Which ESG risks must be disclosed and which stay internal?

QuestionsCategory: ESGWhich ESG risks must be disclosed and which stay internal?
1 Answers
Best Answer
Team GreenSutra Staff answered 17 hours ago
Flat editorial night illustration: A long low threshold ridge crosses a night field. Behind it a sunken pit holds a dense stack of plain unmarked tiles in shadow.

A risk crosses into disclosure when the materiality assessment concludes the topic is material, not when its severity score is high. Material topics are disclosed at topic level, together with policies, actions and targets. Commercially sensitive detail beneath the topic, such as named counterparties, contract values and site level scoring, can stay in the internal register.

Two separate questions get conflated in ESG risk work. The first asks how serious a risk is, which a register answers with severity and likelihood scoring. The second asks whether the topic belongs in a published report, which a disclosure standard answers through materiality. A severe risk on an immaterial topic does not become disclosable by being severe, and a moderate risk on a material topic is disclosable even when the organisation would rather it were not.

Where the threshold sits

Under the ESRS the test is double materiality, and a topic is material where it is significant on either the financial dimension or the impact dimension. The EFRAG implementation guidance puts threshold setting and governance sign off at the close of the assessment. An assessment under the GRI Standards addresses impact materiality only. Either way the assessment sets a threshold, the topic clears it or does not, and the raw register score decides nothing on its own.

Topic level goes out, register level stays in

A material topic is published as a topic, with the policies, actions, targets and metrics the standard names. The evidence beneath it stays internal unless a standard calls for it.

Diagram, Where the ESG disclosure threshold actually sits. Materiality decides, not severity. ESRS: either dimension, GRI: impact only, Threshold signed off. Disclosed: Topic and why material; Policies and actions; Targets and metrics and more.
Where the ESG disclosure threshold actually sits
Register content Disclosed Why
The topic and why it is material Yes The materiality outcome is a required disclosure in itself
Policies, actions, targets and metrics Yes Named by the standard for every material topic
Severity and likelihood scoring Method only Per risk scores are working papers
Named counterparty, site or contract No Commercially sensitive and named by no standard
Live legal or regulatory exposure Topic level The topic is disclosed; case detail follows what the standard names

Deciding a contested item

Three checks settle most arguments over a single register line.

1. Confirm the topic cleared the materiality threshold and that the reason is recorded. 2. Check whether the disclosure standard names the specific datapoint. A named datapoint does not become optional because it is uncomfortable. 3. Where no datapoint is named, publish at topic level and hold the counterparty, contract and site detail in the register where an assurance provider can reach it.

Rating providers read the published set, not the register, and they weight the three pillars differently. One published ESG rating methodology dated May 2026 weights governance highest, at 40 percent against 35 for environmental and 25 for social. Thin governance disclosure therefore costs more than an unpublished register entry ever saves.

Sources: Directive (EU) 2022/2464 (CSRD), GRI Standards

The ESG guide sets out the materiality steps that produce the threshold. ESG solutions covers structuring the evidence behind each material topic so an independent assurance provider can test it.