ESRS 2: General Disclosures·Disclosure Requirement GOV-4
Statement on Due Diligence
Practical guidance for preparing this disclosure. Use this card to identify the information to prepare, verify claims and organise supporting evidence. For exact requirements, always refer to the official European Commission source.
Published passport
Review pendingStandard
ESRS 2: General Disclosures
Disclosure Requirement GOV-4 · 2026-5010-final
Last reviewed
—
LRA educational guidance · Not issued or endorsed by European Commission
Disclosure focus
This disclosure asks the organisation to explain whether, and how, it carries out due diligence as part of its governance and decision-making. In practice, that means describing the main processes used to identify, assess, prevent, mitigate and track material impacts, risks and opportunities, rather than simply stating that a policy exists.
The practical focus is on the real scope and consistency of those processes across the business. Report whether due diligence applies across the whole organisation and value chain, or only to selected activities, regions or flagship sites, and explain any important gaps, exceptions or differences in coverage.
This LRA educational guidance supports disclosure preparation. For the exact requirements, always refer to the official European Commission source.
Before you start
Before you start
A quick mental checklist before you prepare this disclosure — tick each as you settle it.
Preparation
Key information to prepare
| Preparation field | What to capture | Evidence hint | Owner |
|---|---|---|---|
| Control framework overview | A plain description of how the reporting process is governed and controlled, including the main checks, approvals and responsibilities that sit around the data and reporting cycle. | Process maps, control narratives, RACI or responsibility matrix, approval workflow, internal control documentation. | Finance / Reporting Controls |
| Data checking process | How reported data is reviewed for accuracy and consistency before it is published, including the checks performed, who performs them and when they happen. | Validation checklists, review logs, exception reports, sign-off records, data quality rules. | Data Management / Reporting |
| Risk control measures | The controls used to manage reporting-related risks, covering the key risk areas identified and the actions in place to reduce or monitor them. | Risk register, control matrix, mitigation plans, monitoring reports, issue logs. | Risk Management / Internal Control |
| Estimation control methods | The methods and checks used when reported figures are estimated rather than directly measured, including how assumptions are set, reviewed and updated. | Estimation methodology, assumption papers, calculation files, review and approval records, model governance notes. | Finance / Technical Accounting |
How to prepare it
Request the data
Request the due diligence controls evidence
Translate the disclosure into an internal business question — then adapt it to your organisation's own language.
How do we describe the checks, controls and review steps that sit behind our due diligence process, and who owns them?
Use your organisation’s own names for the process, control owners and review forums first, then map them to the disclosure wording. Keep the request in business language rather than framework terms, and check the source material before sign-off.
Weak request
Please provide the ESRS 2:GOV-4 due diligence statement and all related controls, validation, risk and estimation controls.
Why it fails: This uses framework language that many teams do not use day to day, and it does not tell the owner what practical evidence to return. It also bundles several ideas together without asking for the underlying records, owners, dates or source systems.
Better request
Please share the evidence that shows how your team checks, reviews and signs off the information used in [process name] for [period]. Use your normal team terms, and include the control owner, source system or record set, latest version/date, and any logs, approvals or review notes.
Formal email template
Subject: Request for due diligence controls evidence for [reporting period] Hi [name/team], We are preparing the sustainability reporting pack and need your help with the evidence behind our due diligence process for [reporting period]. Please send the following in your own team’s terms, using the names you normally use internally: - a short description of the control set or review steps that support the process - how data or information is checked before it is used in reporting - the main controls used to manage identified risks - the controls used where judgement or estimates are involved - the owner for each control or review step - any supporting records, logs, approvals or review notes Please include the reporting boundary, the period covered, the source system or record set, and the latest version/date for each item. If helpful, you can return this as a table or attach the relevant documents. Please adapt this to your organisation’s language and check the source material before sign-off. Thanks, [preparer name]
Short Teams / Slack version
Hi [name/team] — could you share the evidence for the controls and review steps behind our due diligence process for [period]? Please use your team’s own terms, and include the owner, source record, latest version/date, and any supporting logs or approvals. Thanks.
Industry examples
Manufacturing
Context. The business uses a plant-level quality and compliance review process with manual sign-off on operational data.
Adapted request. Please share the evidence for the checks and sign-off steps used in the plant review process for [period]. Include the control owner, the line or site review step, the log or tracker used, and any exception notes.
Example response. A site control matrix, monthly review log, exception tracker, and sign-off sheet showing the plant manager, quality lead and finance reviewer.
Financial services
Context. The business relies on a formal risk and controls framework with documented testing and escalation.
Adapted request. Please send the evidence behind the risk review and control testing process for [period]. Include the control owner, the testing method, the system of record, and any issues raised or closed.
Example response. A controls register, testing results, issue log, escalation memo, and approval record from the risk committee secretary.
Draft your disclosure
Notes that turn data into a disclosure
LRA training templates — adapt them to your organisation, and check the official source before sign-off.
Method note
Explain how the control framework is defined, what counts as a validation check, how risk controls are identified, and how estimation controls are applied in practice.
Context note
Set out what the control information shows about how the reporting process is governed, checked, and managed, and why those controls matter for the reliability of the reported data.
Fluctuation statement
If the control picture has changed, point to updates in the framework, stronger or weaker validation, revised risk handling, or changes in how estimates are reviewed and supported.
Content index entry
GOV-4 Statement on Due Diligence — [location / page] / [notes]Download Centre
Preparation tools & forms
Professional preparation tools for GOV-4 — free with an LRA Community membership. Register once (it's free) and every download unlocks, together with the Disclosure Library, templates and the LRA AI Assistant.
Assurance readiness
For each claim, check the evidence
| Claim | Risk | Evidence to check |
|---|---|---|
| We limited the figure to the parts of the business and reporting process we had actually defined for this report, and we documented where the boundary starts and ends. | The assurer will test whether the boundary was set consistently, whether any material parts were left out without reason, and whether the stated scope matches the underlying reporting process. | Reporting boundary memo; process maps showing included entities, sites, functions and data owners; scope approval notes; reconciliation between the reported boundary and the source population. |
| We checked that the underlying data set was complete and that the records had not been altered or lost between source systems and the final disclosure. | The assurer will probe for missing records, duplicate entries, manual overrides, weak transfer controls, and whether the final figure can be traced back to source data without unexplained gaps. | Data lineage and transfer logs; completeness checks; exception reports; access and change logs; reconciliation between source extracts, working papers and the published number. |
| We built the disclosure from a defined control set, including ownership, review steps, sign-off points and escalation routes before publication. | The assurer will assess whether the control design is adequate, whether responsibilities were clear, whether reviews happened as described, and whether issues were escalated and resolved in time. | Control framework documentation; RACI or role assignments; review and approval workflow records; issue logs; evidence of escalation and closure; publication sign-off pack. |
| Where the figure relied on estimates, we tested the assumptions, checked the calculation method and compared the result with available supporting evidence before we released it. | The assurer will look for weak assumptions, unsupported inputs, calculation errors, bias in the estimate, and whether sensitivity or reasonableness checks were performed and documented. | Estimation methodology; assumption papers; calculation sheets or model outputs; source evidence supporting inputs; sensitivity or reasonableness checks; reviewer comments and approval records. |
Evidence pack to prepare
Common reporting gaps
Common gaps
Mistakes to avoid when collecting the data
Where judgement is often needed
Examples
Illustrative examples
Synthetic, written by LRA — not from a company report, not text from any standard.
We keep our oversight model simple: the board sets the tone, the audit and risk committees review key controls, and management owns day-to-day checks across reporting, operations, and compliance.
- Before figures are reported, our finance team runs a documented review of source data, reconciles key balances to the ledger, and logs any corrections; in the latest cycle, 18 of 18 material data sets were checked, and 3 required adjustment before sign-off.
- We use a risk register and control testing plan to track the main threats to delivery and reporting quality; 12 of 12 priority risks had named owners, and 10 had active mitigation actions in place at period end.
- Where we rely on estimates, we apply approved assumptions, compare them with prior outcomes, and challenge unusual movements; 7 of 7 significant estimates were reviewed by a second person, and 5 were also tested against external benchmarks.
This example shows a plain-language description of how oversight is organised, how reported data is checked, how key risks are managed, and how estimates are reviewed and challenged.
Our group uses a three-line approach: operational teams prepare the information, specialist functions test it, and the board and its committees receive escalation on matters that could affect reporting or delivery.
- We validate data through automated checks, manual review of exceptions, and reconciliation to underlying records; in the period, 24 of 24 critical data feeds were tested, 4 exceptions were found, and all 4 were cleared before publication.
- For major business and reporting risks, we maintain a control map, assign owners, and monitor whether actions are completed on time; 9 of 9 top risks were assigned, and 8 had controls operating as intended at the reporting date.
- For estimates, we document the basis used, compare assumptions with recent actual results, and require independent review for higher-judgement items; 6 of 6 material estimates were reviewed, and 2 were updated after challenge from the review team.
This example illustrates a different sector’s way of describing governance, data checking, risk management, and controls over judgement-based estimates.
Company reports
How companies report GOV-4 in practice
Examples of full and partial reporting practice. These are evidence-led reviews, not exact disclosure templates to copy.
Ask the Study Studio AI Assistant about this disclosure
Get practical answers for your reporting context. Your first two answers are free — join LRA Community for free to continue without a limit.
Check your understanding
Scenarios to work through
An organisation uses models and estimates to fill gaps in supplier data and to approximate the scale of certain impacts. The team is unsure whether to mention those estimates because the numbers are not exact.
The preparer receives partial evidence for ESRS 2:GOV-4 shortly before sign-off.
A business unit sends data for ESRS 2:GOV-4 using labels that do not match the reporting workbook.
Framework references
Relevant ESRS requirements and related disclosures
Available framework references and nearby disclosures relevant to preparing this requirement.
ESRS
GOV-4
within ESRS 2: General Disclosures
Related & explore
More in ESRS 2 → Browse full catalogue → Disclosure Library home → Search all disclosures →
FAQ
Questions this page answers
Start with the four datapoints listed on the page: control framework overview, data checking process, risk control measures, and estimation control methods. The page also gives a step-by-step preparation flow, so use that to organise the work before you draft.
Use it as a working checklist to move from scoping and data collection into drafting and review. The page is designed to help you turn the disclosure into a practical workflow rather than a theory note.
The page is set up for sustainability/ESG managers, HR or data owners, and assurance reviewers, so ownership should sit with the people who can explain the controls and evidence behind the disclosure. Use the page’s datapoints and evidence pack to assign clear responsibility for each part.
The page includes an evidence pack with five items for assurance readiness, plus four assurance claims to verify using claim, risk and evidence. Use those materials together so the draft is supported by traceable documentation rather than just narrative.
The page says there are four assurance claims to verify, each framed around claim, risk and evidence. Use that structure to test whether the disclosure is backed by the right controls, checks and supporting documents before review.
The page lists common reporting gaps and mistakes, so use that section as a pre-submission check. It is there to help you spot missing control detail, weak evidence or unclear methodology before the draft goes out.
The Download Centre includes a Prep & Assurance workbook in .xlsx format. Use it to organise the datapoints, evidence and assurance checks into a working draft.
The Download Centre also includes a printable Library Card in .pdf format. It is a practical companion for keeping the disclosure requirements, preparation steps and evidence needs in one place while you work.
Yes, but only as an illustrative guide. The page says the examples are synthetic, so they are there to show how a disclosure might look, including the quantitative table, not to replace your own company data.
The draft-output section gives visualisation ideas, narrative starters and a content-index line. Use those prompts to convert your prepared controls and evidence into a readable draft that is easier to review and assure.
More questions this page can help with
Go deeper · GOV-4
Learn to prepare this disclosure end-to-end
This guide covers one Disclosure Requirement. The ESRS / CSRD Reporting course walks the full European workflow — double materiality, datapoints, evidence and assurance — with exercises on your own data.
Available as Guided Flex, Live Cohort, 1:1 Expert Mentorship or Corporate Programme.
Get your GOV-4 tools — free
Your preparation tools are free for LRA Community members and students. Register once (it's free) and your download starts right away — plus the Disclosure Library, templates and the LRA AI Assistant.
You're in — your download is starting
Your file is downloading now. Your Community Cabinet — with the Disclosure Library, templates and the LRA AI Assistant — is ready too.
Open your Cabinet →