Skip to main content

How to Run an ESG Materiality Assessment That Holds Up

A practical guide to designing and executing an ESG materiality assessment that satisfies CSRD double materiality expectations and stands up to auditor, regulator, and investor scrutiny. Readers will finish with a clear method for scoping, evidencing, and governing the exercise.

An ESG materiality assessment identifies which environmental, social, and governance topics matter enough to disclose, manage, and resource. Under CSRD, ISSB, and increasingly under prudential expectations, it is the foundation document that determines what ends up in your sustainability statement, your risk taxonomy, and your board reporting. Done well, it aligns disclosure with strategy. Done poorly, it becomes a stakeholder survey dressed up as governance, and auditors will say so.

Key Executive Takeaways

  • A credible assessment applies double materiality: impact materiality (your effect on people and environment) and financial materiality (sustainability matters affecting enterprise value), each evidenced separately before being combined.
  • The most common failure is treating the exercise as a communications output rather than a governance process, resulting in weak audit trails, undocumented thresholds, and topics that cannot be tied back to risk registers.
  • Auditors and regulators now test the process, not just the result: scoping decisions, stakeholder selection, scoring methodology, and board challenge must all be defensible in writing.

Get the Scope Right Before You Score Anything

Start with the value chain, not the topic list. For a bank or insurer, upstream and downstream boundaries are where most impact and financial materiality actually sit: financed emissions, customer conduct outcomes, third-party technology dependencies, underwriting exposures. If your scope stops at own operations, the assessment will not survive first review.

Use the ESRS topical standards or SASB industry set as a starting inventory, then add sector-specific items your competitors and regulators are already discussing. For financial services, that typically means climate transition risk in the loan book, biodiversity exposure through corporate lending, human rights in supply chain finance, financial inclusion, data ethics, and workforce culture.

Separate Impact and Financial Materiality Before Combining Them

The most frequent methodological error is running a single blended score. ESRS 1 is explicit: the two lenses are assessed independently, then a topic is material if it meets either threshold.

For impact materiality, score severity (scale, scope, irremediability) and likelihood across actual and potential impacts. For financial materiality, score the magnitude and probability of effects on cash flow, cost of capital, access to finance, and reputation over short, medium, and long horizons. Document your thresholds numerically. "High" and "medium" without definitions will not withstand assurance.

Choose Stakeholders Deliberately, Not Conveniently

Stakeholder engagement is where most assessments become indefensible. Sending a survey to your existing investor relations list and a handful of NGOs you already know is not engagement, it is confirmation. Regulators reviewing your process will ask how you identified affected stakeholders, particularly those who cannot self-advocate: future generations, communities affected by financed activities, workers in supplier operations.

Build a stakeholder map that distinguishes affected stakeholders (whose interests you must consider for impact materiality) from users of the sustainability statement (investors, lenders, rating agencies). The methods differ: interviews and proxy representation for the first, structured input for the second.

Build the Evidence File as You Go

Every scoring decision needs a source. That means climate scenario outputs tied to specific topics, litigation and enforcement data for conduct topics, internal loss data for operational resilience, and named stakeholder inputs with dates. If a topic moves from non-material to material between cycles, the trigger must be documented.

What good looks like: a materiality register that maps each material topic to the relevant risk in the enterprise risk taxonomy, the owning executive, the disclosure location, and the KPI reported to the board. If any of those four are missing, the topic is not really being managed.

Govern It Properly

The board or a designated committee must review and approve the material topics, and the minutes must reflect genuine challenge, not ratification. Common weak points auditors flag: no evidence of alternatives considered, no discussion of topics excluded, no linkage to strategy discussions. Bring the assessment to the board with the borderline topics highlighted, not just the shortlist.

What to Do Next

If you are within twelve months of a CSRD reporting obligation or an equivalent assurance milestone, commission an independent readiness review of your current materiality methodology before you refresh it. The gap between what companies believe is defensible and what auditors accept is the single biggest source of restatement risk in this cycle.

Frequently Asked Questions

How often should the assessment be refreshed?

Annually for review, with a full re-run every two to three years or sooner if the business, value chain, or external context shifts materially. Document the rationale for either decision.

Can we combine ESRS and ISSB assessments?

You can run a single process, but you must be able to show the impact materiality lens separately for ESRS. ISSB alone will not satisfy CSRD assurance.

Who should own the process internally?

Sustainability leads the methodology, risk owns the integration with the enterprise risk framework, finance owns the connection to financial planning, and the board owns approval. Fragmented ownership without a single accountable executive is where assessments drift.

What is the biggest red flag in a completed assessment?

A topic list that looks identical to peers with no company-specific topics, and no topics that are uncomfortable to disclose. Both suggest the process optimised for presentation rather than truth.

Frequently asked questions

How often should the assessment be refreshed?

Annually for review, with a full re-run every two to three years or sooner if the business, value chain, or external context shifts materially. Document the rationale for either decision.

Can we combine ESRS and ISSB assessments?

You can run a single process, but you must be able to show the impact materiality lens separately for ESRS. ISSB alone will not satisfy CSRD assurance.

Who should own the process internally?

Sustainability leads the methodology, risk owns the integration with the enterprise risk framework, finance owns the connection to financial planning, and the board owns approval. Fragmented ownership without a single accountable executive is where assessments drift.

What is the biggest red flag in a completed assessment?

A topic list that looks identical to peers with no company-specific topics, and no topics that are uncomfortable to disclose. Both suggest the process optimised for presentation rather than truth.

Related guides

Regulation & Regulatory Change

How to Structure a Board Diversity Disclosure That Satisfies the FCA Without Inviting Activist Scrutiny

This guide sets out how to draft a Listing Rule 6.6.6R(9) and (10) diversity disclosure that meets FCA expectations while managing exposure to activist investors, proxy advisers, and campaign groups. After reading, you will know how to sequence the numerical disclosure, contextual narrative, and forward statements to satisfy regulators without creating avoidable hostages to fortune.

Regulatory submissionRegulatorsInvestors
4 min readRead guide →
Regulation & Regulatory Change

How to Structure a Pillar 3 Remuneration Disclosure for PRA and Proxy Scrutiny

A practical guide to drafting a Pillar 3 remuneration disclosure that satisfies PRA supervisors while surviving ISS, Glass Lewis and institutional investor challenge. Read this to understand how to sequence the narrative, reconcile the two audiences, and avoid the disclosures that most often trigger follow-up.

Regulatory submissionRegulatorsInvestors
4 min readRead guide →
Regulation & Regulatory Change

How to Prepare a Regulatory Filing With Stakeholder Risk Assessment

A practical guide for senior leaders on integrating stakeholder risk assessment into a regulatory filing so it reads as evidence of genuine control, not compliance theatre. After reading, you will know how to sequence the work, what to include, and where filings typically fall short under supervisory review.

Regulatory submissionRegulatorsBoards
4 min readRead guide →
Regulation & Regulatory Change

Structuring a Section 178 Notification That Withstands PRA Group Structure Review

This guide sets out how to prepare a Change in Control notification that presents the acquirer's group with the clarity, completeness, and supervisory logic the PRA expects. After reading, you will know how to sequence disclosures, frame group complexity honestly, and engage the regulator in a way that supports timely approval on the merits.

Regulatory submissionAcquisitionRegulators
4 min readRead guide →
Boards, Governance & Defensibility

Structuring a PRA Senior Manager Attestation on Risk Framework Effectiveness

This guide sets out how to structure a Senior Manager attestation on the effectiveness of a firm's risk framework in a way that meets PRA supervisory expectations and stands up to later challenge. Readers will finish with a clear method for scoping, evidencing, qualifying, and signing an attestation that reflects the true state of the framework.

Regulatory submissionRegulatorsExecutive teams
4 min readRead guide →

Where internal confidence may exceed external evidence

Polar Insight helps leadership teams test critical assumptions against stakeholder, market, regulatory, and operational reality before risk compounds.

Explore Stakeholder Proximity