The following is a guest article by Jack Reagan, Managing Director of UHY. The views expressed are solely those of the author.

Finance professionals are no strangers to complex regulatory and compliance frameworks, but the rapidly evolving ESG (Environmental, Social, and Governance) regulatory landscape often leaves CFOs and finance teams feeling challenged. With fragmented and inconsistent guidance at the U.S. state level and continuously evolving expectations internationally, the ESG compliance environment can daunt even the most experienced finance experts. However, meeting these disparate requirements is no easy task. As ESG regulations mature, companies are realizing that only by ensuring their internal audit capabilities are rigorous and impeccable can they truly meet these expectations.

With this in mind, CFOs and finance teams need to carefully consider the following three key questions when conducting internal audits and laying the groundwork for successful long-term ESG reporting.

1. What is our current ESG strategy and risk landscape?

To ensure internal consistency and establish a clear baseline, companies need to collectively clarify where ESG risks reside, assess overall exposure, and fully understand the ESG challenges they face and the achievements they have made. Auditors must work closely with internal and external stakeholders to understand macro trends in the broader external ecosystem that could impact the ESG risk landscape, such as the potential impact of changes in partner networks on Scope 3 emissions or regulatory adjustments in international jurisdictions. Additionally, in-depth materiality assessments should be conducted to identify priority ESG areas—whether environmental or other issues—ensuring that significant matters are properly addressed. This will help companies further align their ESG roadmaps, identify collaboration and growth opportunities, and address various risks in the most appropriate and effective manner.

2. What are our organization's ESG governance expectations and culture?

Faced with numerous rules and priorities, a common mistake finance professionals make is rushing to address what seems most urgent at the moment. However, only by first accurately understanding how the organization views ESG compliance, the expectations it faces, and how existing infrastructure supports goal achievement can a coherent ESG reporting approach be developed. Companies can refer to frameworks issued by bodies such as the ISSB (International Sustainability Standards Board) to optimize their governance structures, streamline reporting requirements, and establish efficient governance processes. For example, the ISSB requires in-depth disclosure of processes, controls, and procedures related to ESG oversight, including the roles and responsibilities of boards, committees, and individuals involved in oversight. Therefore, auditors must collaborate with senior management, investors, and other parties to build a comprehensive reporting structure.

On this cultural foundation, auditors can work with key stakeholders to integrate governance structures and develop plans to achieve governance goals. This process typically includes:

  • Defining the organization's mandatory or voluntary requirements regarding ESG;
  • Mapping the operational structure, ESG-related risk owners, reporting lines, and end-to-end enterprise risk management (ERM) and strategic planning processes to identify areas for improved oversight and collaboration;
  • Creating opportunities for cross-organizational collaboration and increasing support from senior leadership.

This may seem obvious, but by first identifying these core elements and facts, auditors can build a "launchpad" that enables the organization to achieve results in a transparent and accountable manner.

3. What is our risk mitigation strategy?

Given the highly interconnected nature of today's business world, auditors are likely to identify numerous risk vectors. Adding to the complexity, as companies naturally evolve, new risks are bound to emerge, making a systematic and organized approach to risk mitigation essential for auditors. Effectively addressing risks requires considering multiple factors: based on materiality assessments, organizations need to weigh risk-specific factors, including which stakeholders are directly affected by the risk, the organization's risk appetite for that risk, remediation costs, and where the risk sits in the overall organizational risk "food chain."

Armed with these insights, auditors need to build a business case for "why a risk should be addressed" and "what remediation entails," and seek the necessary support from decision-makers. These response plans must be repeatedly stress-tested to anticipate the actual impact of remediation on direct stakeholders and the broader organizational ESG risk profile before implementation.

ESG compliance is one of the most challenging tasks finance teams continue to face. Unfortunately, for many finance professionals, this challenge is set to intensify as multinational companies face the arrival of CSRD (Corporate Sustainability Reporting Directive) Phase 2 and other new regulations. However, by focusing on the priority areas above, finance teams can ensure their audit work is as efficient as possible and lay the foundation for smoother compliance in the years ahead.