The Regulatory Paradox: Less Reporting for Companies, More Scrutiny for Banks
The CSRD was designed to require approximately 50,000 companies across the EU to publish sustainability reports. Then came the Omnibus package in early 2025, which slashed that number to roughly 5,000–8,000 — a reduction of 80–90%. Many SMEs and mid-market firms were effectively let off the hook.
But for banks and institutional investors, the direction of travel is the exact opposite. While corporate reporting obligations shrank, EBA ESG risk demands tightened. The ESG data market is marked by a hierarchical structure, with a handful of major vendors dominating — see our analysis of the rapidly increasing ESG data market. Banks must still assess the ESG risks embedded in their portfolios; they simply now have far less counterparty data to work with. The message from regulators is clear: even if companies are not required to report, financial institutions are required to know.
What Are the EBA ESG Risk Guidelines?
The EBA ESG risk guidelines establish a common framework for how banks and financial institutions across the EU must integrate ESG-related risks into their internal risk management processes, governance structures, and business strategies.
The new guidelines set binding expectations covering everything from board-level oversight to loan-book transition planning. At their core, they reflect a straightforward regulatory logic: climate change, biodiversity loss, social disruption, and governance failures are not abstract sustainability concerns. They are financial risks. Banks that fail to manage them are carrying unpriced exposures on their balance sheets. For more on how ESG data strengthens supply chain risk management, see our detailed analysis.
“ESG risks, and in particular environmental risks, may have a material impact on the safety and soundness of institutions… These guidelines aim to ensure that institutions develop robust and comprehensive approaches to the management of ESG risks.”
EBA Final Guidelines on ESG Risk Management, June 2024
Who Do the EBA ESG Risk Requirements Apply To?
The guidelines apply to all credit institutions and investment firms subject to EU prudential regulation under the Capital Requirements Directive (CRD). This broadly covers:
- Large universal banks and systemically important institutions (SIIs)
- Mid-size and regional banks operating across EU member states
- Investment firms subject to CRD V/CRR2
- EU subsidiaries of international banking groups
A proportionality principle applies, meaning smaller, non-complex institutions (SNIs) face a lighter burden, but no institution is exempt. Across the EU there are approximately 6,000 credit institutions in scope.
Key Timelines
| Milestone | Date |
|---|---|
| Guidelines published (final) | June 2024 |
| Entry into force | January 2025 |
| Large institutions: full compliance | January 2026 |
| Small and non-complex institutions (SNIs) | January 2027 |
| Full transition plan integration (all institutions) | 2025–2030 |
What Do the EBA ESG Risk Guidelines Demand?
1. Governance and Strategy
Boards and senior management must have defined ESG risk responsibilities. Risk appetite frameworks must explicitly address ESG risk dimensions. Business strategies must be assessed for alignment with EU sustainability goals.
2. Internal Risk Management Integration
ESG risks must be integrated into existing risk categories — credit risk, market risk, operational risk, and liquidity risk frameworks must all be updated to capture ESG risk drivers. For a deeper look at how SFDR and ESG data drive value across these frameworks, see our earlier analysis.
3. Transition Plans
Institutions must develop credible, time-bound transition plans showing how their balance sheets align with a 1.5°C pathway, covering Scope 1, 2 and 3 financed emissions, sector decarbonisation trajectories, and milestones at 1-year, 3-year and 10-year horizons. For context on how ESG data supports Science Based Targets, see our guide.
4. Materiality Assessment
Institutions must conduct structured double materiality assessments, identifying where ESG risks are material to their own financial health, and where their activities have a material impact on the environment and society.
5. Disclosure and Reporting
ESG risk findings must feed into both internal reporting and external disclosures, aligned with CSRD and the Pillar 3 ESG disclosure framework. See also our breakdown of PAI and how ESG data drives sustainable finance under the SFDR.
What Data Does EBA ESG Risk Management Require?
Meeting the EBA ESG risk guidelines is fundamentally a data problem. Banks need granular, reliable ESG data on their counterparties across four key categories:
Environmental Data
- GHG emissions: Scope 1, 2 and 3 (including financed emissions via PCAF methodology)
- Carbon intensity: revenue-weighted and asset-weighted
- Physical risk exposure: flood zones, heat stress, sea level rise, wildfire risk
- EU Taxonomy eligibility and alignment ratios
- Biodiversity footprint: land use, water stress, deforestation linkage
Social Data
- Workforce metrics: employee turnover, gender pay gap, diversity ratios
- Health and safety: accident rates and fatalities
- Supply chain labour standards, particularly for high-risk sectors
Governance Data
- Board composition and independence
- Executive remuneration linked to ESG targets
- Anti-corruption and anti-bribery policies
- Controversy and sanctions screening
Loan-Book Specific Data
- Counterparty ESG scores and ratings
- Sector classification and NACE codes linked to ESG risk profiles
- Real estate energy performance certificates (EPCs) for mortgage portfolios
- SME ESG proxies — a major challenge, given that most SMEs do not report ESG data
Why the EBA ESG Risk Data Gap Is So Hard to Close
Many banks are discovering that the data they need simply does not exist in structured, accessible form, particularly for smaller and mid-market borrowers. Large listed corporates increasingly publish ESG data, but the loan books of most European banks are dominated by SMEs, private companies, and international counterparties that either do not report ESG data voluntarily or report it inconsistently.
“The quality and availability of ESG data remains one of the most significant obstacles to implementing robust ESG risk management… Institutions should use best-effort approaches and proxies where data is unavailable, while continuing to improve data collection over time.”
EBA Final Guidelines on ESG Risk Management, June 2024
Why Traditional ESG Data Collection Cannot Solve This
Manual collection — questionnaires, relationship manager outreach, analyst research — works for a portfolio of 50 companies. It breaks down completely at 5,000 or 50,000. The major global providers (Bloomberg, MSCI, Refinitiv, Sustainalytics) cover large listed companies well, but their universe of 10,000–15,000 companies leaves the bulk of a typical bank’s loan book — private, unlisted, regional, international — completely uncovered.
That is exactly what Cleartraced has built around. Our AI pipeline actively finds, extracts, and structures ESG-relevant data from across the open web: regulatory filings, company websites, news sources, public procurement records, environmental permits, and more. Any company, anywhere, at scale. See our ESG data use cases for concrete examples.
Three Additional Areas to Watch
The Omnibus rollback worsens the data problem. Fewer counterparties will now publish structured sustainability data. The regulatory obligation on banks did not shrink with CSRD. The data supply did.
Climate stress testing is becoming mandatory. Banks must model how orderly transition, disorderly transition, and physical risk scenarios affect their capital adequacy. Climate-related financial disclosures — originally shaped by the TCFD framework and now embedded in ISSB and ESRS standards — are the reporting backbone for these exercises.
Supervisory pressure is rising. NCAs across the EU are already factoring EBA ESG risk management into SREP assessments. Weak data capabilities or missing transition plans can result in Pillar 2 capital add-ons.
The Bottom Line: Act Now
The window for treating EBA ESG risk compliance as a future problem is gone. Large institutions face full compliance from January 2026. Supervisors are already asking questions. And building reliable ESG data coverage across tens of thousands of counterparties takes time.
Banks that begin now will have better risk models, cleaner loan books, lower regulatory capital pressure, and stronger client relationships. Those that delay risk regulatory sanction and being caught flat-footed when the next climate-related credit event hits their portfolio. For a broader perspective on how ESG data is used across the financial sector, see our overview.
EBA ESG Risk Compliance Checklist
Use this as a starting point to assess your institution’s readiness:
- Assign board-level ESG risk ownership. Confirm that your management body has a named individual or committee responsible for ESG risk oversight.
- Update your risk appetite framework. Add explicit ESG risk dimensions to your existing RAF — covering climate, biodiversity, social, and governance factors.
- Map ESG risks to existing risk categories. Review how environmental, social and governance drivers feed into your credit, market, operational, and liquidity risk models.
- Conduct a double materiality assessment. Identify where ESG risks are material to your financial health and where your lending activities impact the environment and society.
- Audit your counterparty ESG data coverage. How many borrowers in your loan book have reliable ESG data? Identify the gaps — especially among SMEs, private companies, and international counterparties. Explore how an ESG data API can automate this process.
- Draft a transition plan. Set 1-year, 3-year, and 10-year milestones for portfolio alignment with a 1.5°C pathway, including Scope 1, 2 and 3 financed emissions targets.
- Stress-test climate scenarios. Model orderly transition, disorderly transition, and physical risk scenarios against your capital adequacy.
- Align disclosures. Ensure ESG risk findings flow into both your Pillar 3 ESG disclosures and CSRD-aligned reporting.
Further Reading
How Cleartraced Can Help
Built to solve the EBA ESG data problem
Our AI pipeline finds and extracts ESG data on any company globally — including the SMEs, private companies, and international counterparties that traditional providers cannot reach.
Custom Coverage
Built around your exact portfolio — not a generic universe.
Full Traceability
Every datapoint links to its exact source — audit-ready.
Regulatory Alignment
Structured for EBA, EU Taxonomy, CSRD, and PCAF.
API Integration
Receive ESG data directly into your systems via REST API.
