Short answer
The answer, before the reasoning
An organisation does not need a dedicated ESG department to prepare a credible GRI report. It does need clear accountability, cross-functional data ownership, access to technical judgement, independent review and governance approval.
A lean team can operate with an executive sponsor, one reporting owner, nominated data owners from finance, HR, health and safety, environment, procurement and legal, targeted external specialist support, an editor, a reviewer and an approver. Word and Excel are sufficient for a controlled first cycle when definitions, evidence, versions, issues and approvals are managed deliberately. Software becomes useful when scale, complexity, multiple entities, assurance or repeatability justify it.
ANSWER | EXPLAIN | APPLY | EVIDENCE | CONNECT | PUBLISH
Article map
This Knowledge Card gives a direct answer, explains the technical logic, shows how to apply it, identifies the evidence needed, and provides a controlled publishing package. Requirements, recommendations, implementation practice and expert interpretation are kept distinct.
In practice
| Stage | What the reader will get |
|---|---|
| 1 | Direct answer and why it matters |
| 2 | Technical explanation and distinctions |
| 3 | Practical method, mapping and examples |
| 4 | Common mistakes, myth correction and reviewer checklist |
| 5 | Related standards, source status and update triggers |
| 6 | Editorial, SEO, visual and CMS package |
Why small teams often make the wrong trade-off
First-time reporters frequently assume that the choice is between building a full sustainability department and assigning the report to communications. Neither assumption is sound. GRI reporting requires impact assessment, evidence from across the organisation, technical interpretation and governance decisions. These functions can be distributed across existing roles, but they cannot be replaced by polished drafting alone.
The lean model is not “one person does everything”. It is a temporary and repeatable operating system in which existing functional owners contribute facts and decisions, a reporting owner coordinates the process, specialists are brought in where judgement is material, and the highest governance body or delegated governance process reviews and approves the reported information and material topics as applicable.
A controlled first cycle should favour a defensible scope, traceable evidence and transparent gaps over a visually ambitious report that cannot be reproduced. The organisation can improve design, automation and breadth in later cycles once the underlying reporting system is stable.
In practice
Quick orientation
| Question | Practical answer |
|---|---|
| What is the minimum internal core? | One sponsor, one reporting owner and named functional data owners. Review and approval responsibilities must also be explicit. |
| Can one person hold several roles? | Yes in a small organisation, but preparation and approval of material claims should not be performed by the same person without independent challenge. |
| Can we work in Word and Excel? | Yes. Use controlled templates, a source register, data dictionary, disclosure tracker, issue log and version rules. |
| When is software justified? | When there are many entities, sites, languages, recurring data workflows, complex calculations, assurance requirements or persistent version-control problems. |
| Can communications own the project? | Communications may coordinate drafting and publication, but should not determine material topics, invent methodologies, approve data or make technical claims alone. |
| Is 12 weeks always enough? | No. The plan in this article is illustrative and assumes limited scope, available evidence, responsive owners and timely decisions. |
In practice
What the GRI Standards require — and what they do not prescribe
| Layer | What it means in practice |
|---|---|
| GRI requirement | An organisation reporting in accordance with the GRI Standards follows the applicable requirements in GRI 1, GRI 2, GRI 3, relevant Sector Standards and relevant Topic Standards. The requirements concern the reporting process and disclosures, not a prescribed department structure. |
| GRI governance disclosure | GRI 2 asks for information on the highest governance body’s role in overseeing impacts, delegation, and its review and approval of the reported information, including material topics. |
| GRI materiality process | GRI 3 requires disclosure of the process used to determine material topics, the list of material topics and how each topic is managed. Determining topics relies on evidence and stakeholder and expert input, not only editorial judgement. |
| GRI reporting principles | Accuracy, balance, clarity, comparability, completeness, sustainability context, timeliness and verifiability should shape data, drafting and review controls. |
| Not prescribed | GRI does not prescribe a dedicated ESG department, a particular software product, a single project timetable or a universal organisational chart. |
| LRA implementation practice | Use a minimum viable reporting office: central coordination, distributed data ownership, targeted expertise, separated challenge and governance gates. |
1. Design roles around decisions, not job titles
The first question is not “Who is our ESG manager?” but “Which decisions and evidence must be owned?” A small organisation can allocate the work to people who already understand operations, finance, workforce, safety, procurement, legal and communications. The reporting owner converts those contributions into one controlled process.
Figure 1. Minimum viable team. Roles may be combined, but materiality, evidence, technical review and governance approval should not disappear.
In practice
| Role | Core responsibility | Typical existing position — Non-negotiable output |
|---|---|---|
| Executive sponsor | Sets scope, secures time and resolves escalated decisions. | CEO, CFO, COO, company secretary or executive director. — Approved mandate, resources and decision rights. |
| Reporting owner | Plans the cycle, coordinates sources, maintains registers, drafts and escalates issues. | Finance controller, company secretary, risk, compliance, strategy or communications lead with technical support. — Controlled project plan, source register, draft and issue log. |
| Functional data owners | Provide and validate data, explanations, policies and evidence. | Finance, HR, H&S, environmental, operations, procurement, legal, quality and IT owners. — Signed-off source data and method notes. |
| Impact / technical specialist | Supports GRI applicability, impact assessment and difficult topic judgements. | Internal risk, legal, H&S or environmental expert; external consultant where needed. — Documented methodology, judgement and limitations. |
| Editorial lead | Makes the approved content clear, balanced and accessible. | Communications, annual-report or corporate-affairs team. — Reader-ready wording without changing technical conclusions. |
| Independent reviewer | Challenges evidence, consistency, boundaries, calculations and claims. | Internal audit, finance reviewer, compliance, external technical reviewer. — Findings log and clearance. |
| Governance approver | Reviews material topics and the reported information under the organisation’s governance arrangements. | Board, committee or highest governance body, depending on structure. — Recorded review, decisions and approval. |
2. Define what communications can — and cannot — do
Communications is often the most available function and may be highly capable at managing deadlines, interviews, report structure and publication. The risk arises when an editorial function becomes the de facto owner of impact identification, metric definitions, estimates and compliance claims.
In practice
| Communications can lead | Communications should not decide alone |
|---|---|
| Report architecture, reader journey, interviews and drafting schedule. | Which impacts are significant and which topics are material. |
| Plain-language editing and consistency of terminology. | The organisational or value-chain boundary of a metric. |
| Collection of approved narrative and visual assets. | Whether an estimate, omission or claim meets the applicable GRI requirement. |
| Publication, accessibility and internal links. | Whether management actions were effective without outcome evidence. |
| Coordination of reviews and comments. | Whether an unsupported statement can be retained because it is reputationally attractive. |
| Maintaining the controlled master after technical approval. | Final technical sign-off or governance approval. |
3. Decide what stays in-house and where specialist support is needed
External support should fill specific capability or independence gaps rather than replace organisational ownership. A consultant cannot determine impacts credibly without access to operational knowledge, affected stakeholders and decision-makers. Equally, a first-time team should not improvise human-rights, biodiversity, climate, geospatial, legal or assurance judgements beyond its competence.
In practice
| Workstream | Usually possible in-house | Consider specialist support when |
|---|---|---|
| Project management | Scope, schedule, owners, meetings, tracker and issue log. | The group is highly diversified or lacks a clear reporting owner. |
| Impact inventory | Initial operational and value-chain mapping and collection of known incidents. | Impacts are complex, cross-border, severe or poorly understood. |
| Materiality method | Apply an approved method and document decisions. | The method is new, contested, or must integrate multiple frameworks. |
| Quantitative data | Extract, reconcile and approve existing operational and financial data. | Calculations need scientific, engineering, GHG, geospatial or statistical expertise. |
| Human rights | Gather policies, grievances, audits and due-diligence information. | Vulnerable groups, severe harm, remedy or confidential cases require expert handling. |
| Drafting | Prepare factual narrative using approved evidence. | The team cannot translate technical content into balanced disclosures. |
| Review / assurance readiness | Perform internal peer review and reconciliation. | External assurance is planned or management needs independent challenge. |
4. Use Word and Excel as a controlled system
Word and Excel can support a first report when the organisation controls identifiers, versions, owners and evidence. The danger is not the file format itself; it is uncontrolled copies, unclear definitions and decisions made in email. A shared folder should contain one controlled master for each register and published output.
A simple naming convention materially reduces errors: YYYY_Project_Register_Version_Status. Use read-only snapshots at governance gates. Store evidence through stable links rather than embedding uncontrolled copies in multiple workbooks. Lock calculation cells where appropriate and retain an exported PDF of approved tables.
In practice
| File / register | Minimum content | Control |
|---|---|---|
| Project plan | Tasks, owners, deadlines, dependencies and governance gates. | One owner; status updated at least weekly. |
| GRI applicability matrix | Universal, Sector and Topic Standards; applicable disclosures; rationale and status. | Technical reviewer approves applicability decisions. |
| Impact inventory and materiality register | Impact, activity/relationship, affected people/environment, evidence, significance, topic and decision. | Decision log and approver retained. |
| Data dictionary | KPI definition, unit, boundary, period, system, calculation, estimate and owner. | Changes require approval and year-on-year bridge. |
| Source and evidence register | Document, source system, owner, date, location, public/private status and reviewer. | Links must work and evidence versions must be frozen. |
| Data request workbook | Disclosure, request, owner, status, value, method, evidence and issue. | No value is accepted without owner and evidence status. |
| Draft report | Controlled Word master with disclosure tags and reviewer comments. | No parallel final drafts; technical changes tracked. |
| Content Index | Disclosure, location, omission and reason where applicable. | Cross-reference checked against final PDF or web page. |
| Issue and decision log | Question, risk, options, decision, rationale, owner and date. | Open critical issues block publication. |
In practice
5. Know when software adds real value
| Stay with controlled Word / Excel when | Consider software when |
|---|---|
| One organisation or a small number of entities and sites. | Dozens of entities, sites, currencies, languages or data owners. |
| A limited number of material topics and relatively stable metrics. | Complex consolidation, workflows, calculations, factor libraries or frequent restatements. |
| The first cycle is focused on building definitions and evidence. | The reporting system must repeat across multiple standards, questionnaires and assurance cycles. |
| The team can maintain one controlled master and clear folder structure. | Version conflicts, manual reminders and email approvals repeatedly fail. |
| External assurance is not yet planned or scope is limited. | Assurance requires stronger audit trails, access controls and evidence retention. |
| Budget is better spent on technical gaps and data quality. | A clear business case exists for automation and integration. |
6. An illustrative 12-week lean plan
The plan below is an implementation example, not a GRI requirement or a promise that every first report can be completed in 12 weeks. It assumes senior sponsorship, a reasonably contained organisation, prompt access to data and a limited number of major technical gaps.
Figure 2. Illustrative 12-week roadmap with four governance gates. Timings must be adapted to organisational complexity, stakeholder engagement and data readiness.
In practice
| Weeks | Workstream | Main actions — Gate / output |
|---|---|---|
| 1–2 | Mobilise and scope | Confirm reporting objective, GRI basis, organisation boundary, roles, standards, timeline and source templates. — Gate 1: sponsor approves scope, resources and decision rights. |
| 3–4 | Identify impacts | Map activities and business relationships; review incidents, complaints, due diligence, sector sources and stakeholder evidence. — Impact inventory and source-gap list. |
| 5–6 | Assess and determine material topics | Apply significance criteria, challenge missing impacts, consider Sector Standards and obtain governance review. — Gate 2: approved material-topic list and decision log. |
| 7–9 | Collect data and draft | Issue focused requests, validate definitions, compile evidence, draft GRI 2, GRI 3 and Topic Standard disclosures, build Content Index. — Controlled first draft and evidence-status dashboard. |
| 10–11 | Review and reconcile | Technical review, finance and HR reconciliations, cross-document consistency, weak-claim challenge and corrections. — Gate 3: technical clearance or documented critical actions. |
| 12 | Approve and publish | Governance review, final Content Index, accessibility, final PDF/web checks, release and lessons learned. — Gate 4: approval record and publication package. |
7. Plan realistic workload, not only elapsed time
A 12-week calendar does not mean 12 weeks of full-time work for every contributor. It does mean that the reporting owner needs protected capacity and that data owners must respond during their active windows. The following ranges are illustrative LRA planning assumptions, not GRI requirements.
In practice
| Role | Illustrative effort | Peak periods |
|---|---|---|
| Executive sponsor | Approximately 1–2 hours per week plus decision gates. | Scope, material topics, critical issues and final approval. |
| Reporting owner | Approximately 2–3 days per week, increasing to 3–4 days during drafting and review. | Weeks 1–2 and 7–12. |
| Functional data owner | Approximately 2–8 hours per active week, depending on the disclosure and data maturity. | Data request, clarification and sign-off windows. |
| Technical specialist | Approximately 5–15 days across the project, more where impacts or methods are complex. | Impact assessment, technical gaps and review. |
| Editorial lead | Approximately 5–10 days after evidence is sufficiently stable. | Drafting, consistency and publication. |
| Independent reviewer | Approximately 3–8 days depending on scope and quality. | Method review, first draft and pre-publication clearance. |
| Governance body | Pre-read plus two or three structured decision points. | Material topics and final reported information. |
8. Protect the first-year scope
A lean team should resist two opposite pressures: attempting every possible metric before material topics are determined, and excluding difficult impacts because data are not ready. The scope should follow the GRI architecture and material-topic process. Where required information is unavailable or incomplete, the organisation should address the applicable omission requirements and improve the data plan rather than inventing completeness.
Start with the reporting basis and applicability decisions, not a graphic design concept.
Collect information on activities, business relationships and impact evidence before finalising the data request.
Prioritise negative impacts and potentially severe impacts when resources are constrained.
Use estimates only where they are reasonable, controlled and transparently explained.
Keep a visible list of source gaps, assumptions and information that needs specialist review.
Do not describe an immature management process as effective without outcome evidence.
Publish a narrower, well-supported report rather than a broad report filled with generic narrative — while still meeting the conditions of the reporting claim selected.
In practice
Hypothetical case: a 180-employee engineering company
| Element | Illustrative case |
|---|---|
| Organisation | A UK engineering services company has 180 employees, three offices, project sites, a regional supplier base and no sustainability team. |
| Internal roles | The CFO sponsors the project; the company secretary is reporting owner; HR, H&S, procurement, finance and operations nominate data owners; communications edits the report. |
| External support | A GRI specialist supports applicability, impact assessment and technical review. A human-rights adviser reviews labour-agency and site-worker risks. |
| Tools | Controlled Word draft, Excel impact register, disclosure tracker, data dictionary and source register stored in a permission-controlled SharePoint folder. |
| Materiality work | The team reviews project impacts, workforce safety, subcontractor labour conditions, energy and travel, local community disruption, procurement practices and client-service impacts. |
| Governance gates | The executive team approves scope; the board reviews material topics; data owners sign off relevant disclosures; the board approves the final report. |
| Constraint | Supplier data are incomplete and project-level travel data are partly estimated. Methods, coverage and improvement actions are disclosed. |
| Outcome | The first report is not positioned as a mature end-state. It establishes repeatable definitions, owners and evidence for the next cycle. |
In practice
Illustrative first-year reporting-basis wording
| Annotation | Why it matters |
|---|---|
| Operating model | Explains how accountability works without presenting department size as a quality claim. |
| Functional validation | Shows that evidence owners, not the editor alone, approve the information. |
| Governance review | Connects the process to oversight and approval. |
| Specialist boundary | Shows where competence was supplemented. |
| Transparent gaps | Avoids implying that a first cycle has complete data. |
In practice
Weak versus stronger lean-team approaches
| Weak wording / approach | Why it is weak | Stronger direction |
|---|---|---|
| “Marketing will prepare the ESG section.” | No impact assessment, data ownership, technical review or governance process is defined. | Name the sponsor, reporting owner, functional owners, specialist support, reviewer and approver. |
| “We need software before we can start.” | The organisation postpones definitions and ownership decisions that software cannot make. | Build the controlled model in simple tools, then automate stable workflows where justified. |
| “Every department sent us what it had.” | Unfocused collection produces inconsistent periods and irrelevant evidence. | Issue disclosure-specific requests with definition, boundary, period, unit and evidence fields. |
| “The consultant owns the report.” | Organisational accountability and knowledge do not transfer to an external provider. | Use the consultant for method, challenge and gaps; keep internal owners and approvals. |
| “We will complete everything in 12 weeks.” | The statement ignores readiness, stakeholder work and technical gaps. | Describe the timetable as an illustrative plan with scope assumptions and escalation rules. |
In practice
Common mistakes and corrections
| Mistake | Risk | Correction |
|---|---|---|
| Assigning the whole report to communications | Substantive claims are made without operational ownership or technical basis. | Separate editorial coordination from impact, data and approval decisions. |
| Collecting all Topic Standard metrics immediately | Time is spent on topics that may not be material while significant impacts are missed. | Determine material topics first, then apply relevant Topic Standards. |
| No protected time for the reporting owner | The project becomes a sequence of missed deadlines and uncontrolled compromises. | Allocate explicit capacity and sponsor-backed escalation. |
| Buying software before process design | The tool embeds unclear definitions and automates inconsistency. | Design the operating model, registers and controls first. |
| No independent challenge | Errors and promotional overstatement survive because preparers review their own work. | Use peer, finance, audit, compliance or external technical review. |
| No evidence register | Draft text cannot be verified or updated in the next cycle. | Assign a source ID, owner, date and status to every material claim. |
| Treating year one as the final state | The organisation hides gaps rather than creating an improvement path. | Disclose limitations and maintain a prioritised next-cycle plan. |
Rule
Myth: “A credible GRI report requires a fully staffed ESG department.”
Reality: GRI does not prescribe a department structure. A small organisation can report credibly through a lean cross-functional model, provided responsibilities, evidence, technical judgement, review and governance approval are real and documented. Why the confusion arises: Large reporters often have specialist departments and software, so teams confuse organisational scale with reporting quality. The essential question is whether the process can identify impacts, produce accurate and complete information, withstand review and repeat next year.
Readiness
Reviewer checklist
- Has an executive sponsor approved the objective, scope, resources and decision rights?
- Is one reporting owner accountable for the controlled master and issue log?
- Are finance, HR, H&S, environment, operations, procurement, legal and other relevant owners named?
- Has the team identified where external technical expertise is required?
- Are preparation, validation, independent review and governance approval distinguished?
- Is there a current GRI applicability matrix, including Sector Standards?
- Does every metric have a definition, boundary, period, method, owner and evidence link?
- Does the impact and materiality process precede topic-specific data collection?
- Are Word and Excel files version-controlled with one approved master?
- Are critical issues and unresolved source gaps visible to the sponsor?
- Has the highest governance body or appropriate governance process reviewed material topics and the reported information?
- Does the publication explain estimates, incomplete information and improvement actions honestly?
- Has the team recorded lessons, owners and next-year automation opportunities?
In practice
Related standards and next steps
| Relationship | Reference | Practical use |
|---|---|---|
| Direct | GRI 1: Foundation 2021 | Reporting requirements and principles; no prescribed ESG department or software. |
| Direct | GRI 2: General Disclosures 2021 | Governance oversight, delegation, review and approval, policies and responsibilities. |
| Direct | GRI 3: Material Topics 2021 | Impact identification, material topics and topic management. |
| Implementation | GRI source register and data request | Create the minimum data and evidence system. |
| Implementation | Internal controls for GRI reporting | Separate preparation, review and approval. |
| Next step | How to prepare a GRI report: complete process | Expand the 12-week roadmap into the full reporting cycle. |
| Advanced | When sustainability reporting software is worth buying | Develop a business case from stable requirements and pain points. |
A communications manager may coordinate drafting and publication, and can act as reporting owner with appropriate technical support. Communications should not decide material topics, invent methodologies, approve data or make technical claims alone; functional owners, specialist review and governance approval must remain explicit and appropriately separated.
Questions
Questions people ask
Do we need an ESG team for GRI?
An organisation does not need a dedicated ESG department to prepare a credible GRI report. It does need clear accountability, cross-functional data ownership, access to technical judgement, independent review and governance approval. A lean team can operate with an executive sponsor, one reporting owner, nominated data owners from finance, HR, health and safety, environment, procurement and legal, targeted external specialist support, an editor, a reviewer and an approver.
Can we prepare a GRI report in Excel?
Word and Excel are sufficient for a controlled first cycle when definitions, evidence, versions, issues and approvals are managed deliberately. Software becomes useful when scale, complexity, multiple entities, assurance or repeatability justify it.
Who should own GRI reporting?
The first question is not “Who is our ESG manager?” but “Which decisions and evidence must be owned?” A small organisation can allocate the work to people who already understand operations, finance, workforce, safety, procurement, legal and communications. The reporting owner converts those contributions into one controlled process.
When do we need software?
Word and Excel are sufficient for a controlled first cycle when definitions, evidence, versions, issues and approvals are managed deliberately. Software becomes useful when scale, complexity, multiple entities, assurance or repeatability justify it.
Can a communications manager prepare the report?
A communications manager may coordinate drafting and publication, and can act as reporting owner with appropriate technical support. Communications should not decide material topics, invent methodologies, approve data or make technical claims alone; functional owners, specialist review and governance approval must remain explicit and appropriately separated.
Take it with you
The checklists as a working spreadsheet
Every checklist and table on this page, with empty status, owner and evidence columns for your team to fill in and keep.
✓ Knowledge Hub AI Assistant · Human-in-the-loop
Ask about this guide
It answers from this page, and reaches into the linked disclosure cards when your question is about the standard itself. Your first two answers are free without signing in.
Go deeper · GRI
Certified GRI Standards Training
This page settles one disclosure. The GRI Standards Certified Training — two live days, taken as a bundle with an ESRS course — walks the whole cycle: material topics, datapoints, evidence, the Content Index and assurance readiness, with exercises on your own data.
Available as two live training days online or on-site in London, bundled with an ESRS course.
