Aller au contenu principal
Accueil / Ressources / ESG in Technology and Communications: What SASB's Software, Hardware, and Telecom Standards Require
Guide

ESG in Technology and Communications: What SASB's Software, Hardware, and Telecom Standards Require

How SASB's five Technology & Communications sector standards — Software & IT Services, Hardware, Semiconductors, Telecommunication Services, and Electronic Manufacturing Services & Original Design Manufacturing — define data privacy, IP protection, conflict-mineral sourcing, workforce diversity, and manufacturing footprint, mapped to Standard ESG subjects S5, G2, G4, S1/S2, E2/E4, and G5.

Mis à jour le 8/18/2026 · 16 min de lecture
Five SASB Technology & Communications standards, five distinct value-chain lenses: data and platforms, chip manufacturing, contract assembly, device lifecycle, and network infrastructure

Why Technology Needs Five Separate Lenses

What Is SASB? explains SASB's general logic of writing one standard per industry rather than one universal ESG questionnaire; the Technology & Communications (TC) sector is one of the clearest illustrations of why that split exists. SASB gives the sector five standards — Software & IT Services (SICS TC-SI), Hardware (TC-HW), Semiconductors (TC-SC), Telecommunication Services (TC-TL), and Electronic Manufacturing Services & Original Design Manufacturing (TC-ES) — each covering a different position in the same value chain: the company that writes the code, the company that designs the device, the company that fabricates the chip inside it, the company that physically assembles it, and the company that carries the traffic once it's in a customer's hands. A generic "tech ESG" questionnaire would either drown a software company in irrelevant manufacturing-emissions questions or let a semiconductor fab skip its water and hazardous-waste exposure entirely; SASB's industry split avoids both failure modes.

The Five SASB Technology Standards at a Glance

Each standard organizes its material risks into a small set of named disclosure topics, each with its own accompanying metrics and metric codes template authors can trace back to the source standard:

  • Software & IT Services — Environmental Footprint of Hardware Infrastructure, Data Privacy & Freedom of Expression, Data Security, Recruiting & Managing a Global, Diverse & Skilled Workforce, Intellectual Property Protection & Competitive Behaviour, Managing Systemic Risks from Technology Disruptions.
  • Hardware — Product Security, Employee Diversity & Inclusion, Product Lifecycle Management, Supply Chain Management, Materials Sourcing.
  • Semiconductors — Greenhouse Gas Emissions, Energy Management in Manufacturing, Water Management, Waste Management, Workforce Health & Safety, Recruiting & Managing a Global & Skilled Workforce, Product Lifecycle Management, Materials Sourcing, Intellectual Property Protection & Competitive Behaviour.
  • Telecommunication Services — Environmental Footprint of Operations, Data Privacy, Data Security, Product End-of-life Management, Competitive Behaviour & Open Internet, Managing Systemic Risks from Technology Disruptions.
  • Electronic Manufacturing Services & Original Design Manufacturing — Water Management, Waste Management, Labour Practices, Workforce Conditions, Health & Safety, Product Lifecycle Management, Materials Sourcing.

No single thread runs through all five — that's the point — but several run through two or three at once: data privacy/security (Software, Telecom), IP protection and competitive behaviour (Software, Semiconductors, Telecom), materials sourcing and supply-chain labour (Hardware, Semiconductors, EMS & ODM), and manufacturing environmental footprint (Semiconductors, EMS & ODM, with a lighter operations-only version in Software and Telecom). The sections below work through each thread in turn.

Data Privacy and Security

Software & IT Services and Telecommunication Services carry near-identical Data Privacy and Data Security topics, reflecting that both sit directly between a consumer and their own personal data. Both require a description of policies and practices relating to targeted advertising and user or customer privacy (TC-SI-220a.1 / TC-TL-220a.1); the number of users or customers whose information is used for secondary purposes (TC-SI-220a.2 / TC-TL-220a.2); total monetary losses from privacy-related legal proceedings (TC-SI-220a.3 / TC-TL-220a.3); and the number of law enforcement requests for user information, the number of users affected, and the percentage resulting in disclosure (TC-SI-220a.4 / TC-TL-220a.4). Data Security adds, for both, the number of data breaches, the percentage that were personal data breaches, the number of users affected, and a description of the entity's approach to identifying and addressing data security risk, including alignment with third-party frameworks like the ISO/IEC 27000 series or NIST's Cybersecurity Framework (TC-SI-230a.1/.2, TC-TL-230a.1/.2). Software carries one metric its telecom counterpart doesn't: a list of countries where the entity's core products or services are subject to government-required monitoring, blocking, or content filtering (TC-SI-220a.5) — the only disclosure topic anywhere in the TC sector that reaches into freedom-of-expression territory rather than data protection alone. Hardware's own privacy exposure is framed narrower and product-centred: Product Security (TC-HW-230a.1) asks only for a description of the entity's approach to identifying and addressing data security risks in its products, not a full privacy-practices disclosure — reflecting that a device maker's exposure runs through what it builds, not what it does with a customer's ongoing data. Semiconductors and EMS & ODM carry no privacy or data-security topic at all: neither sits close enough to an end customer's personal data to make it a material disclosure topic.

Intellectual Property, Competitive Behaviour, and the Open Internet

Software, Semiconductors, and Telecom all carry an Intellectual Property Protection & Competitive Behaviour (or, for Telecom, Competitive Behaviour & Open Internet) topic, each requiring disclosure of total monetary losses from legal proceedings associated with anti-competitive behaviour regulations — price fixing, antitrust behaviour, patent misuse, or network effects (TC-SI-520a.1, TC-SC-520a.1, TC-TL-520a.1). Telecom's version goes considerably further, reflecting the industry's natural-monopoly, last-mile market position: it additionally requires the average actual sustained download speed for owned/commercially-associated content versus non-associated content (TC-TL-520a.2), and a description of the risks and opportunities associated with net neutrality, paid peering, and zero-rating (TC-TL-520a.3) — whether the entity transparently discloses its network policies, whether and when it blocks legal content, and whether it treats affiliated traffic more favourably than everyone else's. No other TC standard carries anything like this open-internet dimension, because no other TC industry sits astride the last mile of infrastructure a customer has no practical way to route around. Hardware and EMS & ODM carry no competitive-behaviour topic at all — neither typically holds the platform-level market power that makes antitrust exposure a material disclosure topic in the way it is for software, chips, and network operators.

Materials Sourcing and Supply Chain Labour

Hardware, Semiconductors, and EMS & ODM each carry a Materials Sourcing topic requiring a description of how the entity manages risks associated with the use of critical materials (TC-HW-440a.1, TC-SC-440a.1, TC-ES-440a.1) — materials the standards define as both essential to production and subject to supply restriction, including antimony, cobalt, gallium, tantalum, and tungsten; platinum group metals; and rare earth elements. Hardware and EMS & ODM extend this into an actual supply-chain audit metric: the percentage of Tier 1 supplier facilities audited under the Responsible Business Alliance's Validated Audit Process (RBA VAP) or an equivalent, split between all facilities and facilities flagged "high-risk" (TC-HW-430a.1, TC-ES-320a.2), plus the resulting non-conformance and corrective-action rates (TC-HW-430a.2, TC-ES-320a.3). The RBA VAP's own definition of a "high-risk" facility is itself worth noting for template authors: it's triggered by a score of 65% or less on at least five sections of the RBA Self-Assessment Questionnaire, or by any of eight disqualifying priority findings — child labour, forced labour, bonded labour, inhumane treatment, imminent health-and-safety issues, imminent environmental issues, falsifying records, or bribery. That list is a direct, checkable operationalization of the same identify-and-remediate logic Human Rights Due Diligence: The UN Guiding Principles Explained covers generically, applied specifically to electronics manufacturing's own highest-risk exposure: the mines and assembly lines several tiers upstream of a finished device. EMS & ODM additionally carries its own standalone Labour Practices topic — the number of work stoppages involving 1,000 or more workers and the total days idle as a result (TC-ES-310a.1) — a classic industrial-relations metric that doesn't appear in any of the sector's other four standards, reflecting EMS & ODM's position as the one TC industry running large-scale, labour-intensive assembly operations directly.

Workforce: Diversity, Recruiting, and Health & Safety

Software and Hardware each require the percentage of gender and diversity-group representation across executive management, non-executive management, technical or professional employees, and all other employees (TC-SI-330a.3, TC-HW-330a.1). Software and Semiconductors both additionally require the percentage of employees that require a work visa, plus a description of the immigration-related risks that creates (TC-SI-330a.1, TC-SC-330a.1) — a direct acknowledgment of how dependent both industries are on globally mobile, specialized technical talent. Software alone adds a third metric its peers don't carry: employee engagement as a percentage, calculated from survey results (TC-SI-330a.2). Semiconductors' version of the topic is narrower than Software's or Hardware's — it stops at the work-visa metric and doesn't carry a parallel gender/diversity-representation requirement. Health and safety exposure runs on an entirely separate axis, carried only by the two industries with real manufacturing-floor risk: Semiconductors requires total monetary losses from legal proceedings tied to employee health and safety violations (TC-SC-320a.2), while EMS & ODM requires the fuller occupational-safety pairing of total recordable incident rate (TRIR) and near-miss frequency rate (NMFR) for both direct and contract employees (TC-ES-320a.1) — the only TC standard that measures near-misses as well as actual incidents, and the only one that explicitly separates direct from contract workforce risk.

Energy, Water, and Manufacturing Footprint

Software, Semiconductors, and Telecom each require total energy consumed, the percentage from grid electricity, and the percentage renewable (TC-SI-130a.1, TC-SC-130a.1, TC-TL-130a.1) — for Software specifically scoped to data-centre infrastructure, for Telecom to network operations. Semiconductors' environmental exposure runs considerably deeper than either: it's the only TC standard carrying a dedicated Greenhouse Gas Emissions topic, requiring gross global Scope 1 emissions with a sub-metric isolating emissions specifically from perfluorinated compounds (TC-SC-110a.1) — a process-chemistry byproduct of chip fabrication with no equivalent anywhere else in the sector — plus a discussion of the entity's emissions-reduction strategy and performance against its own targets (TC-SC-110a.2). Semiconductors and EMS & ODM both carry Water Management (total water withdrawn and consumed, and the percentage of each in High or Extremely High baseline water-stress regions per the World Resources Institute's Aqueduct tool) and Waste Management (hazardous waste generated and the percentage recycled) topics that neither Software, Hardware, nor Telecom carry at all — the clearest single marker of which TC industries actually run water- and chemical-intensive manufacturing floors versus which ones design, sell, or connect the finished product. Hardware itself carries no operational energy, water, or emissions topic; its environmental exposure is channelled entirely through product design instead, consistent with Hardware entities typically outsourcing physical fabrication to EMS & ODM contractors rather than running manufacturing floors themselves.

Product Lifecycle Management and Electronic Waste

Hardware, Semiconductors, Telecom, and EMS & ODM each carry a version of Product Lifecycle Management, though with meaningfully different depth. Hardware's version is the richest in the sector: the percentage of products by revenue containing IEC 62474 declarable substances (TC-HW-410a.1), the percentage of eligible products meeting EPEAT registration or an equivalent environmental-design standard (TC-HW-410a.2), the percentage certified to an energy-efficiency certification (TC-HW-410a.3), and the weight of end-of-life products and e-waste recovered plus the percentage subsequently recycled (TC-HW-410a.4). Semiconductors carries a lighter version of the same declarable-substances metric plus a processor-energy-efficiency metric specific to servers, desktops, and laptops (TC-SC-410a.1/.2), while Telecom's Product End-of-life Management and EMS & ODM's own Product Lifecycle Management topic both stop at the narrower materials-recovery metric: weight of materials recovered through take-back programmes, split by percentage reused, recycled, and landfilled (TC-TL-440a.1, TC-ES-410a.1). Across every version of this topic, e-waste counts as genuinely "recycled" only if the entity can demonstrate it was transferred to a facility with third-party certification to a recognized e-waste standard, such as e-Stewards or the Responsible Recycling (R2) Practices standard — a consistent, checkable bar against greenwashed recycling claims that runs through all four standards identically.

Service Reliability and Systemic Risk

Software and Telecom share a final, narrower topic: Managing Systemic Risks from Technology Disruptions. Software requires the number of performance issues and service disruptions, plus total customer downtime (TC-SI-550a.1), and a discussion of business-continuity risk tied to disruptions of operations (TC-SI-550a.2). Telecom's version is structurally similar but network-specific: system average interruption duration and frequency, and customer average interruption duration (TC-TL-550a.1), plus a discussion of the systems in place to provide unimpeded service during disruptions (TC-TL-550a.2). Both topics exist for the same underlying reason — cloud infrastructure and telecom networks are the two layers other industries' operations now depend on directly, so a disruption at either layer propagates outward in a way a disruption at, say, a single hardware manufacturer's factory typically doesn't.

What's Distinct to Each Standard

Beyond the shared threads above, each standard contributes at least one disclosure topic or metric none of the others do:

  • Software & IT Services — the list of countries where the entity's products are subject to government-required monitoring, blocking, or content filtering (TC-SI-220a.5): the only freedom-of-expression disclosure topic anywhere in the sector.
  • Hardware — the full Product Lifecycle Management cluster (declarable substances, EPEAT registration, energy-efficiency certification, e-waste recovery): the richest environmental product-design topic of the five standards.
  • Semiconductors — Greenhouse Gas Emissions with a perfluorinated-compounds sub-metric (TC-SC-110a.1): a process-chemistry disclosure with no equivalent anywhere else in the sector.
  • Telecommunication Services — the Open Internet topic (net neutrality, paid peering, zero-rating, TC-TL-520a.3): a regulatory-classification disclosure tied directly to telecom's last-mile market position.
  • Electronic Manufacturing Services & Original Design Manufacturing — the Labour Practices topic (work stoppages and days idle, TC-ES-310a.1): a classic industrial-relations metric absent from every other TC standard.

Mapping to Standard ESG Subjects

These five standards' disclosure topics spread across more of Standard ESG's pillars than a single-subject mapping could capture cleanly. Data privacy and security sit inside S5 — Consumer/end-user responsibility, the same industry-dependent subject Consumer and Product Responsibility introduces generically, since both topics are fundamentally about protecting the end user's own data rather than a business-conduct risk toward a counterparty. Intellectual property protection, competitive behaviour, and the open-internet topic map instead to G2 — Ethics, anti-corruption & fair operating practices, alongside Corporate Governance, Ethics and Anti-Corruption's general treatment of fair operating practices. Materials sourcing and the RBA VAP supply-chain audit metrics split across two subjects: the critical-materials-risk disclosure and supplier-audit percentages map to G4 — Sustainable procurement & supply-chain management, while the audit's own priority-finding categories — child labour, forced labour, bonded labour, inhumane treatment — map more precisely to S3 — Human rights & due diligence, since they're a direct, checkable instance of the identify-and-remediate due-diligence cycle. Workforce diversity and recruiting deepen S1 — Labour practices & decent work, while EMS & ODM's TRIR/NMFR and Semiconductors' health-and-safety monetary-loss metric deepen S2 — Occupational health & safety specifically. Energy and water management deepen E2 — Resource use, while product lifecycle and e-waste metrics map more precisely to E4 — Waste, circularity & pollution prevention than to the emissions-focused subjects, since they're measuring material recovery and recyclability rather than GHG output — Semiconductors' own Scope 1/PFC topic is the one metric in this cluster that does deepen E3 — Emissions & climate directly. Finally, the systemic-risk topics map to G5 — Risk management & compliance, covering business-continuity and operational-resilience risk rather than any of the environmental, social, or narrower governance subjects above. This is a broader spread across subjects than the sector's own narrower framing might suggest at first glance — a direct consequence of TC being the SICS sector spanning the widest range of business models, from pure software to heavy chip manufacturing, of any of the eleven.

Which SEIC Sectors This Deepens Coverage For

These five standards carry the most weight for exactly the SEIC groups their SICS codes name directly: software and cloud-service providers (TC-SI), consumer and enterprise device makers (TC-HW), chip designers and fabricators (TC-SC), network operators and internet service providers (TC-TL), and contract electronics manufacturers (TC-ES). A vertically integrated company spanning more than one of these — a device brand that also designs its own silicon, or a fabricator that also does final assembly — should, per SASB's own guidance, consider the disclosure topics of every relevant standard rather than only its primary SICS industry. Outside technology, the materials-sourcing and supply-chain-audit content above has a direct analogue worth cross-referencing in Managing Environmental and Social Risk in High-Impact Industries: The IFC Performance Standards, whose own PS2 covers the same tiered own-operations/contracted/supply-chain labour structure from a project-finance rather than a product-manufacturing angle.

Getting Started

A technology company building out its S5, G2, and G4 evidence base can work through these five standards' shared threads roughly in order of how directly they touch its own business model:

  • Identify which of the five standards actually apply to your business — most companies sit primarily in one, but a vertically integrated company should check every standard relevant to each stage of its value chain.
  • If you handle user or customer data directly, document your data-lifecycle policies and third-party cybersecurity alignment first — this is the single highest-stakes gap for software and telecom companies specifically.
  • If your business involves physical manufacturing or a multi-tier supply chain, inventory your critical-materials exposure and your suppliers' RBA VAP (or equivalent) audit status, including whether any priority findings — child labour, forced labour, bonded labour — have ever been flagged.
  • Review your workforce diversity-representation and recruiting-risk disclosures if your business depends on globally mobile technical talent, and your occupational-safety metrics if you run manufacturing operations directly.
  • Document your energy, water, and (for chip manufacturers specifically) emissions management practices, and your product's end-of-life recovery and recycling pathway, including third-party e-waste certification.

See What Is SASB? for how these standards fit into SASB's broader 77-industry system, and The Standard ESG Certification Protocol: A Public Overview for how industry-dependent subjects fit into the full pillar and subject architecture.

Standard ESG (standardesg.org) draws on SASB's five Technology & Communications sector standards to deepen subjects S5, G2, G4, S1, S2, E2, E4, and G5 for software, hardware, semiconductor, telecom, and contract-manufacturing companies. See The Standard ESG Certification Protocol: A Public Overview for how industry-dependent subjects fit into the full pillar and subject architecture.

Cette page vous a-t-elle été utile ?