77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide
ESG and SRI: Difference, reporting obligations and the ESG officer
ESG & Sustainability

ESG and SRI: Difference, reporting obligations and the ESG officer

17 July 202612 min readBy Dr. Henrik Bauer
CIVAC

ESG and SRI are often confused, but are different concepts. We explain the definitions, the CSRD obligations according to Directive 2022/2464, the role of the ESG officer and the ordering process via the CIVAC Compliance platform and Officer-as-a-Service.

The CSRD Directive 2022/2464 expands the circle of reporting companies in the EU to around 50,000 companies by 2028, compared to around 11,700 under the previous NFRD. The reporting requirement is in accordance with the European Sustainability Reporting Standards (ESRS), which form the basis for Delegated Regulation 2023/2772. Anyone who talks about ESG and SRI today is moving in a regulated, mandatory landscape, no longer in a voluntary marketing tool. Nevertheless, the two terms are regularly used interchangeably in boards of directors, investor meetings and specifications, with unpleasant consequences for reporting consistency and greenwashing risks according to Article 5 of the EU Taxonomy Regulation 2020/852. The supervisory authorities ESMA, BaFin and the Federal Cartel Office have noticeably increased the depth of their examinations in the last two years.

This article clearly separates the two concepts, explains the essential ESG reporting requirements, describes the role of the ESG or sustainability officer and shows how the function can be ordered via the CIVAC Compliance platform and Officer-as-a-Service in two working days. You will receive specific paragraphs, the distinction between reporting obligations and investment strategy, an overview of the documents required in the audit, and an ordering process with a clear SLA. Audit-proof, documented, ESRS-proof, with version status and person responsible for each reporting module, so that the obligations are not only fulfilled on the reporting date, but during ongoing operations.

Key Takeaways

  • ESG is an assessment framework for corporate sustainability, SRI is an investment strategy. Both are related, but are legally regulated differently.
  • The CSRD Directive 2022/2464 requires around 50,000 EU companies to report according to the ESRS by 2028.
  • The ESG officer function is ordered via the CIVAC compliance platform and Officer-as-a-Service in 2 working days and is supported by 37 audit templates.

ESG and SRI: Definitions and their legal anchoring

ESG stands for Environment, Social, Governance and describes an evaluation framework that makes non-financial company performance visible. ESG is now anchored in EU law through several legal acts: the CSRD Directive 2022/2464, the Taxonomy Regulation 2020/852, the SFDR Regulation 2019/2088 for financial market participants and the EU Supply Chain Directive 2024/1760. Operational reporting follows the ESRS, which are structured by sector and topic, from ESRS E1 Climate Change to ESRS G1 Business Conduct. Nationally, the system is supplemented by the German CSRD Implementation Act and the adjustments to the HGB, in particular § 289b to § 289e HGB.

SRI stands for Socially Responsible Investment and describes an investment strategy in which investors incorporate ESG criteria into the selection of their securities. SRI is therefore a consequence, not the obligation itself. SRI is regulated in particular by the SFDR Regulation 2019/2088 and the supplementary RTS Regulation 2022/1288, which specify disclosure obligations for financial products in accordance with Articles 6, 8 and 9 SFDR. According to Article 9 SFDR, a fund that advertises itself as sustainable must pursue a specific sustainability goal, disclose the methodology and measure the impact using defined key figures.

The confusion between ESG and SRI has real consequences. Anyone who shows SRI results in an investor presentation without substantiating the underlying ESG data according to ESRS risks accusations of greenwashing under Article 5 of the Taxonomy Regulation. The CIVAC Compliance Platform and Officer-as-a-Service separates the two data layers in the workspace and ensures that reporting data and investment communications are based on the same source. The ESG officer is responsible for both strands in a uniform reporting line to the management, with a documented version status for each data point and a clearly regulated release before any external communication. This clean separation is also essential for investor discussions because institutional investors are increasingly actively questioning the origin of data.

CSRD obligations: Who has to report and when

The CSRD Directive 2022/2464 came into force on January 5, 2023 and will be applied gradually. The first reporting obligation applies to the 2024 financial year for companies that were already subject to the NFRD, i.e. large capital market-oriented companies with more than 500 employees. From the 2025 financial year, all large companies that meet two of the three criteria will be recorded: more than 250 employees, more than 50 million euros in net sales, more than 25 million euros in total assets. From 2026, the obligation also applies to listed SMEs with the exception of micro-enterprises, with an opt-out option until 2028.

The German implementation takes place via the CSRD Implementation Act, which integrates the regulations into the HGB. In terms of content, the report follows the ESRS standards, which are organised into two pillars: cross-sectional standards (ESRS 1 and 2) and topic-specific standards for environmental (E1 to E5), social (S1 to S4) and governance (G1). Dual materiality is a central principle: a topic is reportable if it is either financially material or the company has a significant impact on people and the environment. Both perspectives must be documented with justification.

In practice, this means a risk and materiality analysis that is updated annually, as well as the collection of quantitative and qualitative data points. The ESRS includes over 1,100 data points, not all of which are relevant to every company. The ESG officer coordinates the data collection, documents the materiality analysis and ensures that the report is ready for an audit, because the report is audited by the auditor with limited assurance in accordance with Section 322 of the German Commercial Code (HGB). The FAQ page answers typical detailed questions about threshold values, consolidation groups and transitional regulations that are particularly prone to conflict in the first reporting period.

SRI strategies and SFDR: what financial market participants must disclose

The SFDR Regulation 2019/2088 obliges financial market participants such as fund companies, asset managers and insurers to make the sustainability features of their products transparent. The regulation distinguishes between three product categories. Art. 6 SFDR applies to products that are not related to sustainability but must disclose risks. Art. 8 SFDR covers products that promote ecological or social characteristics. Art. 9 SFDR concerns products with a specific sustainability goal, such as climate neutrality, social impact or nature conservation. The classification must be consistent with the product structure and the actual investment policy.

The operational implementation is carried out via the RTS Regulation 2022/1288, which requires standardised templates for pre-contractual information, regular reports and website disclosures. SRI strategies typically rely on best-in-class selection, exclusion lists, ESG integration or thematic investing in areas such as renewable energy. Anyone who offers an SRI product must document the methodology, disclose data sources and report on the effect of the product compared to a comparison group. So-called Principal Adverse Impacts (PAI) must also be disclosed at entity level using defined indicators.

The connection with ESG is close: SRI strategies are based on ESG data, which increasingly comes from the CSRD reports of the invested companies. Medium-sized companies that want to be held in the portfolios of institutional investors must provide CSRD-compliant data, even if they are not required to report themselves. Others run compliance like a filing cabinet. We run it like software. The CIVAC Compliance Platform supports data delivery via structured templates that are ESRS-compliant and can be adapted to the requirements of institutional investors. This makes the ESG function a prerequisite for capital market access, not just a mandatory reporting exercise. A consistent interface between reporting data and sales materials is proven to reduce regulatory risks. Anyone who integrates the requirements early into product development avoids costly improvements during sales release.

ESRS at a glance: the twelve standards and their data points

The European Sustainability Reporting Standards (ESRS) were established as a binding reporting basis in Delegated Regulation 2023/2772. They include two cross-sectional standards (ESRS 1 General Requirements, ESRS 2 General Information) and ten topic-specific standards. The environmental standards range from ESRS E1 Climate Change to ESRS E2 Pollution, ESRS E3 Water and Marine Resources, ESRS E4 Biodiversity to ESRS E5 Circular Economy. The social standards include ESRS S1 Own Workforce, ESRS S2 Value Chain Workers, ESRS S3 Affected Communities and ESRS S4 Consumers and End Users. There is also ESRS G1 Business Conduct, which covers topics such as corruption, lobbying and payment practices.

The complexity lies in the granularity. In total, over 1,100 data points are defined, many of which are conditional: they only need to be reported if the topic was identified as material in the materiality analysis. Climate change according to ESRS E1 is actually relevant for almost all companies because Scope 1, Scope 2 and Scope 3 emissions as well as transition plans are usually essential. ESRS S1 records diversity, compensation, collective bargaining agreements, work accidents and training hours in a depth that HR systems often do not yet reflect.

The ESRS data collection is mapped in the CIVAC Workspace via structured entry forms, automated validation rules and a central database, with EU data residency and ISO/IEC 27001:2022 ISMS in the background. Data points are labelled with source, collection date and responsible person. The auditor calls, the evidence is ready. Anyone who clearly documents materiality analysis and data point collection noticeably reduces the auditor's audit effort because samples and plausibility checks are prepared with clear source documentation and correction loops are eliminated. This means that the function gains speed in subsequent periods, and the reporting process turns from a special project into a calendar-planned routine.

EU taxonomy and greenwashing risks

The EU Taxonomy Regulation 2020/852 is the classification system for environmentally sustainable economic activities. It defines six environmental goals and determines the conditions under which an economic activity is considered to be taxonomy-compliant. Companies required to report must report the proportion of their revenue, capital expenditures and operating expenses that are taxonomy-ready and taxonomy-compliant. Delegated Regulations 2021/2139 and 2023/2486 specify the technical assessment criteria for individual economic activities, from electricity generation to building construction to data centres and industrial processes.

Greenwashing risks arise when companies or financial products make sustainability statements that are not based on verifiable data or do not meet the taxonomy requirements. Article 5 of the Taxonomy Regulation prohibits misleading sustainability communication, and the ESMA supervisory authority has made it clear in several statements that marketing material also falls under the obligation. Violations can lead to injunctive relief and claims for damages under the UWG, and to ad hoc obligations and market manipulation under capital market law under MAR Regulation 596/2014. Competitors also have the right to sue and are increasingly using this method.

The operational defence against greenwashing allegations is the clean data chain: sources, calculation methods, assumptions, validations and approvals must be completely documented. The appointment certificate, signed, filed, verifiable. This applies not only to the appointment of the ESG officer, but also to each individual data point in the report. CIVAC Workspace captures data points with an audit trail, including change log and release round. Anyone who looks through the role overview on civac.de will find the interfaces between ESG officer, compliance officer and LkSG officer shown, which are typically the first points of contact for greenwashing issues and require a common escalation procedure. A documented escalation chain between ESG, compliance and law is the key defence against regulatory authorities and competitors. Obligations to provide clarification also apply in the current year, not just on the reporting date, so ongoing monitoring makes sense.

The ESG officer: tasks, reporting line, profile

The ESG or sustainability officer has no express legal obligation to appoint, but in fact arises from the CSRD reporting obligation and the internal organisational obligation of the management according to Section 91 Paragraph 2 AktG and Section 130 OWiG. The tasks are divided into six areas: materiality analysis, data management, report creation, stakeholder communication, audit support and strategy development. Each area is supported with frequencies and deadlines, such as the annual double materiality analysis or the quarterly data collection for KPIs.

The reporting line goes directly to the CFO or the Board of Directors because ESG data is increasingly embedded in financial reporting and the management report in accordance with Section 289b HGB contains sustainability reporting. An intermediate line via communication or marketing is not audit-proof because it dilutes operational data sovereignty. The ESG officer works closely with controlling, human resources and purchasing because this is where the majority of ESRS data points are created. He is also responsible for investor dialogue and communication with rating agencies such as MSCI, ISS ESG or Sustainalytics.

The profile is hybrid: sustainability qualifications, knowledge of accounting and project management skills. Pure sustainability training without reference to financial reporting falls short because the CSRD obligation is expressly part of the management report. The ESG officer can be licensed internally or appointed externally via the CIVAC Compliance platform and Officer-as-a-Service. Licence the workspace for your internal representatives or have our representatives order it. The SLA is 2 business days, classic orders take 2 to 6 weeks. This means that the function can still be used in the current financial year. A clearly regulated reporting format with key figures, materiality comments and the status of measures is the prerequisite for reliable management on the board.

Data collection in practice: Clearly record Scope 1, 2 and 3

The greenhouse gas protocol (GHG Protocol) distinguishes between three scopes. Scope 1 includes direct emissions from our own sources, such as vehicle fleets or company heating systems. Scope 2 records indirect emissions from purchased energy, i.e. electricity, district heating or steam. Scope 3 includes all other indirect emissions in the value chain, from upstream logistics through the use phase of sold products to disposal. ESRS E1 requires reporting on all three scopes, supplemented by a transition plan for climate neutrality with interim goals and a catalogue of measures.

Data collection begins with the energy purchase bill, goes through fuel bills and maintenance contracts to supplier questionnaires for Scope 3. The challenge lies in Scope 3: 15 categories, from purchased goods to investments, must be considered individually. For medium-sized companies without sophisticated supply chain data, a categorical materiality assessment that excludes non-essential categories and prioritises essential categories with available data quality makes sense. Double counting between your own reporting and the supply chain must be excluded so that group consumption is not counted twice across two reports.

In the CIVAC Workspace, emission data is stored with emission factors from the Federal Environment Agency (UBA), DEFRA or IEA; the calculation path is transparent and versioned. The data quality level is documented for each data point, from verified measurements to modelled values ​​with assumptions. This makes it possible to see in the audit which data comes directly from measurements and which comes from models, which makes defending against greenwashing accusations much easier. Deadline begins as soon as we become aware of it. Anyone who discovers data errors after publication must correct them promptly and document the correction transparently with justification and the new calculation status. The platform also supports the annual updating of emission factors to ensure comparability between reporting periods.

Audit and Limited Assurance: what the auditor requires

According to Art. 19a of the CSRD-compliant accounting guidelines, sustainability reporting is checked with limited assurance, initially by the auditor, and in the future by so-called Independent Assurance Service Providers. Limited assurance means a negative conclusion: the auditor confirms that he has not identified any matters that contradict the assumption that the report complies with the ESRS requirements. A later extension to reasonable assurance is planned after 2028, with higher audit requirements and detailed data point checks.

The auditor typically requires three sets of documentation: first, the materiality analysis with methodology and results, second, the data point collection with sources and calculation paths, third, the governance documentation with responsibilities, approvals and reports to management. Weak points are regularly a lack of materiality justifications, inconsistent calculation logic between years and a lack of versioning of assumptions. The auditor calls, the evidence is ready. A lack of connectivity between the management report, consolidated financial statements and ESG report leads to follow-up questions that stretch out the audit mandate.

All 490 audit templates are prepared in the CIVAC Workspace, from the materiality analysis to the data collection protocol to the governance report. The ISO/IEC 27001:2022 ISMS controls in the background ensure the integrity of the data, documented with 93 controls. Data points are versioned, changes are recorded with reasons and who is responsible. In follow-up audits, the effort is noticeably reduced because the previous year's data is not reconstructed, but rather updated from ongoing operations. This turns the audit from a crisis exercise into a routine, and the ESG function gains operational time for strategic issues such as transition plans or supplier development in accordance with the EU Supply Chain Directive. Group consolidations with subsidiaries can also be mapped, with clearly documented consolidation groups and eliminations. The EFRAG Q&A platform and the DPR's FAQ answers supplement practice with binding interpretation instructions for individual questions.

From analysis to order: the route via CIVAC

If you want to clearly separate ESG and SRI, have to fulfil the CSRD reporting requirements and want to serve SRI investors with consistent data, appointing an ESG officer is the operational lever. CIVAC is a compliance platform and officer-as-a-service with two reference models. In the first model, you licence the workspace for your internal ESG officer and use the ESRS data structure, the 490 audit templates and the reporting line to management. In the second model, our representatives assign their function and work in the workspace, which your management can view at any time. Licence the workspace for your internal representatives or have our representatives order it.

The SLA for an order is 2 working days, instead of the classic 2 to 6 weeks. You receive the appointment certificate, reporting line and catalogue of tasks in one process, EU data residency and ISO/IEC 27001:2022 ISMS with 93 controls active. A materiality analysis, an ESRS data point collection plan and an initial report to management are included in the onboarding, so that the function reaches a measurable level and is ready for audit from the first month. An initial interface plan for controlling, human resources and purchasing is also created during onboarding.

If you would like to specifically check whether your company falls under the CSRD, which ESRS standards are essential for you and which reference model is economically suitable, write to info@civac.de or use the contact form on civac.de. You will receive an initial assessment within 24 hours with an indication of materiality, ordering method and cost framework. Turn reading into an assignment. If you wish, you will also receive an overview of the interfaces to the compliance and LkSG officers so that duplication of work can be avoided from the outset. If necessary, an initial webinar with the Board of Directors and CFO can also be scheduled in which the materiality matrix is ​​sharpened together.

FAQ

What is the most important difference between ESG and SRI?

ESG is an environmental, social and governance assessment framework that is subject to mandatory reporting in the EU via the CSRD Directive 2022/2464 and the ESRS standards. SRI is an investment strategy where investors use ESG data for security selection, regulated via SFDR Regulation 2019/2088. ESG is the database, SRI is the investment decision based on it. Both concepts are now closely linked because SRI strategies are increasingly accessing CSRD data.

When does the CSRD reporting requirement apply to my company?

For large companies previously subject to NFRD, the CSRD obligation applies from the 2024 financial year. From the 2025 financial year, large companies will be recorded with two of the three criteria: more than 250 employees, more than 50 million euros in sales or more than 25 million euros in total assets. From 2026, the obligation also applies to listed SMEs with transitional regulations until 2028.

What specific tasks does the ESG officer have?

Six task areas are standard: double materiality analysis, ESRS data management, report creation, stakeholder communication, audit support with the auditor and strategy development including transition plan according to ESRS E1. The reporting line leads directly to the CFO or board of directors, with interfaces to controlling, human resources, purchasing and compliance officers in a common risk and measures register. During onboarding, you will also receive an interface plan for all relevant specialist functions to avoid duplication of work.

How is the CSRD report checked in the first years?

Sustainability reporting is checked with limited assurance, initially by the auditor in accordance with Section 322 of the German Commercial Code (HGB). The auditor confirms that he has not noticed any issues that contradict ESRS conformity. From 2028 onwards, the expansion to reasonable assurance is planned, with significantly increased audit requirements and random detailed examination of data points including the supply chain. Early preparation of the data point collection avoids correction loops in the first year of the exam.

What greenwashing risks exist in ESG communication?

Article 5 of Taxonomy Regulation 2020/852 prohibits misleading sustainability communication. Violations can lead to injunctive relief and claims for damages under UWG, and to ad hoc obligations and market manipulation under capital market law under MAR Regulation 596/2014. The clean data chain with sources, calculation methods, assumptions and approvals is the most important defence against greenwashing accusations from competitors. ESMA supervisory reports are also increasingly systematically tracking greenwashing issues beyond marketing material.

Can the ESG officer be appointed externally?

Yes, external ordering is common, especially for SMEs without their own sustainability department. The order is placed via the CIVAC Compliance platform and Officer-as-a-Service in 2 working days with the appointment certificate, reporting line and catalogue of tasks. Onboarding includes materiality analysis, ESRS data plan, first management report and an interface plan to controlling, human resources and purchasing. This means the function is ready for audit from the first month and delivers documented reports to management.

No obligation

Sounds like a lot of work?

Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.

Turn this into a mandate.

Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.

Related articles