What General Counsel at Private Companies Needs to Understand About ESG
ESG is landing on general counsel's desk more often, and not always through channels that make the scope obvious. A customer contract with new sustainability representations. A GP questionnaire that nobody else picked up. A request to review a European regulation that may or may not apply to the company. An internal policy that needs sign-off before it can go out.
None of these feel like the same issue, but they are all ESG, and they all have legal dimensions. The challenge for most GCs at PE-backed companies is figuring out which parts are genuinely legal work and which parts need a different kind of expertise.
Here is how to think about it.
Customer contracts with ESG requirements
This is often the first place ESG shows up for legal. A customer sends a contract for renewal and there is a new section: supplier code of conduct, sustainability representations, ESG compliance requirements. Sometimes it is a standalone supplier questionnaire. Sometimes it is embedded in the contract itself.
The legal question is straightforward: what are you being asked to represent and warrant, and can the company actually stand behind it? The harder question is whether the company has the underlying data and documentation to support those representations. A representation that the company has a sustainability policy is only as good as the policy itself. A warranty related to emissions data requires an actual GHG inventory.
The GC can review the contract language and assess the legal risk. But confirming that the company can actually make the representations being asked for requires knowing what ESG documentation exists and whether it is accurate. If the company has not done a carbon footprint, a representation about emissions data is a liability.
Updating your own contracts with ESG language
As ESG becomes standard in supplier relationships, companies are also being asked to add ESG language to their own contracts. Supplier codes of conduct, environmental compliance requirements, data privacy and security provisions tied to ESG frameworks.
Getting this language right requires understanding what the company is actually committed to and what it can actually enforce. A supplier code of conduct that references standards the company does not itself meet creates exposure. Vague or aspirational ESG contract language is harder to enforce and easier to challenge.
The GC's role is to make sure the language is accurate, enforceable, and consistent with what the company is representing elsewhere. That requires knowing what the company's actual ESG commitments are, which means working closely with whoever owns the ESG program internally. Bonterms has published open source climate contract provisions that are increasingly being used as a baseline for ESG-related commercial terms. Salesforce's supplier sustainability resource library illustrates what large companies are asking of their suppliers. Both are useful reference points for understanding where commercial ESG expectations are heading.
Regulation to know about
A growing body of ESG regulation is relevant to PE-backed private companies, directly or indirectly. Key frameworks to be aware of:
US: California's SB 253 (Climate Corporate Data Accountability Act) requires companies doing business in California with annual revenue over $1 billion to disclose Scope 1, 2, and 3 emissions. SB 261 (Climate-Related Financial Risk Act) requires companies with revenue over $500 million doing business in California to disclose climate-related financial risks. Both are in active implementation as of 2026, with enforcement subject to ongoing litigation. Companies incorporated outside California may still be subject to these laws if they do business in the state.
EU: The Corporate Sustainability Reporting Directive (CSRD), the Sustainable Finance Disclosure Regulation (SFDR), the German Supply Chain Due Diligence Act, and the Corporate Sustainability Due Diligence Directive (CSDDD).
Climate risk is worth flagging as a distinct category. The Task Force on Climate-related Financial Disclosures (TCFD) framework has been widely adopted by investors and is increasingly embedded in regulatory requirements globally. GPs and sophisticated investors may ask portfolio companies to assess and disclose climate-related risks to the business. This is a different exercise from emissions reporting. It requires input from finance and operations on how physical and transition risks could affect the business.
Most US-based private companies are not directly subject to all of these. Indirect exposure through customer and investor relationships is real and increasing. The GC's job is to understand which apply directly, which apply indirectly, and what the actual obligations are. Understanding what data needs to be collected and how to produce it is where ESG expertise comes in.
Internal ESG policy drafting and sign-off
Most ESG documentation requires legal review before it is published or shared externally. A sustainability policy, a supplier code of conduct, a climate commitment, a modern slavery statement. These are not marketing documents. They create representations about the company's practices and commitments that can have legal consequences if they are inaccurate or aspirational rather than grounded in actual practice.
The GC's role in policy development is to make sure the language is accurate, that it does not overcommit the company to things it cannot deliver, and that it is consistent with other representations the company is making to investors, customers, and regulators.
What the GC typically does not need to own is the substantive content of the policy. What the company's actual sustainability practices are, what targets are achievable, what frameworks apply. That is ESG expertise. The GC reviews and approves. They do not need to draft from scratch.
Modern slavery statements deserve specific mention. The UK Modern Slavery Act and Australia's Modern Slavery Act 2018 both establish mandatory reporting requirements for larger organisations. But smaller companies, well below either threshold, are increasingly being asked for modern slavery statements by customers who are themselves subject to these laws. A US-based professional services firm with no UK or Australian operations may still find one showing up in a customer RFP. The GC typically owns this document, and producing it well requires input from procurement and operations, not just legal.
GP questionnaires landing on legal's desk
This happens more than it should. A GP sends an ESG questionnaire, nobody is sure who owns it, and it ends up with legal because it looks like a compliance document. The GC ends up trying to answer questions about GHG emissions, EDCI metrics, and science-based targets without the context or data to do so accurately.
The GC can usefully own the governance sections of a GP questionnaire: board composition, policy documentation, legal and regulatory compliance. They should not be expected to own the environmental data sections without support.
If GP ESG questionnaires are consistently landing on legal's desk, that is a signal that the company needs a clearer internal owner for ESG reporting. Legal can play a coordinating role but should not be the default owner of the entire response.
How the company represents itself on ESG
As companies make more ESG commitments publicly, the accuracy of those representations becomes a legal issue, not just a communications one. Sustainability reports, website claims, investor materials, RFP responses, supplier questionnaires. All of these create representations that can have consequences if they are inaccurate or overstated.
Greenwashing exposure is real and growing. Relevant frameworks and guidance include the EU's Empowering Consumers for the Green Transition Directive, the FTC Green Guides, and the UK CMA's Green Claims Code. The GC does not need to be an expert in all of these, but should know they exist and when to flag a claim for closer review.
The GC's role is not to approve every piece of sustainability content, but to establish a review process for material ESG representations. Any specific claim the company makes — reduced emissions by a certain percentage, a certification achieved, a supplier standard met — should be confirmed as accurate before it goes out.
A representation that the company has a carbon footprint is only as defensible as the methodology behind it. A claim about supplier standards is only as defensible as the supplier code of conduct and the process behind it. Legal's role is to make sure the company is not making commitments it cannot substantiate.
ESG as a risk management issue
Most GCs are trained to think about risk. ESG belongs in that framework.
Regulatory risk is the most obvious: non-compliance with reporting requirements, failure to meet contractual ESG obligations, or misalignment with emerging disclosure standards all create legal exposure. Reputational risk follows. An unsubstantiated ESG claim, a supplier relationship linked to labor violations, or a data breach affecting ESG-sensitive information can all become legal issues quickly.
Transaction risk is also real. In M&A and investment contexts, ESG due diligence is becoming standard. Buyers and investors are looking at whether the company has made ESG commitments it cannot substantiate, whether there are regulatory compliance gaps, and whether ESG representations in disclosure documents are accurate. A company that has not done a carbon footprint, has no sustainability policy, and cannot answer basic questions about its supply chain practices is carrying ESG risk into a transaction.
Finally there is contractual risk. As ESG provisions in commercial contracts become more specific and more enforceable, the risk of being unable to meet a representation or warranty tied to ESG data increases. A company that has made representations about its emissions without a GHG inventory, or about supplier standards without a supplier code of conduct, has created contractual risk that may not surface until a renewal or dispute.
How ESG is changing the legal function
ESG is reshaping what in-house legal work looks like at private companies.
Contract complexity is increasing. What started as broad sustainability language is evolving into specific representations about emissions data, supplier standards, and regulatory compliance. GCs who understand the ESG landscape will be better positioned to negotiate these provisions and assess the risk they create.
Disclosure risk is growing. As companies make more ESG commitments publicly, the legal exposure from inaccurate or aspirational claims increases. Greenwashing litigation is still emerging but the regulatory framework around it is tightening.
Regulatory volume is not slowing down. CSRD, CSDDD, SFDR, California SB 253 and SB 261, and equivalent legislation elsewhere are all moving in the same direction. Even companies not directly subject to these regulations will feel them indirectly through customer and investor relationships.
Board governance expectations are shifting. Investors and regulators increasingly expect boards to have oversight of ESG matters, which has implications for committee structures, director responsibilities, and disclosure obligations.
None of this means the GC needs to become an ESG expert. It means ESG literacy is becoming a practical requirement for effective in-house legal work at a PE-backed company.
Where legal work ends and ESG expertise begins
Legal owns the review, sign-off, and accuracy assessment of ESG representations and commitments. ESG expertise owns the underlying data, methodology, and program that makes those representations accurate.
A GC who knows where that line is will be more effective at both. They will know which questions to ask of the ESG consultant, which contract representations require substantiation, and which regulatory obligations need specialist input. They will also know when to bring in outside help rather than trying to own a workload that slows everything down or creates risk through inaccurate representations.
The right model is a GC who understands the ESG landscape well enough to review and approve, working alongside an ESG consultant who owns the data and documentation.
If you are in a legal role at a PE-backed company and want to talk through how to structure ESG responsibilities internally, get in touch or learn more about fractional ESG support and carbon footprint consulting.
ESG is landing on general counsel's desk more often, and not always through channels that make the scope obvious. A customer contract with new sustainability representations. A GP questionnaire that nobody else picked up. A request to review a European regulation that may or may not apply to the company. An internal policy that needs sign-off before it can go out.