Level 2 · Decision guide·EU Voluntary Standard 2026 · Disclosure guides
Must an EU Voluntary Sustainability Report Be Public?
How to choose between a public report, management-report section, counterparty pack, lender pack and restricted evidence access without losing control of confidentiality or versions.
Published passport
Current as at 10 August 2026
Reviewed by
Dr Ross KurinkoLinkedIn
Strategic ESG Advisor · IFRS S1 & S2 / GRI / ESRS expert
GRI Certified Global Trainer · PhD, University of Cambridge · ESG-AI expert
15+ years on FTSE 100 & Fortune Global 500 disclosures
Canary Wharf, London
LRA educational guidance · Not issued or endorsed by European Commission
Edition written against
—
Published
10 Aug 2026
Knowledge Hub guide
Last reviewed
10 Aug 2026
Short answer
The answer, before the reasoning
No. The voluntary standard says that the report’s primary function is to inform actual or potential business counterparties and that the undertaking may decide to make it public. If it does so, it may use a separate section of its management report, where one exists, or a separate document.
The better operational question is therefore not “public or private?” in isolation, but which users need which approved information, through which controlled channel?
Technical status
EDITORIAL STATUS
<p>This article is publication-ready in structure and grounded in the Commission-adopted text. Before external release, confirm publication of the delegated regulation in the Official Journal, applicable national transposition, the reporting period, data-protection constraints and the final wording of any compliance statement.</p>
Why the publication question matters
Voluntary reporting projects often begin with a simple assumption: once a sustainability report exists, it should be uploaded to the website. That may be commercially sensible, but it is not the only model contemplated by the EU voluntary standard. The standard is designed first to help an undertaking communicate with business counterparties - including customers, lenders and other market users - and then permits the undertaking to choose public availability.
The choice affects much more than website design. A public report has a broad and partly unknown audience. A lender pack may be used in credit analysis. A customer pack may be reviewed by procurement or due-diligence teams. Supporting evidence may contain personal data, trade secrets, contract terms or system extracts that should never be released without a defined reason and access decision. Treating all of these as the same document creates avoidable confidentiality, consistency and governance risk.
Quick orientation
Figure 1. One controlled information core can support several delivery channels, each with its own audience and access rules. London Reporting Academy learning visual.
In practice
| Question | Practical answer |
|---|---|
| Must the report be public? | No. Public availability is an undertaking decision under the adopted standard. |
| What is its primary function? | To inform actual or potential business counterparties. |
| Where can a public report sit? | In a separate section of the management report, where the undertaking has one, or in a separate document. |
| Can other documents be cross-referenced? | Yes, when they are accessible at the same time and from the same document set. |
| Can sensitive information be omitted? | In specified circumstances and subject to disclosure and reassessment conditions. |
| Must all evidence be public? | No general requirement says that source evidence must be published. It should be traceable and access-controlled. |
What the standard actually says about location and timing
The reporting-location rules should be read as a sequence. First, where large undertakings or banks need an annual update, the sustainability report is prepared annually. Where the undertaking prepares financial statements, the sustainability reporting period is aligned with the period used for those statements. Second, the report’s primary function is to inform actual or potential business counterparties. Third, the undertaking decides whether to make the report public.
If the undertaking chooses public availability, the standard permits two presentation routes. It may place the sustainability report in a separate section of the management report, if it has one, or present the sustainability report as a separate document. This is a presentation choice. It does not by itself change the disclosures included in the selected module, the reporting basis, the period or the need to explain permitted omissions.
Rule
IMPORTANT DISTINCTION
<p>A public report is an access choice. A compliance statement for Option A or Option B is a content claim. Making a short customer extract public does not automatically make that extract the complete voluntary-standard report.</p>
Five delivery channels and what each one is for
1. Public standalone report
A standalone report is usually the clearest route when the undertaking wants a reusable public document for customers, employees, investors, communities and prospective lenders. It can be designed around the selected Basic or Basic-plus-Comprehensive option and can include a basis-of-preparation section, explanatory notes, links and a visible version date.
The public route also creates the widest exposure. The undertaking should assume that statements may be compared with financial statements, product claims, tender responses, policies and later reporting periods. Confidentiality review must therefore happen before publication, not after a sensitive datapoint has been circulated.
2. Separate section of the management report
Including the sustainability report in the management report can strengthen governance and period alignment because the sustainability information is presented beside financial and strategic information. It can also reduce duplication where the undertaking already publishes a management report. The sustainability section should remain identifiable, and any cross-references should lead to material that is available at the same time and from the same document set.
A management-report section is not automatically the best solution for every undertaking. Some smaller entities do not prepare or publish such a report. Others may want a concise counterparty-facing sustainability document rather than a longer corporate report. The standard recognises this by permitting a separate document.
3. Counterparty pack
A counterparty pack is a practical, purpose-specific output for a customer, distributor, tender authority or supply-chain partner. It may contain approved disclosures, a datapoint table, methodology notes and links to the complete report. This format can reduce friction because the recipient receives the information relevant to its request rather than a large publication with no navigation.
However, the pack must be labelled accurately. If it contains only selected information, call it an extract, response pack or sustainability information pack. Do not repeat the full Option A or Option B compliance statement in a way that implies the extract itself contains the entire selected module. Where the complete report exists, identify its location and version.
4. Lender or financing pack
Banks and other finance providers may need information to support credit, risk, covenant, sustainable-finance or portfolio processes. A lender pack can reuse the same approved metrics and narratives while adding clear explanations of reporting boundary, estimates, methodology, financial-statement linkages and data limitations.
Not every lender request is made for Accounting Directive sustainability reporting. The purpose should therefore be recorded separately. The value-chain cap has a defined reporting purpose and does not automatically govern every credit-risk or due-diligence request. A purpose label prevents the organisation from assuming either that every request is capped or that every request must be answered.
5. Restricted evidence access
Evidence is not simply a longer version of the report. It includes source-system extracts, calculations, contracts, invoices, employee records, incident files, approvals, estimation models and reviewer comments. Much of this material may be confidential, personal or commercially sensitive. The undertaking should maintain a controlled evidence register that identifies the owner, location, access level, retention period, report claim supported and review status.
A lender or customer may be given selected evidence under a secure process, but the decision should be purpose-specific. Where a summary, redacted extract, independent confirmation or methodology note meets the information need, unrestricted transfer of source records is usually unnecessary.
Confidentiality: omission is controlled, not silent
The adopted standard allows specified information to be omitted. The categories include information whose disclosure would, in exceptional cases, be seriously prejudicial to the undertaking’s commercial position; qualifying trade secrets; classified information; and other information protected from unauthorised access or disclosure by Union or national law or for the privacy or security of natural or legal persons.
This is not a general “confidential” tick-box. The undertaking should identify the exact datapoint, the applicable category, the reason the condition is met, the person approving the conclusion and the alternative wording that can still be disclosed. For each omitted datapoint, the undertaking discloses that it used the exemption, and it reassesses at every reporting date whether omission remains justified.
In practice
| Control question | Evidence to retain |
|---|---|
| What exact information is being withheld? | Datapoint identifier, draft answer and affected report version. |
| Which omission category applies? | Legal or commercial assessment linked to the relevant category. |
| Why would disclosure create the stated harm or breach? | Specific rationale; avoid generic “commercially sensitive” wording. |
| Who approved the omission? | Named business owner and legal/privacy review where appropriate. |
| How will use of the exemption be disclosed? | Approved public wording linked to B1 and the omitted datapoint. |
| When will it be reassessed? | Next reporting date and event-based triggers. |
Cross-references and document-set discipline
The standard permits cross-references to avoid publishing the same information twice, but the referenced disclosure must be accessible at the same time and from the same document set as the sustainability report. A link to a document that is behind an unrelated login, updated on a different timetable or likely to disappear creates a practical completeness problem.
Create a publication manifest before release. It should list the report, referenced policies, financial statements, appendices and methodology notes; record the version and access route for each item; and confirm that all public links work on the intended publication date. If a referenced document is later replaced, the manifest should show whether the report remains understandable and whether an archive version is needed.
Version control: one approved core, several outputs
The strongest operating model is not one identical file for every user. It is one controlled information core from which several approved outputs are generated. The core contains the selected module, reporting basis, reporting period, datapoint definitions, current values, narrative answers, omissions, evidence references, owners and approval status.
In practice
| Version field | Why it matters |
|---|---|
| Report ID and version | Distinguishes the current report from draft, superseded and recipient-specific files. |
| Reporting period and cut-off | Prevents a bank pack using later data while appearing identical to the public report. |
| Module and basis | Shows Option A or B and individual or consolidated reporting. |
| Recipient and purpose | Explains why an extract differs from another output. |
| Confidentiality classification | Controls public, shared-under-NDA and restricted information. |
| Approval date and approver | Shows which version was authorised for release. |
| Change log | Records corrections, restatements and updates after issue. |
| Evidence snapshot | Preserves the support available when the response was made. |
In practice
How user expectations differ
| User / channel | Typical expectation | Control response |
|---|---|---|
| Public reader | Understandable, balanced, navigable information and stable links. | Plain-language context, visible period and basis, accessible tables, public source set. |
| Customer / procurement | Fast answers to supplier questions, often in a portal or spreadsheet. | Mapped extract, clear purpose and period, response history, no uncontrolled copy-and-paste. |
| Bank / lender | Consistent metrics, methodology, limitations and evidence for risk or credit decisions. | Lender pack, controlled evidence access, estimates explained, finance consistency check. |
| Board / management | Confidence that external claims are coherent and approved. | Release summary, exception log, version and sign-off dashboard. |
| Assurance or reviewer | Traceability from disclosure to source and approval. | Evidence register, calculation files, change log and access to restricted support. |
A controlled publication workflow
1. Define the audience and purpose. Decide whether the output is a complete report, public management-report section, customer extract, lender pack or evidence response.
2. Lock the reporting identity. Confirm the undertaking, individual or consolidated basis, selected module, reporting period and cut-off date.
3. Build from the approved information core. Do not create a parallel spreadsheet simply because a recipient has a different template.
4. Apply confidentiality and data-protection review. Assess each sensitive datapoint and identify whether redaction, aggregation, omission or restricted evidence is appropriate.
5. Test completeness and labelling. Make clear whether the output is the complete selected module or a purpose-specific extract.
6. Approve and distribute. Record recipient, channel, access conditions, issue date, approver and evidence snapshot.
7. Monitor and correct. Retain the issued file, log later corrections and ensure public references remain accessible.
Hypothetical example: one manufacturer, three audiences
Context. Northbridge Components has 240 employees and prepares Option B information for the year ended 31 December. Its largest customer asks for environmental and workforce data, its bank asks for a credit-review pack, and management is considering publishing a sustainability report.
Decision. Northbridge approves one Option B reporting core. It publishes a standalone report containing the complete selected module, with a short confidentiality note for two permitted omissions. It sends the customer a mapped extract that identifies the full report and version. It sends the bank the same approved metrics plus methodology notes and a redacted energy-invoice sample through a restricted data room.
Control outcome. Every output shows the same reporting period, boundary and metric values. The customer and bank files are labelled as extracts rather than separate compliant reports. The evidence register records who accessed the invoice sample and why. When an emissions factor is corrected, Northbridge updates the core, issues a correction to both recipients and updates the public report change note.
Hypothetical scenario
ILLUSTRATIVE WORDING - PUBLIC AVAILABILITY
<p>“This sustainability report has been prepared for the year ended 31 December 20X6 using Option B of the EU voluntary sustainability reporting standard on a consolidated basis. The report is made publicly available as a separate document. Purpose-specific extracts may be provided to business counterparties; the complete report and its version are identified in each extract. Supporting evidence is retained under controlled access and is not part of the public report unless expressly referenced.” Illustrative wording only. Adapt it to the actual module, basis, period, publication channel, omissions and legal context.</p>
Illustrative only. It shows how the decision is made, not wording that can be copied or relied on.
In practice
Weak versus stronger publication wording
| Weak wording | Why it is weak | Stronger approach |
|---|---|---|
| “Our ESG report is available on request.” | No period, module, basis, version or explanation of what “ESG report” means. | Identify the voluntary-standard option, period, basis, current version, access route and whether the file is complete or an extract. |
| “Confidential data has been removed.” | No datapoint, category, condition, disclosure of exemption or reassessment. | Apply and document the paragraph 22 test for each datapoint and disclose use of the exemption. |
| “The bank has all supporting evidence.” | Overbroad and potentially inaccurate; may expose personal or commercial data. | Describe the evidence categories provided, access conditions and any redaction or alternative assurance. |
| “This customer questionnaire is our compliant report.” | A questionnaire may contain only selected items and different definitions. | Call it a mapped response extract and point to the complete selected module where appropriate. |
In practice
Common mistakes and corrections
| Mistake | Risk | Correction |
|---|---|---|
| Publishing a polished PDF built from a separate marketing spreadsheet. | Metrics diverge from lender and customer responses. | Generate all outputs from the approved reporting core and reconcile at release. |
| Treating all customer requests as public-report content. | Unnecessary disclosure and confidentiality risk. | Classify purpose and select the minimum appropriate access channel. |
| Using the full compliance statement in a partial extract. | Misleading completeness claim. | Label the extract accurately and identify the complete report/version. |
| Deleting sensitive answers without an omission record. | No defensible basis or reassessment trail. | Maintain datapoint-level exception approval and public exemption wording. |
| Linking to changeable policies without a document manifest. | Report may become incomplete or historically misleading. | Record referenced version and preserve accessible archive material. |
| Allowing each sales or finance team to answer independently. | Contradictory answers and uncontrolled disclosure. | Use designated owners, response history and approval thresholds. |
Myth
“A voluntary sustainability report is only credible if every calculation and source document is public.”
Reality
Credibility comes from clear scope, consistent data, transparent methods, balanced limitations and traceable evidence. Evidence may need to remain restricted because it contains personal data, trade secrets or commercially sensitive records. The correct model is public transparency where appropriate, controlled evidence where necessary, and no unsupported claims anywhere.
Readiness
Reader checklist
- The selected module and individual or consolidated basis are approved.
- The reporting period is aligned with the applicable financial-information period.
- The undertaking has explicitly decided whether the complete report will be public.
- Every issued extract states its recipient, purpose, period, version and completeness status.
- Public cross-references are available at the same time and from the same document set.
- Each confidentiality omission has a datapoint-level basis, approval, disclosure and reassessment date.
- Restricted evidence has an owner, access classification, retention period and distribution log.
- Customer, lender and public outputs reconcile to the approved reporting core.
- Corrections and superseded versions can be identified and communicated.
- Another law, contract or financing condition has been checked separately.
Self-check
- Why does optional public availability not mean that a partial public extract can be described as the complete Option A or Option B report?
- What conditions must be controlled when the undertaking omits a commercially sensitive datapoint?
- Which version fields would allow a reviewer to reconcile a customer pack with the public report six months later?
Related learning path
Next step: How to Answer Customer and Bank ESG Questionnaires Using the EU Voluntary Standard.
Commercial response: How to Respond to an Above-Cap Sustainability Data Request Without Damaging the Customer Relationship.
Requester perspective: How Large Companies Should Redesign Supplier ESG Questionnaires Around the Value Chain Cap.
Evidence and status: Protected Undertaking Self-Declaration: What Suppliers and Requesters Should Document.
Rule
USE OF THIS SECTION
<p>The following material supports technical review, CMS publication, AI retrieval and future updating. It is not intended to appear in full on the public web page.</p>
Take it with you
The checklists as a working spreadsheet
Every checklist and table on this page, with empty status, owner and evidence columns for your team to fill in and keep.
✓ LRA AI Assistant · Human-in-the-loop
Ask about this guide
It answers from this page, and reaches into the linked disclosure cards when your question is about the standard itself. Your first two answers are free without signing in.
Go deeper · EU Voluntary Standard 2026
ESG Reporting Full Stack
There is no standalone LRA course for this framework yet. The Full Stack programme covers the reporting system it sits in — materiality, data, drafting and assurance — with exercises on your own data.
Available as Guided Flex, Live Cohort, 1:1 Expert Mentorship or Corporate Programme.