In the area of responsible corporate governance, it is also important to develop long-term sustainability strategies and ensure their operationalisation, implementation and monitoring.
Creating transparency, analysing risks and developing strategies
Above all, this includes taking care of the major risks associated with sustainability and identifying and assessing risks in a timely manner.
Creating transparency, analysing risks and developing strategies to ensure due diligence along the supply chain are also part of this area of responsibility, as are the expansion and implementation of circular economy strategies.
Our range of services
We support you with
- the development of a comprehensive ESG framework that includes ESG risks, business areas and lines of defence;
- the integration of ESG-related risks into its policies and procedures;
- the integration of the ESG framework into areas such as business unit strategies, risk management, third-party monitoring and the accountability of the Executive Board;
- adapting your policies when necessary to reflect changes in emerging risks, operating environments or activities.
Our portfolio includes professional consultancy services relating to CSR and sustainability:
- Integration of CSR and sustainability into governance systems - risk management, internal control system, compliance management system, internal audit
- Impact measurement and impact assessment: KPMG True Value
- Human rights & social compliance
- Climate (risk) management and reporting in accordance with TCFD
- Implementation and certification of management systems in the areas of environment, energy and occupational safety
- Technical audits (e.g. EU ETS, energy audits)
- Sustainable Supply Chain
More Insights on ESG Risk & Controls Services
Your contacts
Dr. Jan-Hendrik Gnändiger
Partner, Audit, Global & EMA ESG Reporting Advisory Lead, Head of ESG Germany, Head of Sustainability Reporting & Governance Germany
KPMG AG Wirtschaftsprüfungsgesellschaft
Eun-Hye Cho
Partner, Audit, Regulatory Advisory, Sustainability Reporting & Governance
KPMG AG Wirtschaftsprüfungsgesellschaft
Integrating ESG risk management into operational control
ESG risk encompasses sustainability-related events and developments that may affect a company’s business model, financialfinancial position, reputation or the achievement of a company’s objectives. Effective ESG risk management links these risks to clear responsibilities, robust data and transparent controls. Otherwise, particularly in decentralised organisational structures, gaps can arise between sustainability strategy, risk management, specialist departments and reporting.
Companies therefore need a management framework that assesses ESG risks consistently and integrates them into existing governance systems. This includes defined risk categories, assessment criteria, thresholds, escalation procedures and regular reports to management and supervisory bodies. A materiality analysis can identify relevant areas of concern. For ongoing risk management, specific controls at the process, data and system levels are also required. Integration into a cross-organisational Corporate Risk Management framework supports consistent assessment and management.
From risk profile to ESG Risk Control Framework
An ESG Risk Control Framework links identified risks to business processes, data sources, control objectives, control activities and responsible parties. This mapping provides transparency regarding which measures mitigate a risk, how frequently a control is carried out and what evidence must be available to demonstrate that it has been carried out.
Controls may be designed to be either preventative or detective. Examples range from mandatory approvals and plausibility checks to automated data validation, deviation analyses and documented escalations. A risk-based approach is crucial: the frequency of controls and the scope of testing should be based on the significance, likelihood of occurrence and potential impact of the respective ESG risk. Existing structures in the area of Internal Controls provide a suitable starting point for this.
Ensure responsibilities, data and evidence are robustly structured
Clearly defined control owners coordinate the implementation, documentation and further development of the controls. In addition, data controllers should specify the systems from which ESG information is sourced, how it is processed and what quality checks are carried out. Consistent record-keeping facilitates internal reviews and creates a robust basis for external audits.
Manual interfaces, estimates and information from subsidiaries or third parties require particular attention. Standardised guidelines, harmonised data models and uniform control descriptions help to identify discrepancies at an early stage and address them in a targeted manner.
Integrating ESG risk into existing governance structures
To ensure consistent management, business units, the central ESG function, risk management, compliance, the internal control system and Internal Audit build upon a common risk framework. The operational departments are responsible for risks and controls within their processes. Monitoring functions define methods, collate information and scrutinise their adequacy. Internal Audit can carry out a risk-based assessment to determine whether governance and control mechanisms are functioning as intended.
Management reports should not consist solely of status updates. Meaningful key risk indicators, control deviations, outstanding actions and changes to the risk profile enable targeted management. If defined thresholds are exceeded, transparent escalation and decision-making processes are required.
Assess effectiveness and further develop ESG risk controls
An ESG risk control framework is not complete upon initial implementation. Regular design assessments and effectiveness tests reveal whether controls are appropriately designed and function reliably in day-to-day operations. Any weaknesses identified should be prioritised according to risk, addressed with appropriate measures, and tracked until they are rectified.
Frequently asked questions
ESG risk refers to risks arising from environmental, social and governance factors that may affect a company’s business model, financial position, reputation or ability to meet its objectives. These include, for example, climate, supply chain, human rights, governance and data risks.
ESG reporting prepares sustainability-related information for internal and external audiences. ESG risk management identifies, assesses and manages the underlying risks. Both areas should be linked through shared processes, responsibilities and data sources.
An ESG risk control framework comprises a structured risk taxonomy, defined control objectives, specific control activities, designated control owners and verifiable evidence. In addition, there are escalation procedures, reporting processes and regular effectiveness tests.
Firstly, an assessment is made as to whether a control is appropriately designed and addresses the associated risk. Subsequently, spot checks, document reviews or data analyses reveal whether the control was reliably implemented within the intended timeframe.
ESG Risk Advisory is particularly useful where responsibilities are unclear, data sources are inconsistent, or ESG controls have not yet been systematically documented and reviewed. New business models, changing risk profiles or increasing audit requirements may also necessitate further development.