Knowledge & Perspectives

BRSR Core Explained: What the FY 2026-27 Mandate Means for the Full Top 1,000

FY 2026-27 is the year BRSR Core assessment or assurance reaches the full top 1,000 listed companies in India. For companies entering scope for the first time, the data being collected right now will go to a third party. This guide explains what BRSR Core actually requires, what the first three waves of assessment revealed, and what a readiness checklist looks like for a company that has not yet built social governance systems behind its disclosures.
Table of Contents

Regulatory Intelligence

FY 2026-27 has started. For companies in the second half of India’s top 1,000 listed entities, this is not a preparation year. It is the year their BRSR Core data goes to a third party for the first time.

The data being collected right now, on workforce safety, wages, grievances, and supplier relationships, is the data an assessor or assurer will review. If the governance systems that generate that data do not exist, the problem will not be visible at the filing stage. It will be visible when someone external asks to see the evidence behind the numbers.

That is a different kind of pressure from anything these companies have faced under BRSR before.

What BRSR and BRSR Core Actually Are, and Why the Difference Matters

BRSR is India’s mandatory ESG disclosure framework for the top 1,000 listed companies by market capitalisation. Introduced by SEBI and made mandatory from FY 2022-23, it replaced the earlier Business Responsibility Report and requires companies to report against nine principles of the National Guidelines on Responsible Business Conduct. The nine principles cover governance, environmental performance, and a range of social topics from employee welfare and human rights to community impact and consumer responsibility.

BRSR Core is a focused subset within that framework. It pulls out a defined list of Key Performance Indicators across nine ESG attributes that SEBI considers material enough to require independent third-party verification. Those attributes span greenhouse gas emissions, water, energy, waste and circularity, employee wellbeing and safety, gender and inclusion, inclusive development, fairness in customer and supplier relationships, and openness of business.

The practical distinction is this: BRSR captures a company’s stated position on sustainability. BRSR Core captures the specific numbers that must be defensible when a third party tests them.

That shift from self-declared disclosure to evidence-tested data is where most governance gaps become visible for the first time.

Three Things Most Companies Treat as One

BRSR, BRSR Core, and third-party assessment or assurance are three distinct layers. Treating them as the same thing leads to under-investment in the wrong areas and over-confidence in the wrong places.

BRSR is the full template covering all nine NGRBC principles. Broad, narrative and quantitative, it is the annual disclosure that all top 1,000 listed companies file.

BRSR Core is the subset of KPIs within that template which SEBI has identified as high priority for external verification. These are the numbers that trigger a formal assessment or assurance requirement on a phased basis.

Third-party assessment or assurance is the independent review performed on BRSR Core data. It is either a full assurance engagement conducted under recognised assurance standards, or a somewhat lighter assessment under Industry Standards Forum (ISF) standards introduced in December 2024.

Companies that conflate these three layers tend to underestimate the evidence requirements for BRSR Core and over-invest in narrative disclosure that assessors are not actually checking. The companies that distinguish clearly between the three are better positioned to sequence their work and direct governance investment where it actually matters.

The Glide Path, and Where We Stand Today

SEBI’s July 2023 circular established a four-year phased rollout for BRSR Core assessment or assurance:

Financial YearCompanies in scope
FY 2023-24Top 150 listed entities
FY 2024-25Top 250 listed entities
FY 2025-26Top 500 listed entities
FY 2026-27 (current year)Top 1,000 listed entities

(Source: SEBI Circular SEBI/HO/CFD/CFD-SEC-2/P/CIR/2023/122, 12 July 2023)

The top 150, 250, and 500 companies have already been through at least one assessment or assurance cycle. The next 500 companies are entering this regime for the first time in FY 2026-27, which began on 1 April 2026.

Two significant changes were introduced by SEBI’s March 2025 circular. First, the term “assurance” was replaced with “assessment or assurance”, giving companies the choice between a full assurance engagement and the lighter ISF assessment route. Second, BRSR Core value chain disclosures were moved from comply-or-explain to voluntary for the top 250 listed entities, with assessment or assurance of those disclosures also voluntary from FY 2026-27. The threshold for a qualifying value chain partner was revised to entities individually contributing 2% or more of purchases or sales. For most listed entities, this means approximately 0 to 10 qualifying partners rather than the much larger numbers the original 2023 rules implied.

(Source: SEBI Circular SEBI/HO/CFD/CFD-PoD-1/P/CIR/2025/42, 28 March 2025)

What the First Three Waves of Assessment Actually Revealed

KPMG’s February 2026 analysis of 94 NIFTY100 BRSR reports from FY 2024-25 provides the clearest available picture of how the first cohorts of companies performed under BRSR Core assessment or assurance. The findings are directly relevant to companies entering scope for the first time.

45 of 94 companies revised their prior-year BRSR data after ISF standards were published in December 2024. Prior-year data quality was a documented problem, not a theoretical risk. If the underlying governance systems were sound, the ISF standards would not have required revisions.

30 companies took more than 50 days after their financial audit to complete BRSR assurance. The companies that completed fastest, some on the same day as their financial audit, are the ones that had built data governance systems before the assessment cycle began. The ones that took longest were doing a data scramble at year-end.

One construction-sector company received a qualified assurance opinion because it could not provide sufficient evidence for certain BRSR Core disclosures. A qualified opinion is a public disclosure failure. It signals to investors, buyers, and regulators that the company’s BRSR Core data could not be independently verified.

All 94 companies chose reasonable assurance over the lighter ISF assessment route. Despite the option being available, no NIFTY100 company used it. This signals that companies serious about credibility treat assurance as an investment, not a compliance minimum.

(Source: KPMG India, Accounting and Auditing Update, Chapter 1: Emerging Trends in BRSR Reporting, February 2026)

Where the Social Governance Gap Sits Inside BRSR Core

Several BRSR Core attributes are not environmental metrics. They are social governance outputs. And they are the ones most likely to expose a governance gap in mid-sized companies.

The social attributes within BRSR Core include: safety incident rates and fatalities, employee wellbeing benefits and wages, wages paid to women as a proportion of total wages, job creation in smaller towns and underserved areas, grievance and sexual harassment complaint records, and fairness in customer and supplier relationships.

These numbers cannot be reliably generated by an HR team filling out a template at year-end. They require defined KPI ownership, consistent data capture throughout the year, functioning grievance channels with records, escalation processes, and board-level visibility.

When those systems do not exist, one of two things happens. Either the numbers are incomplete and inconsistent, which creates problems at assessment. Or the numbers are filled in retrospectively, which creates a different and more serious problem when an assessor asks to see the underlying evidence.

The most common pattern SVEGA sees in mid-sized companies is a BRSR disclosure that shows workforce safety data, but no incident tracking system behind it. No defined escalation mechanism. No board reporting cadence. The disclosure exists. The governance does not.

10-Point BRSR Core Readiness Checklist

This checklist is written for companies entering BRSR Core assessment or assurance for the first time in FY 2026-27. Work through it against your current position.

1. Named KPI ownership

For each BRSR Core KPI, there is a specific named individual responsible for the data, not just a department or committee.

2. Written metric definitions

Each KPI has a documented definition covering scope, inclusions, exclusions, and calculation method, so data is consistent across locations and financial years.

3. Traceable data sources

Every BRSR Core number can be traced back to a source system, register, or report. Numbers that exist only in a consolidated spreadsheet with no source trail will not hold up under assessment.

4. Incident and grievance infrastructure

Safety incidents and grievances are logged in a structured format with categories, dates, actions taken, and closure status. The log is maintained continuously, not compiled at year-end.

5. Supplier and customer controls

The company has a basic supplier compliance model and clarity on customer fairness policies beyond a signed code of conduct.

6. Evidence packs

For each BRSR Core KPI, there is a retrievable set of documents: registers, calculations, policies, board minutes, and supporting data. An assessor should be able to satisfy a query from a single file pull.

7. Board and committee visibility

Social governance KPIs appear on a board or committee dashboard at least quarterly. Annual visibility at filing time is not governance visibility.

8. Assessment or assurance decision made

The company has decided whether to pursue reasonable assurance or ISF assessment and has identified or engaged an external provider well before year-end. Starting this search in February is too late.

9. Value chain mapping (where relevant)

For companies with material supply chains, there is at least a basic map of significant value chain partners and a plan for responding to buyer questionnaires, even if SEBI’s value chain reporting is now voluntary.

10. Internal dry run completed

At least one internal review or mock assessment has been done on BRSR Core data for a prior period, so issues surface internally rather than during the formal assessment cycle.

If more than three or four of these points are incomplete, the issue is not the BRSR Core template. It is the absence of governance systems that can support the numbers being reported.

What FY 2026-27 Means in Practical Terms

Because the financial year has already started, companies that have not built governance systems yet are not behind on preparation. They are behind on execution. The data that will appear in their first BRSR Core assessment is being collected now, across every month of this financial year.

Trying to rebuild data retrospectively at year-end is one of the primary reasons companies in the first waves took 50-plus days to complete assurance after their financial audit. Building systems mid-year reduces that problem but does not eliminate it.

For companies outside the top 1,000 but inside significant supply chains, the position has changed less than it might appear. SEBI’s value chain voluntary shift reduced direct regulatory pressure. But large EU companies still in scope under the revised CSRD thresholds (1,000 or more employees, EUR 450 million or more net turnover) still cascade ESG questionnaires to their Indian suppliers. The EU Forced Labour Regulation and Deforestation Regulation continue to create near-term due diligence requirements for Indian exporters in targeted sectors. Buyer-side pressure has not softened at the same pace as regulatory pressure.

(Source: EU Directive 2026/470, 26 February 2026; SEBI LODR Master Circular, 30 January 2026)

Frequently Asked Questions about BRSR

What is BRSR Core and how is it different from BRSR?

BRSR is India’s full ESG disclosure framework for the top 1,000 listed companies, covering nine NGRBC principles across environmental, social, and governance topics. BRSR Core is a focused subset of KPIs within BRSR that SEBI has identified as high priority for third-party assessment or assurance. The distinction matters because BRSR is self-declared disclosure while BRSR Core data must be independently verified.

Which companies are required to comply with BRSR Core in FY 2026-27?

All top 1,000 listed companies by market capitalisation are in scope for BRSR Core assessment or assurance in FY 2026-27. This is the final year of the glide path that started with the top 150 companies in FY 2023-24. The relevant financial year began on 1 April 2026. (Source: SEBI Circular, 12 July 2023)

What is the difference between BRSR Core assessment and BRSR Core assurance?

Both are forms of third-party verification of BRSR Core data. Reasonable assurance is the higher standard, requiring audit-style procedures under recognised assurance standards such as ISAE 3000 or ISSA 5000. Assessment is a somewhat lighter option under ISF standards introduced in December 2024. Despite the choice being available, KPMG’s February 2026 analysis found that all 94 NIFTY100 companies subject to the requirement chose reasonable assurance. (Source: SEBI Circular, 28 March 2025; KPMG India, February 2026)

Are BRSR Core value chain disclosures mandatory in FY 2026-27?

No. SEBI’s March 2025 circular moved value chain ESG disclosures to voluntary for the top 250 listed entities, with assessment or assurance of those disclosures also voluntary from FY 2026-27. The threshold for a qualifying value chain partner was revised to 2% or more of individual purchases or sales. For most listed entities this means approximately 0 to 10 qualifying partners. (Source: SEBI Circular, 28 March 2025)

What happens if a company receives a qualified BRSR Core assurance opinion?

A qualified opinion means the assurer could not verify one or more BRSR Core disclosures to the required standard due to insufficient evidence. This becomes part of the company’s public annual report. KPMG’s February 2026 analysis identified one construction-sector NIFTY100 company that received a qualified opinion. The consequences include reduced investor and buyer confidence, regulatory scrutiny, and the cost of remediation before the next assessment cycle. (Source: KPMG India, February 2026)

What does ‘social governance’ have to do with BRSR Core?

Several BRSR Core attributes are social in nature: workforce safety, wages, grievances, gender inclusion, and fairness in supplier and customer relationships. These KPIs cannot be reliably generated by a year-end data collection exercise. They require continuous data capture, defined ownership, functional grievance channels, and board visibility. Companies without social governance systems tend to produce BRSR Core social KPIs that assessors cannot verify against underlying evidence.

How long does BRSR Core assurance typically take?

Based on KPMG’s February 2026 analysis of NIFTY100 companies, 30 out of 94 took more than 50 days after their financial audit to complete BRSR assurance. Companies with strong data governance systems completed it much faster, some on the same day as the financial audit. Engaging your assurance or assessment provider early in the financial year rather than after the financial audit is one of the clearest ways to reduce the timeline. (Source: KPMG India, February 2026)

Picture of Priyanka Bajiraj

Priyanka Bajiraj

Priyanka Bajiraj is a sustainability and social ESG professional with 10 years of experience across sustainability research, social governance advisory, UN exposure, and operational systems thinking.

Through SVEGA, Priyanka focuses on helping organisations move beyond ESG narratives and build practical governance systems that make social responsibility measurable, accountable, and operational.

WHAT'S INCLUDED

Build supplier systems that protect growth and market access.

Regulatory Intelligence

The four labour codes came into force on 21 November 2025, repealing twenty-nine central labour laws, and the final central rules followed on 8 May 2026. For a factory of about a hundred people, several obligations are now settled and headcount-triggered: a new wage definition that lifts provident fund and gratuity costs, appointment letters for every worker, a grievance committee at twenty workers, a works committee at a hundred, and a creche at fifty.

Supplier Accountability

For a growing number of Indian manufacturers and exporters, a SMETA audit has become the compliance test that actually gates the order, ahead of anything SEBI requires. A buyer in Europe or the United States asks for one, and a factory that never had a BRSR obligation suddenly has an auditor at the gate. It matters here for one specific reason: SMETA measures a site against the ETI Base Code as well as Indian law, whichever protects the worker more, so a factory that is fully compliant with the labour codes can still receive findings. This post walks through what the auditor does on the day, and where mid-sized Indian factories most often lose ground.

Social Governance Fundamentals

Most social compliance advice in India is written for the top 1,000 listed companies. The unlisted manufacturers and exporters that carry the bulk of the country’s production sit below the BRSR line but still face buyer audits, the labour codes, and customer questionnaires. This post explains who the missing middle is and what social governance actually means for a company this size.

Governance Architecture

BRSR requires every listed company to disclose grievance mechanisms and resolution data across all nine NGRBC Principles. The Industrial Relations Code, 2020 mandates a Grievance Redressal Committee for any establishment with 20 or more workers. Most companies have the policy document. Very few have a functioning system with documented intake, defined workflows, escalation triggers, and closure records. This post maps the full regulatory requirement, identifies the five failure modes that show up in assessment and audit, provides an eight-step build guide for mid-sized companies, and includes FAQs on contract worker access, zero-grievance red flags, and the distinction between POSH and general grievance mechanisms.

REACH US

If this resonates with the governance challenges you are navigating,

we welcome a focused conversation about where your organisation stands and what building the right systems would look like.