Skip to main content
Category: Corporate Governance

Environmental, Social and Governance (ESG)

Also known as: ESG, Environmental, Social, and Governance, ESG criteria, ESG factors
Simply put

ESG stands for environmental, social, and governance, and refers to a set of standards used to consider how an organization operates in relation to the planet and its people. It is commonly used to measure an organization's societal and environmental impact alongside its governance practices. Investors and companies may use ESG as a framework for assessing non-financial impacts, risks, and opportunities.

Formal definition

Environmental, Social and Governance (ESG) is a broad framework for identifying, assessing, and reporting environmental, social, and governance issues in the context of business and investment. It is commonly applied as a balanced scorecard for non-financial impacts, risks, and opportunities, and is also used as an investing principle that prioritizes environmental issues, social issues, and corporate governance considerations. The three components are analytically distinct: the environmental and social dimensions concern an organization's external impacts on the planet and people, while the governance dimension overlaps with the governance pillar of GRC insofar as it addresses corporate oversight structures, decision rights, and accountability. Specific ESG standards, disclosure obligations, and metrics vary by jurisdiction, sector, and applicable regulatory or voluntary reporting regime; this entry does not cover particular frameworks, disclosure requirements, or implementation methods.

Why it matters

ESG has become a significant reference point for how organizations articulate and are assessed on their non-financial impacts, risks, and opportunities. Because it spans environmental and social externalities as well as corporate governance, it sits at the intersection of investor expectations, stakeholder scrutiny, and, in many jurisdictions, evolving disclosure regimes. For governance professionals, the governance component of ESG overlaps directly with the oversight structures, decision rights, and accountability mechanisms already central to GRC, while the environmental and social dimensions typically extend the organization's attention outward to its impacts on the planet and people.

Who it's relevant to

Governance professionals and boards
The governance component of ESG overlaps with the governance pillar of GRC, addressing oversight structures, decision rights, and accountability. Boards and governance teams may use ESG framing to consider how the organization operates in relation to the planet and its people alongside established corporate governance practices.
Risk managers
ESG is commonly applied as a means of identifying and assessing non-financial risks and opportunities that financial reporting alone may not surface. Risk functions may use it as a balanced scorecard to consider environmental and social impacts in addition to governance-related exposures.
Compliance and disclosure specialists
Because ESG-related disclosure obligations vary by jurisdiction, sector, and applicable regulatory or voluntary regime, compliance professionals are typically concerned with identifying which specific requirements apply to their organization. ESG as a concept does not itself prescribe those obligations.
Investors and investment analysts
ESG is used as an investing principle that prioritizes environmental, social, and corporate governance considerations, and as a framework for assessing non-financial impacts, risks, and opportunities. Investors may apply ESG factors when evaluating organizations alongside financial analysis.

Inside ESG

Environmental (E) component
Addresses an organization's interactions with the natural environment, commonly including matters such as greenhouse gas emissions, energy and resource use, waste and pollution, water management, and impacts on biodiversity. The specific factors that are material vary by industry and jurisdiction.
Social (S) component
Concerns relationships with people and communities, commonly encompassing labor practices, health and safety, diversity and inclusion, human rights in operations and supply chains, customer and product responsibility, and community engagement. Materiality of these factors differs across sectors and regions.
Governance (G) component
Relates to the structures, roles, and decision rights that direct and oversee an organization, such as board composition and independence, executive remuneration, business ethics, and oversight of ESG-related matters. This pillar overlaps with corporate governance concepts but is scoped here to how governance supports and oversees ESG performance and disclosure.
ESG disclosure and reporting
The practice of communicating ESG-related information to stakeholders, which may follow voluntary frameworks or, in some jurisdictions, mandatory reporting requirements. Applicable standards and obligations vary by jurisdiction, sector, and organization size, and continue to evolve.
Materiality assessment
The process of determining which ESG topics are significant enough to warrant management attention and disclosure. Approaches differ; some frameworks focus on financial materiality to the organization, while others also consider the organization's impacts on people and the environment.
ESG risk considerations
The identification, assessment, and treatment of uncertainties arising from ESG factors against organizational objectives. This situates ESG within risk management practice, though ESG itself spans governance, risk, and compliance rather than being confined to any single pillar.

Common questions

Answers to the questions practitioners most commonly ask about ESG.

Is ESG the same as corporate sustainability or ethical investing?
Not precisely. ESG refers to a set of environmental, social, and governance factors used to describe and assess how an organization manages related risks and impacts, often in the context of investment analysis and non-financial disclosure. Corporate sustainability is a broader organizational concept, while ethical or values-based investing reflects specific investor preferences. ESG is commonly used as an analytical and reporting lens rather than a single defined program, and its meaning can vary by user and context.
Does a strong ESG rating mean an organization is compliant and low-risk?
No. An ESG rating is an assessment produced by a rating provider using its own methodology and data sources, and methodologies differ across providers, so scores are not directly comparable. A rating reflects one provider's view of certain factors and does not confirm compliance with any specific law, regulation, or standard, nor does it guarantee low risk. Compliance obligations and risk exposure should be assessed separately against the applicable requirements and the organization's own risk framework.
How does ESG relate to an organization's existing GRC structures?
ESG topics typically map across all three GRC pillars rather than forming a separate silo. The governance dimension often connects to existing board oversight, decision rights, and accountability structures; the environmental and social dimensions frequently surface as risks to be identified, assessed, and treated within the risk management process; and disclosure and conduct expectations may create compliance obligations depending on jurisdiction and sector. Many organizations integrate ESG considerations into existing governance, risk, and compliance processes rather than building parallel ones. This entry does not cover specific integration tooling or implementation designs.
Which functions are commonly involved in managing ESG matters?
Responsibilities often span multiple functions and lines of accountability. Operational and business functions that own the underlying activities commonly sit in the first line; risk, compliance, sustainability, and disclosure functions may provide oversight and challenge in the second line; and internal audit may provide independent assurance over ESG-related processes and reporting as a third-line activity. It is important to keep assurance activities distinct from the management activities being assured. Specific allocation of roles varies by organization size, sector, and structure.
What should organizations consider when preparing ESG disclosures?
Considerations commonly include which reporting frameworks or regulatory requirements apply, as these depend on jurisdiction, sector, listing status, and organization size and can differ significantly across regions. Organizations frequently consider the reliability and traceability of underlying data, the consistency of definitions and boundaries used, and whether disclosures are subject to internal or external assurance. Because requirements are evolving in many jurisdictions, this entry does not state specific mandatory disclosure obligations, which should be confirmed against the applicable rules and, where appropriate, with qualified advisers.
How can ESG factors be incorporated into risk assessment?
ESG factors are often treated as potential sources of risk that can be identified, assessed, and treated within an organization's existing risk management process, consistent with the approach described in widely used risk frameworks. This may involve considering how environmental, social, or governance-related uncertainties could affect stated objectives, and evaluating both inherent and residual exposure after any controls are applied. The relevance and materiality of specific factors typically depend on the organization's context, sector, and stakeholders. Detailed assessment methodologies and control design are outside the scope of this entry.

Common misconceptions

ESG is essentially the same as corporate social responsibility (CSR) or sustainability under a new name.
While the concepts overlap, ESG is commonly used to organize environmental, social, and governance factors in a structured way that is often linked to disclosure, risk assessment, and stakeholder communication. It is not simply a rebranding, and the terms may carry different scopes and expectations depending on context.
ESG reporting is a single, universal, mandatory standard that applies the same way to all organizations.
ESG reporting obligations and frameworks vary by jurisdiction, industry, and organization size. Some regimes are voluntary and others mandatory, and the applicable requirements continue to evolve. Presenting any one regime as universal misrepresents the landscape.
The governance component of ESG is separate from and unrelated to an organization's broader governance structures.
The governance pillar of ESG draws on the same structures, roles, and decision rights that direct and oversee an organization. It is best understood as how that governance supports and oversees ESG matters, rather than a distinct or standalone governance system.

Best practices

Conduct a materiality assessment to identify which ESG topics are significant to your organization's sector, jurisdiction, and objectives, and revisit it as circumstances change.
Confirm which ESG disclosure obligations and frameworks apply to your organization given its jurisdiction, industry, and size, rather than assuming a single universal requirement.
Integrate ESG factors into existing risk management processes so that ESG-related uncertainties are identified, assessed, and treated against objectives consistently with other risks.
Clarify board and management oversight roles for ESG matters, keeping decision rights and accountability explicit within existing governance structures.
Distinguish clearly between the environmental, social, and governance components when defining metrics and controls, noting where a topic spans more than one pillar.
Keep assurance over ESG information independent from the management activities that generate that information, so that objectivity and independence distinctions are preserved.
a promotional banner asking how ready are you for PCI DSS 4.0? With a call-to-action to get the checklist now.