Person
Person

Jul 30, 2026

ESG Risk Review: 6 Steps for Due Diligence

ESG Strategy

In This Article

A six-step ESG due diligence process to identify, score, and act on material environmental, social, and governance risks.

ESG Risk Review: 6 Steps for Due Diligence

A weak ESG review can change a deal fast. In one KPMG study, 53% of respondents said material ESG findings led to canceled deals, and 42% said findings cut the purchase price.

If I need to explain this article in plain English, I’d put it this way: an ESG risk review helps me spot labor, climate, governance, community, and legal issues before I sign, buy, fund, or approve anything. The six-step process is simple:

  • Set the scope so I know what decision, entities, sites, and time period I’m reviewing

  • Pick the ESG issues that matter most to the sector, footprint, and legal setting

  • Check records and data to see what the company says and what the files show

  • Talk to people and visit sites to test whether day-to-day conditions match the paper record

  • Score and rank risks by impact, likelihood, and control gaps

  • Assign actions with owners, budgets, dates, and follow-up

What matters most is not the checklist. It’s the outcome: a ranked list of risks and a funded action plan that can shape pricing, contract terms, remediation steps, or a go/no-go call.

This article lays out that six-step process in a clear order so I can turn ESG due diligence into a decision tool, not just a filing step.

6-Step ESG Due Diligence Process for Risk Review

6-Step ESG Due Diligence Process for Risk Review

ESG webinar: ESG due diligence

Step 1: Define Scope and Material ESG Risks

Define the scope before you pull documents or line up interviews. A tight scope keeps the review centered on the risks that matter.

Set the Review Boundary and Decision Context

Start by naming the decision this review needs to support - acquisition, project finance, procurement, or partnership. Then spell out what the review must inform: pricing, indemnities, remediation, or a go/no-go call.

Next, define the boundary. List the legal entities, sites, subsidiaries, joint ventures, and value-chain tiers in scope so the work stays tied to the entities and geographies that can shape the decision. Just as important, note what is not in scope and why.

Set the time horizon and the rules that apply. Near-term operating risks are not the same as 5- to 10-year transition risks. In the U.S., reviews should cover SEC climate disclosure, anti-bribery, labor and employment law, and the environmental permits that apply. If the business touches other markets, include foreign human-rights due diligence rules where they fit.

Capture all of this in a one-page memo. It should cover the decision context, boundaries, geography, time horizon, standards, assumptions, and exclusions. Once that scope is locked, the document review can start.

Identify Material Environmental, Social, and Governance Issues

Use the decision context to separate enterprise-value risks from broader impact issues. In this setting, materiality means an ESG issue can affect value, cause harm, or trigger legal or regulatory exposure.

Sector is the fastest first screen. A coastal logistics operator carries higher physical climate risk. A food-processing company has sharp worker health and safety exposure. An apparel brand may face forced-labor risk in its supply chain. SASB's sector-specific materiality maps are a good place to start, but don't stop there. Test those topics against the company's actual footprint - its locations, workforce size, input materials, and regulatory setting. Put the heaviest weight on topics that can shift pricing, timing, liability, or approval.

Use the table below to connect common ESG issues to decision-level risk channels, indicators, and data sources.

Material ESG Issue

Likely Impact Channels

Sample Indicators

Common Data Sources

Climate Exposure

Physical asset damage; transition costs (carbon pricing, fuel switching)

Scope 1, 2, and 3 GHG emissions; location in flood, wildfire, or heat hazard zones

Utility bills, site maps, climate-risk assessments, climate disclosures

Energy Use

Operating costs; regulatory compliance

Energy consumption by source; % renewable

Energy audits, procurement records

Water Stewardship

Operational disruption in water-stressed areas

Water withdrawal and discharge intensity

Facility meters, WRI Aqueduct, local basin risk maps

Pollution and Waste

Cleanup liability; permit violations

Spill history, discharge violations, waste volumes, remediation liabilities

Environmental permits, incident logs, site inspection reports

Labor Practices

Talent retention; legal liability; strikes

Turnover rate; overtime hours; employee complaints

HR records, payroll data, union reports

Worker Health and Safety

Productivity loss; legal exposure

OSHA recordable injury rate; lost-time incidents; training completion

Incident logs, OSHA records, training records

Human Rights

Reputational damage; supply-chain disruption

% of suppliers screened; audit findings; grievance counts

Supplier audits, NGO reports, KnowTheChain benchmarks

Community Impacts

License to operate; project delays

Land-access disputes; indigenous rights concerns; community grievances

Stakeholder engagement records, local government filings

Board Oversight

Governance failure; investor confidence

% of directors independent; ESG committee charter; executive comp linkage to ESG

Proxy statements, board committee charters

Ethics and Anti-Corruption

Fines; debarment; loss of investor trust

Hotline reports; third-party due diligence coverage; disciplinary actions

Compliance audits, whistleblower logs, case files

One practical caution: avoid recency bias. Don't give too much weight to issues making headlines if they are not structurally important for the sector and geography at hand. A topic can be politically visible and still have little bearing on the business under review. The goal is a defensible shortlist, not the longest checklist.

Next, review the documents and performance data that test these assumptions.

Steps 2 and 3: Review Documents and Gather Stakeholder Input

Once you've identified your material ESG issues, the next job is to build the evidence base behind the decision. In practice, that means running two tracks at the same time: a structured document review and direct stakeholder engagement. One without the other leaves blind spots.

Step 2: Review Policies, Records, and Performance Data

The document review sets your baseline. It shows what the company says it will do, what it reports doing, and what the records suggest is happening underneath. Start with the documents tied to the highest-risk issues from Step 1. That usually includes policies, permits, incident logs, audit findings, supplier reports, grievance records, HR and training data, and ESG dashboards.

Look at each record with a simple test in mind: is it current, complete, consistent, and credible? A policy that hasn't changed in years, even though OSHA or SEC requirements have moved on, should put you on alert.

This is where triangulation matters. Don't read records in isolation. Compare them and see whether they line up. If a facility's sustainability report points to a strong safety culture, but training records cover only part of the workforce and incident logs show a rising lost-time injury rate, that's not just messy data. It's a control failure. Every mismatch gives you a clue about where to dig next, who to interview, and what to test during site checks.

Step 3: Interview Stakeholders and Verify Actual Operating Conditions

Use the gaps and contradictions from the document review to shape your interviews. Documents show the paper trail. Interviews and site checks tell you whether that paper trail matches day-to-day conditions.

Your stakeholder outreach should include the people who control the risk, report on it, or live with the outcome: executives, legal and compliance teams, operations and EHS managers, HR, and affected workers or community representatives. The UN Guiding Principles on Business and Human Rights make clear that identifying human-rights risks requires meaningful consultation with potentially affected groups, not just management. The OECD Guidelines for Multinational Enterprises make a similar point, calling for meaningful engagement with relevant stakeholders or their legitimate representatives as part of due diligence.

Good interviews don't just ask people to repeat policy language. They get into execution, exceptions, and ownership. Ask how policies work in practice, which controls break down most often, what was escalated in the last 12 months, and what is still unresolved.

Site visits add something no file or dashboard can give you: direct observation. A visit can confirm whether wastewater treatment systems are operating as documented, whether personal protective equipment is actually being used, or whether subcontractor activity on-site is undisclosed and unmanaged. They're most useful when the risk depends on physical operations, labor conditions, or community-facing effects. Think of a site visit as a spot check, not a full audit. Even so, a well-planned visit to a sample of representative facilities can surface execution problems that might otherwise slip into the scoring stage unnoticed.

The table below shows how each evidence source supports the review.

Evidence Type

Strengths

Limitations

Best-Use Case

Internal Documents

Formal commitments, historical KPIs, permit and audit records

May be aspirational, incomplete, or curated for disclosure

Establishing the baseline "paper" reality and stated goals

External Data

Independent verification via regulatory databases, media reports, court records, or NGO findings

May lack internal context; can be outdated

Identifying enforcement actions or controversies not disclosed internally

Stakeholder Interviews

Reveals culture, implementation gaps, and unreported issues

Subject to bias, coaching, or fear of retaliation

Testing whether staff and communities experience policies as functional

Site Visits

Direct observation of physical conditions and control effectiveness

Resource-intensive; a snapshot that may not reflect normal operations

Verifying high-risk environmental, labor, or community-facing conditions

When documents, interviews, and site observations don't match, treat that conflict as a risk signal. Don't wave it away as a paperwork problem. Work out whether the mismatch comes from timing, poor data quality, or an actual control breakdown. Then ask for supporting records, check outside sources, and carry any unresolved conflicts forward as flagged items into the scoring step. The quality of evidence here will shape how accurate - and how defensible - your risk scores are.

Steps 4 and 5: Score Risks and Rank Priorities

Now comes the part where raw evidence has to become something people can use. You’ve gathered documents, interviews, and site notes. The next job is to turn that mix into scores that different teams can compare, question, and defend. The point is consistency. If the framework is simple and well documented, an investment committee, a procurement team, or an external auditor can follow the logic without having to rebuild the whole review from scratch.

Step 4: Apply Scoring Logic for Impact, Likelihood, and Controls

Use the evidence from Steps 2 and 3 to score each risk the same way across the board. Rate each ESG risk on three dimensions: impact, likelihood, and control effectiveness. Use a 1–5 scale for impact and likelihood. Score control effectiveness on its own so you can calculate residual risk. That turns a pile of evidence into a decision input teams can line up side by side.

Impact is about severity. Likelihood is about the chance the issue will occur within the review horizon, which is often 3–5 years. In U.S.-based reviews, it helps to anchor the low end of impact to exposure below $50,000 and the high end to multi-million-dollar losses, enforcement action, or serious harm to workers or communities. For likelihood, a score of 1 means rare, while 5 means recurring or clearly signaled by trend data.

Multiply impact by likelihood to get inherent risk. Then adjust for control effectiveness to estimate residual risk. Score control effectiveness based on design, implementation, and monitoring. Just as important, write down the evidence behind the score, the assumptions you made, and any weak spots in the data. That makes the scoring auditable and repeatable across assets, suppliers, or acquisition targets.[1][5][6]

Step 5: Rank the Highest-Priority ESG Risks

Once residual risk scores are in place, sort issues by residual risk level and urgency for action. Residual risk shows what exposure is still left. Urgency shows how soon the issue could hit operations, finances, or stakeholders. A risk with a high residual score and a near-term trigger, like a regulatory deadline or active stakeholder pressure, usually needs attention sooner than a large structural risk that may not peak for several years.

Use a heat map for a fast visual read, and use the risk register for the full detail.[1][2][3][10] Here’s what a working register can look like across a set of ESG issues:

Risk Issue

Impact Score (1–5)

Likelihood Score (1–5)

Control Effectiveness (1–5)

Residual Risk Level

Urgency

Key Driver

Water scarcity at plant A

5

4

2

Critical

Near-term (0–2 yrs)

Physical climate risk

Third-party labor practices

4

3

2

High

Near-term (0–2 yrs)

Supply chain governance

Data privacy compliance

3

3

4

Medium

Medium-term (2–5 yrs)

Regulatory complexity

Waste management performance

3

2

3

Low–Medium

Long-term (>5 yrs)

Operational efficiency

The key driver column is where the register starts doing real work. It points to the mitigation lever. If the issue is a supply chain governance gap, the next move may be stronger supplier audits and tighter contract terms. If the issue is physical climate risk at a manufacturing site, the answer may lean more toward infrastructure spending and local stakeholder engagement. That one column helps shift the register from a scoring sheet into a decision tool, showing where budgets and executive attention should go.

Keep the register current as climate data, regulations, or audit findings shift. A static register loses its use fast. Treat it as a live document that feeds capital allocation, procurement decisions, and board-level risk reporting.[4][7][8][9] Use the ranked list to set owners, timelines, and budgets in Step 6.

Step 6: Build Action Plans and Wrap Up

The ranked risk register from Step 5 matters only if it leads to action. Step 6 turns that list into a formal ESG action plan: clear steps, measurable targets, and set deadlines that leaders can fund and track. Before anything moves, each item needs a named owner.

Assign Owners, Timelines, and Budgets to Top Risks

Start with the highest-priority residual-risk items and write one clear action for each. A solid action plan should spell out the risk, action, owner, due date, budget, KPI, and tracking method. Give each action to the person or team that controls the system or decision tied to that risk. They should also have budget authority, or at least a clear path to escalate if they don’t.

Be specific. Use fixed dates. Match the budget to the work. Then add a buffer for surprises and the cost of continued monitoring. A top ESG risk should move through three stages:

  • assessment

  • remediation

  • verification

Each stage should have an owner, a deadline, a budget, and a clear check for completion. That’s what turns a risk review from a spreadsheet exercise into something people can manage.

Once those fields are in place, move the plan into governance. Put material actions into board approvals, loan covenants, or contract terms. In transactions, high-priority actions may become closing conditions or post-close covenants. Track progress monthly at the task level, quarterly at the executive level, and semiannually at the board level with simple status labels: On Track, At Risk, or Off Track.

Conclusion: The Six-Step ESG Due Diligence Process at a Glance

With actions assigned and tracked, the review is ready to close. The flow is straightforward: define scope, review evidence, gather input, score, rank, and act. The point is not the register itself. The point is the funded plan that shapes decisions, whether that means approving a transaction, putting conditions on a deal, shifting capital, or renegotiating contract terms.

Teams that treat the action plan as the main output are the ones that reduce exposure over time.

For teams that need implementation support, Council Fire helps turn ESG findings into action.

FAQs

How long should an ESG risk review take?

An ESG risk review isn’t a one-time project. It’s an ongoing process that teams revisit, refine, and repeat over time. The pace depends on the size of the organization, how ready the data is, and how much complexity sits across the business.

As a general guide, supply chain due diligence may run on a 12-month cycle. Climate risk assessments often take 3 to 6 months for the first round. Double materiality assessments usually span 10 to 16 weeks.

That initial work is only part of the picture. Regular monitoring, annual updates, and periodic reassessments are all part of keeping the review current and useful as conditions shift.

Who should be involved in the ESG due diligence process?

An effective ESG due diligence process works best when it pulls in people from across the business. Inside the company, that means involving the ESG or sustainability team along with finance, risk management, legal, compliance, HR, and operations. Each group sees a different part of the picture, and that matters when you're trying to spot issues early and judge them clearly.

Outside the company, the circle should be just as broad. Bring in employees, suppliers, customers, local communities, and people who rely on sustainability information, including investors, lenders, and regulators. External consultants can add rigor and an outside view, but senior leadership still needs to stay visibly involved. If leaders step back, the process can start to feel like a box-checking exercise instead of a serious business review.

What should I do if ESG findings reveal major gaps before a deal closes?

If ESG due diligence surfaces major gaps before a deal closes, the next step is active risk management. Spotting the problem isn’t enough. You need to record the issues, show what action was taken, and track the result.

Put corrective action plans in place with clear timelines and named steps. When the problem is serious, that may mean contract terms, sourcing changes, or, if there’s no workable path forward, responsible disengagement. Keep thorough records throughout the process so your response is well supported and in line with regulatory expectations.

Related Blog Posts

FAQ

01

What does it really mean to “redefine profit”?

02

What makes Council Fire different?

03

Who does Council Fire work with?

04

What does working with Council Fire actually look like?

05

How does Council Fire help organizations turn big goals into action?

06

How does Council Fire define and measure success?

Person
Person

Jul 30, 2026

ESG Risk Review: 6 Steps for Due Diligence

ESG Strategy

In This Article

A six-step ESG due diligence process to identify, score, and act on material environmental, social, and governance risks.

ESG Risk Review: 6 Steps for Due Diligence

A weak ESG review can change a deal fast. In one KPMG study, 53% of respondents said material ESG findings led to canceled deals, and 42% said findings cut the purchase price.

If I need to explain this article in plain English, I’d put it this way: an ESG risk review helps me spot labor, climate, governance, community, and legal issues before I sign, buy, fund, or approve anything. The six-step process is simple:

  • Set the scope so I know what decision, entities, sites, and time period I’m reviewing

  • Pick the ESG issues that matter most to the sector, footprint, and legal setting

  • Check records and data to see what the company says and what the files show

  • Talk to people and visit sites to test whether day-to-day conditions match the paper record

  • Score and rank risks by impact, likelihood, and control gaps

  • Assign actions with owners, budgets, dates, and follow-up

What matters most is not the checklist. It’s the outcome: a ranked list of risks and a funded action plan that can shape pricing, contract terms, remediation steps, or a go/no-go call.

This article lays out that six-step process in a clear order so I can turn ESG due diligence into a decision tool, not just a filing step.

6-Step ESG Due Diligence Process for Risk Review

6-Step ESG Due Diligence Process for Risk Review

ESG webinar: ESG due diligence

Step 1: Define Scope and Material ESG Risks

Define the scope before you pull documents or line up interviews. A tight scope keeps the review centered on the risks that matter.

Set the Review Boundary and Decision Context

Start by naming the decision this review needs to support - acquisition, project finance, procurement, or partnership. Then spell out what the review must inform: pricing, indemnities, remediation, or a go/no-go call.

Next, define the boundary. List the legal entities, sites, subsidiaries, joint ventures, and value-chain tiers in scope so the work stays tied to the entities and geographies that can shape the decision. Just as important, note what is not in scope and why.

Set the time horizon and the rules that apply. Near-term operating risks are not the same as 5- to 10-year transition risks. In the U.S., reviews should cover SEC climate disclosure, anti-bribery, labor and employment law, and the environmental permits that apply. If the business touches other markets, include foreign human-rights due diligence rules where they fit.

Capture all of this in a one-page memo. It should cover the decision context, boundaries, geography, time horizon, standards, assumptions, and exclusions. Once that scope is locked, the document review can start.

Identify Material Environmental, Social, and Governance Issues

Use the decision context to separate enterprise-value risks from broader impact issues. In this setting, materiality means an ESG issue can affect value, cause harm, or trigger legal or regulatory exposure.

Sector is the fastest first screen. A coastal logistics operator carries higher physical climate risk. A food-processing company has sharp worker health and safety exposure. An apparel brand may face forced-labor risk in its supply chain. SASB's sector-specific materiality maps are a good place to start, but don't stop there. Test those topics against the company's actual footprint - its locations, workforce size, input materials, and regulatory setting. Put the heaviest weight on topics that can shift pricing, timing, liability, or approval.

Use the table below to connect common ESG issues to decision-level risk channels, indicators, and data sources.

Material ESG Issue

Likely Impact Channels

Sample Indicators

Common Data Sources

Climate Exposure

Physical asset damage; transition costs (carbon pricing, fuel switching)

Scope 1, 2, and 3 GHG emissions; location in flood, wildfire, or heat hazard zones

Utility bills, site maps, climate-risk assessments, climate disclosures

Energy Use

Operating costs; regulatory compliance

Energy consumption by source; % renewable

Energy audits, procurement records

Water Stewardship

Operational disruption in water-stressed areas

Water withdrawal and discharge intensity

Facility meters, WRI Aqueduct, local basin risk maps

Pollution and Waste

Cleanup liability; permit violations

Spill history, discharge violations, waste volumes, remediation liabilities

Environmental permits, incident logs, site inspection reports

Labor Practices

Talent retention; legal liability; strikes

Turnover rate; overtime hours; employee complaints

HR records, payroll data, union reports

Worker Health and Safety

Productivity loss; legal exposure

OSHA recordable injury rate; lost-time incidents; training completion

Incident logs, OSHA records, training records

Human Rights

Reputational damage; supply-chain disruption

% of suppliers screened; audit findings; grievance counts

Supplier audits, NGO reports, KnowTheChain benchmarks

Community Impacts

License to operate; project delays

Land-access disputes; indigenous rights concerns; community grievances

Stakeholder engagement records, local government filings

Board Oversight

Governance failure; investor confidence

% of directors independent; ESG committee charter; executive comp linkage to ESG

Proxy statements, board committee charters

Ethics and Anti-Corruption

Fines; debarment; loss of investor trust

Hotline reports; third-party due diligence coverage; disciplinary actions

Compliance audits, whistleblower logs, case files

One practical caution: avoid recency bias. Don't give too much weight to issues making headlines if they are not structurally important for the sector and geography at hand. A topic can be politically visible and still have little bearing on the business under review. The goal is a defensible shortlist, not the longest checklist.

Next, review the documents and performance data that test these assumptions.

Steps 2 and 3: Review Documents and Gather Stakeholder Input

Once you've identified your material ESG issues, the next job is to build the evidence base behind the decision. In practice, that means running two tracks at the same time: a structured document review and direct stakeholder engagement. One without the other leaves blind spots.

Step 2: Review Policies, Records, and Performance Data

The document review sets your baseline. It shows what the company says it will do, what it reports doing, and what the records suggest is happening underneath. Start with the documents tied to the highest-risk issues from Step 1. That usually includes policies, permits, incident logs, audit findings, supplier reports, grievance records, HR and training data, and ESG dashboards.

Look at each record with a simple test in mind: is it current, complete, consistent, and credible? A policy that hasn't changed in years, even though OSHA or SEC requirements have moved on, should put you on alert.

This is where triangulation matters. Don't read records in isolation. Compare them and see whether they line up. If a facility's sustainability report points to a strong safety culture, but training records cover only part of the workforce and incident logs show a rising lost-time injury rate, that's not just messy data. It's a control failure. Every mismatch gives you a clue about where to dig next, who to interview, and what to test during site checks.

Step 3: Interview Stakeholders and Verify Actual Operating Conditions

Use the gaps and contradictions from the document review to shape your interviews. Documents show the paper trail. Interviews and site checks tell you whether that paper trail matches day-to-day conditions.

Your stakeholder outreach should include the people who control the risk, report on it, or live with the outcome: executives, legal and compliance teams, operations and EHS managers, HR, and affected workers or community representatives. The UN Guiding Principles on Business and Human Rights make clear that identifying human-rights risks requires meaningful consultation with potentially affected groups, not just management. The OECD Guidelines for Multinational Enterprises make a similar point, calling for meaningful engagement with relevant stakeholders or their legitimate representatives as part of due diligence.

Good interviews don't just ask people to repeat policy language. They get into execution, exceptions, and ownership. Ask how policies work in practice, which controls break down most often, what was escalated in the last 12 months, and what is still unresolved.

Site visits add something no file or dashboard can give you: direct observation. A visit can confirm whether wastewater treatment systems are operating as documented, whether personal protective equipment is actually being used, or whether subcontractor activity on-site is undisclosed and unmanaged. They're most useful when the risk depends on physical operations, labor conditions, or community-facing effects. Think of a site visit as a spot check, not a full audit. Even so, a well-planned visit to a sample of representative facilities can surface execution problems that might otherwise slip into the scoring stage unnoticed.

The table below shows how each evidence source supports the review.

Evidence Type

Strengths

Limitations

Best-Use Case

Internal Documents

Formal commitments, historical KPIs, permit and audit records

May be aspirational, incomplete, or curated for disclosure

Establishing the baseline "paper" reality and stated goals

External Data

Independent verification via regulatory databases, media reports, court records, or NGO findings

May lack internal context; can be outdated

Identifying enforcement actions or controversies not disclosed internally

Stakeholder Interviews

Reveals culture, implementation gaps, and unreported issues

Subject to bias, coaching, or fear of retaliation

Testing whether staff and communities experience policies as functional

Site Visits

Direct observation of physical conditions and control effectiveness

Resource-intensive; a snapshot that may not reflect normal operations

Verifying high-risk environmental, labor, or community-facing conditions

When documents, interviews, and site observations don't match, treat that conflict as a risk signal. Don't wave it away as a paperwork problem. Work out whether the mismatch comes from timing, poor data quality, or an actual control breakdown. Then ask for supporting records, check outside sources, and carry any unresolved conflicts forward as flagged items into the scoring step. The quality of evidence here will shape how accurate - and how defensible - your risk scores are.

Steps 4 and 5: Score Risks and Rank Priorities

Now comes the part where raw evidence has to become something people can use. You’ve gathered documents, interviews, and site notes. The next job is to turn that mix into scores that different teams can compare, question, and defend. The point is consistency. If the framework is simple and well documented, an investment committee, a procurement team, or an external auditor can follow the logic without having to rebuild the whole review from scratch.

Step 4: Apply Scoring Logic for Impact, Likelihood, and Controls

Use the evidence from Steps 2 and 3 to score each risk the same way across the board. Rate each ESG risk on three dimensions: impact, likelihood, and control effectiveness. Use a 1–5 scale for impact and likelihood. Score control effectiveness on its own so you can calculate residual risk. That turns a pile of evidence into a decision input teams can line up side by side.

Impact is about severity. Likelihood is about the chance the issue will occur within the review horizon, which is often 3–5 years. In U.S.-based reviews, it helps to anchor the low end of impact to exposure below $50,000 and the high end to multi-million-dollar losses, enforcement action, or serious harm to workers or communities. For likelihood, a score of 1 means rare, while 5 means recurring or clearly signaled by trend data.

Multiply impact by likelihood to get inherent risk. Then adjust for control effectiveness to estimate residual risk. Score control effectiveness based on design, implementation, and monitoring. Just as important, write down the evidence behind the score, the assumptions you made, and any weak spots in the data. That makes the scoring auditable and repeatable across assets, suppliers, or acquisition targets.[1][5][6]

Step 5: Rank the Highest-Priority ESG Risks

Once residual risk scores are in place, sort issues by residual risk level and urgency for action. Residual risk shows what exposure is still left. Urgency shows how soon the issue could hit operations, finances, or stakeholders. A risk with a high residual score and a near-term trigger, like a regulatory deadline or active stakeholder pressure, usually needs attention sooner than a large structural risk that may not peak for several years.

Use a heat map for a fast visual read, and use the risk register for the full detail.[1][2][3][10] Here’s what a working register can look like across a set of ESG issues:

Risk Issue

Impact Score (1–5)

Likelihood Score (1–5)

Control Effectiveness (1–5)

Residual Risk Level

Urgency

Key Driver

Water scarcity at plant A

5

4

2

Critical

Near-term (0–2 yrs)

Physical climate risk

Third-party labor practices

4

3

2

High

Near-term (0–2 yrs)

Supply chain governance

Data privacy compliance

3

3

4

Medium

Medium-term (2–5 yrs)

Regulatory complexity

Waste management performance

3

2

3

Low–Medium

Long-term (>5 yrs)

Operational efficiency

The key driver column is where the register starts doing real work. It points to the mitigation lever. If the issue is a supply chain governance gap, the next move may be stronger supplier audits and tighter contract terms. If the issue is physical climate risk at a manufacturing site, the answer may lean more toward infrastructure spending and local stakeholder engagement. That one column helps shift the register from a scoring sheet into a decision tool, showing where budgets and executive attention should go.

Keep the register current as climate data, regulations, or audit findings shift. A static register loses its use fast. Treat it as a live document that feeds capital allocation, procurement decisions, and board-level risk reporting.[4][7][8][9] Use the ranked list to set owners, timelines, and budgets in Step 6.

Step 6: Build Action Plans and Wrap Up

The ranked risk register from Step 5 matters only if it leads to action. Step 6 turns that list into a formal ESG action plan: clear steps, measurable targets, and set deadlines that leaders can fund and track. Before anything moves, each item needs a named owner.

Assign Owners, Timelines, and Budgets to Top Risks

Start with the highest-priority residual-risk items and write one clear action for each. A solid action plan should spell out the risk, action, owner, due date, budget, KPI, and tracking method. Give each action to the person or team that controls the system or decision tied to that risk. They should also have budget authority, or at least a clear path to escalate if they don’t.

Be specific. Use fixed dates. Match the budget to the work. Then add a buffer for surprises and the cost of continued monitoring. A top ESG risk should move through three stages:

  • assessment

  • remediation

  • verification

Each stage should have an owner, a deadline, a budget, and a clear check for completion. That’s what turns a risk review from a spreadsheet exercise into something people can manage.

Once those fields are in place, move the plan into governance. Put material actions into board approvals, loan covenants, or contract terms. In transactions, high-priority actions may become closing conditions or post-close covenants. Track progress monthly at the task level, quarterly at the executive level, and semiannually at the board level with simple status labels: On Track, At Risk, or Off Track.

Conclusion: The Six-Step ESG Due Diligence Process at a Glance

With actions assigned and tracked, the review is ready to close. The flow is straightforward: define scope, review evidence, gather input, score, rank, and act. The point is not the register itself. The point is the funded plan that shapes decisions, whether that means approving a transaction, putting conditions on a deal, shifting capital, or renegotiating contract terms.

Teams that treat the action plan as the main output are the ones that reduce exposure over time.

For teams that need implementation support, Council Fire helps turn ESG findings into action.

FAQs

How long should an ESG risk review take?

An ESG risk review isn’t a one-time project. It’s an ongoing process that teams revisit, refine, and repeat over time. The pace depends on the size of the organization, how ready the data is, and how much complexity sits across the business.

As a general guide, supply chain due diligence may run on a 12-month cycle. Climate risk assessments often take 3 to 6 months for the first round. Double materiality assessments usually span 10 to 16 weeks.

That initial work is only part of the picture. Regular monitoring, annual updates, and periodic reassessments are all part of keeping the review current and useful as conditions shift.

Who should be involved in the ESG due diligence process?

An effective ESG due diligence process works best when it pulls in people from across the business. Inside the company, that means involving the ESG or sustainability team along with finance, risk management, legal, compliance, HR, and operations. Each group sees a different part of the picture, and that matters when you're trying to spot issues early and judge them clearly.

Outside the company, the circle should be just as broad. Bring in employees, suppliers, customers, local communities, and people who rely on sustainability information, including investors, lenders, and regulators. External consultants can add rigor and an outside view, but senior leadership still needs to stay visibly involved. If leaders step back, the process can start to feel like a box-checking exercise instead of a serious business review.

What should I do if ESG findings reveal major gaps before a deal closes?

If ESG due diligence surfaces major gaps before a deal closes, the next step is active risk management. Spotting the problem isn’t enough. You need to record the issues, show what action was taken, and track the result.

Put corrective action plans in place with clear timelines and named steps. When the problem is serious, that may mean contract terms, sourcing changes, or, if there’s no workable path forward, responsible disengagement. Keep thorough records throughout the process so your response is well supported and in line with regulatory expectations.

Related Blog Posts

FAQ

01

What does it really mean to “redefine profit”?

02

What makes Council Fire different?

03

Who does Council Fire work with?

04

What does working with Council Fire actually look like?

05

How does Council Fire help organizations turn big goals into action?

06

How does Council Fire define and measure success?

Person
Person

Jul 30, 2026

ESG Risk Review: 6 Steps for Due Diligence

ESG Strategy

In This Article

A six-step ESG due diligence process to identify, score, and act on material environmental, social, and governance risks.

ESG Risk Review: 6 Steps for Due Diligence

A weak ESG review can change a deal fast. In one KPMG study, 53% of respondents said material ESG findings led to canceled deals, and 42% said findings cut the purchase price.

If I need to explain this article in plain English, I’d put it this way: an ESG risk review helps me spot labor, climate, governance, community, and legal issues before I sign, buy, fund, or approve anything. The six-step process is simple:

  • Set the scope so I know what decision, entities, sites, and time period I’m reviewing

  • Pick the ESG issues that matter most to the sector, footprint, and legal setting

  • Check records and data to see what the company says and what the files show

  • Talk to people and visit sites to test whether day-to-day conditions match the paper record

  • Score and rank risks by impact, likelihood, and control gaps

  • Assign actions with owners, budgets, dates, and follow-up

What matters most is not the checklist. It’s the outcome: a ranked list of risks and a funded action plan that can shape pricing, contract terms, remediation steps, or a go/no-go call.

This article lays out that six-step process in a clear order so I can turn ESG due diligence into a decision tool, not just a filing step.

6-Step ESG Due Diligence Process for Risk Review

6-Step ESG Due Diligence Process for Risk Review

ESG webinar: ESG due diligence

Step 1: Define Scope and Material ESG Risks

Define the scope before you pull documents or line up interviews. A tight scope keeps the review centered on the risks that matter.

Set the Review Boundary and Decision Context

Start by naming the decision this review needs to support - acquisition, project finance, procurement, or partnership. Then spell out what the review must inform: pricing, indemnities, remediation, or a go/no-go call.

Next, define the boundary. List the legal entities, sites, subsidiaries, joint ventures, and value-chain tiers in scope so the work stays tied to the entities and geographies that can shape the decision. Just as important, note what is not in scope and why.

Set the time horizon and the rules that apply. Near-term operating risks are not the same as 5- to 10-year transition risks. In the U.S., reviews should cover SEC climate disclosure, anti-bribery, labor and employment law, and the environmental permits that apply. If the business touches other markets, include foreign human-rights due diligence rules where they fit.

Capture all of this in a one-page memo. It should cover the decision context, boundaries, geography, time horizon, standards, assumptions, and exclusions. Once that scope is locked, the document review can start.

Identify Material Environmental, Social, and Governance Issues

Use the decision context to separate enterprise-value risks from broader impact issues. In this setting, materiality means an ESG issue can affect value, cause harm, or trigger legal or regulatory exposure.

Sector is the fastest first screen. A coastal logistics operator carries higher physical climate risk. A food-processing company has sharp worker health and safety exposure. An apparel brand may face forced-labor risk in its supply chain. SASB's sector-specific materiality maps are a good place to start, but don't stop there. Test those topics against the company's actual footprint - its locations, workforce size, input materials, and regulatory setting. Put the heaviest weight on topics that can shift pricing, timing, liability, or approval.

Use the table below to connect common ESG issues to decision-level risk channels, indicators, and data sources.

Material ESG Issue

Likely Impact Channels

Sample Indicators

Common Data Sources

Climate Exposure

Physical asset damage; transition costs (carbon pricing, fuel switching)

Scope 1, 2, and 3 GHG emissions; location in flood, wildfire, or heat hazard zones

Utility bills, site maps, climate-risk assessments, climate disclosures

Energy Use

Operating costs; regulatory compliance

Energy consumption by source; % renewable

Energy audits, procurement records

Water Stewardship

Operational disruption in water-stressed areas

Water withdrawal and discharge intensity

Facility meters, WRI Aqueduct, local basin risk maps

Pollution and Waste

Cleanup liability; permit violations

Spill history, discharge violations, waste volumes, remediation liabilities

Environmental permits, incident logs, site inspection reports

Labor Practices

Talent retention; legal liability; strikes

Turnover rate; overtime hours; employee complaints

HR records, payroll data, union reports

Worker Health and Safety

Productivity loss; legal exposure

OSHA recordable injury rate; lost-time incidents; training completion

Incident logs, OSHA records, training records

Human Rights

Reputational damage; supply-chain disruption

% of suppliers screened; audit findings; grievance counts

Supplier audits, NGO reports, KnowTheChain benchmarks

Community Impacts

License to operate; project delays

Land-access disputes; indigenous rights concerns; community grievances

Stakeholder engagement records, local government filings

Board Oversight

Governance failure; investor confidence

% of directors independent; ESG committee charter; executive comp linkage to ESG

Proxy statements, board committee charters

Ethics and Anti-Corruption

Fines; debarment; loss of investor trust

Hotline reports; third-party due diligence coverage; disciplinary actions

Compliance audits, whistleblower logs, case files

One practical caution: avoid recency bias. Don't give too much weight to issues making headlines if they are not structurally important for the sector and geography at hand. A topic can be politically visible and still have little bearing on the business under review. The goal is a defensible shortlist, not the longest checklist.

Next, review the documents and performance data that test these assumptions.

Steps 2 and 3: Review Documents and Gather Stakeholder Input

Once you've identified your material ESG issues, the next job is to build the evidence base behind the decision. In practice, that means running two tracks at the same time: a structured document review and direct stakeholder engagement. One without the other leaves blind spots.

Step 2: Review Policies, Records, and Performance Data

The document review sets your baseline. It shows what the company says it will do, what it reports doing, and what the records suggest is happening underneath. Start with the documents tied to the highest-risk issues from Step 1. That usually includes policies, permits, incident logs, audit findings, supplier reports, grievance records, HR and training data, and ESG dashboards.

Look at each record with a simple test in mind: is it current, complete, consistent, and credible? A policy that hasn't changed in years, even though OSHA or SEC requirements have moved on, should put you on alert.

This is where triangulation matters. Don't read records in isolation. Compare them and see whether they line up. If a facility's sustainability report points to a strong safety culture, but training records cover only part of the workforce and incident logs show a rising lost-time injury rate, that's not just messy data. It's a control failure. Every mismatch gives you a clue about where to dig next, who to interview, and what to test during site checks.

Step 3: Interview Stakeholders and Verify Actual Operating Conditions

Use the gaps and contradictions from the document review to shape your interviews. Documents show the paper trail. Interviews and site checks tell you whether that paper trail matches day-to-day conditions.

Your stakeholder outreach should include the people who control the risk, report on it, or live with the outcome: executives, legal and compliance teams, operations and EHS managers, HR, and affected workers or community representatives. The UN Guiding Principles on Business and Human Rights make clear that identifying human-rights risks requires meaningful consultation with potentially affected groups, not just management. The OECD Guidelines for Multinational Enterprises make a similar point, calling for meaningful engagement with relevant stakeholders or their legitimate representatives as part of due diligence.

Good interviews don't just ask people to repeat policy language. They get into execution, exceptions, and ownership. Ask how policies work in practice, which controls break down most often, what was escalated in the last 12 months, and what is still unresolved.

Site visits add something no file or dashboard can give you: direct observation. A visit can confirm whether wastewater treatment systems are operating as documented, whether personal protective equipment is actually being used, or whether subcontractor activity on-site is undisclosed and unmanaged. They're most useful when the risk depends on physical operations, labor conditions, or community-facing effects. Think of a site visit as a spot check, not a full audit. Even so, a well-planned visit to a sample of representative facilities can surface execution problems that might otherwise slip into the scoring stage unnoticed.

The table below shows how each evidence source supports the review.

Evidence Type

Strengths

Limitations

Best-Use Case

Internal Documents

Formal commitments, historical KPIs, permit and audit records

May be aspirational, incomplete, or curated for disclosure

Establishing the baseline "paper" reality and stated goals

External Data

Independent verification via regulatory databases, media reports, court records, or NGO findings

May lack internal context; can be outdated

Identifying enforcement actions or controversies not disclosed internally

Stakeholder Interviews

Reveals culture, implementation gaps, and unreported issues

Subject to bias, coaching, or fear of retaliation

Testing whether staff and communities experience policies as functional

Site Visits

Direct observation of physical conditions and control effectiveness

Resource-intensive; a snapshot that may not reflect normal operations

Verifying high-risk environmental, labor, or community-facing conditions

When documents, interviews, and site observations don't match, treat that conflict as a risk signal. Don't wave it away as a paperwork problem. Work out whether the mismatch comes from timing, poor data quality, or an actual control breakdown. Then ask for supporting records, check outside sources, and carry any unresolved conflicts forward as flagged items into the scoring step. The quality of evidence here will shape how accurate - and how defensible - your risk scores are.

Steps 4 and 5: Score Risks and Rank Priorities

Now comes the part where raw evidence has to become something people can use. You’ve gathered documents, interviews, and site notes. The next job is to turn that mix into scores that different teams can compare, question, and defend. The point is consistency. If the framework is simple and well documented, an investment committee, a procurement team, or an external auditor can follow the logic without having to rebuild the whole review from scratch.

Step 4: Apply Scoring Logic for Impact, Likelihood, and Controls

Use the evidence from Steps 2 and 3 to score each risk the same way across the board. Rate each ESG risk on three dimensions: impact, likelihood, and control effectiveness. Use a 1–5 scale for impact and likelihood. Score control effectiveness on its own so you can calculate residual risk. That turns a pile of evidence into a decision input teams can line up side by side.

Impact is about severity. Likelihood is about the chance the issue will occur within the review horizon, which is often 3–5 years. In U.S.-based reviews, it helps to anchor the low end of impact to exposure below $50,000 and the high end to multi-million-dollar losses, enforcement action, or serious harm to workers or communities. For likelihood, a score of 1 means rare, while 5 means recurring or clearly signaled by trend data.

Multiply impact by likelihood to get inherent risk. Then adjust for control effectiveness to estimate residual risk. Score control effectiveness based on design, implementation, and monitoring. Just as important, write down the evidence behind the score, the assumptions you made, and any weak spots in the data. That makes the scoring auditable and repeatable across assets, suppliers, or acquisition targets.[1][5][6]

Step 5: Rank the Highest-Priority ESG Risks

Once residual risk scores are in place, sort issues by residual risk level and urgency for action. Residual risk shows what exposure is still left. Urgency shows how soon the issue could hit operations, finances, or stakeholders. A risk with a high residual score and a near-term trigger, like a regulatory deadline or active stakeholder pressure, usually needs attention sooner than a large structural risk that may not peak for several years.

Use a heat map for a fast visual read, and use the risk register for the full detail.[1][2][3][10] Here’s what a working register can look like across a set of ESG issues:

Risk Issue

Impact Score (1–5)

Likelihood Score (1–5)

Control Effectiveness (1–5)

Residual Risk Level

Urgency

Key Driver

Water scarcity at plant A

5

4

2

Critical

Near-term (0–2 yrs)

Physical climate risk

Third-party labor practices

4

3

2

High

Near-term (0–2 yrs)

Supply chain governance

Data privacy compliance

3

3

4

Medium

Medium-term (2–5 yrs)

Regulatory complexity

Waste management performance

3

2

3

Low–Medium

Long-term (>5 yrs)

Operational efficiency

The key driver column is where the register starts doing real work. It points to the mitigation lever. If the issue is a supply chain governance gap, the next move may be stronger supplier audits and tighter contract terms. If the issue is physical climate risk at a manufacturing site, the answer may lean more toward infrastructure spending and local stakeholder engagement. That one column helps shift the register from a scoring sheet into a decision tool, showing where budgets and executive attention should go.

Keep the register current as climate data, regulations, or audit findings shift. A static register loses its use fast. Treat it as a live document that feeds capital allocation, procurement decisions, and board-level risk reporting.[4][7][8][9] Use the ranked list to set owners, timelines, and budgets in Step 6.

Step 6: Build Action Plans and Wrap Up

The ranked risk register from Step 5 matters only if it leads to action. Step 6 turns that list into a formal ESG action plan: clear steps, measurable targets, and set deadlines that leaders can fund and track. Before anything moves, each item needs a named owner.

Assign Owners, Timelines, and Budgets to Top Risks

Start with the highest-priority residual-risk items and write one clear action for each. A solid action plan should spell out the risk, action, owner, due date, budget, KPI, and tracking method. Give each action to the person or team that controls the system or decision tied to that risk. They should also have budget authority, or at least a clear path to escalate if they don’t.

Be specific. Use fixed dates. Match the budget to the work. Then add a buffer for surprises and the cost of continued monitoring. A top ESG risk should move through three stages:

  • assessment

  • remediation

  • verification

Each stage should have an owner, a deadline, a budget, and a clear check for completion. That’s what turns a risk review from a spreadsheet exercise into something people can manage.

Once those fields are in place, move the plan into governance. Put material actions into board approvals, loan covenants, or contract terms. In transactions, high-priority actions may become closing conditions or post-close covenants. Track progress monthly at the task level, quarterly at the executive level, and semiannually at the board level with simple status labels: On Track, At Risk, or Off Track.

Conclusion: The Six-Step ESG Due Diligence Process at a Glance

With actions assigned and tracked, the review is ready to close. The flow is straightforward: define scope, review evidence, gather input, score, rank, and act. The point is not the register itself. The point is the funded plan that shapes decisions, whether that means approving a transaction, putting conditions on a deal, shifting capital, or renegotiating contract terms.

Teams that treat the action plan as the main output are the ones that reduce exposure over time.

For teams that need implementation support, Council Fire helps turn ESG findings into action.

FAQs

How long should an ESG risk review take?

An ESG risk review isn’t a one-time project. It’s an ongoing process that teams revisit, refine, and repeat over time. The pace depends on the size of the organization, how ready the data is, and how much complexity sits across the business.

As a general guide, supply chain due diligence may run on a 12-month cycle. Climate risk assessments often take 3 to 6 months for the first round. Double materiality assessments usually span 10 to 16 weeks.

That initial work is only part of the picture. Regular monitoring, annual updates, and periodic reassessments are all part of keeping the review current and useful as conditions shift.

Who should be involved in the ESG due diligence process?

An effective ESG due diligence process works best when it pulls in people from across the business. Inside the company, that means involving the ESG or sustainability team along with finance, risk management, legal, compliance, HR, and operations. Each group sees a different part of the picture, and that matters when you're trying to spot issues early and judge them clearly.

Outside the company, the circle should be just as broad. Bring in employees, suppliers, customers, local communities, and people who rely on sustainability information, including investors, lenders, and regulators. External consultants can add rigor and an outside view, but senior leadership still needs to stay visibly involved. If leaders step back, the process can start to feel like a box-checking exercise instead of a serious business review.

What should I do if ESG findings reveal major gaps before a deal closes?

If ESG due diligence surfaces major gaps before a deal closes, the next step is active risk management. Spotting the problem isn’t enough. You need to record the issues, show what action was taken, and track the result.

Put corrective action plans in place with clear timelines and named steps. When the problem is serious, that may mean contract terms, sourcing changes, or, if there’s no workable path forward, responsible disengagement. Keep thorough records throughout the process so your response is well supported and in line with regulatory expectations.

Related Blog Posts

FAQ

What does it really mean to “redefine profit”?

What makes Council Fire different?

Who does Council Fire work with?

What does working with Council Fire actually look like?

How does Council Fire help organizations turn big goals into action?

How does Council Fire define and measure success?