Quick Read

On 2 July 2026, EU Regulation 2024/3005 brought ESG rating providers under ESMA supervision, requiring methodology transparency and governance standards—but the regulation does not extend to the unaudited data submissions companies provide to raters, creating an asymmetry where the rating methodology is now transparent and regulated while the underlying information remains unexamined and ungoverned. This transparency requirement transforms the submission from a marketing exercise into a governance obligation, as companies can now identify which datapoints carry weight in ratings and are therefore expected by boards to manage them accordingly. The paper examines this evidence gap and why the parties best positioned to close it—assurance providers and auditors—are structurally excluded from doing so under current frameworks.

IN BRIEF

  • Regulation (EU) 2024/3005 on the transparency and integrity of ESG rating activities applied from 2 July 2026. It brings ESG rating providers operating in the EU under the direct supervision of ESMA.

  • Providers already operating in the EU must notify ESMA by 2 August 2026 and apply for authorisation or recognition by 2 November 2026, failing which they must cease their EU activities.

  • The Regulation imposes methodology transparency, conflict-of-interest management, governance and independence requirements on rating providers. It imposes nothing on the companies being rated.

  • ESG ratings submissions are prepared internally, typically by investor relations or the sustainability team. No accreditation regime, assurance standard or independent review requirement applies to them.

  • Because methodologies must now be disclosed, the submission has ceased to be a black box and become a controllable variable. The absence of any control over it is correspondingly harder to explain.

Executive summary

On 2 July 2026, ESG rating became a regulated financial service in the European Union. Regulation (EU) 2024/3005 requires ESG rating providers operating in the EU to be authorised by ESMA, to disclose their methodologies, to manage conflicts of interest, and to meet governance and independence standards. Providers already active in the EU must notify ESMA by 2 August 2026 and submit an application for authorisation or recognition by 2 November 2026, or cease their EU activities.

This is a substantial and overdue reform, and it addresses exactly half of the problem.

An ESG rating is an opinion, formed by applying a methodology to a body of information. The Regulation now governs the opinion, the methodology, and the party that forms it. It governs nothing about the information. That information — hundreds of datapoints, submitted annually, describing policies, governance structures, incident histories, emissions, targets, board composition and supply chain practices — is assembled by the rated company's own staff, checked by nobody outside it, supported by evidence nobody examines, and submitted.

THE ASYMMETRY, STATED ONCE

Your ESG rating is now a supervised opinion about an unsupervised submission. The regulator improved the middle of the chain and left both ends untouched. One of those ends is inside your company.

This paper sets out what the Regulation actually does, why the transparency requirement makes the submission a governance problem rather than a marketing exercise, where the evidence gap sits, and why the obvious parties to close it are structurally excluded from doing so.

1. What the Regulation does

Diagram showing three boxes representing ESG rating data governance stages, with the regulation's scope highlighted in the mi

Figure 1 — The regulation improved the middle box. The submission and the consequences sit outside it.

Term

Definition

ESG rating

Under Regulation (EU) 2024/3005: an opinion, a score, or a combination of the two, based on an established methodology and a defined ranking system of rating categories, regarding the ESG profile of, the exposure to ESG risks of, or the impact on ESG factors of a legal person, financial instrument, financial product, or a public authority.

ESG rating provider

A legal person whose occupation includes the issuance and publication or distribution of ESG ratings on a professional basis. From 2 July 2026, providers operating in the EU require authorisation by ESMA.

Date of application

2 July 2026. Providers already operating in the EU must notify ESMA by 2 August 2026 and apply for authorisation or recognition by 2 November 2026.

Methodology transparency

The Regulation requires disclosure of the methodologies, models and key rating assumptions used. This is the provision with the greatest consequence for rated companies, because it removes the excuse that the score is unknowable.

Conflict of interest requirements

The Regulation imposes governance and independence obligations on rating providers, including in relation to activities that could compromise the independence of the rating.

Two provisions matter more than the rest for a company being rated, and neither is addressed to it.

Methodology transparency changes the company's position

Until 2 July 2026, a company that scored poorly could reasonably claim the methodology was opaque, the weightings unknown, and the outcome unpredictable. That claim is now substantially weaker. Where a rating provider is required to disclose its methodology, models and key assumptions, a company can determine which datapoints carry weight, which do not, and where its submission is failing to reach the evidence.

A variable that is knowable and consequential is a variable that a board is expected to govern. The transparency requirement was written to discipline the raters. Its practical effect is to remove a company's defence for not managing its own submission.

Conflict rules close the obvious door

The Regulation imposes independence and conflict-of-interest obligations on rating providers in respect of activities that could compromise the independence of their rating activities. The clear implication is that a rating provider cannot sell a rated company assistance in improving the rating that provider assigns.

This forecloses the arrangement that would otherwise have emerged: the rater as advisor. It also leaves the rated company with a problem, which the third paper in this series takes up. If the rater cannot help, and the consultant who prepared the submission cannot independently examine it, who can?

A regulator who forbids the referee from coaching has not thereby appointed anyone to check the team sheet.

2. What the submission actually is

It is worth being concrete, because executives who have never seen one imagine something more governed than it is.

An ESG ratings submission is a response to a structured questionnaire, running in most cases to several hundred datapoints, covering environmental performance, social practices, governance structures, controversies, and disclosure quality. It is completed on a portal, against a deadline, by a small team. Each response is either a data value, a yes or no, or a reference to a public disclosure. Some responses permit supporting documentation to be uploaded; most do not require it.

Attribute

Financial statements

ESG ratings submission

Prepared by

Group finance, under a documented close process

Investor relations or sustainability, typically two to four people

Governed by

IFRS or local GAAP

The rating agency's methodology, disclosed but not designed for comparability across agencies

Internal control

ICFR, with management assertion and, under SOX 404, auditor attestation

None required, and in most companies none exists

Independent examination

Statutory audit, reasonable assurance, by an accredited auditor

None. No accreditation regime applies.

Evidence retained

Audit file, retained under regulation

Portal submission. Working papers, where they exist, are personal.

Accountability for error

Named directors, with statutory consequences

Unassigned

Consequence of error

Restatement, regulatory action

A published score that influences index inclusion, credit margins and procurement, and that is difficult to correct

The comparison is not rhetorical

A large listed company will spend several million euros a year assuring a set of financial statements whose principal readers are analysts.

It will spend nothing at all on the ESG submission that determines whether it appears in an index those analysts must track.

The disproportion is not a judgement about the relative importance of the two. It is a description of where the governance was built and where it was not.

3. Where the exposure sits

The absence of independent examination produces three distinct exposures, and companies tend to worry about the least serious of them.

Exposure one: the score is lower than the performance

This is the exposure companies notice, because it is the one that appears in an investor relations report. Points are lost because a practice is undisclosed, or disclosed in language the methodology does not recognise, or disclosed in a document the analyst did not find. The remedy is administrative and the cost of the failure is a lower score.

Exposure two: the submission asserts something the company cannot support

This is the exposure companies do not notice, because nothing in the process surfaces it. The rating agency does not verify the response. It scores it. A company may therefore assert, in a submission, that it conducts human rights due diligence across its supply chain, that its board reviews climate risk quarterly, or that it has a functioning grievance mechanism — and the assertion enters a published score without anyone inside the company being asked to produce the evidence.

The assertion is now on the record. It has been relied upon by index providers, asset managers and lenders. And it sits in a submission that nobody independent has examined.

A rating agency does not audit your submission. It publishes a score derived from it. The first person to test the assertion may be a regulator, a short seller, or an acquirer's diligence team.

Exposure three: the submission contradicts the assured sustainability statement

The sustainability statement is, for in-scope CSRD reporters, subject to limited assurance under ISSA 5000 from 15 December 2026. The ratings submission is not. Both describe the same organisation, in the same year, to different audiences, using different definitions, prepared by different teams.

Where the two disagree — a different emissions boundary, a different count of incidents, a different characterisation of the same policy — the discrepancy is visible to anybody who reads both. Nobody inside most companies has ever read both.

A FIVE-MINUTE TEST FOR THE NEXT AUDIT COMMITTEE MEETING

Take the last ESG ratings submission and the last assured sustainability statement. Compare the emissions figures, the incident counts, and the description of the whistleblowing mechanism. If they differ, ask who reconciled them. The answer will be that nobody did, because nobody was asked.

4. Why nobody has fixed this

The gap has persisted for a decade, through the growth of ESG ratings into a market that shapes capital allocation, for four structural reasons rather than through negligence.

  1. The submission has no owner in the accountability architecture. It is not a financial disclosure, so finance does not own it. It is not a regulatory filing, so legal does not own it. It is not a sustainability report, so the reporting team does not own it. Investor relations completes it, and investor relations does not own controls.

  2. No accreditation regime covers it. Certification under ISO/IEC 17021-1 examines management systems. Verification under ISO/IEC 17029 examines claims. Assurance under ISSA 5000 examines reported sustainability information. A ratings submission is none of these things as a matter of form, though it contains assertions that would fall within all three.

  3. The rating agency is not a regulator and does not check. Its business is to score what is submitted, at scale, across thousands of issuers. It is not resourced to verify, it is not accredited to verify, and following Regulation (EU) 2024/3005 it is not permitted to be commercially entangled in improving what it scores.

  4. The result is invisible until it is not. An unsupported assertion in a submission produces no immediate consequence. It produces a consequence when somebody with an interest in the company being wrong goes looking, which is generally at the worst moment.

5. What changed on 2 July 2026

Three things, and their combined effect is greater than any of them separately.

Change

What it does to the rater

What it does to the rated company

ESMA authorisation

Rating providers must be authorised, and must notify ESMA by 2 August 2026 and apply by 2 November 2026

Raises the credibility of the score, and therefore the reliance placed on it and the consequence of it being wrong

Methodology transparency

Methodologies, models and key assumptions must be disclosed

Removes the defence that the score was unknowable. The submission becomes a governable variable.

Conflict of interest and independence requirements

Constrains activities that could compromise independence

Forecloses the rater as a source of help, leaving the rated company to establish its own control

Note the direction of the third row. A regulation designed to protect the integrity of ratings has, as a by-product, removed the most convenient party a company might have leaned on. This is precisely what happened in financial audit when non-audit services were restricted after Enron: the effect was not that the work stopped being necessary. The effect was that companies had to build the capability internally, and buy the independent examination from somebody with nothing else to sell them.

6. The shape of the answer

The Non-Financial Audit Universe paper in this series identified ESG ratings submissions as one of four significant domains for which no accredited independent testing regime exists. This paper has explained why that matters now rather than in 2020.

The answer has three parts, and the second and third are the subject of Papers 20 and 21.

  • Put the submission in the audit universe. A named evidence owner. A last-tested date, which will read "never". A risk score, which will be high, because materiality is high, external reliance is high, consequence of error is high, and control maturity is at floor.

  • Understand where the points are actually lost. Not, as most companies assume, in performance. In disclosure, in mapping, and in evidence. Paper 20 sets out the four categories and the very different remedies each requires.

  • Obtain independent pre-submission review from a party that can conclude adversely. Not the rater, which is now constrained from doing so. Not the consultant who drafted the submission. Paper 21 sets out what such a review is, and — more importantly — what it must not become.

THE ONE SENTENCE TO TAKE TO THE BOARD

As of 2 July 2026, the party forming an opinion about our ESG performance is supervised by a European regulator, and the information they form it from is prepared by three people in investor relations and checked by nobody.

Questions this paper answers

When did the EU ESG Ratings Regulation take effect?

Regulation (EU) 2024/3005 on the transparency and integrity of ESG rating activities applied from 2 July 2026. ESG rating providers already operating in the EU must notify ESMA by 2 August 2026 if they wish to continue, and must apply for authorisation or recognition by 2 November 2026, failing which they must cease their EU activities.

What does the ESG Ratings Regulation require of rating providers?

Authorisation by ESMA, which becomes their direct supervisor. Disclosure of methodologies, models and key rating assumptions. Management of conflicts of interest, including constraints on activities that could compromise the independence of rating activities. Governance and independence standards. It makes ESG rating a supervised financial service in the EU for the first time.

Does the ESG Ratings Regulation apply to the companies being rated?

No. The Regulation governs ESG rating providers. It imposes no obligation on rated companies, and it does not require that a ratings submission be independently reviewed, supported by evidence, controlled, or governed. The opinion is now supervised. The information from which the opinion is formed is not.

Why does methodology transparency matter to a rated company?

Because it removes the defence that the score was unknowable. Where a rating provider must disclose its methodology, models and key assumptions, a company can determine which datapoints carry weight and where its submission is failing to reach the evidence. A variable that is both knowable and consequential is one a board is expected to govern, and the ratings submission has just become one.

Can an ESG rating agency help a company improve its rating?

The Regulation imposes independence and conflict-of-interest obligations on rating providers in respect of activities that could compromise the independence of their rating activities. The clear implication is that a provider cannot sell a rated company assistance in improving the rating that provider assigns. This forecloses the arrangement in which the rater acts as advisor, and leaves the rated company to establish its own control over the submission.

Who checks an ESG ratings submission?

In most companies, nobody. The submission is prepared by investor relations or the sustainability team, completed against a deadline, and sent. No accreditation regime covers it: certification under ISO/IEC 17021-1 examines management systems, verification under ISO/IEC 17029 examines specific claims, and assurance under ISSA 5000 examines reported sustainability information. A ratings submission is none of these as a matter of form, notwithstanding that it contains assertions falling within all three.

What is the biggest risk in an unexamined ratings submission?

Not the lower score. The assertion that cannot be supported. A rating agency does not verify a response; it scores it. A company may therefore assert that it conducts supply chain human rights due diligence, or that its board reviews climate risk quarterly, and the assertion enters a published score relied upon by index providers, asset managers and lenders — without anyone inside the company having been asked to produce the evidence. The first party to test it may be a regulator, a short seller, or an acquirer's diligence team.

References and sources

  • Regulation (EU) 2024/3005 of the European Parliament and of the Council of 27 November 2024 on the transparency and integrity of Environmental, Social and Governance (ESG) rating activities, and amending Regulations (EU) 2019/2088 and (EU) 2023/2859. Published in the Official Journal of the European Union, December 2024. Date of application: 2 July 2026.

  • ESMA, ESG Rating Providers — supervisory information and application timelines. Notification deadline 2 August 2026; applications for authorisation from 2 August 2026 and at the latest by 2 November 2026.

  • ESMA, Final Report on draft regulatory technical standards under the ESG Ratings Regulation, 15 October 2025, submitted to the European Commission for adoption as delegated regulations.

  • Commission Delegated Regulation specifying the information to be included in applications for authorisation and recognition as an ESG rating provider, adopted 26 May 2026.

  • IAASB, ISSA 5000, General Requirements for Sustainability Assurance Engagements; effective for periods beginning on or after 15 December 2026.

  • Sarbanes-Oxley Act of 2002, section 201 — prohibited non-audit services, and the structural precedent for a regulator foreclosing the examiner from advising the examined.

  • Speeki, The Non-Financial Audit Universe (Whitepaper Series 1, Paper 03), July 2026, identifying ESG ratings submissions as a domain with no accredited independent testing regime.

About Speeki

Speeki is an accredited ESG assurance and certification body operating in more than 100 countries. Speeki provides management system certification, verification and validation, and sustainability assurance. Speeki does not provide consulting services. Its independence is structural.

For current details of Speeki's accreditations and their scope, please refer to speeki.com.

© 2026 Speeki. This paper is provided for general information and does not constitute legal, accounting or assurance advice.