Six major ESG rating agencies correlate with each other at 0.54 on average, with the correlation between any two ratings on the same company running from 0.38 to 0.71. Credit ratings from the major agencies sit above 0.9 on published estimates.
The more useful finding in the same research is where that gap comes from. Berg, Kölbel and Rigobon decomposed the divergence and found measurement accounts for 56 per cent of it, scope for 38 per cent and weighting for just 6 per cent. Measurement is the biggest driver, which means two providers looking at the same company and the same attribute arrive at different numbers before anyone argues about what matters.
The study dates from 2022 and several of the providers it examined have since been renamed or absorbed into larger groups. Treat the structural finding as durable and the vendor names as not, which is itself a reason to read the termination clause carefully.
So the procurement question is not which provider is best. There is no such thing. The question is which measurement system you can explain, defend and reproduce three years from now when an assurance provider asks where a figure came from.
Source Coverage: Demand The Reported Versus Modelled Split
This is the question that separates a usable dataset from an expensive one, and it is almost never asked properly.
Do not ask about coverage. Every provider will tell you coverage is excellent. Ask instead for the percentage of values in each field that are company-reported, drawn from a regulator or government source, obtained from a third party, or modelled.
Then insist on that split per field and per region rather than in aggregate. The aggregate conceals the problem. Scope 1 and 2 might be 85 per cent reported across a European large-cap universe and 15 per cent reported across your Asian supplier base, and the blended figure tells you nothing about either.
The follow-up matters more. Can the provider flag every delivered value with its provenance, as a field in the data rather than a note in the documentation? If estimated values arrive looking identical to reported ones, you cannot safely use the dataset in anything that will be assured, because you will not know which numbers have a source document behind them.
Before signing, hand the provider a sample of 50 entities drawn from your actual universe, including the private companies and mid-sized suppliers you genuinely need. Coverage demonstrations run on large caps, where everyone looks competent.
Update Frequency Is Two Separate Questions
Providers answer the frequency question and skip the latency one.
Ask how often the dataset refreshes, then ask what the lag is between a company publishing a figure and that figure appearing in your feed. A quarterly refresh with a nine month lag is a dataset about the year before last. Ask for the observed distribution of that lag across your universe, not the target in the service description.
Controversies and incidents run on a different clock from annual metrics. Find out whether an adverse event is captured within days, at the next scheduled refresh, or whenever an analyst gets to it. If you use the data for supplier screening or exclusion lists, that answer determines whether the screen works.
Methodology: Ask For The Document, Not The Summary
Request the full methodology document, under version control, with a change log. A marketing summary is not a methodology.
Two questions then do the real work. What notice do you give before a methodology change takes effect? And when methodology changes, do you restate history?
The second is the one that causes damage. If a provider silently revises its approach and backfills the dataset, the figure you disclosed last year no longer exists anywhere in the system. Your prior-year report becomes unreconcilable against your current data, and you will discover this during an audit rather than before one.
The protection is point-in-time or as-of access: the ability to pull the dataset as it stood on a date you specify, so you can reproduce exactly what you published. Ask for it in the contract. Providers that have it will say so immediately. Providers that do not will explain why you do not need it.
Regulatory pressure now helps here. Both the EU and Indian regimes push rating providers toward methodology transparency, so a refusal to share methodology is harder to justify than it was two years ago.
Licensing Is Where These Deals Go Wrong Later
Most disputes with data vendors are licensing disputes, and they surface when something else is already urgent. Name each right explicitly rather than relying on a general internal-use clause.
Internal use, specifying which legal entities and how many users. Group structures change and a licence written for one subsidiary does not travel.
Use in regulatory filings and assured reports. Some licences exclude this, and others price it as a separate tier. Finding out after you have built the disclosure is expensive.
Redistribution to lenders, auditors, insurers and joint venture partners. Each is a separate permission in most licences.
Derived data. If you compute something from the feed, is the output yours, and can you publish it? Vendors differ sharply on this.
Use for training or fine-tuning models. A growing number of licences now prohibit it outright. If your team has any intention of building internal tooling on the data, settle this at signature.
Rights on termination. This is the clause worth fighting over. Do you retain, in perpetuity, the historical data you have already reported against? If the answer is no, your audit trail disappears the day you switch provider, and you are locked in by your own disclosure history rather than by the quality of the product.
Auditability: Buy For The Assurance Conversation You Will Have
Limited assurance under ISAE 3000 or ISSA 5000 turns on traceability. For every number in your report, the assurance provider asks where it came from and whether you can show it.
That translates into specific requirements of a data vendor. Per-value provenance. A link or citation to the source document, not just a source category. Timestamps. The methodology version applied to that value. And the ability to regenerate a historical extract on demand.
Two questions beyond the technical ones. Will the provider engage directly with your assurance provider, and does that carry a fee? And have they done it before, for a client at your scale?
Ask for a reference from an assurance provider rather than from a client. A client tells you whether the product is pleasant to use. An assurance provider tells you whether the data survives scrutiny.
Data Export: Assume You Will Leave
Negotiate exit at entry, because you will have no leverage later.
You want both an API and a bulk flat-file export. API-only access makes bulk historical analysis painful and migration worse.
You want schema documentation and a commitment on schema stability, with a defined notice period before breaking changes. Silent schema changes break pipelines, and they break them on the morning the data is needed.
You want a full historical export on termination, in a non-proprietary format, delivered within a stated period.
And check the entity identifiers. Does the provider supply LEI, ISIN or other standard identifiers alongside its own, or only its proprietary ID? A proprietary-only identifier is a switching cost dressed as a feature. Remapping an entity universe is weeks of work that nobody budgets for.
Regulatory Status, If Ratings Are In Scope
If the contract covers ESG ratings rather than raw data alone, regulatory status is now a live diligence item with a near-term deadline.
Regulation (EU) 2024/3005 has applied since 2 July 2026. Providers wanting to continue offering ESG ratings in the EU had to notify ESMA between 2 July and 2 August 2026, and the authorisation application window closes on 2 November 2026, which is a month away. Small providers meeting the EU Accounting Directive thresholds, broadly a balance sheet up to 5 million euros, turnover up to 10 million and no more than 50 employees, can use a three year temporary regime under Article 5. Article 11 allows EU providers to endorse ratings from affiliated third country entities, and Article 12 sets out the third country route.
Ask directly whether your provider has notified and applied, then check the ESMA register rather than taking the answer on trust.
In India, ESG Rating Providers must be registered with SEBI under the Credit Rating Agencies Regulations as amended on 4 July 2023. Registered providers publish final ratings on their own websites and disclose updates within 10 days under the Master Circular dated 12 July 2023. A Core ESG Rating must rest on third-party assured data, which ties the rating directly to the BRSR Core assurance glide path: the top 150 listed entities by market capitalisation from FY2023-24, 250 from FY2024-25, 500 from FY2025-26 and 1,000 from FY2026-27, the year now running. Note that SEBI specified reasonable assurance for BRSR Core throughout, not limited, which is a higher bar than most international regimes apply.
One distinction worth holding onto. These regimes govern ratings, not raw data provision. The same vendor can be an unregulated data supplier and a regulated rating provider, and a single contract may cover both. Work out which parts of your purchase sit on which side of that line, because the transparency rights you get differ.
A Pre-Signature Test Pack
Six things to obtain before the contract is signed, all of which a serious provider can produce within two weeks:
A provenance-flagged delivery of 50 entities you selected from your own universe, not theirs.
The field-level reported versus modelled split for those 50, broken out by region.
The full methodology document with version history and change log.
A point-in-time extract for a date you choose, to prove historical reproducibility.
The licence marked up against the six rights listed above, with each one answered yes or no rather than described.
One reference from an assurance provider who has tested the data in a real engagement.
If a provider cannot or will not supply those, the gap is not in your procurement process. Given that measurement accounts for more than half of the divergence between the major providers, a vendor who will not show you how they measure is asking you to publish numbers you cannot explain. That is a reasonable thing to decline.
General guidance only. Regulatory requirements for ESG rating providers differ by jurisdiction and the dates and thresholds cited reflect the position at the time of writing. Verify a provider's regulatory status directly with the relevant authority, including the ESMA register of authorised ESG rating providers and SEBI's register of registered ESG Rating Providers. Take professional and legal advice on contract terms for your circumstances.
Sources
Berg, MIT Sloan Sustainability Initiative, Regulation (EU), European Securities and Markets Authority, SEBI Master Circular on ESG Rating Providers, International Auditing and Assurance Standards Board, SEBI BRSR Core framework and value chain disclosure circular, International Organization of Securities Commissions, Organisation for Economic Co-operation and Development, KPMG India, Pictet Asset Management
This article is intended for general professional information and does not constitute legal, financial, or investment advice.
Subscribe to our newsletter for more insights, case studies, and ESG intelligence.
Keep abreast of the top ESG Events on OneStop ESG Events.
OneStop ESG Educate: Your go-to source for top ESG courses and training programs tailored to your needs.
Stay informed with the latest insights on OneStop ESG News.
Discover meaningful career opportunities on OneStop ESG Jobs.
.png%3Falt%3Dmedia%26token%3D936a1447-6184-4900-9737-20dcc3f97fa3&w=3840&q=100)

.png%3Falt%3Dmedia%26token%3D910a4ea1-9886-4e46-a5c9-0b48aa7b96bf&w=1920&q=90)
.png%3Falt%3Dmedia%26token%3D4baa5b05-0600-4d01-bc6d-20831e71d3e4&w=1920&q=90)
.png%3Falt%3Dmedia%26token%3D48faafb6-8161-4419-845e-06701bb71f3e&w=1920&q=90)
.png%3Falt%3Dmedia%26token%3D8c16bfa9-f7de-4a81-aba3-6492a996d768&w=1920&q=90)
.png%3Falt%3Dmedia%26token%3D057b4e58-4986-45c7-9421-48f58dbc001e&w=1920&q=90)