.

2
Conduct a salient risk identification

Using the three S3 sub-topics as a lens — economic/social/cultural rights, civil and political rights, Indigenous Peoples' rights — identify where your operations or value chain create the most severe potential impacts. Severity is assessed by scale, scope, and irremediability. Prioritise the most salient risks for deeper assessment and action.

3
Audit existing community engagement processes

Document how your company currently engages with affected communities: who leads it, at what project stages, through what channels, and with what frequency. Identify gaps — particularly for communities that may be harder to reach (remote, low-literacy, non-digital). Where Indigenous Peoples are involved, assess whether your engagement approach meets FPIC requirements.

4
Assess your grievance mechanisms

Review whether existing channels (hotlines, community liaison roles, online portals) are genuinely accessible to affected communities — not just to employees. Check whether concerns raised are tracked, responded to within a defined timeframe, and escalated appropriately. Document the number and nature of concerns received and how they were resolved.

5
Align S3 disclosures with CSDDD due diligence

If your company is in CSDDD scope (or preparing for it), map your due diligence process steps to the S3 disclosure requirements. The impact identification work feeds S3-1 and S3-4; the stakeholder engagement process feeds S3-2; the grievance mechanism feeds S3-3. Avoid building parallel processes — one integrated workflow should serve both obligations.

6
Set up structured tracking for community engagement and grievances

S3-4 and S3-5 require evidence of effectiveness — which means you need a system of record. Log community engagements (date, community, topic, outcome), grievances received (date, nature, status, resolution), and actions taken. This data underpins both your S3 disclosures and your CSDDD due diligence documentation.


Frequently asked questions

help_outlineDoes every CSRD reporter need to complete S3 disclosures?expand_more

No. ESRS S3 is a topical standard — it only applies if your double materiality assessment concludes that affected communities are a material topic for your company. If the DMA finds S3 non-material, you are not required to report under it, but you should document your reasoning clearly, as auditors and investors will scrutinise that conclusion.

help_outlineWhat is the difference between S3 and S2 when it comes to supply chain communities?expand_more

S2 covers workers in the value chain — people in a labour relationship with a supplier or other business partner. S3 covers communities affected by those same supply chain activities — people who live near a supplier's factory, downstream from its effluent, or on land that a supplier has acquired. The same supply chain operation can trigger both S2 (for the workers) and S3 (for the surrounding community).

help_outlineWhat does free, prior and informed consent (FPIC) actually require in practice?expand_more

FPIC is a right of Indigenous Peoples, recognised in the UN Declaration on the Rights of Indigenous Peoples and ILO Convention 169. In the S3 context, it means that before a company takes actions affecting indigenous lands, territories, resources, or cultural property, it must seek consent through a process that is: free (no coercion or manipulation), prior (before the activity begins, not after), and informed (based on full disclosure of the nature, scope, and impacts of the proposed activity). FPIC is not simply consultation — it requires genuine consent, which can be withheld.

help_outlineHow does the revised ESRS (adopted July 2026) change S3 specifically?expand_more

The revised ESRS, adopted on 3 July 2026 and applying from FY2027, simplifies S3 by making many datapoints conditional on the DMA outcome rather than mandatory. The number of mandatory datapoints across all ESRS has been cut by more than 60%. For S3, this means companies without material community impacts face a lighter disclosure burden. However, the core structure — policies, engagement, grievances, actions, targets — and the FPIC requirements for Indigenous Peoples remain substantively intact.

help_outlineMy company is not in CSDDD scope. Does S3 still apply?expand_more

Yes, if your company is in CSRD scope and S3 is material, you must report under S3 regardless of CSDDD scope. The CSDDD and CSRD are separate legal instruments with different thresholds. After the Omnibus I amendments, the CSDDD applies to companies with more than 5,000 employees and €1.5 billion turnover, while the CSRD (Wave 2) applies to companies with more than 1,000 employees and €450 million turnover. Many CSRD reporters will be in S3 scope without being in CSDDD scope.

help_outlineWhat is the most common gap companies find when preparing for S3?expand_more

The most common gap is the absence of a structured system for tracking community engagement and grievances. Companies often have informal processes — a community liaison officer who keeps notes, a local manager who handles complaints — but no centralised log that can generate the evidence needed for S3-3, S3-4, and S3-5 disclosures. Building that system of record early is the single most impactful preparation step.


The bottom line

ESRS S3 is not a box-ticking exercise for companies with a physical footprint. It is a structured framework for understanding and disclosing how your operations and value chain affect the people who live alongside them - and for demonstrating that you have the policies, engagement processes, and grievance channels to manage those impacts responsibly.

The revised ESRS, adopted in July 2026, has reduced the datapoint burden. But it has not reduced the underlying expectation: that companies with material community impacts will have genuine, documented, and effective approaches to managing them. The CSDDD, for those in scope, adds a legal obligation to act - not just to report.

The most practical starting point is not the disclosure template. It is the community engagement log and the grievance register. If those are structured, current, and complete, the S3 disclosures largely write themselves.