Article

CSRD, ESRS and VSME in Business Central: simpler reporting still needs evidence

CSRD, ESRS and VSME simplify sustainability reporting, but not the need for evidence. Prepare Business Central without living in Excel.

July 8, 2026 - A Way How Product Team

CSRD, ESRS and VSME in Business Central: simpler reporting still needs evidence

On 3 July 2026, the European Commission adopted a revision of the European Sustainability Reporting Standards (ESRS) and a voluntary standard for smaller companies outside the direct scope of CSRD. The political message is clear: less administrative burden, fewer mandatory datapoints, and more proportionality (European Commission).

Good.

But be careful with the comfortable reading.

Simpler reporting does not remove the need to prove where each data point came from, who validated it, and what evidence supports it. For many companies running Microsoft Dynamics 365 Business Central, the question will no longer be only “are we subject to CSRD?” or “should we use VSME?”. It will be more specific, and more uncomfortable: when a customer, group company, bank, or auditor asks for ESG information, can we answer without rebuilding six months of work in Excel?

That is where the real problem begins.

Regulatory relief does not remove operational pressure

The ESRS revision is part of the Omnibus simplification package. Among other measures, the Commission intends to focus CSRD on larger companies, reduce reporting requirements, and protect smaller businesses from excessive value chain information requests through a proportionate voluntary standard (European Commission).

On paper, that reduces friction.

In practice, many mid-sized companies will still receive questions. Maybe not because they are directly required to report under CSRD, but because they sell to a company that is, belong to a group, finance an operation, prepare for certification, or bid for contracts where traceability carries more and more weight.

And those questions rarely arrive in the abstract.

They sound like this:

  • Which suppliers are involved in this process?
  • Who approved this material change?
  • Where is the review evidence?
  • Which incidents were identified, and how were they closed?
  • What controls prevent unvalidated data from being used?

These are not sustainable marketing questions. They are operational questions.

VSME: voluntary does not mean irrelevant

This is where VSME comes in.

The PICH BNFIX practical guide for SMEs, on page 28, defines VSME as the abbreviation for Voluntary European Sustainability Reporting Standard for Small and Medium-Sized Enterprises: a voluntary European sustainability reporting standard for SMEs.

The important word is voluntary. But voluntary should not be confused with decorative.

VSME is gaining relevance because it gives SMEs a common language for answering ESG requests without getting trapped in different questionnaires for every customer, bank, or investor. It does not impose CSRD-like obligations on companies outside scope, but it brings order to a conversation that is already happening in the market.

For a company running Business Central, this changes the angle. VSME should not be seen as “another report” someone completes at year-end. It should be read as an early signal of which operational information needs to stay under control throughout the year:

  • supplier and value chain data,
  • environmental consumption, incidents, or evidence where applicable,
  • internal policies or practices that require approval,
  • workforce, safety, or compliance records,
  • governance decisions that need to be explained.

The advantage of VSME is that it brings sustainability into a proportionate framework for SMEs. The risk is treating it as one more template, rather than as a discipline of data and evidence.

In other words: VSME simplifies the language of reporting, but it does not create the traceability that supports it.

ESG data often starts in unglamorous places

Picture an industrial company using Business Central for purchasing, suppliers, inventory, fixed assets, and accounting. It is not a large listed group, but it supplies components to larger European customers. One day it receives a sustainability-related information request: supplier data, compliance evidence, relevant changes, incidents, and approvals linked to certain products or services.

The team knows the information exists.

The problem is that it exists in too many places:

  • supplier records in Business Central,
  • attachments in shared folders,
  • approvals by email,
  • comments in Teams,
  • spreadsheets maintained by purchasing,
  • evidence collected only when someone asks for it.

The result is familiar: a week of internal chasing to prepare an answer that should have come from the process itself. Not because the team lacks willingness, but because the evidence was generated outside a governed sequence.

At that point, CSRD or ESRS stop being regulatory acronyms and become an internal control question: can the company explain its operational data with enough context?

Business Central has the pieces; sequence is what is missing

Business Central already contains much of the story: suppliers, documents, master data changes, approvals, users, ledger entries, change traces, and operational data explaining what happened.

The risk appears when those pieces live separately.

A supplier change may have a technical log, but not necessarily clear evidence of review. An approval may exist, but outside the ERP. An incident may have been resolved correctly, but without a visible owner or associated deadline. Supplier documentation may be archived, but not linked to the process that required it.

When an ESG request arrives, the team does not fail because it has no data. It fails because it has to reconstruct the story.

And reconstruction is not governance.

What should change before the next request

The right answer is not to create another master sustainability spreadsheet. That usually works for the first quarter and becomes operational debt by the second.

The answer is to turn the processes that feed that evidence into traceable circuits inside Business Central.

1. Define which events deserve control

Not every data point needs a ceremony. But some events should trigger formal review:

  • onboarding or changing a critical supplier,
  • modifying sensitive information related to product, service, or compliance,
  • receiving certificates or external evidence,
  • quality, safety, environmental, or privacy incidents,
  • approving relevant exceptions.

The key is not to wait for the final report. If the event is material to a future explanation, it should be governed when it happens.

2. Assign real responsibility

Evidence without an owner ages badly.

In processes linked to CSRD, ESRS, or value chain requests, each stage should have a clear owner: who requests, who reviews, who approves, who corrects, and who closes. Not as a decorative org chart, but as visible responsibility in daily operations.

When “everyone is involved,” no one is accountable.

3. Capture evidence in the ERP context

Useful evidence is not just a PDF stored in a folder. It is the PDF plus its context:

  • which operation required it,
  • who provided it,
  • who reviewed it,
  • when it was accepted,
  • which decision it allowed to move forward,
  • which exception was documented.

That context is what usually gets lost when evidence lives in emails and scattered folders. And it is exactly what becomes hardest to rebuild when a review arrives.

4. Monitor deadlines and exceptions

ESG processes do not fail only because data is wrong. They also fail because delays remain invisible: expired certificates, pending reviews, suppliers not responding, blocked approvals, incidents left open for too long.

Serious internal control does not only check whether something was done. It checks whether it was done on time and what happened when it was not.

Where AWH GRC fits without becoming an ESG platform

AWH GRC should not be positioned as another external ESG reporting repository, or as a dedicated VSME tool. Its value is different: it acts as an internal control system for critical operational processes inside Business Central.

That makes it especially useful under this kind of indirect regulatory pressure. It allows decisions, owners, deadlines, and evidence to remain connected to the context where the operation already lives: suppliers, documents, changes, incidents, and internal controls in the ERP.

This is not about promising that a tool “solves CSRD” or “prepares VSME” by magic. That would be a bad promise.

The more reasonable promise is stronger: if your critical processes generate evidence as they run, answering CSRD, ESRS, VSME, or value chain requests stops being an archaeological dig.

That is the important shift: moving from collecting proof at the end to producing traceability while the work happens.

This approach connects with an idea we covered in our article on compliance reports and continuous audit in Business Central: internal control should not depend on someone reviewing late what nobody governed on time.

The question to ask now

The ESRS revision may reduce formal burden for many companies. VSME, in turn, can provide a clearer framework for those outside the direct scope of CSRD that still receive sustainability requests from customers or lenders.

But no regulatory simplification fixes a poorly traced operational process.

Before discussing whether the company falls inside the exact perimeter, it is worth answering something more basic:

If tomorrow we are asked for evidence about suppliers, incidents, approvals, or controls related to sustainability, can we retrieve it from Business Central with enough context?

If the answer is yes, regulatory simplification becomes an advantage.

If the answer is no, the problem is not CSRD. It is that the organization still depends too much on memory, emails, and spreadsheets to explain decisions that should already be governed.

And when evidence is improvised at the end, even a simpler regulation can feel heavy.

Want to implement this in your organization?

We help teams move from manual controls to structured, traceable governance inside Business Central.