Skip to the answer

Disclosure GuidesPillar guides, articles, FAQ and expert notes

Level 2 · Explainer·GRI · Disclosure guides

GRI Evidence Pack: source documents, calculations, methodologies, data-owner confirmations, review controls, approvals, access and retention

A reporting team often has evidence, but not an evidence system. Source files remain in personal inboxes, calculations are overwritten, screenshots cannot be reproduced, policy versions do not match the reporting period, data owners approve figures informally, and the final PDF is published without a clear link to the files reviewed. This creates avoidable rework and makes it difficult to demonstrate that the reporting principles were applied.

Who this is for A 14-minute read for reporting teams working through Data, evidence, controls and assurance, and for reviewers testing whether the evidence behind it holds.

Published passport

Current as at 11 August 2026
RK Reviewed by Dr Ross KurinkoLinkedIn Strategic ESG Advisor · IFRS S1 & S2 / GRI / ESRS expert GRI Certified Global Trainer · PhD, University of Cambridge · ESG-AI expert 15+ years on FTSE 100 & Fortune Global 500 disclosures Canary Wharf, London LRA educational guidance · Not issued or endorsed by GRI

Edition written against

TECHNICAL STATUS: Current as at 1 August 2026. GRI requires verifiable information but does not prescribe …

Published

12 Aug 2026

Knowledge Hub guide

Last reviewed

11 Aug 2026

Short answer

The answer, before the reasoning

A GRI evidence pack should allow an informed reviewer to trace every material public claim from the published wording or metric back to its original source, methodology, calculation, data-owner confirmation, review control and approval. GRI does not prescribe one software platform, folder structure or universal retention period.

It does require information to be gathered, recorded, compiled and analysed so that its quality can be examined. The practical objective is therefore a controlled evidence architecture: complete enough to support the report, proportionate to risk, protected by access rules and preserved as an immutable record of the final release.

The evidence pack is not only for external assurance. It supports internal review, board or management approval, audit trails, corrections, restatements, future-year comparatives and defensible public claims. It also creates a safer boundary between public evidence, ordinary internal working files and restricted information such as personal grievance data, legal advice or commercially sensitive supplier records.

Quick orientation

Quick orientation

Applies to
Any GRI reporting project, from first-year reporting to mature controlled reporting and assurance preparation.
Primary decision
What evidence must be retained, how it is classified and linked, who reviews it, and when it can be deleted or archived.
Key source
GRI 1 Verifiability principle, supported by Accuracy, Balance, Completeness, GRI 2 evidence needs and GRI 3 materiality disclosures.
Common confusion
Treating the final report, the content index or a shared drive full of files as sufficient evidence without traceability and version control.

What GRI requires - and what it leaves to the organisation

Not prescribed by GRI

A particular document-management platform, reporting software or cloud provider.

One mandatory folder tree, file-naming convention or evidence-ID format.

A universal number of years for retaining every evidence item.

External assurance for every GRI report, although GRI encourages credibility-enhancing measures.

Publication of every internal or restricted evidence document.

A legal review of every disclosure; the need and scope depend on the claim, jurisdiction and risk.

Figure 1. A defensible evidence pack combines access classification, a traceability chain from public claim to original source and approval, and a controlled folder structure. Evidence quality depends on linkage, version control and proportionate access rather than the volume of files retained.

Rule

NORMATIVE CORE

Under the Verifiability principle, information must be gathered, recorded, compiled and analysed so that it can be examined to establish its quality. GRI guidance expects documentation to be organised for review by people other than the preparers, key reporting decisions to be documented, original sources to be identifiable, and reliable evidence to support assumptions and calculations. The organisation should be able to obtain representations from original sources about accuracy within acceptable margins and explain uncertainty clearly.

In practice

The minimum traceability chain

Link Question the evidence must answer Typical record
1. Published claim or disclosure Exactly what did the organisation publish, where, for which period and boundary? Final PDF/web capture; content-index row; disclosure ID; final wording; metric and unit; release version.
2. Original source Where did the underlying information originate? System extract; invoice; meter file; HR report; incident record; policy; minutes; stakeholder record; third-party statement.
3. Methodology and transformation How was source information defined, filtered, converted, estimated, classified or aggregated? Methodology note; data dictionary; calculation workbook; code/version; assumptions; emission factor; mapping rules.
4. Data-owner confirmation Who is accountable for the source and confirms completeness and accuracy? Signed representation; workflow approval; controlled email; data-owner checklist; exception statement.
5. Review and reconciliation Who challenged the information and what tests were performed? Recalculation; variance analysis; financial or operational reconciliation; sample test; exception log; reviewer notes.
6. Governance approval and final release Who approved the conclusion, and which immutable version was published? Material-topic approval; disclosure sign-off; legal review where relevant; management or board record; release checklist; file hash or locked archive.

In practice

Evidence classes: public, internal and restricted

Class Examples Access and publication treatment
Public Published report and GRI content index; public policies; public methodologies; published data tables; assurance statement; public source references. May be linked or disclosed. Retain the exact final version and public URLs. Public does not mean uncontrolled: archive the source and publication date.
Internal System extracts; calculations; data mappings; materiality files; stakeholder summaries; data-owner confirmations; working papers; review notes; draft approvals. Available to authorised preparers, reviewers and assurance providers. Protect against editing after final sign-off and retain enough context to reproduce the result.
Restricted Personal grievance or whistleblowing data; legal advice; protected employee information; commercially sensitive supplier records; security data; investigation files. Use least-privilege access, privacy and legal controls. Link through a restricted evidence ID or controlled summary rather than copying sensitive detail into broad reporting folders.

In practice

Recommended controlled folder structure

Folder Contents and control purpose
00_Admin_and_Source_Register Project charter, reporting timetable, standards and editions, source manifest, roles, access matrix, evidence register, approval matrix and update log.
01_Boundary_and_Perimeter Reporting organisation, legal-entity list, financial reconciliation, site list, value-chain map, metric boundaries, acquisitions/disposals and boundary approvals.
02_Materiality_and_Impacts Context analysis, impact inventory, Sector Standard review, significance assessment, threshold, topic grouping, testing, material-topic approval and Disclosure 3-1/3-2 support.
03_Stakeholder_Engagement Stakeholder map, existing-channel assessment, engagement briefs, consent and safeguards, notes, survey methodology, grievance summaries, expert evidence and limitations.
04_Methodologies_and_Metrics Data dictionary, metric definitions, calculation methods, emission factors, estimates, assumptions, restatements, units, transformations and code or workbook versions.
05_Disclosure_Drafting_and_Mapping GRI 2 matrix, 3-3 files, Topic Standard mapping, Sector references, omission memos, draft wording, annotated review and content-index working file.
06_Review_and_Approvals Data-owner representations, technical review, legal/privacy review where relevant, internal audit, assurance requests, governance minutes, issue log and final sign-off.
07_Publication_and_Notification Final report, final content index, public-source links, language versions, web captures, publication checklist, file hashes, notification/registration and confirmation.
08_Archive_and_Change_Log Immutable final evidence set, superseded versions, correction records, restatements, retention decisions, legal holds and future-year handover.

In practice

Source register: the control centre of the pack

Field Purpose
Evidence ID Stable identifier used in calculations, review notes, disclosures and restricted-access references.
Disclosure / claim link GRI disclosure, material topic, content-index row or public statement supported by the evidence.
Source description and owner What the source is, where it came from, responsible function and contact.
Period and boundary Reporting period, cut-off date, entities, sites, workers, products, value-chain segment and exclusions.
Version and retrieval date Exact file/system version, extraction timestamp and whether the source can be reproduced.
Method / transformation Calculation, mapping, estimate, conversion, aggregation or judgement applied after extraction.
Quality and limitation Completeness, accuracy, uncertainty, missing scope, manual intervention and known control weakness.
Access class Public, internal or restricted, plus authorised roles and storage location.
Review and approval Preparer, reviewer, data-owner confirmation, approver, date and open issues.
Retention and hold Retention rule, archive date, disposal date, legal hold, privacy restriction and review trigger.

Practical file-naming convention

Illustrative filename: 2026_EVD-ENE-014_GRI-302-1_Group_Energy-Calculation_v03_APPROVED.xlsx. The exact convention is optional, but it should make the period, evidence link, subject, scope, version and status visible without opening the file. Avoid names such as “final-final-new.xlsx” or overwriting the reviewed version with a later draft.

Rule

NAMING PATTERN

[Reporting year]_[Evidence ID]_[Disclosure or topic]_[Entity or scope]_[Document type]_[Version]_[Status].ext

In practice

Evidence categories by reporting activity

Activity Evidence to retain Key control
Source standards and interpretation Official standards, amendments, FAQs, effective dates, internal technical memos and approved terminology. Source version and exact anchor for every normative claim.
Reporting boundary Entity register, site list, financial reconciliation, value-chain map, boundary decisions and changes. Reconcile every metric and narrative to the approved perimeter.
Materiality Impact inventory, stakeholder/expert evidence, significance assessment, threshold, Sector Standard review, testing and approval. Trace each material topic to evidence, criteria and approval; retain excluded-topic rationale.
Narrative disclosures Policies, procedures, responsibilities, minutes, implementation records, outcomes, incidents, limitations and review comments. Do not support an effectiveness claim only with existence of a policy or activity.
Quantitative metrics Original extract, data dictionary, calculation, factor, unit conversion, estimate, reconciliation, data-owner sign-off and variance review. A reviewer can reproduce the number and identify boundary, period and assumptions.
Targets and commitments Approved target, baseline, boundary, methodology, governance approval, progress calculation and change record. Public wording matches the approved commitment and does not overstate certainty or scope.
Reasons for omission Disclosure-specific analysis, allowed reason, legal/confidentiality basis, missing-scope record, explanation and remediation plan. The public explanation matches the evidence and the omission is permitted.
Content index and statement Final disclosure mapping, link test, standard titles, Sector references, statement sign-off and release copy. The index points to substantive current disclosures and the claim matches the completed checklist.
Assurance and review Request list, samples, findings, responses, corrections, unresolved items, conclusion and management representations. Separate assurance evidence from the organisation’s own approval and do not overstate the assurance scope.

Data-owner confirmation: what it should cover

The source system or record and the extraction date are identified.

The population, entity, site, workforce, product or value-chain boundary is complete or limitations are specified.

Definitions, units, reporting period and cut-off rules are understood and applied.

Manual adjustments, estimates and exclusions are listed and supported.

The data owner has reviewed unusual movements, negative results and known incidents, not only the final total.

The file supplied is the version reviewed and has not been altered after confirmation.

The data owner understands the proposed public claim and has flagged any wording that goes beyond the evidence.

Open issues, remediation dates and responsible persons are recorded.

In practice

Retention logic: no universal number, but a controlled decision

Retention factor Question for the policy
Legal and regulatory requirements Do company law, tax, employment, environmental, privacy, record-keeping or sector rules require a particular retention or deletion period?
Assurance and audit cycle How long must source evidence remain available for current and future assurance, internal audit, regulator or lender review?
Comparatives and restatements How many reporting periods are needed to reproduce trends, explain methodology changes and support restatements?
Claims and limitation periods Could the disclosure be relevant to litigation, investigation, grievance, contract or public-claim challenge? Is a legal hold required?
Privacy and data minimisation Does retaining personal or sensitive data remain necessary and lawful? Can the evidence be anonymised, aggregated or replaced by a controlled representation?
Contractual and client obligations Do supplier, customer, grant, financing, assurance or consulting contracts impose retention, confidentiality or return/destruction requirements?
Business continuity and knowledge transfer What minimum evidence is needed for next-year reporting, staff turnover, methodology continuity and correction of errors?
Storage and disposal control Who approves archive or deletion, how is disposal evidenced, and how are backups, exports and restricted copies addressed?

Rule

RETENTION PRINCIPLE

Define retention by evidence category and risk, not by one arbitrary period for every file. A restricted grievance record may need a shorter privacy-driven period or legal hold, while an approved methodology, baseline and final calculation may need longer preservation to support comparatives and restatements.

Hypothetical example: an energy metric under review

The evidence-pack review assigns an evidence ID to each site source, preserves the original extracts, documents the acquisition cut-off and estimation method, adds a calculation and unit-conversion methodology, and obtains data-owner confirmations. A reviewer recalculates the total, reconciles it to site records and challenges the reduction narrative. The final disclosure explains the boundary and the material operational factor rather than attributing the entire reduction to efficiency measures. The approved workbook and public wording are locked together in the final release set.

Hypothetical scenario

HYPOTHETICAL SCENARIO

A group reports total energy consumption and a year-on-year reduction. The calculation workbook contains copied values from twelve sites, but the original meter files are not linked, one site uses estimated data, an acquired facility is included for only six months and the reduction claim does not explain a production shutdown. The spreadsheet is named “Energy final v7”.

Illustrative only. It shows how the decision is made, not wording that can be copied or relied on.

In practice

Weak versus stronger evidence architecture

Criterion Weak pack Stronger pack
Traceability Files are grouped by department but not linked to claims. Every claim and content-index row links to evidence IDs and review status.
Original sources Only copied values or screenshots remain. Original extracts are preserved with retrieval date, owner and reproducibility information.
Methodology The preparer understands the calculation but no method is documented. Definitions, boundary, transformations, estimates, factors and changes are recorded.
Version control Files are overwritten and “final” has several meanings. Draft, reviewed, approved and published versions are distinct; the release set is immutable.
Approvals Approval is inferred from an email thread. Data-owner, technical reviewer and governance approvals are explicit and tied to a version.
Restricted data Sensitive records are copied into broad folders. Restricted evidence is separated, access-controlled and linked through non-sensitive IDs or summaries.
Retention Everything is kept forever or deleted ad hoc. Category-based retention, privacy review, legal holds, archive and disposal are controlled.

In practice

Common mistakes and corrections

Mistake Why it fails Correction
Keeping only the final report The published output does not show the source, method, judgement or approval behind it. Archive the complete claim-to-source chain and final release record.
Using email inboxes as the evidence repository Access, retention, version and handover are uncontrolled. Move approved evidence and confirmations into the controlled pack with stable IDs.
Retaining every draft without status Reviewers cannot identify the approved version and may rely on superseded information. Use clear statuses, change logs and an immutable final set; archive superseded versions separately.
Assuming policy existence proves effectiveness A policy supports a process description but not a claim about outcomes or impact reduction. Retain implementation and outcome evidence and challenge causal language.
No evidence for negative results or limitations The pack supports positive claims only, undermining Balance and credibility. Retain incident, gap, uncertainty and corrective-action evidence and reflect it in public wording.
Copying personal grievance data into the reporting folder Creates privacy, retaliation and access risks. Keep case data restricted; use anonymised summaries, evidence IDs and authorised review.
Using one retention period for all files May conflict with privacy deletion, legal holds, assurance needs or contractual obligations. Adopt category- and risk-based retention with documented approval.
No link between late corrections and approvals The report can change after sign-off without re-review. Use change control that identifies affected claims, evidence, approvers and publication files.

Rule

MYTH VERSUS REALITY

Myth: “An evidence pack is just a folder full of source documents.” Reality: volume is not traceability. A defensible pack links each public claim to the relevant source, method, owner, review, limitation and approval, while controlling access and preserving the exact evidence set behind the published version.

Readiness

Readiness checklist for internal review or assurance

  • A controlled source register covers every material disclosure, metric, omission and statement of use.
  • Every evidence item has a stable ID, owner, period, boundary, version, access class and review status.
  • Original source data can be identified and, where necessary, reproduced from the source system.
  • Methodologies, definitions, units, transformations, estimates and assumptions are documented and current.
  • Materiality judgements, stakeholder inputs, threshold and approvals are traceable to Disclosure 3-1 and 3-2.
  • Each material topic has evidence supporting the corresponding Disclosure 3-3 and relevant Topic Standard disclosures.
  • Data-owner representations cover completeness, accuracy, boundary, estimates and known limitations.
  • Reviewer tests, reconciliations, exceptions and corrections are documented and resolved or transparently open.
  • Public, internal and restricted evidence are separated and access-controlled.
  • Legal, privacy, confidentiality and assurance restrictions are addressed without concealing reportable limitations.
  • The final content index, statement of use, report and web links are locked to the approved evidence set.
  • Publication, GRI notification or registration, corrections, restatements and retention decisions have clear owners and records.

A data-owner confirmation should identify the source and extraction date and confirm the population, boundary, definitions, units, reporting period and cut-off, while listing adjustments, estimates, exclusions and limitations. It should also record review of unusual movements, negative results and known incidents, the confirmed file version, any wording that exceeds the evidence, and open issues with owners and dates.

Store personal grievance evidence as restricted information under least-privilege access, privacy and legal controls, not in the ordinary reporting folder. Link it through a restricted evidence ID or an anonymised controlled summary, and set retention or legal holds according to the evidence category and risk while recording authorised review.

Self-check

  1. What is the difference between possessing evidence and having a traceable evidence architecture?
  2. Why should restricted personal data not be copied into the ordinary reporting folder?
  3. Which six links should a reviewer be able to follow from a published metric?
  4. Why is a universal retention period inappropriate for every evidence category?

Questions

Questions people ask

What documents should be retained for a GRI report?

Under the Verifiability principle, information must be gathered, recorded, compiled and analysed so that it can be examined to establish its quality. GRI guidance expects documentation to be organised for review by people other than the preparers, key reporting decisions to be documented, original sources to be identifiable, and reliable evidence to support assumptions and calculations.

Does GRI prescribe an evidence folder structure?

A GRI evidence pack should allow an informed reviewer to trace every material public claim from the published wording or metric back to its original source, methodology, calculation, data-owner confirmation, review control and approval. GRI does not prescribe one software platform, folder structure or universal retention period.

What should a data-owner confirmation cover?

A data-owner confirmation should identify the source and extraction date and confirm the population, boundary, definitions, units, reporting period and cut-off, while listing adjustments, estimates, exclusions and limitations. It should also record review of unusual movements, negative results and known incidents, the confirmed file version, any wording that exceeds the evidence, and open issues with owners and dates.

How long should GRI evidence be retained?

A GRI evidence pack should allow an informed reviewer to trace every material public claim from the published wording or metric back to its original source, methodology, calculation, data-owner confirmation, review control and approval. GRI does not prescribe one software platform, folder structure or universal retention period.

How should confidential grievance evidence be stored?

Store personal grievance evidence as restricted information under least-privilege access, privacy and legal controls, not in the ordinary reporting folder. Link it through a restricted evidence ID or an anonymised controlled summary, and set retention or legal holds according to the evidence category and risk while recording authorised review.

In practice

Related standards and practical connections

Relationship Reference Practical connection
Primary GRI 1, Verifiability principle Organisation of evidence, reviewability, original sources, assumptions, calculations and uncertainty.
Supporting GRI 1, Accuracy, Balance and Completeness Evidence quality, negative information, scope and missing coverage.
Implementation GRI 2 disclosures Entity, governance, policy, workforce, grievance, assurance and reporting-period evidence.
Implementation GRI 3 disclosures Materiality process, stakeholder/expert evidence, material topics and management evidence.
Publication GRI 1 Requirements 6-9 Omission records, content index, statement approval and notification evidence.
Assurance Organisation-specific assurance criteria and engagement scope Additional evidence and retention requirements may apply; do not assume GRI alone defines the assurance file.

Sources

Primary sources

Take it with you

The checklists as a working spreadsheet

Every checklist and table on this page, with empty status, owner and evidence columns for your team to fill in and keep.

Download .xlsx

✓ LRA AI Assistant · Human-in-the-loop

Ask about this guide

It answers from this page, and reaches into the linked disclosure cards when your question is about the standard itself. Your first two answers are free without signing in.

Try
2 free answers Automated · the LRA team is one click away

Go deeper · GRI

GRI Standards Certified Training

A full reporting cycle with a mentor: impact inventory, threshold, Topic Standard selection, Content Index and assurance readiness.

Available as Guided Flex, Live Cohort, 1:1 Expert Mentorship or Corporate Programme.

See course formats
/en/knowledge-hub/disclosure-guides/gri/gri-evidence-controls-and-assurance/gri-evidence-pack-source-documents-calculations-methodologies-data-own/