Tao-Ru Wang

王韜儒

中

What sustainability actually affects is not the letter of the text.
It is whose decisions change, and what follows from them.

Tao-Ru Wang's research runs in two directions: how carbon pricing, carbon accounting methodology, and sustainability disclosure take effect inside a company, and how stakeholders and the wider social environment shape its transition from outside. Sustainability is a broad subject, yet these questions circle the same one: after a rule takes effect, whose decisions actually change. The approach is applied rather than methodological, weighted toward what can be verified and what can be executed.

Sustainability ManagerISO 14064-1 Lead VerifierCarbon accountingNet-zero transitionGovernment affairs

← Writing Sustainability Disclosure Standards
The EU ESG Ratings Regulation (EU) 2024/3005

The EU ESG Ratings Regulation (EU) 2024/3005

Core claim

What this regulation truly changes is not the internal workflow of ESG rating providers, but who is entitled to issue an ESG rating that can be trusted; the EU has folded an industry once left entirely to market self-regulation into a supervisory framework modelled on the one governing credit rating agencies, and through amendments to SFDR extends data traceability requirements down to every rating a financial institution cites in its marketing. For Taiwan's industry, the significance lies not in whether companies come under ESMA's direct supervision but in the fact that the appetite for verifiable data among upstream EU capital providers can only keep growing, a pressure that will travel through supply-chain audits and financing due diligence to land, in two different forms, heavier disclosure obligations and a reshuffling of market demand, on rated Taiwanese exporters and the verification bodies that supply them with third-party assurance.

An Article-by-Article Analysis and Impact Assessment for Taiwan’s Industry

Recognition Boundary

I. Core Claim

What this regulation truly changes is not the internal workflow of ESG rating providers, but who is entitled to issue an ESG rating that can be trusted. The EU has taken an industry that was once left entirely to market self-regulation, with each provider running its own methodology, and folded it into a supervisory framework modelled on the one governing credit rating agencies. Through amendments to SFDR, it then extends data traceability requirements all the way down to every rating that a financial institution cites in its marketing communications. For Taiwan’s industry, the significance of this shift lies not in whether Taiwanese companies come under ESMA’s direct supervision, since most will not, but in the fact that the appetite for verifiable data among upstream EU capital providers can only keep growing. That pressure will ultimately travel through supply-chain audits and financing due diligence, landing indirectly on the Taiwanese exporters rated by international agencies and on the verification bodies that supply those exporters with third-party assurance. The two groups feel the pressure in different directions: the former face heavier disclosure obligations, the latter face a reshuffling of market demand.

II. Purpose, Scope and Definitions

Article 1 states the Regulation’s purpose at the outset: to build a common supervisory framework that strengthens the integrity, transparency, comparability, accountability, reliability, governance and independence of ESG rating activities, and to prevent greenwashing and social washing. Article 2 defines the scope, and is the provision most worth checking line by line against any given case. The Regulation applies to providers operating in the Union. A provider established in the Union is considered to be operating there once it publishes ratings on its website, or distributes them by subscription or contract to regulated financial undertakings, to companies within the scope of certain listed directives, or to Union institutions; a provider established outside the Union is only caught when it distributes ratings by subscription or contract to those same categories of recipient. The same article carves out a long list of exclusions, private ratings, ratings a financial undertaking uses purely for internal purposes, ratings developed exclusively for accreditation or certification and not aimed at investment decisions, external reviews and second-party opinions on green bonds, ratings that non-profits publish free of charge, and ratings that natural persons such as academics or journalists publish for non-commercial purposes. Article 3 then defines an ESG rating as covering both an ‘ESG opinion,’ where an analyst is directly involved in the judgement, and an ‘ESG score,’ derived purely from a statistical or algorithmic model, a distinction that later shapes the granularity of the disclosure obligations.

III. Market Access: Authorisation, Equivalence, Endorsement and Recognition

Articles 4 through 14 form the procedural core of the Regulation. Any legal person that wishes to operate as an ESG rating provider in the Union must hold one of four statuses: ESMA authorisation, an equivalence decision, authorisation for endorsement, or recognition. Article 5 sets up a transitional regime for small providers, those meeting the small-undertaking or small-group thresholds under Directive 2013/34/EU may operate under a lighter notify-and-register process, subject only to the organisational and transparency provisions, without immediately obtaining full authorisation, though they must apply for full authorisation once three years have passed or once they outgrow the small-provider threshold. Articles 10 through 12 address non-EU providers through equivalence decisions, intra-group endorsement, and a recognition regime designed for small non-EU providers; each pathway reflects the same underlying logic, that supervisory consistency should not come at the cost of shutting out providers who are still working through the application process. Article 14 requires ESMA to maintain a public register listing every provider holding authorisation, equivalence, endorsement or recognition status, which becomes the first checkpoint for confirming whether a given rating carries supervisory standing.

IV. General Governance Principles and the Small-Provider Exemption

Article 15 sets out the general governance principles. It requires that a provider’s rating activities remain independent of political and economic influence, that methodologies be rigorous, systematic, independent and verifiable, and that they be reviewed at least annually. It also requires a permanent, independent oversight function reporting directly to management, so that rating quality is not compromised by commercial pressure. Article 22 opens a narrow exemption window for small providers, allowing them to apply to ESMA for relief from certain heavier obligations under Article 15, but ESMA reviews each request against whether the provider’s size is genuine, whether it has built internal controls sufficient to protect analyst independence, and whether the exemption is truly proportionate to its scale and complexity, precisely to prevent providers from understating their size to dodge supervision.

V. Methodology Transparency and Disclosure Obligations

Articles 23 and 24 are the two provisions most directly disruptive to the rating industry’s existing business model. Article 23 requires public disclosure of methodologies, models and key rating assumptions, along with more granular information for users, including which dimension of the double-materiality principle a rating addresses, how weight is assigned across E, S and G factors, and the limitations of both the data and the methodology used. Article 24 requires more detailed, product-specific disclosure to users, rated items and issuers for each rating actually issued, so that users can perform their own due diligence before deciding whether to rely on a given rating. Together, these two provisions expose to public scrutiny a long-standing complaint about ESG ratings, that they were something of a black box and that the same company could receive wildly different scores from different providers.

VI. Independence and Management of Conflicts of Interest

Articles 25 through 27 address the commercial structure of rating providers themselves. Article 25 imposes a core separation-of-business rule: a provider cannot, within the same legal entity, offer ESG ratings alongside consulting, credit rating, benchmark administration, investment activities, auditing, or banking, insurance or reinsurance services. Benchmark administration, investment, credit and insurance activities may coexist within the same entity if the provider can demonstrate adequate risk-segregation measures, but credit rating and audit or consulting activities allow for no such carve-out and must sit in a separate legal entity. The article also addresses conflicts at the individual level, senior management may not trade financial instruments issued by any entity the provider rates, and anyone involved in the rating process who has a relationship that could compromise objective judgement must be excluded from that particular rating decision. Article 26 requires providers to build internal policies for employees involved in the rating process, so that any relationship that could threaten independence is identified and addressed promptly rather than after a dispute has already surfaced. Article 27 addresses fair, reasonable, transparent and non-discriminatory treatment of users, centred on a fee structure that must be cost-based and free of discriminatory pricing among users in comparable positions.

VII. The Annex III Disclosure Checklist

Annex III turns the disclosure obligations in Articles 23 and 24 into a concrete checklist, split into two parts. The first part corresponds to Article 23 and covers what must be published on a provider’s website, the purpose and scope of the rating, the weighting assigned across factors where they are aggregated, data sources and processing methods, the limitations of the methodology, the nature of engagement with rated entities, conflicts of interest and mitigation measures, and whether the rating takes into account international agreements such as the Paris Agreement. The second part corresponds to Article 24 and covers supplementary, product-specific information provided to users and rated entities that is not made public. Notably, in its draft technical standards, ESMA has specified most items under the first part in considerable detail, while deliberately leaving greater flexibility on the second part, a distinction that reflects a simple logic: public disclosure needs standardisation to be comparable, but forcing a single format onto the product-specific detail of each individual rating would risk flattening the methodological diversity that different providers are meant to bring to the market.

VIII. Industry Impact Analysis: The EU and Taiwan

1. Impact on Rated Enterprises

Taiwanese exporters are unlikely to fall directly under ESMA’s supervision, since most of the international agencies that rate them are established outside the Union, and providing a rating to a recipient that is not a regulated EU financial undertaking does not necessarily constitute operating in the Union under Article 2. That does not mean Taiwanese companies are unaffected. The real pressure comes from downstream. EU institutional investors and banks, in order to meet their own SFDR marketing-disclosure obligations, must publish on their websites the methodology source and ESMA registration link for any rating they cite, which will push them toward providers that hold EU supervisory status. Those providers, in turn, need to pass Annex III’s methodology-disclosure scrutiny, and will therefore demand more complete, more verifiable emissions and governance data from the companies they rate, in formats closer to EU convention. For Taiwanese exporters already preparing CBAM filings or supply-chain due-diligence packages, this means the same batch of emissions data may need to satisfy GHG verification, CBAM reporting and an international rating provider’s data requests all at once, each with its own granularity and format, materially raising the cost of coordination.

One easily overlooked feature is that rated entities have the right to request the dataset a provider used to produce their rating, and to flag factual errors in it. This right cannot be used to influence methodology or outcome, but it does give rated companies a complaint channel that was largely absent before. For Taiwanese companies, this means that on receiving an unfavourable rating, it is worth first checking whether the underlying data the provider relied on is accurate, rather than simply accepting the result, one of the few features of this Regulation that actually works in a rated company’s favour.

2. Impact on Verification Bodies

Verification bodies occupy a more distinctive position, because Article 2 explicitly excludes ratings developed exclusively for accreditation or certification purposes, not aimed at investment decisions, from the scope of supervision. This means GHG verification activity of the ISO 14064 type is not, in principle, reclassified as a supervised ESG rating, and verification bodies do not need to apply for ESMA authorisation. But this exclusion line also marks out both an opportunity and a risk. The opportunity is that, as rating providers come under growing pressure to disclose methodology limitations and data quality, they will increasingly need underlying data that comes from a credible, third-party-verified source rather than a company’s own self-reported figures, which gives bodies already holding ISO 14064 verification credentials a potential new service line, packaging verified data as a product that rating providers can adopt directly, on top of their existing verification business. The risk lies in the boundary itself. Article 3’s definition of an ESG rating is fairly broad, covering any opinion or score produced under an established methodology and ranking system, regardless of what label is attached to it. If a verification body were to launch a separate scoring or ranking product aimed at investment decisions, alongside its existing verification business, it could cross the line drawn in Article 2(2)(o), moving from an excluded certification activity into an ESG rating provider requiring authorisation. For any organisation currently designing a carbon or ESG data monitoring system, this boundary is worth building into the product design from the outset, rather than discovering it after the fact through an unplanned reclassification.

Taken together, this Regulation transmits its pressure through Taiwan’s industry along an asymmetric path. Rated companies face rising disclosure and data-governance burdens, while verification bodies face a reshuffling of market demand, part of their existing verification business has a chance to convert into a data-supply role, but they must at the same time guard the product boundary that keeps them from being reclassified as rating providers themselves. These two directions, one on the enterprise side and one on the service side, are really the same underlying demand for data credibility, showing up in different forms at different nodes of the same supply chain.

References

  1. European Parliament and Council of the European Union. (2024). Regulation (EU) 2024/3005 of the European Parliament and of the Council of 27 November 2024 on the transparency and integrity of Environmental, Social and Governance (ESG) rating activities, and amending Regulations (EU) 2019/2088 and (EU) 2023/2859. Official Journal of the European Union. https://eur-lex.europa.eu/eli/reg/2024/3005/oj/eng
  2. European Securities and Markets Authority. (n.d.). ESG rating providers. ESMA. https://www.esma.europa.eu/esmas-activities/new-supervisory-and-oversight-mandates
  3. Financial Regulations. (2026). EU ESG Ratings Regulation: ESMA authorisation, provider obligations, and what financial institutions must do before July 2026. https://financialregulations.eu/blog/eu-esg-ratings-regulation-guide
  4. Freshfields Sustainability. (2026). The next regulatory layer for ESG rating providers: ESMA consults on draft RTS. https://sustainability.freshfields.com/post/102kbfu/the-next-regulatory-layer-for-esg-rating-providers-esma-consults-on-draft-rts
  5. Mondaq. (2024). New EU regulation on ESG ratings published. https://www.mondaq.com/financial-services/1562372/new-eu-regulation-on-esg-ratings-published
  6. Stibbe. (2026). ESG ratings and new EU supervision as of 2 July 2026. https://www.stibbe.com/publications-and-insights/esg-ratings-and-new-eu-supervision-as-of-2-july-2026
  7. Synesgy. (2026). ESG ratings transparency: How companies can prepare for new ESMA rules. https://www.synesgy.com/en/esg-guide/esg-ratings-transparency-how-companies-can-prepare-for-new-esma-rules/

ESG Ratings Regulation · ESMA supervision · methodology disclosure · independence and conflicts of interest · Annex III · SFDR · Taiwan exporters · verification bodies

First published on LinkedIn . This site holds the canonical version.