← Back to blog

Seven Step ESG Risk Assessment Aligned with EBA and COSO for Risk Teams

September 15, 2026
Seven Step ESG Risk Assessment Aligned with EBA and COSO for Risk Teams

An ESG risk assessment is a structured process that identifies, scores, and documents environmental, social, and governance risks across an organization's operations and value chain. The direct output is a prioritized, auditable risk register paired with key risk indicators (KRIs) and mitigation plans that feed directly into enterprise risk management. Done correctly, it satisfies the regulatory expectation of a long-term outlook, not just a snapshot of current exposure.


TL;DR:

  • A comprehensive ESG risk assessment must differentiate among environmental, social, and governance risks to prioritize effectively.
  • Risks are mapped across the entire value chain, with physical risks like climate hazards requiring geospatial data and social risks focusing on supplier conditions.
  • Regulators demand a double materiality approach, assessing both financial impacts and environmental or social effects over at least a 10-year horizon.
  • Embedding ESG into existing risk frameworks requires board ownership, clear KRIs, and connection to internal controls to ensure actionable governance.
  • Starting small with pilot projects, centralizing data, and obtaining targeted training ensures credible assessments that withstand external scrutiny.

Esgtraininginstitute
Build Stronger ESG Risk Skills
Develop practical competence in climate strategy, carbon accounting, and sustainable finance through standards aligned ESG training.
Explore ESG training

Table of Contents

What Does an ESG Risk Assessment Actually Cover?

ESG risk spans three distinct categories, and treating them as one undifferentiated bucket is where most assessments go wrong. Environmental risk covers physical hazards (flooding, water stress, extreme heat) and transition risk (carbon pricing, stranded assets, shifting energy costs). Social risk covers labor practices, community relations, product safety, and human rights exposure across suppliers. Governance risk covers board oversight, executive accountability, bribery and corruption controls, and data integrity.

Each category needs to be mapped across three points in the value chain: upstream (suppliers and raw materials), operations (your own facilities and workforce), and downstream (customers, product use, disposal). A garment manufacturer's biggest social risk usually sits upstream, in a supplier's factory conditions rather than in its own headquarters.

ESG has become an enterprise risk issue for a concrete reason: regulators and investors now expect it to be treated with the same rigor as credit or market risk, highlighting the differences between ISR, ESG et investissement catholique in sustainable finance. The EBA's guidelines on managing ESG risks require institutions to embed ESG identification, measurement, and monitoring into existing internal processes rather than running it as a side project.

The business impacts are concrete, not theoretical:

  • Operational disruption from physical climate events (flooded plants, disrupted logistics routes)
  • Regulatory fines for non-compliance with disclosure or environmental standards
  • Reputational loss following supplier labor violations or governance scandals
  • Higher cost of capital when investors flag unmanaged transition risk

How Do You Conduct an ESG Risk Assessment?

A repeatable ESG risk assessment methodology follows seven steps, each with a defined output you can hand to auditors or board committees. This sequence mirrors the structured workflows used across industry step-by-step guides and adapts them to enterprise risk management standards.

  1. Map the value chain. Document upstream suppliers, operating sites, and downstream product flows. Output: a value-chain map with geographic and sector tags.
  2. Identify candidate risks. Pull from regulatory checklists, sector-specific hazard databases, and internal incident history. Output: a long list of candidate ESG risks, unscreened.
  3. Gather data. Combine internal data (energy use, incident logs, supplier audits) with external sources (climate hazard models, sanctions lists, NGO reports). Output: a data inventory with source and confidence rating per risk.
  4. Score likelihood and impact. Apply a consistent scale, typically 1 to 5, aligned with your existing ERM likelihood/impact framework so ESG risks sit on the same scale as operational or credit risks. Output: a scored risk list.
  5. Prioritize through double materiality. Filter scored risks by both financial materiality (impact on the business) and impact materiality (impact on people and the environment). Output: a materiality matrix.
  6. Design mitigation. For each material risk, assign an owner, a control, and a target timeline. Output: mitigation plans linked to risk register entries.
  7. Monitor and report. Set KRIs with thresholds, assign a reporting cadence, and prepare documentation for internal or external assurance. Output: a live risk dashboard.

A sample risk register row looks like this: Risk type: physical (flood exposure, Tier 1 supplier, Southeast Asia); Likelihood: 3; Impact: 4; Owner: procurement director; Mitigation: dual-sourcing plan by Q3; KRI: percentage of Tier 1 suppliers in flood zones with contingency contracts.

Quantitative scoring works well for physical risks with measurable exposure, like flood zones or water stress indices. Qualitative scoring fits governance risks that resist clean numeric proxies, like board independence or whistleblower program maturity. Scenario analysis belongs where time horizons stretch beyond typical planning cycles, particularly for transition risk tied to carbon pricing or policy shifts.

What Regulators Expect from a Materiality Assessment

Double materiality asks two questions at once: does this ESG issue affect the company's financial performance, and does the company's activity affect people or the environment on this issue? A risk can be material on either axis alone, which is why single-axis materiality assessments miss things regulators now expect institutions to catch.

The EBA's final guidelines require a combination of methodologies, not a single lens. Institutions need exposure-based screening for near-term risks, portfolio and sector-based analysis for medium-term concentration, and scenario-based testing for a long-term view stretching to at least 10 years. That 10-year floor is deliberate: it forces institutions to look past the current budget cycle into structural transition risk.

A sample materiality matrix plots axes of financial impact against stakeholder impact, with each risk plotted as a point. Risks landing in the top-right quadrant, high on both axes, become the priority list for the risk register.

Building an audit-ready process means documenting more than the conclusions. Practitioners should record:

  • The methodologies applied and why they were chosen for each risk category
  • Stakeholder groups consulted and how their input was weighted
  • Thresholds used to separate material from non-material risks
  • Written rationale for any risk excluded as non-material

Materiality reviews are not a one-time exercise. Best practice ties updates to an annual cycle plus triggers, such as a major acquisition, a new regulatory requirement, or a significant supply chain shift, with the EBA's guidance treating this as institution-specific rather than fixed to a calendar date. A double materiality assessment under ESRS framework gives a useful reference point for structuring stakeholder input and scoring axes.

Embedding ESG Risk into Your Control Framework

Assessment results only matter if they change how the organization operates day to day. That means folding ESG risk into existing risk appetite statements, assigning named owners for each material risk, and running ESG scenarios through the same internal capital adequacy processes (ICAAP-style, where applicable) used for other enterprise risks.

COSO's guidance on applying ERM to ESG risks breaks integration into five components: governance and culture, strategy and objective-setting, risk identification and prioritization, controls and review, and information and reporting. Skipping the governance step is the most common failure. Without board-level ownership, ESG risk data tends to stay in a sustainability team's spreadsheet instead of reaching the risk committee.

Sample KRIs with amber/red thresholds might include:

  • Percentage of critical suppliers audited in the past 12 months (amber below 80%, red below 60%)
  • Carbon price sensitivity of EBITDA under a $100/ton scenario
  • Number of unresolved governance control failures past their remediation deadline

Governance roles should mirror the three-lines model: business units own the risk, a second-line function sets and challenges methodology, and internal audit tests whether controls actually work. A robust ESG control framework built on a centralized data hub and verifiable calculations is what makes ESG reporting defensible under external assurance rather than a collection of claims.

Pro Tip: Route ESG KRIs onto the same risk dashboard your operational and credit risk teams already use. A separate ESG dashboard almost guarantees the board reviews it separately, and separate review is how ESG risk stays disconnected from capital allocation decisions.

Choosing Metrics and Running Scenario Analysis

Physical and transition risks need different KRIs because they behave on different timelines. Physical risk KRIs track exposure today: percentage of facilities in high water-stress zones, insured losses from extreme weather events. Transition risk KRIs track exposure to policy and market shifts: carbon price sensitivity, percentage of revenue tied to high-emission product lines.

Useful threshold examples:

  • Green: a low proportion of Tier 1 suppliers in high physical-risk zones
  • Amber: a moderate proportion, triggering enhanced monitoring
  • Red: a significant proportion, triggering mandatory mitigation planning

Scenario analysis works best run across multiple time horizons at once, not just one. The EBA guidance points to scenario-based and portfolio-alignment methods as the tools for testing resilience across short, medium, and long-term windows. A three-degree warming scenario tells you something different at year 3 than at year 15, and both numbers belong in the same report.

Monitoring only earns trust when it connects to a fixed reporting cadence and, ideally, external assurance review, which is what turns an internal tracking exercise into decision-useful information for the board and investors.

Tools, Templates, and Supplier Risk Assessment

A workable risk register template needs consistent fields across every entry: risk type, value-chain location, likelihood, impact, financial materiality, impact materiality, mitigation owner, target date, and linked KRI. Supplier assessments should use the same fields, plus a data source column, so an auditor can trace every score back to its origin.

Structured ESG risk register illustration

Choose geospatial hazard models when you need location-specific physical risk data, such as flood or drought exposure for a specific facility address. Choose vendor ESG data platforms when you need broad supplier coverage across governance and labor indicators that don't reduce to coordinates. Benchmarking approaches like S&P Global's Corporate Sustainability Assessment methodology show how industry-specific scoring and disclosure analysis can standardize comparisons across a supplier base.

The most common pitfall is disconnected data: transition risk data sitting in a sustainability team's file while operational risk controls live in a separate system. Insiders in ESG risk practice note that failing to connect external-facing risks with internal controls weakens mitigation planning before it starts. Fix this by assigning one data owner responsible for reconciling both sides before scores enter the register.

What Practitioners Get Wrong When Starting Out

Most teams start with a framework debate and never finish it. Skip that and centralize your data first: one hub, one set of definitions, one named owner for each risk category before you touch a scoring template.

Run your first full assessment on a single business unit or a handful of critical suppliers, not the whole enterprise. A contained pilot surfaces data gaps and governance friction cheaply, and those lessons scale far better than a company-wide rollout built on untested assumptions.

Training closes the last gap. Risk owners who understand materiality thresholds and assurance practitioners who know what auditors will actually test are what separate a credible ESG risk assessment from a slide deck. A double materiality assessment resource and a look at what ESG auditors need in 2026 are reasonable starting points before committing to a full training path.

— Ransford

Build Assessment Skills Through Esgtraininginstitute Certification

Reading a methodology is one thing. Running it under audit scrutiny, defending your materiality thresholds to a risk committee, and setting KRIs that assurance practitioners will actually accept is another. Certification pathways are offered to close that gap, built directly around the steps this article walks through.

Esgtraininginstitute

Certification tracks cover ESG fundamentals and materiality logic for professionals new to the discipline; deeper topics such as risk scoring, carbon accounting, and climate scenario methodology for risk managers and sustainability leads running live assessments; assurance-focused content for internal auditors and assurance practitioners testing ESG controls with rigor applied to financial reporting; and corporate workshops allowing risk teams to train together on a shared methodology rather than learning it in silos.

Each pathway maps to a stage of the seven-step process: materiality scoring, KRI design, control documentation, and assurance readiness. Review the accreditation pathways to find the certification that matches your current role and start building the credential your next assessment cycle will need.

Sources

FAQ

What Is ESG Risk Assessment?

An ESG risk assessment is a structured process to identify, score, and monitor environmental, social, and governance risks that could affect an organization's financial performance or long-term operations. The output is typically a prioritized risk register with linked KRIs and mitigation plans.

Is ESG Still Relevant in 2026?

Yes. Regulatory frameworks like the EBA's ESG risk management guidelines and reporting standards continue to expand, and investors increasingly price transition and physical risk into cost of capital, making ESG assessment a standard component of enterprise risk management rather than a voluntary add-on.

What Is an ESG Assessment?

An ESG assessment evaluates a company's exposure to environmental, social, and governance risks and, in many frameworks, its impact on the environment and society through double materiality analysis. It typically results in a materiality matrix and a scored list of priority risks.

What Does ESG Stand For?

ESG stands for environmental, social, and governance, the three risk categories used to evaluate a company's sustainability exposure and practices. Each category covers distinct risk types, from physical climate hazards to labor conditions to board oversight.

How Often Should an ESG Risk Assessment Be Updated?

Most organizations run a full materiality review annually, with additional updates triggered by events like acquisitions, new regulations, or major supply chain changes. Documentation should capture the rationale for both material and non-material conclusions at each update.