SUST

Notícias · 4 min · 30/07/2026

Sustainability’s Next Challenge Isn’t Reporting – It’s Building Better Data

Guest post by: Jim Hietala, Vice President, Sustainability and Market Development for The Open Group […]

Sustainability’s Next Challenge Isn’t Reporting – It’s Building Better Data

Guest post by: Jim Hietala, Vice President, Sustainability and Market Development for The Open Group

There is a pattern that shows up whenever an industry experiences a wave of new regulation.

The first response is usually predictable: organizations focus on compliance. New reporting requirements appear, teams are assembled, consultants are hired, spreadsheets multiply, and everyone works hard to demonstrate that they’re meeting the latest obligations.

It’s a rational response. Regulators expect disclosures, investors want transparency, and companies need to show progress. But over time, a different question starts to emerge: are we spending more effort proving we’re doing something than actually improving outcomes?

I’ve seen this dynamic before.

In the early 2000s, cybersecurity teams found themselves navigating an increasingly fragmented regulatory environment. Requirements and industry standards arrived in quick succession. Each framework had different terminology, evidence requirements and approaches to demonstrating compliance.

Organizations responded by building separate compliance processes around each requirement. The result was predictable: duplication, complexity and growing operational costs. The sustainability world today feels remarkably familiar.

Companies are simultaneously responding to a growing list of national, regional and supply-chain disclosure requirements. Each serves a purpose. Each reflects legitimate stakeholder needs. But collectively, they create a risk that should sound recognizable to anyone who has lived through previous compliance cycles. Organizations can begin optimizing for disclosure rather than decarbonisation.

The compliance trap

One of the most important lessons cybersecurity learned was that compliance and outcomes are not the same thing.

By the mid-2000s, it was entirely possible for an organization to pass audits and satisfy regulatory requirements while remaining exposed to significant cyber risk. The compliance boxes had been checked. The underlying problem had not necessarily been solved. Eventually, the industry shifted its focus. The conversation moved from “Are we compliant?” to “Are we secure?”

That change in thinking transformed how cybersecurity programs were built. Rather than designing processes around individual regulations, organizations began investing in shared controls, common data models and risk-management frameworks that could support multiple requirements simultaneously.

Compliance became an output of a well-functioning system rather than the primary objective. Sustainability is approaching a similar moment. Reporting remains essential. Few sustainability leaders would argue otherwise. But disclosure alone does not reduce emissions. Reporting frameworks can tell us what happened; they do not automatically help organizations understand what actions to take next.

The real challenge is ensuring that reporting requirements do not consume so much attention and resource that they crowd out the work of actually reducing emissions.

Scope 3 exposes the problem

If there is one area where this tension becomes obvious, it is Scope 3 emissions. Most organizations now recognize that the majority of their emissions sit outside their direct operations. Yet collecting reliable emissions data across complex supply chains remains extraordinarily difficult.

The default response has often been to request more information. More supplier surveys. More questionnaires. More reporting exercises. But anyone who has worked with large supply chains knows that more requests do not necessarily produce better data.

Cybersecurity encountered an almost identical problem through third-party risk management. Large organizations were sending lengthy security questionnaires to vendors, often asking for essentially the same information in slightly different formats. Vendors spent enormous amounts of time responding. Buyers spent enormous amounts of time reviewing responses.

The process generated activity, but not always insight. The breakthrough came when industries began collaborating around common frameworks and standardized approaches.

The sustainability world is beginning to move in the same direction. Initiatives such as Open Footprint® Forum and PACT are working toward shared data standards that allow organizations to collect emissions information once and use it across multiple reporting requirements. The underlying logic is simple but powerful: standardize the data layer rather than continually expand the reporting one.

Why AI makes this more urgent

There is another reason this matters. Virtually every sustainability team is now exploring how artificial intelligence can help with reporting, emissions analysis, supplier engagement and reduction planning.

The opportunity is real. But AI introduces a challenge that cybersecurity teams learned long ago. AI is only as useful as the data beneath it.

Organizations often talk about applying AI to sustainability, but many are still managing emissions data through disconnected systems, spreadsheets and inconsistent supplier submissions. If the underlying data lacks structure, consistency and comparability, AI will simply process poor-quality information faster.

The organizations most likely to benefit from AI are not necessarily the ones collecting the most data but the ones building the strongest data foundations.

That means investing in standardized emissions data, common methodologies and systems that can support multiple use cases beyond reporting.

A shift from reporting systems to decision systems

The practical lesson from cybersecurity is not that compliance is unimportant. It is that compliance works best when it sits on top of a strong operational foundation. For sustainability leaders, that means thinking beyond the next disclosure deadline and asking a broader question: does our emissions data help us make better decisions?

Can it identify reduction opportunities?

Can it support supplier engagement?

Can it inform investment decisions?

Can it scale as reporting requirements evolve?

Organizations that build around those questions will find themselves in a stronger position regardless of what new regulations emerge.

The sustainability community does not need fewer disclosures. Transparency remains essential. What it does need is a stronger focus on the underlying emissions data infrastructure that makes meaningful action possible.

The lesson from cybersecurity is that fragmented compliance eventually reaches its limits. The organizations that move ahead are the ones that stop treating reporting as the destination and start treating it as a by-product of better systems.

For sustainability, that shift may be the difference between measuring emissions and actually reducing them.

Ler conteúdo