Skip to the answer

Disclosure GuidesPillar guides, articles, FAQ and expert notes

Level 2 · Decision guide·EU Voluntary Standard 2026 · Disclosure guides

Does the EU Value Chain Cap Apply to Banks, Customers and Procurement Platforms?

How reporting, lending, due diligence, product compliance and voluntary procurement purposes change the legal treatment of the same datapoint

Who this is for A 10-minute read for reporting teams working through Value chain cap: scope and protected undertaking status, and for reviewers testing whether the evidence behind it holds.

Short answer

The answer, before the reasoning

The value chain cap follows purpose and legal role, not the label of the requester or the datapoint alone. A bank or customer can be subject to the cap when it is a CSRD reporting undertaking and seeks information from a protected undertaking for its sustainability reporting.

The same bank's request for credit underwriting, loan monitoring, SFDR-related use or another financial-service purpose is outside this statutory cap, although the delegated-act recital encourages financial institutions to limit such requests as far as possible to Annex I. Due-diligence and product-compliance requests are also outside the cap. A procurement platform does not change the result: identify the ultimate requester and purpose, split mixed-purpose fields, and apply the cap only to the CSRD-reporting subset.

How reporting, lending, due diligence, product compliance and voluntary procurement purposes change the legal treatment of the same datapoint

Rule

KNOWLEDGE CARD PACKAGE

<p>Public practitioner article followed by a controlled editor and publisher pack with claims, mapping, SEO, sources, update triggers and review flags.</p>

Why this question matters

A supplier may receive the same greenhouse-gas question from a customer, bank and platform. One request can sit inside Annex II, another can be outside the statutory cap but commercially important, and a third can be required by a separate legal regime. Treating the datapoint as inherently 'capped' or 'not capped' produces the wrong answer.

Quick orientation

Quick orientation

Applies to
Mixed-purpose sustainability data requests from customers, banks, investors, procurement teams and digital platforms.
Primary decision
Which requester/purpose combinations fall within the statutory cap and which require separate legal or commercial analysis.
Key sources
Directive (EU) 2026/470, C(2026) 5011 recital 5 and Annex II.
Common confusion
Assuming that a bank is always outside the cap or that a procurement platform's mandatory field is automatically legally mandatory.

Technical status

CURRENT LEGAL STATUS

<p>Current legal status at 1 August 2026. The European Commission adopted C(2026) 5011 on 3 July 2026, but the delegated regulation had not yet entered into force because it remained subject to European Parliament and Council scrutiny and Official Journal publication. Its value-chain-cap article is intended to apply for financial years beginning on or after 1 January 2027. Directive (EU) 2026/470 is in force at EU level, but Member States have until 19 March 2027 to transpose the relevant reporting amendments. Confirm the current Official Journal and national-law position before relying on a statutory right, prohibition or formal compliance statement.</p>

The purpose test comes first

1. Identify the ultimate organisation that will use the data, not only the person or platform collecting it.

2. Ask which decision, report or legal obligation the information supports.

3. Separate CSRD sustainability reporting from lending, investment, due diligence, product compliance and voluntary procurement.

4. Confirm whether the respondent is a protected undertaking and which Annex II column applies.

5. Classify each datapoint and granularity separately; a mixed request can contain within-cap, above-cap and outside-cap lines.

6. Apply the relevant contract, legal basis, rights, notices and approvals to each purpose lane.

Purpose classification matrix

Figure 5. The same emissions datapoint can be within the cap for a customer's CSRD reporting, outside the cap for lending or due diligence, and subject to separate contract or legal controls. Purpose changes the treatment.

In practice

Requester and purpose Cap treatment Practical control
Customer asks for value-chain data for its CSRD report. Potentially within cap Test protected status, Annex II band, exact datapoint and necessity.
Bank asks a supplier/borrower for data for the bank's own CSRD sustainability report. Potentially within cap A bank can be a reporting undertaking; identify whether the respondent is in its value chain and the request is genuinely for CSRD reporting.
Bank asks for credit underwriting, pricing, covenant monitoring or portfolio risk. Outside statutory cap Review lending terms, financial regulation, data necessity and recital 5 encouragement separately.
Financial market participant requests data for SFDR, benchmark or investment-product purposes. Outside statutory cap Assess the separate regulatory and contractual basis; Annex I may support data reuse but is not a statutory ceiling for that purpose.
Customer asks for supply-chain due diligence. Outside statutory cap Directive expressly preserves requests for Union due-diligence requirements; check proportionality and applicable due-diligence law.
Customer asks for product, safety, customs, traceability or market-access compliance. Outside statutory cap Classify under the relevant product or sector law and contract.
Procurement team requests voluntary tender-scoring information. Usually outside statutory cap Confirm that the information is genuinely for procurement evaluation, not an indirect CSRD reporting request.
Procurement platform collects data for several customers and purposes. Mixed Require purpose tags, ultimate-requester identification and separate required/voluntary logic per field.
Undertaking voluntarily prepares an Annex I report for multiple users. Voluntary reporting choice The report may reduce repeated requests but does not convert every use into a capped CSRD request.

Banks: two distinct roles

A bank can act as a CSRD reporting undertaking, a lender, an investor, a financial market participant or several of these at once. The request should therefore state the bank's role and purpose. Where the bank seeks information from a protected undertaking for the bank's own Article 19a or 29a sustainability reporting, the cap can apply. Where the bank seeks the same information for credit risk, pricing, loan monitoring or another financial-services obligation, the request is outside this statutory cap.

Rule

FINANCIAL-INSTITUTION ENCOURAGEMENT

<p>Recital 5 of the Commission-adopted delegated act encourages financial institutions, financial market participants, insurers and credit institutions, for purposes beyond CSRD reporting, to limit requests from undertakings with 1,000 employees or fewer as far as possible to the information in Annex I. This is policy encouragement, not the same as the statutory Annex II cap or a supplier right to decline.</p>

In practice

Customers: reporting, due diligence and procurement are not interchangeable

Customer request Purpose evidence Result
Energy and GHG for ESRS value-chain reporting ESRS/reporting use, material matter and calculation need. Annex II cap test.
Human-rights questionnaire for due diligence Due-diligence policy, risk screening or legal requirement. Outside this cap; separate basis.
Product traceability and compliance certificate Product/market-access requirement. Outside this cap; sector/product rules.
Supplier scorecard for preferred-supplier status Tender or relationship-management criteria. Usually voluntary/contractual, unless also used as an indirect CSRD request.
One questionnaire serving all purposes Line-level purpose mapping. Mixed classification; split and label fields.

Procurement platforms: technology does not determine the law

The directive covers information requested directly or indirectly. A platform cannot turn an above-cap CSRD request into a valid mandatory field merely by acting as an intermediary. Equally, the platform may collect information for several lawful purposes outside the cap. The configuration must therefore preserve purpose, requester and legal-basis metadata.

In practice

Platform control Minimum field
Ultimate requester Legal name and reporting role of each customer using the data.
Purpose code CSRD reporting; lending; due diligence; product compliance; procurement; voluntary benchmarking; other.
Cap status Within Annex II; above Annex II; outside cap; pending clarification.
Mandatory flag Separate legal/contract basis; do not equate platform configuration with legal obligation.
Notice Above-cap identification and right-to-decline notice where applicable.
Data use and access Who receives the data, retention period, confidentiality and permitted reuse.
Version Question text, Annex II mapping version, purpose owner and change history.

Same datapoint, different treatment: worked example

For an 8-employee supplier, the same Scope 1/2 datapoint is not in the special Annex II column. Even for a customer's CSRD purpose, it would therefore be above the cap, illustrating why purpose and employee band must be tested together.

In practice

Request for Scope 1/2 emissions from a 120-employee supplier Treatment
Customer needs supplier information for its CSRD value-chain calculation. Potentially within Annex II, subject to necessity and national implementation.
Customer wants a detailed decarbonisation score for preferred-supplier ranking. Outside the statutory cap unless it is also a disguised/combined CSRD-reporting request; commercial terms apply.
Bank needs emissions for credit-risk assessment. Outside the statutory cap; lending and recital 5 considerations apply.
Bank needs emissions for its own CSRD reporting and the supplier is in its value chain. Potentially within the cap.
Buyer needs emissions under another product or sector legal regime. Outside this cap; assess that regime.

In practice

Purpose statement template

Field Example entry
Ultimate requester ABC Bank plc / XYZ Manufacturing Group.
Requester role CSRD reporting undertaking; lender; due-diligence principal; procurement buyer.
Purpose Specific report, decision or legal obligation supported.
Respondent relationship Supplier, customer, borrower, investee or other value-chain relationship.
Datapoints and granularity Exact fields, units, period, boundary and required methodology.
Cap classification Within, above, outside or mixed, with Annex II reference.
Other legal/contract basis Contract clause, due-diligence law, product rule, financing term or voluntary request.
Mandatory/voluntary status Legal obligation, contractual obligation, requested voluntarily or right to decline.
Data use Recipients, retention, onward sharing and confidentiality.

Hypothetical example: one platform, three purposes

A procurement platform collects energy, GHG, grievance and product-compliance data for a large retailer. The retailer confirms that energy and GHG support its CSRD report, grievance data support due diligence, and product information supports market-access compliance. The supplier has 75 employees.

The platform maps energy and GHG to Annex II and marks them potentially within cap; grievance and product fields are labelled outside the statutory cap with their separate legal/contract basis. A transition-plan request is marked above cap and voluntary, with the right-to-decline notice. The supplier can now make a controlled line-by-line response instead of treating the whole questionnaire as one legal category.

In practice

Weak versus stronger mixed-purpose request

Weak Stronger
“Requested by our bank” is the only purpose description. Identifies whether the bank acts for CSRD reporting, lending, investment or another regulatory purpose.
All platform fields are marked legally mandatory. Each field has a purpose, legal basis, cap status and voluntary/mandatory flag.
One consent permits unlimited reuse across customers. Permitted users, purposes, retention and onward sharing are specific and controlled.
A supplier relies on Annex II to reject product-compliance data. The product-law basis is reviewed independently from the cap.

Common mistakes

Classifying the request from the requester's industry rather than its legal role and purpose.

Assuming banks are always outside the cap or always entitled to the full Comprehensive Module.

Failing to separate a bank's CSRD reporting from credit-risk use.

Treating due-diligence or product-compliance requests as capped because the datapoint also appears in Annex I.

Using a procurement platform's 'mandatory' setting as evidence of a legal duty.

Bundling several purposes without line-level labels and notices.

Ignoring data-sharing, confidentiality and permitted-use controls when one platform serves multiple customers.

In practice

MYTH The legal treatment of an ESG datapoint is fixed once it appears in Annex II.
REALITY Annex II sets a ceiling only for qualifying CSRD-reporting requests to protected undertakings. The same datapoint can sit outside the statutory cap when requested for lending, due diligence, product compliance or voluntary procurement. Purpose, parties, employee band, necessity and other legal bases all matter.

Readiness

Mixed-purpose request checklist

  • The ultimate requester and its role are identified.
  • Every request category has a written purpose code.
  • CSRD-reporting fields are separated from lending, due diligence, product and procurement fields.
  • Protected status and employee band are current.
  • Annex II mapping and necessity are documented for the CSRD subset.
  • Above-cap fields and the right to decline are clearly identified.
  • Outside-cap fields have a separate legal or contractual basis.
  • Platform mandatory flags match the actual obligation.
  • Data use, recipients, retention and confidentiality are controlled.
  • The supplier receives a line-level explanation and contact for challenge.

In practice

Related requirements and next steps

Relation Reference Why it matters
Direct Directive (EU) 2026/470 other-purpose clause Confirms that the cap does not affect due-diligence and other-purpose requests.
Direct C(2026) 5011 recital 5 Encouragement for financial institutions beyond CSRD purposes.
Prerequisite EU Value Chain Cap Explained Within/above/outside classification and Annex II.
Prerequisite Protected Undertaking Test Respondent status and employee band.
Next step Can a Supplier Refuse an ESG Data Request? Purpose classification translated into a controlled response.

Take it with you

The checklists as a working spreadsheet

Every checklist and table on this page, with empty status, owner and evidence columns for your team to fill in and keep.

Download .xlsx

✓ LRA AI Assistant · Human-in-the-loop

Ask about this guide

It answers from this page, and reaches into the linked disclosure cards when your question is about the standard itself. Your first two answers are free without signing in.

Try
2 free answers Automated · the LRA team is one click away

Go deeper · EU Voluntary Standard 2026

ESG Reporting Full Stack

There is no standalone LRA course for this framework yet. The Full Stack programme covers the reporting system it sits in — materiality, data, drafting and assurance — with exercises on your own data.

Available as Guided Flex, Live Cohort, 1:1 Expert Mentorship or Corporate Programme.

See the Full Stack programme
/en/knowledge-hub/disclosure-guides/eu-voluntary/eu-voluntary-cap-scope-and-protected-status/does-the-eu-value-chain-cap-apply-to-banks-customers-and-procurement-p/