The ICT sector rarely thinks of itself first when it comes to sustainability rules. Software, hosting, cloud services and IT service provision feel like a sector without a chimney. That image is misleading. The computing power behind data, the chain of equipment and the dependence on energy and rare raw materials mean that ICT companies come into view on multiple fronts at once: as an energy user, as a buyer in a long and often opaque supply chain, and increasingly as a supplier to other sectors that themselves must comply with stricter rules. Anyone working for a major client in the financial sector or construction receives requests for sustainability data passed on through that client, even without the company itself falling directly under those rules.
The question "which ESG rules apply to the ICT sector" has no fixed answer, because no rule has been written specifically for ICT. The obligations that apply follow from a combination of factors: the size of the company, whether it is listed on a stock exchange, the extent to which it works with personal data or critical infrastructure, and its position in the chain of clients that themselves have reporting obligations. A software company with a handful of employees falls under a different regime than a cloud service provider delivering critical services to the financial sector. It is the same lack of clarity that recurs with the question of which ESG rules apply to financial services: the name of the sector does not determine the regime, the characteristics of the company do.
European regulation forms the basis, but the way member states translate that regulation into national law differs. Definitions of size, the scope of reporting obligations and the deadlines within which obligations must be met are filled in differently per country. For an ICT company active in multiple countries, or one that falls under a group report via a parent company in another country, this means that the European rule alone is not sufficient as an answer. The national implementation must always be checked alongside it. That same national gold-plating plays a role in the ESG obligations in the energy sector and in the rules that apply to the real estate sector: in each case the European text is the starting point, never the endpoint.
Topics that often recur are the energy consumption of data centers and computing centers, the origin and lifespan of hardware, working conditions in the equipment supply chain, and the question of whether sustainability data must be supplied to clients that themselves have reporting obligations. Whether a specific obligation applies depends on the precise size of the company, the sector it supplies to and the country of establishment. The current text of the relevant regulation, with the associated thresholds and deadlines, can be found with the legislator or supervisory authority responsible for it; that text changes, and a landing page is not the place to freeze thresholds that may change tomorrow.
For ICT companies, the position in the chain is often more decisive than their own size. A supplier of software solutions to the construction sector receives questions about material use and emissions passed on that originally belong to the obligations of the construction sector. The same mechanism applies toward energy companies, real estate parties and financial institutions. Anyone who does not know what information a client needs to meet its own obligations is often confronted with this only at a late stage. That is one of the patterns described in the ways companies are caught off guard by legislation: it is not one's own sector, but sometimes the client's sector, that determines what is asked.
Knowing which rules a company falls under is a first step. The follow-up question is whether a board can demonstrate that it knows these obligations, has assigned them to an owner and has provided them with evidence. That distinction between knowledge and demonstrability is central to the description of how a board demonstrates that it is in control: a list of obligations without an owner and without evidence offers little support in practice during a review or audit.
The Compliance Check being developed for csrdcompliance.net brings these obligations together in an overview per company: which rule applies, who within the organization is responsible for it, what evidence is needed and which control belongs to it. The tool is still under construction. Anyone wishing to use it once it becomes available can sign up for the waiting list.
Once it is clear which obligations apply and who is responsible for them, the question of how much time their execution takes and which part of that can be automated naturally follows. Collecting evidence, maintaining records and repeating checks are tasks that can be broken down effectively. The werkscan (work scan) from FTE TO AI calculates per task which part of that work can be taken over by AI, so that a board not only knows what needs to happen, but also gets a realistic picture of what will structurally continue to cost time and what will not.
Vraag maar welke verplichting op u van toepassing is, en waaraan u dat kunt aantonen.
Answers come from this site’s knowledge base. Not tailored advice, and not a scan of your company.