ESG compliance
You are in a meeting and are asked whether the organization complies with the rules that apply to it. There is an answer, but no one can substantiate it. There is a policy, written by someone who has since moved to a different role. There is practice, which on the work floor runs slightly differently than that policy describes. There is evidence, scattered across folders, mailboxes and the memory of a few people who have been doing it this way for years. And there is the question without an owner: who exactly is responsible for the reporting on the supply chain, for the emissions data, for the new packaging rules? No one has ever said no to that question, but no one has said yes either. That is not just a compliance risk. It is a governance risk, because "we think it's fine" is not an answer with which a board can be in control.
The Compliance Check is not advice and not an opinion. It is a set of documents and overviews that are on the table after the scan, each with its own function.
First an applicability overview: per obligation — CSRD/VSME, CSDDD, EUDR, PPWR, CBAM, sectoral regulation and the national gold-plating provisions per country — it is indicated whether it applies to your organization, based on the data you have entered about your company profile. Not a loose statement, but a matrix you can browse through.
Then a status picture per obligation: met, gap, or risk, weighted by likelihood and impact. This is not a score on the organization as a whole, but an indication of where further examination can take place.
Next a control matrix: per obligation an owner, a control, a frequency and a place where the record is kept. This is the document with which you can show how something is monitored, not only whether it was ever written down.
Alongside this a remediation roadmap: the gaps in order of risk, aligned with the risk structure your organization already uses.
And an evidence vault: a document checklist per obligation, with a trail that runs from report line to source to piece of evidence. Every outcome can be traced back to the source data that was entered or supplied — nothing is assumed that has not been demonstrated.
Finally a one-page board report and a horizon scanner subscription that reports what is changing, who it affects and what needs to be done. Per obligation, it is also factually described where opportunities lie — better supplier information, lower costs, a stronger story — without promising an outcome from this.
Everything the tool shows comes from two places: what you enter yourself about your company profile, activities and countries, and the reglia obligations matrix with the associated module datasets in which the regulation is recorded. There is no interpretation based on experience or gut feeling. Every line in the report can be traced back to an entered data point and a consulted source. That is precisely why a board can act on it: not because the report is right, but because every conclusion can be verified. How that scan technically proceeds step by step is described on how it works; what the various outcomes mean in practice is explained on outcomes.
The check goes through four steps. First the company profile: data on sector, size, legal form, product and countries, recorded read-first as the basis for the rest. Then the applicability scan: which obligations apply, including the national gold-plating provisions that are often underestimated. Next the gap inquiry and the evidence: per obligation, policy is set against practice, with documents that go into the vault. And finally the control matrix, roadmap and the report: ownership, risk order and the board report, followed by the scanner subscription that keeps signaling changes.
Three things are explicitly not part of what you get back. First, csrdcompliance does not build its own obligations register alongside all the others; the tool runs on the reglia obligations matrix and the reglia module datasets, not on a self-invented list. Second, there is no proven track record to refer to — there are no completed engagements at other companies to show as a reference. The tool structures what exists, it does not prove a history of results. Third: there is currently no working tool yet. The button on this site is in waitlist mode; those who sign up are in line for the moment the Compliance Check becomes active. More background on the regulation itself, apart from the tool, is in the knowledge base.
What you do with the report is up to you. Doing it yourself means you manage the register, the control matrix and the roadmap yourself, with the evidence vault and a quarterly board report as a fixed rhythm. Partially guided means a partner supports the policy-versus-practice investigation and the training of the board on the outcomes. Outsourcing means the entire compliance process goes to that partner, with this check as the baseline on which further work is built. None of the three routes is prescribed; the report only makes them possible.
This report tells you which obligations apply and where the evidence is missing. What that means in concrete terms for tasks, hours and systems — who is going to do it and with what capacity — is a question that only arises once the scan is complete, and that belongs to the work scan of [ftetoai.com](https://ftetoai.com).
Vraag maar welke verplichting op u van toepassing is, en waaraan u dat kunt aantonen.
Answers come from this site’s knowledge base. Not tailored advice, and not a scan of your company.