No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • Home
  • About
    • About CCI
    • CCI Magazine
    • Writing for CCI
    • Career Connection
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Library
    • Download Whitepapers & Reports
    • Download eBooks
    • New: Living Your Best Compliance Life by Mary Shirley
    • New: Ethics and Compliance for Humans by Adam Balfour
    • 2021: Raise Your Game, Not Your Voice by Lentini-Walker & Tschida
    • CCI Press & Compliance Bookshelf
  • Podcasts
    • Great Women in Compliance
    • Unless: The Podcast (Hemma Lomax)
  • Research
  • Webinars
  • Events
  • Subscribe
Jump to a Section
  • At the Office
    • Ethics
    • HR Compliance
    • Leadership & Career
    • Well-Being at Work
  • Compliance & Risk
    • Compliance
    • FCPA
    • Fraud
    • Risk
  • Finserv & Audit
    • Financial Services
    • Internal Audit
  • Governance
    • ESG
    • Getting Governance Right
  • Infosec
    • Cybersecurity
    • Data Privacy
  • Opinion
    • Adam Balfour
    • Jim DeLoach
    • Mary Shirley
    • Yan Tougas
No Result
View All Result
Corporate Compliance Insights
Home Compliance

New Challenge for US Compliance and Risk Leaders: Aligning With EU Sustainability Directive

CSRD requirements will take many American companies where they’ve never been before

by Lukas Tunikaitis
September 12, 2023
in Compliance, Governance
flags lined up outside eu commission

Despite the flurry of real and rhetorical backlash against ESG reporting in the United States, many U.S. companies will not be able to escape stringent sustainability reporting requirements emanating from the EU. And the time to gear up for compliance is short, writes Lukas Tunikaitis, sustainability consultant in UL Solutions’ ESG advisory and assurance practice.

The need to comply with robust, complex ESG reporting requirements is no longer simply a concept or something on the horizon for a significant segment of U.S. companies. Non-EU based firms with EU operations or a listing on an EU stock exchange will be affected by the EU’s Corporate Sustainability Reporting Directive (CSRD). For many of these companies, whether public or private, the requirements will be prodigious, demanding significant changes in process, oversight, measurement and systems — not to mention mindset and operational strategy.

Companies in the EU, especially larger ones, mostly are better positioned to be in compliance. CSRD requirements were built on existing ESG practices in the EU, which are generally more stringent than those in the U.S. Since EU-based companies will need to report 2024 CSRD data in 2025, most firms are already operating in line with the requirements or have taken key steps to get there in anticipation of 2025.

Compliance and risk officers and corporate boards at U.S. companies with EU operations and/or stock exchange listings should recognize that they cannot put CSRD directives on the back burner. CSRD will likely affect all of them, and the proverbial clock is ticking.

The directive amounts to a continuum of new responsibilities for non-EU companies, and risk and compliance teams should be evaluating whether their organizations are appropriately set up from an operational, financial, human resources, governance and strategic standpoint. In fact, compliance teams would be well-served to start asking the tough questions of teams throughout the company and doing the due diligence right now.

The CSRD landscape for U.S. companies

Many U.S. companies will have to begin reporting 2028 CSRD data in 2029. These are non-EU companies with overall revenue of more than 150 million euros and a large EU-based subsidiary, a subsidiary listed in an EU-regulated market and/or an EU-based branch with at least 40 million euros in revenue.

But the timeframe is even tighter for many other companies based outside the EU. Some will need to report 2024 CSRD data in 2025 — these are companies already subject to previous EU Non-Financial Reporting Directive (NFRD) regulations, have EU-listed securities and have more than 500 employees. Firms with between 250 and 500 employees, revenue over 40 million euros or a balance sheet over 20 million euros (satisfying any two out of three conditions) will need to report 2025 CSRD data in 2026. 

The runway is also short for many small- to medium-sized enterprises (SMEs) as well. Those with EU-listed securities and consolidated revenue between 8 to 40 million euros, a balance sheet of 4 to 20 million euros and between 50 and 250 employees (satisfying any two out of three conditions) will need to report 2026 data in 2027. Companies in this range do have an option to opt-out of the reporting requirements for two years as a part of a transitional period, as long as they state why the information has not been provided. 

While having months or even years ahead of the need to report may seem ample, the reality is that the directive and its requirements are complex and new to many companies in the U.S. Reporting may require strategic shifts, a new level of financial analysis, new kinds of subsidiary-specific analyses, and a new mindset. Detailed research into and work with supply chains may be necessary as well. Any and all of these are time-consuming and may require significant changes.

women working in chinese clothing factory
Compliance

Shattering the Complacency of Western Compliance

by JP Stevenson
September 6, 2023

Conventional wisdom in the West suggests that labor and ethical standards are problems — just not here. But as LRQA’s JP Stevenson explores data that says this simply is not the case.

Read moreDetails

A new level of ESG rigor integrated with financial reporting

In general, U.S. firms are used to reporting qualitative and quantitative ESG and sustainability key performance indicators (KPIs) in a stand-alone sustainability report. CSRD will raise the bar by requiring companies to report sustainability data for EU subsidiaries with the company’s financial data in the corporate annual report. Additionally, these companies will have to state within the annual report how the ESG KPIs are integrated into the company’s governance, strategy, risk management approaches, executive remuneration schemes and financial decision-making processes.

CSRD will likely take many non-EU companies into areas of reporting they haven’t been before. For example, CSRD may require non-EU firms to report on their EU operations’ use of resources, waste and the degree to which the company is advancing resource efficiency and the circular economy. It should be noted that, to date, many U.S. companies have only reported on carbon emissions and plans to reduce them. Other areas they may now need to report on include working conditions and company procedures for ensuring fair remuneration and equal opportunities. These new areas will also need to be reported within the context of financial impact, risk management and business strategy.

Additionally, there’s the company’s, or the EU-based subsidiary’s, value chain. There will be required reporting on suppliers’ sustainability policies and the overall effect the suppliers’ operations have on society and the environment. This may be a particularly challenging dimension of the directive, especially for compliance and risk teams.

Double materiality

An essential part of CSRD for compliance and risk leaders to incorporate is the concept of double materiality. It requires companies to evaluate and report how their operations and decisions impact the resources and people they rely on to keep operations going. Another way to think about double materiality: A company or subsidiary must report on how sustainability issues affect its business (“outside in”) and how the company’s activities impact society and the environment (“inside out”).

Another item that compliance leaders need to oversee is assurance. CSRD data that companies report will have to be externally audited. This means that the data must be high quality, but it also means that time must be built into processes for a CSRD-accepted third party to conduct a review.

Immediate priorities for the compliance function

Compliance and risk executives would be well-served by ensuring that senior management has started in earnest to understand whether its EU-based subsidiaries will be subject to CSRD requirements. Leaders, with compliance’s input, must develop a workable timeline for getting ready for CSRD. The compliance team should also work hand in hand with managers to make sure there is a working group or team of outside experts in place to perform the gap analysis that lays out what the company will need to do (that it isn’t already doing) to align and comply with CSRD. The company may also need to complete gap analyses for several EU-based subsidiaries and the organization overall.

The best guidance that risk and compliance officers can impart to managers is that it will pay off to start right now to construct the most needed programs so that almost all the variables will line up with CSRD when the time comes for the company to report. Now is the time for American companies with operations in the EU to embrace the idea that ESG needs to be at the core of their strategy and risk management approach.


Tags: ESGSupply Chain
Previous Post

Managing Contracts Good First Step Under EU’s New Sustainability Directive

Next Post

AI Has the Power to Revolutionize Fraud Investigations

Lukas Tunikaitis

Lukas Tunikaitis

Lukas Tunikaitis is an ESG and sustainability specialist at UL Solutions. He helps organizations accelerate their transition to a net-zero carbon economy using science-based solutions, while also achieving regulatory compliance. He is passionate about sustainable finance, climate risk management and ESG strategies to drive long-term enterprise value creation.

Related Posts

eu flags brussels

EU’s Regulatory Retreat? The Omnibus Package’s Impact on Sustainability Reporting

by Jon Solorzano, Kelly Rondinelli and Jacob Baltzegar
April 28, 2025

Extended timelines and reduced requirements offer relief as substantial reforms remain under consideration

data abstract green purple

66% of CISOs Worry Cyber Threats Are More Advanced Than Companies’ Defenses

by Staff and Wire Reports
April 25, 2025

US business sector falling behind in adoption of renewable energy

tree cover

Sustainability Belongs Everywhere

by Alekhya Reddy
April 2, 2025

Climate-related compliance extends beyond reporting mandates to address strategic business continuity challenges

supply chain shipping containers

‘You Don’t Want to Be the First Company to Not Comply’: How Trump’s Tariffs Are Shaking Supply Chains

by Cathy Siegner
March 31, 2025

The ripple effects of tariff policies extend far beyond simple cost increases, creating complex compliance challenges that span legal, financial...

Next Post
ai generated robot sherlock holmes

AI Has the Power to Revolutionize Fraud Investigations

No Result
View All Result

Privacy Policy | AI Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Research
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2025 Corporate Compliance Insights

Welcome to CCI. This site uses cookies. Please click OK to accept. Privacy Policy
Cookie settingsACCEPT
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT
No Result
View All Result
  • Home
  • About
    • About CCI
    • CCI Magazine
    • Writing for CCI
    • Career Connection
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Library
    • Download Whitepapers & Reports
    • Download eBooks
    • New: Living Your Best Compliance Life by Mary Shirley
    • New: Ethics and Compliance for Humans by Adam Balfour
    • 2021: Raise Your Game, Not Your Voice by Lentini-Walker & Tschida
    • CCI Press & Compliance Bookshelf
  • Podcasts
    • Great Women in Compliance
    • Unless: The Podcast (Hemma Lomax)
  • Research
  • Webinars
  • Events
  • Subscribe

© 2025 Corporate Compliance Insights