Skip to main content
Category: Regulatory Disclosure

ESG Metrics

Also known as: ESG, ESG indicators, ESG KPIs, environmental, social, and governance metrics
Simply put

ESG metrics are measurable indicators used to assess how an organization performs on environmental impact, social responsibility, and governance practices. They can be quantitative or qualitative data points that help evaluate a company's performance across these three areas. Organizations commonly use them to track progress and report on sustainability-related matters.

Formal definition

ESG metrics are specific, measurable quantitative and qualitative performance measures used to assess an organization's performance across environmental, social, and governance dimensions. In practice they function as data points and key performance indicators (KPIs) that reflect performance on discrete ESG issues, and may support both compliance-oriented reporting and broader performance management. This entry defines the general concept only; it does not specify which particular metrics apply, nor the disclosure standards, frameworks, or jurisdictional reporting obligations that may govern their selection, measurement, and assurance, which typically vary by jurisdiction, sector, and organization.

Why it matters

ESG metrics have become a focal point where governance, risk management, and compliance intersect. They give boards, investors, and other stakeholders measurable indicators to assess how an organization performs across environmental impact, social responsibility, and governance practices, rather than relying on general statements of intent. Because these metrics can be quantitative or qualitative, they allow performance on discrete ESG issues to be tracked over time and compared against stated objectives and targets.

Their significance extends beyond internal management to external reporting. In many contexts, ESG metrics support disclosure to investors, regulators, and the public, and they may feed into compliance-oriented reporting obligations. As sources in this area note, tracking ESG performance is often positioned as more than a compliance exercise, it is also used to inform strategy and performance management. This dual role means the selection and integrity of the metrics chosen carry weight: metrics that do not reflect the issues most material to an organization may misdirect attention or misrepresent performance.

At the same time, the specific metrics that apply, and the standards, frameworks, and assurance expectations that govern them, typically vary by jurisdiction, sector, and organization. This variability creates governance and risk considerations around comparability, consistency, and reliability of the data reported. Organizations should be cautious not to treat any single set of ESG metrics as universally applicable or as a guarantee of favorable outcomes.

Who it's relevant to

Governance professionals and boards
ESG metrics give directors and governance functions measurable indicators to oversee performance on environmental, social, and governance matters. They can support board-level monitoring of objectives and provide a basis for accountability, though the choice of metrics and their reliability warrant careful governance attention.
Compliance officers
Where ESG metrics feed into disclosure or reporting obligations, compliance functions have an interest in whether the metrics selected align with applicable requirements. Because reporting obligations typically vary by jurisdiction, sector, and organization, compliance teams generally need to confirm which standards and frameworks apply rather than assuming a universal set.
Risk managers
ESG metrics can serve as inputs for identifying and monitoring ESG-related risks against organizational objectives. Risk managers may use them to track exposure on discrete issues over time, while remaining mindful that metrics are indicators of performance and do not by themselves guarantee outcomes.
Internal auditors and assurance providers
Assurance functions may be called upon to evaluate the reliability of ESG metrics and the processes that produce them. Their role is distinct from the management activities that generate the data, and maintaining independence and objectivity is important when assessing how metrics are measured and reported.
Investors and external stakeholders
Investors and other external stakeholders use ESG metrics to evaluate an organization's performance across environmental, social, and governance areas. Comparability and consistency can be limited because the specific metrics and governing standards vary, so stakeholders should consider the context in which each metric is reported.

Inside ESG

Environmental metrics
Quantitative and qualitative indicators relating to an organization's environmental impact, such as greenhouse gas emissions, energy and water consumption, waste generation, and resource use. The specific metrics tracked commonly vary by industry, jurisdiction, and the reporting framework adopted.
Social metrics
Indicators addressing an organization's relationships with people and communities, which may include workforce composition and diversity data, health and safety incidents, labor practices, and community engagement. The relevance and definition of particular metrics typically depend on sector and applicable regulation.
Governance metrics
Indicators concerning the structures, roles, and decision rights that direct the organization, such as board composition and independence, executive remuneration linkage, ethics and anti-corruption measures, and oversight arrangements. These metrics sit primarily within the governance pillar and should not be conflated with operational compliance measures.
Reporting frameworks and standards
Voluntary and, in some jurisdictions, mandatory frameworks that shape how ESG metrics are defined, measured, and disclosed. Requirements differ across jurisdictions, sectors, and organization size, and no single global standard applies uniformly; practitioners should identify which framework governs their disclosures.
Data collection and assurance considerations
The processes for gathering, validating, and, where applicable, obtaining independent assurance over ESG data. Assurance over ESG metrics is an activity distinct from the management processes that generate the underlying data, and the availability and level of assurance vary by organization and jurisdiction.

Common questions

Answers to the questions practitioners most commonly ask about ESG.

Are ESG metrics the same as an organization's sustainability strategy?
No. ESG metrics are quantitative or qualitative measures used to track performance across environmental, social, and governance dimensions; they are indicators, not the strategy itself. A sustainability or ESG strategy sets objectives, priorities, and resource commitments, while metrics are one input used to monitor progress against those objectives. Treating the metrics as the strategy risks measuring activity without a coherent direction. Metrics also do not, on their own, determine whether performance is adequate; that judgment depends on targets, context, and stakeholder expectations.
Does reporting ESG metrics mean an organization is compliant with ESG regulations?
Not necessarily. Disclosing ESG metrics and meeting a regulatory obligation are distinct. Reporting metrics reflects measurement and communication, whereas compliance concerns adherence to specific disclosure laws, standards, or regulatory requirements that vary by jurisdiction, sector, and organization size. An entity may publish metrics voluntarily without falling under a mandatory regime, or may be subject to prescribed disclosure requirements that specify content, format, assurance, and timing. Whether a given metric satisfies an applicable obligation depends on the relevant legal framework in the applicable jurisdiction.
How should an organization select which ESG metrics to track?
Selection commonly begins with identifying the environmental, social, and governance topics most relevant to the organization's objectives, sector, and stakeholders, often informed by a materiality or relevance assessment. Metrics are then chosen to reflect those topics and, where applicable, to align with disclosure frameworks or regulatory requirements that apply in the organization's jurisdiction. Practitioners typically favor metrics that are measurable, verifiable, and comparable over time. This entry does not prescribe specific metrics or tooling, as appropriate choices vary by context.
Who is typically responsible for ESG metrics within an organization?
Responsibilities are commonly distributed across functions. Under a three lines model, operational owners in the first line generally collect and report the underlying data and manage the related activities, while second line functions such as risk, compliance, or a dedicated ESG or sustainability team may set methodology, monitor, and provide oversight. Governance bodies typically hold decision rights over targets and disclosures. Independent assurance over ESG metrics, where obtained, is an assurance activity that should remain distinct from the management functions that produce the data, to preserve objectivity.
How can the quality and reliability of ESG metrics be supported?
Reliability is commonly supported through documented definitions and calculation methodologies, consistent data sources, controls over data collection and aggregation, and periodic review. Some organizations obtain external assurance, the scope and level of which can vary and may be required or voluntary depending on the applicable jurisdiction and framework. Clear methodology helps address comparability challenges, since ESG metrics can be calculated differently across organizations. This entry does not address specific assurance standards, control designs, or software implementations.
How do ESG metrics relate to an organization's risk management activities?
ESG metrics can serve as inputs to risk identification and monitoring, for example by surfacing exposures related to environmental, social, or governance factors that may affect objectives. In this sense certain ESG metrics may function as indicators used within enterprise or operational risk processes. However, a metric is a measure rather than a control or a risk assessment; it does not by itself treat risk or guarantee outcomes. How ESG considerations are integrated into risk management depends on the organization's frameworks, appetite, and applicable requirements.

Common misconceptions

ESG metrics are governed by a single, universally mandatory global standard.
ESG disclosure and measurement obligations vary considerably by jurisdiction, industry, and organization size. Some regimes impose mandatory reporting while others rely on voluntary frameworks, and the applicable framework should be identified for the relevant context rather than assumed to be universal.
ESG metrics belong entirely to the compliance function.
ESG metrics span more than one pillar. The governance dimension concerns structures and decision rights, the environmental and social dimensions often relate to risk and operational management, and compliance concerns adherence to applicable disclosure obligations. Treating all ESG metrics as a compliance-only matter can obscure these distinctions.
Reporting an ESG metric is equivalent to having independent assurance over it.
Producing and disclosing a metric is a management activity, whereas assurance is a separate activity intended to provide independent confidence over the data. The presence of a reported figure does not by itself indicate that it has been independently verified, and assurance levels differ across organizations.

Best practices

Identify which reporting frameworks and jurisdictional obligations apply to your organization before selecting metrics, rather than assuming a single universal standard applies.
Map each metric to the appropriate pillar, environmental, social, or governance, and note where a metric spans more than one, to preserve clarity in oversight and reporting.
Establish documented data collection and validation processes so that the origin, calculation basis, and boundaries of each metric are traceable.
Keep management-produced ESG data distinct from any independent assurance activity, and clearly disclose whether and to what level metrics have been assured.
Use qualified, context-specific language when reporting, stating the applicable jurisdiction, sector, and framework rather than presenting metrics as universally comparable.
Periodically review the relevance of selected metrics as regulatory requirements and framework expectations evolve across jurisdictions.
Promotional banner for the Penetration Report Template Kit