CSRD, ESRS, and the New Materiality of IT: What CIOs Need Their Boards to Understand

When the Corporate Sustainability Reporting Directive began reshaping disclosure requirements across the EU, most executive attention understandably went to the obvious material topics: energy use, emissions, supply chain labour practices, packaging. IT infrastructure rarely made the first cut of "what matters." That is changing, and CIOs are often the ones who first see why — while boards are still catching up.

This is not a technical shift. It is a strategic and governance shift, and it requires a shared vocabulary between the CIO, the CFO, and the board that, in many organisations, does not yet exist.

Double materiality, in plain terms

The ESRS framework asks companies to assess materiality from two directions at once. The first is financial materiality: does this topic create a financial risk or opportunity for the company? The second is impact materiality: does the company's activity in this area create a meaningful impact on people or the environment, regardless of whether that impact shows up on the balance sheet?

IT infrastructure passes both tests more easily than most organisations initially assume. On the financial side, hardware refresh cycles, extended-use strategies, and secondary-market recovery directly affect capital expenditure and total cost of ownership — this is a live financial number, not a hypothetical one. On the impact side, IT hardware manufacturing carries a significant embedded carbon and critical-raw-material footprint, and the choice between disposal, recycling, and extended reuse has a real and quantifiable environmental consequence.

Once a topic passes double materiality, it is no longer optional to report on it — it becomes part of the same disclosure discipline as financial statements, subject to assurance and audit scrutiny.

Why this lands on the CIO's desk

The data required to report meaningfully on IT circularity — asset inventories, retirement schedules, reuse and resale rates, disposal method, extended service life — sits inside IT operations, not inside sustainability or finance teams. This creates a structural problem: the people who own the reporting obligation (increasingly, the CFO and sustainability function, under board oversight) do not own the underlying data, and the people who own the data (IT) have historically not been asked to produce it in reporting-grade form.

This is precisely why CIOs are finding themselves in unexpected conversations with their CFO and board about material topics that, a few years ago, would never have crossed their desk. It is also an opportunity: a CIO who can walk into that conversation with clean, credible data on the organisation's IT asset lifecycle is solving a real governance problem for the whole executive team, not just answering a question about servers.

The gap between good practice and reportable practice

Many organisations already do some of the right things informally. IT teams often already resell or redeploy retired hardware where it's convenient, and some data destruction processes are already reasonably rigorous. The problem is that "informally reasonable" is not the same as "reportable." ESRS-aligned disclosure requires consistent methodology, an audit trail, and figures that can be defended under external assurance.

This gap tends to surface in three specific places. First, inventory: many organisations cannot say with confidence what IT assets they currently hold, where they are in their lifecycle, or when they are scheduled for retirement — informal spreadsheets and departmental knowledge substitute for a real asset register. Second, outcome tracking: even where hardware is resold or recycled, the organisation frequently cannot quantify what proportion of retired assets followed which path, because no one was measuring it for reporting purposes. Third, the boundary with data security: circularity data — which assets left the organisation and where they went — is inseparable from data protection evidence, since a defensible disposal record has to demonstrate both what happened to the asset and what happened to the data on it. Reporting teams often don't realise these two datasets need to be the same record.

What good governance looks like here

Boards do not need to become experts in IT asset management to govern this well. They need to ask the right questions and expect credible answers, in the same way they already do for financial controls.

A useful test for any board is whether the organisation can currently produce, on request, a defensible answer to: what IT assets did we retire in the last reporting period, what happened to each of them, and what evidence do we hold to support that claim? If the honest answer involves several days of email archaeology across IT, procurement, and facilities, the underlying process is not yet at reporting standard — regardless of how well-intentioned the actual practice may be.

The organisations moving fastest on this are treating it as a governance and process design problem, not a data collection exercise bolted on at year-end. That means building the asset lifecycle process itself to generate reporting-grade evidence as a by-product of normal operations — a decommissioning process that produces a certificate of data destruction and a resale or recycling record automatically, rather than one that requires reconstruction after the fact.

The strategic upside of getting ahead of this

There is a natural temptation to treat CSRD and ESRS as a compliance burden to be minimised. That framing misses a genuine opportunity. Organisations that build credible, well-evidenced IT circularity practices are not just satisfying an auditor — they are building a defensible, differentiated position on resource efficiency at a moment when investors, insurers, and increasingly customers and public-sector procurement processes are starting to ask these questions directly, independent of formal disclosure requirements.

For CIOs, this is a rare moment where a topic that has always been operationally important — how we manage the lifecycle of our infrastructure — is being elevated by regulation into a board-level conversation. The organisations that respond by simply generating a spreadsheet to satisfy the auditor will find themselves doing the same scramble every reporting cycle. The organisations that respond by building lifecycle governance properly, once, will find that the reporting requirement becomes almost incidental — a natural output of a process that was already creating financial and risk-management value on its own terms.

That is the real materiality argument for IT circularity: not that regulation requires it, but that the underlying discipline is worth building regardless, and CSRD has simply made the business case impossible to ignore any longer.


Next
Next

The Boardroom Case for Circular IT: Why Asset Lifecycle Strategy Is Now a CEO Decision