The U.S. Securities and Exchange Commission (SEC) this year prioritized protecting investors from companies that abuse the name of environmental, social, and governance (ESG) investing to sell products, with one SEC official saying these companies are 'panning for gold in green.'

A recent SEC warning suggests that CFOs of companies committed to sustainable investing should review regulatory risks in the 'green' space.

The SEC's examination division warned this month in a 'risk alert' that some financial firms may mislead investors in their approach to ESG principles, marking an intensification of SEC scrutiny on ESG.

Philip Bezanson, a lawyer at Bracewell LLP, said CFOs can reduce compliance risks and develop ESG disclosure strategies by studying how the SEC constructs cybersecurity disclosure rules and enforcement mechanisms. He believes the SEC is likely to draw from its cybersecurity approach when developing investor protections for ESG disclosures and identifying investigation targets.

Of course, differences between ESG and cybersecurity will lead the SEC to adopt two different approaches. Cybersecurity is relatively straightforward to understand, while ESG lacks global consensus, making SEC regulation, corporate compliance, and standardization of disclosure rules more complex.

Bezanson said in an interview that the definition of ESG 'varies from person to person,' and this ambiguity 'really raises questions about how enforcement will proceed.'

Furthermore, cybersecurity is largely a dry technical challenge, while 'ESG has broad media retail appeal,' Bezanson said. Companies will face pressure to make public statements on ESG, and executives and board members need to choose their words carefully.

Compared to cybersecurity, 'there may be more opportunities to make high-profile statements that could ultimately be deemed misleading by the SEC,' Bezanson said. When developing ESG disclosures, CFOs need to find a balance between caution and transparency.

'The risk with ESG disclosure is that you might expose your shortcomings too much, leading the market to dislike you or you get sued; or you overstate your strengths when you're not actually that good, and the SEC investigates you,' he said.

Suspicion of 'greenwashing'

Companies that fail to deliver on ESG promises may at least be publicly accused of 'greenwashing.'

Bezanson said ESG may also be more politically divisive than cybersecurity. 'We are only beginning to see the ways it could become a politically challenging topic.'

Tensions have already emerged among SEC commissioners. On March 3, the examination division first mentioned climate-related risks in its description of 2021 priorities, with Acting Chair Allison Herren Lee saying the SEC is 'incorporating climate and ESG considerations into the agency's broader regulatory framework.'

Lee (a Democrat) said the SEC will review proxy voting practices 'to ensure that voting aligns with investors' best interests and expectations' and review companies' business continuity plans 'in light of the increasing physical risks posed by climate change.'

The next day, the enforcement division announced the creation of a climate and ESG task force consisting of 22 members from SEC headquarters, including the Office of the Whistleblower, regional offices, and 'specialized units' within the division.

The SEC said in a press release: 'Consistent with investors' increasing focus on and reliance on climate and ESG-related disclosures,' the task force 'will develop initiatives to proactively identify ESG-related misconduct.'

On the same day (March 4), two Republican SEC commissioners issued a statement questioning whether the SEC's recent 'announcements represent a change in current Commission practice, or a continuation of the status quo with new public relations gimmicks? Time will tell.'

Commissioners Hester Peirce and Elad Roisman said: 'We assume the new initiatives are just a continuation of what staff have done for over a decade, rather than evaluating public filers' disclosures under any new standards.'

Partisan divisions

ESG may also become an increasingly partisan issue in Congress. 'I think a lot of ESG-related matters in SEC enforcement will be subject to political influence,' Bezanson said.

Nevertheless, the SEC may handle ESG enforcement in important ways similar to how it handles cybersecurity, he said.

First, as with high-profile cybersecurity cases, the SEC will focus on companies with 'material and misleading statements or omissions' when reviewing ESG disclosures, Bezanson said.

Peirce emphasized this standard in an April 12 statement. 'Companies claiming to do ESG investing need to explain to investors what they mean by ESG, and they need to walk the talk,' she said. 'As with any other investment strategy, advisers and funds should not make statements inconsistent with their practices, and our examiners will focus on consistency between statements and practices.'

Second, as with cybersecurity, the SEC will ensure enforcement for ESG lapses when confident it can win, Bezanson said. 'They want to bring cases they can win.'

Third, as employees, investors, industries, and other stakeholders learn more about ESG investing and reach consensus on common standards in public and private meetings, the SEC will gradually refine its guidance and enforcement.

'This will certainly take a period of preparation,' Bezanson said, giving CFOs time to take steps to prepare for SEC ESG disclosure enforcement, including:

  • DefineWhat ESG means for the company, and share that definition with employees and external stakeholders. 'Managing expectations is a good thing in many different situations, especially when venturing into a fairly new disclosure area,' Bezanson said.

  • EnsureThat company statements and comments are consistent with the company's ESG definition, and prepare for situations where executives may be stumped by questions. CFOs should establish systems and controls that produce 'clear and consistent messaging' in marketing materials, web pages, speeches, slides, and other communications, Bezanson said. They should also be prepared to promptly correct any misstatements.

  • TrackThe evolution of SEC guidance and enforcement on ESG, as well as statements and policies of peer companies. The SEC's 2010 guidance on climate change risk disclosure is a starting point.

CFOs should ask: 'What are others in our industry saying about this risk, and are we saying enough—or are we saying too much?' Bezanson said.

CFOs who closely monitor the SEC's approach are likely to have time to build the right ESG policies and systems.

'I expect enforcement will be incremental,' Bezanson said, similar to the SEC's cautious pace on cybersecurity, 'unless you see truly egregious examples of misleading statements.'