

Jul 30, 2026
ESG Risk Review: 6 Steps for Due Diligence
ESG Strategy
In This Article
A six-step ESG due diligence process to identify, score, and act on material environmental, social, and governance risks.
ESG Risk Review: 6 Steps for Due Diligence
A weak ESG review can change a deal fast. In one KPMG study, 53% of respondents said material ESG findings led to canceled deals, and 42% said findings cut the purchase price.
If I need to explain this article in plain English, I’d put it this way: an ESG risk review helps me spot labor, climate, governance, community, and legal issues before I sign, buy, fund, or approve anything. The six-step process is simple:
Set the scope so I know what decision, entities, sites, and time period I’m reviewing
Pick the ESG issues that matter most to the sector, footprint, and legal setting
Check records and data to see what the company says and what the files show
Talk to people and visit sites to test whether day-to-day conditions match the paper record
Score and rank risks by impact, likelihood, and control gaps
Assign actions with owners, budgets, dates, and follow-up
What matters most is not the checklist. It’s the outcome: a ranked list of risks and a funded action plan that can shape pricing, contract terms, remediation steps, or a go/no-go call.
This article lays out that six-step process in a clear order so I can turn ESG due diligence into a decision tool, not just a filing step.

6-Step ESG Due Diligence Process for Risk Review
ESG webinar: ESG due diligence
Step 1: Define Scope and Material ESG Risks
Define the scope before you pull documents or line up interviews. A tight scope keeps the review centered on the risks that matter.
Set the Review Boundary and Decision Context
Start by naming the decision this review needs to support - acquisition, project finance, procurement, or partnership. Then spell out what the review must inform: pricing, indemnities, remediation, or a go/no-go call.
Next, define the boundary. List the legal entities, sites, subsidiaries, joint ventures, and value-chain tiers in scope so the work stays tied to the entities and geographies that can shape the decision. Just as important, note what is not in scope and why.
Set the time horizon and the rules that apply. Near-term operating risks are not the same as 5- to 10-year transition risks. In the U.S., reviews should cover SEC climate disclosure, anti-bribery, labor and employment law, and the environmental permits that apply. If the business touches other markets, include foreign human-rights due diligence rules where they fit.
Capture all of this in a one-page memo. It should cover the decision context, boundaries, geography, time horizon, standards, assumptions, and exclusions. Once that scope is locked, the document review can start.
Identify Material Environmental, Social, and Governance Issues
Use the decision context to separate enterprise-value risks from broader impact issues. In this setting, materiality means an ESG issue can affect value, cause harm, or trigger legal or regulatory exposure.
Sector is the fastest first screen. A coastal logistics operator carries higher physical climate risk. A food-processing company has sharp worker health and safety exposure. An apparel brand may face forced-labor risk in its supply chain. SASB's sector-specific materiality maps are a good place to start, but don't stop there. Test those topics against the company's actual footprint - its locations, workforce size, input materials, and regulatory setting. Put the heaviest weight on topics that can shift pricing, timing, liability, or approval.
Use the table below to connect common ESG issues to decision-level risk channels, indicators, and data sources.
Material ESG Issue | Likely Impact Channels | Sample Indicators | Common Data Sources |
|---|---|---|---|
Climate Exposure | Physical asset damage; transition costs (carbon pricing, fuel switching) | Scope 1, 2, and 3 GHG emissions; location in flood, wildfire, or heat hazard zones | Utility bills, site maps, climate-risk assessments, climate disclosures |
Energy Use | Operating costs; regulatory compliance | Energy consumption by source; % renewable | Energy audits, procurement records |
Water Stewardship | Operational disruption in water-stressed areas | Water withdrawal and discharge intensity | Facility meters, WRI Aqueduct, local basin risk maps |
Pollution and Waste | Cleanup liability; permit violations | Spill history, discharge violations, waste volumes, remediation liabilities | Environmental permits, incident logs, site inspection reports |
Labor Practices | Talent retention; legal liability; strikes | Turnover rate; overtime hours; employee complaints | HR records, payroll data, union reports |
Worker Health and Safety | Productivity loss; legal exposure | OSHA recordable injury rate; lost-time incidents; training completion | Incident logs, OSHA records, training records |
Human Rights | Reputational damage; supply-chain disruption | % of suppliers screened; audit findings; grievance counts | Supplier audits, NGO reports, KnowTheChain benchmarks |
Community Impacts | License to operate; project delays | Land-access disputes; indigenous rights concerns; community grievances | Stakeholder engagement records, local government filings |
Board Oversight | Governance failure; investor confidence | % of directors independent; ESG committee charter; executive comp linkage to ESG | Proxy statements, board committee charters |
Ethics and Anti-Corruption | Fines; debarment; loss of investor trust | Hotline reports; third-party due diligence coverage; disciplinary actions | Compliance audits, whistleblower logs, case files |
One practical caution: avoid recency bias. Don't give too much weight to issues making headlines if they are not structurally important for the sector and geography at hand. A topic can be politically visible and still have little bearing on the business under review. The goal is a defensible shortlist, not the longest checklist.
Next, review the documents and performance data that test these assumptions.
Steps 2 and 3: Review Documents and Gather Stakeholder Input
Once you've identified your material ESG issues, the next job is to build the evidence base behind the decision. In practice, that means running two tracks at the same time: a structured document review and direct stakeholder engagement. One without the other leaves blind spots.
Step 2: Review Policies, Records, and Performance Data
The document review sets your baseline. It shows what the company says it will do, what it reports doing, and what the records suggest is happening underneath. Start with the documents tied to the highest-risk issues from Step 1. That usually includes policies, permits, incident logs, audit findings, supplier reports, grievance records, HR and training data, and ESG dashboards.
Look at each record with a simple test in mind: is it current, complete, consistent, and credible? A policy that hasn't changed in years, even though OSHA or SEC requirements have moved on, should put you on alert.
This is where triangulation matters. Don't read records in isolation. Compare them and see whether they line up. If a facility's sustainability report points to a strong safety culture, but training records cover only part of the workforce and incident logs show a rising lost-time injury rate, that's not just messy data. It's a control failure. Every mismatch gives you a clue about where to dig next, who to interview, and what to test during site checks.
Step 3: Interview Stakeholders and Verify Actual Operating Conditions
Use the gaps and contradictions from the document review to shape your interviews. Documents show the paper trail. Interviews and site checks tell you whether that paper trail matches day-to-day conditions.
Your stakeholder outreach should include the people who control the risk, report on it, or live with the outcome: executives, legal and compliance teams, operations and EHS managers, HR, and affected workers or community representatives. The UN Guiding Principles on Business and Human Rights make clear that identifying human-rights risks requires meaningful consultation with potentially affected groups, not just management. The OECD Guidelines for Multinational Enterprises make a similar point, calling for meaningful engagement with relevant stakeholders or their legitimate representatives as part of due diligence.
Good interviews don't just ask people to repeat policy language. They get into execution, exceptions, and ownership. Ask how policies work in practice, which controls break down most often, what was escalated in the last 12 months, and what is still unresolved.
Site visits add something no file or dashboard can give you: direct observation. A visit can confirm whether wastewater treatment systems are operating as documented, whether personal protective equipment is actually being used, or whether subcontractor activity on-site is undisclosed and unmanaged. They're most useful when the risk depends on physical operations, labor conditions, or community-facing effects. Think of a site visit as a spot check, not a full audit. Even so, a well-planned visit to a sample of representative facilities can surface execution problems that might otherwise slip into the scoring stage unnoticed.
The table below shows how each evidence source supports the review.
Evidence Type | Strengths | Limitations | Best-Use Case |
|---|---|---|---|
Internal Documents | Formal commitments, historical KPIs, permit and audit records | May be aspirational, incomplete, or curated for disclosure | Establishing the baseline "paper" reality and stated goals |
External Data | Independent verification via regulatory databases, media reports, court records, or NGO findings | May lack internal context; can be outdated | Identifying enforcement actions or controversies not disclosed internally |
Stakeholder Interviews | Reveals culture, implementation gaps, and unreported issues | Subject to bias, coaching, or fear of retaliation | Testing whether staff and communities experience policies as functional |
Site Visits | Direct observation of physical conditions and control effectiveness | Resource-intensive; a snapshot that may not reflect normal operations | Verifying high-risk environmental, labor, or community-facing conditions |
When documents, interviews, and site observations don't match, treat that conflict as a risk signal. Don't wave it away as a paperwork problem. Work out whether the mismatch comes from timing, poor data quality, or an actual control breakdown. Then ask for supporting records, check outside sources, and carry any unresolved conflicts forward as flagged items into the scoring step. The quality of evidence here will shape how accurate - and how defensible - your risk scores are.
Steps 4 and 5: Score Risks and Rank Priorities
Now comes the part where raw evidence has to become something people can use. You’ve gathered documents, interviews, and site notes. The next job is to turn that mix into scores that different teams can compare, question, and defend. The point is consistency. If the framework is simple and well documented, an investment committee, a procurement team, or an external auditor can follow the logic without having to rebuild the whole review from scratch.
Step 4: Apply Scoring Logic for Impact, Likelihood, and Controls
Use the evidence from Steps 2 and 3 to score each risk the same way across the board. Rate each ESG risk on three dimensions: impact, likelihood, and control effectiveness. Use a 1–5 scale for impact and likelihood. Score control effectiveness on its own so you can calculate residual risk. That turns a pile of evidence into a decision input teams can line up side by side.
Impact is about severity. Likelihood is about the chance the issue will occur within the review horizon, which is often 3–5 years. In U.S.-based reviews, it helps to anchor the low end of impact to exposure below $50,000 and the high end to multi-million-dollar losses, enforcement action, or serious harm to workers or communities. For likelihood, a score of 1 means rare, while 5 means recurring or clearly signaled by trend data.
Multiply impact by likelihood to get inherent risk. Then adjust for control effectiveness to estimate residual risk. Score control effectiveness based on design, implementation, and monitoring. Just as important, write down the evidence behind the score, the assumptions you made, and any weak spots in the data. That makes the scoring auditable and repeatable across assets, suppliers, or acquisition targets.[1][5][6]
Step 5: Rank the Highest-Priority ESG Risks
Once residual risk scores are in place, sort issues by residual risk level and urgency for action. Residual risk shows what exposure is still left. Urgency shows how soon the issue could hit operations, finances, or stakeholders. A risk with a high residual score and a near-term trigger, like a regulatory deadline or active stakeholder pressure, usually needs attention sooner than a large structural risk that may not peak for several years.
Use a heat map for a fast visual read, and use the risk register for the full detail.[1][2][3][10] Here’s what a working register can look like across a set of ESG issues:
Risk Issue | Impact Score (1–5) | Likelihood Score (1–5) | Control Effectiveness (1–5) | Residual Risk Level | Urgency | Key Driver |
|---|---|---|---|---|---|---|
Water scarcity at plant A | 5 | 4 | 2 | Critical | Near-term (0–2 yrs) | Physical climate risk |
Third-party labor practices | 4 | 3 | 2 | High | Near-term (0–2 yrs) | Supply chain governance |
Data privacy compliance | 3 | 3 | 4 | Medium | Medium-term (2–5 yrs) | Regulatory complexity |
Waste management performance | 3 | 2 | 3 | Low–Medium | Long-term (>5 yrs) | Operational efficiency |
The key driver column is where the register starts doing real work. It points to the mitigation lever. If the issue is a supply chain governance gap, the next move may be stronger supplier audits and tighter contract terms. If the issue is physical climate risk at a manufacturing site, the answer may lean more toward infrastructure spending and local stakeholder engagement. That one column helps shift the register from a scoring sheet into a decision tool, showing where budgets and executive attention should go.
Keep the register current as climate data, regulations, or audit findings shift. A static register loses its use fast. Treat it as a live document that feeds capital allocation, procurement decisions, and board-level risk reporting.[4][7][8][9] Use the ranked list to set owners, timelines, and budgets in Step 6.
Step 6: Build Action Plans and Wrap Up
The ranked risk register from Step 5 matters only if it leads to action. Step 6 turns that list into a formal ESG action plan: clear steps, measurable targets, and set deadlines that leaders can fund and track. Before anything moves, each item needs a named owner.
Assign Owners, Timelines, and Budgets to Top Risks
Start with the highest-priority residual-risk items and write one clear action for each. A solid action plan should spell out the risk, action, owner, due date, budget, KPI, and tracking method. Give each action to the person or team that controls the system or decision tied to that risk. They should also have budget authority, or at least a clear path to escalate if they don’t.
Be specific. Use fixed dates. Match the budget to the work. Then add a buffer for surprises and the cost of continued monitoring. A top ESG risk should move through three stages:
assessment
remediation
verification
Each stage should have an owner, a deadline, a budget, and a clear check for completion. That’s what turns a risk review from a spreadsheet exercise into something people can manage.
Once those fields are in place, move the plan into governance. Put material actions into board approvals, loan covenants, or contract terms. In transactions, high-priority actions may become closing conditions or post-close covenants. Track progress monthly at the task level, quarterly at the executive level, and semiannually at the board level with simple status labels: On Track, At Risk, or Off Track.
Conclusion: The Six-Step ESG Due Diligence Process at a Glance
With actions assigned and tracked, the review is ready to close. The flow is straightforward: define scope, review evidence, gather input, score, rank, and act. The point is not the register itself. The point is the funded plan that shapes decisions, whether that means approving a transaction, putting conditions on a deal, shifting capital, or renegotiating contract terms.
Teams that treat the action plan as the main output are the ones that reduce exposure over time.
For teams that need implementation support, Council Fire helps turn ESG findings into action.
FAQs
How long should an ESG risk review take?
An ESG risk review isn’t a one-time project. It’s an ongoing process that teams revisit, refine, and repeat over time. The pace depends on the size of the organization, how ready the data is, and how much complexity sits across the business.
As a general guide, supply chain due diligence may run on a 12-month cycle. Climate risk assessments often take 3 to 6 months for the first round. Double materiality assessments usually span 10 to 16 weeks.
That initial work is only part of the picture. Regular monitoring, annual updates, and periodic reassessments are all part of keeping the review current and useful as conditions shift.
Who should be involved in the ESG due diligence process?
An effective ESG due diligence process works best when it pulls in people from across the business. Inside the company, that means involving the ESG or sustainability team along with finance, risk management, legal, compliance, HR, and operations. Each group sees a different part of the picture, and that matters when you're trying to spot issues early and judge them clearly.
Outside the company, the circle should be just as broad. Bring in employees, suppliers, customers, local communities, and people who rely on sustainability information, including investors, lenders, and regulators. External consultants can add rigor and an outside view, but senior leadership still needs to stay visibly involved. If leaders step back, the process can start to feel like a box-checking exercise instead of a serious business review.
What should I do if ESG findings reveal major gaps before a deal closes?
If ESG due diligence surfaces major gaps before a deal closes, the next step is active risk management. Spotting the problem isn’t enough. You need to record the issues, show what action was taken, and track the result.
Put corrective action plans in place with clear timelines and named steps. When the problem is serious, that may mean contract terms, sourcing changes, or, if there’s no workable path forward, responsible disengagement. Keep thorough records throughout the process so your response is well supported and in line with regulatory expectations.
Related Blog Posts

Latest Articles
©2025
FAQ
01
What does it really mean to “redefine profit”?
02
What makes Council Fire different?
03
Who does Council Fire work with?
04
What does working with Council Fire actually look like?
05
How does Council Fire help organizations turn big goals into action?
06
How does Council Fire define and measure success?


Jul 30, 2026
ESG Risk Review: 6 Steps for Due Diligence
ESG Strategy
In This Article
A six-step ESG due diligence process to identify, score, and act on material environmental, social, and governance risks.
ESG Risk Review: 6 Steps for Due Diligence
A weak ESG review can change a deal fast. In one KPMG study, 53% of respondents said material ESG findings led to canceled deals, and 42% said findings cut the purchase price.
If I need to explain this article in plain English, I’d put it this way: an ESG risk review helps me spot labor, climate, governance, community, and legal issues before I sign, buy, fund, or approve anything. The six-step process is simple:
Set the scope so I know what decision, entities, sites, and time period I’m reviewing
Pick the ESG issues that matter most to the sector, footprint, and legal setting
Check records and data to see what the company says and what the files show
Talk to people and visit sites to test whether day-to-day conditions match the paper record
Score and rank risks by impact, likelihood, and control gaps
Assign actions with owners, budgets, dates, and follow-up
What matters most is not the checklist. It’s the outcome: a ranked list of risks and a funded action plan that can shape pricing, contract terms, remediation steps, or a go/no-go call.
This article lays out that six-step process in a clear order so I can turn ESG due diligence into a decision tool, not just a filing step.

6-Step ESG Due Diligence Process for Risk Review
ESG webinar: ESG due diligence
Step 1: Define Scope and Material ESG Risks
Define the scope before you pull documents or line up interviews. A tight scope keeps the review centered on the risks that matter.
Set the Review Boundary and Decision Context
Start by naming the decision this review needs to support - acquisition, project finance, procurement, or partnership. Then spell out what the review must inform: pricing, indemnities, remediation, or a go/no-go call.
Next, define the boundary. List the legal entities, sites, subsidiaries, joint ventures, and value-chain tiers in scope so the work stays tied to the entities and geographies that can shape the decision. Just as important, note what is not in scope and why.
Set the time horizon and the rules that apply. Near-term operating risks are not the same as 5- to 10-year transition risks. In the U.S., reviews should cover SEC climate disclosure, anti-bribery, labor and employment law, and the environmental permits that apply. If the business touches other markets, include foreign human-rights due diligence rules where they fit.
Capture all of this in a one-page memo. It should cover the decision context, boundaries, geography, time horizon, standards, assumptions, and exclusions. Once that scope is locked, the document review can start.
Identify Material Environmental, Social, and Governance Issues
Use the decision context to separate enterprise-value risks from broader impact issues. In this setting, materiality means an ESG issue can affect value, cause harm, or trigger legal or regulatory exposure.
Sector is the fastest first screen. A coastal logistics operator carries higher physical climate risk. A food-processing company has sharp worker health and safety exposure. An apparel brand may face forced-labor risk in its supply chain. SASB's sector-specific materiality maps are a good place to start, but don't stop there. Test those topics against the company's actual footprint - its locations, workforce size, input materials, and regulatory setting. Put the heaviest weight on topics that can shift pricing, timing, liability, or approval.
Use the table below to connect common ESG issues to decision-level risk channels, indicators, and data sources.
Material ESG Issue | Likely Impact Channels | Sample Indicators | Common Data Sources |
|---|---|---|---|
Climate Exposure | Physical asset damage; transition costs (carbon pricing, fuel switching) | Scope 1, 2, and 3 GHG emissions; location in flood, wildfire, or heat hazard zones | Utility bills, site maps, climate-risk assessments, climate disclosures |
Energy Use | Operating costs; regulatory compliance | Energy consumption by source; % renewable | Energy audits, procurement records |
Water Stewardship | Operational disruption in water-stressed areas | Water withdrawal and discharge intensity | Facility meters, WRI Aqueduct, local basin risk maps |
Pollution and Waste | Cleanup liability; permit violations | Spill history, discharge violations, waste volumes, remediation liabilities | Environmental permits, incident logs, site inspection reports |
Labor Practices | Talent retention; legal liability; strikes | Turnover rate; overtime hours; employee complaints | HR records, payroll data, union reports |
Worker Health and Safety | Productivity loss; legal exposure | OSHA recordable injury rate; lost-time incidents; training completion | Incident logs, OSHA records, training records |
Human Rights | Reputational damage; supply-chain disruption | % of suppliers screened; audit findings; grievance counts | Supplier audits, NGO reports, KnowTheChain benchmarks |
Community Impacts | License to operate; project delays | Land-access disputes; indigenous rights concerns; community grievances | Stakeholder engagement records, local government filings |
Board Oversight | Governance failure; investor confidence | % of directors independent; ESG committee charter; executive comp linkage to ESG | Proxy statements, board committee charters |
Ethics and Anti-Corruption | Fines; debarment; loss of investor trust | Hotline reports; third-party due diligence coverage; disciplinary actions | Compliance audits, whistleblower logs, case files |
One practical caution: avoid recency bias. Don't give too much weight to issues making headlines if they are not structurally important for the sector and geography at hand. A topic can be politically visible and still have little bearing on the business under review. The goal is a defensible shortlist, not the longest checklist.
Next, review the documents and performance data that test these assumptions.
Steps 2 and 3: Review Documents and Gather Stakeholder Input
Once you've identified your material ESG issues, the next job is to build the evidence base behind the decision. In practice, that means running two tracks at the same time: a structured document review and direct stakeholder engagement. One without the other leaves blind spots.
Step 2: Review Policies, Records, and Performance Data
The document review sets your baseline. It shows what the company says it will do, what it reports doing, and what the records suggest is happening underneath. Start with the documents tied to the highest-risk issues from Step 1. That usually includes policies, permits, incident logs, audit findings, supplier reports, grievance records, HR and training data, and ESG dashboards.
Look at each record with a simple test in mind: is it current, complete, consistent, and credible? A policy that hasn't changed in years, even though OSHA or SEC requirements have moved on, should put you on alert.
This is where triangulation matters. Don't read records in isolation. Compare them and see whether they line up. If a facility's sustainability report points to a strong safety culture, but training records cover only part of the workforce and incident logs show a rising lost-time injury rate, that's not just messy data. It's a control failure. Every mismatch gives you a clue about where to dig next, who to interview, and what to test during site checks.
Step 3: Interview Stakeholders and Verify Actual Operating Conditions
Use the gaps and contradictions from the document review to shape your interviews. Documents show the paper trail. Interviews and site checks tell you whether that paper trail matches day-to-day conditions.
Your stakeholder outreach should include the people who control the risk, report on it, or live with the outcome: executives, legal and compliance teams, operations and EHS managers, HR, and affected workers or community representatives. The UN Guiding Principles on Business and Human Rights make clear that identifying human-rights risks requires meaningful consultation with potentially affected groups, not just management. The OECD Guidelines for Multinational Enterprises make a similar point, calling for meaningful engagement with relevant stakeholders or their legitimate representatives as part of due diligence.
Good interviews don't just ask people to repeat policy language. They get into execution, exceptions, and ownership. Ask how policies work in practice, which controls break down most often, what was escalated in the last 12 months, and what is still unresolved.
Site visits add something no file or dashboard can give you: direct observation. A visit can confirm whether wastewater treatment systems are operating as documented, whether personal protective equipment is actually being used, or whether subcontractor activity on-site is undisclosed and unmanaged. They're most useful when the risk depends on physical operations, labor conditions, or community-facing effects. Think of a site visit as a spot check, not a full audit. Even so, a well-planned visit to a sample of representative facilities can surface execution problems that might otherwise slip into the scoring stage unnoticed.
The table below shows how each evidence source supports the review.
Evidence Type | Strengths | Limitations | Best-Use Case |
|---|---|---|---|
Internal Documents | Formal commitments, historical KPIs, permit and audit records | May be aspirational, incomplete, or curated for disclosure | Establishing the baseline "paper" reality and stated goals |
External Data | Independent verification via regulatory databases, media reports, court records, or NGO findings | May lack internal context; can be outdated | Identifying enforcement actions or controversies not disclosed internally |
Stakeholder Interviews | Reveals culture, implementation gaps, and unreported issues | Subject to bias, coaching, or fear of retaliation | Testing whether staff and communities experience policies as functional |
Site Visits | Direct observation of physical conditions and control effectiveness | Resource-intensive; a snapshot that may not reflect normal operations | Verifying high-risk environmental, labor, or community-facing conditions |
When documents, interviews, and site observations don't match, treat that conflict as a risk signal. Don't wave it away as a paperwork problem. Work out whether the mismatch comes from timing, poor data quality, or an actual control breakdown. Then ask for supporting records, check outside sources, and carry any unresolved conflicts forward as flagged items into the scoring step. The quality of evidence here will shape how accurate - and how defensible - your risk scores are.
Steps 4 and 5: Score Risks and Rank Priorities
Now comes the part where raw evidence has to become something people can use. You’ve gathered documents, interviews, and site notes. The next job is to turn that mix into scores that different teams can compare, question, and defend. The point is consistency. If the framework is simple and well documented, an investment committee, a procurement team, or an external auditor can follow the logic without having to rebuild the whole review from scratch.
Step 4: Apply Scoring Logic for Impact, Likelihood, and Controls
Use the evidence from Steps 2 and 3 to score each risk the same way across the board. Rate each ESG risk on three dimensions: impact, likelihood, and control effectiveness. Use a 1–5 scale for impact and likelihood. Score control effectiveness on its own so you can calculate residual risk. That turns a pile of evidence into a decision input teams can line up side by side.
Impact is about severity. Likelihood is about the chance the issue will occur within the review horizon, which is often 3–5 years. In U.S.-based reviews, it helps to anchor the low end of impact to exposure below $50,000 and the high end to multi-million-dollar losses, enforcement action, or serious harm to workers or communities. For likelihood, a score of 1 means rare, while 5 means recurring or clearly signaled by trend data.
Multiply impact by likelihood to get inherent risk. Then adjust for control effectiveness to estimate residual risk. Score control effectiveness based on design, implementation, and monitoring. Just as important, write down the evidence behind the score, the assumptions you made, and any weak spots in the data. That makes the scoring auditable and repeatable across assets, suppliers, or acquisition targets.[1][5][6]
Step 5: Rank the Highest-Priority ESG Risks
Once residual risk scores are in place, sort issues by residual risk level and urgency for action. Residual risk shows what exposure is still left. Urgency shows how soon the issue could hit operations, finances, or stakeholders. A risk with a high residual score and a near-term trigger, like a regulatory deadline or active stakeholder pressure, usually needs attention sooner than a large structural risk that may not peak for several years.
Use a heat map for a fast visual read, and use the risk register for the full detail.[1][2][3][10] Here’s what a working register can look like across a set of ESG issues:
Risk Issue | Impact Score (1–5) | Likelihood Score (1–5) | Control Effectiveness (1–5) | Residual Risk Level | Urgency | Key Driver |
|---|---|---|---|---|---|---|
Water scarcity at plant A | 5 | 4 | 2 | Critical | Near-term (0–2 yrs) | Physical climate risk |
Third-party labor practices | 4 | 3 | 2 | High | Near-term (0–2 yrs) | Supply chain governance |
Data privacy compliance | 3 | 3 | 4 | Medium | Medium-term (2–5 yrs) | Regulatory complexity |
Waste management performance | 3 | 2 | 3 | Low–Medium | Long-term (>5 yrs) | Operational efficiency |
The key driver column is where the register starts doing real work. It points to the mitigation lever. If the issue is a supply chain governance gap, the next move may be stronger supplier audits and tighter contract terms. If the issue is physical climate risk at a manufacturing site, the answer may lean more toward infrastructure spending and local stakeholder engagement. That one column helps shift the register from a scoring sheet into a decision tool, showing where budgets and executive attention should go.
Keep the register current as climate data, regulations, or audit findings shift. A static register loses its use fast. Treat it as a live document that feeds capital allocation, procurement decisions, and board-level risk reporting.[4][7][8][9] Use the ranked list to set owners, timelines, and budgets in Step 6.
Step 6: Build Action Plans and Wrap Up
The ranked risk register from Step 5 matters only if it leads to action. Step 6 turns that list into a formal ESG action plan: clear steps, measurable targets, and set deadlines that leaders can fund and track. Before anything moves, each item needs a named owner.
Assign Owners, Timelines, and Budgets to Top Risks
Start with the highest-priority residual-risk items and write one clear action for each. A solid action plan should spell out the risk, action, owner, due date, budget, KPI, and tracking method. Give each action to the person or team that controls the system or decision tied to that risk. They should also have budget authority, or at least a clear path to escalate if they don’t.
Be specific. Use fixed dates. Match the budget to the work. Then add a buffer for surprises and the cost of continued monitoring. A top ESG risk should move through three stages:
assessment
remediation
verification
Each stage should have an owner, a deadline, a budget, and a clear check for completion. That’s what turns a risk review from a spreadsheet exercise into something people can manage.
Once those fields are in place, move the plan into governance. Put material actions into board approvals, loan covenants, or contract terms. In transactions, high-priority actions may become closing conditions or post-close covenants. Track progress monthly at the task level, quarterly at the executive level, and semiannually at the board level with simple status labels: On Track, At Risk, or Off Track.
Conclusion: The Six-Step ESG Due Diligence Process at a Glance
With actions assigned and tracked, the review is ready to close. The flow is straightforward: define scope, review evidence, gather input, score, rank, and act. The point is not the register itself. The point is the funded plan that shapes decisions, whether that means approving a transaction, putting conditions on a deal, shifting capital, or renegotiating contract terms.
Teams that treat the action plan as the main output are the ones that reduce exposure over time.
For teams that need implementation support, Council Fire helps turn ESG findings into action.
FAQs
How long should an ESG risk review take?
An ESG risk review isn’t a one-time project. It’s an ongoing process that teams revisit, refine, and repeat over time. The pace depends on the size of the organization, how ready the data is, and how much complexity sits across the business.
As a general guide, supply chain due diligence may run on a 12-month cycle. Climate risk assessments often take 3 to 6 months for the first round. Double materiality assessments usually span 10 to 16 weeks.
That initial work is only part of the picture. Regular monitoring, annual updates, and periodic reassessments are all part of keeping the review current and useful as conditions shift.
Who should be involved in the ESG due diligence process?
An effective ESG due diligence process works best when it pulls in people from across the business. Inside the company, that means involving the ESG or sustainability team along with finance, risk management, legal, compliance, HR, and operations. Each group sees a different part of the picture, and that matters when you're trying to spot issues early and judge them clearly.
Outside the company, the circle should be just as broad. Bring in employees, suppliers, customers, local communities, and people who rely on sustainability information, including investors, lenders, and regulators. External consultants can add rigor and an outside view, but senior leadership still needs to stay visibly involved. If leaders step back, the process can start to feel like a box-checking exercise instead of a serious business review.
What should I do if ESG findings reveal major gaps before a deal closes?
If ESG due diligence surfaces major gaps before a deal closes, the next step is active risk management. Spotting the problem isn’t enough. You need to record the issues, show what action was taken, and track the result.
Put corrective action plans in place with clear timelines and named steps. When the problem is serious, that may mean contract terms, sourcing changes, or, if there’s no workable path forward, responsible disengagement. Keep thorough records throughout the process so your response is well supported and in line with regulatory expectations.
Related Blog Posts

FAQ
01
What does it really mean to “redefine profit”?
02
What makes Council Fire different?
03
Who does Council Fire work with?
04
What does working with Council Fire actually look like?
05
How does Council Fire help organizations turn big goals into action?
06
How does Council Fire define and measure success?


Jul 30, 2026
ESG Risk Review: 6 Steps for Due Diligence
ESG Strategy
In This Article
A six-step ESG due diligence process to identify, score, and act on material environmental, social, and governance risks.
ESG Risk Review: 6 Steps for Due Diligence
A weak ESG review can change a deal fast. In one KPMG study, 53% of respondents said material ESG findings led to canceled deals, and 42% said findings cut the purchase price.
If I need to explain this article in plain English, I’d put it this way: an ESG risk review helps me spot labor, climate, governance, community, and legal issues before I sign, buy, fund, or approve anything. The six-step process is simple:
Set the scope so I know what decision, entities, sites, and time period I’m reviewing
Pick the ESG issues that matter most to the sector, footprint, and legal setting
Check records and data to see what the company says and what the files show
Talk to people and visit sites to test whether day-to-day conditions match the paper record
Score and rank risks by impact, likelihood, and control gaps
Assign actions with owners, budgets, dates, and follow-up
What matters most is not the checklist. It’s the outcome: a ranked list of risks and a funded action plan that can shape pricing, contract terms, remediation steps, or a go/no-go call.
This article lays out that six-step process in a clear order so I can turn ESG due diligence into a decision tool, not just a filing step.

6-Step ESG Due Diligence Process for Risk Review
ESG webinar: ESG due diligence
Step 1: Define Scope and Material ESG Risks
Define the scope before you pull documents or line up interviews. A tight scope keeps the review centered on the risks that matter.
Set the Review Boundary and Decision Context
Start by naming the decision this review needs to support - acquisition, project finance, procurement, or partnership. Then spell out what the review must inform: pricing, indemnities, remediation, or a go/no-go call.
Next, define the boundary. List the legal entities, sites, subsidiaries, joint ventures, and value-chain tiers in scope so the work stays tied to the entities and geographies that can shape the decision. Just as important, note what is not in scope and why.
Set the time horizon and the rules that apply. Near-term operating risks are not the same as 5- to 10-year transition risks. In the U.S., reviews should cover SEC climate disclosure, anti-bribery, labor and employment law, and the environmental permits that apply. If the business touches other markets, include foreign human-rights due diligence rules where they fit.
Capture all of this in a one-page memo. It should cover the decision context, boundaries, geography, time horizon, standards, assumptions, and exclusions. Once that scope is locked, the document review can start.
Identify Material Environmental, Social, and Governance Issues
Use the decision context to separate enterprise-value risks from broader impact issues. In this setting, materiality means an ESG issue can affect value, cause harm, or trigger legal or regulatory exposure.
Sector is the fastest first screen. A coastal logistics operator carries higher physical climate risk. A food-processing company has sharp worker health and safety exposure. An apparel brand may face forced-labor risk in its supply chain. SASB's sector-specific materiality maps are a good place to start, but don't stop there. Test those topics against the company's actual footprint - its locations, workforce size, input materials, and regulatory setting. Put the heaviest weight on topics that can shift pricing, timing, liability, or approval.
Use the table below to connect common ESG issues to decision-level risk channels, indicators, and data sources.
Material ESG Issue | Likely Impact Channels | Sample Indicators | Common Data Sources |
|---|---|---|---|
Climate Exposure | Physical asset damage; transition costs (carbon pricing, fuel switching) | Scope 1, 2, and 3 GHG emissions; location in flood, wildfire, or heat hazard zones | Utility bills, site maps, climate-risk assessments, climate disclosures |
Energy Use | Operating costs; regulatory compliance | Energy consumption by source; % renewable | Energy audits, procurement records |
Water Stewardship | Operational disruption in water-stressed areas | Water withdrawal and discharge intensity | Facility meters, WRI Aqueduct, local basin risk maps |
Pollution and Waste | Cleanup liability; permit violations | Spill history, discharge violations, waste volumes, remediation liabilities | Environmental permits, incident logs, site inspection reports |
Labor Practices | Talent retention; legal liability; strikes | Turnover rate; overtime hours; employee complaints | HR records, payroll data, union reports |
Worker Health and Safety | Productivity loss; legal exposure | OSHA recordable injury rate; lost-time incidents; training completion | Incident logs, OSHA records, training records |
Human Rights | Reputational damage; supply-chain disruption | % of suppliers screened; audit findings; grievance counts | Supplier audits, NGO reports, KnowTheChain benchmarks |
Community Impacts | License to operate; project delays | Land-access disputes; indigenous rights concerns; community grievances | Stakeholder engagement records, local government filings |
Board Oversight | Governance failure; investor confidence | % of directors independent; ESG committee charter; executive comp linkage to ESG | Proxy statements, board committee charters |
Ethics and Anti-Corruption | Fines; debarment; loss of investor trust | Hotline reports; third-party due diligence coverage; disciplinary actions | Compliance audits, whistleblower logs, case files |
One practical caution: avoid recency bias. Don't give too much weight to issues making headlines if they are not structurally important for the sector and geography at hand. A topic can be politically visible and still have little bearing on the business under review. The goal is a defensible shortlist, not the longest checklist.
Next, review the documents and performance data that test these assumptions.
Steps 2 and 3: Review Documents and Gather Stakeholder Input
Once you've identified your material ESG issues, the next job is to build the evidence base behind the decision. In practice, that means running two tracks at the same time: a structured document review and direct stakeholder engagement. One without the other leaves blind spots.
Step 2: Review Policies, Records, and Performance Data
The document review sets your baseline. It shows what the company says it will do, what it reports doing, and what the records suggest is happening underneath. Start with the documents tied to the highest-risk issues from Step 1. That usually includes policies, permits, incident logs, audit findings, supplier reports, grievance records, HR and training data, and ESG dashboards.
Look at each record with a simple test in mind: is it current, complete, consistent, and credible? A policy that hasn't changed in years, even though OSHA or SEC requirements have moved on, should put you on alert.
This is where triangulation matters. Don't read records in isolation. Compare them and see whether they line up. If a facility's sustainability report points to a strong safety culture, but training records cover only part of the workforce and incident logs show a rising lost-time injury rate, that's not just messy data. It's a control failure. Every mismatch gives you a clue about where to dig next, who to interview, and what to test during site checks.
Step 3: Interview Stakeholders and Verify Actual Operating Conditions
Use the gaps and contradictions from the document review to shape your interviews. Documents show the paper trail. Interviews and site checks tell you whether that paper trail matches day-to-day conditions.
Your stakeholder outreach should include the people who control the risk, report on it, or live with the outcome: executives, legal and compliance teams, operations and EHS managers, HR, and affected workers or community representatives. The UN Guiding Principles on Business and Human Rights make clear that identifying human-rights risks requires meaningful consultation with potentially affected groups, not just management. The OECD Guidelines for Multinational Enterprises make a similar point, calling for meaningful engagement with relevant stakeholders or their legitimate representatives as part of due diligence.
Good interviews don't just ask people to repeat policy language. They get into execution, exceptions, and ownership. Ask how policies work in practice, which controls break down most often, what was escalated in the last 12 months, and what is still unresolved.
Site visits add something no file or dashboard can give you: direct observation. A visit can confirm whether wastewater treatment systems are operating as documented, whether personal protective equipment is actually being used, or whether subcontractor activity on-site is undisclosed and unmanaged. They're most useful when the risk depends on physical operations, labor conditions, or community-facing effects. Think of a site visit as a spot check, not a full audit. Even so, a well-planned visit to a sample of representative facilities can surface execution problems that might otherwise slip into the scoring stage unnoticed.
The table below shows how each evidence source supports the review.
Evidence Type | Strengths | Limitations | Best-Use Case |
|---|---|---|---|
Internal Documents | Formal commitments, historical KPIs, permit and audit records | May be aspirational, incomplete, or curated for disclosure | Establishing the baseline "paper" reality and stated goals |
External Data | Independent verification via regulatory databases, media reports, court records, or NGO findings | May lack internal context; can be outdated | Identifying enforcement actions or controversies not disclosed internally |
Stakeholder Interviews | Reveals culture, implementation gaps, and unreported issues | Subject to bias, coaching, or fear of retaliation | Testing whether staff and communities experience policies as functional |
Site Visits | Direct observation of physical conditions and control effectiveness | Resource-intensive; a snapshot that may not reflect normal operations | Verifying high-risk environmental, labor, or community-facing conditions |
When documents, interviews, and site observations don't match, treat that conflict as a risk signal. Don't wave it away as a paperwork problem. Work out whether the mismatch comes from timing, poor data quality, or an actual control breakdown. Then ask for supporting records, check outside sources, and carry any unresolved conflicts forward as flagged items into the scoring step. The quality of evidence here will shape how accurate - and how defensible - your risk scores are.
Steps 4 and 5: Score Risks and Rank Priorities
Now comes the part where raw evidence has to become something people can use. You’ve gathered documents, interviews, and site notes. The next job is to turn that mix into scores that different teams can compare, question, and defend. The point is consistency. If the framework is simple and well documented, an investment committee, a procurement team, or an external auditor can follow the logic without having to rebuild the whole review from scratch.
Step 4: Apply Scoring Logic for Impact, Likelihood, and Controls
Use the evidence from Steps 2 and 3 to score each risk the same way across the board. Rate each ESG risk on three dimensions: impact, likelihood, and control effectiveness. Use a 1–5 scale for impact and likelihood. Score control effectiveness on its own so you can calculate residual risk. That turns a pile of evidence into a decision input teams can line up side by side.
Impact is about severity. Likelihood is about the chance the issue will occur within the review horizon, which is often 3–5 years. In U.S.-based reviews, it helps to anchor the low end of impact to exposure below $50,000 and the high end to multi-million-dollar losses, enforcement action, or serious harm to workers or communities. For likelihood, a score of 1 means rare, while 5 means recurring or clearly signaled by trend data.
Multiply impact by likelihood to get inherent risk. Then adjust for control effectiveness to estimate residual risk. Score control effectiveness based on design, implementation, and monitoring. Just as important, write down the evidence behind the score, the assumptions you made, and any weak spots in the data. That makes the scoring auditable and repeatable across assets, suppliers, or acquisition targets.[1][5][6]
Step 5: Rank the Highest-Priority ESG Risks
Once residual risk scores are in place, sort issues by residual risk level and urgency for action. Residual risk shows what exposure is still left. Urgency shows how soon the issue could hit operations, finances, or stakeholders. A risk with a high residual score and a near-term trigger, like a regulatory deadline or active stakeholder pressure, usually needs attention sooner than a large structural risk that may not peak for several years.
Use a heat map for a fast visual read, and use the risk register for the full detail.[1][2][3][10] Here’s what a working register can look like across a set of ESG issues:
Risk Issue | Impact Score (1–5) | Likelihood Score (1–5) | Control Effectiveness (1–5) | Residual Risk Level | Urgency | Key Driver |
|---|---|---|---|---|---|---|
Water scarcity at plant A | 5 | 4 | 2 | Critical | Near-term (0–2 yrs) | Physical climate risk |
Third-party labor practices | 4 | 3 | 2 | High | Near-term (0–2 yrs) | Supply chain governance |
Data privacy compliance | 3 | 3 | 4 | Medium | Medium-term (2–5 yrs) | Regulatory complexity |
Waste management performance | 3 | 2 | 3 | Low–Medium | Long-term (>5 yrs) | Operational efficiency |
The key driver column is where the register starts doing real work. It points to the mitigation lever. If the issue is a supply chain governance gap, the next move may be stronger supplier audits and tighter contract terms. If the issue is physical climate risk at a manufacturing site, the answer may lean more toward infrastructure spending and local stakeholder engagement. That one column helps shift the register from a scoring sheet into a decision tool, showing where budgets and executive attention should go.
Keep the register current as climate data, regulations, or audit findings shift. A static register loses its use fast. Treat it as a live document that feeds capital allocation, procurement decisions, and board-level risk reporting.[4][7][8][9] Use the ranked list to set owners, timelines, and budgets in Step 6.
Step 6: Build Action Plans and Wrap Up
The ranked risk register from Step 5 matters only if it leads to action. Step 6 turns that list into a formal ESG action plan: clear steps, measurable targets, and set deadlines that leaders can fund and track. Before anything moves, each item needs a named owner.
Assign Owners, Timelines, and Budgets to Top Risks
Start with the highest-priority residual-risk items and write one clear action for each. A solid action plan should spell out the risk, action, owner, due date, budget, KPI, and tracking method. Give each action to the person or team that controls the system or decision tied to that risk. They should also have budget authority, or at least a clear path to escalate if they don’t.
Be specific. Use fixed dates. Match the budget to the work. Then add a buffer for surprises and the cost of continued monitoring. A top ESG risk should move through three stages:
assessment
remediation
verification
Each stage should have an owner, a deadline, a budget, and a clear check for completion. That’s what turns a risk review from a spreadsheet exercise into something people can manage.
Once those fields are in place, move the plan into governance. Put material actions into board approvals, loan covenants, or contract terms. In transactions, high-priority actions may become closing conditions or post-close covenants. Track progress monthly at the task level, quarterly at the executive level, and semiannually at the board level with simple status labels: On Track, At Risk, or Off Track.
Conclusion: The Six-Step ESG Due Diligence Process at a Glance
With actions assigned and tracked, the review is ready to close. The flow is straightforward: define scope, review evidence, gather input, score, rank, and act. The point is not the register itself. The point is the funded plan that shapes decisions, whether that means approving a transaction, putting conditions on a deal, shifting capital, or renegotiating contract terms.
Teams that treat the action plan as the main output are the ones that reduce exposure over time.
For teams that need implementation support, Council Fire helps turn ESG findings into action.
FAQs
How long should an ESG risk review take?
An ESG risk review isn’t a one-time project. It’s an ongoing process that teams revisit, refine, and repeat over time. The pace depends on the size of the organization, how ready the data is, and how much complexity sits across the business.
As a general guide, supply chain due diligence may run on a 12-month cycle. Climate risk assessments often take 3 to 6 months for the first round. Double materiality assessments usually span 10 to 16 weeks.
That initial work is only part of the picture. Regular monitoring, annual updates, and periodic reassessments are all part of keeping the review current and useful as conditions shift.
Who should be involved in the ESG due diligence process?
An effective ESG due diligence process works best when it pulls in people from across the business. Inside the company, that means involving the ESG or sustainability team along with finance, risk management, legal, compliance, HR, and operations. Each group sees a different part of the picture, and that matters when you're trying to spot issues early and judge them clearly.
Outside the company, the circle should be just as broad. Bring in employees, suppliers, customers, local communities, and people who rely on sustainability information, including investors, lenders, and regulators. External consultants can add rigor and an outside view, but senior leadership still needs to stay visibly involved. If leaders step back, the process can start to feel like a box-checking exercise instead of a serious business review.
What should I do if ESG findings reveal major gaps before a deal closes?
If ESG due diligence surfaces major gaps before a deal closes, the next step is active risk management. Spotting the problem isn’t enough. You need to record the issues, show what action was taken, and track the result.
Put corrective action plans in place with clear timelines and named steps. When the problem is serious, that may mean contract terms, sourcing changes, or, if there’s no workable path forward, responsible disengagement. Keep thorough records throughout the process so your response is well supported and in line with regulatory expectations.
Related Blog Posts

FAQ
What does it really mean to “redefine profit”?
What makes Council Fire different?
Who does Council Fire work with?
What does working with Council Fire actually look like?
How does Council Fire help organizations turn big goals into action?
How does Council Fire define and measure success?


