Of interest.

ESGRR: A Practical Guide for ESG Rating Providers

On 2 July 2026, the new European Regulation on the transparency and integrity of ESG rating activities (ESGRR)[1] will take full effect, with the aim of enhancing the credibility, transparency, and comparability of ESG ratings, which are increasingly used by investors, financial institutions, and issuers in their investment and financial decision-making.

The ESG ratings market has, in fact, been the target of criticism for some time, particularly regarding the lack of transparency in methodologies, unclear assessment parameters, and potential conflicts of interest among rating providers. The ESGRR therefore establishes a uniform regulatory framework, oversight by the European Securities and Markets Authority (ESMA), and a requirement to obtain authorization to operate as an ESG rating provider. In this article, we will first examine the context of the ESGRR’s creation and its objectives, and then focus on the main obligations and requirements for ESG rating providers.

General Information on the ESGRR
Until now, ESG rating providers in the European Union have operated in an environment lacking uniform regulation and specialized oversight. Individual providers have used different methodologies, data sources, and approaches to sustainability assessment, which has led to limited comparability of ratings and, in many cases, uncertainty regarding what a specific rating actually evaluates. The European Commission has repeatedly highlighted these shortcomings as part of its initiatives in the area of sustainable finance, identifying insufficient transparency of methodologies, inconsistencies in assessments, and potential conflicts of interest among ESG rating providers as key issues. These concerns were subsequently confirmed by the European Commission’s 2022 public consultation, which highlighted significant differences between individual ESG ratings. In practice, this could lead (and did lead) to situations where different providers assigned completely different ratings to the same company.

The ESGRR is also part of the European Union’s broader regulatory framework for sustainable finance. It builds primarily on the SFDR, the Taxonomy Regulation, and the sustainability reporting rules under the CSRD.

The aim of the ESGRR is not to standardize the methodologies used or the resulting ratings, but to ensure that users have sufficient information to assess how the rating was derived, what factors it takes into account, and what its limitations are.

New requirements for disclosing relevant information about providers are intended to strengthen the integrity of the ESG ratings market, enhance investor protection, and ensure that ratings used in the European Union are high-quality, transparent, and sufficiently reliable. To this end, it introduces an obligation to obtain authorization from the European Securities and Markets Authority (ESMA), sets out extensive requirements for governance, conflict of interest management, methodologies, and disclosure, and simultaneously establishes unified EU supervision of ESG rating providers.

What is an ESG rating?
The basic prerequisite for determining whether a specific entity or its activities fall under the ESGRR is an assessment of whether the resulting product of those activities constitutes an ESG rating at all. According to Article 3 of the ESGRR, an ESG rating is defined as an opinion, a score, or a combination thereof regarding a rated item’s profile or characteristics, which is based on a rule-based methodology and a defined ranking system of rating categories and which assesses environmental, social, human rights, or governance factors, or exposure to related risks.

It follows from the definition that (i) it must be the result of an assessment activity, i.e., a specific opinion or score enabling the evaluation of the assessed entity, and at the same time (ii) such an assessment must be based on a predefined methodology and a defined rating system (for example, through a rating scale, score, or other classification).

At the same time, the Regulation explicitly confirms that an ESG rating does not always have to include all three ESG components. The regulation applies both to aggregated ESG ratings that combine environmental (E), social (S), and governance (G) factors, and to ratings focused solely on one of these areas. A provider may issue separate environmental, social, or governance ratings, or a combination thereof. However, if they provide an aggregated ESG rating, they must be transparent regarding how they combine the individual components and what weight they assign to them in the assessment.

Entities Subject to the ESGRR
An ESG rating provider is defined as a legal entity whose activities include the issuance, publication, or distribution of ESG ratings on a professional basis. This corresponds to the requirement that any legal entity wishing to operate as an ESG rating provider in the Union must be subject to one of the regimes enabling operation in the EU, in particular an ESMA authorization.

However, the ESGRR does not automatically apply to all products and services related to sustainability. Excluded from its scope are, in particular, ESG data products that do not contain an assessment element in the form of an ESG rating, as well as investment research, certain types of external assessments of sustainable bonds, and ratings created exclusively for accreditation or certification purposes.

At the same time, the regulation does not apply to private ESG ratings prepared on an individual order, provided they are not further distributed, nor to ESG ratings used exclusively for the internal needs of financial institutions or groups of companies. Non-commercial ESG ratings published by non-profit organizations, academics, journalists, or other individuals also remain outside the scope of the ESGRR, provided they are not provided for a fee or as part of a business activity.

ESMA Authorization to Provide ESG Ratings
The provision of ESG ratings in the European Union is a regulated activity; therefore, any legal entity wishing to operate as an ESG rating provider in the Union must fall under one of the regimes expressly provided for in the ESGRR. The basic regime is authorization issued by ESMA; in addition, the ESGRR also allows third-country providers to operate in the EU market based on an equivalence decision, an endorsement regime, or a recognition regime.[2]

The application for authorization must contain a comprehensive set of information enabling an assessment of whether the applicant meets all the requirements of the ESGRR. The application includes, among other things, information on the ownership structure, organizational structure, governance system, methodologies used in issuing ESG ratings, rules for managing conflicts of interest, outsourcing relationships, and internal control mechanisms. ESMA then assesses whether the applicant meets the conditions set out in the Regulation and decides whether to grant or deny authorization.

At the same time, the ESGRR introduces a special temporary regime for small ESG rating providers. These providers may operate for a limited period based on registration without having to obtain full authorization, subject only to selected provisions of the Regulation, particularly regarding organizational requirements and transparency.

Governance and Organizational Requirements for ESG Rating Providers
One of the key pillars of the ESGRR is the requirement that ESG rating providers have an appropriate governance and management system in place to ensure the independence, integrity, quality, and reliability of the ratings issued. The Regulation is not based solely on the requirement for transparency toward users of ratings, but also imposes on providers the obligation to establish an internal organizational structure and control mechanisms capable of preventing conflicts of interest and ensuring the consistent functioning of the rating process.

General Governance Principles – An ESG rating provider must establish and maintain appropriate policies, procedures, and organizational measures to ensure compliance with the requirements of the Regulation. These measures must include, in particular, effective internal control mechanisms, a clear division of responsibilities, an adequate record-keeping and documentation system, and sufficient human, technical, and financial resources necessary for the proper provision of ESG ratings.

Methodologies and the rating process – The ESGRR requires providers to use methodologies that are rigorous, systematic, and objective, based on relevant information, and that are continuously reviewed and updated at least once a year.

Internal control functions and oversight – ESG rating providers are required to establish effective internal oversight mechanisms for rating activities, including independent oversight tasked with monitoring the integrity of the rating process and the effectiveness of the safeguards in place. In connection with all of the above obligations, providers must maintain adequate records of the rating process, the data used, methodologies, decision-making processes, and measures taken regarding risk management and conflicts of interest.

Requirements for employees and persons involved in the rating process – Rating analysts, employees, and other persons involved in issuing ESG ratings must act independently and must not be influenced by the financial, commercial, or personal interests of the rated entities. A person involved in the rating process must not participate in the assessment if a conflict of interest could be considered (self-assessment, personal interest in the assessment, nepotism, or other conflict-of-interest situations).

Outsourcing and Intra-Group Relationships
The ESGRR explicitly permits ESG rating providers to outsource certain functions or services related to the provision of ESG ratings. At the same time, however, it stipulates that outsourcing must not lead to a weakening of the provider’s internal control mechanisms, a deterioration in the quality of ESG ratings, or a limitation on ESMA’s ability to exercise effective supervision over the provider.

The fundamental principle is that responsibility for fulfilling the obligations under the Regulation always remains with the ESG rating provider.[3] The Regulation also limits the scope of activities that may be outsourced. Outsourcing must not result in the transfer of senior management’s responsibility or create a situation where the ESG rating provider would effectively become merely a formal intermediary without sufficient in-house resources and expertise. The provider must continue to possess sufficient knowledge and expertise to be able to competently assess the results of outsourced activities and make appropriate decisions.

Outsourcing plays a significant role, particularly within corporate groups. Many ESG rating providers utilize centralized analytical, data, IT, or compliance functions provided by other entities within the group. The ESGRR does not preclude such arrangements but subjects them to the same requirements as outsourcing to third parties. The ESG rating provider must therefore be able to demonstrate the allocation of responsibilities among the various entities, the existence of appropriate control mechanisms, comprehensive contractual documentation of all relationships, a description of outsourced activities, and other relevant information.

Transparency of ESG Ratings, Disclosure Requirements, and ESAP
One of the most significant changes is the extensive transparency regime. Providers will be required to publish detailed information on their websites regarding individual ESG rating products, including the methodologies and models used, the assessed E, S, and G factors, the method of aggregating individual factors, and so on. The ESGRR distinguishes between two levels of disclosed information: (i) information intended for the general public, which must be published on the provider’s website, and (ii) more detailed information provided to users of ESG ratings.[4]

In particular, providers must disclose whether their rating assesses ESG risks, ESG impacts, or both; how it takes into account the principle of double materiality; which specific environmental, social, and governance factors are included in the assessment; whether there are limitations regarding data availability; and whether and how it uses estimates or proxy indicators. At the same time, there must be a transparent explanation of how the rating category system works, what methodologies and models are used, and what the key assumptions of the rating process are.

The ESGRR also builds on the European Single Access Point (ESAP) initiative, which aims to make regulatory information available in a standardized and easily searchable format.

ESMA Supervision and Sanctions
ESMA directly supervises compliance with the ESGRR and is responsible not only for authorizing ESG rating providers but also for the ongoing supervision of their activities. To this end, it has extensive investigative powers, including the right to request information and documents, and to conduct investigations and on-site inspections.

If ESMA identifies a breach of the obligations set out in the ESGRR, it may impose corrective measures, administrative fines, or penalties. Sanctions may be imposed, for example, for providing ESG ratings without the appropriate authorization, violating conflict-of-interest management rules, failing to meet organizational requirements, or breaching disclosure obligations. In the most serious cases, ESMA may also suspend or withdraw authorization to provide ESG ratings.

Conclusion
The ESGRR represents the first comprehensive European regulation of the ESG ratings market and, at the same time, a significant step toward greater transparency and credibility of sustainable finance in the European Union. Although it allows providers a considerable degree of flexibility in choosing methodologies and rating approaches, it introduces extensive requirements regarding organizational structure, conflict of interest management, outsourcing of activities, disclosure of information, and regulatory oversight. The provision of ESG ratings will thus be classified as a regulated activity subject to direct supervision by ESMA.

Both existing and future ESG rating providers will need to assess in a timely manner whether their products and activities actually fall within the scope of the ESGRR and subsequently evaluate their readiness for the new regulatory requirements. In addition to the authorization process itself (during which applicants will have to demonstrate that they meet a wide range of initial compliance requirements), subsequent implementation will primarily involve revising methodologies, establishing an appropriate governance system, assessing outsourcing and intra-group relationships, and preparing for extensive disclosure obligations.

There is not much time left until 2 July 2026, and the scope of the required measures is significant. Particularly for providers operating within international groups or utilizing a more extensive model of outsourcing activities, the implementation of ESGRR may require significant changes to current operations and the addition of necessary contractual documentation.

If you need to assess whether the ESGRR applies to your business, prepare for the authorization process before ESMA, or set up internal processes in accordance with the new regulation, please do not hesitate to contact us.


[1] Regulation (EU) 2024/3005 of the European Parliament and of the Council of 27 November 2024 on the transparency and integrity of environmental, social, and governance (ESG) rating activities and amending Regulations (EU) 2019/2088 and (EU) 2023/2859 (Text with EEA relevance)

[2] The equivalence regime is based on a decision by the European Commission that the legal and supervisory framework of a given third country is equivalent to the requirements of the ESGRR; the endorsement regime allows an ESG rating provider authorized in the EU to assume responsibility for ratings issued by an entity from the same group outside the EU and to distribute them within the Union, and the recognition regime allows selected third-country providers, particularly smaller entities, to obtain direct recognition from ESMA for meeting the conditions set out in the ESGRR; for further details, see Articles 10, 11, and 12 of the ESGRR.

[3] See Article 21 of the ESGRR.

[4] The Commission’s delegated regulation from April 2026 significantly elaborates on the content of the information to be disclosed and sets out a more detailed structure for the required disclosures.

 

Mgr. Jakub Málek, managing partner – malek@plegal.cz

Mgr. Ráchel Kouklíková, junior lawyer – kouklikova@plegal.cz

 

www.peytonlegal.en

 

11. 6 .2026

 

Back