Short answer
The answer, before the reasoning
A GRI evidence pack should allow an informed reviewer to trace every material public claim from the published wording or metric back to its original source, methodology, calculation, data-owner confirmation, review control and approval. GRI does not prescribe one software platform, folder structure or universal retention period.
It does require information to be gathered, recorded, compiled and analysed so that its quality can be examined. The practical objective is therefore a controlled evidence architecture: complete enough to support the report, proportionate to risk, protected by access rules and preserved as an immutable record of the final release.
The evidence pack is not only for external assurance. It supports internal review, board or management approval, audit trails, corrections, restatements, future-year comparatives and defensible public claims. It also creates a safer boundary between public evidence, ordinary internal working files and restricted information such as personal grievance data, legal advice or commercially sensitive supplier records.
Quick orientation
Quick orientation
- Applies to
- Any GRI reporting project, from first-year reporting to mature controlled reporting and assurance preparation.
- Primary decision
- What evidence must be retained, how it is classified and linked, who reviews it, and when it can be deleted or archived.
- Key source
- GRI 1 Verifiability principle, supported by Accuracy, Balance, Completeness, GRI 2 evidence needs and GRI 3 materiality disclosures.
- Common confusion
- Treating the final report, the content index or a shared drive full of files as sufficient evidence without traceability and version control.
What GRI requires - and what it leaves to the organisation
Not prescribed by GRI
A particular document-management platform, reporting software or cloud provider.
One mandatory folder tree, file-naming convention or evidence-ID format.
A universal number of years for retaining every evidence item.
External assurance for every GRI report, although GRI encourages credibility-enhancing measures.
Publication of every internal or restricted evidence document.
A legal review of every disclosure; the need and scope depend on the claim, jurisdiction and risk.
Figure 1. A defensible evidence pack combines access classification, a traceability chain from public claim to original source and approval, and a controlled folder structure. Evidence quality depends on linkage, version control and proportionate access rather than the volume of files retained.
Rule
NORMATIVE CORE
Under the Verifiability principle, information must be gathered, recorded, compiled and analysed so that it can be examined to establish its quality. GRI guidance expects documentation to be organised for review by people other than the preparers, key reporting decisions to be documented, original sources to be identifiable, and reliable evidence to support assumptions and calculations. The organisation should be able to obtain representations from original sources about accuracy within acceptable margins and explain uncertainty clearly.
In practice
The minimum traceability chain
| Link | Question the evidence must answer | Typical record |
|---|---|---|
| 1. Published claim or disclosure | Exactly what did the organisation publish, where, for which period and boundary? | Final PDF/web capture; content-index row; disclosure ID; final wording; metric and unit; release version. |
| 2. Original source | Where did the underlying information originate? | System extract; invoice; meter file; HR report; incident record; policy; minutes; stakeholder record; third-party statement. |
| 3. Methodology and transformation | How was source information defined, filtered, converted, estimated, classified or aggregated? | Methodology note; data dictionary; calculation workbook; code/version; assumptions; emission factor; mapping rules. |
| 4. Data-owner confirmation | Who is accountable for the source and confirms completeness and accuracy? | Signed representation; workflow approval; controlled email; data-owner checklist; exception statement. |
| 5. Review and reconciliation | Who challenged the information and what tests were performed? | Recalculation; variance analysis; financial or operational reconciliation; sample test; exception log; reviewer notes. |
| 6. Governance approval and final release | Who approved the conclusion, and which immutable version was published? | Material-topic approval; disclosure sign-off; legal review where relevant; management or board record; release checklist; file hash or locked archive. |
In practice
Evidence classes: public, internal and restricted
| Class | Examples | Access and publication treatment |
|---|---|---|
| Public | Published report and GRI content index; public policies; public methodologies; published data tables; assurance statement; public source references. | May be linked or disclosed. Retain the exact final version and public URLs. Public does not mean uncontrolled: archive the source and publication date. |
| Internal | System extracts; calculations; data mappings; materiality files; stakeholder summaries; data-owner confirmations; working papers; review notes; draft approvals. | Available to authorised preparers, reviewers and assurance providers. Protect against editing after final sign-off and retain enough context to reproduce the result. |
| Restricted | Personal grievance or whistleblowing data; legal advice; protected employee information; commercially sensitive supplier records; security data; investigation files. | Use least-privilege access, privacy and legal controls. Link through a restricted evidence ID or controlled summary rather than copying sensitive detail into broad reporting folders. |
In practice
Recommended controlled folder structure
| Folder | Contents and control purpose |
|---|---|
| 00_Admin_and_Source_Register | Project charter, reporting timetable, standards and editions, source manifest, roles, access matrix, evidence register, approval matrix and update log. |
| 01_Boundary_and_Perimeter | Reporting organisation, legal-entity list, financial reconciliation, site list, value-chain map, metric boundaries, acquisitions/disposals and boundary approvals. |
| 02_Materiality_and_Impacts | Context analysis, impact inventory, Sector Standard review, significance assessment, threshold, topic grouping, testing, material-topic approval and Disclosure 3-1/3-2 support. |
| 03_Stakeholder_Engagement | Stakeholder map, existing-channel assessment, engagement briefs, consent and safeguards, notes, survey methodology, grievance summaries, expert evidence and limitations. |
| 04_Methodologies_and_Metrics | Data dictionary, metric definitions, calculation methods, emission factors, estimates, assumptions, restatements, units, transformations and code or workbook versions. |
| 05_Disclosure_Drafting_and_Mapping | GRI 2 matrix, 3-3 files, Topic Standard mapping, Sector references, omission memos, draft wording, annotated review and content-index working file. |
| 06_Review_and_Approvals | Data-owner representations, technical review, legal/privacy review where relevant, internal audit, assurance requests, governance minutes, issue log and final sign-off. |
| 07_Publication_and_Notification | Final report, final content index, public-source links, language versions, web captures, publication checklist, file hashes, notification/registration and confirmation. |
| 08_Archive_and_Change_Log | Immutable final evidence set, superseded versions, correction records, restatements, retention decisions, legal holds and future-year handover. |
In practice
Source register: the control centre of the pack
| Field | Purpose |
|---|---|
| Evidence ID | Stable identifier used in calculations, review notes, disclosures and restricted-access references. |
| Disclosure / claim link | GRI disclosure, material topic, content-index row or public statement supported by the evidence. |
| Source description and owner | What the source is, where it came from, responsible function and contact. |
| Period and boundary | Reporting period, cut-off date, entities, sites, workers, products, value-chain segment and exclusions. |
| Version and retrieval date | Exact file/system version, extraction timestamp and whether the source can be reproduced. |
| Method / transformation | Calculation, mapping, estimate, conversion, aggregation or judgement applied after extraction. |
| Quality and limitation | Completeness, accuracy, uncertainty, missing scope, manual intervention and known control weakness. |
| Access class | Public, internal or restricted, plus authorised roles and storage location. |
| Review and approval | Preparer, reviewer, data-owner confirmation, approver, date and open issues. |
| Retention and hold | Retention rule, archive date, disposal date, legal hold, privacy restriction and review trigger. |
Practical file-naming convention
Illustrative filename: 2026_EVD-ENE-014_GRI-302-1_Group_Energy-Calculation_v03_APPROVED.xlsx. The exact convention is optional, but it should make the period, evidence link, subject, scope, version and status visible without opening the file. Avoid names such as “final-final-new.xlsx” or overwriting the reviewed version with a later draft.
Rule
NAMING PATTERN
[Reporting year]_[Evidence ID]_[Disclosure or topic]_[Entity or scope]_[Document type]_[Version]_[Status].ext
In practice
Evidence categories by reporting activity
| Activity | Evidence to retain | Key control |
|---|---|---|
| Source standards and interpretation | Official standards, amendments, FAQs, effective dates, internal technical memos and approved terminology. | Source version and exact anchor for every normative claim. |
| Reporting boundary | Entity register, site list, financial reconciliation, value-chain map, boundary decisions and changes. | Reconcile every metric and narrative to the approved perimeter. |
| Materiality | Impact inventory, stakeholder/expert evidence, significance assessment, threshold, Sector Standard review, testing and approval. | Trace each material topic to evidence, criteria and approval; retain excluded-topic rationale. |
| Narrative disclosures | Policies, procedures, responsibilities, minutes, implementation records, outcomes, incidents, limitations and review comments. | Do not support an effectiveness claim only with existence of a policy or activity. |
| Quantitative metrics | Original extract, data dictionary, calculation, factor, unit conversion, estimate, reconciliation, data-owner sign-off and variance review. | A reviewer can reproduce the number and identify boundary, period and assumptions. |
| Targets and commitments | Approved target, baseline, boundary, methodology, governance approval, progress calculation and change record. | Public wording matches the approved commitment and does not overstate certainty or scope. |
| Reasons for omission | Disclosure-specific analysis, allowed reason, legal/confidentiality basis, missing-scope record, explanation and remediation plan. | The public explanation matches the evidence and the omission is permitted. |
| Content index and statement | Final disclosure mapping, link test, standard titles, Sector references, statement sign-off and release copy. | The index points to substantive current disclosures and the claim matches the completed checklist. |
| Assurance and review | Request list, samples, findings, responses, corrections, unresolved items, conclusion and management representations. | Separate assurance evidence from the organisation’s own approval and do not overstate the assurance scope. |
Data-owner confirmation: what it should cover
The source system or record and the extraction date are identified.
The population, entity, site, workforce, product or value-chain boundary is complete or limitations are specified.
Definitions, units, reporting period and cut-off rules are understood and applied.
Manual adjustments, estimates and exclusions are listed and supported.
The data owner has reviewed unusual movements, negative results and known incidents, not only the final total.
The file supplied is the version reviewed and has not been altered after confirmation.
The data owner understands the proposed public claim and has flagged any wording that goes beyond the evidence.
Open issues, remediation dates and responsible persons are recorded.
In practice
Retention logic: no universal number, but a controlled decision
| Retention factor | Question for the policy |
|---|---|
| Legal and regulatory requirements | Do company law, tax, employment, environmental, privacy, record-keeping or sector rules require a particular retention or deletion period? |
| Assurance and audit cycle | How long must source evidence remain available for current and future assurance, internal audit, regulator or lender review? |
| Comparatives and restatements | How many reporting periods are needed to reproduce trends, explain methodology changes and support restatements? |
| Claims and limitation periods | Could the disclosure be relevant to litigation, investigation, grievance, contract or public-claim challenge? Is a legal hold required? |
| Privacy and data minimisation | Does retaining personal or sensitive data remain necessary and lawful? Can the evidence be anonymised, aggregated or replaced by a controlled representation? |
| Contractual and client obligations | Do supplier, customer, grant, financing, assurance or consulting contracts impose retention, confidentiality or return/destruction requirements? |
| Business continuity and knowledge transfer | What minimum evidence is needed for next-year reporting, staff turnover, methodology continuity and correction of errors? |
| Storage and disposal control | Who approves archive or deletion, how is disposal evidenced, and how are backups, exports and restricted copies addressed? |
Rule
RETENTION PRINCIPLE
Define retention by evidence category and risk, not by one arbitrary period for every file. A restricted grievance record may need a shorter privacy-driven period or legal hold, while an approved methodology, baseline and final calculation may need longer preservation to support comparatives and restatements.
Hypothetical example: an energy metric under review
The evidence-pack review assigns an evidence ID to each site source, preserves the original extracts, documents the acquisition cut-off and estimation method, adds a calculation and unit-conversion methodology, and obtains data-owner confirmations. A reviewer recalculates the total, reconciles it to site records and challenges the reduction narrative. The final disclosure explains the boundary and the material operational factor rather than attributing the entire reduction to efficiency measures. The approved workbook and public wording are locked together in the final release set.
Hypothetical scenario
HYPOTHETICAL SCENARIO
A group reports total energy consumption and a year-on-year reduction. The calculation workbook contains copied values from twelve sites, but the original meter files are not linked, one site uses estimated data, an acquired facility is included for only six months and the reduction claim does not explain a production shutdown. The spreadsheet is named “Energy final v7”.
Illustrative only. It shows how the decision is made, not wording that can be copied or relied on.
In practice
Weak versus stronger evidence architecture
| Criterion | Weak pack | Stronger pack |
|---|---|---|
| Traceability | Files are grouped by department but not linked to claims. | Every claim and content-index row links to evidence IDs and review status. |
| Original sources | Only copied values or screenshots remain. | Original extracts are preserved with retrieval date, owner and reproducibility information. |
| Methodology | The preparer understands the calculation but no method is documented. | Definitions, boundary, transformations, estimates, factors and changes are recorded. |
| Version control | Files are overwritten and “final” has several meanings. | Draft, reviewed, approved and published versions are distinct; the release set is immutable. |
| Approvals | Approval is inferred from an email thread. | Data-owner, technical reviewer and governance approvals are explicit and tied to a version. |
| Restricted data | Sensitive records are copied into broad folders. | Restricted evidence is separated, access-controlled and linked through non-sensitive IDs or summaries. |
| Retention | Everything is kept forever or deleted ad hoc. | Category-based retention, privacy review, legal holds, archive and disposal are controlled. |
In practice
Common mistakes and corrections
| Mistake | Why it fails | Correction |
|---|---|---|
| Keeping only the final report | The published output does not show the source, method, judgement or approval behind it. | Archive the complete claim-to-source chain and final release record. |
| Using email inboxes as the evidence repository | Access, retention, version and handover are uncontrolled. | Move approved evidence and confirmations into the controlled pack with stable IDs. |
| Retaining every draft without status | Reviewers cannot identify the approved version and may rely on superseded information. | Use clear statuses, change logs and an immutable final set; archive superseded versions separately. |
| Assuming policy existence proves effectiveness | A policy supports a process description but not a claim about outcomes or impact reduction. | Retain implementation and outcome evidence and challenge causal language. |
| No evidence for negative results or limitations | The pack supports positive claims only, undermining Balance and credibility. | Retain incident, gap, uncertainty and corrective-action evidence and reflect it in public wording. |
| Copying personal grievance data into the reporting folder | Creates privacy, retaliation and access risks. | Keep case data restricted; use anonymised summaries, evidence IDs and authorised review. |
| Using one retention period for all files | May conflict with privacy deletion, legal holds, assurance needs or contractual obligations. | Adopt category- and risk-based retention with documented approval. |
| No link between late corrections and approvals | The report can change after sign-off without re-review. | Use change control that identifies affected claims, evidence, approvers and publication files. |
Rule
MYTH VERSUS REALITY
Myth: “An evidence pack is just a folder full of source documents.” Reality: volume is not traceability. A defensible pack links each public claim to the relevant source, method, owner, review, limitation and approval, while controlling access and preserving the exact evidence set behind the published version.
Readiness
Readiness checklist for internal review or assurance
- A controlled source register covers every material disclosure, metric, omission and statement of use.
- Every evidence item has a stable ID, owner, period, boundary, version, access class and review status.
- Original source data can be identified and, where necessary, reproduced from the source system.
- Methodologies, definitions, units, transformations, estimates and assumptions are documented and current.
- Materiality judgements, stakeholder inputs, threshold and approvals are traceable to Disclosure 3-1 and 3-2.
- Each material topic has evidence supporting the corresponding Disclosure 3-3 and relevant Topic Standard disclosures.
- Data-owner representations cover completeness, accuracy, boundary, estimates and known limitations.
- Reviewer tests, reconciliations, exceptions and corrections are documented and resolved or transparently open.
- Public, internal and restricted evidence are separated and access-controlled.
- Legal, privacy, confidentiality and assurance restrictions are addressed without concealing reportable limitations.
- The final content index, statement of use, report and web links are locked to the approved evidence set.
- Publication, GRI notification or registration, corrections, restatements and retention decisions have clear owners and records.
A data-owner confirmation should identify the source and extraction date and confirm the population, boundary, definitions, units, reporting period and cut-off, while listing adjustments, estimates, exclusions and limitations. It should also record review of unusual movements, negative results and known incidents, the confirmed file version, any wording that exceeds the evidence, and open issues with owners and dates.
Store personal grievance evidence as restricted information under least-privilege access, privacy and legal controls, not in the ordinary reporting folder. Link it through a restricted evidence ID or an anonymised controlled summary, and set retention or legal holds according to the evidence category and risk while recording authorised review.
Self-check
- What is the difference between possessing evidence and having a traceable evidence architecture?
- Why should restricted personal data not be copied into the ordinary reporting folder?
- Which six links should a reviewer be able to follow from a published metric?
- Why is a universal retention period inappropriate for every evidence category?
Questions
Questions people ask
What documents should be retained for a GRI report?
Under the Verifiability principle, information must be gathered, recorded, compiled and analysed so that it can be examined to establish its quality. GRI guidance expects documentation to be organised for review by people other than the preparers, key reporting decisions to be documented, original sources to be identifiable, and reliable evidence to support assumptions and calculations.
Does GRI prescribe an evidence folder structure?
A GRI evidence pack should allow an informed reviewer to trace every material public claim from the published wording or metric back to its original source, methodology, calculation, data-owner confirmation, review control and approval. GRI does not prescribe one software platform, folder structure or universal retention period.
What should a data-owner confirmation cover?
A data-owner confirmation should identify the source and extraction date and confirm the population, boundary, definitions, units, reporting period and cut-off, while listing adjustments, estimates, exclusions and limitations. It should also record review of unusual movements, negative results and known incidents, the confirmed file version, any wording that exceeds the evidence, and open issues with owners and dates.
How long should GRI evidence be retained?
A GRI evidence pack should allow an informed reviewer to trace every material public claim from the published wording or metric back to its original source, methodology, calculation, data-owner confirmation, review control and approval. GRI does not prescribe one software platform, folder structure or universal retention period.
How should confidential grievance evidence be stored?
Store personal grievance evidence as restricted information under least-privilege access, privacy and legal controls, not in the ordinary reporting folder. Link it through a restricted evidence ID or an anonymised controlled summary, and set retention or legal holds according to the evidence category and risk while recording authorised review.
In practice
Related standards and practical connections
| Relationship | Reference | Practical connection |
|---|---|---|
| Primary | GRI 1, Verifiability principle | Organisation of evidence, reviewability, original sources, assumptions, calculations and uncertainty. |
| Supporting | GRI 1, Accuracy, Balance and Completeness | Evidence quality, negative information, scope and missing coverage. |
| Implementation | GRI 2 disclosures | Entity, governance, policy, workforce, grievance, assurance and reporting-period evidence. |
| Implementation | GRI 3 disclosures | Materiality process, stakeholder/expert evidence, material topics and management evidence. |
| Publication | GRI 1 Requirements 6-9 | Omission records, content index, statement approval and notification evidence. |
| Assurance | Organisation-specific assurance criteria and engagement scope | Additional evidence and retention requirements may apply; do not assume GRI alone defines the assurance file. |
Sources
Primary sources
- GRI 1: Foundation 2021 — Verifiability principle and section 5.2 on credibility and internal controls
- GRI 2: General Disclosures 2021 — entity scope, reporting period, restatements, assurance, governance, policy, grievance and stakeholder disclosures
- GRI 3: Material Topics 2021 — impact identification, sources, scope, limitations, significance, threshold, stakeholders, experts and approval
- GRI Standards Glossary 2025 — impact, stakeholder, business relationships and value-chain terms
- GRI Standards Report Registration System FAQs — notification timing and report-registration evidence
Take it with you
The checklists as a working spreadsheet
Every checklist and table on this page, with empty status, owner and evidence columns for your team to fill in and keep.
✓ LRA AI Assistant · Human-in-the-loop
Ask about this guide
It answers from this page, and reaches into the linked disclosure cards when your question is about the standard itself. Your first two answers are free without signing in.
Go deeper · GRI
GRI Standards Certified Training
A full reporting cycle with a mentor: impact inventory, threshold, Topic Standard selection, Content Index and assurance readiness.
Available as Guided Flex, Live Cohort, 1:1 Expert Mentorship or Corporate Programme.
