Data processes
Institutions’ internal procedures should provide for the implementation of sound information management systems to identify, collect, structure and analyse the data that is necessary to support the assessment, management and monitoring of ESG risks. Such systems should be implemented across the institution as part of the overall data governance and IT infrastruc-ture. Institutions should regularly review their practices to ensure they remain up to date with public (e.g. increased data availability due to regulatory initiatives) and market developments and should have in place arrangements to assess and improve data quality.
Institutions’ internal procedures should ensure that institutions gather and use the infor-mation needed to assess, manage, and monitor the current and forward-looking ESG risks they may be exposed to via their counterparties, by aiming at collecting client- and asset-level data at an appropriately granular level.
Institutions’ internal procedures should build on both internally and externally available ESG data, including by regularly reviewing and making use of sustainability information disclosed by their counterparties, in particular in accordance with European Sustainability Reporting Standards developed under the Directive 2013/34/EU (opens EUR-Lex in a new tab) or voluntary reporting standard for non-listed Small and Medium-size Enterprises (SMEs) as per the Communication COM (2023) 535 on the SME relief package(9).
Institutions should assess which other sources of data would effectively support the assessment, management and monitoring of ESG risks, such as information obtained through engagement with clients and counterparties as part of new and existing business relationships, or third-party data. When institutions use services of third-party providers to gain access to ESG data, institutions should ensure they have a sufficient understanding of the sources, data and methodologies used by data providers, including their potential limitations.
Where the quality or availability of data is initially not sufficient to meet risk management needs, institutions should assess these gaps and their potential impacts. Institutions should take and document remediating actions, including the use of estimates or proxies, e.g. based on sectoral- and/or regional-level characteristics and, when feasible, making adjustments to account for counterparty-specific aspects. Institutions should seek to reduce the use of estimates and proxies over time as ESG data availability and quality improve.
For large corporate counterparties as defined by Article 3(4) (opens EUR-Lex in a new tab) of Directive 2013/34/EU (opens EUR-Lex in a new tab), institutions should consider collecting or obtaining the following data points, where applicable:
For environmental risks:
geographical location of key assets (e.g. production sites) and exposure to environmental hazards (e.g. temperature-related, wind-related, water-related, solid mass-related hazards) at the level of granularity needed for appropriate physical risk analysis, and availability of insurance;
current and, if available, targeted greenhouse gas (GHG) scope 1, 2 and 3 emissions in absolute value and, where relevant, in intensity value;
dependency on fossil fuels, either in terms of economic factor inputs or revenue base;
energy and water demand and/or consumption, either in terms of economic factor inputs or revenue base;
level of energy efficiency for real estate exposures and the debt servicing capacity of the counterparty;
the current and anticipated financial effects of environmental risks and opportunities on the counterparty’s financial position, financial performance and cash flows;
transition-related strategic plans, including transition plan for climate change mitigation disclosed in accordance with Article 19a (opens EUR-Lex in a new tab) or Article 29a (opens EUR-Lex in a new tab) of Directive (EU) 2022/2464 (opens EUR-Lex in a new tab), when available;
b. For social and governance risks:
alignment with the OECD Guidelines for Multinational Enterprises, UN Guiding Principles on Business and Human Rights and International Labour Organisation Declaration on Fundamental Principles and Rights at Work;
negative material impacts on own workers, workers in the value chain, affected communities and consumers/end-users including information on due diligence efforts or processes to avoid and remediate such impacts.
For exposures towards other types of counterparties than large corporates, institutions should:
determine the data points needed for the identification, measurement and management of ESG risks, considering the list provided in paragraph 28 to support that assessment;
where needed to address data gaps, use expert judgment, qualitative data, portfolio-level assessments and proxies in line with paragraph 27.