Who Audits the Raters: The EU Just Put ESG Scores Under Supervision
For years, ESG ratings sat outside the governance conversation they helped create. A score could influence a bond price, a procurement shortlist, or an index inclusion, and almost nobody asked what stood behind the number. That changed on 2 July 2026.
Regulation (EU) 2024/3005 on the transparency and integrity of ESG rating activities now applies. Providers wishing to operate in the Union generally require authorisation or recognition from the European Securities and Markets Authority (ESMA), while eligible small providers may instead use the Regulation's temporary registration regime. ESMA acts as the sole direct supervisor. Unlike many EU financial regulations, supervision sits directly with ESMA rather than national competent authorities. That tells you something about how the legislators saw the problem: as a single market issue rather than twenty-seven local ones.
What the regulation actually requires
The mechanics are worth knowing:
- Providers must apply for authorisation or recognition within four months of 2 July 2026.
- Providers already operating in the Union on 2 January 2025 face different transitional deadlines. Most providers had to notify ESMA of their intention to apply by 2 August 2026 before submitting a full application by 2 November 2026, while eligible small providers using the temporary regime have until 2 November 2026 to notify ESMA.
- Eligible small providers, those qualifying as "small undertakings" under the EU Accounting Directive, may use a temporary lighter registration regime with fewer ongoing obligations. They can opt into full authorisation if they prefer.
- The application itself is substantive. It covers organisational structure, ownership, senior management, staffing, and operations.
ESMA also published a statement on 1 July 2026 addressing how third parties may publish or distribute ESG ratings during the window between the regulation applying and providers actually being authorised. That kind of interim guidance usually signals a regulator that expects the transition to be messy.
Why this is a data governance story
I have written before about why ESG reporting struggled for so long: not because the numbers were impossible to calculate, but because organisations could not always show where a figure came from. The reporting side has spent several hard years fixing that. Source documents got attached to figures. Assumptions got written down with a name and a date next to them.
Meanwhile, the ratings built on top of those figures were subject to no comparable discipline. Two providers could look at the same company and produce meaningfully different scores, and the methodology gap between them was often opaque to the company being rated, let alone to the investor using the score.
A rating is only as defensible as the process that produced it, and until now, very little of that process has had to be shown to anyone.
This is the same logic that produced CSRD, arriving one layer up the chain. First, the reporting company had to demonstrate provenance. Now the organisations scoring that company are being asked for theirs.
What it means in practice
If you work inside a reporting function, three things follow.
Your rating provider may be in transition. Between now and authorisation, some providers may consolidate, some may exit the EU market, and some may change methodology to fit the new transparency requirements. A score that moves next year may reflect the regulation rather than your performance. That is worth explaining internally before someone else notices the change and draws the wrong conclusion.
Methodology questions become easier to ask. The regulation strengthens transparency around methodologies, assumptions, and governance. If you have ever tried to understand why a score moved and received something unsatisfying in response, the ground has shifted. It is reasonable to start asking better questions, even if the regulation does not guarantee complete explanations for every rating change.
The provenance discipline travels. If you have already built the audit trail on your own data, you are in a good position to interrogate what a rater does with it. If you have not, you now have two gaps rather than one.
The part I find genuinely interesting
There is a political science reading here that I keep coming back to. Ratings are a form of private governance. They set standards, reward compliance, and impose costs, all without any democratic mandate or formal accountability. That arrangement worked as long as the stakes were low. Once ESG scores started feeding financing terms and index construction, the stakes stopped being low, and the absence of oversight became conspicuous.
Bringing raters under supervision does not make their scores correct. It makes them accountable for the governance, transparency, and integrity of the processes by which those scores are produced, which is a different and more achievable goal. That distinction sits at the heart of most good governance design.
The reporting side of this profession spent years learning to answer one question about every figure it published: how do you know? It seems fair that the people grading that work should have to answer it, too.
Working on something in this space? I'd be glad to compare notes. Get in touch.