Author: William Tygart

  • Top Commercial Real Estate ESG Programs: Leaders, Benchmarks, and What Makes One Best-in-Class

    The leading commercial real estate (CRE) ESG programs share a common backbone: a validated net-zero-by-2040 target covering Scopes 1, 2, and 3; annual GRESB benchmarking with a 5-star rating and “Green Star” recognition; a portfolio certified to LEED, BREEAM, and ENERGY STAR; and disclosure aligned to the ISSB (IFRS S1/S2), GRI, and, where in scope, the EU CSRD. As of 2025, firms such as Prologis (net zero by 2040), JLL and CBRE (both SBTi-validated net zero by 2040), BXP, Kilroy, Hines, Brookfield, and Tishman Speyer set the pace. What separates a best-in-class program from a marketing claim is third-party validation of targets, audited data, embodied-carbon (Scope 3) accountability, and capital actually deployed against the plan.

    What does an ESG program actually mean in commercial real estate?

    In CRE, “ESG” is the discipline of measuring and managing a building portfolio’s environmental footprint, social impact, and governance quality, then disclosing that performance to investors, lenders, tenants, and regulators. Because buildings account for roughly a third or more of global energy-related emissions, the environmental pillar dominates: energy and water efficiency, on-site and procured renewables, waste diversion, and the carbon embedded in construction materials. The social pillar covers tenant health and wellbeing, community investment, diversity, and workforce practices. Governance covers board oversight of climate risk, data assurance, executive compensation tied to ESG metrics, and ethics.

    For owners and REITs, ESG is increasingly financial rather than reputational. Green-certified, energy-efficient assets command rent and valuation premiums, qualify for green financing, and face lower obsolescence risk as building-performance standards (BPS) and embodied-carbon rules spread across U.S. and European cities. For services firms such as JLL and CBRE, ESG is also a product line: they advise owners on decarbonization and manage millions of square feet against client sustainability goals.

    How do leading CRE firms structure their ESG programs?

    A best-in-class CRE ESG program is built on five structural elements: a science-aligned decarbonization target, a benchmarking and certification regime, a data-and-assurance backbone, governance with board-level accountability, and transparent reporting under recognized frameworks. The strongest programs treat these as an integrated system rather than separate initiatives.

    Net-zero and carbon-reduction targets

    The current standard is a long-dated net-zero target supported by near-term interim milestones, ideally validated by the Science Based Targets initiative (SBTi). Examples reported by the companies themselves:

    • Prologis has committed to net zero emissions by 2040 across Scopes 1, 2, and 3, with interim goals including 1 gigawatt of solar generation (plus storage) and submission of its net-zero target to the SBTi for validation. Because most of Prologis’s footprint is Scope 3, progress depends on customer and supply-chain partnership rather than direct control.
    • JLL was one of the first seven companies to receive SBTi-validated net-zero targets under the Net-Zero Standard in October 2021, committing to net zero across its value chain by 2040, with absolute reductions of 51% by 2030 and 95% by 2040.
    • CBRE has committed to net zero across its value chain by 2040, with SBTi-validated near-term 2030 targets to cut Scope 1 and 2 by 50% and emissions from managed properties by 55% per square foot from a 2019 baseline.
    • BXP (formerly Boston Properties) pursued carbon-neutral operations and set an emissions target aligned to a 1.5°C trajectory under the SBTi.
    • Kilroy Realty reports achieving carbon-neutral operations and has been recognized by GRESB as a regional sustainability leader among publicly traded real estate companies in the Americas.
    • Tishman Speyer has committed to net zero carbon emissions by 2050.

    The credibility test is not the headline year but the structure beneath it: a baseline year, interim targets, third-party validation, and an explicit plan for Scope 3, which for most owners is the largest and hardest category.

    GRESB benchmarking

    GRESB (the Global Real Estate Sustainability Benchmark) is the de facto ESG benchmark for the sector. In the 2025 Real Estate Assessment, 1,002 fund managers submitted 2,382 assessments, with the Standing Investments average score rising to 79 and Development to 87.9; a new Residential Component debuted at 80.1. Leading firms participate every year, target a 5-star rating (the top quintile), and earn “Green Star” recognition for balancing strong management with strong performance. GRESB scores are widely used by institutional investors to compare funds and to drive engagement, so a high, improving GRESB result is one of the clearest external signals of a serious program.

    Green-building certifications

    Certifications translate building performance into a market-recognized label. The three most common in CRE differ in geography, scope, and method:

    Certification Owner / scope Primary geography What it measures 2025 note
    LEED U.S. Green Building Council (USGBC); design, construction, operations U.S. and global Holistic: energy, water, materials, indoor environment, location LEED v5 launched April 28, 2025; certification opened Nov 3, 2025. About 50% of credits now tied to decarbonization; Platinum requires minimum carbon reductions and effectively fully electric systems.
    BREEAM Building Research Establishment (BRE); uses licensed assessors UK and Europe Weighted scoring across categories; results expressed as a percentage Dominant benchmark in European portfolios; assessor-verified evidence.
    ENERGY STAR U.S. EPA; operational benchmarking U.S. Energy-efficiency performance only (1-100 score) Narrower than LEED/BREEAM; widely used as an operational baseline across U.S. portfolios.

    BXP, for example, has reported certifying roughly 34 million square feet of its portfolio to LEED, with most of its actively managed office space certified and a large share at Gold and Platinum levels. The strongest programs use ENERGY STAR for operational benchmarking, LEED or BREEAM for whole-asset certification, and increasingly track WELL or Fitwel for the health/social dimension.

    Embodied carbon and Scope 3

    The frontier of CRE ESG is embodied carbon, the emissions locked into concrete, steel, and other materials before a building opens. Per the GHG Protocol, embodied carbon almost always lands in Scope 3 (Purchased Goods and Services, Capital Goods, and transportation), and for developers it can rival or exceed decades of operational emissions. Leading developers now require Environmental Product Declarations (EPDs) to compare and select lower-carbon materials, calculate whole-life carbon, and specify low-carbon concrete and steel. Regulators are catching up: California’s climate-disclosure laws phase in large-company reporting including Scope 3 on 2026 data, and cities from Boston to Los Angeles are weighing embodied-carbon limits in building permits. A program that reports only operational (Scope 1 and 2) emissions while ignoring embodied carbon is incomplete by current standards.

    Social and governance practices

    On the social side, leaders invest in tenant health (air quality, daylight, amenities), community development, affordable or workforce housing where relevant, and supplier diversity. On governance, the markers are board- or committee-level oversight of climate risk (BXP, for instance, established a board sustainability committee), third-party assurance of ESG data, linkage of executive compensation to sustainability KPIs, and clear climate-risk scenario analysis. Governance is what makes the environmental and social claims auditable rather than aspirational.

    What reporting frameworks do CRE companies use?

    Disclosure has consolidated rapidly. The key frameworks a CRE sustainability lead should know in 2025-2026:

    • ISSB (IFRS S1 and S2) are the emerging global baseline. IFRS S2 fully incorporates the TCFD recommendations and, in effect, replaces TCFD, which disbanded on January 1, 2024, with the IFRS Foundation assuming its monitoring role. By mid-2025, more than 30 jurisdictions representing over 60% of global GDP had committed to adopting or aligning with the ISSB standards. The ISSB issued amendments in 2025 to ease implementation of certain Scope 3 GHG disclosures.
    • GRI (Global Reporting Initiative) remains the most widely used framework for multi-stakeholder impact reporting and uses a double-materiality lens.
    • TCFD (Task Force on Climate-related Financial Disclosures) is now legacy but its four-pillar structure (governance, strategy, risk management, metrics and targets) lives on inside IFRS S2.
    • EU CSRD (Corporate Sustainability Reporting Directive) requires reporting under the European Sustainability Reporting Standards (ESRS) on a double-materiality basis. The 2025 “Omnibus I” simplification narrows scope to EU entities with more than 1,000 employees and over €450 million net turnover, cutting the number of in-scope companies sharply and reducing ESRS data points; the changes enter into force on March 18, 2026, with member states given 12 months to transpose them.

    The practical implication: ISSB and CSRD differ on materiality. ISSB looks only at financial materiality (how sustainability affects the business), while CSRD and GRI apply double materiality (also how the business affects people and the environment). A global CRE firm typically maps its disclosures to both.

    Why is GRESB the key ESG benchmark for CRE?

    GRESB matters because it is investor-driven and asset-specific. Unlike a generic corporate ESG rating, GRESB scores real-estate funds and portfolios on a standardized methodology covering both management (policies, governance, stakeholder engagement) and performance (energy, GHG, water, waste, certifications, data coverage). Institutional capital allocators use GRESB results in due diligence and ongoing engagement, which gives the benchmark real teeth: a slipping GRESB score can trigger investor questions, while a 5-star “Green Star” result is a credible, comparable signal. Because the 2025 cycle drew over 2,300 assessments globally, GRESB also functions as the industry’s largest pooled dataset, letting managers benchmark against true peers rather than self-selected narratives.

    What distinguishes a best-in-class CRE ESG program? (A rubric)

    Use the following rubric to separate leading programs from box-checking. Leaders score “strong” across most rows; laggards cluster in “basic” or “absent.”

    Attribute Best-in-class (strong) Developing (basic) Laggard (absent)
    Decarbonization target SBTi-validated net zero by 2040, interim 2030 milestones, all scopes Self-set net-zero year, no validation No target or operations-only
    Scope 3 / embodied carbon Measured and managed; EPDs and whole-life carbon for new development Scope 3 estimated, embodied carbon not addressed Scope 1 and 2 only
    GRESB Annual participation, 5-star, Green Star, improving trend Participates, mid-tier score Does not participate
    Certifications Majority of portfolio LEED/BREEAM; ENERGY STAR benchmarking; WELL/Fitwel for health Flagship assets certified only No certifications
    Data and assurance Audited/third-party-assured data, high coverage, like-for-like tracking Self-reported, partial coverage Anecdotal or absent
    Reporting frameworks ISSB/IFRS S2, GRI, CSRD where in scope One framework, partial alignment Press-release-only
    Governance Board/committee oversight, exec comp linked to ESG KPIs Management-level only No formal oversight
    Capital deployment Funded retrofit/renewable pipeline, green financing Pilots only No capital committed

    The single most important distinction is the gap between targets and execution. A validated 2040 net-zero target is only credible if it is paired with funded retrofits, on-site or contracted renewables, assured data, and a real Scope 3 plan. Programs that publish ambitious commitments without capital, coverage, or assurance behind them are, by current professional standards, incomplete.

    How should an asset or REIT investor evaluate a CRE ESG program?

    Start with the disclosures, not the marketing. Pull the company’s latest sustainability or annual ESG report and its GRESB result, then check: Is the net-zero target SBTi-validated, and does it cover Scope 3? What share of the portfolio is certified and ENERGY STAR-benchmarked? Is the emissions data third-party assured, and what is the data-coverage percentage? Is there board-level governance and exec-comp linkage? For new development, is embodied carbon measured? Finally, look for a funded transition plan, because the strongest signal a program is real is capital flowing into retrofits, electrification, and renewables, not just a commitment slide.

    Frequently asked questions

    What is GRESB and why does it matter in CRE?

    GRESB is the Global Real Estate Sustainability Benchmark, an investor-driven standard that scores real-estate funds and portfolios on management and performance. In 2025 it drew 1,002 fund managers and 2,382 assessments. Institutional investors use GRESB scores in due diligence, so a 5-star “Green Star” rating is a widely trusted signal of a strong ESG program.

    What is the difference between LEED, BREEAM, and ENERGY STAR?

    LEED (USGBC, U.S.-led and global) and BREEAM (BRE, UK and Europe) are holistic, whole-building certifications covering energy, water, materials, and indoor environment; BREEAM uses licensed assessors and percentage scores, while LEED uses points. ENERGY STAR (U.S. EPA) is narrower, scoring only operational energy efficiency. LEED v5, launched in 2025, ties about half its credits to decarbonization.

    What net-zero targets have major CRE firms set?

    Prologis targets net zero by 2040 across all scopes. JLL and CBRE both target net zero across their value chains by 2040 with SBTi-validated interim 2030 goals. Tishman Speyer has committed to net zero by 2050, and Kilroy reports carbon-neutral operations. The credibility marker is SBTi validation plus a Scope 3 plan, not the headline year alone.

    What is embodied carbon and why is it now central to CRE ESG?

    Embodied carbon is the emissions tied to producing and installing building materials such as concrete and steel. Per the GHG Protocol it falls under Scope 3, and for new development it can rival decades of operational emissions. Leaders use Environmental Product Declarations (EPDs) and whole-life carbon analysis, and regulators in California and several cities are moving to require disclosure or limits.

    Is TCFD still required, or has ISSB replaced it?

    TCFD disbanded on January 1, 2024, and its recommendations are now embedded in the ISSB’s IFRS S2 standard, which the IFRS Foundation oversees. Companies that previously reported to TCFD generally transition to IFRS S1 and S2, which more than 30 jurisdictions have committed to adopt or align with as of mid-2025.

    How does the EU CSRD affect U.S. CRE firms?

    CSRD requires reporting under the ESRS on a double-materiality basis and can reach non-EU groups with significant EU operations. The 2025 “Omnibus I” package narrowed scope to entities with more than 1,000 employees and over €450 million net turnover and cut ESRS data points; the revisions enter into force on March 18, 2026. U.S. CRE firms with large European footprints should confirm whether they remain in scope.

    What single factor best signals a credible CRE ESG program?

    Capital deployment against a validated plan. Ambitious targets are common; what distinguishes leaders is funded retrofits, electrification, contracted renewables, high data coverage with third-party assurance, and a concrete Scope 3 strategy. A strong, improving GRESB score plus SBTi-validated targets is the fastest external proxy for that underlying execution.

    Sources & further reading

  • Business Continuity in the Hotel Industry: Resilience and Continuity Planning for Hospitality

    Business continuity in the hotel industry is the discipline of keeping a property safe, operational, and revenue-generating through disruptions such as hurricanes, cyberattacks, power loss, pandemics, and staffing crises. The internationally recognized framework is ISO 22301, the standard for business continuity management systems (BCMS), which runs on a Plan-Do-Check-Act lifecycle built around a Business Impact Analysis (BIA), defined Recovery Time and Recovery Point Objectives (RTO/RPO), tested recovery strategies, and rehearsed crisis communications. For hotels, the stakes are unusually high because the asset, the workforce, the guests, and the data systems all sit under one roof, and a single outage can simultaneously threaten life safety, brand reputation, and asset value.

    What is business continuity in the hotel industry?

    Business continuity (BC) is the capability of a hotel to continue delivering products and services at acceptable, predefined levels following a disruptive incident. It is broader than disaster recovery, which focuses narrowly on restoring IT systems and data. Business continuity covers the whole operation: front desk and reservations, housekeeping, food and beverage, the property management system (PMS), payment processing, life-safety systems, guest communications, and the supply chain that feeds linens, food, and energy into the building.

    Hotels are a uniquely concentrated risk environment. Unlike an office that empties at night, a hotel is occupied 24 hours a day by guests who depend on the property for shelter, safety, and information during an emergency. A continuity failure is therefore not only a financial event but potentially a life-safety event. This is why mature hotel BC programs integrate emergency response and life safety directly into the continuity plan rather than treating them as separate documents.

    What are the biggest threats to hotel business continuity?

    The hospitality risk landscape in 2024-2026 is defined by the convergence of physical, digital, and human threats. Extreme weather is intensifying, ransomware has become an industry-wide epidemic, and labor shortages have made it harder to staff a coordinated response. The table below summarizes the leading threats, their operational impact, and core mitigations.

    Threat Operational impact Core mitigation
    Natural disasters & extreme weather (hurricanes, floods, wildfire, extreme heat) Property damage, forced closure, evacuation, lost occupancy; insurers raising premiums 20-50% or withdrawing from high-risk areas Resilient construction to current flood/wind codes, flood barriers, backup power, pre-arranged evacuation and sheltering protocols, parametric insurance
    Cyberattacks & guest-data breaches (ransomware, social engineering) PMS and payment outages, theft of guest PII and card data, regulatory investigations; average hospitality breach cost ~$4.03M in 2025 Multi-factor authentication, help-desk verification procedures, network segmentation, immutable offline backups, PCI DSS compliance, incident response plan
    Power & utility failure Loss of HVAC, lighting, electronic locks, PMS, refrigeration; immediate guest-safety and comfort impact Generators with tested fuel supply, uninterruptible power supply (UPS) for critical systems, manual override procedures for door locks and check-in
    Pandemics & public-health events Demand collapse, occupancy crashes, workforce illness, sustained operating-model changes Flexible staffing models, hygiene and isolation protocols, scenario-based demand planning, cross-training, liquidity reserves
    Supply-chain disruption Shortages of food, linens, amenities, and critical spare parts; price volatility Diversified and local suppliers, safety stock of critical items, vendor continuity clauses, alternate-sourcing playbooks
    Staffing & labor shortages Inability to clean rooms, staff the response, or maintain service; recovery delays Cross-training, retention incentives, automation of low-value tasks, on-call and agency rosters, documented emergency duty assignments

    How serious is the cyber threat to hotels specifically?

    Cyber risk has moved to the front of the hotel continuity agenda. The 2023 attack on MGM Resorts International cost the company more than $100 million and was executed by the Scattered Spider group through a single social-engineering (vishing) call to the IT help desk, where an attacker impersonated an employee and obtained super-administrator access. On March 29, 2024, Omni Hotels & Resorts suffered an attack that forced systems offline and disrupted reservations, payment processing, and digital room-key access across many properties. In 2024, a breach at hotel-technology vendor Otelier exposed data tied to brands including Marriott, Hilton, and Hyatt, adding roughly half a million accounts to breach-notification databases. According to the 2025 Verizon Data Breach Investigations Report, ransomware features in 44% of breaches, and the average cost of a hospitality data breach reached approximately $4.03 million in 2025. The lesson for continuity planners is that the weakest link is often a process (help-desk verification) rather than a firewall.

    How does extreme weather threaten hotel continuity and value?

    2024 was the warmest year in the observational record, accompanied by an extraordinary run of extreme events. The financial tail is long: arrivals to the Hawaiian island of Maui were still down 24% a year after the 2023 wildfires, representing an estimated US$2.6 billion impact. During the 2024 Atlantic hurricane season, Hurricane Milton damaged or closed roughly a quarter of hotels in directly impacted Florida markets, according to JLL Hotels & Hospitality Group, while properties built to current standards for flooding, storm surge, and high winds suffered minimal damage. Annual climate-related economic losses exceeded US$230 billion per year during 2015-2024. For hotel real estate, this translates into rising insurance costs, restricted coverage in coastal zones, and growing investor scrutiny of physical climate exposure.

    What is the business continuity planning lifecycle for a hotel?

    ISO 22301 organizes continuity around a continuous Plan-Do-Check-Act (PDCA) lifecycle rather than a one-time document. The core phases below apply directly to a hotel.

    Phase What it produces Hotel-specific focus
    1. Business Impact Analysis (BIA) & risk assessment Inventory of critical functions, maximum tolerable downtime, dependencies Reservations/PMS, payment processing, electronic locks, life safety, housekeeping, F&B, guest communications
    2. Set RTO and RPO targets Recovery deadlines and acceptable data-loss windows per function Payment and PMS typically demand the shortest RTO/RPO; back-office can tolerate longer
    3. Recovery strategies Backup systems, manual workarounds, alternate sites, redundancy Manual check-in procedures, offline lock overrides, cloud PMS failover, generator power
    4. Plan development & emergency response Written BC plan, incident response, evacuation and life-safety procedures Integrated with NFPA 101 life-safety and fire procedures; clear duty assignments
    5. Crisis communications Pre-drafted messaging, contact trees, spokesperson roles Guests, staff, suppliers, owners/brand, media, and authorities
    6. Testing & exercises Validated, rehearsed plan; identified gaps Tabletop and full-scale drills; learning captured from real events
    7. Review & continual improvement Updated plan reflecting changes and lessons learned Refresh after staff turnover, renovations, system changes, and incidents

    What is a Business Impact Analysis for a hotel?

    The Business Impact Analysis (BIA) is the foundation of the entire program. It identifies the hotel’s critical functions, quantifies how long each can be offline before unacceptable harm occurs, and maps the dependencies between them. For a hotel, the BIA typically prioritizes guest services, reservations, the PMS, payment processing, electronic door locks, life-safety systems, housekeeping, and food and beverage operations. The output of the BIA drives every downstream decision, because it tells planners where to concentrate scarce time, capital, and redundancy.

    What do RTO and RPO mean for hotel systems?

    Recovery Time Objective (RTO) is the maximum acceptable time a function can be down after a disruption. Recovery Point Objective (RPO) is the maximum acceptable amount of data loss, measured in time. In a hotel, payment processing and the PMS usually carry the most aggressive targets: an RTO measured in minutes to a few hours, and an RPO low enough that no completed reservation or folio charge is lost. A guest-loyalty analytics dashboard, by contrast, can tolerate an RTO of days. Setting these targets explicitly, per function, is what turns a vague aspiration (“get back up fast”) into an engineerable backup and failover design.

    How do hotels protect guest safety and life safety?

    Because guests sleep on the premises, life safety is the non-negotiable core of hotel continuity. In the United States, the governing framework is the NFPA 101 Life Safety Code, supported by NFPA 13 (sprinkler installation), NFPA 72 (fire alarm and signaling), NFPA 25 (inspection and maintenance of water-based suppression), and NFPA 96 (commercial cooking fire protection). Modern mid-rise and high-rise hotels generally require full sprinkler coverage, interconnected audible and visual fire alarms in all guest rooms and common areas, battery-backed emergency lighting, illuminated exit signage, and, in larger properties, an emergency voice/alarm communication system (EVACS) to direct occupants during an event. Sprinkler systems must be inspected and tested annually under NFPA 25, alarm notification devices require regular testing under NFPA 72, and staff must be trained to recognize alarms, locate the source, and execute response steps. A continuity plan that ignores these life-safety obligations is incomplete; conversely, a strong life-safety program is the first layer of resilience.

    How do hotels build cyber and IT resilience?

    IT resilience for hotels centers on three system families: the property management system (PMS), payment and point-of-sale systems, and the growing layer of IoT and smart-room devices (electronic locks, thermostats, voice assistants, building-management systems). Each is a continuity dependency and an attack surface.

    Practical measures include multi-factor authentication on all administrative and remote access; strict identity-verification procedures at the IT help desk to defeat the social-engineering tactics that breached MGM; network segmentation so that a compromised guest Wi-Fi or smart-room controller cannot reach the PMS or payment environment; immutable, offline backups tested against ransomware; and PCI DSS compliance for cardholder data. Cloud-based PMS platforms can improve resilience by enabling failover and off-site data, but they also create vendor dependencies; the Otelier breach showed that a third-party hotel-tech provider can become the single point of failure for multiple brands. A robust IT continuity plan therefore includes manual fallback procedures, such as paper check-in and offline lock overrides, so the front desk can keep operating even when systems are dark.

    What is ISO 22301 and why does it matter for hotels?

    ISO 22301 is the international standard for business continuity management systems. The current published edition is ISO 22301:2019, which streamlined the original 2012 version. In February 2024, ISO published Amendment 1 (ISO 22301:2019/Amd 1:2024), adding climate-action requirements that oblige organizations to consider how climate change may affect their operations and stakeholders, a direct concern for weather-exposed hotel assets. A further revision is under development through ISO/TC 292 and is anticipated to follow. ISO 22301 matters for hotels because it provides a recognized, auditable structure, certification can support insurance negotiations, and brand and owner agreements increasingly expect documented continuity capability. Insurers reward proactive risk management: hotels with thorough continuity plans are viewed as less likely to file large claims, which can translate into more favorable premiums and coverage terms.

    How does business continuity connect to ESG and resilience reporting?

    For institutionally owned hotel real estate, business continuity has become part of the environmental, social, and governance (ESG) story, specifically the resilience dimension. The GRESB Real Estate Assessment, widely used by institutional real estate investors, asks entities in its 2025 framework to describe how they incorporate resilience into their climate strategy, including whether scenario analysis is used to evaluate that strategy. Physical climate risks, flooding, heatwaves, and wildfires, are increasingly seen as material to asset value; nearly two in five respondents in a GRESB and MIPIM survey said physical climate impacts will have the biggest effect on asset values in 2026. The practical implication is that a hotel’s BIA, climate scenario analysis, recovery strategies, and tested response are no longer purely operational artifacts. They are inputs to investor reporting, capital access, and valuation. ISO 22301’s 2024 climate amendment and the resilience indicators in GRESB are converging: a well-run continuity program is now also an ESG asset.

    How should a hotel test and maintain its continuity plan?

    A plan that is never exercised is a liability, because gaps surface only during a real crisis. ISO 22301 requires that continuity procedures be exercised and tested regularly, appropriate to the organization’s activities and risk profile. The most accessible method is the tabletop exercise: a guided, scenario-based discussion that brings decision-makers together to walk through a crisis, such as a ransomware lockout during peak occupancy or an evacuation during a hurricane. Tabletops reveal policy and communication gaps and clarify each leader’s authority limits and decision rights without real-world pressure. More advanced programs add part-scale or full-scale exercises, such as a live failover of the PMS or a timed evacuation drill, and they treat real incidents as learning opportunities. Plans should be refreshed after major staff turnover, renovations, system migrations, and every actual incident, closing the Plan-Do-Check-Act loop.

    Frequently asked questions

    What is the difference between business continuity and disaster recovery in a hotel?

    Disaster recovery is a subset of business continuity focused on restoring IT systems and data after an outage. Business continuity is broader: it keeps the whole hotel operation running, including front desk, housekeeping, life safety, supply chain, and guest communications, not just the technology.

    Which standard governs hotel business continuity?

    ISO 22301 is the international standard for business continuity management systems. The current edition is ISO 22301:2019, with a 2024 amendment adding climate-action requirements. In the United States, life-safety elements are governed separately by NFPA codes such as NFPA 101.

    What are RTO and RPO and which hotel systems need the tightest targets?

    RTO (Recovery Time Objective) is how fast a function must be restored; RPO (Recovery Point Objective) is how much data loss is acceptable. Payment processing and the property management system typically need the tightest targets, often an RTO of minutes to hours and a near-zero RPO so no reservation or charge is lost.

    What was the lesson of the MGM Resorts cyberattack for hotels?

    The 2023 MGM attack, which cost over $100 million, began with a single social-engineering phone call to the IT help desk that yielded administrator access. The lesson is that strong identity-verification procedures at the help desk and multi-factor authentication are as important to continuity as technical defenses.

    How often should a hotel test its business continuity plan?

    ISO 22301 calls for regular exercises appropriate to the organization’s risk profile. In practice, hotels should run at least an annual tabletop exercise, conduct life-safety and evacuation drills on the schedule their jurisdiction and NFPA codes require, and refresh the plan after any major change or real incident.

    Does business continuity affect a hotel’s insurance and asset value?

    Yes. Insurers view hotels with thorough continuity plans as lower-risk and may offer more favorable premiums and coverage terms. For institutionally owned properties, resilience and climate scenario analysis feed ESG frameworks such as GRESB, where physical climate risk is increasingly treated as material to asset value.

    How does a pandemic factor into hotel continuity planning?

    Pandemics create demand collapse and workforce illness simultaneously. Continuity plans address them through flexible staffing models, cross-training, hygiene and isolation protocols, scenario-based demand planning, and liquidity reserves. Many operators permanently streamlined staffing models after the COVID-19 period, blending labor reductions with technology-driven efficiency.

    Sources & further reading

  • ESG in Banking and Investment: Risk, Lending, and Disclosure

    ESG in banking and investment means integrating environmental, social, and governance factors into credit risk, underwriting, lending, and portfolio construction, and disclosing those exposures under frameworks such as the ISSB’s IFRS S1/S2, the EU’s CSRD/ESRS and SFDR, and the Basel Committee’s voluntary climate-risk disclosure framework. The practice is now being reshaped by two opposing forces in 2025-2026: regulatory consolidation around the ISSB baseline globally, and a sharp US “anti-ESG” retreat that drove every major Wall Street bank out of the Net-Zero Banking Alliance (NZBA) between December 2024 and January 2025 and prompted the SEC to abandon and then move to rescind its 2024 climate-disclosure rules.

    What does ESG actually mean for a bank or asset manager?

    For financial institutions, ESG is not a marketing layer; it is a set of risk factors and a disclosure regime. On the banking side, ESG enters through credit risk: climate transition risk (stranded assets, carbon-pricing exposure), physical risk (flood, wildfire, and heat damage to collateral), and governance and reputational risk in counterparties. On the investment side, ESG enters portfolio management through screening, integration, thematic allocation, stewardship, and impact strategies. Both sides converge on one hard requirement: comparable, decision-useful disclosure. The dominant theme of 2025-2026 is that disclosure rules are simultaneously converging on the ISSB global baseline and being scaled back in scope, especially in the United States and the European Union.

    How is ESG used in credit risk, underwriting, and lending?

    Banks integrate ESG into underwriting primarily as a forward-looking risk overlay rather than a values screen. Climate transition risk can impair the creditworthiness of carbon-intensive borrowers as carbon costs rise and demand shifts; physical risk can destroy or devalue real-estate and infrastructure collateral. Supervisors increasingly expect banks to run climate scenario analysis, identify concentrations, and reflect material climate risk in their internal capital adequacy assessment. The European Central Bank, the Bank of England, and the US Federal Reserve have all run climate scenario exercises, though none currently impose an explicit climate capital add-on. In practice, ESG factors most often affect pricing, covenants, and concentration limits rather than the binary decision to lend.

    What are ESG-linked loans and sustainability-linked bonds?

    Two instrument families dominate sustainable finance, and they work differently:

    • Use-of-proceeds instruments (green/social/sustainability bonds and loans): capital is ring-fenced for defined eligible projects (renewables, clean transport, affordable housing). Green bonds remained the largest single category, at roughly 53-57% of labeled issuance through 2024-2025.
    • Sustainability-linked instruments (SLLs and SLBs): proceeds are general-purpose, but the coupon or margin steps up or down based on the borrower hitting predefined sustainability performance targets (KPIs/SPTs). These face the most greenwashing scrutiny because weak targets produce a label with little substance.

    The labeled bond market hit roughly USD 1 trillion to 1.1 trillion in 2024 (World Bank and Climate Bonds Initiative data), with cumulative labeled issuance reaching about USD 6.2 trillion by December 2024. The sustainability-linked segment has cooled markedly: S&P Global forecast only about USD 35 billion of SLB issuance for 2025, far below the 2021-2023 peak, and labeled loan volumes fell roughly 52% from H1 2024 to H1 2025 as borrowers dropped labels whose pricing benefit (often just a few basis points of margin step-down) no longer justified the verification burden. On 26 March 2025, the loan-market trade associations (LMA/LSTA/APLMA) tightened the Sustainability-Linked Loan Principles, making post-signing verification by a qualified external reviewer mandatory (“shall” rather than “should”).

    How do investment and asset-management firms integrate ESG?

    Asset managers deploy a spectrum of approaches, often within the same firm: negative/exclusionary screening (e.g., excluding controversial weapons or thermal coal), positive/best-in-class screening, full ESG integration into financial analysis, thematic and impact investing, and active ownership through proxy voting and engagement. Post-2023, the industry has shifted language from “ESG investing” toward “sustainable investing,” “transition finance,” and “responsible investing,” partly to sidestep US political controversy and partly to comply with tighter fund-naming rules. Stewardship and engagement remain widely practiced even where firms have muted public ESG branding.

    Which disclosure frameworks apply to financial institutions?

    A bank or asset manager operating across major markets faces an overlapping stack of frameworks. The single most important shift is that the ISSB’s IFRS S1 and S2 have become the global baseline, formally consolidating the legacy TCFD recommendations (the IFRS Foundation took over TCFD monitoring in 2024).

    Framework Issuer / jurisdiction Status (2025-2026) Relevance to financial institutions
    IFRS S1 / S2 (ISSB) IFRS Foundation (global) Global baseline; adopted or being adopted by 35+ jurisdictions representing more than half of global GDP Entity-wide sustainability and climate risk disclosure; absorbs TCFD; basis for UK, Hong Kong, Singapore, Brazil, Nigeria, Malaysia regimes
    CSRD / ESRS EU In force but scaled back by the 2025 “Omnibus” simplification package Mandatory double-materiality reporting for large EU banks and insurers; scope sharply reduced
    SFDR EU (ESMA/EC) Under “SFDR 2.0” overhaul (proposal Nov 2025) Product-level disclosure and de facto fund labeling for asset managers
    TCFD FSB (legacy) Disbanded 2023; monitoring absorbed by ISSB Still referenced in many national rules; superseded by IFRS S2
    Basel climate-risk disclosure BCBS Published 13 June 2025 as voluntary, not Pillar 3 Bank-specific climate-risk disclosure template; adoption left to national regulators
    SEC climate rules US SEC Stayed since April 2024; SEC moved to rescind in 2025-2026 Effectively defunct for US registrants

    What changed with the EU’s CSRD “Omnibus” package?

    In 2025 the EU enacted an “Omnibus” simplification that dramatically narrowed the Corporate Sustainability Reporting Directive. The final deal raised the mandatory threshold to EU companies with more than 1,000 employees and over EUR 450 million in net turnover, cutting the in-scope population by an estimated ~90% versus the original 250-employee threshold. EFRAG delivered simplified ESRS that reduce mandatory data points by roughly 60-70% (from about 1,073 to around 320). The Commission is expected to adopt the revised ESRS by delegated act around mid-2026, with effect potentially from FY2027. Large EU banks and insurers remain in scope, but value-chain data requests from smaller counterparties are now capped.

    How do SFDR’s Article 6, 8, and 9 categories work, and what is “SFDR 2.0”?

    The EU Sustainable Finance Disclosure Regulation (SFDR) was designed as a disclosure regime but was used by the market as a labeling system. Almost half of EU assets under management sit in Article 8 or Article 9 products.

    SFDR classification Plain-language meaning Market nickname
    Article 6 No sustainability focus, or ESG risks merely considered; baseline disclosure “Non-ESG”
    Article 8 Promotes environmental or social characteristics “Light green”
    Article 9 Has sustainable investment as its objective “Dark green”

    In November 2025 the European Commission proposed “SFDR 2.0,” replacing the Article 8/9 regime with three formal product categories – broadly Sustainable, Transition, and ESG (collection/basics) – each anchored by a roughly 70% portfolio threshold, common exclusions, and short-form disclosures. The legislative process is expected to run through 2026-2027, with application unlikely before 2028. Until then, the Article 6/8/9 framework remains in force.

    What do fund-naming and greenwashing rules require?

    Two regimes police the gap between a fund’s name and its holdings. In the EU, ESMA’s fund-naming guidelines took effect in 2024 with a compliance deadline of May 2025: funds using ESG, “sustainable,” “impact,” or environmental terms such as “green” must invest at least 80% of assets in line with the relevant characteristics and apply Paris-Aligned Benchmark exclusions. The effect was immediate – per an ESMA study of 924 funds, about 64% changed their names ahead of the deadline, with many simply dropping ESG terminology rather than greening portfolios.

    In the United States, the SEC’s amended Names Rule (adopted September 2023) extended the longstanding “80% investment policy” to fund names suggesting “particular characteristics,” explicitly capturing ESG and sustainability funds: a fund whose name implies an ESG focus must hold at least 80% of assets consistent with that focus. The SEC began reviewing the rule’s application to ESG names in 2026, leaving its long-term future uncertain.

    What is the “anti-ESG” backlash, and what did it actually change?

    The 2024-2026 US backlash combined state-level legislation, litigation threats, and political pressure that materially changed institutional behavior even where the underlying risk analysis did not change. The clearest signal was the collapse of the Net-Zero Banking Alliance (NZBA): between December 2024 and January 2025, Goldman Sachs, Wells Fargo, Citigroup, Bank of America, Morgan Stanley, and finally JPMorgan Chase (7 January 2025) all exited, and the alliance subsequently paused operations and moved to restructure into a looser framework body. Major US asset managers similarly stepped back from net-zero investor coalitions such as Climate Action 100+ and the Net Zero Asset Managers initiative, which suspended activities in early 2025.

    Crucially, most institutions framed these as departures from coalitions and public commitments, not from risk management. Banks continued climate scenario analysis, transition-risk modeling, and sustainable-finance underwriting where commercially driven. The same period saw regulators retreat on mandates: the SEC stopped defending its climate rules in March 2025 and proposed full rescission; the Basel Committee downgraded its bank climate-disclosure framework to voluntary in June 2025 after US pressure, dropping the requirement to disclose financed and facilitated emissions regardless of materiality. The net effect is a bifurcated world: a tighter, ISSB-anchored disclosure regime maturing across the UK, EU, and Asia-Pacific, and a deregulatory, depoliticized posture in the United States.

    Frequently asked questions

    Is ESG investing legally required for US banks?

    No. There is no US federal mandate requiring banks or asset managers to “do ESG.” US disclosure of climate risk via the SEC’s 2024 rules was stayed and is being rescinded. ESG-relevant obligations for US firms now flow mainly from fiduciary duty, the Names Rule for fund branding, and exposure to EU rules when operating in Europe.

    What replaced the TCFD framework?

    The ISSB’s IFRS S2 absorbed and superseded the TCFD recommendations. The Task Force on Climate-related Financial Disclosures was disbanded in 2023, and the IFRS Foundation took over monitoring climate-related disclosure progress in 2024. National rules built on TCFD are migrating to the IFRS S1/S2 baseline.

    Did banks abandon climate risk management when they left the NZBA?

    Generally no. Leaving the Net-Zero Banking Alliance removed a public coalition commitment but did not switch off internal climate-risk analysis, scenario testing, or sustainable-finance lending, which banks largely retained as commercial and prudential disciplines.

    What is the difference between a green bond and a sustainability-linked bond?

    A green bond ring-fences proceeds for specific eligible green projects, so its “greenness” is in how the money is spent. A sustainability-linked bond can fund anything, but its coupon adjusts based on whether the issuer meets predefined sustainability targets, so its integrity depends entirely on how ambitious those targets are.

    Does a fund called “sustainable” have to hold a minimum percentage of sustainable assets?

    Yes, in both major markets. Under ESMA’s EU guidelines, ESG/sustainability-named funds must hold at least 80% of assets aligned with those characteristics and apply benchmark exclusions. Under the SEC Names Rule, an ESG-named US fund must keep at least 80% of assets consistent with the name.

    Is the EU still requiring CSRD reporting after the Omnibus changes?

    Yes, but for far fewer companies. The 2025 Omnibus package raised the mandatory threshold to roughly 1,000 employees and EUR 450 million in net turnover, cutting in-scope entities by an estimated 90% and reducing required ESRS data points by 60-70%. Large EU banks and insurers remain in scope.

    Is the Basel climate-disclosure framework mandatory for banks?

    No. The Basel Committee published its climate-related financial-risk disclosure framework on 13 June 2025 as a voluntary standard outside the Pillar 3 mandatory requirements, leaving adoption to individual national regulators.

    Sources & further reading

  • ESG Ratings Compared: MSCI vs Sustainalytics vs ISS ESG vs CDP vs EcoVadis (2026 Methodology Guide)

    The five most-cited ESG rating systems — MSCI, Morningstar Sustainalytics, ISS ESG, CDP, and EcoVadis — measure different things, on different scales, in different directions. MSCI grades industry-relative resilience on an AAA–CCC letter scale; Sustainalytics scores absolute unmanaged risk from 0 to 100 where lower is better; ISS ESG flags “Prime” status on an A+ to D- scale; CDP scores environmental disclosure from A to D-; and EcoVadis awards medals to suppliers by percentile rank. Because they define and weight “ESG” so differently, their scores for the same company correlate only about 0.54 on average. This guide explains each methodology, why the numbers disagree, and how to improve every one.

    ESG ratings at a glance: the five systems compared

    Provider Owned by What it measures Scale & direction Relative or absolute Primary audience
    MSCI ESG Ratings MSCI Inc. Resilience to financially material, industry-specific ESG risks & opportunities AAA → CCC (7 tiers); 0–10 underlying score. Higher is better. Industry-relative (vs. GICS sub-industry peers) Asset managers, index funds
    Morningstar Sustainalytics Morningstar Magnitude of a company’s unmanaged ESG risk 0–100 risk score; 5 bands (Negligible → Severe). Lower is better. Absolute (comparable across industries) Investors, brokerages, risk teams
    ISS ESG Corporate Rating ISS STOXX (Deutsche Börse) Absolute ESG performance vs. demanding best-in-class expectations A+ → D-; “Prime/Not Prime” threshold; decile rank 1–10. Higher is better. Absolute grade + relative decile European institutional investors
    CDP CDP (nonprofit) Quality of environmental disclosure and action (climate, water, forests) A/A- → D/D- (+ F for non-response). Higher is better. Absolute (criteria-based) Investors & procurement
    EcoVadis EcoVadis Quality of a supplier’s sustainability management system 0–100 score; Medals by percentile (Bronze → Platinum). Higher is better. Relative (percentile vs. all assessed companies) Procurement / supply-chain teams

    The single most important takeaway: a “good” score in one system does not translate to another, because the systems are not measuring the same construct. MSCI asks “is this company managing its material risks better than its peers?” Sustainalytics asks “how much unmanaged risk is left on the table, in absolute terms?” CDP asks “how good is this company’s environmental disclosure?” Comparing a Sustainalytics “Low Risk” to an MSCI “AA” is comparing different questions, not different answers to the same question.

    Why ESG ratings disagree (the research most people miss)

    Credit ratings from Moody’s and S&P correlate at roughly 0.99. ESG ratings do not come close. The landmark study on this is “Aggregate Confusion: The Divergence of ESG Ratings” by Berg, Kölbel & Rigobon, published in the Review of Finance (2022). Examining six major raters, they found:

    • Average correlation of just 0.54 across ESG ratings, ranging from 0.38 to 0.71.
    • Governance ratings are the least correlated, at 0.30 — the dimension investors often assume is most objective is actually where raters disagree most.
    • The social dimension correlates at about 0.42.

    They decompose the disagreement into three sources:

    1. Measurement (56%) — raters measure the same attribute (e.g., “employee turnover”) using different indicators and data, and reach different conclusions.
    2. Scope (38%) — raters include different sets of attributes. One counts lobbying; another doesn’t.
    3. Weight (6%) — raters weight the same attributes differently.

    The study also identified a “rater effect” (a halo): once an agency forms an overall view of a company, that view bleeds into how it scores individual categories. The practical consequence — confirmed in follow-on research — is that ESG rating divergence sends companies mixed signals about which actions the market actually values, and can dampen the incentive to improve.

    What this means for you: never treat a single ESG score as ground truth. Triangulate across providers, and always ask what the rating measures before you act on it.

    MSCI ESG Ratings: industry-relative resilience (AAA–CCC)

    What it measures. MSCI ESG Ratings assess a company’s resilience to financially material, industry-specific ESG risks and opportunities. It is explicitly a financial materiality lens — “which ESG issues could hit the bottom line in this industry, and how well is this company managing them?”

    The scale. Companies receive a 0–10 underlying score that maps to a seven-tier letter rating:

    • Leader: AAA, AA
    • Average: A, BBB, BB
    • Laggard: B, CCC

    How it works. MSCI identifies the Key Issues that are material for each GICS sub-industry. Each Environmental or Social Key Issue carries a weight of roughly 5% to 30% of the total rating, set according to how much the industry contributes to that issue’s negative externality and how quickly the issue is expected to materialize. Scores are then normalized within each industry, so the rating is fundamentally peer-relative: an AA tells you the company leads its industry on managing material risks, not that it is “sustainable” in an absolute sense.

    Worth knowing for 2026: MSCI announced a multi-stage ESG Ratings model update (disclosed October 2025) that is transitioning through 2026. If you are benchmarking or citing a specific rating, confirm it against MSCI’s current model rather than an older snapshot.

    How to improve an MSCI rating: focus only on the Key Issues MSCI deems material for your sub-industry (managing an immaterial issue won’t move the score), strengthen disclosure on those issues, and remember the score is relative — improvement requires outpacing peers, not just improving in absolute terms.

    Morningstar Sustainalytics: absolute unmanaged risk (0–100, lower is better)

    What it measures. The Sustainalytics ESG Risk Rating measures the magnitude of a company’s unmanaged ESG risk — the portion of material ESG exposure that the company has not addressed through programs and policies. Crucially, it runs in the opposite direction from MSCI: a lower score is better.

    The scale. Scores run 0 to 100 and sort into five risk categories:

    • Negligible: 0–10
    • Low: 10–20
    • Medium: 20–30
    • High: 30–40
    • Severe: 40+

    How it works. For each Material ESG Issue (MEI), Sustainalytics calculates Exposure (how much risk the business is inherently subject to) and then subtracts Managed Risk (the part addressed by the company) — plus a recognized band of risk that is simply unmanageable for that business. Unmanaged Risk = Exposure − Managed Risk. Because exposure is assessed at the sub-industry level but the final score is absolute, Sustainalytics ratings are designed to be comparable across industries and regions — a key difference from MSCI’s peer-relative approach. This is the rating you most often see surfaced on retail brokerages and finance portals.

    How to improve a Sustainalytics score: close the gap between exposure and management — demonstrate concrete programs, policies, and outcomes on your highest-exposure MEIs. Because the score is absolute, real management improvements move it even if peers don’t change.

    ISS ESG Corporate Rating: “Prime” status (A+ to D-)

    What it measures. Now part of ISS STOXX (Deutsche Börse Group), the ISS ESG Corporate Rating evaluates a company against demanding, absolute best-in-class performance expectations for its industry.

    The scale. A twelve-grade scale from A+ (best) to D- (worst), with two headline outputs:

    • Prime / Not Prime: companies that clear an industry-specific threshold (often C+, but higher for industries with greater ESG exposure) earn “Prime” status — a signal of ESG investability.
    • Decile rank (1–10): shows relative standing within the industry, where 1 is the strongest and 10 the weakest.

    How it works. ISS ESG combines an absolute letter grade (against a fixed bar) with a relative decile rank (against peers), so you get both “did it meet the standard?” and “how does it rank?” in one rating. As of 2025, ISS defines SMEs as companies with fewer than 500 employees and under USD 500 million in revenue, reflecting expanding mandatory sustainability reporting.

    How to improve an ISS ESG rating: identify the industry-specific Prime threshold and the absolute criteria behind it, then prioritize the indicators that lift you above the Prime line — the binary Prime status often matters more to investors than incremental grade movement.

    CDP: environmental disclosure, scored A to D-

    What it measures. CDP is different in kind from the others — it is a nonprofit disclosure platform, not a paid third-party rater. Companies respond to CDP’s questionnaire and are scored on the completeness and ambition of their environmental disclosure and action across Climate Change, Forests, and Water Security (with new scoring for cocoa, coffee, and rubber added in 2025).

    The scale. Four bands, each reflecting a level of progress:

    • A / A- — Leadership (the “A List”)
    • B / B- — Management
    • C / C- — Awareness
    • D / D- — Disclosure
    • F — failure to provide sufficient information / non-response

    How it works. A company must satisfy CDP’s “Essential Criteria” at each level to progress — and as of 2025 those criteria apply at every tier, not just the top. A notable 2025 change: companies must have Scope 1 and Scope 2 emissions externally verified to reach the highest scores, and Forests and Water Security are now publicly scored for the financial-services sector. Because CDP rewards disclosure quality, a high CDP score signals transparency and process maturity — not necessarily low ESG risk.

    How to improve a CDP score: map your response against the Essential Criteria for the level you’re targeting, secure third-party verification of Scope 1 & 2 emissions early, and treat the questionnaire as a year-round data project rather than an annual scramble.

    EcoVadis: supply-chain medals by percentile

    What it measures. EcoVadis assesses the quality of a company’s sustainability management system — primarily for procurement and supply-chain vetting. It is evidence-based: companies submit documentation, which EcoVadis evaluates through a Policies–Actions–Results (P-A-R) lens.

    The scale. A 0–100 score across 21 criteria in four themes — Environment; Labor & Human Rights; Ethics; and Sustainable Procurement — translated into medals by percentile:

    • Platinum: top 1% of assessed companies
    • Gold: top 5%
    • Silver: top 15%
    • Bronze: top 35%

    How it works. Medals are awarded relative to all companies assessed in the prior 12 months, so the bar moves with the population. A company is not eligible for any medal if its score in any single theme falls below 30, which prevents one strong theme from masking a weak one. As of January 2025, EcoVadis displays unrounded theme scores (e.g., 68/100) and uses them in the overall calculation.

    How to improve an EcoVadis medal: close your weakest theme first (the sub-30 cutoff is the most common medal-blocker), and supply concrete evidence for Policies, Actions, and Results — claims without documentation don’t score.

    How to use multiple ESG ratings together

    Because each system answers a different question, the right move is to read them as complementary, not competing:

    • Want financial-materiality and peer benchmarking? Lead with MSCI.
    • Want an absolute, cross-industry risk number? Lead with Sustainalytics.
    • Need a Prime/Not-Prime investability screen (especially in Europe)? Use ISS ESG.
    • Assessing environmental transparency and climate action? Use CDP.
    • Vetting a supplier? Use EcoVadis.

    When two providers disagree sharply on the same company, that’s signal, not noise: it usually means they scope ESG differently (the 38% scope-divergence finding) or weight a controversy differently. Read the underlying sub-scores, not just the headline grade.

    For a deeper walkthrough of how each scoring methodology is built and provider-specific tactics for lifting a score, see our companion guide to ESG ratings methodology and rating-improvement strategy.

    Frequently asked questions

    Which ESG rating is the most accurate?

    None is definitively “most accurate” because they measure different things. MSCI and ISS ESG measure managed performance and resilience; Sustainalytics measures unmanaged risk; CDP measures environmental disclosure; EcoVadis measures supply-chain management systems. “Accuracy” depends on the question you’re asking. The more useful goal is to match the rating to your use case and triangulate across at least two.

    Why does the same company get different ESG scores?

    Because raters disagree on what to measure (scope), how to measure it (measurement), and how to weight it (weight). Research by Berg, Kölbel & Rigobon (2022) found ESG ratings correlate only about 0.54 on average, with measurement differences driving 56% of the divergence. A “rater effect” halo also nudges category scores toward each agency’s overall view of the company.

    Is a low Sustainalytics score good or bad?

    Good. The Sustainalytics ESG Risk Rating runs 0–100 where lower is better — a low score means little unmanaged risk. This is the opposite of MSCI, CDP, ISS ESG, and EcoVadis, where higher is better. Reversing this direction is one of the most common ESG-rating mistakes.

    What does an MSCI rating of A or BBB mean?

    On MSCI’s AAA–CCC scale, both A and BBB fall in the “Average” band — the company is neither a leader (AAA/AA) nor a laggard (B/CCC) at managing the ESG risks material to its industry. Because the rating is industry-relative, the same letter can reflect very different absolute practices across sectors.

    Is CDP an ESG rating?

    Not in the traditional sense. CDP is a nonprofit environmental disclosure platform that scores the quality of a company’s reporting and action on climate, water, and forests (A to D-). It rewards transparency and management maturity rather than scoring overall ESG risk, which is why CDP is best read alongside a true risk or performance rating.

    Does MSCI use CDP data?

    ESG raters draw on many overlapping public sources — corporate filings, CDP disclosures, regulatory data, news and NGO reports — but each applies its own model, indicators, and weights on top. Shared inputs do not produce shared conclusions, which is a core reason ratings still diverge even when raters read the same underlying disclosures.

    What’s the difference between EcoVadis Gold and Platinum?

    Both are percentile awards: Platinum goes to the top 1% of companies assessed by EcoVadis in the prior 12 months, and Gold to the top 5%. Because they’re relative to the assessed population, the score needed for each medal can shift year to year. No medal is awarded if any single theme scores below 30.

    Sources & further reading

  • Local Law 97 Deadline June 30, 2026: File Your Report or Buy the $60 Extension

    Last updated: June 9, 2026. By Will Tygart, author of the Commercial Restoration Carbon Protocol (CRCP) and a filed public commenter in CARB’s SB 253 Scope 3 rulemaking. Every regulatory claim in this article links to its primary source.

    If a covered NYC building has not yet filed its Local Law 97 emissions report for calendar year 2025, there are exactly two moves left, and both expire on June 30, 2026: file the report in the BEAM portal by June 30, or apply by June 30 for a $60 extension that moves the filing deadline to August 29, 2026. The Department of Buildings has stated in writing that the blanket extensions it granted in 2025 do not apply to filing year 2026. There is no December reprieve coming this time.

    This guide is written for the person who actually coordinates the filing: the property manager. It covers what is due, what missing the deadline costs (in real dollars per month), how the three-portal filing process works, and what to do if your building is over its cap.

    The 2026 LL97 deadline, in one table

    Date What happens Source
    May 1, 2026 LL97 report on calendar-year-2025 emissions was due (Admin Code §28-320.6.2) DOB service notice, Feb 27, 2026
    June 30, 2026 Hard end of the 60-day grace period — AND the last day to apply for an extension Same notice; 1 RCNY 103-14(g)(2)
    August 29, 2026 Extended filing deadline, only for buildings that applied by June 30 ($60 fee) Same notice

    The extension is applied for as a ticket inside the BEAM portal; the $60 fee is paid separately in DOB NOW: Safety. No professional attestation is required to request it. Sixty dollars is the cheapest insurance in NYC real estate this month.

    What missing the deadline actually costs

    Local Law 97 has two separate penalties, and the one for not filing is usually worse than the one for emitting too much.

    • Failure to file: gross floor area × $0.50 per month, assessed for each month the report is not submitted within the 12 months following May 1 — and if you file after the grace period, penalties accrue retroactively to May 1 (DOB violations page).
    • Exceeding the cap: (actual emissions − emissions limit) × $268 per metric ton of CO2e, assessed annually.
    • False filing: a misdemeanor, with fines up to $500,000.

    Worked example: a 60,000 sq ft Midtown office building

    The 2024–2029 emissions cap for office space is 0.00758 tCO2e per square foot (1 RCNY 103-14). So the building’s annual limit is 60,000 × 0.00758 = 454.8 tCO2e.

    • If the building actually emitted 550 tCO2e in 2025, the overage penalty is (550 − 454.8) × $268 = $25,514 for the year.
    • If the same building simply fails to file, the penalty is 60,000 × $0.50 = $30,000 per month.

    Read that again: one month of not filing costs more than a full year of being 21% over the cap. Whatever your building’s emissions situation is, filing is always the cheaper move — and for the roughly 91% of buildings currently under their 2024–2029 caps, the report costs only the filing fee ($210 for a simple report) and the engineer’s time.

    Enforcement is no longer theoretical

    On April 22, 2026, DOB published its first-year results (press release): approximately 93% of covered privately-owned properties filed their CY2024 reports, the DOB Sustainability Bureau is now auditing filings from roughly 28,000 buildings, and about 1,400 properties that never filed are receiving Notices of Deficiency with a 60-day cure window before DOB attorneys take the cases to OATH.

    Filing rates by borough: Manhattan 95%, Brooklyn 93%, Bronx 92%, Queens 91%, Staten Island 83%. By building type, offices and hotels led at 95%; houses of worship (81%) and garages (80%) trailed. If your portfolio includes the laggard categories, your buildings are statistically the ones DOB’s enforcement queue is built from.

    How the filing actually works (the three-portal reality)

    The single most common operational complaint about LL97 is that compliance lives in three systems that sync overnight. As DOB’s own assistant commissioner for sustainability put it: “You cannot complete a report in one day and you need to plan for that.” (Habitat, March 2025)

    1. DOB NOW: Safety — pay the filing fee first ($210 simple report / $615 complex / $60 extension / $950 good-faith-efforts report, per 1 RCNY 101-03). BEAM does not unlock until the payment clears, which happens overnight.
    2. ENERGY STAR Portfolio Manager (ESPM) — your building’s energy data flows from here. Note: “Other” and “Mixed Use” property types are prohibited for LL97 reporting; the building must be typed correctly.
    3. BEAM (nyc.beam-portal.org) — where the report itself is filed, and where extensions, Covered Buildings List disputes, and penalty-mitigation requests are submitted as numbered tickets.

    Two coordination traps: the email addresses for the owner, property manager, and energy provider must be consistent across all three systems, and only a Registered Design Professional (a licensed PE or RA) can certify and submit the Article 320 report. The property manager does not file — the property manager coordinates: portal access, BBL/BIN numbers, fee payment, utility data, and the RDP’s calendar. If you have not booked your RDP yet, that is today’s call, not June 29’s.

    Over your cap? File anyway — then mitigate

    Filing and penalty exposure are separate questions. If your building exceeded its 2025 cap:

    • Good-faith efforts mitigation (1 RCNY 103-14(i)(2)) can reduce penalties — but it legally requires the annual report to be filed, LL84 benchmarking to be current, and an LL88 lighting/sub-metering attestation, plus one qualifying path (a decarbonization plan, an approved DOB application for compliance work, electric-readiness upgrades, a prior under-cap year, critical-facility status, or a pending adjustment).
    • RECs can offset emissions attributable to electricity only, must be NYC-deliverable, and are currently uncapped for the 2024–2029 period — except that buildings using the decarbonization-plan path are barred from them (DOB REC policy).
    • Offsets are capped at 10% of your emissions limit and the only eligible program is the city’s Affordable Housing Reinvestment Fund, priced at $268/ton — deliberately equal to the penalty rate.
    • Disaster damage is a named mitigating factor: under 1 RCNY 103-14(i)(1), an owner who documents that a hurricane, severe flooding, or fire precluded compliance in a calendar year — with photographs and a narrative — “may result in a penalty of zero dollars” for that year. If your building had a major loss event in 2025, your restoration contractor’s job file is now LL97 evidence. Ask for it.

    What this deadline means for each seat at the table

    If you are the… June 30 means…
    Owner You bear the penalty: $0.50/sqft/month for silence, $268/ton for overage. The $60 extension protects you for $60. Authorize it today.
    Facility / property manager You own the pipeline: three portals, matching emails, the RDP booking, the utility data, and the ticket trail. The overnight-sync delays mean June 30 work must start this week.
    Tenant Your energy use counts against the building’s whole-building number, and the A–F energy grade posted at your entrance every October comes from the same data. Expect your landlord to get more interested in your submeter.

    The rest of the 2026 compliance calendar

    Deadline Obligation
    June 30, 2026 LL97 CY2025 report grace ends; last day for $60 extension application
    Aug 29, 2026 Extended LL97 filing deadline (extension-approved buildings only)
    Oct 1–31, 2026 LL33/LL95 energy grade labels (A–F) must be posted near every public entrance
    Dec 31, 2026 LL87 Energy Efficiency Reports due for buildings in the 2026 cycle
    May 1, 2028 Good-faith decarbonization-plan filers must show a DOB-approved application for their 2030-cap work
    Jan 1, 2030 The cliff: caps tighten sharply — roughly 57% of covered properties currently emit more than their 2030 limit (Urban Green Council)

    That last row is the real story of 2026. Only about 9% of properties exceed today’s caps; about 57% exceed the 2030 caps. The buildings that use this filing cycle to understand their numbers — including the carbon that enters and leaves through their vendors and capital projects — are the ones that will plan their way under the 2030 line instead of writing checks over it.

    Frequently asked questions

    When is the Local Law 97 report due in 2026?

    The report on calendar-year-2025 emissions was due May 1, 2026, with a statutory grace period through June 30, 2026. Buildings that apply by June 30 for a $60 extension have until August 29, 2026.

    What happens if my building misses the June 30, 2026 deadline?

    Without an approved extension, the failure-to-file penalty is gross floor area × $0.50 per month, assessed retroactively to May 1 — $30,000 per month on a 60,000 sq ft building. Filing late stops the clock; it does not refund it.

    How much does an LL97 extension cost and how do I get one?

    $60. Apply as a ticket in the BEAM portal by June 30, 2026 and pay the fee in DOB NOW: Safety; the deadline moves to August 29, 2026. No professional attestation is required to apply.

    Who can actually file the LL97 report?

    Only a Registered Design Professional — a New York licensed Professional Engineer or Registered Architect — can certify and submit an Article 320 emissions report. The property manager coordinates the data, portals, and payment, but cannot self-file.

    Will DOB extend the deadline again like it did in 2025?

    No. DOB’s February 27, 2026 service notice states that “deadline extensions issued by service notice in 2025 do not apply to filing year 2026.” Plan on June 30, not on a repeat of last year’s December reprieve.

    How are Local Law 97 fines calculated?

    Overage: (actual emissions − your building’s limit) × $268 per metric ton CO2e, per year. Non-filing: floor area × $0.50 per month. A false filing is a misdemeanor with fines up to $500,000.

    Does my restoration contractor’s carbon count toward LL97?

    No. LL97 counts only emissions from operating the building — on-site fuel combustion plus purchased electricity and steam. Contractor operations, hauling, disposal, and materials are outside the cap. But that vendor carbon is exactly what GRESB, California SB 253, and corporate tenant reporting increasingly demand — see the Commercial Restoration Carbon Protocol (CRCP) for how property managers are starting to collect it.

    Primary sources

BC ESG

ESG Strategy, Sustainability Intelligence, and Business Continuity for Forward-Thinking Organizations

© 2026 BC ESG — Business Continuity, ESG & Sustainability Intelligence