1) Introduction: What EY’s Paper Really Signals about Non-financial Data
EY’s new report, Half the Picture, or the Whole Story?, reporting on a survey of UK executives, arrives at a moment when UK businesses are making faster, higher-value, and higher-risk decisions than ever before. The headline finding is stark: 71% of major decisions rely on incomplete or unreliable data, while only 14% of organisations have real-time access to non-financial information.
At first glance, the report reads like a familiar analysis of fragmented systems and poor data quality. But the deeper message is strategic. EY is preparing the market for a regulatory world in which non-financial information — risk, resilience, sustainability, supply chain exposure, and governance — becomes a regulated, auditable component of corporate reporting.
Put simply: the audit marketplace is shifting from financial statements to integrated financial + non-financial assurance, and EY is positioning itself at the center of that transformation.
2) ISSB and CSRD: EY’s True Agenda — The New Non-Financial Assurance Market
The second half of the EY paper is effectively a blueprint for aligning companies with two global frameworks now reshaping corporate reporting:
ISSB (International Sustainability Standards Board)
ISSB standards — issued by the IFRS Foundation — require companies to disclose:
- climate and transition risks
- supply chain and operational resilience
- governance structures
- exposure to geopolitical, physical, and environmental risks
These disclosures must be decision-grade, auditable, and investor-relevant — a major new assurance market for accounting firms.
CSRD (Corporate Sustainability Reporting Directive – EU)
CSRD goes further, mandating:
- detailed sustainability disclosures (ESRS)
- “double materiality” reporting
- mandatory third-party assurance
- coverage of non-EU companies with significant EU revenues
Under CSRD, non-financial reporting is no longer voluntary — it is regulated, structured, and assurance-bound.
EY’s “Total Reporting” language — governance, controls, assurance readiness — is not accidental. It is a direct response to ISSB and CSRD and a signal of where EY intends to lead its clients.
3) The Forward-Looking Risk Imperative: Upstream and Downstream Intelligence
While EY frames non-financial data through ESG and reporting, organisations face a more immediate challenge: understanding real-time risk exposure in their value chains — both upstream (suppliers) and downstream (customers).
Executives increasingly ask:
- Which customers present growing financial, cyber, or operational risks?
- Which suppliers are vulnerable to disruption, sanctions, climate shocks, or fraud?
- Where are the hidden dependencies that could trigger a domino effect?
- Do we understand the resilience of each partner — not just their balance sheet?
These are forward-looking risks, not historical ones.
Traditional financial statements cannot answer these questions.
Standard B2B business information cannot answer them either.
Only a new generation of non-financial intelligence — cyber posture, supply chain transparency, workforce stability, environmental exposure, geopolitical sensitivity — can reveal whether a counterpart is truly resilient.
Corporate value creation increasingly depends on anticipating disruption before it reaches the balance sheet.
4) The Data Void on Non-Financial Data: Accuracy, Reliability, and Timeliness are Still Missing
EY’s own findings confirm a structural market failure: the data required for upstream/downstream risk intelligence is:
- inconsistent
- unverified
- manually collected
- backward-looking
- siloed across providers
- rarely real-time
Examples:
- Supply chain tier-2 and tier-3 exposure is often unknown.
- Cyber and fraud risk ratings are fragmented and vary by provider.
- ESG data is self-reported and unaudited.
- Operational disruption data is anecdotal or delayed.
- Private companies — 90%+ of counterparties — disclose almost nothing.
This gap is dangerous: companies are being asked to manage real-time systemic risk with data that is neither real-time nor systemic.
The result is precisely what EY reports:
- gut-driven decisions
- mispriced risk
- blind spots in supply chains
- delayed recognition of emerging failures
- preventable losses and reputational damage
This void is what makes the next development inevitable.
5) Why Rating Agencies Will Become the Backbone of Non-Financial Risk Intelligence
The key question is now obvious:
Who will supply the structured, accurate, auditable non-financial data required for ISSB/CSRD compliance and forward-looking risk monitoring?
Not traditional credit bureaus.
Not small ESG boutiques.
Not generalist data vendors.
IEI’s opinion is that the only institutions with the necessary capabilities are the global rating agencies and risk-intelligence platforms, because they already provide:
Deep risk-modelling expertise
Moody’s, S&P, and Fitch are built to quantify:
- default likelihood
- systemic risk
- resilience under stress
- scenario analysis
These models naturally extend into:
- cyber risk
- supply chain vulnerability
- climate resilience
- operational fragility
Global reach across non-public companies
Moody’s Orbis, for example, covers 450+ million entities — indispensable under CSRD’s requirement to report on suppliers and value-chain impacts, including SMEs.
Data structures that support audit and assurance
Rating agencies have:
- transparent methodologies
- documented scoring logic
- historical continuity
- governance oversight
- regulatory credibility
This is the type of infrastructure ISSB/CSRD will demand.
The ability to deliver real-time early-warning indicators
Rating agencies increasingly integrate:
- payment behaviour
- macro risk signals
- adverse media
- cyber exposures
- litigation and enforcement events
- operational disruptions
Exactly the intelligence companies need before risk crystallises.
Conclusion
EY’s report identifies a problem — but behind it lies a much larger transformation. Non-financial information is becoming mandatory, auditable, and central to risk assessment. Companies now require real-time intelligence on both customers and suppliers to anticipate systemic threats and protect value.
Yet the current data ecosystem is fragmented, unreliable, and too slow for modern risk management. As regulatory pressure expands under ISSB and CSRD, rating agencies may emerge as the indispensable suppliers of assurance-ready non-financial data — covering both public and private companies worldwide.
One could say this shift marks the beginning of a new era: risk intelligence as the foundation of corporate decision-making. If you ask me, I think the rating agencies are already into it.
Source: EY Survey Report, Intrepid Explorers, LLC research supported by ChatGPT