Quick Answer:
ESG reporting in Australia is no longer voluntary for entities above the Corporations Act thresholds. Group 1 began reporting for financial years starting 1 January 2025, Group 2 from 1 July 2026 and Group 3 from 1 July 2027. The reports are subject to assurance, and ASIC has already secured $34.7 million in court penalties across three greenwashing cases. That combination, mandatory data, external assurance and enforcement against inaccurate claims, is why ESG reporting has outgrown spreadsheets. The requirement is no longer to publish a number. It is to evidence where the number came from.
In this guide
- What ESG reporting is
- ESG reporting in Australia is no longer voluntary
- The part most organisations miss: assurance
- What inaccurate ESG reporting costs in Australia
- 6 risks of managing ESG reporting manually
- The ESG data you already hold
- What a digital risk management system is
- How it supports ESG reporting
- Who owns ESG reporting
- 8 steps to make the transition
- Bringing it together
- Frequently asked questions
For most of the last decade, ESG reporting in Australia was something an organisation chose to do.
It sat with marketing or the sustainability lead, the numbers were assembled once a year from whatever sources could be found, and nobody audited them.
All three of those conditions have now changed, and they changed while a lot of organisations were still treating ESG reporting as a communications exercise.
The data is mandatory for entities above the thresholds, it is subject to assurance, and the regulator has taken three companies to court over claims that did not hold up.
Dates and thresholds below were checked against ASIC and the AASB in August 2026. Requirements vary by entity type and reporting period.
What ESG Reporting Is
ESG reporting is the disclosure of how an organisation performs against environmental, social and governance measures, and how the risks attached to those measures are governed.
The environmental pillar covers emissions, resource use and climate exposure. The social pillar covers workforce practices, safety, training, conduct and community impact.
The governance pillar covers board oversight, accountability, ethics and risk management.
The distinction that matters most
ESG reporting is a financial disclosure regime in Australia, not an environmental one. The Australian standard asks how sustainability risks affect the entity’s cash flows, access to finance and cost of capital. That framing decides who owns it internally, and the answer is the chief financial officer and the board rather than a sustainability team working alone.
The social and governance pillars are where most Australian employers already hold data without realising it.
Training completions, incident records, policy acknowledgements, conduct investigations and board minutes are all ESG evidence.
They are usually spread across four systems owned by three functions, which is the practical problem this guide is about.
ESG Reporting In Australia Is No Longer Voluntary
Mandatory climate-related financial disclosure is now part of the Corporations Act, administered by ASIC, with the reporting content set by the Australian accounting standard AASB S2. It phases in by entity size across three groups.
| Group | Financial years starting | Revenue | Gross assets | Employees |
|---|---|---|---|---|
| Group 1 | 1 Jan 2025 to 30 Jun 2026 | $500m or more | $1bn or more | 500 or more |
| Group 2 | 1 Jul 2026 to 30 Jun 2027 | $200m or more | $500m or more | 250 or more |
| Group 3 | On or from 1 Jul 2027 | $50m or more | $25m or more | 100 or more |
An entity must meet at least two of the three criteria.
Separate tests capture National Greenhouse and Energy Reporting registered corporations from Group 1, and asset owners such as registered schemes and superannuation entities with $5 billion or more in assets from Group 2.
The thresholds are set out in Table 2 of ASIC Regulatory Guide 280, and ASIC also publishes guidance on who must prepare a sustainability report.
The threshold that catches ordinary Australian businesses
Group 3, from 1 July 2027: revenue of $50 million, or gross assets of $25 million, or 100 employees, meeting two of the three. A great many organisations that have treated ESG reporting as a large-company problem are captured by that. The lead time looks generous and it is not, because the first report needs a full year of collected data behind it.
Two further points decide how much work this is.
Scope 3 emissions, meaning those in your value chain, are not required in an entity’s first reporting year and become mandatory from the second, which means supplier data collection has to begin during year one.
And entities below every threshold are still affected, because reporting entities must understand their value chain and will ask their suppliers for exactly this information.
If you want the strategic view of how this converges with your wider compliance obligations, see GRC and ESG convergence. This guide stays on the reporting system itself.
The Part Most Organisations Miss: Assurance
A sustainability report is not simply published. It is assured.
The Australian Auditing and Assurance Standards Board has issued standards for sustainability assurance engagements, including ASSA 5000 covering general requirements and ASSA 5010 covering the timeline for audits and reviews of information in sustainability reports under the Corporations Act. Current detail sits with the AUASB.
This single fact changes what an ESG reporting process has to produce. An assurer does not accept a figure.
They ask where it came from, who calculated it, what the source record was, whether the method was consistent with last period, and who reviewed it.
The discipline is the same one described in audit-ready risk management.
| What you report | What an assurer asks for | Where a manual process fails |
|---|---|---|
| An emissions figure | The underlying meter or invoice data, the calculation method and any conversion factors used | The spreadsheet holds the result, and the source files sit in an inbox |
| A training completion rate | Which employees, which course version, on which dates | The learning system holds it, the report holds a number typed in from a screenshot |
| An incident or safety metric | The incident records behind it, including how the categories were defined | Categories changed midway through the period and nobody recorded when |
| A governance claim about board oversight | The board papers and minutes showing the risk was actually considered | The claim is true and the evidence was never assembled |
| A prior-period comparison | That the method did not change, or a documented explanation of the change | The method changed when a person changed, and it was never written down |
Read the third column as a list of failure modes rather than a criticism.
Every one of them is normal in an organisation that has been reporting voluntarily, because voluntary reporting was never tested this way.
What Inaccurate ESG Reporting Costs In Australia
Greenwashing is usually discussed as a reputational risk. In Australia it is now a financial one with court judgments attached.
ASIC has run three greenwashing civil penalty actions to judgment, and the Federal Court imposed a combined $34.7 million in penalties.
| Case | Penalty | What the conduct was |
|---|---|---|
| Mercer Superannuation (ASIC’s first greenwashing case) | $11.3 million | Admitted making misleading statements about the sustainable nature and characteristics of some superannuation investment options |
| Vanguard Investments Australia | $12.9 million | Misleading claims about ESG exclusionary screens. The largest of the three |
| Active Super | $10.5 million | Invested in securities it had claimed were eliminated or restricted by its ESG investment screens |
Beyond the court actions, ASIC reported 47 regulatory interventions on greenwashing misconduct in the 15 months to 30 June 2024, including infringement notice payments of more than $123,000. The detail is in ASIC Report 791.
The pattern worth noticing in all three cases
None of these organisations were accused of not caring about sustainability. They were penalised because what they published did not match what their own records showed. That is a data and systems failure rather than an ethical one, and it is exactly the failure a manual ESG reporting process makes likely.
The lesson for organisations well outside financial services is the same.
Any public ESG claim, including one on a careers page or in a tender response, has to be supportable from a record you could produce on request.
Claims about safety performance, diversity, training or emissions are all capable of being wrong in the same way, and the culture that lets an unsupportable claim go unchallenged is itself a risk worth managing. See cultural risk management.
6 Risks Of Managing ESG Reporting Manually
These are the failure modes that turn a reporting obligation into an exposure. Each is ordinary and none requires anybody to behave badly.
1. Inconsistent and unreliable ESG data
ESG data arrives from different systems in different formats, collected by people applying different definitions, with no shared controls over how it is captured.
Two sites count a contractor injury differently, a category changes mid-year, and the consolidated figure means less than it appears to.
Nobody notices until an assurer asks how the number was derived.
2. Poor visibility across ESG risks and metrics
Where ESG data lives in separate spreadsheets rather than one system, no stakeholder can see the whole disclosure position between reporting cycles, and visibility of the ESG controls is worse still.
A metric can drift for ten months and only surface when the annual pack is assembled, at which point the period is closed and nothing can be done about it.
This is the argument for continuous risk monitoring applied to ESG data.
3. Weak accountability and ownership
Manual ESG reporting concentrates work in whoever assembles the pack, which quietly transfers ownership and accountability to that person.
The operational owners of each ESG metric are not accountable for its accuracy because they never see it in context, so ownership exists on an organisation chart and nowhere else.
Ownership is the first thing an assurer tests and the hardest to retrofit.
The same problem appears wherever registers are maintained by hand, which is covered in why manual risk registers fail.
4. Difficulty demonstrating evidence and assurance
This is the risk that has grown most. A manual ESG process is built to produce a disclosure, not to produce an evidence trail showing the controls behind it.
When the assurer asks for the source record behind a figure from eight months ago, the answer involves searching an inbox.
5. Increased exposure to greenwashing claims
Where the ESG reporting process has no controls over its own inputs, the organisation is publishing disclosure claims it cannot substantiate to a regulator, an assurer, an investor or any other stakeholder.
As the three ASIC cases show, the intention behind the claim is not the point. The gap between the claim and the record is the point.
6. Inefficient reporting cycles and last-minute pressure
Manual ESG reporting compresses a year of data collection into a few weeks, which is when errors enter the disclosure.
Under assurance that compression is worse, because the assurer’s questions arrive after the team that assembled the data has returned to its normal work.
The ESG Data You Already Hold
Most Australian organisations approaching ESG reporting for the first time assume they need to start collecting.
Usually they need to start connecting. The social and governance pillars draw heavily on records that already exist somewhere in the business.
| ESG pillar | What is reportable | Where it usually already lives | What is missing |
|---|---|---|---|
| Social | Training and competency completion rates | The learning system, by person and course version | A link to the ESG metric, so the figure can be traced back |
| Social | Safety performance, incidents and near misses | The incident register | Consistent categories across sites, which is what makes the total defensible |
| Social | Workforce composition and turnover | Payroll and the human resources system | An agreed definition of the measure that does not change between periods |
| Governance | Policy acknowledgements and code of conduct coverage | The policy system, with dates and versions | Evidence that the acknowledgement was current at the time it mattered |
| Governance | Board oversight of material risks | Board papers and minutes | A record connecting the oversight to the specific risk being reported |
| Governance | Conduct matters and how they were handled | Investigation records | Central visibility, since these are often held locally |
| Environmental | Energy and fuel consumption | Invoices and meter data held by finance or facilities | A documented calculation method and conversion factors |
Read the fourth column. In almost every row the data exists and the connection does not.
That is why ESG reporting is usually a systems problem rather than a data collection problem, and why it sits naturally alongside the indicators you already report to the board rather than in a separate workstream.
A useful first exercise
Take three metrics from your last ESG report and try to produce the underlying record for each, without asking the person who compiled the report. How many you can produce, and how long it takes, is a fair prediction of how your first assurance engagement will go.
What A Digital Risk Management System Is
A digital risk management system is software that holds an organisation’s risks, controls, owners, incidents and evidence in one place, with a change history attached to each record.
Where a spreadsheet stores results, a digital risk management system stores the controls behind them and the trail that shows those controls were operating.
For ESG reporting and disclosure specifically, the relevant capability of a digital risk management system is not analytics.
It is that the record is created as a by-product of doing the work, rather than assembled afterwards.
A training completion recorded when it happens, tied to a person and a course version, is assurance-grade evidence of a control operating.
The same fact typed into a spreadsheet in October is a number with no controls behind it.
For how these systems are chosen and implemented, see the risk management software buyer’s checklist and implementing risk management software.
How A Digital Risk Management System Supports ESG Reporting
| Capability | What it does for ESG reporting | The risk it removes |
|---|---|---|
| 1. Centralised ESG risk and data management | Holds environmental, social and governance disclosure data in one register, with consistent categories and controls across sites and functions | Inconsistent definitions producing a consolidated figure nobody can defend |
| 2. Clear ownership and accountability | Assigns ownership of each ESG risk and metric to a named stakeholder who sees it year-round, not only at reporting time | Accountability collapsing onto whoever assembles the pack |
| 3. Linking ESG risks to controls and actions | Connects each ESG risk to the controls managing it and the corrective actions raised against them | Reporting a risk with no evidence anything is being done about it |
| 4. Real-time visibility and reporting | Gives real-time visibility of movement between cycles, so a drifting ESG metric surfaces while the period is still open | Discovering a problem after the reporting period has closed |
| 5. Stronger evidence for assurance and audits | Produces the source record, the owner, the date and the change history on request | An assurance finding because the evidence trail cannot be reconstructed |
| 6. Reducing greenwashing and disclosure risk | Ties every published ESG disclosure claim back to a record and a control that supports it | Publishing a claim the organisation’s own data does not substantiate |
The fifth row is the one that has changed in value most. Two years ago it was good practice. Under mandatory reporting with assurance, it is the difference between a clean opinion and a finding.
Why this belongs with risk rather than with finance alone
ESG data is risk data, and ESG controls are risk controls. Emissions exposure, safety performance, conduct, training and board oversight are all things you already track as risks. Reporting them separately from the risk management system means maintaining two versions of the same information, and the two will disagree at the worst possible moment. Managing them in one register is how integrated risk management handles operational data generally.
Who Owns ESG Reporting, And Who Has To Be In The Room
ESG disclosure fails on ownership more often than on data. The disclosure crosses more functions than almost any other reporting obligation, and where ownership is unclear the work defaults to whoever assembled last year’s pack. That is not accountability, it is availability.
| Stakeholder | What they own in ESG reporting | What the digital risk management system gives them |
|---|---|---|
| Board | Oversight of material sustainability risks, and the governance disclosure itself | Visibility of ESG risks and controls between reporting cycles, not only at year end |
| Chief financial officer | The disclosure as a financial report, including its accuracy and its assurance | An evidence trail behind every figure, produced on request rather than reconstructed |
| Risk and compliance | The ESG risk register, the controls attached to each risk and the regulatory watch | One register rather than a separate ESG spreadsheet that disagrees with the main one |
| Human resources | The social pillar: workforce data, training, conduct and policy acknowledgements | Training and policy records that already carry the dates and versions assurance requires |
| Safety | Incident, hazard and psychosocial data feeding the social disclosure | Consistent incident categories across sites, which is what makes a total defensible |
| Operations and procurement | Energy, resource and value-chain data, including Scope 3 supplier information | A single place to record supplier responses as they arrive rather than at year end |
| Company secretary | That board consideration of ESG risks is minuted and retrievable | Governance evidence linked to the specific risk being disclosed |
Every one of these stakeholders holds part of the disclosure and none holds all of it.
A digital risk management system does not resolve the ownership question, and it does make the answer visible, because an unowned ESG risk in a shared register is obvious in a way an unowned figure in a spreadsheet is not.
The ownership test worth running before your first mandatory report
Take each metric you expect to disclose and name the individual accountable for its accuracy. Not the function, the person. Where you cannot name one, that is the metric your assurance engagement will raise, and it is far cheaper to resolve it now than during the engagement.
8 Steps To Make The Transition
| Step | What you do | What good looks like at the end |
|---|---|---|
| 1. Review your current ESG reporting process | Map how each figure in last year’s report was produced, from source to publication | A written list of every metric with its source system and the person who produced it |
| 2. Identify key ESG risks and metrics | Decide what you actually have to report against your group and framework, rather than everything you could report | A shortlist tied to an obligation, not an aspiration |
| 3. Define ownership and responsibilities | Name an accountable owner for each metric, sitting where the data originates | Owners who can describe their metric without preparation |
| 4. Engage stakeholders across the organisation | Bring in finance, operations, human resources, safety and procurement early, since ESG data crosses all of them | Agreement on definitions before any system is configured |
| 5. Implement the system in phases | Start with the metrics that carry an obligation and the worst current evidence trail | One pillar reporting cleanly, rather than three reporting partially |
| 6. Align the system with your ESG frameworks | Configure categories and calculations to match the standard you report under | Data that maps to the disclosure without manual restatement |
| 7. Provide targeted training and support | Train the people who enter the data on what the figure is used for, not on the software | Fewer definitional errors at source, which is where they are cheapest to fix |
| 8. Monitor, review and improve | Review data quality between reporting cycles, not at the end of them | Issues found while the period is open and can still be corrected |
Where organisations most often go wrong
Steps 2 and 4, both skipped in favour of moving quickly to step 5. Configuring a digital risk management system before agreeing what is being disclosed and what each category means makes a second configuration almost certain, because the definitions get settled during the first reporting cycle instead of before it.
Bringing It Together
ESG reporting in Australia has moved through three changes at once.
It became mandatory above the Corporations Act thresholds, it became subject to assurance, and it became enforceable, with $34.7 million in greenwashing penalties already awarded.
Any one of those would have been manageable with a spreadsheet. Together they change what the process has to produce.
The requirement is no longer to publish a number. It is to evidence where the number came from, who owned it, how it was calculated and whether the method changed, at any point in the following years.
That is a risk management problem rather than a disclosure problem, and organisations that treat it as one have a significant advantage: most of the social and governance disclosure data is already sitting in their risk, incident, training and policy records, attached to controls that are already operating. The work is connecting it, not creating it.
If you are captured by Group 3 from 1 July 2027, the practical starting point is not software selection. It is step 1 above: map how each figure in your last ESG report was produced, and which control supported it, and see how many of them you could evidence today.
Frequently Asked Questions
1. What is ESG reporting?
ESG reporting is the disclosure of how an organisation performs against environmental, social and governance measures, and how the risks attached to them are governed. In Australia it is treated as a financial disclosure regime rather than an environmental one, because the standard asks how sustainability risks affect the entity’s cash flows, access to finance and cost of capital.
2. Is ESG reporting mandatory in Australia?
Yes, for entities above the thresholds in the Corporations Act. Mandatory climate-related financial disclosure phases in across three groups: Group 1 for financial years starting 1 January 2025, Group 2 from 1 July 2026, and Group 3 from 1 July 2027. An entity must meet at least two of three criteria on revenue, gross assets and employee numbers. Separate tests capture NGER registered corporations and large asset owners.
3. Which businesses does Group 3 capture?
From financial years starting 1 July 2027, entities meeting two of three criteria: consolidated revenue of $50 million or more, consolidated gross assets of $25 million or more, or 100 or more employees. This is the threshold that brings genuinely mid-sized Australian businesses into scope, and the first report needs a full prior year of data behind it.
4. Does an ESG report need to be audited?
Sustainability reports are subject to assurance. The Australian Auditing and Assurance Standards Board has issued standards for sustainability assurance engagements, including ASSA 5000 on general requirements and ASSA 5010 on the timeline for audits and reviews. The practical effect is that every figure needs a source record, a calculation method and an owner that can be produced on request.
5. What are the penalties for greenwashing in Australia?
ASIC has run three greenwashing civil penalty actions to judgment and the Federal Court imposed a combined $34.7 million: $12.9 million against Vanguard Investments Australia, $11.3 million against Mercer Superannuation, and $10.5 million against Active Super. ASIC also reported 47 regulatory interventions on greenwashing in the 15 months to 30 June 2024. In each court case the issue was that published claims did not match the organisation’s own records.
6. Why does ESG reporting need a risk management system rather than a spreadsheet?
Because the ESG obligation is now to evidence the number and the controls behind it, not simply to publish a disclosure. A spreadsheet holds a result. Assurance requires the source record, the calculation method, the owner, the date and whether the method changed between periods. A digital risk management system creates that evidence trail as a by-product of the work, which is the only way it exists reliably eight months later.
7. When do Scope 3 emissions have to be reported?
Scope 3 emissions, meaning those in an entity’s value chain, are not required in the first reporting year and become mandatory from the second reporting period. Because Scope 3 depends on supplier data, the collection process usually needs to begin during the first year rather than the second.
8. We are below every threshold. Does ESG reporting still affect us?
Indirectly, and often sooner than the thresholds suggest. Reporting entities must understand their value chain, which means larger customers will ask smaller suppliers for emissions, safety and governance information. Being unable to answer becomes a commercial problem with that stakeholder, in tenders and contract renewals, well before it becomes a legal one. Investors and lenders ask the same questions.
Sources
- ASIC, Who must prepare a sustainability report
- ASIC Regulatory Guide 280, Sustainability reporting, Table 2
- AASB, Australian Sustainability Reporting Standards frequently asked questions
- Australian Auditing and Assurance Standards Board, sustainability assurance standards
- ASIC 24-213MR, Vanguard greenwashing action results in record $12.9 million penalty
- ASIC 24-173MR, First greenwashing case results in $11.3 million penalty for Mercer
- ASIC 25-042MR, Active Super ordered to pay $10.5 million penalty
- ASIC Report 791, Interventions on greenwashing misconduct 2023 to 2024
Read more
- GRC and ESG convergence in Australia
- Risk management: the complete guide for Australian businesses
- The regulatory changes already in force
- Comparing risk management systems in Australia
- Integrated risk management
- The Australian Sustainability Standards
- Key Risk Indicators: Why KRIs Matter In Modern Risk Management?
- Implementing Risk Management Software: 5 Essential Steps in a Step-by-Step Guide
- Wage Theft, Psychosocial Risk, ESG: Why 2026 Is the Breaking Point for Legacy GRC Tools in Australia
- The Top 10 Risk Management Systems Every Australian Business Should Consider in 2026
See how Sentrient supports governance, risk and compliance
Sentrient brings governance, risk and compliance together so policy, training, incident and risk records sit in one system. That matters when an assurer or a regulator asks you to show how a figure was produced, and when.
Disclaimer: This article is general information, not legal advice. Reporting thresholds, commencement dates and assurance requirements were checked against ASIC, the AASB and the AUASB in August 2026 and can change. Confirm your position with the relevant regulator or a qualified adviser before acting.
