
Simpler Reporting, Harder Judgment
TL;DR
The CSRD Omnibus I Directive, finalised February 2026, narrows CSRD and CSDDD scope thresholds, removes the harmonised EU civil liability regime, and removes the CSDDD requirement to adopt a climate transition plan, but none of it changes whether climate and sustainability risk is financially material to an institution's balance sheet. Supervisory pressure through the ECB's SREP/Pillar 2 process and EIOPA's Solvency II/ORSA framework was never contingent on CSRD scope and is unaffected by the Omnibus. Institutions that treat scope relief as governance relief, rather than scaling proportionately, are recreating the exact structural gap this series has tracked from the start.
Simpler disclosure rules do not remove the board's obligation to govern material sustainability risk.
Brussels did not remove the governance question when it simplified the reporting rules. It handed more of it to the board.
The relief that looks like relief
For two years, mid-tier financial institutions across Europe have been asking the same question in one form or another: when does this get easier? In February 2026, the Council of the European Union gave them an answer. The Omnibus I Directive, finalised after more than a year of negotiation, narrows the scope of the CSRD and the Corporate Sustainability Due Diligence Directive, delays several reporting timelines, and strips out provisions that institutions had spent two years building infrastructure to meet.
For a lot of firms, the instinct on reading the headlines will be relief. Fewer companies in scope. Lighter due diligence obligations. No more mandatory climate transition plan. A simplified set of reporting standards on the way. It reads, at first pass, like the regulatory tide going out.
It is worth being precise about what actually changed before deciding what it means, because the two are not the same thing, and the gap between them is where the governance risk in this article sits.
What the Omnibus actually changes
The mechanics are specific, and they are worth setting out plainly, starting with the scope thresholds themselves.
Directive: CSRD. Original threshold: phased scope, large companies, listed SMEs, third-country subsidiaries. Revised threshold under Omnibus I: more than €450 million turnover and 1,000 employees.
Directive: CSDDD. Original threshold: more than 1,000 employees and more than €450 million turnover. Revised threshold under Omnibus I: more than 5,000 employees and more than €1.5 billion turnover, plus a franchisor carve-in.
The harmonised EU-wide civil liability regime under the CSDDD has been removed. Liability for due diligence failures now falls back to national law in each member state, which means a multinational institution's exposure depends on where a claim is brought, not on a single EU standard.
The CSDDD requirement to adopt and implement a climate transition plan has been removed, although companies in CSRD scope that have a plan must still disclose it. Sector-specific reporting standards have been replaced with non-binding guidance rather than binding requirements. Due diligence has been restructured into a two-stage process: an initial scoping exercise based on available information, followed by a targeted deeper assessment only where the scoping stage identifies a specific concern. Information requests to smaller value-chain partners are capped, and companies with fewer than 1,000 employees can decline requests that exceed voluntary reporting standards. The reasonable assurance requirement for sustainability disclosures has been dropped, and assurance deadlines have been pushed out.
EFRAG published draft simplified reporting standards in December 2025. The European Commission is required to adopt the revised standards within six months of the Amendment Directive entering into force on 18 March 2026, with application expected from fiscal year 2027 reporting. Companies newly out of scope because of the raised thresholds are excluded for fiscal years 2025 and 2026. Companies still in scope under the original Wave 1 rules continue reporting under the existing framework, using the interim relief already available, unless and until their member state formally transposes an exemption into national law.
That is what the Omnibus does. None of it is trivial, and none of it should be dismissed. But look closely at the list and a pattern becomes clear. Almost everything that has been removed is a reporting or process obligation. Almost nothing that has been removed is the underlying question of whether sustainability risk is financially material to the institution and whether it is being governed.
Ninety percent of companies, and one governance obligation that did not move
The scale of the scope reduction is significant. Legal commentary tracking the Omnibus estimates that ninety percent of the companies originally expected to fall under CSRD are now out of scope. For those firms, and for institutions whose customers, borrowers, or portfolio companies drop out of scope alongside them, the change is real and material to their compliance calendar.
It is not, however, a change to whether climate and sustainability risk is material to their balance sheet.
This is the distinction that boards need to hold onto through 2026 and into 2027, and it is easy to lose. A firm dropping out of CSRD scope stops having a mandatory disclosure obligation. It does not stop having credit exposure to transition risk in its loan book, underwriting exposure to physical risk in its property portfolio, or investor and counterparty expectations that have not moved just because Brussels adjusted a threshold. The disclosure obligation and the underlying risk were never the same thing. The Omnibus makes that separation harder to ignore, not easier, because it removes the disclosure requirement while leaving the risk exactly where it was.
Institutions that respond to the Omnibus by quietly dismantling the governance infrastructure they built for CSRD, the risk taxonomy integration, the board reporting lines, the materiality assessment process, are not simplifying. They are recreating the exact structural gap this series has been describing from the start: a financially material risk sitting outside the governance framework, observed rather than governed.
The judgment shift
The more consequential change in the Omnibus is not the scope reduction. It is what happens to the judgment boards and management are now required to exercise.
Under the original CSRD and its detailed sector-specific standards, a large part of the reporting exercise was mechanical. The standards specified what to disclose and how. Materiality assessments still mattered, but the framework did a considerable amount of the work for the institution.
The simplified standards move in the opposite direction. Sector-specific requirements become non-binding guidance rather than a compliance checklist. Materiality determinations carry more weight because there is less prescriptive structure sitting underneath them. And auditors, under early guidance on the post-Omnibus regime, are expected to scrutinise not just what a company disclosed, but why a company decided a topic was not material and therefore excluded it. The burden shifts from justifying inclusion to justifying omission.
That is a governance problem dressed up as a compliance simplification. A board that could previously point to a detailed standard as the basis for its disclosure decisions now has to be able to demonstrate the reasoning behind a judgment call, made with less prescriptive guidance, under more scrutiny of what was left out. If that reasoning was never documented, if the materiality assessment behind it was never challenged at board level, if the process that produced the judgment cannot be reconstructed and defended, the institution has more discretion and less protection at the same time.
What this looks like in practice
Take a mid-tier European bank that expects to fall out of CSRD scope under the revised thresholds. Sustainability reporting has, until now, been treated as a compliance exercise, owned by a small team, built against the detailed original standards, reviewed by a sustainability committee that reports narratively to the board twice a year.
When the bank confirms it is out of scope, the instinct across the organisation is to wind the function down. The reporting team is redeployed. The sustainability committee's agenda thins out. The materiality assessment that used to happen annually is quietly discontinued, because nobody is asking for it anymore.
Eighteen months later, the bank's credit committee is reviewing a concentration of exposure in commercial real estate that has not been screened for transition risk since the reporting obligation lapsed. A large institutional investor conducting counterparty due diligence asks for the bank's current view on climate-related financial risk in its loan book and receives a materiality assessment that is two years out of date. A supervisor, applying proportionality principles that were never conditional on CSRD scope in the first place, asks how the bank is governing a risk it publicly acknowledged as material in a report it produced only three years earlier.
None of that exposure was created by the Omnibus. It was created by treating a disclosure obligation and a governance obligation as the same thing, and assuming that removing one removes the other.
The supervisory hammer that never needed CSRD
Even institutions that read every word of the Omnibus correctly can still miss the point if they treat CSRD as the primary source of climate governance pressure. It never was, for banks. The ECB's expectations on climate and environmental risk, embedded in supervisory review through the SREP process, in Pillar 2 capital assessments, and in ICAAP risk identification, were built independently of the CSRD disclosure regime and were not amended by the Omnibus. The ECB's 2022 climate stress test and its ongoing thematic reviews remain part of the supervisory toolkit regardless of what happens to CSRD. A bank supervised by the ECB, or by a national competent authority such as BaFin, the ACPR, or the Banco de España applying the same guide, can still receive a Pillar 2 add-on for weak climate risk governance whether or not that bank has ever produced a CSRD report. The disclosure directive and the supervisory mandate travel on separate legal tracks, and only one of them just got lighter.
For insurers, the same logic runs through EIOPA's expectations under Solvency II and the ORSA process. For all regulated financial institutions, the point is the same: supervisors judge climate risk governance through their own prudential mandate, not through whether a firm happens to fall inside or outside a disclosure directive's scope threshold. A board that treats being out of CSRD scope as evidence that its supervisor has stopped asking is confusing two different regulators' authority for one.
This is the argument mid-tier institutions most need to hear, because it is the one most likely to be missed in the relief of a lighter compliance calendar. The supervisory hammer was never CSRD. It was always prudential.
The legal exposure moved. It did not disappear.
For institutions that remain in CSRD scope, the immediate task is different but related. The removal of the harmonised civil liability regime under the CSDDD means exposure now varies by the national law of each member state in which the institution operates or is challenged. For a firm with cross-border operations, that is not necessarily simpler. It is more fragmented, and it requires legal judgment about exposure in multiple jurisdictions rather than a single EU standard to point to.
Fragmentation cuts both ways. Claimants now have an incentive to bring a due diligence claim in whichever member state offers the most favourable procedural rules, the longest limitation period, or the most claimant-friendly standard of proof, rather than in the jurisdiction where the institution is headquartered or where the harm occurred. That is forum shopping, and it is a direct consequence of removing a single EU standard, not a side effect of it. An institution operating across a dozen member states now needs to understand its worst-case exposure across a dozen separate legal regimes, not its exposure under one.
There is a second legal exposure that has nothing to do with the CSDDD liability regime and everything to do with years of voluntary public statements. An institution that has published sustainability reports, climate transition plans, and ESG commitments for the past three or four years, then stops the moment the mandatory requirement lifts, has not simply reduced its compliance burden. It has created a visible gap between what it said publicly and what it is doing now, at exactly the moment when greenwashing enforcement under the EU's Unfair Commercial Practices Directive, national consumer protection regimes, and increasingly assertive securities regulators is intensifying rather than easing.
A revoked disclosure requirement is not a liability shield. Public statements made during the 2023 to 2025 reporting cycles do not disappear when the requirement that prompted them does, and remain available as evidence in national proceedings on misleading commercial practices.
The removal of the mandatory transition plan removes a specific obligation. It does not remove the expectation, from the ECB, from institutional investors applying their own stewardship standards, and from sophisticated counterparties, that an institution with material transition risk exposure has thought through how that exposure evolves over time. A bank or insurer that no longer has to adopt a transition plan but also no longer has one internally, having stopped producing it the moment the mandatory requirement lifted, has not reduced its risk. It has removed the evidence that the risk was being managed.
This is the same governance mandate this series opened with, applied to a specific regulatory moment. The mandate has not moved because the regulators simplified a directive. If anything, a lighter compliance framework with more discretionary judgment inside it is a framework that rewards institutions with strong governance discipline and penalises institutions that were only ever meeting the letter of the prior standard.
What still has to be true?
None of this requires new infrastructure. It requires clarity on two things that matter more now than they did eighteen months ago. Who, specifically, owns sustainability risk governance in an institution now navigating national liability exposure rather than a single EU standard. And whether the institution can show, from its own records, how a materiality judgment was reached, what was considered and excluded, and who challenged it, in a framework built on discretion rather than prescription.
Institutions that already have both in place will find the post-Omnibus environment far less threatening than the headlines suggest. Institutions that do not will find the gap has quietly widened, while nobody outside the boardroom was required to check.
Do not read scope relief as risk relief
The temptation for institutions newly out of CSRD scope, particularly mid-tier firms that found the original compliance burden disproportionate to their size, is to treat the Omnibus as license to step back from sustainability governance altogether.
That reading confuses proportionality with exemption. Proportionality was never meant to describe the depth of a compliance exercise dictated by an EU directive. It describes how deeply a firm needs to invest in assessing a financially material risk relative to its size and complexity, calibrated to its own portfolio. That calibration question existed before the Omnibus, and it exists after it. What has changed is the absence of an external framework forcing the exercise. What has not changed is the exposure the exercise was designed to surface.
Institutions that use the scope relief to scale their governance appropriately, keeping a materiality process, keeping board-level ownership, keeping the documentation discipline, while reducing the reporting overhead that no longer applies to them, are reading the Omnibus correctly. Institutions that use it to stop the underlying work are storing up exactly the exposure this series has been describing from its first article, just with a longer fuse.
Questions before the next board risk committee
Before the next Board Risk Committee or ICAAP cycle, six questions are worth putting on record.
Scope status. Has our CSRD scope status actually changed under the revised thresholds, and has that determination been documented, not assumed from headlines?
Deliberate scaling. If we have fallen out of scope, have we made a deliberate decision to maintain a proportionate materiality assessment and governance process, or has the function simply been allowed to lapse?
The supervisor question. Could our supervisor identify a Pillar 2 or ICAAP-relevant climate governance weakness in our institution today, entirely independent of our CSRD status?
Materiality reasoning. Could we show, with documentation, the reasoning behind a decision that a specific sustainability topic was not material to our business, in a form that would satisfy an auditor applying the post-Omnibus scrutiny standard?
Jurisdictional exposure. If our harmonised EU civil liability exposure has been replaced by exposure under multiple national regimes, do we understand what that means for us specifically, in the jurisdictions where we actually operate, and where a claimant might now choose to bring a case against us?
The transition plan gap. If we no longer produce a mandatory climate transition plan, do we still have an internal view of how our transition risk exposure evolves over the life of our lending book or investment portfolio, or did that thinking stop when the requirement did, leaving a visible gap between what we said publicly and what we do now?
If those questions produce hesitation, the governance gap the Omnibus was never designed to close is already there.
Closing
Scope relief changes the paperwork. It does not remove the exposure.
Regulators simplified the paperwork. They did not simplify the underlying question of whether a financially material risk is governed or merely observed. Institutions that understand that distinction will use the relief as it was intended, to focus their governance effort where it is proportionate and defensible. Institutions that mistake the relief for permission will find that the next time someone asks for evidence, a supervisor, an investor, a court applying national law, the reporting obligation that used to force the discipline is the only thing that is gone. The risk, and the standard they will be judged against, is still exactly where it was.
Not sure whether your governance framework is proportionate to your revised CSRD scope, or simply lapsed along with the reporting requirement? The ARCHITECT™ Governance Maturity Assessment gives mid-tier financial institutions a structured diagnostic over two to three weeks, showing what to keep, what to scale back, and what the Omnibus never actually changed.
Start the ARCHITECT™ Governance Maturity Assessment →
Sources
Author bio
Brendan Walsh is the founder of Walsh SRA and creator of the ARCHITECT™ Governance System. He brings more than 30 years of global executive leadership at American Express across the US, Europe and Asia, including as Chairman of American Express Services Europe and American Express Bank Russia. He has served as a Board Advisor to OFGEM, the UK energy regulator, and as a Board Member of the ECB's Euro Retail Payments Board. He holds a Master's in Sustainability from Harvard and GARP certifications in Sustainability & Climate Risk and AI Risk. Walsh SRA advises mid-tier banks, insurers, asset managers and private equity firms on governance for climate, sustainability and AI risk.