Where does ESG risk sit in an IT services business?

QuestionsCategory: ESGWhere does ESG risk sit in an IT services business?
1 Answers
Best Answer
Team GreenSutra Staff answered 17 hours ago
Flat editorial night illustration: A lone tall cabinet stands on an open plain, six doors swung wide on hinges. The lowest door shows stacked hardware and cooling fans.

ESG risk in an IT services business sits mostly outside the environment, concentrated instead in data protection, workforce practice and commercial conduct. The SASB Software & IT Services Standard names six disclosure topics, and only one of them describes a physical footprint. The remaining five cover privacy, security, workforce, intellectual property and systemic technology disruption.

The intuition that a firm with no factory carries little ESG exposure rarely survives its first client security questionnaire. Exposure does not vanish in an asset light business; it relocates. In IT services it relocates into the data held on behalf of clients, into the people holding that data, and into the conduct rules governing both.

What the standard setter says the topics are

The SASB Standards, for which the ISSB has been responsible since August 2022, are categorised under a classification system covering 77 industries across 11 sectors. Software & IT Services sits in the Technology & Communications sector, and its industry description reaches entities delivering specialised IT functions such as consulting and outsourced services, which is the passage that brings an Indian IT services exporter inside the industry. Version 2023-12 of that standard is effective for annual periods beginning or after 1 January 2025.

Diagram, Where the exposure actually sits. Asset light, not risk light (The exposure relocates, it does not disappear). One physical topic: Hardware and compute. Five that are not: Data privacy; Data security; Global workforce and more.
Where the exposure actually sits
Disclosure topic Where the exposure actually sits
Environmental Footprint of Hardware Infrastructure The single physical topic: the hardware and computing capacity behind the service
Data Privacy & Freedom of Expression Client and end user data, consent, and how handling obligations are met
Data Security Breach exposure across delivery centres and client environments
Recruiting & Managing a Global, Diverse & Skilled Workforce Attrition, skills supply, composition of a distributed workforce
Intellectual Property Protection & Competitive Behaviour Code ownership, licensing, competition conduct
Managing Systemic Risks from Technology Disruptions Continuity where client operations depend on the service

Two consequences for the risk register

1. The environmental line narrows rather than disappears. It concentrates in compute, cooling and hardware refresh, and is answerable with meter data and procurement records rather than with a site inventory. 2. The social and governance lines carry most of the weight, and their evidence is contractual and procedural: access controls, incident logs, retention schedules, workforce composition, code provenance and continuity testing.

No GRI Sector Standard covers software as of August 2026. Software appears in Group 3 of the prioritised sector list approved in November 2025, behind every sector already published or in progress. Until it publishes, the SASB standard is the only published industry specific basis, and a material topic list should state plainly which basis it rests on.

Sources: SASB Software & IT Services Standard, version 2023-12, SASB Sustainable Industry Classification System industry list

ESG solutions structures the evidence behind each of the six topics and readies the data file for whoever assures, rates or scores it. The ESG guide sets out how a material topic list is built and defended. The same ranked exposure areas and named gaps can be produced ahead of the first data collection.