top of page

The Ultimate Guide to ESG: How ESG Actually Works Inside a Business (2026)

  • Jul 29
  • 14 min read

Updated: Aug 2


"ESG" gets thrown around a lot, sometimes as a badge of honor, sometimes as a punchline, depending on who's talking. But strip away the politics for a second and there's a genuinely useful management idea underneath it: a structured way for a company to track, manage, and report on the non-financial risks and opportunities that increasingly move the needle on financial ones.

This guide breaks down what ESG actually is, how it's different from "sustainability" and "CSR" (people mix these up constantly), how a company actually builds an ESG program step by step, who's responsible for it internally, and because the regulatory ground has shifted a lot in 2026, what the reporting landscape looks like right now, not two years ago.

1. What ESG Actually Stands For

ESG stands for Environmental, Social, and Governance, three categories of non-financial factors that investors, employees, customers, and regulators use to evaluate how a company operates, beyond just its revenue and profit numbers.

It's not a brand-new idea. Its roots trace back to socially responsible investing in the 1960s and 70s, when investors first started screening out companies involved in things like tobacco or weapons manufacturing. The term "ESG" itself was popularized in the mid-2000s after the United Nations helped drive it into the mainstream, publishing a set of ESG investing principles and outlining a legal framework for factoring ESG data into investment decisions. Since then, it's evolved into a much more formalized, measurable discipline.

Each of the three pillars covers a distinct set of issues:

  • Environmental: energy consumption, water usage, greenhouse gas emissions and overall carbon footprint, waste management, air and water pollution, deforestation, biodiversity loss, and climate adaptation.

  • Social: how a company treats its employees, supply chain workers, customers, and the communities it operates in. This includes fair pay and living wages, diversity, equity and inclusion, workplace health and safety, responsible sourcing, supply chain oversight, and community engagement.

  • Governance: internal management practices and controls: board composition, executive compensation, financial transparency, regulatory compliance, risk management, data privacy, and policies around corruption, bribery, and conflicts of interest.

How this gets implemented: in practice, a company doesn't tackle all of this at once. It typically starts by mapping which of these E, S, and G issues are actually material to its specific business, a mining company and a software company will have very different environmental priorities, for example, and builds its program around what matters most for its industry and stakeholders.

To make this concrete, here's roughly how the pillars translate into day-to-day operational decisions:

  • A manufacturing company might focus environmental effort on energy efficiency and waste reduction on the production line, social effort on factory worker safety, and governance effort on supply chain audits to catch labor violations before they become headline risk.

  • A financial services firm typically has a lighter direct environmental footprint (no smokestacks), so its environmental disclosures often center on financed emissions, the carbon footprint of what it lends to and invests in, while governance (data privacy, conflicts of interest, anti-money-laundering controls) tends to carry more relative weight.

  • A retailer usually weights social factors heavily, supply chain labor conditions, living wages for store staff, alongside environmental packaging and logistics emissions.

This is exactly why generic, one-size-fits-all ESG checklists tend to produce weak programs: the relative importance of each pillar is industry-specific, which is also why reporting frameworks like SASB build separate materiality standards for dozens of individual industries rather than one universal list.

Three-column breakdown of the E, S, and G pillars with example issues under each — useful as the section's anchor graphic.
Three-column breakdown of the E, S, and G pillars with example issues under each — useful as the section's anchor graphic.

Section takeaway: ESG isn't one thing. It's three distinct categories of risk and opportunity (environmental, social, governance), and no two companies will weight them the same way. The starting point is always figuring out which issues are actually material to your business.

2. ESG vs. Sustainability vs. CSR: They're Not the Same Thing

This is one of the most common mix-ups in the field, and it's worth being precise about, because the three terms serve different purposes:

  • Business sustainability is the broadest of the three. It's about positioning a company for long term success through responsible management practices and business strategy in general.

  • Corporate social responsibility (CSR) is a general framework for taking business actions that produce societal benefits. It's more about intent and values than measurement.

  • ESG is the most formalized of the three: a structured strategy built around measurable goals, defined processes for tracking and managing performance, and public reporting on the results.

Put simply: sustainability is the goal, CSR is the philosophy, and ESG is the accountability system, the part with numbers, targets, and disclosures attached to it.

How this gets implemented: if your company already has sustainability values or a CSR mission statement, ESG is the layer you add on top to make those values auditable, turning "we care about the environment" into "we're tracking Scope 1 and 2 emissions and have committed to a 30% reduction by 2030."

A useful way to spot the difference in practice: ask whether a claim could be independently verified by an auditor. "We're committed to protecting the environment" is a CSR style statement, genuine, but not checkable. "We reduced Scope 1 and 2 emissions by 14% against a 2020 baseline, verified by a third party assurance provider" is an ESG style statement: it has a number, a baseline, a timeframe, and (ideally) external verification. This is also why "greenwashing" accusations tend to land specifically on ESG claims rather than general CSR language: once a company puts a number in a report, that number becomes a target for scrutiny in a way that a values statement never is.

It's also worth noting these three concepts aren't strictly hierarchical in every company's org chart. Some businesses run CSR and ESG as separate functions with different owners (a CSR or community affairs team focused on philanthropy and volunteering, and a separate ESG or sustainability team focused on disclosure and compliance), which can create duplicated effort if the two teams aren't coordinating on the same underlying data.

A nested scope diagram showing ESG as the measurable core sitting inside CSR and sustainability.
A nested scope diagram showing ESG as the measurable core sitting inside CSR and sustainability.

Section takeaway: Sustainability is the destination, CSR is the mindset, and ESG is the measurement and reporting system that holds a company accountable for both.

3. Why Companies Actually Invest in ESG

Beyond the values driven case, there are concrete business reasons companies build ESG programs:

  • Competitive advantage. Companies with credible ESG programs tend to strengthen their market position and brand relative to competitors, and they become more attractive to the growing pool of ESG focused investors, who collectively manage trillions of dollars in ESG and sustainable investment assets in the US alone.

  • Better financial performance. ESG initiatives, from energy efficiency to waste reduction to smarter supply chains, can directly cut operating costs, while also supporting stronger margins over time.

  • Customer loyalty. Buyers increasingly factor ESG into purchasing decisions. In one industry survey of IT professionals, 70% said they believed their company would pay a price premium of more than 5% for products from vendors with strong ESG practices.

  • Regulatory readiness. Companies with mature ESG data infrastructure adapt faster when new disclosure requirements land, and as you'll see in the regulatory section below, that landscape keeps moving.

  • Talent and retention. ESG initiatives are linked to higher employee engagement, easier hiring, and improved standing in the communities where a company operates.

How this gets implemented: the business case for ESG works best when it's framed in the language finance and operations teams already use (cost savings, risk reduction, capital access) rather than purely as a values statement. That's usually what gets ESG budget approved at the leadership level.

One tool that makes this business case concrete is the materiality matrix, a simple two axis chart plotting ESG issues by "importance to the business" on one axis and "importance to stakeholders" on the other. Issues that land in the top right quadrant (high on both axes) are the ones that deserve the most budget and board attention; issues in the bottom left quadrant can usually be monitored rather than actively managed. Companies like Unilever have publicly credited this kind of prioritization exercise with helping embed ESG into core business strategy rather than treating it as a side project. Unilever's materiality process reportedly feeds directly into executive compensation, with a portion of the CEO's bonus tied to specific ESG targets like emissions reduction. Rating agencies use a similar concept at scale: S&P Global builds a separate materiality matrix for each of 62 industries, since "carbon emissions" is a top right issue for an airline but a much lower priority for a software company.


A materiality matrix scatter chart showing where different ESG issues would plot in terms of stakeholder vs. business importance.
A materiality matrix scatter chart showing where different ESG issues would plot in terms of stakeholder vs. business importance.

Section takeaway: ESG isn't just a values exercise. It has a measurable connection to cost savings, customer loyalty, access to capital, and talent retention, which is why it keeps surviving budget cuts even when it's politically contested.

4. How to Actually Build an ESG Strategy: An 8 Step Process

This is the part most guides skip: the actual mechanics of building an ESG program inside a real organization. Here's the process, roughly in order:

  1. Get input from stakeholders. Talk to board members, executives, employees, institutional investors, customers, suppliers, and community leaders about the issues that matter most to them.

  2. Assess materiality. Not every ESG issue matters equally to every business. Identify which issues are most important to your company and stakeholders, and which are lower priority. This becomes the basis for everything that follows.

  3. Establish a baseline. Document current performance, policies, and statistics on the ESG factors you plan to address. You can't measure progress without a starting point.

  4. Define measurable goals. Set specific objectives and KPIs. Some goals will be about improvement; others might simply be about maintaining current performance in areas that are already strong.

  5. Build a deployment roadmap. Create a detailed implementation plan with timelines, milestones, and clear ownership.

  6. Choose reporting standards and frameworks. There are several major options, and many companies end up using more than one to satisfy different reporting and disclosure needs. As a quick orientation: GRI is the broadest, stakeholder facing standard (used by more companies globally than any other); IFRS S1/S2 from the ISSB are the investor facing standards that absorbed the older SASB and TCFD frameworks; CDP is a specific disclosure system for climate, water, and forest data that investors and customers frequently request directly; and ESRS is the EU's own standard tied to CSRD compliance. Most large multinationals report against a combination of GRI (for broad stakeholder transparency) and ISSB or ESRS (for investor facing financial materiality) rather than picking just one. The full detail on each of these is in the references section below.

  7. Collect, analyze, and report on data. Once the program is running, set up processes for ongoing data collection and analysis. Full external reports are usually annual; internal progress updates should happen more frequently.

  8. Review and revise. ESG requirements shift as regulations, stakeholder expectations, and business priorities evolve. The strategy needs regular reassessment, not a "set it and forget it" approach.

How this gets implemented: the biggest failure mode here is skipping step 2 (materiality) and step 3 (baseline) and jumping straight to picking a reporting framework. Without a materiality assessment, companies end up reporting on issues that look good but aren't actually relevant to their risk profile, which shows up as "greenwashing" to a sharp eyed investor or auditor even when it isn't intentional. A second common failure mode is treating step 8 as optional. Because ESG data collection processes take real effort to stand up, teams are often tempted to leave them running unchanged for years, but stakeholder priorities, regulations, and even the company's own operations (a new product line, an acquisition, a new market) shift constantly, so a strategy frozen at step 4 quietly drifts out of relevance.

An eight step process flow, ideally shown as a repeating cycle rather than a one time linear project.
An eight step process flow, ideally shown as a repeating cycle rather than a one time linear project.


Section takeaway: ESG strategy isn't a single initiative. It's an eight step operating cycle running from stakeholder input through materiality, baseline, goal setting, implementation, reporting, and revision. Skipping the materiality and baseline steps is the most common reason ESG programs feel unfocused.

5. Who Actually Owns ESG Inside a Company

ESG oversight typically starts at the board level or in the C suite, often with the CEO or an executive committee taking the operational lead. Many companies now have a dedicated Chief Sustainability Officer, Chief ESG Officer, or VP of Sustainability, and some have a Chief Diversity Officer working closely with HR on DEI programs.

Beyond these dedicated roles, individual ESG initiatives are usually distributed across departments and owned by their respective heads:

  • The CFO typically oversees ESG related financial disclosures and risk quantification.

  • The CMO manages ESG related brand, marketing, and customer communication.

  • General counsel handles ESG related regulatory and legal compliance.

  • The CIO plays a particularly large role in environmental initiatives specifically, given IT's high energy consumption and the growing volume of e-waste as systems and devices are replaced. The CIO also has to ensure the company's systems and tools can actually support ESG data collection across the business.

Software vendors have built entire product categories around supporting this structure: tools that handle materiality assessments, carbon footprint and greenhouse gas accounting, performance monitoring and benchmarking, sustainability reporting, and risk disclosure. Analyst firms like Forrester Research now evaluate these sustainability management platforms specifically on features like materiality assessment support, GHG accounting accuracy, benchmarking and auditing capability, and how well they generate audit ready disclosure reports, which tells you how much this has matured into its own software category rather than a bolt on feature of general compliance tools.

One pattern worth flagging: companies without a dedicated ESG software layer often end up managing this entire process in spreadsheets, pulled together manually once a year for the annual report. That approach tends to break down exactly when it matters most (during an audit, an investor due diligence request, or a new regulatory filing with a tight deadline), because the underlying data was never structured for repeatable extraction in the first place.

How this gets implemented: smaller companies without a dedicated ESG or sustainability officer can still run an effective program by assigning clear ownership, even part time, to someone with cross functional visibility (often finance or legal), rather than letting ESG become "everyone's job and no one's job."

A simple governance org chart with board and CEO oversight at the top, an ESG officer beneath, branching out to functional owners across finance, marketing, legal, and IT/HR.
A simple governance org chart with board and CEO oversight at the top, an ESG officer beneath, branching out to functional owners across finance, marketing, legal, and IT/HR.
Section takeaway: ESG ownership is rarely one person's job. It starts with board and C suite oversight, often anchored by a dedicated sustainability or ESG officer, but execution is distributed across finance, legal, marketing, HR, and IT.

6. How ESG Performance Actually Gets Measured

ESG metrics fall into two broad types:

  • Quantitative metrics: greenhouse gas emissions, energy and water usage, waste generated, compensation data, employee turnover rates, charitable contributions, and workforce and board diversity figures.

  • Qualitative metrics: labor practices, community engagement, codes of conduct, and business ethics policies.

These metrics feed into two things companies actually use them for:

  1. Internal risk management: tracking KPIs against a framework like the triple bottom line, which treats social and environmental impact alongside financial performance as core "bottom line" categories, not side issues.

  2. External ESG ratings: third party rating agencies combine reported metrics with their own data to produce ESG scores (a number or letter grade) that investors and other stakeholders use when evaluating a company.

How this gets implemented: a practical starting point for most companies is picking 8 to 12 KPIs that map directly to the material issues identified in step 2 of the strategy process above, rather than trying to track everything a rating agency might ask about. Depth on what matters beats breadth on what doesn't.

Worth understanding as a business owner: ESG ratings from different agencies (MSCI, S&P Global, Sustainalytics, and others) frequently disagree with each other for the same company, sometimes significantly. This isn't necessarily a sign that ratings are unreliable. It usually reflects genuinely different methodologies, different weightings of the E, S, and G pillars, and different underlying data sources. The practical implication is that chasing a single rating agency's specific scoring criteria is a weaker long term strategy than building genuinely strong underlying data and letting multiple ratings reflect that independently.

KPI dashboard mockup showing example ESG metrics (emissions, water use, turnover, diversity, giving) the way a sustainability reporting tool would display them.


Section takeaway: ESG measurement mixes hard numbers (emissions, turnover, diversity data) with qualitative judgment (ethics, community relationships), and both feed into internal risk tracking and the external ratings that investors actually look at.

7. The 2026 Regulatory Reality Check

This is the part of the ESG conversation that's changed the most recently, and it's worth being precise about where things actually stand as of mid 2026. The picture is quite different from what most ESG explainer content (including older versions of this one) describes.

United States: SEC climate rule is being rescinded, not implemented. The SEC adopted a climate related disclosure rule in March 2024, but it was stayed almost immediately amid litigation and never actually took effect. Following a change in SEC leadership, the agency stopped defending the rule in court, and in May 2026 the Commission formally proposed rescinding it entirely, citing compliance costs it estimates at roughly $4.9 billion in annualized savings if withdrawn. A final vote was expected later in 2026. In short: there is currently no enforceable federal ESG or climate disclosure mandate in the US.

But state level rules still apply. California's SB 253 requires large companies doing business in the state to report Scope 1 and 2 greenhouse gas emissions, with an initial deadline in August 2026 (Scope 3 reporting follows in 2027). A companion law, SB 261 (climate related financial risk disclosure), is currently under a temporary judicial stay but companies are advised to stay "report ready."

The EU has significantly narrowed CSRD, not expanded it. The original expectation, reflected in a lot of older ESG content, was that the Corporate Sustainability Reporting Directive would eventually require roughly 50,000 companies to report. That's no longer accurate. In early 2026, the EU finalized its "Omnibus I" simplification package, which raised the CSRD's scope thresholds substantially, to companies with more than 1,000 employees and over €450 million in net turnover, removing an estimated 80% of previously in scope companies from mandatory reporting. The simplified reporting standards (ESRS) are also being cut down, with mandatory data points reduced by roughly 60%.

Other jurisdictions are moving in different directions entirely. It's worth noting the US and EU pullback isn't a universal global trend. The UK, Japan, and several other markets have continued rolling out their own sustainability disclosure requirements aligned with ISSB standards on their own timelines, largely independent of the US and EU developments described above. A company operating in only one or two of these markets faces a very different compliance picture than a company operating across all of them, which is part of why "what does ESG regulation require" no longer has a single clean answer.

What this means practically for a business right now:

  • Mandatory, enforceable ESG disclosure obligations are currently concentrated at the state level (like California) and for larger EU exposed companies, not a single unified global standard.

  • Voluntary reporting frameworks remain fully active and are, if anything, more important now as a way to signal credibility to investors and customers in the absence of binding federal rules.

  • Companies operating internationally should expect to track multiple, evolving jurisdictional requirements rather than one stable global rulebook. This is exactly the kind of fragmentation a strong internal ESG data process is built to handle.


How this gets implemented: rather than reporting reactively to whichever rule is currently enforceable, most credible ESG programs build their data collection around the most rigorous applicable standard (often the EU's ESRS or the ISSB's IFRS S1/S2) so that scaling up or down to meet a shifting patchwork of state and national rules doesn't require rebuilding the whole reporting process each time.


Chronological timeline of the 2024 to 2026 US and EU regulatory shifts, plus a before and after comparison of CSRD's scope thresholds.

Section takeaway: The regulatory picture has moved a lot since 2024. The US federal climate rule is being rescinded, while the EU has sharply narrowed CSRD's scope. Mandatory ESG disclosure today is patchier and more jurisdiction specific than it looked two years ago, which makes voluntary standards and strong internal data infrastructure more important, not less.

Key Takeaways

  • ESG has three pillars: environmental, social, governance. Every company needs to figure out which issues within each pillar are actually material to its business, rather than trying to address everything at once.

  • ESG, sustainability, and CSR are related but distinct: sustainability is the long term goal, CSR is the values framework, and ESG is the measurable, reportable accountability layer.

  • The business case for ESG is concrete: cost savings, customer loyalty, easier access to capital, and stronger talent retention, not just reputation management.

  • Building an ESG program is an 8 step cycle: stakeholder input, materiality assessment, baseline, goal setting, roadmap, framework selection, data reporting, and revision. Skipping materiality and baseline steps is the most common reason programs lose focus.

  • Ownership is distributed, typically anchored by board or C suite oversight and a sustainability or ESG officer, but executed across finance, legal, marketing, HR, and IT.

  • Measurement blends quantitative and qualitative metrics, feeding both internal risk management (like triple bottom line tracking) and external ESG ratings.

  • The regulatory landscape has shifted significantly in 2026: the US SEC climate rule is being rescinded, EU CSRD scope has been cut by roughly 80% under the Omnibus reform, and mandatory disclosure is now more concentrated at the state and larger company level, making voluntary reporting standards and internal data readiness more important than ever.


Comments


bottom of page