Skip to the answer

Disclosure GuidesPillar guides, articles, FAQ and expert notes

Level 2 · Decision guide·GRI · Disclosure guides

How to Prepare a GRI Report

An end-to-end workflow from mobilisation and impact assessment to disclosure controls, the GRI content index, approval and publication.

Who this is for A 9-minute read for reporting teams working through Data, evidence, controls and assurance, and for reviewers testing whether the evidence behind it holds.

Short answer

The answer, before the reasoning

To prepare a GRI report, define the reporting objective and governance, understand the organisation’s context, identify and assess impacts, determine material topics, apply relevant Sector and Topic Standards, collect controlled evidence, draft management approach and topic disclosures, complete the GRI content index, resolve omissions, perform technical QA, obtain approval, publish and notify GRI. The materiality process must drive disclosure selection; the content index should be built throughout the project, not at the end.

LRA Knowledge Hub visual — branded for editorial and learning use.

Publication-ready educational draft. Confirm jurisdiction-specific legal scope and the latest adopted standard versions before publication.

PUBLIC ARTICLE

Rule

WHO THIS IS FOR

Sustainability, ESG, finance, risk, legal, internal audit and reporting professionals who need a practical and technically controlled explanation.

First: a “GRI report” does not have to be one stand-alone document

Organisations commonly publish a sustainability report, integrated report or annual report and describe it as a GRI report. GRI information can also be published across several locations, provided users can find it through a clear GRI content index and the organisation meets the requirements of its chosen reporting route.

The project should therefore be designed as a reporting system: governance, materiality, disclosure requirements, data, evidence, drafting, control and publication. Starting with page design before those elements are stable usually creates a polished document with weak compliance.

Figure 1. A reliable GRI report is produced through a controlled process, with governance and evidence running through every step.

Step 1 — Mobilise the project

Confirm the reporting period, publication date, language, channels and intended reporting route: in accordance with or with reference to the GRI Standards.

Appoint an executive sponsor, technical lead, project manager, topic owners, data owners, reviewers and final approvers.

Define entities, operations and value-chain relationships to be considered, and reconcile the sustainability reporting perimeter with the financial reporting group.

Create a standards register using current official versions and effective dates.

Agree the evidence, version-control and sign-off protocol before data collection begins.

Step 2 — Understand the organisation’s context

Build a current picture of activities, products, services, markets, workers, sites, supply chains, customers, business relationships, governance and regulatory exposure. Context is the foundation for impact identification and for the General Disclosures in GRI 2.

Step 3 — Identify actual and potential impacts

Use due-diligence records, incidents, grievances, audits, stakeholder evidence, scientific or sector sources and value-chain analysis to identify positive and negative impacts. Write each entry as a clear impact statement rather than a broad topic label.

Step 4 — Assess significance and determine material topics

Apply the GRI 3 criteria to assess impact significance and prioritise the most significant impacts. Group related impacts into material topics, document the threshold and approval, and retain a watchlist of emerging or below-threshold impacts.

Step 5 — Apply the relevant Sector Standards

Check whether one or more GRI Sector Standards applies to the organisation’s activities. Use the Standard to challenge the completeness of impact identification, consider the topics described for the sector, map associated disclosures and document any required explanation for sector topics concluded not to be material.

Step 6 — Build the disclosure register

The disclosure register is the project’s control centre. It converts the material-topic list and GRI architecture into assignable evidence requirements.

In practice

Field What to record
GRI reference Standard, disclosure number, title, requirement and applicable version.
Applicability logic Why the disclosure is relevant to the material topic and impacts, or why it is not applicable.
Required information Each qualitative and quantitative component, including methods, breakdowns and contextual explanation.
Owner and reviewer Named data owner, narrative owner, technical reviewer and approver.
Boundary and method Entities, sites, workforce categories, value-chain coverage, units, definitions and calculation method.
Evidence location System report, policy, minutes, invoice, model, survey, audit file or other controlled source.
Status and gap Complete, partial, unavailable, confidential, legally restricted or awaiting approval.
Publication location Report section, page, web page or linked document used in the content index.

Step 7 — Collect data and evidence

Issue data requests from the disclosure register, not from an informal list of metrics. Quantitative data should include definitions, units, source systems, calculation files, boundary notes, prior-year comparatives and reviewer evidence. Narrative information should be supported by approved policies, governance records, action plans, incident logs and performance evidence rather than generic commitments.

Rule

CONTROL PRINCIPLE

A value is not reporting-ready merely because it appears in a spreadsheet. It must have an owner, defined boundary, documented method, source evidence, review status and explanation of material changes.

Step 8 — Draft the disclosures

Draft GRI 2 General Disclosures, GRI 3-1 and 3-2, and GRI 3-3 for each material topic. Add relevant Topic and Sector Standard disclosures. Where the GRI disclosures do not fully describe a significant impact, add entity-specific information rather than forcing the impact into an unsuitable metric.

A strong GRI 3-3 management approach explains

the actual and potential impacts associated with the material topic;

whether and how the organisation is involved through its activities or business relationships;

policies or commitments, including responsible conduct and human-rights commitments where relevant;

actions to prevent or mitigate potential negative impacts, address actual negative impacts and manage positive impacts;

how the effectiveness of actions is tracked, including goals, targets, indicators, lessons and stakeholder feedback.

Step 9 — Manage gaps and reasons for omission

For in-accordance reporting, an organisation that cannot comply with a relevant disclosure or requirement can use only the reasons for omission permitted by GRI and must provide the required explanation. The categories include not applicable, legal prohibitions, confidentiality constraints and information unavailable or incomplete. The exact conditions and explanation requirements in GRI 1 must be followed.

In practice

Situation Weak response Stronger controlled response
Information unavailable “Data not available.” Identify the missing component, explain why it is unavailable, state the actions underway and provide the expected timeframe where required.
Confidentiality concern “Confidential.” Confirm that the GRI confidentiality conditions are met and explain the constraint without disclosing protected information.
Not applicable Leave the cell blank. Explain why the disclosure or requirement does not apply to the organisation or material topic.
Legal restriction Remove the disclosure silently. Identify the legal prohibition and use the permitted omission explanation.

Step 10 — Complete the GRI content index

Build the index as a live output from the disclosure register. It should state the reporting route and period, identify the GRI Standards used, list disclosures and precise locations, show reasons for omission, address applicable Sector Standard information and contain the required statement of use.

Rule

STATEMENT OF USE

For in-accordance reporting, use the statement prescribed in GRI 1 and insert the organisation name and reporting period exactly. Do not invent a stronger claim such as “GRI certified” or “fully approved by GRI”.

Step 11 — Perform technical QA, approval and assurance

Trace every content-index location to the final proof, not the draft.

Check every “shall” component of each reported disclosure.

Reconcile totals, units, boundaries and comparative figures across the report and financial statements.

Check that claims about policies, targets and progress are supported by evidence.

Review reasons for omission and the reporting statement.

Obtain governance approval and preserve the decision record.

Where external assurance is used, agree scope and evidence expectations early; assurance is encouraged but is not itself a condition for reporting in accordance with GRI.

Step 12 — Publish, notify GRI and improve

Publish the report and content index in accessible locations, complete the GRI notification step, retain the final evidence archive and record feedback. The next cycle should begin with changes in activities, incidents, business relationships, stakeholder evidence and standards — not by copying last year’s topic list.

In practice

Illustrative 14-week production plan

Weeks Workstream Key output
1–2 Mobilisation and context Governance, perimeter, standards register, project plan and context map.
3–5 Impact identification and materiality Impact register, significance assessment, Sector Standard review and approved material topics.
6–9 Disclosure mapping and evidence collection Disclosure register, data files, narrative evidence and gap actions.
10–11 Drafting Draft report sections, management approaches and live content index.
12–13 Technical QA, governance review and assurance Resolved comments, approved figures, omission record and assurance evidence.
14 Publication and notification Final report, content index, web publication, GRI notification and lessons log.

Common mistakes

Copying the previous year’s material topics without reassessing impacts.

Starting data collection before establishing materiality and disclosure applicability.

Treating GRI 2 as a short company-profile section and missing governance or policy requirements.

Reporting policy existence but not actions, effectiveness or impact evidence.

Using page references that point to a topic mention rather than the required disclosure information.

Applying “not applicable” to disclosures that are merely difficult to collect.

Using the statement “GRI compliant” without meeting the formal in-accordance requirements.

Leaving the content index and technical review until the publication deadline.

Rule

MYTH VS REALITY

Myth: “Preparing a GRI report means filling in a table of GRI indicators.” Reality: the table is only the final map. The core work is impact assessment, management information, controlled evidence and a defensible link from material topics to disclosures.

Readiness

Final readiness checklist

  • • ☐ The reporting route, period, perimeter and governance are approved.
  • • ☐ Current Universal and applicable Sector and Topic Standards are in the standards register.
  • • ☐ Material topics are supported by a current GRI 3 assessment.
  • • ☐ Every disclosure has an applicability conclusion, owner, evidence and final location.
  • • ☐ Boundaries, methods, units and comparatives are documented and reconciled.
  • • ☐ GRI 3-3 is complete for every material topic.
  • • ☐ Every omission uses a permitted category and required explanation.
  • • ☐ The content index, statement of use and notification step are complete.
  • • ☐ Technical, governance and assurance reviews are closed.

Bottom line

A credible GRI report is the visible output of a controlled reporting process. Material impacts determine material topics; material topics determine relevant disclosures; and every disclosure is supported by evidence, review and a transparent content index. When that chain is intact, design and storytelling can strengthen the report without replacing its technical foundation.

Official source anchors

The links below point to the official standard-setter or legislative source. They should be rechecked as part of the pre-publication update control.

1. GRI 1: Foundation 2021. Foundation requirements, reporting principles, in-accordance and with-reference routes. Open official source

2. GRI 3: Material Topics 2021. Official requirements and guidance for determining and reporting material topics. Open official source

3. GRI Standards — English language. Official GRI access point for the Universal, Sector and Topic Standards. Open official source

4. How to use the GRI Standards. Official GRI guidance and support resources for reporting organisations. Open official source

Technical status

LEGAL AND TECHNICAL NOTE

This educational article does not provide legal advice. Reporting scope, effective dates, transitional provisions and jurisdictional adoption must be checked for the relevant entity and reporting period.

Take it with you

The checklists as a working spreadsheet

Every checklist and table on this page, with empty status, owner and evidence columns for your team to fill in and keep.

Download .xlsx

✓ LRA AI Assistant · Human-in-the-loop

Ask about this guide

It answers from this page, and reaches into the linked disclosure cards when your question is about the standard itself. Your first two answers are free without signing in.

Try
2 free answers Automated · the LRA team is one click away

Go deeper · GRI

GRI Standards Certified Training

A full reporting cycle with a mentor: impact inventory, threshold, Topic Standard selection, Content Index and assurance readiness.

Available as Guided Flex, Live Cohort, 1:1 Expert Mentorship or Corporate Programme.

See course formats
/en/knowledge-hub/disclosure-guides/gri/gri-evidence-controls-and-assurance/how-to-prepare-a-gri-report/