In this article, Dan Harris tests the provisional regulatory response to the risks, particularly bias, presented by ESG ratings providers when they repackage information scraped off the internet and elevate its status into a “score”. He suggests an industry form of comfort letter for incorporation into contracts between ESG ratings providers and investment managers.