ESRS S4 Consumers and End-users: The Standard That Audits Your Product Decisions
Of the four ESRS social standards, S4 is the one that sounds easiest. Own workforce is an HR data project. Value-chain workers means supplier audits. Affected communities means the site next to the plant. Consumers and end-users? You already run NPS.
Then you read the text, and S4 turns out to be the standard that asks how your product was designed, how it is marketed, and what you did the last time protecting a user cost you a quarter.
This is a guide to ESRS S4 — Consumers and End-users — as it stands after the 3 July 2026 adoption, and to where the evidence for it actually sits inside a company.
Where the standard stands
On 3 July 2026 the European Commission adopted the delegated acts containing the revised ESRS and the voluntary standard (Linklaters; Cooley). Parliament and Council have a two-month scrutiny period, extendable by two further months, and may reject the acts whole but not amend them. The revised standards apply to financial years beginning on or after 1 January 2027, first reports in 2028, with early application permitted for financial years starting 1 January 2026 (Linklaters).
Mandatory datapoints across the set are down 61% against the 2023 standards, and total datapoints down more than 70%. Why that reduction is a remapping exercise rather than a lighter year is covered in our analysis of the revised datapoint set.
The text below follows the amended S4 draft EFRAG published in November 2025, which is the basis of the adopted act. Confirm final paragraph numbering against the Official Journal text when it publishes.
Who counts, and the line the standard draws
S4 covers consumers and end-users of your products and services, in three sub-topic groups the standard names explicitly:
- Information-related impacts — including privacy, access to information, and freedom of expression.
- Personal safety — including health and safety, protection of children, and security of a person.
- Social inclusion — including access to products and services, responsible marketing practices, and non-discrimination.
Read that list next to your own org chart. Privacy sits with the data protection officer and the platform team. Protection of children sits with product and trust-and-safety. Responsible marketing sits with growth. Access to products and services sits with pricing. Not one of those functions files anything into a sustainability platform today.
The standard also draws a boundary that is worth knowing before an internal argument starts about it: unlawful use or misuse of your products and services by consumers or end-users falls outside the scope. You report on the impacts your product has on the people using it. You do not report on what a bad actor does with it.
Like every topical standard, S4 is conditional. You report against it where consumers and end-users emerge from your double materiality assessment as material — which, for anything sold to the public, they generally do.
Four disclosure requirements
The amended standard runs to four requirements, with the old remedy and grievance-channel material folded into S4-2 — the same consolidation applied across S1, S2 and S3.
| Requirement | What it asks |
|---|---|
| S4-1 | Policies for managing material impacts, risks and opportunities related to consumers and end-users — and whether they cover all users or specific groups, for example particular age groups. |
| S4-2 | How you engage with users or credible proxies, how their perspectives inform your decisions, the channels available for raising concerns, whether a grievance mechanism exists, how you assess whether those channels work, and your approach to remediation. |
| S4-3 | Key actions and resources, the tension disclosure below, and substantiated human rights incidents connected to consumers and end-users. |
| S4-4 | Qualitative and/or quantitative targets. |
S4-2 carries one instruction that quietly widens the work: you must describe how you gain insight into the perspectives of users who may be particularly vulnerable or marginalised — the standard’s own examples are persons with disabilities and children — where you take action to understand those perspectives. An aggregate satisfaction score cannot answer that. It is designed not to.
The clause that changes the conversation
Inside S4-3, alongside the ordinary requirement to describe actions taken to prevent, mitigate and remediate negative impacts, sits this:
including its approach in situations where tensions arise between such actions and other business pressures (for example, practices related to marketing, sales and data use)
The standard names the pressures itself. Marketing. Sales. Data use.
This is not a disclosure about a policy document. It asks what happened when the safeguard and the growth target pointed in different directions — the dark-pattern that lifted conversion, the retention flow that made cancellation hard, the data-sharing that funded the free tier, the age-gate that cost signups. Those decisions were made in product reviews and growth meetings, usually months or years before anyone opened a reporting template, and almost never with a note attached explaining the trade-off.
Reconstructing that history is where most of the S4 effort will actually go. Not writing — archaeology.
The incidents disclosure
For sub-topics assessed as material, and subject to relevant privacy regulation, S4-3 requires disclosure of human rights incidents connected to consumers and end-users identified in the reporting period.
The application requirements define what counts. Incidents in scope are those relating to a failure to respect internationally recognised human rights as defined in CSRD Article 29b(2)(b)(iii), understood as substantiated instances of:
- judicial and non-judicial proceedings that have been initiated — cases before domestic courts and tribunals, mediation, complaints filed with National Contact Points for the OECD Guidelines for Multinational Enterprises; and/or
- incidents registered by the undertaking, including those identified through its own internal processes.
Three practical notes are written into the text. You are not expected to list every incident, and may aggregate — by type of incident, or by the users affected. The materiality filter applied to this information is based primarily on the severity of the impacts on consumers and end-users, not on financial magnitude. And where changes in incidents help explain whether your grievance channels are working, you may cross-reference the two disclosures.
Note what this data is and where it lives. Litigation and regulatory complaints sit with legal. NCP complaints sit with legal or public affairs. Internally registered incidents sit in a trust-and-safety queue, a privacy incident register, or a support system — and only if someone built the register in the first place. None of it flows out of an emissions platform, and the number cannot be estimated: this is a count of substantiated events, not a modelled figure.
The investor plumbing behind it
The reason these two items exist in this shape is visible in the standard’s own footnotes.
The grievance-mechanism disclosure in S4-2 supports SFDR indicator #11 in Table I of Annex I to Commission Delegated Regulation (EU) 2022/1288 — lack of processes and compliance mechanisms to monitor compliance with the UNGPs and OECD Guidelines. The incidents disclosure supports indicator #10 in Table I and indicator #14 in Table III of the same regulation — violations of the UNGPs and OECD Guidelines, and the number of identified cases of severe human rights issues and incidents. It also feeds benchmark administrators under Regulation (EU) 2020/1816, which requires the number of benchmark constituents subject to social violations.
For assessing whether your channels are effective, the standard points at the effectiveness criteria for non-judicial grievance mechanisms in the UN Guiding Principles on Business and Human Rights, Principle 31.
In plain terms: an asset manager holding your equity has a regulatory obligation to report principal adverse impact indicators that your S4 disclosure feeds. This is not a document filed once and forgotten. It is an input into someone else’s mandatory filing, which is exactly the kind of number that gets checked.
What to do before FY2027
Four things, in the order that saves the most time later.
- Find out whether an incident register exists. Not whether you have a policy about incidents — whether a list of substantiated events exists, with dates and outcomes, covering litigation, regulatory complaints, NCP filings and internally identified cases. If it does not, the first reporting year has no baseline. Building the register is a longer job than writing the narrative around it.
- Map the three sub-topics to the functions that own them. Privacy to the DPO. Personal safety and child protection to product and trust-and-safety. Access, pricing and marketing practice to commercial. Each owner needs to know that their decisions are now reportable.
- Start writing down trade-offs as they happen. The S4-3 tension disclosure is nearly impossible to reconstruct after the fact and nearly free to capture at the time — a two-line note in the decision record of a product review costs nothing in the meeting and saves weeks in the reporting cycle.
- Check whether your vulnerable-user engagement is evidenced. If you take action to understand the perspectives of users with disabilities or children, the standard expects you to describe how. Accessibility testing records, advisory panels and consultation notes are the evidence; a satisfaction average is not.
The pattern across S1 through S4 is now consistent, and it is the pattern that catches reporting teams out. The environmental standards ask for measurements. The social standards ask for records — of engagement, of remediation, of incidents. Measurements can be recalculated at year end. Records either exist or they do not.
Our free CSRD readiness check scores your position across seven dimensions in about three minutes, including whether the underlying evidence for the social standards is actually in place. If the gap is in the plumbing rather than the writing, that is what Socious Report was built to close: one dataset, drafted into ESRS, SSBJ and ISSB outputs, with the audit trail attached.