csrdcompliance Put me on the waitlist

Kennisbank

Which ESG rules apply to financial services

A sector hit from two sides

Financial institutions are rarely subject to reporting obligations for their own operations alone. A bank, insurer or asset manager faces obligations regarding its own organisation, and at the same time obligations that arise from its role as financier or investor. That second layer arises because the climate and sustainability impact of deployed capital is attributed to the institution itself, at least in part. Where a manufacturing company reports on its own chain, a financial institution often also has to say something about the chain of its clients and investments. That makes the scope broader than for most other sectors, and this is structurally underestimated during the first inventory.

Which rules come into play, and why this differs per institution

Whether an institution falls under a particular reporting obligation depends on the type of licence, the size of the balance sheet or assets under management, and whether the institution is listed. An insurer has different reference points than an investment firm, and a small regional bank may fall under different thresholds than a large bank. In addition, sector-specific sustainability obligations play a role alongside the general reporting frameworks, with their own definitions of what counts as sustainable and their own indicators for exposure to climate risk. Which combination of rules applies, and from what point in time, depends on the exact qualification of the institution. That qualification also changes when the size of the institution changes, when a merger takes place, or when the legislator adjusts the thresholds. The current classification and the precise deadlines are set out in the legal texts and the accompanying technical standards, not in a fixed table that will still be correct tomorrow.

The national layer comes on top

European frameworks for the financial sector are implemented nationally and sometimes supplemented nationally, with each member state applying its own supervisory approach. An institution active in multiple countries may encounter different interpretations of the same European rule, depending on how the national supervisor handles it. This is the same dynamic visible in the ESG obligations that apply to the energy sector and in the rules that apply to the real estate sector: the European headline is the starting point, the national implementation determines what is actually asked of an institution in practice. For financial institutions, the supervisor adds an extra layer on top of that, with its own expectations about how climate risk is factored into operations.

What this means for the burden of proof

The core of the issue is not only which rules apply, but who within the institution is responsible for which part, what evidence belongs to it, and which control demonstrates that the obligation is complied with structurally and not incidentally. Within a financial institution, that responsibility often runs across multiple departments: risk, compliance, the credit function and the investment function each hold a piece of the puzzle. Without a clear owner per obligation, there is a risk that no one has the overall picture, while a supervisor or auditor specifically wants to see that overall picture. How a board builds up that overall picture and makes it demonstrable is described on the page about how a board demonstrates that it is in control.

Why this often reaches the agenda too late

At financial institutions, sustainability reporting is sometimes treated as an extension of regular financial reporting, while the underlying data comes from entirely different sources: credit portfolios, investment mandates, counterparty data. That data is not always available in the form the reporting requires, and gathering it takes time that is not always planned in advance. The same underestimation of preparation time occurs in other sectors with complex chains, as described on the page about why companies are caught off guard by legislation that had been known for a long time. For financial institutions, the risk is greater, because the chain does not stop at their own suppliers but continues into the portfolios of clients.

The Compliance Check for financial institutions

The Compliance Check maps out which obligations apply to a specific institution, who within the organisation owns each obligation, what evidence is needed, and which control demonstrates that the process is in place. This is not a substitute for legal advice and not a second set of rules alongside the law, but the layer that makes visible whether an institution can demonstrate what it claims to do. The tool is currently being built. Anyone who wants to use it once it becomes available can sign up for the waiting list.

From compliance to the deployment of people

Mapping out obligations, owners, evidence and controls is exactly the type of work that can be broken down into repeatable tasks: gathering data, linking it to regulation, recording who signs off on what. FTE TO AI offers a work scan that calculates per task which part of it can be taken over by AI, so that compliance teams can see where capacity is freed up for the assessment that remains human work.

Alpha 60de assistent van de Compliance Check

Vraag maar welke verplichting op u van toepassing is, en waaraan u dat kunt aantonen.

Answers come from this site’s knowledge base. Not tailored advice, and not a scan of your company.