ESRS G1: Business Conduct·Disclosure Requirement G1-1
Policies (Business Conduct)
Practical guidance for preparing this disclosure. Use this card to identify the information to prepare, verify claims and organise supporting evidence. For exact requirements, always refer to the official European Commission source.
Published passport
Review pendingStandard
ESRS G1: Business Conduct
Disclosure Requirement G1-1 · 2026-5010-final
Last reviewed
—
LRA educational guidance · Not issued or endorsed by European Commission
Disclosure focus
This disclosure asks an organisation to explain whether it has formal policies that set expectations for business conduct, and how those policies are used in practice. The focus is not just on saying a policy exists, but on showing what it covers, who it applies to, and whether it is embedded in day-to-day decision-making rather than sitting only on paper.
In practical terms, the organisation should think about coverage across the whole business, not only a few flagship sites or headquarters functions. A useful report will make clear whether the policy applies group-wide, to specific entities, operations or activities, and whether there are any important gaps, exceptions or differences in implementation across locations or parts of the business.
This LRA educational guidance supports disclosure preparation. For the exact requirements, always refer to the official European Commission source.
Before you start
Before you start
A quick mental checklist before you prepare this disclosure — tick each as you settle it.
Preparation
Key information to prepare
| Preparation field | What to capture | Evidence hint | Owner |
|---|---|---|---|
| Policy title | The exact name used for the policy in the organisation’s records, as approved and currently in use. | Approved policy register, intranet policy page, or board/management paper showing the current title. | Legal / Compliance |
| Policy coverage | A plain description of what the policy applies to, including the business areas, activities or entities it covers. | Policy scope section, group policy framework, or entity applicability matrix. | Legal / Compliance |
| Coverage share | The proportion of the organisation’s own operations and relevant upstream or downstream activities that fall within the policy’s reach, expressed as a number. | Coverage assessment, operational boundary mapping, or value-chain scoping workbook. | Sustainability / Risk |
| Policy aims | The main outcomes the policy is intended to achieve, stated in business terms and aligned to the approved document. | Policy objectives section, strategy paper, or management approval pack. | Sustainability / Strategy |
| Anti-bribery policy | Whether the organisation has a formal policy covering bribery and corruption prevention. | Approved anti-bribery or anti-corruption policy, policy register, or compliance framework. | Legal / Compliance |
| UN alignment | Whether the anti-corruption policy is stated to align with the United Nations approach referenced by the organisation. | Policy text, approval paper, or compliance statement showing the stated alignment. | Legal / Compliance |
| Speak-up policy | Whether there is a formal policy that lets people raise concerns or report wrongdoing through a whistleblowing route. | Whistleblowing policy, speak-up procedure, or ethics hotline policy. | Legal / Compliance |
| Whistleblower law coverage | Whether that whistleblowing policy is framed to cover the legal protections or requirements that apply in the relevant jurisdictions. | Policy wording, legal review note, or jurisdictional compliance mapping. | Legal / Compliance |
| Sensitive roles | The job families, functions or positions that are treated as higher exposure to bribery or corruption risk. | Risk assessment, role-based controls matrix, or anti-corruption training scope. | Risk / Compliance |
| Risk countries | The countries or territories identified as higher risk for bribery or corruption exposure in the organisation’s assessment. | Country risk assessment, third-party risk map, or compliance risk register. | Risk / Compliance |
| Public-sector exposure | A description of where the organisation’s activities involve contact with public officials, regulators or other public bodies. | Government interaction log, sales pipeline notes, licensing records, or public affairs register. | Risk / Compliance |
How to prepare it
Request the data
Request the business conduct policy pack and coverage details
Translate the disclosure into an internal business question — then adapt it to your organisation's own language.
Which policies and related coverage details do we need to describe our business conduct controls for the reporting period?
Use your organisation’s own policy names, control labels and team names first, then map them to the reporting disclosure. Keep the ask in everyday internal language rather than framework wording, and check the source documents before sign-off.
Weak request
Please provide the ESRS G1:G1-1 policy disclosures, including the policy name, scope, coverage, objectives, anti-corruption alignment, whistleblower coverage, high-risk functions, high-risk countries, and exposure to public authorities.
Why it fails: This uses framework language that many internal owners will not use day to day, so it is harder to route and answer quickly. It also bundles several concepts without telling the owner which documents to pull, where to look, or how to describe the business areas in their own terms.
Better request
Please send the latest business conduct policy documents and a short summary covering: the document names, what each one is for, which parts of the business or group they apply to, whether we have an anti-bribery / corruption policy, whether we have a speak-up policy and who it covers, which roles or locations carry higher exposure, which markets we treat as higher risk, and where we deal with public bodies or officials. Use our internal terms first, then we will map them to the reporting disclosure. Please check the source documents before sign-off.
Formal email template
Subject: Request for policy pack and coverage details for [reporting period] Hi [name], We are pulling together the evidence pack for our [reporting period] sustainability reporting. Could you please send the current documents and a short summary for the business conduct policy area? Please include: - the policy name(s) - what each document covers - which parts of the business or group are included - the main aims of each document - whether we have a policy covering anti-bribery / corruption matters - whether we have a speak-up / whistleblowing policy - whether the speak-up route covers the relevant legal entities and workers we need to include - the roles, functions and locations that carry higher exposure - any countries or markets we treat as higher risk - any areas where we deal directly with public bodies or officials If it is easier, you can send a link to the latest approved version plus a short note confirming the points above. Please use our internal terms where possible, and we will map them to the reporting disclosure. Please also check the source documents before sign-off. Thanks, [preparer name]
Short Teams / Slack version
Hi [name] — could you share the latest policy docs and a short note on scope, coverage, aims, higher-risk roles/locations, and any public-sector touchpoints for [reporting period]? Please use our internal terms. We’ll map them to the reporting disclosure and check the source docs before sign-off. धन्यवाद / Thanks, [preparer name]
Industry examples
Manufacturing
Context. A group with overseas sales teams, customs activity and third-party distributors.
Adapted request. Please share the latest ethics, anti-bribery and speak-up documents, plus a short note on which plants, sales teams, distributors and countries they cover, and where we have customs, licensing or other public-authority touchpoints.
Example response. Policy pack includes the Code of Conduct, Anti-bribery Policy and Speak-Up Policy. Coverage: group-wide for employees and contractors; distributor clause applies to appointed third parties. Higher-exposure roles: export sales, customs brokerage, tendering and government account managers. Higher-risk markets: Country A, Country B and Country C. Public-authority touchpoints: customs clearance, import permits and local licensing.
Financial services
Context. A regulated business with client onboarding, market-facing teams and a formal speak-up channel.
Adapted request. Please provide the conduct, anti-bribery and speak-up documents, and confirm which legal entities, client-facing teams and overseas offices they cover, plus any roles with higher exposure and any dealings with regulators or public bodies.
Example response. Documents: Conduct Policy, Anti-Corruption Standard and Speak-Up Procedure. Coverage: all regulated entities and employees; contractors included in the speak-up route. Higher-exposure roles: onboarding, relationship management, procurement and public-sector sales. Higher-risk locations: Region X and Region Y. Public-authority touchpoints: licensing, supervisory reviews and permit applications.
Draft your disclosure
Notes that turn data into a disclosure
LRA training templates — adapt them to your organisation, and check the official source before sign-off.
Method note
This disclosure can explain which policies were reviewed, how the organisation defined their scope and coverage, and what counts as a high-risk role, location or external exposure for the purposes of the data set.
Context note
Taken together, these data points show whether the organisation has formal controls in place, how far they extend across operations and the value chain, and where the main corruption-related risk areas are concentrated.
Fluctuation statement
If the figures or coverage changed from the prior period, the reporter can attribute that to policy updates, a broader or narrower scope, changes in the list of higher-risk roles or countries, or a revised view of exposure to public authorities.
Content index entry
G1-1 Policies (Business Conduct) — [location / page] / [notes]Download Centre
Preparation tools & forms
Professional preparation tools for G1-1 — free with an LRA Community membership. Register once (it's free) and every download unlocks, together with the Disclosure Library, templates and the LRA AI Assistant.
Assurance readiness
For each claim, check the evidence
| Claim | Risk | Evidence to check |
|---|---|---|
| We limited the coverage figure to the parts of the business we had actually reviewed for this topic, and we can show how we decided what was in and what was left out. | An assurer will probe whether the boundary was set consistently, whether any relevant entities, sites or activities were omitted, and whether the inclusion/exclusion logic was applied in the same way across the reporting period. | ['Boundary-setting memo or reporting note showing the inclusion/exclusion rules used for the figure', 'List of entities, sites, functions or activities included in the review, with reasons for any exclusions', 'Internal sign-off or review trail confirming the boundary decision'] |
| We based the disclosed figure on the operations and roles we had mapped as higher exposure areas, and we kept the underlying mapping so it can be traced back. | An assurer will test whether the higher-risk areas were identified using a clear method, whether the mapping was complete, and whether the disclosed scope matches the underlying risk assessment. | ['Risk assessment or mapping document identifying the higher-exposure functions, roles, locations or activities', 'Source data or registers used to build the mapping', 'Version-controlled working papers showing how the disclosed scope was derived from the risk assessment'] |
| Where we used a defined term in the disclosure, we applied the same internal meaning throughout and checked that the wording matched our source materials. | An assurer will look for inconsistent use of key terms, a mismatch between the narrative and the source definition, or a definition that was applied selectively. | ['Internal glossary or policy definitions used for the disclosure', 'Draft-to-final comparison showing consistent use of the term', 'Review notes confirming the wording was checked against the source definition'] |
| For the policy information, we pulled together the policy name, what it covers, where it applies, and what it is meant to achieve, then checked that each part was stated clearly. | An assurer will test whether the policy description is complete, whether the stated coverage matches the actual policy documents, and whether the objectives are supported by the underlying text. | ['Current policy documents and any related procedure documents', 'Summary table linking each policy to its scope, coverage and stated purpose', 'Management review or legal/compliance review confirming the summary is accurate'] |
| We confirmed that the anti-corruption and anti-bribery policy set was current and aligned with our internal framework before we published the disclosure. | An assurer will probe whether the policy was actually in force, whether it covered the relevant risks, and whether the disclosure overstates the maturity or completeness of the policy set. | ['Approved anti-corruption and anti-bribery policy documents with effective dates', 'Policy review or approval records showing the latest update cycle', 'Cross-check between the disclosure and the policy text'] |
| We checked that the whistleblowing policy was in place and active at the reporting date, and we retained the approval trail and version history. | An assurer will test whether the policy existed at the relevant date, whether it was formally approved, and whether the disclosure is based on a current document rather than a draft or obsolete version. | ['Whistleblowing policy document with approval date and version control', 'Evidence of publication or internal communication of the policy', 'Document control records showing the policy was current at the reporting date'] |
Evidence pack to prepare
Common reporting gaps
Common gaps
Mistakes to avoid when collecting the data
Where judgement is often needed
Examples
Illustrative examples
Synthetic, written by LRA — not from a company report, not text from any standard.
We describe a group-wide anti-bribery and integrity policy that applies to our own sites and the parts of the supply chain where we have direct oversight, and it is aimed at preventing misconduct and supporting ethical conduct. The policy is built to align with the recognised sustainability principles, and we also maintain a separate speaking-up policy that covers employees and contractors and is intended to meet the legal protections available in the jurisdictions where we operate.
- The integrity policy covers 100% of our owned operations and 85% of tier-1 suppliers by spend; it is active across all business units.
- We identify 42 roles as more exposed to bribery risk, mainly procurement, sales, customs, logistics and government-facing managers; 18 of those roles sit in three higher-risk countries, and 12 roles regularly deal with public bodies.
Synthetic example for practitioner review only. It shows how to narrate the policy name, where it applies, what it is meant to achieve, whether the anti-corruption and speaking-up arrangements exist, whether the anti-corruption policy is aligned to the UN Compact, and which roles, countries and public-authority touchpoints are treated as higher risk.
Our compliance framework includes a gifts, hospitality and anti-corruption policy for the company and the controlled entities we manage, with the aim of reducing bribery risk and reinforcing fair dealing. We also run a confidential reporting policy that is designed to operate in line with local legal protections, and the anti-corruption policy is mapped to the recognised sustainability principles.
- The policy reaches 100% of our operating sites and 70% of our key intermediaries by contract coverage; it is intended for all staff and relevant third parties.
- We classify 27 positions as higher exposure, including customs brokers, fleet managers, tendering staff and country leads; 9 of those positions are in two higher-risk countries, and 7 positions involve routine contact with regulators or other public bodies.
Synthetic example for practitioner review only. It demonstrates a different sector and wording while still covering the policy title, who and what it applies to, the intended purpose, the existence of anti-corruption and whistleblowing arrangements, the UN alignment, and the main higher-risk roles, countries and public-authority interfaces.
Company reports
How companies report G1-1 in practice
Examples of full and partial reporting practice. These are evidence-led reviews, not exact disclosure templates to copy.
Ask the Study Studio AI Assistant about this disclosure
Get practical answers for your reporting context. Your first two answers are free — join LRA Community for free to continue without a limit.
Check your understanding
Scenarios to work through
A group finance team has one conduct policy for the parent company, but the overseas sales subsidiary uses a separate local code and the procurement team follows a third document. The reporting lead is deciding whether to describe one group-wide policy or several separate ones.
A preparer has a draft anti-bribery policy, but it only mentions employees and says nothing about agents, distributors, or other third parties used in sales. The team is unsure whether that is enough for the business conduct note.
The compliance team has a whistleblowing procedure for employees in the UK, but contractors in another country use a separate hotline run by a local provider. The reporting lead is deciding how to answer the policy question for the year-end report.
A multinational has identified customs brokers, public-sector sales contacts, and permit applications as the areas where conduct risk is highest. The draft note lists these activities, but it does not say which countries are most exposed or whether dealings with public bodies are part of the picture.
Framework references
Relevant ESRS requirements and related disclosures
Available framework references and nearby disclosures relevant to preparing this requirement.
ESRS
G1-1
within ESRS G1: Business Conduct
Related & explore
More in ESRS G1 → Browse full catalogue → Disclosure Library home → Search all disclosures →
FAQ
Questions this page answers
The page says to prepare the policy title, policy coverage, coverage share, policy aims, anti-bribery policy, UN alignment, speak-up policy, whistleblower law coverage, sensitive roles, risk countries and public-sector exposure. Use that list as your starting checklist before drafting.
Use it as a practical workflow to move from identifying the relevant policy and scope to collecting the supporting data and evidence. It is designed to help you prepare the disclosure rather than interpret the underlying standard.
The page points you to policy coverage and coverage share, so you should define what the policy applies to and how much of the business it covers. Keep the scope consistent with the rest of the datapoints you collect for the disclosure.
The page does not assign a single owner, so you need to decide ownership internally based on who holds the policy, the coverage data and the evidence. A practical approach is to name one accountable lead and then map supporting inputs from the relevant functions.
The page says there is an evidence pack with five items for assurance readiness. Use that pack to support the claims you make and to show where each datapoint came from.
The page says there are six assurance claims to verify, each linked to a claim, risk and evidence. Use those claims to test whether the disclosure is supported by the underlying records before you finalise it.
The page includes a list of common reporting gaps and mistakes, so use that as a pre-submission check. It is there to help you spot missing scope, weak evidence or inconsistent wording before the draft goes out.
The page has a draft-output section with visualisation ideas, narrative starters and a content-index line. Use those to turn the collected datapoints into a readable draft rather than starting from a blank page.
The Download Centre includes a Prep & Assurance workbook in .xlsx format and a printable Library Card in .pdf format. Use the workbook to organise the preparation and evidence, and the card as a quick reference while drafting or reviewing.
Yes. It includes a 'From company reports' table that links to real published reports at the pages where the topic is disclosed, which you can use as reference points when shaping your own draft.
The page includes synthetic illustrative example disclosures, including a quantitative table. Treat these as made-up examples for learning how the disclosure might look, not as reporting requirements.
More questions this page can help with
Go deeper · G1-1
Learn to prepare this disclosure end-to-end
This guide covers one Disclosure Requirement. The ESRS / CSRD Reporting course walks the full European workflow — double materiality, datapoints, evidence and assurance — with exercises on your own data.
Available as Guided Flex, Live Cohort, 1:1 Expert Mentorship or Corporate Programme.
Get your G1-1 tools — free
Your preparation tools are free for LRA Community members and students. Register once (it's free) and your download starts right away — plus the Disclosure Library, templates and the LRA AI Assistant.
You're in — your download is starting
Your file is downloading now. Your Community Cabinet — with the Disclosure Library, templates and the LRA AI Assistant — is ready too.
Open your Cabinet →