ESG policy for a small business: what it is and what to put in one
In short
An ESG policy is a written statement of how a company handles its environmental impact, its treatment of people, and how decisions get made and checked. Full CSRD reporting duties now apply only above 1,000 employees and EUR 450 million turnover, so a small company that publishes one is doing it because a customer, bank or tender asks, not because the law compels it. Ripe Leads' own ESG-1 statement is one example: self-authored, internally approved, and named here by clause.
On this page
What an ESG policy actually is
An ESG policy is a written statement covering three areas: environmental impact, treatment of people, and how the company governs its own decisions. ESG stands for environmental, social and governance, and the policy is the document that says what the company does in each area, not just that it cares about them.
The environmental part covers things like travel, energy use and equipment. The social part covers how employees, freelance partners and candidates are treated. The governance part covers conflicts of interest, gifts, data protection and who is responsible for reviewing the policy each year.
A company evaluating a supplier for a tender or a contract often asks for this document first, because it is meant to summarise commitments that sit in more detailed policies underneath it. A well-built ESG statement points to those underlying documents rather than repeating them.
For a small company, an ESG policy is often the first governance document that exists at all. It sets out, in one place, what the company will and will not do, and who inside the company is responsible for keeping that true.
Who the law actually requires to have one
The Corporate Sustainability Reporting Directive, Directive (EU) 2022/2464, set out mandatory sustainability reporting duties for larger companies. A 2026 amending law, Directive (EU) 2026/470, adopted 24 February 2026 and published in the Official Journal on 26 February 2026, narrowed that scope substantially. It is adopted, in-force EU law, not a proposal still working through Parliament.
Under the current, post-amendment text, mandatory CSRD reporting applies only to undertakings exceeding both an average of more than 1,000 employees and a net turnover of more than EUR 450,000,000, for financial years starting on or after 1 January 2027. The original 2022 text also covered ordinary large undertakings at a lower threshold and listed small and medium companies; those lower tiers are no longer in scope.
A related law, the Corporate Sustainability Due Diligence Directive (EU) 2024/1760, now applies only above 5,000 employees and EUR 1,500,000,000 turnover, with Member States transposing it by 26 July 2028 and in-scope companies applying it from 26 July 2029. A company of a few people sits far outside both thresholds by any measure.
That does not remove every reason to have a policy. A large customer's own CSRD reporting can still reach into its supply chain asking for information, though the 2026 amendment gives companies under 1,000 employees a statutory right to refuse requests beyond what a voluntary EU standard, VSME, specifies. Banks collect ESG data from borrowers of any size to meet their own separate disclosure obligations, which is a knock-on effect of the bank's duties, not a direct legal duty on the borrower. Neither of these is the same as a small company itself being required by law to publish an ESG policy.
What belongs in an ESG policy
A workable ESG policy states who it applies to and what the company actually does, department by department, rather than a general aspiration. It should name a scope: the director, employees, and any partners working under contract, since a policy that does not say who it binds is hard to hold anyone to.
On the environmental side, expect commitments on how the company travels, what equipment it buys and how it disposes of it, and how it handles paper and printing. On the social side, expect how partners and employees are selected and paid, how conflicts of interest are handled, and a channel for raising a concern. On governance, expect who reviews the policy, how often, and where it gets published.
A useful ESG policy also names the more detailed policies that sit underneath it. A single document cannot carry the full detail of a travel policy, a data protection policy and a whistleblowing procedure at once, so a well-structured statement summarises each and links to the fuller document.
Numbers and deadlines matter more than adjectives. A policy that states a payment term in days, a review date, or a response time for a complaint is easier to check than one that promises to act "promptly" or "responsibly" without saying what that means in practice.
A short document that names real figures is more useful to a reader than a long one built from general language. A tender evaluator or a bank asking for this document is usually looking for specifics they can verify, not a page of intent statements that could apply to almost any company in any sector.
What to check when you are reading someone else's
Look first for a scope clause. If the policy does not say whether it covers employees only, or employees and contractors, or a wider supply chain, it is hard to know what it actually commits the company to in any given situation.
Look for a named reviewer and a review date. A policy with no stated owner and no stated review cycle is often a document that was written once and never revisited, regardless of what it says on the page.
Check whether the document claims any certification, audit or external verification, and if it does, ask for the certificate or the auditor's name. A policy that uses words like "certified" or "verified" without naming who did the certifying or verifying is a document worth double-checking before it goes into a vendor file.
Check the publication date and whether the text reads as if it was actually followed, meaning it names real numbers, real deadlines, real named roles, rather than only general statements that could describe any company.
What Ripe Leads' ESG-1 commits to
Ripe Leads is the trading name of UAB "Kofi Tech." Its ESG statement, document code ESG-1, applies to the director, employees and partners working under contract, and describes a company that "provides business consulting and trains freelance specialists in sales and operations," works remotely, and has no production, warehouses or vehicle fleet.
On the environmental side, ESG-1 commits to no separate office, meetings by video call with travel only at a client's request, and printing "only when a law or an authority requires paper." On the social side, it commits to written bilingual contracts with freelancers stating fee and payment term, paying supplier and partner invoices within 10 days, selecting partners on competence only, and free training for employees and partners under a separate programme, EIP-1.
ESG-1 states zero tolerance for harassment, bullying or violence at work, with the director examining a complaint within 10 working days. It sets a whistleblower channel by email, allows an anonymous report, and commits to no adverse action against a good-faith reporter. On governance, it commits to declaring and paying taxes in Lithuania, disclosing conflicts of interest to the director before a transaction, and neither giving nor accepting a gift or payment meant to influence a business decision.
The director is named as responsible for implementing the statement, reviews it annually by 31 March, and approves any change by order. The statement and its annual review are published at kofitech.eu. The full text sits at the ESG-1 document on the sustainability page, alongside the twelve other policies it cross-references.
Keeping it current
ESG-1 sets its own review cadence: the director reviews it annually, by 31 March, and any change is approved by order rather than by informal edit. That gives the document a fixed point in the calendar where it either gets updated or is confirmed unchanged, rather than sitting untouched indefinitely.
The document is published at kofitech.eu, alongside the other twelve documents in the same set. Publishing it in plain HTML, rather than as a PDF handed out only on request, means the commitments are checkable by anyone who asks, including a customer running vendor due diligence.
The company code, registered address and VAT number named in the document give a reader a way to check the underlying legal entity independently of the policy text itself, through Lithuania's own public company register.
What this document does not prove
ESG-1, and the other twelve documents in the same set, are self-authored and approved internally by UAB "Kofi Tech." They are not audited, certified or verified by any third party, and no sustainability label, badge or score is claimed anywhere in connection with them. From 27 September 2026, the Empowering Consumers Directive, (EU) 2024/825, bans a self-awarded sustainability label outright, which is one more reason these pages carry no badge.
A written commitment is not the same as an independently checked one. A reader who needs third-party assurance, rather than a company's own written word, should ask what independent audit exists, because none is claimed here.
Frequently asked
What is an ESG policy?
Does a small business have to publish an ESG policy by law?
What should an ESG policy for a small company include?
Is Ripe Leads' ESG statement independently certified?
Where can I read Ripe Leads' actual ESG policy?
Want the accounts behind these numbers?
Book a short strategy call. We will show you which employers in your region and role family are hiring right now, and what we would write to them.
Book a strategy call