An ESG risk register feeds a disclosure through a four stage handoff: a register row becomes a material topic, the material topic becomes a disclosed metric or narrative, and that metric becomes an assured datapoint. The register itself is never published. What reaches the report is the subset that clears the materiality threshold, restated in the language of the reporting standard.
A register is an internal working document that no reporting standard asks for in raw form; published verbatim it would expose unresolved scores. What a standard asks for is the output of the process that built it.
From register row to assured datapoint

| Stage | Artefact | Test before it moves on |
|---|---|---|
| Register row | Description, owner, inherent and residual score, control | Scored and owned, not a placeholder |
| Material topic | A topic clearing the materiality threshold | Significant on impact, on financial effect, or both |
| Disclosed metric or narrative | A figure, or a policy, action or target in prose | Does the standard ask for a number or for prose |
| Assured datapoint | The subset inside the assurance scope | Traceable to a source record by a practitioner |
Rows drop out at every stage, and the attrition is the point. A row that fails the materiality threshold stays in the register and stays managed, but never becomes disclosed copy.
What materiality does to a row
The EFRAG implementation guidance for the ESRS sets out a double materiality assessment combining financial materiality, how an issue affects the organisation, with impact materiality, how the organisation affects people and the environment. A topic is material where it is significant on either dimension. Impacts are scored by severity, itself scale, scope and irremediability, and by likelihood; financial effects by magnitude and likelihood. Thresholds then fix the material set, and both that set and the assessment method are disclosed. An assessment under the GRI Standards addresses impact materiality only, so the two mappings shed different rows.
Each surviving row needs four things recorded before it can carry a disclosed figure:
- the source system or document behind the number, and the person accountable for it;
- the boundary: which sites, entities and value chain segments it covers;
- the method, and any restatement of a prior period;
- whether the datapoint sits inside or outside the assurance scope.
Where the chain ends
The last stage narrows the set again. Under ISAE 3000 (Revised) a limited assurance engagement gathers less evidence and supports a negative form of conclusion, that nothing has come to the practitioner’s attention causing a belief that the information is materially misstated. Less evidence is not no evidence. A figure that cannot be traced back to its register row and its source record still fails.
GreenSutra structures the register, maps rows to topics and readies the data file. Independent accredited third parties provide the assurance.
Sources: EFRAG, ESRS implementation guidance, IAASB, ISAE 3000 (Revised)
The ESG guide sets out materiality and the disclosure sequence, and ESG solutions covers register construction, topic mapping and assurance readiness. Before the register exists, the free ESG risk assessment tool names the areas and the gaps that later become disclosure rows.
