Short answer
The answer, before the reasoning
ESRS S4 should be organised around the product or service and the people who use it. When consumer or end-user impacts, risks or opportunities are material, the undertaking explains the affected products, services and user groups through three lenses: information-related impacts, including privacy and access to information; personal safety, including health, child protection and personal security; and social inclusion, including access, responsible marketing and non-discrimination.
It then reports policies, engagement and channels, remedy, actions, substantiated human-rights incidents, targets and entity-specific metrics supported by product-level evidence.
ESRS S4 product-impact lenses: information and privacy, personal safety, and inclusion and access.
Why this question matters
Consumer reporting is fragmented between product safety, quality, privacy, accessibility, marketing and customer service. Each function sees a different signal: recall, breach, complaint, access barrier, misleading claim or harm to vulnerable users. Without a product- and user-level model, S4 can become duplicate regulatory reporting or a customer-satisfaction page.
ESRS S4 asks how products, services, information, design and business practices create material impacts, and how they are managed. The answer requires three lenses, vulnerable-user evidence, controlled complaints and incidents, and evidence that product, marketing, sales and data decisions change when harm is identified.
Quick orientation
At a glance
- Applies to
- Undertakings with material IROs relating to consumers or end-users of their products and services.
- Primary decision
- Which product/user impact pathways are material, and how complaints, incidents, privacy, access and product evidence are controlled.
- Core sources
- Revised ESRS S4, ESRS 1 materiality/value-chain provisions and ESRS 2 general disclosure requirements.
- Common confusion
- Treating customer satisfaction as a substitute for consumer-impact assessment or excluding harms merely because user behaviour contributed.
- Technical status
- Commission-adopted revised ESRS dated 3 July 2026; final Official Journal and entry-into-force check required.
The three S4 impact lenses
ESRS S4 product-impact lenses: information and privacy, personal safety, and inclusion and access.
In practice
| Lens | Issues | Evidence |
|---|---|---|
| Information-related | Privacy, access to accurate/understandable information and freedom of expression | Privacy assessments, notices, labels, data/content governance |
| Personal safety | Health and safety, protection of children and personal security | Product testing, risk files, adverse events and recalls |
| Social inclusion | Access, responsible marketing, non-discrimination and accessibility | Accessibility/affordability analysis, user research and complaints |
In practice
The four S4 disclosure requirements
| DR | Content |
|---|---|
| S4-1 | Policies and groups covered. |
| S4-2 | Engagement, representatives/proxies, vulnerable groups, channels, grievance effectiveness and remedy. |
| S4-3 | Actions, marketing/sales/data-use tensions, effectiveness and human-rights incidents. |
| S4-4 | Qualitative or quantitative targets under GDR-T. |
1. Build a product, service and user impact map
Customer satisfaction is one signal, not an impact assessment. A service can score highly while exposing a small user group to severe harm or excluding people with disabilities. Complaint volume can also increase when a channel becomes more trusted.
In practice
| Field | Question | Source |
|---|---|---|
| Product/service population | Which products, markets, channels and versions connect to the impact? | Catalogue, usage/revenue, risk classifications |
| User group | Who uses or is exposed, including vulnerable and non-purchasing end-users? | User research, complaints and credible proxies |
| Impact pathway | Information, privacy, safety, access, marketing, design or service delivery? | Risk files, incidents and external evidence |
| Connection | Caused, contributed or directly linked through product or relationship? | Design, contracts, platforms and data flows |
| Materiality | Severity/likelihood and related risk/opportunity? | IRO assessment and user evidence |
| Data limitation | Where is product or user coverage incomplete? | Data-quality and proxy register |
2. Policies and vulnerable-user coverage
S4-1 states whether policies cover specific groups or all consumers and end-users. Connect policies to material impacts across information/privacy, safety and inclusion, and show implementation in product, engineering, safety, privacy, marketing, sales, customer operations, suppliers and distributors.
Information and privacy: clear information, data minimisation, rights and content/algorithm governance.
Safety: product risk, adverse-event monitoring, child protection, recalls and corrective action.
Inclusion: accessibility, non-discrimination, responsible marketing and access where material.
Vulnerable groups: children, disabled, older, low-literacy, low-income or otherwise affected users.
Implementation: product-development gates, assessments, marketing approval and escalation.
3. Engagement, representatives and credible proxies
S4-2 explains engagement with consumers/end-users, representatives or credible proxies and how perspectives informed decisions. Direct research should include affected and vulnerable users where relevant. Consumer, disability, patient or child-rights organisations can provide credible proxy evidence if their independence and connection are explained. The key evidence is the decision or control that changed.
In practice
| Route | Useful for | Control |
|---|---|---|
| Direct user research | Comprehension, usability, accessibility and product experience | Include affected/vulnerable users and ethical safeguards |
| Consumer/disability organisation | Rights and access evidence | Independence and connection |
| Complaint/support analytics | Patterns by product, version and market | Duplicates, access bias and severity |
| Regulator/ombudsman/expert | Systemic context | Distinguish external context from engagement |
4. Channels, complaints, grievances and remedy
Effectiveness is not demonstrated by fast closure alone. Assess format and language, awareness, safety, escalation, root-cause quality, remedy, user confirmation and recurrence. The process should also reach end-users who are not direct purchasers.
In practice
| Record | Meaning | Treatment |
|---|---|---|
| Service contact | Routine request or query | Not automatically a complaint or incident |
| Complaint | Dissatisfaction or concern | Classify by issue, product, severity and outcome |
| Grievance | Concern through a process intended to address harm | Track access, investigation, remedy and recurrence |
| Allegation/adverse event | Claim or event needing triage | Not automatically substantiated |
| Substantiated incident | Objective, factual and verifiable instance or formal finding | Report proportionately, subject to privacy |
| Recall/regulatory case | Formal corrective or legal process | Connect to action, remedy and impact evidence |
5. Actions, resources and business-pressure tensions
S4-3 asks how negative impacts are prevented, mitigated, ended, minimised or remediated and how tensions with marketing, sales and data-use pressures are handled. Growth targets, launch schedules, engagement metrics, cross-selling or data monetisation can conflict with privacy, safety or inclusion outcomes.
In practice
| Pathway | Action | Evidence |
|---|---|---|
| Information | Redesign label/notice or marketing approval | Comprehension test and corrected materials |
| Privacy | Data minimisation, setting change or rights process | Privacy assessment, rights and remedy evidence |
| Safety | Design correction, recall, warning or stop distribution | Risk file, affected units and completion |
| Vulnerable users | Age-appropriate/default safeguards and representative engagement | Testing, safeguard use and outcome |
| Access | Accessible design, alternative channel or coverage change | Accessibility testing and user outcome |
6. Misuse and unlawful use
The revised S4 scope excludes misuse or unlawful use by consumers/end-users. This is not a universal safe harbour. Test whether the harm is truly independent of design, foreseeable use, instructions, safeguards, marketing, access model or data practices. A deliberate unforeseeable alteration may fall outside S4; a foreseeable behaviour made harmful by inadequate warnings or controls may not.
7. Incidents, privacy and aggregation
For material S4 sub-topics, report human-rights incidents subject to privacy. The application requirements focus on substantiated and verified instances and use severity as the primary information-materiality basis. Maintain a restricted register with product version, market, user group, source, investigation, substantiation, severity, affected population, action, remedy and public aggregation. Child, health, privacy and security information require strict access controls.
8. Targets and entity-specific metrics
S4-4 uses GDR-T. Because S4 does not prescribe a broad metric catalogue, entity-specific metrics may be needed: comprehension-test results, accessibility coverage, substantiated severe safety/privacy incidents, affected units, remedy completion, user confirmation, rights-request barriers or responsible-marketing corrections. Define product/user population, method and limitation.
S4 evidence lineage: complaints are inputs; substantiated incidents, action, remedy and outcomes require validation.
Nine-step implementation workflow
Map products, services, markets, channels, user groups and vulnerable contexts.
Assess the three S4 lenses, severity/likelihood and connection.
Map policies and product/business controls.
Design direct, representative or proxy engagement.
Create a controlled taxonomy for contacts, complaints, grievances, adverse events and incidents.
Assess channel effectiveness and remedy.
Approve product, safety, privacy, marketing, sales or data-use actions.
Set outcome targets and entity-specific metrics.
Reconcile product evidence, incidents and public wording through legal/privacy and governance review.
Hypothetical case: digital financial service and vulnerable users
The undertaking treats the concerns as potential information and inclusion impacts, tests the journey with affected users and a disability organisation, changes cost presentation and defaults, creates an assisted channel, reviews model and marketing incentives, and provides remedy for materially misleading cases. The disclosure separates routine complaints from substantiated incidents and protects case details.
In practice
Weak versus stronger reporting
| Weak wording | Stronger structure |
|---|---|
| “Customer satisfaction was 92%.” | Explain the impact, product/user population, vulnerable groups, engagement, incidents, action, remedy and outcomes. |
| “We comply with all product regulations.” | Use regulatory compliance as evidence within the broader impact model. |
| “Misuse is outside our responsibility.” | Assess foreseeability, design, information, safeguards and marketing. |
| “Complaint volumes fell.” | Define categories, access, severity, incidents, remedy and reasons for movement. |
In practice
Common mistakes and corrections
| Mistake | Correction |
|---|---|
| Starting with satisfaction | Map product/user impacts and severity first. |
| Combining complaints and incidents | Use a controlled case taxonomy and substantiation criteria. |
| Regulatory compliance as whole disclosure | Add engagement, action, remedy and outcome evidence. |
| Ignoring non-customer end-users | Map exposure and user groups beyond purchasers. |
| Overusing misuse exclusion | Apply a documented product-impact test. |
| Publishing sensitive cases | Aggregate and restrict privacy/health/child/security detail. |
Readiness
S4 evidence checklist
- Product/service, market, channel and user-group map.
- Vulnerable-user and representative/proxy evidence.
- Policies and implementation controls.
- Safety, privacy, accessibility and information assessments.
- Controlled complaint/grievance/incident taxonomy.
- Channel, remedy and effectiveness evidence.
- Action and business-pressure decisions.
- Metric methodologies, targets and limitations.
- Restricted incident register and legal/privacy approval.
In practice
Connections to other ESRS
| Standard | Connection |
|---|---|
| E5 | Product resource use and circularity information can affect consumers. |
| E1 | Transition products, pricing and access can create impacts. |
| S3 | A person can be a community member and consumer, but the pathways differ. |
| G1 | Conduct and speak-up controls can support S4. |
| ESRS 2 | IRO, policy/action/target/metric and financial-effects architecture. |
Sources
Primary sources
Take it with you
The checklists as a working spreadsheet
Every checklist and table on this page, with empty status, owner and evidence columns for your team to fill in and keep.
✓ LRA AI Assistant · Human-in-the-loop
Ask about this guide
It answers from this page, and reaches into the linked disclosure cards when your question is about the standard itself. Your first two answers are free without signing in.
Go deeper · ESRS
ESRS and CSRD training
Double materiality, datapoints and the sustainability statement, with a mentor on your own report.
Available as Guided Flex, Live Cohort, 1:1 Expert Mentorship or Corporate Programme.
