ESG Due Diligence (2026): The Post-Omnibus Scope Reset + the Scope 3 Evidence Test
Co-founder at Peony. Former M&A at Nomura, early-stage VC at Backed VC, and growth-equity / secondaries investor at Target Global. I write about investors, fundraising, and deal advisors from the deal-side perspective I spent years in.
Last updated: August 2026
I'm Sean Yu, co-founder of Peony, a virtual data room company. Before Peony I spent my career on the deal side, and ESG is the workstream I most often watch get run badly in both directions — either skipped as soft, or bloated into a compliance ritual that produces a report nobody prices off. In an acquisition, the point of ESG due diligence is not to score the target against a framework — it is to find the sustainability and governance facts that change the price, the contract, or the 100-day plan, and to ignore the ones that do not. The reason 2026 is a genuine reset is that the regulatory ground moved under everyone's feet: the EU's Omnibus simplification, adopted as Directive (EU) 2026/470 on 24 February 2026, narrowed both the CSRD and the CSDDD so sharply that most guides written before it — and, frankly, a lot written after it — describe obligations that no longer bind the target in front of you.
The named trap in this post is the Scope 3 evidence test — the difference between a target that measures its value-chain emissions on activity data and one that estimates them from spend and reports the estimate as if it were a measurement. It is the ESG equivalent of an earnings restatement, and it is the finding that most often separates a real ESG file from a decorated one. I run Peony, a data room company used by 6,800+ customers across M&A and private equity, and this guide maps the materiality frame, the Scope 1/2/3 evidence test, the verified 2026 regulatory map with each threshold attached to the right directive, how findings move price, and how to run the evidence room — every regulatory claim carried with its instrument name and date, and the tooling framed honestly, including where a GRC platform or an enterprise VDR is the better call than us.
Quick answer: ESG due diligence is the buyer's review of a target's environmental, social, and governance profile to price the sustainability risks and value drivers a financial and legal review misses. It is broader than environmental due diligence (the Phase I/II site-and-liability review, which is one workstream inside it). Scope the review by materiality — E/S/G pillar × deal-impact tier, tied to an evidence class — not a generic 12-topic checklist. The decisive analytical test is the Scope 3 evidence test: activity-based data is defensible, spend-based data is a proxy, and a restated baseline is a red flag. The verified 2026 regulatory picture is a reset: the EU Omnibus (Directive (EU) 2026/470, in force 18 March 2026) scoped CSRD reporting to companies over €450M turnover and 1,000 employees and CSDDD due diligence to companies over €1.5B turnover and 5,000 employees (application 26 July 2029); Germany's LkSG reporting obligation was abolished retroactively to 1 January 2023; and the SEC climate rule is dormant with a rescission proposed. Findings move price through a price chip, a specific indemnity, an escrow, or the 100-day plan — and Deloitte's 2024 survey found ~72% of buyers had walked from a deal on ESG red flags.

Why is ESG due diligence different in 2026?
ESG due diligence is different in 2026 because the regulatory scaffolding that a lot of the practice was built on has been cut back, so the review has to rest on commercial reasoning rather than on the assumption that a filing regime binds the target. For most of the last five years, ESG DD borrowed its urgency from a wall of coming EU rules. In 2026 that wall is much smaller, and pretending otherwise produces a review that prices obligations the target does not have.
Start with the reset itself, because the details matter and this is exactly the area where imprecise guides mislead. The EU's Omnibus I simplification package was adopted as Directive (EU) 2026/470 on 24 February 2026, published in the Official Journal, and entered into force on 18 March 2026 (EUR-Lex; Council of the EU press release, 24 February 2026). It amended four directives at once, but the two that matter for a deal are the CSRD and the CSDDD, and it did two different things to them. It raised the CSRD reporting threshold to undertakings exceeding both €450 million net turnover and 1,000 employees on average during the financial year — up from the prior 250-employee threshold, removing the great majority of previously in-scope companies. And it raised the CSDDD due-diligence scope, separately and much higher, to companies with more than 5,000 employees and more than €1.5 billion net worldwide turnover. Those are different numbers attached to different obligations, and the most common error in ESG-DD content — including a competitor guide published the day before this one — is to present the CSRD reporting threshold as though it were the ESG-DD trigger. It is not. The due-diligence duty binds a far smaller, much larger-cap set of companies than the reporting duty.
The reset did not come out of nowhere. It was preceded by the 'stop-the-clock' Directive (EU) 2025/794 of April 2025, which postponed the CSRD and CSDDD start dates while the Commission prepared the substantive simplification; Directive (EU) 2026/470 is the package that then narrowed the scope. The practical timeline now: the CSDDD amendments transpose by 26 July 2028, with a single application date of 26 July 2029 for all in-scope companies; the CSRD amendments transpose by 19 March 2027; and the Commission must revise the European Sustainability Reporting Standards (ESRS) by delegated act by 18 September 2026.
The same softening shows up outside the EU's core directives. In Germany, the Supply Chain Due Diligence Act (LkSG) is still on the books, but its reporting obligation was abolished retroactively from 1 January 2023, the reporting form was switched off on 7 November 2025, and enforcement has narrowed to serious violations pending a CSDDD-aligned overhaul. In the United States, the SEC's climate-disclosure rule is dormant — adopted in March 2024, stayed weeks later, defense ended in March 2025, and a rescission proposed in 2026. Nothing under it is currently due.
So why run ESG DD at all in 2026? Because the durable reasons were never the filing regimes. A target can sit below every reporting threshold and still carry ESG facts that move a deal: it may sell into the value chain of a large in-scope company that pushes requirements down its supply chain, hold customer contracts with decarbonization or labor clauses, face transition risk that erodes its forward margin, or carry a governance or supply-chain exposure that a buyer would inherit. The reset does not make ESG DD optional; it makes it commercial — a review justified by value and risk, not by the assumption that a specific directive binds the target. The rest of this guide is the practitioner version of that discipline.
What is ESG due diligence?
ESG due diligence is the structured pre-acquisition review of a target's environmental, social, and governance profile, run so a buyer can price the sustainability risks and value drivers that the financial, legal, and commercial workstreams do not capture. It sits alongside the other workstreams in a buy-side due diligence process and feeds the same outputs — the price, the reps and warranties, the indemnity package, and the value-creation plan.
The distinction that trips people up is ESG DD versus environmental due diligence, which are related but not the same. Environmental DD is the site-and-liability review: Phase I and Phase II Environmental Site Assessments, contaminated-land and remediation exposure, permits, and cleanup obligations. It answers a specific question — does the physical asset carry an environmental liability the buyer would assume. ESG DD is broader and asks a different question across three pillars: is the way this business operates durable and defensible on environmental, social, and governance grounds, and where does that change the deal. On a physical-asset deal you run both, with the environmental review as one workstream inside the wider ESG frame; on a software or services deal, the environmental site review may be trivial while the governance and social pillars carry the weight. This post is the M&A ESG workstream; where the deal touches contaminated land or a BFPP defense, the environmental due diligence guide owns that layer and this post does not re-derive it.
One more boundary, because the DD cluster has adjacent posts that sound similar. ESG DD reviews the target company and its value chain. Third-party due diligence reviews intermediaries and counterparties — the anti-bribery, sanctions, and forced-labor screening of agents, suppliers, and partners under frameworks like FCPA, OFAC, and UFLPA — and while it overlaps with the social pillar of ESG DD (a forced-labor screen appears in both), it is a distinct workstream with its own jurisdictional frame. Where the two meet — screening a target's supplier list — this post points to it rather than duplicating it.
How do you scope ESG materiality for an acquisition?
You scope ESG materiality by working from the deal outward, because the failure mode of ESG DD is a checklist that treats every topic as equally important and produces a report nobody prices off. The materiality map is the first deliverable, and it is what makes the rest of the review efficient. The frame below is deliberately not a fixed list of twelve topics — a generic topic list is exactly what produces noise. It is a method for deriving the topics that matter for this target.
Step one: map the topics to the business model and the value chain. The material ESG topics follow what the business actually does. An apparel, electronics, or food target inherits supply-chain human-rights and forced-labor exposure because its value chain reaches into higher-risk geographies. A heavy-industrial, energy, or manufacturing target inherits energy intensity, process emissions, and transition risk. A data-center or compute-heavy target inherits power consumption and grid exposure. A consumer-brand target inherits governance and reputational sensitivity. You do not start from a universal list; you start from the sector and the value chain and let the material topics surface.
Step two: split every topic into value-relevant and compliance-only. This is the discipline that separates useful ESG DD from theater. A value-relevant topic changes cash flow, cost of capital, or the exit multiple — a carbon-price exposure that raises input costs, a customer contract that requires a funded decarbonization commitment, a labor practice that threatens a licence to operate. A compliance-only topic is a reporting or filing obligation with no cash-flow consequence beyond the cost of complying. Both belong in the report; they get weighted differently. Conflating them — treating a disclosure formality as if it were a value risk, or burying a real margin threat under a pile of formalities — is the single most common way an ESG report loses the reader who has to price the deal.
Step three: tie each material topic to an evidence class. How hard a finding is depends on what kind of evidence supports it, and naming the class up front tells you how much to trust it:
- Measured-and-assured data — an emissions inventory built on activity data and independently assured, an audited safety record. This is the evidence you can price off directly.
- Management-attested claims — a policy, a target, or a commitment with no independent verification. Useful, but it is an assertion until you test it.
- Third-party-dependent value-chain data — a supplier's self-reported emissions or labor figures you cannot audit. This is the softest class, and it is where most Scope 3 and supply-chain findings live, so you treat it as an estimate and price the uncertainty.
The output is a short, ranked map: the handful of topics that are both material and value-relevant, each tagged with its evidence class, with the compliance-only items listed separately so they inform the reps without distorting the price. The ISSB's standards center financial materiality; the EU's ESRS run double materiality — financial plus impact — and a CSRD-scope target's own reporting will reflect both lenses. For a deal frame, though, the financial-materiality instinct is the one that carries: focus the review on what affects the enterprise, and let everything else be a footnote.
Why is the Scope 3 evidence test the finding that most often decides an ESG file?
The Scope 3 evidence test decides an ESG file because it is where a precise-looking number most often turns out to be a proxy, and a buyer who cannot tell a measurement from an estimate will price a fiction. This is the named analytical trap of the post, and it is worth stating precisely, because the credible version is very different from the vague "check their carbon footprint" that lesser guides offer.
The three scopes. Under the GHG Protocol's framework — the standard the vast majority of corporate inventories use — Scope 1 is direct emissions from owned or controlled sources (on-site combustion, company vehicles, process emissions); Scope 2 is indirect emissions from purchased electricity, steam, heating, and cooling; and Scope 3 is everything else in the value chain. The GHG Protocol's Corporate Value Chain (Scope 3) Standard splits Scope 3 into 15 categories — 8 upstream and 7 downstream — running from purchased goods and services and business travel on the upstream side to the use and end-of-life of sold products on the downstream side. For most companies, Scope 3 dwarfs Scopes 1 and 2, which is exactly why it is the hardest to verify and the easiest to decorate.
Scope 1 and 2: verify the boundary and the assurance. These usually rest on the target's own meters and invoices, so they are verifiable. The diligence work is confirming the organizational boundary — which legal entities and which sites are included, and whether that boundary matches the perimeter of the deal — and whether the figures carry independent assurance or are self-reported. A clean Scope 1/2 number with a clear boundary and third-party assurance is a good sign; a number with an undefined boundary is a question, not an answer.
Scope 3: the spend-based versus activity-based test. Here is where the review earns its fee, because most targets estimate Scope 3, and the estimation method decides whether the figure means anything.
- A spend-based figure multiplies dollars spent in a category by an average emissions factor. It is quick, it is what a first-time reporter produces, and it is barely better than a proxy — two suppliers with identical spend but wildly different emissions look the same.
- An activity-based figure uses physical quantities — kilograms of a material, kilometres shipped, kilowatt-hours consumed, units produced — and is defensible because it reflects what actually happened.
A target that reports a precise-looking Scope 3 total built entirely from spend data has handed you an estimate dressed as a measurement. That is not fraud — spend-based accounting is a legitimate starting point — but it must be priced as an estimate, and a decarbonization commitment resting on a spend-based baseline is resting on sand.
The restated-baseline red flag. The second trap is the restated baseline. An emissions baseline that has been quietly re-cut — a base year moved, a boundary redrawn, a category dropped — so that a reduction target now looks achievable is the emissions equivalent of an earnings restatement, and it deserves the same scrutiny. Ask for the version history of the baseline and the reason for any restatement. A legitimate restatement (an acquisition changed the perimeter, a methodology improved) has a documented rationale; an illegitimate one exists to make a target look on-track. Four questions separate a real inventory from a decorated one: what is the methodology, what is the organizational boundary, what is the assurance status, and what is the version history of the baseline. A target that can answer all four has a real inventory. A target that answers none of them has a marketing deck, and that gap is itself a finding.
What is the verified 2026 ESG regulatory map?
The verified 2026 regulatory map has six instruments a deal team should be able to name and status, and the discipline that matters is attaching each threshold to the right instrument with its real date — because this is the exact area where a confident-looking but wrong citation does the most damage. The table is the reference; the notes after it flag the two things most guides get wrong.
| Instrument | What it is | 2026 status (with dates) |
|---|---|---|
| CSRD (EU reporting) | EU sustainability-reporting directive | Scoped by Directive (EU) 2026/470 to undertakings over €450M turnover and 1,000 employees. Transposition 19 March 2027. ESRS revised by delegated act due 18 September 2026. |
| CSDDD (EU due diligence) | EU value-chain human-rights and environmental due-diligence duty | Scoped by the same directive to companies over €1.5B turnover and 5,000 employees. Transposition 26 July 2028; single application date 26 July 2029. |
| SFDR (EU finance) | Sustainable Finance Disclosure Regulation | Delegated Regulation (EU) 2022/1288 sets 18 mandatory PAI indicators. 'SFDR 2.0' review underway; Council agreed its negotiating mandate 24 June 2026; final text expected ~2026-27. |
| ISSB (global baseline) | IFRS Foundation's IFRS S1 and S2 | Per the IFRS Foundation's June 2025 status update, 36 jurisdictions had adopted the standards or were taking steps toward adoption. |
| LkSG (Germany) | German Supply Chain Due Diligence Act | In force, but reporting obligation abolished retroactively to 1 January 2023; reporting form deactivated 7 November 2025; enforcement narrowed to serious violations; CSDDD-aligned overhaul pending. |
| SEC climate rule (US) | SEC climate-related disclosure rule | Adopted March 2024, stayed; SEC ended its defense 27 March 2025; rescission proposed in 2026. Nothing currently due. |
The two things to get right. First, the CSRD reporting threshold (>1,000 employees, €450M turnover) and the CSDDD due-diligence scope (>5,000 employees, €1.5B turnover) are different numbers for different obligations inside the same directive. A guide that says "ESG due diligence applies to companies over 1,000 employees and €450M" has quoted the reporting threshold and mislabeled it as the due-diligence trigger — a mistake that is easy to make because both numbers live in Directive (EU) 2026/470, and one that matters because it overstates who carries the CSDDD duty by a wide margin. Second, the map moves: the SFDR is mid-review, the ESRS is being revised, and the SEC rule is mid-rescission, so any regulatory claim in an ESG report should carry an as-of date. The version above is current as of August 2026; the durable practice is to cite the instrument and check its status, not to rely on a number you remember. For the value-chain compliance frame that overlaps here — FCPA, OFAC, UFLPA, and the CSDDD as it applies to counterparty screening — see third-party due diligence.
There is also a quieter provision worth knowing: the Omnibus introduced a value-chain information cap built on the VSME (the voluntary sustainability-reporting standard for SMEs). In substance, a CSRD-obligated company cannot demand more ESG data from a smaller supplier than the VSME standard covers, which caps the reporting burden that flows down a supply chain to SME targets. For a deal, that means a small target's exposure to a large customer's ESG data requests is bounded — a useful fact when you are assessing how much sustainability-reporting overhead a smaller acquisition actually inherits.
How do ESG due diligence findings move deal price?
ESG findings move price through the same four levers as any diligence finding — the price itself, the indemnity package, an escrow, or a post-close plan — and the right lever depends on whether the finding is a quantifiable liability or a durability risk. The discipline that separates useful ESG DD from compliance theater is insisting that every material finding lands somewhere concrete.
Quantifiable liabilities behave like any other finding. A remediation obligation, a supply-chain fine exposure, or a funding gap in a decarbonization commitment the target has contractually promised can be sized and turned into a price reduction, a specific indemnity carved out of the general reps (separately capped, surviving longer than the general survival period), or an escrow scaled to the estimate. These are the findings a financial or legal reviewer already knows how to structure; the ESG work is surfacing and sizing them.
Durability risks are priced through the model. Some ESG findings do not produce a discrete liability but do threaten the forward numbers: a customer concentration in a client that will drop the target on a governance finding, a transition risk that erodes margin as carbon costs rise, or a reputational exposure that raises churn. These are priced through a lower multiple or a haircut to the forecast, not through an indemnity, because there is no single number to escrow — there is a probability-weighted drag on value.
The 100-day plan is ESG DD's most distinctive lever. Many ESG findings are fixable, and a buyer who intends to own and improve the asset can price the cost of the fix and build it into the value-creation plan rather than walking away. A missing supplier screen, an emissions inventory that needs rebuilding on activity data, a governance policy gap — each has a cost and a timeline, and folding that into the 100-day plan turns a red flag into a work item. This is why ESG DD, done well, is as much a value-creation input as a risk screen: the same finding that would scare a passive buyer is an improvement lever for an active one.
To make the mechanics concrete, here is an illustrative example (not a real deal). Consider a target whose diligence surfaces a Scope 3 inventory built entirely on spend data, a supplier list that has never been run against a forced-labor screen, and a public decarbonization commitment with no capital plan behind it. None of these is a discrete legal liability, so none produces an escrow on its own — but together they represent a value risk (the commitment may cost real capital to meet) and a governance gap (the unscreened supply chain). A disciplined buyer prices the rebuild of the inventory and the supplier screen as a defined cost in the 100-day plan, seeks a rep that the target is not aware of forced-labor exposure in its supply chain with a specific indemnity behind it, and adjusts the model for the capital the decarbonization commitment will actually require. The purchase price may or may not move; what always happens is that each finding is allocated in writing. The alternative — nodding at the glossy ESG report and pricing nothing — is how a buyer inherits a problem it was told about and chose not to price.
The market backdrop says this is not hypothetical: Deloitte's 2024 ESG in M&A Trends Survey, which polled 500 M&A leaders, found that roughly 72% had declined to proceed with an acquisition because of ESG red flags found in diligence. Walking away is a real and common outcome — which is the strongest argument for doing the review well enough to find the flag before, not after, you sign.
Who runs ESG due diligence, and how long does it take?
ESG due diligence is run by an ESG advisory team that scopes the materiality map and coordinates the review, pulling in specialists where a topic demands depth, and it runs as a parallel workstream rather than a sequential gate, so it usually does not extend the deal on its own. The exception is the value-chain data chase, which can.
Who does the work. The core is an ESG advisory firm (or an in-house sustainability team on a large acquirer) that builds the materiality map and runs the review across the three pillars. Where a topic needs specialist depth, the team brings in the specialist: an emissions consultant to rebuild or test an inventory, a supply-chain human-rights firm for a forced-labor audit, an environmental engineer for a Phase I/II assessment where physical assets are involved, and counsel to translate findings into reps, indemnities, and the transition plan. On a private-equity deal, the ESG lead often sits within the deal team and coordinates the external advisors; the review then feeds the PE diligence process and the value-creation plan.
The process, in short. Scope the materiality map from the sector and value chain; issue the evidence request list against the three pillars; review what comes back and, critically, chase what does not; test the high-stakes items (the emissions inventory, the supplier screen) against their evidence class; and translate findings into the price, the reps, the indemnities, and the 100-day plan. The DD process guide covers the overall sequencing this plugs into.
The timeline. ESG DD runs in parallel with financial, legal, and commercial diligence, so on its own it rarely sets the critical path. What can stretch it is the third-party-dependent evidence: a supplier's emissions or labor data arrives on the supplier's schedule, not the deal's, and a target that has to gather value-chain data rather than retrieve it can add weeks. Across 334 M&A transactions on the Peony platform, blended time-to-close reached about 8.6 months in Q2 2026 (State of M&A Data Rooms, Q2 2026), and the deals that run long are typically the ones where evidence had to be assembled rather than reviewed. That makes data quality the controllable variable — a target with an assured inventory, a screened supplier list, and documented policies is reviewed quickly; a target with a report but no underlying data forces a rebuild that consumes both the budget and the clock. For the full index of first-party Peony datasets behind these numbers, see Peony Research.
How do you run the data room for ESG due diligence?
You run an ESG diligence room in five steps built around two facts a generic deal room does not have to handle: much of the evidence is workforce-and-supply-chain data carrying GDPR and personal-data sensitivity, and much of it is third-party-dependent, so the chase for missing evidence is a real part of the work. The goal is a room where each reviewer works their pillar independently, personal data stays controlled, and the evidence gaps are visible from day one.
1. Structure the folders on the three pillars. Environmental, social, governance — with the emissions inventory (and its methodology and boundary), the supplier map and screens, the workforce data, and the governance policies each in their own place. Structuring by pillar makes gaps obvious: a missing assured inventory or an unscreened supplier list shows up as an empty folder rather than surfacing late when an advisor asks.
2. Gate the room and stage the reveal. Nobody sees a file until they have signed an NDA, and the reveal is staged so the most sensitive material — detailed workforce data, supplier identities, commercially confidential contracts — sits behind a deeper tier than the high-level policies. Staging keeps identifiable and confidential data segregated from less-trusted parties, which matters when a plausible buyer might be a competitor who would value the supplier list for reasons unrelated to the deal.
3. Set granular permission groups per reviewer. This is the ESG-specific requirement. The environmental advisor sees the emissions and energy data; employment counsel sees the workforce folder; the governance reviewer sees the board and anti-bribery material. Each reviewer gets their own granular permission group with its own view, so no one sees a workstream they were not assigned — which matters acutely here because the workforce data is personal data under GDPR, and over-broad access is a compliance problem in itself.
4. Redact personal data, and watermark the sensitive material. Where a document must be shared but should not expose identifiable employee information — individual compensation, names, IDs in an incident log — use Advanced Redaction to strip it before sharing, and turn on dynamic watermarking so every page carries the viewer's identity and screenshot protection for anything sensitive. The cleaner default is to share aggregate and de-identified workforce data wherever the analysis allows, and to redact identifiers in place only where the individual-level detail is genuinely needed.
5. Run the evidence chase through file requests and Q&A. ESG DD almost always opens with gaps — an unscreened supplier list, a missing methodology, a policy with no enforcement records — and a structured request-and-answer thread beats an email chain for tracking what was asked, what came back, and what is still outstanding. The analytics also show which reviewers are working which pillar and where they are stuck, useful for managing a multi-advisor team.
The honest scope of the room. The data room is the exchange and evidence layer for the deal, not a portfolio-wide ESG monitoring platform. Continuous emissions monitoring across a portfolio, ongoing CSRD or ISSB reporting workflows, and year-round supplier scoring belong on a GRC or sustainability-management platform built for that job; for a mega-cap process with millions of pages and a staffed, managed Q&A desk, an enterprise VDR (Datasite, Intralinks) is the right tool, and I would say so. Peony runs the mid-market deal-stage ESG room on the Data Room plan at $52 per admin per month with unlimited rooms, granular permissions, dynamic watermarking, and file requests; Advanced Redaction sits on the Deal Team tier for the personal-data-stripping work, and NDA gating starts on the Business plan at $30 per admin per month. Viewers are always free, so a full advisory team adds nothing to the bill. This is the model behind Peony serving 6,800+ customers across M&A, private equity, and diligence workflows.
What are the common mistakes in ESG due diligence?
The common mistakes in ESG due diligence cluster around two opposite failures — treating it as a box-ticking ritual, or treating it as soft and skipping the parts that price — plus the specific technical traps that let a decorated file pass as a real one. Each is avoidable.
- Running a generic checklist instead of a materiality map. The most common error is reviewing every ESG topic at equal weight, which buries the two or three findings that actually move the deal under a pile of formalities. Scope from the business model and value chain, and separate value-relevant from compliance-only.
- Pricing a spend-based Scope 3 number as if it were measured. Accepting a precise-looking value-chain emissions figure without asking whether it rests on activity data or spend estimates. The number can be off by an order of magnitude, and a decarbonization commitment built on it is built on sand.
- Missing a restated baseline. Not asking for the version history of the emissions baseline, and taking a reduction target at face value when the baseline was quietly re-cut to make it achievable.
- Quoting stale or mislabeled regulation. Describing pre-Omnibus CSRD/CSDDD scope as current, or presenting the CSRD reporting threshold as the CSDDD due-diligence trigger. Attach every threshold to the right instrument with an as-of date.
- Loading personal data into the room without controls. Sharing identifiable workforce data — individual compensation, health records, names in an incident log — without redaction or per-reviewer permissions, turning the diligence file into a GDPR exposure.
- Producing findings that price nothing. The compliance-theater failure: a long ESG report that identifies risks but never translates them into a price chip, a rep, an escrow, or a 100-day work item. A finding that changes nothing about the deal was not material.
- Treating ESG DD as environmental DD, or vice versa. Assuming a Phase I ESA covers the ESG review, or that an ESG scorecard covers contaminated-land liability. They are different reviews; on a physical-asset deal you need both.
The unifying lesson is that ESG DD rewards a commercial mindset: scope to what matters for this target, test the evidence hard enough to tell a measurement from an estimate, attach every regulatory claim to its instrument, and insist that every material finding lands somewhere concrete — so the review confirms a durable, defensible business rather than certifying a glossy report.
Related Resources
- What Is Due Diligence? — the definitional root of the DD cluster and the hub this post spokes from
- Environmental Due Diligence — the Phase I/II ESA, contaminated-land, PFAS, and BFPP-defense layer inside the environmental pillar
- Third-Party Due Diligence — the FCPA / OFAC / UFLPA / CSDDD counterparty-screening frame that overlaps the social pillar
- Vendor Due Diligence Checklist — the seller-commissioned pre-market pack, a different concept from third-party DD
- Manufacturing Due Diligence — the certification, capex, and supply-chain review where ESG is energy- and supply-chain-heavy
- LP Operational Due Diligence — what institutional LPs test in a fund, including its ESG and SFDR posture
- M&A Due Diligence Process Guide — the full buy-side DD framework this workstream plugs into
- Buy-Side Due Diligence — the buy-side process and the workstream sequencing
- Private Equity Due Diligence — the PE process and the 100-day value-creation plan ESG findings feed
- Financial Due Diligence — where quantified ESG liabilities become price chips, reps, and escrows
- Legal Due Diligence — the reps, warranties, and indemnity structure that carries ESG findings
- HR Due Diligence — the workforce and labor review that overlaps the social pillar
- Sell-Side Due Diligence — the seller-side version, for a company preparing its ESG evidence for a buyer
- Due Diligence Cost Breakdown — comparative diligence costs across deal sizes and workstreams
For ESG due diligence specifically, Peony's data room — used by 6,800+ customers — gives each pillar's reviewers their own permissioned folder so the environmental advisor, employment counsel, and governance reviewer work independently in one room; Advanced Redaction to strip personal data before sharing; dynamic watermarking and screenshot protection for anything sensitive; file requests and Q&A to run the value-chain evidence chase; and an exportable audit trail of who reviewed which evidence — the record a buyer wants if a dispute over what was disclosed ever arises. Try Peony free for 14 days — no credit card required.
About the author: Sean Yu is the co-founder of Peony, the data room platform used by 6,800+ customers across M&A, fundraising, and diligence workflows — including private-equity deal teams and corporate acquirers running ESG workstreams. Before Peony, Sean spent his career on the deal side — M&A at Nomura, early-stage VC at Backed VC, and growth-equity / secondaries at Target Global — running and supporting buy-side and sell-side processes across industrials, software, and infrastructure in North America and Europe. He studied Biomedical Engineering at Imperial College London on a full scholarship before dropping out to build companies. Contact: sean@peony.ink • LinkedIn.
Sources
- EUR-Lex — Directive (EU) 2026/470 of 24 February 2026 amending Directives 2006/43/EC, 2013/34/EU, (EU) 2022/2464 (CSRD) and (EU) 2024/1760 (CSDDD) (Omnibus I; CSRD scope >€450M turnover + >1,000 employees; CSDDD scope >€1.5B turnover + >5,000 employees; application 26 July 2029) — https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=OJ%3AL_202600470
- Council of the EU — Council signs off simplification of sustainability reporting and due diligence requirements (press release, 24 February 2026) — https://www.consilium.europa.eu/en/press/press-releases/2026/02/24/council-signs-off-simplification-of-sustainability-reporting-and-due-diligence-requirements-to-boost-eu-competitiveness/
- EUR-Lex — Directive (EU) 2025/794 of 14 April 2025 ('Stop-the-clock' Directive, postponing CSRD/CSDDD application dates) — https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=OJ:L_202500794
- European Commission — Corporate sustainability due diligence (CSDDD topic page) — https://commission.europa.eu/topics/business-and-industry/doing-business-eu/sustainability-due-diligence-responsible-business/corporate-sustainability-due-diligence_en
- EUR-Lex — Commission Delegated Regulation (EU) 2022/1288 (SFDR RTS; 18 mandatory PAI indicators, Annex I, Table 1; applicable 1 January 2023) — https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022R1288
- Council of the EU — Council agrees position on simpler transparency rules for sustainable financial products (SFDR 2.0 negotiating mandate, 24 June 2026) — https://www.consilium.europa.eu/en/press/press-releases/2026/06/24/council-agrees-position-on-simpler-transparency-rules-for-sustainable-financial-products/
- IFRS Foundation — Jurisdictional profiles evidencing progress towards adoption of ISSB Standards (June 2025; 36 jurisdictions adopted or taking steps) — https://www.ifrs.org/news-and-events/news/2025/06/ifrs-foundation-publishes-jurisdictional-profiles-issb-standards/
- GHG Protocol (WRI / WBCSD) — Corporate Value Chain (Scope 3) Accounting and Reporting Standard (15 categories; 8 upstream / 7 downstream) — https://ghgprotocol.org/corporate-value-chain-scope-3-standard
- SEC — SEC Proposes Rescission of Climate-Related Disclosure Rules (press release 2026-49) — https://www.sec.gov/newsroom/press-releases/2026-49-sec-proposes-rescission-climate-related-disclosure-rules
- Deloitte — 2024 ESG in M&A Trends Survey (500 M&A leaders; ~72% declined a deal over ESG red flags) — https://www.deloitte.com/ce/en/services/consulting-financial/analysis/global-esg-ma-survey.html
- Peony — State of M&A Data Rooms, Q2 2026 (334 transactions; ~8.6 months blended time-to-close) — https://www.peony.ink/blog/state-of-ma-data-rooms
- Peony Research — first-party dataset index — https://www.peony.ink/research
You might also like
May 16, 2026
38 Due Diligence Red Flags Across 6 Streams (2026): Severity Matrix + Walk Rate
Aug 21, 2026
Insurance Due Diligence in M&A (2026): The Collateral Trap + Loss-Run Playbook
Aug 19, 2026
Manufacturing Due Diligence (2026): The Certification, Capex, and Tariff Checks That Price the Deal

