DEV Community

Manu Shukla
Manu Shukla

Posted on • Originally published at ecorpit.com

BRSR Core reaches the top 1000 in FY2026-27: build the ESG data platform now

BRSR Core reaches the top 1000 in FY2026-27: build the ESG data platform now

Summary. SEBI's BRSR Core phasing widens to the top 1000 listed entities by market capitalisation in FY2026-27, after covering the top 150 in FY2023-24, the top 250 in FY2024-25 and the top 500 in FY2025-26. BRSR Core is a subset of the full Business Responsibility and Sustainability Report covering nine ESG attributes, from greenhouse gas footprint to openness of business, each backed by measured parameters and intensity ratios adjusted for purchasing power parity. The SEBI circular of 28 March 2025 replaced the earlier assurance-only framing with assessment or assurance and made value-chain ESG disclosures voluntary for the top 250 from FY2025-26, with value chain defined as partners individually accounting for 2 percent or more of purchases or sales, capped at 75 percent coverage by value. Full BRSR reporting has been mandatory for the top 1000 since FY2022-23, under a format first introduced in May 2021 and updated by the circular of 12 July 2023. One constraint shapes the whole delivery plan: SEBI requires the assurance provider to have no conflict of interest and to provide no non-audit or non-assurance services, including consulting, to the listed entity or its group. The firm that signs off your numbers cannot build the system that produces them. And because the underlying data includes wages, safety incidents and POSH complaints, the Digital Personal Data Protection Act, 2023 applies, with a ceiling of ₹250 crore for failure to take reasonable security safeguards.

What BRSR Core actually asks of your systems

BRSR itself has been mandatory for the top 1000 listed companies since FY2022-23, structured in three sections: general disclosures, management and process disclosures, and principle-wise performance disclosures mapped to the nine National Guidelines on Responsible Business Conduct principles.

BRSR Core narrows that to a smaller set of high-scrutiny metrics that must survive third-party review. Reading the nine attributes as a systems problem rather than a reporting problem changes what you build.

ESG attribute What the system must produce Where the data actually lives
Greenhouse gas footprint Scope 1 and Scope 2 totals with gas-wise break-up, plus emission intensity Utility bills, fuel logs, plant SCADA, fleet telematics
Water footprint Total consumption, consumption intensity, discharge by destination and treatment level Meter readings, effluent treatment plant logs
Energy footprint Total energy consumed, renewable share, energy intensity Utility bills, generation logs, purchase records
Embracing circularity Waste by specified category, total waste, waste intensity, recovery and disposal routes Weighbridge records, vendor manifests
Employee wellbeing and safety Wellbeing spend as a share of revenue, safety incidents including contract workforce Finance ledgers, EHS systems, contractor records
Gender diversity POSH complaints, gross wages paid to women as a share of wages HRMS, payroll, grievance registers
Inclusive development Share of inputs from MSMEs and small producers, wages in smaller towns Procurement master data, payroll geography
Fairness with customers and suppliers Data-breach instances as a share of security events, days of accounts payable Security incident register, accounts payable ageing
Openness of business Purchase and sales concentration with trading houses, dealers and related parties ERP transaction data, related-party master

Two observations follow from that table, and both are engineering problems.

The data sits in at least eight systems that were never designed to reconcile with each other. Payroll and procurement share no common key. Weighbridge data lives in a plant system nobody in the corporate office has read access to. Contractor safety records are held by the contractor.

And the metrics are ratios, not totals. Emission intensity, water intensity, energy intensity, waste intensity and the purchasing-power-parity-adjusted revenue ratios all divide an operational number by a financial one. That means the ESG numbers must reconcile to the audited financials, on the same entity boundary and the same reporting period. Most first-attempt ESG spreadsheets do not.

The constraint that decides your delivery model

SEBI's framework puts the responsibility for choosing a competent assurance provider on the board of the listed entity, and it requires that there is no conflict of interest with that provider. Specifically, the assurance provider and its associates must not sell their products to the entity or provide any non-audit or non-assurance services, including consulting, to the listed entity or its group entities.

That is a procurement rule with an architecture consequence. The Big Four firm reviewing your BRSR Core numbers cannot also be the firm that designs your emissions calculation methodology, builds your data pipelines or configures your ESG platform. Those are separate engagements with separate suppliers, and treating them as one is a conflict, not an efficiency.

For a listed entity entering the FY2026-27 wave, that means the build side needs an engineering partner and the sign-off side needs an independent assessor, contracted separately. Getting that sequencing wrong in procurement costs a quarter.

Assessment or assurance is not a softening

The March 2025 circular introduced flexibility between assessment and assurance for BRSR Core and for value-chain ESG disclosures. Read carelessly, that sounds like relief. It is not, and companies should stop relying on 2023-era summaries that still describe the regime only in reasonable-assurance language.

Reasonable assurance is a materially higher bar than the limited assurance common elsewhere. Under limited assurance, a reviewer can largely rely on management's disclosures. Reasonable assurance requires checking the organisation's ESG metrics and verifying disclosures against actual protocols, performance and standards. The evidence file has to exist independently of the narrative.

Requirement What a spreadsheet gives you What an evidence-grade system gives you
Source traceability A number typed by someone in March A row that links to the meter reading or invoice it came from
Methodology An email thread A versioned calculation with documented emission factors and boundaries
Restatements Overwritten cells An audit trail showing what changed, when and why
Entity boundary Assumed Explicit, and reconciled to the consolidated financials
Value-chain data Chased by email each January A supplier portal with submission timestamps
Access control Whoever has the file link Role-based, logged, and defensible under DPDP

The third row is the one that costs companies their first assurance cycle. Data gets restated during review, and without an audit trail there is no way to show the reviewer why the number moved.

Value chain: voluntary today, structural tomorrow

The current position, following the March 2025 update, is that ESG disclosures for the value chain apply to the top 250 listed entities on a voluntary basis from FY2025-26, with assessment or assurance of those disclosures voluntary from FY2026-27. SEBI's framing focuses on upstream and downstream partners that individually account for 2 percent or more of purchases or sales by value, and a listed entity may limit disclosure to cover 75 percent of total purchases and 75 percent of total sales by value, disclosing the percentage covered.

Voluntary is not the same as absent. A private company that is not itself subject to BRSR can still receive a data request from a listed customer preparing its disclosures, covering emissions, energy, water, waste, wages, safety, diversity, human rights and governance information. Suppliers to large listed groups should expect the request regardless of whether SEBI compels the buyer to ask.

The March 2025 update also added a leadership indicator under Principle 6 for green credits, asking companies to disclose how many green credits have been generated or procured by the listed entity and by its top ten value-chain partners by purchase and sales value. Green credits are an additional disclosure item. They do not substitute for emissions accounting, renewable electricity accounting or offsets, and conflating them in a dashboard is an easy way to fail review.

A build sequence that fits the FY2026-27 timeline

Companies entering scope in FY2026-27 are reporting on a financial year that has already started. The runway is for building the collection system during the year, not for reconstructing it in April 2027.

  1. Confirm applicability and boundary. Which entities consolidate, which joint ventures are in scope, which plants report.
  2. Map each of the nine attributes to a named data owner and a named source system. Where no system exists, that gap is your first build.
  3. Fix the ratio denominators first. Agree with finance which revenue figure, which entity boundary and which period every intensity ratio divides by.
  4. Build ingestion for the highest-volume sources: utility and fuel data, payroll, procurement, EHS. Manual entry survives only for genuinely low-frequency inputs.
  5. Version the methodology. Emission factors, boundaries, exclusions, assumptions and estimation approaches all need to be stored as data, not as a document.
  6. Build the evidence store: source documents linked to computed values, with immutable history.
  7. Add the value-chain portal only after internal data is stable. Chasing suppliers before your own numbers reconcile wastes the relationship.
  8. Run a dry review with an independent party before the real cycle, and treat every question they cannot answer from the system as a defect.

Step 3 is where most programmes are won or lost. If finance and sustainability disagree about the revenue denominator in November, the disagreement is a meeting. If they disagree in the middle of an assurance cycle, it is a restatement.

The DPDP overlap nobody plans for

BRSR Core requires wage data broken down by gender, safety incidents naming contract workers, POSH complaint counts and payroll geography. That is personal data, and in several cases sensitive personal data, moving out of HR systems into a reporting platform with a wider audience than HR ever had.

Under the Digital Personal Data Protection Act, 2023, penalties are fixed rupee amounts in the Schedule rather than a share of turnover, and they are assessed per instance. Failure to take reasonable security safeguards to prevent a personal data breach carries a ceiling of ₹250 crore. Failure to notify the Data Protection Board of India and affected individuals carries ₹200 crore. Building an ESG platform that copies raw payroll rows into a broadly readable warehouse creates that exposure for the sake of two aggregate numbers.

The engineering answer is aggregation at the boundary: compute the gender wage ratio and the smaller-towns wage share inside the HR domain, and publish only the aggregates to the ESG layer, with the underlying records reachable through a controlled, logged path for assurance purposes. Our DPDP Act engineering playbook sets out that boundary pattern in more detail, and it applies almost unchanged here.

Listed entities running several 2026 compliance programmes at once should also look at where they overlap. The SEBI digital accessibility audit deadline lands in the same period and draws on the same corporate governance function, and the evidence discipline behind SOC 2 and ISO 27001 audit readiness is the same discipline BRSR Core assurance asks for.

Build, buy or configure

There are three routes and the honest answer depends on how messy your source systems are, not on the size of the company.

Route Fits when Main risk Time to first reportable cycle
ESG SaaS platform, configured Data already sits in a small number of clean systems Vendor data model fights your entity boundary Fastest when sources are clean
Custom data platform Many plants, heavy manual sources, unusual boundaries Build cost and internal ownership Longer, but fits the actual estate
Extend the existing data warehouse A working warehouse and a data team already exist ESG requirements get deprioritised against BI work Medium, depends on team capacity
Spreadsheets plus consultants Only for a first, single-year filing No audit trail, no repeatability Fast once, painful annually
Hybrid: SaaS front end, custom ingestion Common in manufacturing groups Two suppliers, one integration seam Medium

Timeframes above are directional. Anyone quoting a fixed duration without seeing your source systems is guessing.

Manufacturing groups usually land on the hybrid or custom routes, because plant-level energy, water and waste data rarely arrives in a form a generic connector understands. Where an industrial data layer already exists for operations, the ESG platform should read from it rather than duplicate it; our work on Industry 4.0 and manufacturing AI covers that shared foundation. Groups with a distributed supplier base should expect the value-chain portal to be the longest pole, which is a supply-chain systems problem more than an ESG one, close to what we describe in logistics and supply chain application development.

What eCorpIT does on this work

We build the data platform side, not the assurance side, which is the correct separation under SEBI's conflict-of-interest requirement.

That means source system integration for utility, fuel, payroll, procurement and EHS data; a versioned calculation layer where emission factors, boundaries and estimation methods are stored as data with history; an evidence store linking every computed value to its source document; role-based access with logging designed aligned with DPDP Act requirements; a supplier submission portal for value-chain data; and reconciliation of every intensity ratio denominator against the audited financials. Our data platform engineering service covers the underlying build, and reporting output can sit on whatever BI layer the group already runs.

Engagements typically run as a scoping phase covering applicability, boundary and source mapping, then an ingestion and calculation build, then an evidence and access layer, then a dry-run review cycle. We do not act as your assessor or assurance provider, and we would tell you to keep those contracts separate even if we could.

FAQ

When does BRSR Core apply to the top 1000 listed entities?

The BRSR Core assessment or assurance requirement applies in phases by market capitalisation: the top 150 listed companies in FY2023-24, the top 250 in FY2024-25, the top 500 in FY2025-26 and the top 1000 in FY2026-27. Full BRSR reporting has been mandatory for the top 1000 since FY2022-23.

What are the nine BRSR Core ESG attributes?

They are greenhouse gas footprint, water footprint, energy footprint, embracing circularity including waste management, employee wellbeing and safety, enabling gender diversity in business, enabling inclusive development, fairness in engaging with customers and suppliers, and openness of business. Each carries specified parameters and, for the environmental attributes, intensity ratios.

Can our assurance provider also build the ESG data platform?

No. SEBI requires the listed entity to ensure there is no conflict of interest with the assurance provider, and that the provider and its associates do not sell products or provide non-audit or non-assurance services, including consulting, to the entity or its group. Build and sign-off must be contracted to separate suppliers.

Are value-chain ESG disclosures mandatory now?

Following the March 2025 SEBI circular, ESG disclosures for the value chain apply to the top 250 listed entities on a voluntary basis from FY2025-26, with assessment or assurance voluntary from FY2026-27. Suppliers may still receive data requests from listed customers preparing disclosures, regardless of whether the buyer is compelled.

How is the value chain defined for these disclosures?

SEBI's current framing covers upstream and downstream partners that individually account for 2 percent or more of the listed entity's purchases or sales by value. An entity may limit disclosure to cover 75 percent of total purchases and 75 percent of total sales by value, and should disclose the percentage of purchases and sales actually covered.

Why do intensity ratios complicate the build?

Intensity ratios divide an operational measure such as emissions, water, energy or waste by a financial measure, with revenue adjusted for purchasing power parity used for comparability. That forces the ESG data to reconcile with the audited financials on the same entity boundary and reporting period, which spreadsheets assembled separately rarely do.

Does the DPDP Act apply to ESG reporting data?

Yes, where the underlying data includes wages by gender, safety incidents naming individuals, POSH complaints or payroll geography. Penalties under the Schedule are fixed rupee amounts assessed per instance, up to ₹250 crore for failure to take reasonable security safeguards and ₹200 crore for failure to notify a breach.

What should a company entering scope in FY2026-27 do first?

Confirm applicability and the consolidation boundary, then map each of the nine attributes to a named data owner and source system, then agree the denominators for every intensity ratio with finance. Those three steps decide whether the rest of the programme is an engineering build or an annual firefight.

How eCorpIT can help

eCorpIT is a Gurugram-based technology consultancy founded in 2021, working with Indian listed groups and their suppliers on the data engineering behind compliance reporting. Our senior engineering teams handle source-system integration, versioned calculation layers, evidence stores and supplier portals, and we design applications aligned with DPDP Act requirements rather than claiming certifications we do not hold. We are CMMI Level 5, MSME certified and ISO 27001:2022 certified, and we work with AWS, Microsoft and Google platforms. If BRSR Core reaches your entity in FY2026-27 and the data still lives in spreadsheets, talk to our data engineering team.

References

  1. BRSR and sustainability reporting requirements in India — Keslio, current position after the March 2025 circular, updated 25 May 2026.
  2. SEBI circular on BRSR Core framework for assurance and ESG disclosures for value chain — SEBI, 12 July 2023.
  3. SEBI March 2025 circular on assessment or assurance, value-chain ESG disclosures and green credits — SEBI.
  4. SEBI Industry Standards on Reporting of BRSR Core — SEBI, December 2024.
  5. SEBI January 2026 LODR master circular — SEBI.
  6. Format of BRSR Core, Annexure I — SEBI, attribute-by-attribute parameters and assurance approach.
  7. ESG reporting in India: BRSR Core, ERP rules and ISSB standards — India Briefing, Dezan Shira & Associates.
  8. SEBI circular on Business Responsibility and Sustainability Reporting by listed entities — SEBI, May 2021.
  9. Penalties and adjudication under India's DPDP Act, 2023 — King Stubb & Kasiva.
  10. Updated BRSR format, Annexure II — SEBI.
  11. Master circular for ESG rating providers — SEBI.
  12. IFRS S1 and IFRS S2 sustainability disclosure standards — ISSB.

Last updated: 4 August 2026.

Top comments (0)