Skip to main content
Category: Regulatory Disclosure

Sustainability Report

Also known as: ESG Report, ESG Reporting
Simply put

A sustainability report is a document that a company publishes to disclose how it performs on environmental, social, and governance (ESG) matters, and how its activities affect them. It communicates this information to stakeholders such as investors, regulators, customers, and the public. Organizations commonly use these reports to meet disclosure expectations and to demonstrate accountability for their non-financial performance.

Formal definition

A sustainability report is a published corporate disclosure of an organization's performance, progress, and impacts across environmental, social, and governance (ESG) dimensions. It typically presents both an organization's effects on ESG factors and its management of related matters, serving compliance, stakeholder trust, and accountability objectives. As a disclosure instrument, it sits primarily within the governance and reporting domain and is distinct from the underlying management and control activities that generate the disclosed performance; the report communicates outcomes rather than constituting the controls themselves. The specific content, structure, and applicable reporting frameworks or regulatory requirements vary by jurisdiction, sector, and organization size, and are not addressed in this entry.

Why it matters

Sustainability reports have become a central instrument through which organizations demonstrate accountability for their non-financial performance. As disclosure expectations from investors, regulators, customers, and the wider public have grown, these reports serve as the primary channel for communicating how an organization performs on environmental, social, and governance matters and how its activities affect them. For governance professionals, the report is a visible manifestation of the organization's stance on ESG issues and a mechanism for building and maintaining stakeholder trust.

The governance stakes are meaningful because a sustainability report communicates outcomes to parties who may make decisions based on it. Investors may weigh disclosed ESG performance in capital allocation, customers may consider it in procurement, and regulators may examine it against applicable disclosure obligations. Because the content, structure, and applicable frameworks vary by jurisdiction, sector, and organization size, the significance and required rigor of a given report depend heavily on context; what satisfies expectations in one setting may fall short in another.

It is important to recognize what a sustainability report is and is not. The report is a disclosure that communicates performance; it is distinct from the underlying management and control activities that generate that performance. Treating the report itself as evidence of effective ESG management, rather than as a disclosure of outcomes produced by controls elsewhere in the organization, is a common conceptual error that governance and assurance functions should guard against.

Who it's relevant to

Governance and Disclosure Professionals
Those responsible for corporate disclosure use sustainability reports to communicate ESG performance and impacts to stakeholders and to demonstrate accountability for non-financial performance. The report sits within the governance and reporting domain and reflects the organization's stance on ESG matters.
Compliance Officers
Compliance functions may engage with sustainability reporting where disclosure expectations or regulatory requirements apply. Because these requirements vary by jurisdiction, sector, and organization size, compliance professionals typically assess which obligations are relevant to their specific context.
Investors and Other External Stakeholders
Investors, regulators, customers, and the public are the primary audiences for a sustainability report. They rely on it to understand how an organization performs on ESG matters and how its activities affect those factors, and may use the disclosed information in their own decisions.
Assurance and Internal Audit Functions
Assurance providers should keep the distinction between the report and the underlying activities clear. The report communicates outcomes and is not itself the set of controls; assurance work generally focuses on whether disclosed performance is supported by the management and control activities that generate it, maintaining independence from those activities.

Inside Sustainability Report

Environmental Disclosures
Information on an organization's environmental impacts, which may include energy use, greenhouse gas emissions, water consumption, waste, and resource management. The specific metrics disclosed commonly vary by reporting framework, jurisdiction, and sector.
Social Disclosures
Information addressing an organization's relationships with employees, communities, and other stakeholders, which may cover labor practices, health and safety, diversity, and human rights considerations. The scope typically depends on the framework applied and the organization's context.
Governance Disclosures
Information on the structures, roles, and decision rights through which sustainability matters are directed and overseen, such as board oversight of sustainability topics and accountability arrangements. This element reflects the governance pillar and should be distinguished from compliance reporting on specific regulatory obligations.
Materiality Assessment
A process used to identify which sustainability topics are significant enough to report, based on their relevance to the organization and its stakeholders. Approaches to determining materiality may differ across frameworks and jurisdictions.
Reporting Framework or Standard Reference
An indication of the framework, standard, or set of guidelines the report follows. Frameworks are issued by different bodies with differing scope, and organizations may reference more than one. Applicable frameworks and any mandatory requirements typically vary by jurisdiction and sector.
Targets and Performance Data
Stated objectives and associated performance information for sustainability topics over a defined reporting period. The presence, definition, and comparability of metrics commonly vary by framework and organization.

Common questions

Answers to the questions practitioners most commonly ask about Sustainability Report.

Is a sustainability report the same as a compliance filing that guarantees an organization is meeting its ESG obligations?
No. A sustainability report is primarily a disclosure and communication document describing an organization's environmental, social, and governance performance and commitments. It does not by itself constitute compliance with any legal obligation, nor does it guarantee that stated targets are met. In some jurisdictions and sectors, certain sustainability or non-financial disclosures may be mandated, but the report is a means of reporting rather than a control that ensures conformance. The underlying obligations, controls, and assurance activities are distinct from the report that describes them.
Does publishing a sustainability report mean the disclosed data has been independently audited?
Not necessarily. Publication and assurance are separate matters. A sustainability report may be issued with no external assurance, with limited assurance, or with reasonable assurance, and the level obtained typically depends on the assurance engagement commissioned and applicable requirements. Assurance, where performed, is an independent activity distinct from management's preparation of the report. Readers should look for an explicit assurance statement identifying the practitioner, scope, and level of assurance rather than assuming that publication implies verification.
Which functions are typically involved in preparing a sustainability report?
Preparation commonly involves data owners across the business who generate the underlying environmental, social, and governance information, a coordinating function such as a sustainability, finance, or reporting team that consolidates and drafts disclosures, and governance bodies that review and approve the report. In three-lines terms, management functions prepare and own the data, second-line functions may support consistency and policy alignment, and any independent assurance sits separately. The specific allocation varies by organization size, structure, and jurisdiction.
How can an organization support the reliability of the data in a sustainability report?
Organizations commonly apply controls over data collection, aggregation, and calculation similar in spirit to those used for financial reporting, such as defined data definitions, documented methodologies, reconciliation, and review before publication. Establishing clear ownership, maintaining an audit trail, and applying consistent measurement boundaries over time can support reliability and comparability. This entry does not address specific tooling or implementation configurations, which vary by organization.
What frameworks or standards might guide the content of a sustainability report?
Organizations may reference recognized reporting frameworks and standards issued by various bodies to structure disclosures, and applicable requirements differ by jurisdiction, sector, and organization size. Because the landscape includes multiple frameworks with differing scopes and because mandatory requirements vary, an organization should confirm which frameworks or regulatory disclosure obligations apply to its own context rather than assuming a single universal standard. This entry does not provide legal advice on which requirements are binding in a given jurisdiction.
How does a sustainability report relate to an organization's governance and risk management processes?
A sustainability report can reflect outputs of governance and risk processes, for example by disclosing how ESG-related risks are identified, assessed, and overseen, but the report itself is a disclosure output rather than the governance or risk management activity. Governance concerns the structures and decision rights that direct sustainability matters, risk management concerns treating relevant uncertainties against objectives, and the report communicates results of these. Keeping this distinction clear helps avoid treating the act of reporting as a substitute for the underlying processes.

Common misconceptions

A sustainability report is an audited, assurance-grade document equivalent to financial statements.
A sustainability report is primarily a management disclosure. Whether any part is subject to independent assurance varies by jurisdiction, framework, and organizational choice; the report itself should not be confused with the independent assurance activity that may or may not accompany it.
Sustainability reporting is voluntary everywhere and follows a single universal standard.
Reporting obligations and the frameworks that apply commonly differ across jurisdictions, industries, and organization sizes. In some contexts disclosure may be mandatory, while in others it is voluntary, and organizations may draw on multiple frameworks issued by different bodies.
A sustainability report demonstrates that the organization is compliant and that its risks are controlled.
A report is a disclosure of information, not evidence that compliance obligations have been met or that risks have been effectively treated. Governance oversight, compliance with applicable laws, and risk management are distinct activities that the report may describe but does not by itself guarantee.

Best practices

Define and document a materiality assessment process to determine which sustainability topics warrant disclosure, and record the basis for those decisions.
Identify the applicable framework(s), standard(s), and any mandatory requirements for the organization's specific jurisdiction, industry, and size before selecting metrics, rather than assuming a universal standard applies.
Keep governance, risk, and compliance disclosures clearly distinguished within the report, describing board and management oversight structures separately from adherence to legal obligations and from risk treatment.
Use qualified, defensible language for performance claims and avoid presenting targets or metrics as guaranteed outcomes.
Where independent assurance is obtained over any part of the report, clearly delineate what is assured from management-prepared content, preserving the independence of the assurance function.
Maintain traceable supporting evidence for reported data and disclosures so that figures, targets, and topic selections can be substantiated and reviewed.
Promotional banner for the Penetration Report Template Kit