Executive Summary
With SEBI's BRSR Core assurance mandate entering full force for the top 150 listed companies in FY2026-27, enterprises face a critical inflection point in how they collect, govern, and verify ESG data. Building a credible, audit-ready ESG data architecture is no longer a future aspiration—it is an immediate boardroom imperative.
<p><strong>Executive Summary:</strong> The Securities and Exchange Board of India's (SEBI) Business Responsibility and Sustainability Report (BRSR) Core framework has redefined the ESG disclosure landscape for Indian listed companies. As mandatory third-party assurance requirements expand to the top 150 listed entities by market capitalisation in FY2026-27—with a broader rollout anticipated for the top 1,000 by FY2027-28—the quality of underlying ESG data infrastructure has become the decisive variable separating compliant, credible disclosures from those that invite regulatory scrutiny or investor scepticism. This article examines the structural imperatives of building a robust BRSR Core-aligned ESG data architecture, the common failure modes organisations encounter, and the strategic actions that sustainability and compliance leaders must take now.</p>
<h2>The BRSR Core Mandate: Where Indian ESG Reporting Stands Today</h2> <p>SEBI introduced the BRSR framework in 2021 as a replacement for the Business Responsibility Report (BRR), anchoring Indian ESG disclosure within the National Guidelines on Responsible Business Conduct (NGRBC). The BRSR Core—a subset of 49 high-value Key Performance Indicators (KPIs) drawn from the broader BRSR—was introduced through SEBI's circular of July 2023 and represents a qualitative leap in disclosure expectations. Unlike the broader BRSR, which permits self-declaration, BRSR Core KPIs require <strong>reasonable or limited assurance from an independent third-party assurance provider</strong>.</p> <p>The phased rollout has been deliberate but unambiguous in its direction. The top 150 listed companies by market capitalisation were required to obtain BRSR Core assurance beginning FY2023-24 on a comply-or-explain basis, transitioning to mandatory compliance for FY2024-25 onwards. As of FY2026-27, the regulatory expectation is clear: assurance is not optional, and the quality of that assurance is under increasing scrutiny from institutional investors, proxy advisory firms, and SEBI's own surveillance mechanisms.</p> <p>The 49 BRSR Core KPIs span three broad ESG dimensions: environmental metrics (including GHG Scope 1 and Scope 2 emissions, energy intensity, water withdrawal and consumption, and waste generation), social metrics (including gender pay ratios, workforce health and safety, and supply chain sustainability assessments), and governance metrics (including transparency in related-party transactions and complaint redressal mechanisms). Each of these KPIs demands a traceable, verifiable data trail—a requirement that exposes significant gaps in how most Indian enterprises currently manage ESG information.</p>
<h2>The Hidden Fragility: Why ESG Data Infrastructure Fails Assurance</h2> <p>In our advisory engagements across manufacturing, financial services, and infrastructure sectors, Praxis Consulting consistently identifies a recurring pattern: organisations invest heavily in the <em>reporting</em> layer of ESG—hiring sustainability managers, subscribing to disclosure platforms, and commissioning glossy sustainability reports—while significantly underinvesting in the <em>data layer</em> that underpins those disclosures. When an independent assurance provider arrives, this fragility becomes immediately visible.</p> <p>The most prevalent failure modes include:</p> <ul> <li><strong>Fragmented data ownership:</strong> GHG emissions data sits with the environment team, energy consumption data with facilities management, water data with plant operations, and workforce safety data with HR—each function maintaining its own spreadsheets with no unified data governance protocol. Reconciliation at the reporting stage is manual, error-prone, and difficult to audit.</li> <li><strong>Absence of a defined data lineage:</strong> Assurance providers require evidence of how a reported number was derived—the source system, the calculation methodology, the conversion factors applied, and the review controls exercised. Without documented data lineage, even accurate numbers cannot be assured.</li> <li><strong>Inconsistent boundary definitions:</strong> Many organisations report GHG emissions for their corporate headquarters but exclude manufacturing subsidiaries or joint ventures, citing operational complexity. BRSR Core's organisational boundary requirements align with GHG Protocol principles, and boundary inconsistencies are a leading cause of qualified assurance opinions.</li> <li><strong>Methodology drift:</strong> Emission factors, waste classification standards, and water stress methodologies evolve. Organisations that do not maintain a formal ESG accounting policy document—updated annually and approved by senior management—struggle to demonstrate year-on-year comparability, a key assurance criterion.</li> <li><strong>Supply chain data gaps:</strong> BRSR Core's Principle 2 KPIs require disclosures on the percentage of input material sourced from MSMEs and on supply chain sustainability assessments. For large enterprises with thousands of tier-1 and tier-2 suppliers, this data is rarely available in any structured form.</li> </ul> <p>The consequence of these gaps is not merely a qualified assurance opinion—though that carries its own reputational cost. In an environment where SEBI is actively monitoring disclosure quality and institutional investors are deploying ESG data analytics to make capital allocation decisions, structurally weak ESG data infrastructure represents a material governance risk.</p>
<h2>Designing a BRSR Core-Aligned ESG Data Architecture</h2> <p>A credible ESG data architecture is not a technology implementation project—it is a governance design exercise that technology subsequently enables. The architecture must address four interdependent layers: <strong>data governance, data collection, data validation, and data reporting.</strong></p> <p><strong>Layer 1 — ESG Data Governance:</strong> The foundation is a formal ESG Data Governance Policy that defines data ownership (who is accountable for each KPI), data stewardship (who is responsible for collection and quality), data standards (which methodologies, emission factors, and classification systems are authoritative), and escalation protocols (how disputes or anomalies are resolved). This policy should be approved by the Board's ESG or Audit Committee and reviewed annually. A cross-functional ESG Data Council—comprising representatives from operations, finance, HR, legal, and IT—should be constituted to operationalise the policy.</p> <p><strong>Layer 2 — Data Collection Infrastructure:</strong> For organisations with multiple manufacturing sites, offices, and subsidiaries, manual data collection via email and spreadsheets is structurally incompatible with assurance requirements. Enterprises should evaluate purpose-built ESG data management platforms—or, where ERP systems like SAP S/4HANA are deployed, leverage native sustainability modules—to automate data ingestion from source systems. Critical design principles include: single source of truth for each KPI, automated unit conversion and emission factor application, and role-based access controls that create an audit trail of who entered, reviewed, and approved each data point.</p> <p><strong>Layer 3 — Internal Data Validation:</strong> Before external assurance, a structured internal validation process should be established. This includes: reasonableness checks (comparing current period data against prior periods and industry benchmarks), completeness checks (verifying that all in-scope facilities and entities have submitted data), and cross-functional sign-off (requiring the relevant functional head to certify the accuracy of data within their domain). Internal audit should be formally tasked with conducting a pre-assurance readiness review at least 60 days before the external assurance engagement commences.</p> <p><strong>Layer 4 — Reporting and Disclosure Controls:</strong> The final layer involves the controls governing how validated data is translated into BRSR disclosures. This includes a disclosure checklist mapped to all 49 BRSR Core KPIs, a formal review and approval workflow involving the Chief Sustainability Officer (or equivalent), CFO, and Company Secretary, and a version control protocol that preserves the audit trail from source data to published disclosure.</p>
<h2>Integrating BRSR Core with Global Frameworks and Investor Expectations</h2> <p>Indian enterprises operating in global capital markets or with multinational customer relationships face a compounding disclosure challenge: BRSR Core requirements must be met simultaneously with expectations from global frameworks including the <strong>GRI Standards, ISSB's IFRS S1 and S2</strong> (which India is progressively aligning with through the Institute of Chartered Accountants of India's roadmap), the <strong>CDP Climate and Water questionnaires</strong>, and customer-driven requirements from EcoVadis assessments and supply chain sustainability programmes.</p> <p>The strategic opportunity here is framework harmonisation. BRSR Core's GHG KPIs are largely consistent with GHG Protocol Corporate Standard methodology, which also underpins IFRS S2 and CDP. Organisations that design their data architecture around GHG Protocol principles from the outset—defining organisational boundaries using the operational control approach, applying consistent global warming potential (GWP) values from the latest IPCC Assessment Report, and calculating both location-based and market-based Scope 2 emissions—will find that BRSR Core assurance, CDP disclosure, and IFRS S2-aligned reporting can be served from a single, unified data infrastructure.</p> <p>Institutional investors and ESG rating agencies are also raising their analytical sophistication. Firms like MSCI, Sustainalytics, and ISS ESG are increasingly distinguishing between <em>assured</em> and <em>unassured</em> ESG data in their scoring models. A reasonable assurance opinion on BRSR Core KPIs—as opposed to limited assurance—signals a materially higher level of data quality and governance maturity, and is beginning to translate into measurable ESG rating improvements for early movers.</p>
<h2>The Role of Technology and Agentic AI in ESG Data Management</h2> <p>The convergence of ESG data management with enterprise technology transformation is accelerating. The Indian GRC platform market—encompassing ESG data management as a significant and growing segment—is projected to expand from USD 1,788 million in 2025 to USD 4,443 million by 2034, reflecting a CAGR of 10.64%. Within this growth, a particularly significant development is the emergence of <strong>agentic AI capabilities</strong> in ESG data platforms.</p> <p>Where first-generation ESG software focused on data aggregation and reporting, agentic AI systems are now capable of continuous anomaly detection in incoming ESG data streams, automated flagging of boundary inconsistencies or methodology deviations, real-time benchmarking of reported metrics against sector peers, and regulatory change monitoring—automatically mapping updates to SEBI circulars or revised GHG Protocol guidance to existing data collection templates.</p> <p>For BRSR Core compliance, the practical implication is significant: organisations that deploy AI-augmented ESG data platforms can reduce the manual effort of assurance preparation by an estimated 40-60%, while simultaneously improving data quality and audit trail completeness. However, technology adoption must be preceded by—not substituted for—the governance design work described above. An AI system operating on poorly governed, fragmented data will produce assured errors at scale rather than assured accuracy.</p> <p>It is also worth noting the intersection with India's <strong>Digital Personal Data Protection (DPDP) Act, 2023</strong>: workforce-related BRSR KPIs—including gender pay ratios and safety incident data—involve personal data. Organisations must ensure that their ESG data collection and storage practices are compliant with DPDP Act obligations, including purpose limitation and data minimisation principles, to avoid creating a compliance conflict between BRSR disclosure and data protection requirements.</p>
<h2>Strategic Priorities for Sustainability and Compliance Leaders</h2> <p>For Chief Sustainability Officers, CFOs, and Compliance Officers at organisations within or approaching the BRSR Core assurance perimeter, the window for reactive, last-minute preparation is closing. The following strategic priorities should be addressed in the immediate term:</p> <ul> <li><strong>Conduct a BRSR Core readiness diagnostic:</strong> Map current data availability, quality, and governance status against all 49 KPIs. Identify the highest-risk gaps—typically Scope 1 and Scope 2 GHG data completeness, water accounting at facility level, and supply chain sustainability metrics—and develop a remediation roadmap with clear ownership and timelines.</li> <li><strong>Formalise ESG accounting policies:</strong> Document the methodologies, emission factors, organisational boundaries, and calculation approaches for each quantitative KPI. This policy document is the single most important artefact an assurance provider will request, and its absence is the most common cause of assurance delays.</li> <li><strong>Engage your assurance provider early:</strong> BRSR Core assurance is not an end-of-year exercise. Assurance providers should be engaged at the beginning of the financial year to agree on the assurance scope, methodology, and evidence requirements. Early engagement also allows for interim data quality reviews that reduce the risk of material findings at year-end.</li> <li><strong>Align Board oversight:</strong> The Audit Committee or a dedicated ESG Committee of the Board should receive quarterly updates on BRSR Core data quality, assurance readiness, and any material changes in ESG performance. Board-level engagement signals governance seriousness to investors and regulators alike, and is increasingly expected as part of SEBI's broader corporate governance expectations.</li> </ul> <p>The trajectory of SEBI's BRSR framework is unambiguous: mandatory assurance will extend progressively to the top 1,000 listed companies, assurance standards will tighten, and the consequences of inadequate disclosure—whether regulatory action, investor downgrading, or reputational damage—will intensify. The organisations that will navigate this environment with confidence are those that treat ESG data architecture as a core governance investment today, not a compliance afterthought tomorrow.</p> <p><em>Praxis Consulting's Sustainability & ESG Advisory practice has supported over 60 Indian and multinational enterprises in building BRSR-aligned ESG data frameworks, conducting assurance readiness assessments, and designing board-level ESG governance structures. If your organisation is navigating the BRSR Core assurance mandate or seeking to build a credible, future-ready ESG data infrastructure, we invite you to connect with our advisory team for a confidential diagnostic conversation.</em></p>
Actionable Recommendations
Commission a structured BRSR Core readiness diagnostic immediately, mapping data availability and governance quality across all 49 KPIs to identify critical gaps and build a time-bound remediation roadmap before your assurance engagement window opens.
Develop and formally approve an ESG Accounting Policy document that codifies organisational boundaries, GHG Protocol methodology choices, emission factor sources, and data review controls—this single document is the cornerstone of a defensible assurance engagement.
Establish a cross-functional ESG Data Council with defined ownership for each BRSR Core KPI category, and task Internal Audit with conducting a pre-assurance readiness review at least 60 days before the external assurance provider's fieldwork commences.
Evaluate purpose-built ESG data management platforms or ERP-native sustainability modules to automate data collection, conversion, and audit trail generation—prioritising solutions with agentic AI capabilities that can flag anomalies and regulatory changes in real time.

