ESG risk assessment or materiality assessment: which comes first?

QuestionsCategory: ESGESG risk assessment or materiality assessment: which comes first?
1 Answers
Best Answer
Team GreenSutra Staff answered 17 hours ago
Flat editorial night illustration: A stepped hillside terrace. On the upper level a faceless figure sets round tokens onto a wide two pan balance.

The materiality assessment comes first: it decides which environmental, social and governance topics are significant enough to enter the ESG risk register, and the register then decides what is done about each one. Materiality sets the scope. The register carries owners, controls and dates. Run in reverse, a register fills with topics nobody tested for significance.

The EFRAG implementation guidance for the ESRS sets out the materiality assessment as a self contained process that ends in a determined list of material topics. Materiality runs first and produces that ranked list. The ESG risk register is what happens to the list afterwards. Merging the two is how a register acquires entries that were never tested for significance, and loses topics that would have cleared the threshold.

Why materiality has to run first

The EFRAG double materiality process runs in six steps: understand the context; identify the actual and potential impacts, risks and opportunities; engage stakeholders; assess significance; set thresholds and determine the material topics; validate through governance sign off and disclose. Step two is where the two exercises are conflated, because it names risks. Identifying a candidate risk is not managing it. Management begins only after step five fixes a threshold and step six records a sign off, because an unstable list cannot carry an owner or a review date.

Diagram, Materiality first, then the register. Materiality runs first (Sets the scope: which topics are significant). The risk register runs second (Sets the action: owners, controls, review dates).
Materiality first, then the register
Dimension Materiality assessment ESG risk register
Purpose Decide which topics are significant Decide what is done about each one
Output A threshold and a ranked list of material topics Owners, controls, mitigations and review dates
Owner Sustainability or reporting function, validated by governance sign off Risk function, one named accountable owner per entry
Refresh Re run when the business model, value chain or regulation moves Reviewed on a standing cycle as controls change

What the first exercise hands to the second

A register is only defensible if it traces back to the assessment that populated it. What transfers:

1. The material topics themselves, and the threshold each one cleared. 2. The significance scores behind them: severity, meaning scale, scope and irremediability, and likelihood on the impact side; magnitude and likelihood on the financial side. 3. The stakeholder evidence gathered from employees, customers, suppliers, communities, investors and regulators. 4. The governance sign off, which is what makes the list traceable rather than an opinion.

One qualification. An organisation that already keeps an enterprise risk register usually starts from it, and that is a legitimate input to step two rather than a substitute for it. An enterprise register is typically built on financial materiality alone, so it stays silent on impact materiality, and under the ESRS significance on either dimension is enough to make a topic material. An assessment under the GRI Standards has the mirror gap, addressing impact materiality only.

Sources: EFRAG ESRS implementation guidance, GRI Standards

ESG solutions runs the materiality scan first and structures the evidence behind each topic that clears the threshold, and the ESG reporting guide sets out the double materiality method step by step. The consultant prepares and structures that evidence; independent accredited third parties assure the resulting data file.