ESG compliance
Policy and practice diverge, evidence is scattered and obligations have no fixed owner. This page shows how the tool organises that, from first input to board report, and what is asked of you at each step. Anyone who first wants to know exactly what the tool is can read that on what it is; anyone who wants to see what a report delivers can find that on outcomes.
The first step is read-first: nothing is calculated, things are recorded. You supply the basic data the scan needs: sector, size, legal form, products and the countries in which the company is active, including any subsidiaries or branches. This can be done in one go, but the fields can also be split up: someone from legal fills in the legal form and the list of countries, someone from procurement or operations the product data. No fixed order is needed, but a fixed storage place is: everything comes together in one profile that forms the basis for the next step.
The time this takes lies mainly in bringing together data that is currently scattered here and there: a chamber of commerce extract, a product list, an overview of countries of activity. Filling it in itself is quick; gathering the right documents can take longer, depending on how fragmented that information is within the organisation.
The company profile is checked against the reglia obligations matrix: CSRD/VSME, CSDDD, EUDR, PPWR, CBAM, sector-specific rules and the national add-ons per country. The scan shows which obligations apply based on the data supplied, and which national additions apply on top of that. This is machine work: the profile is compared against a dataset, not interpreted by an advisor. That is also why the outcome remains explainable: every outcome can be traced back to a rule in the matrix and a field in the profile, not to an estimate that is otherwise unrecorded.
The turnaround time of this step lies in the processing itself, which is fast, and in the check afterwards: verifying that the identified obligations match what has actually been stated in terms of activities and countries.
For each obligation that comes out of the scan, an inquiry follows: what is stated on paper (policy) and what happens in practice, and with which document can that be substantiated. This step is particularly well suited to being divided among multiple people: the owner of an obligation within the organisation supplies the evidence for that specific part, without that person needing to oversee the entire process. Documents end up in a vault with a recorded trail from report line to source to piece of evidence, so that it can later be reconstructed what a conclusion is based on.
This step usually takes the most time, because evidence is often spread across departments and systems that are not used to sharing with each other. Exactly how much time that is depends on how many obligations come out of the scan and how complete the documentation already is.
The outcomes of the gap inquiry are combined into a control matrix: per obligation an owner, a control, a frequency and a record. Gaps are placed in a remediation roadmap, ordered by risk, aligned with the risk structure that is already in place. All of this results in a one-page board report: compliant, gap or risk per obligation, weighted by likelihood and impact, with the opportunity side named factually alongside the risk side, such as better supplier information or lower costs.
The report is intended to be discussed in a board meeting, not to be skimmed through: one page, with the matrix and the roadmap as underlying documents for anyone who wants to look further.
A one-off scan shows a status at a given moment. A repeat run shows difference: which gaps have been closed, which new obligations have been added because legislation has changed or business activities have shifted. The horizon scanner subscription signals changes in between: what is changing, who it affects and what needs to happen as a result, so that the next scan contains no surprises that could already have been known in the meantime.
The tool does not build its own obligations register; it runs on the reglia obligations matrix and the reglia module datasets. There are no completed engagements to point to: the tool structures what exists, it does not prove a track record. And the button is currently in waitlist mode; there is not yet an active Compliance Check to start with.
Anyone who wants to carry out the process themselves uses the register, control matrix and roadmap together with the evidence vault and a quarterly board report. Anyone who wants to work in a partly guided way can have a partner provide support with the policy-versus-practice investigation and board training. Anyone who wants to outsource the whole thing places the entire compliance process with a partner, with this check as the baseline measurement. More background on the underlying regulations can be found in the knowledge base.
Whichever route is chosen, the gaps and the roadmap are ultimately work: tasks someone has to do, hours that have to come from somewhere, systems that have to record them. Anyone who wants to translate that into capacity and deployment will find a starting point for that in the work scan from [FTE to AI](https://ftetoai.com).
Vraag maar welke verplichting op u van toepassing is, en waaraan u dat kunt aantonen.
Answers come from this site’s knowledge base. Not tailored advice, and not a scan of your company.