Your EHS Records Are Now a Sustainability Disclosure. Are They Audit-Ready?

Business professionals reviewing charts and documents in a sustainability reporting meeting

The request came in on a Tuesday afternoon: a calendar invite from the sustainability team labeled “ESG report safety data review.” In past years, this meant sending a spreadsheet with your annual TRIR and a lost-time injury summary. This year, the meeting notes arrived ahead of the call. They needed recordable incident rates normalized to hours worked, a count of high-consequence injuries with severity classification, the percentage of the workforce covered under a formal occupational health and safety management system, and confirmation that the data had been reviewed by accountable parties. Third-party assurance was scheduled for the following month.

If that scenario feels familiar, it should. For EHS professionals at large organizations with EU operations or EU-headquartered clients, this is not a hypothetical. It is the current reporting cycle. And for many EHS teams, the moment it arrives reveals a gap that no one planned for: the difference between data that satisfies OSHA recordkeeping and data that survives independent assurance.

Why ESG Reporting Changed What EHS Data Has to Be

The EU’s Corporate Sustainability Reporting Directive (CSRD) is the most significant shift in how organizations document and disclose safety performance in a generation. Large companies began reporting under CSRD in 2025, covering fiscal year 2024 data. The workforce standard, ESRS S1 (Own Workforce), requires specific occupational health and safety disclosures structured for external assurance rather than internal management use.

The OSHA 300 log captures what happened, who was involved, and whether the event meets the threshold for recording. ESRS S1 asks for those same incidents presented as rates per million hours worked, categorized by severity, cross-referenced to OHS system coverage, and attested as complete by accountable parties. These are not the same thing. One is a regulatory record. The other is a statement made to investors and external auditors.

ESRS S1 Required Occupational Health & Safety Disclosures

Metric What Must Be Disclosed
Fatalities Count and rate per million hours worked
Recordable incidents Count and rate per million hours worked
High-consequence injuries Count, rate per million hours, and severity classification
Work-related ill health Number of cases and types of conditions
OHS management system Scope of coverage, ISO 45001 certification status

Source: EFRAG, ESRS S1 Own Workforce

The Audit-Readiness Gap Most EHS Programs Have Not Closed

The gap is rarely a missing metric. It is structural. Incident management programs built to satisfy OSHA recordkeeping requirements capture what happened, who was involved, and whether the event crosses the recording threshold. ESG assurance providers ask a different set of questions: Was every incident classified by the same criteria across all sites? Are the hours-worked denominators reliable and traceable to payroll or timekeeping records? Is there an audit trail from the summary figure to the original investigation documentation? Is the person attesting to the data confident it reflects actual events rather than reporting behavior shaped by local site culture?

That last question is the one most sustainability disclosures are not equipped to answer. And it points to something EHS professionals working in a systems-thinking tradition have understood for years: incident rates do not measure safety. They measure reporting.

The Underreporting Problem Sustainability Disclosures Cannot Ignore

When workers at a facility have learned that submitting a near-miss report leads to blame, investigation, or disciplinary action, they stop submitting. The TRIR drops. In a world where that TRIR is now a public sustainability disclosure, the organization is asserting to investors a safety performance it has not actually achieved.

This is where the systems-thinking lens matters. When workers take at-risk actions or fail to report incidents, the question that drives a good investigation is not who was careless. It is what the system put in place that made that behavior the rational choice. A workforce that underreports is almost always responding to an environment where reporting carries consequences and silence carries none.

Organizations that have built genuine near-miss and incident reporting culture, through blameless investigation processes, visible corrective action closure, and frontline access to reporting that bypasses management gatekeeping, tend to show higher reported incident rates than organizations with comparable actual injury rates but a culture of silence. In the short term that looks like worse performance. In the context of ESG disclosure, it is what data integrity actually looks like. Investors and assurance providers who understand safety are beginning to recognize the difference.

Steps to Prepare EHS Data for ESG Assurance

1

Standardize incident classification criteria across all sites
Ensure every site applies the same definitions for recordable events, high-consequence injuries, and work-related ill health. Site-specific interpretations create inconsistencies that auditors will flag.
2

Establish reliable hours-worked denominators
Rates per million hours require consistent hours-worked data tied to actual labor records, broken down by site and work type if required by the reporting standard.
3

Build traceable audit trails from summary to source
Every number in your ESG disclosure should trace back to individual investigation records. If an auditor asks to see the cases behind a rate, the answer should take minutes, not days.
4

Remove friction from frontline incident reporting
High near-miss reporting volume relative to recordable incidents is a signal of a healthy reporting culture. Programs that make it easy to report, with no barriers for frontline workers, produce more trustworthy aggregate data.
5

Track and disclose corrective action closure rates
Whether your program actually acts on what it finds is itself a material data point. Corrective action completion rates demonstrate that the OHS management system functions, not just exists.

What Changes When You Build for Disclosure

EHS programs designed with data integrity as a first-class requirement look different from programs designed around compliance minimums. They use standardized incident classification across all sites rather than site-specific interpretations of what “recordable” means. They track near-miss and first-aid events even when not required, because the ratio of near-misses to recordable incidents signals how the reporting system is functioning. They document corrective action closure rates because that data shows the program responds to what it finds. And they build reporting access into frontline workflows so that submitting an incident observation requires less friction than not submitting one.

None of this is new practice. These are the elements that have always distinguished a mature EHS program from a compliant one. What is new is that these elements now contribute directly to an organization’s external reputation, investor relations, and procurement eligibility in a measurable, disclosed, audited way.

How Q-Incident Can Help

Quantum’s Q-Incident module gives EHS teams a centralized, structured platform for recording, classifying, and investigating workplace incidents across all sites. Every record is captured with consistent classification criteria and linked to investigation documentation, producing the kind of structured, traceable output that ESG assurance providers expect to see when they pull the data behind a disclosed TRIR.

Frontline access matters here as much as the data structure. Workers can submit incident and near-miss reports by scanning a site QR code and entering only their employee ID, with no app download and no password required. That reduction in reporting friction directly supports the honest, high-volume near-miss reporting that makes incident data trustworthy at an aggregate level, which is exactly what audit-readiness for sustainability disclosure requires. Learn more about how Quantum EHS Management supports organizations preparing for complex disclosure requirements.

Scroll to Top