ESG risk is scored on two separate axes: impact severity, decomposed into scale, scope and irremediability, and financial effect, scored on magnitude, with likelihood applied to potential items on both axes. Severity asks how grave, how widespread and how reversible the harm is. Magnitude asks what the effect costs. The two axes are recorded separately, never merged into one figure.
Severity and likelihood are not a single judgement. The ESRS method splits the question into an impact axis and a financial axis, then decomposes each one before any score is recorded.
The components that carry the score

| Axis | Component | Question it settles | What pushes the score up |
|---|---|---|---|
| Impact | Scale | How grave is the harm | Serious harm to health, rights or ecosystems |
| Impact | Scope | How widespread is it | A whole workforce, community or catchment rather than one site |
| Impact | Irremediability | Can the harm be put right | Damage that cannot be reversed or compensated |
| Financial | Magnitude | What is the effect worth | Effect on cash flows, cost of capital or access to finance |
| Both | Likelihood | How probable is it | A recurring operating condition rather than a remote event |
Likelihood attaches to potential items. An actual negative impact that has already occurred is assessed on severity alone, because probability has stopped being a question. Where potential harm falls on people, severity takes precedence over likelihood, so a rare but irreversible human rights impact is not scored down for being unlikely.
Why one blended number destroys the answer
A register that carries a single figure per risk is unusable at the point where it matters, because the figure cannot be acted on. Multiplying severity by likelihood and averaging the axes hides:
- whether a high score came from breadth or from irreversibility, which decide different controls;
- whether the exposure is an impact on people, a financial effect, or both;
- which component moved between assessments, and therefore whether anything improved.
A single comparable number is a rating provider’s product, not an operator’s. One published ESG risk rating methodology deliberately compresses exposure less management into a score on a 0 to 100 scale, banded into five named categories, so that companies in different sectors can be compared. That compression is the point for a reader ranking issuers. It is the opposite of what an internal register needs, which is the component detail that names the control to build.
Sources: ESRS 1, Commission Delegated Regulation (EU) 2023/2772, Published ESG risk rating methodology
The ESG guide sets out the materiality assessment steps that this scoring sits inside, and ESG solutions covers register design and evidence preparation for the assessment. The same ranked exposure areas and named gaps can be produced ahead of the first data collection.
