Skip to the answer

Disclosure GuidesPillar guides, articles, FAQ and expert notes

Level 2 · Explainer·GRI · Disclosure guides

Internal Controls for GRI Reporting: Data Owners, Reviewers and Approval Workflow

A practical control model from source system to publication, covering ownership, preparation, independent review, narrative claims, estimates, external datasets, group consolidation, change logs and sign-off.

Who this is for A 10-minute read for reporting teams working through Data, evidence, controls and assurance, and for reviewers testing whether the evidence behind it holds.

Short answer

The answer, before the reasoning

GRI does not prescribe one internal-control framework, but its reporting principles require information to be accurate, complete, comparable, timely and verifiable. Assign an owner, preparer, independent reviewer and accountable approver to each disclosure; retain source evidence, calculation logic, estimates, judgements and change records; and reconcile the report, Content Index and supporting pack.

First-time reporters need proportionate controls, not necessarily complex software.

LRA Knowledge Hub visual — branded for editorial and learning use.

Source-grounded educational draft. Final LRA technical sign-off is required before publication.

PUBLIC ARTICLE

In practice

FORMAT

FORMAT LANGUAGE VERSION
Expert Tool Guide British English 1.0 • 1 August 2026

The control objective: another person can reproduce the answer

Internal controls make sustainability information reviewable. The central test is simple: can a competent person who did not prepare the disclosure move from the published claim to the source, understand the boundary and method, reproduce the calculation or reasoning, identify the approvals and see what changed? If not, the information may look polished but it is not yet verifiable.

GRI 1 does not prescribe a control framework, a RACI or specific software. It establishes reporting principles and an in-accordance architecture that make controls necessary in practice. Accuracy requires reliable methods and sufficient detail; completeness requires the significant impacts and required information to be covered; comparability and timeliness require stable definitions and controlled periods; verifiability requires a documented evidence trail. The model below is therefore implementation practice designed to support those outcomes.

Figure 1. A publication control is complete only when the claim has passed through controlled source, preparation, independent review, approval and versioned release.

Quick orientation

APPLIES TO First-time and experienced GRI reporters, data owners, reviewers, int
PRIMARY DECISION Who prepares, reviews and approves each disclosure and what evidence and controls are required before publication.
KEY SOURCES GRI 1 reporting principles, with disclosure-specific evidence needs
COMMON CONFUSION Assuming that controls are needed only for metrics, while narrative claims, methodology, omissions and page references remain uncontrolled.

Technical status

IMPLEMENTATION STATUS

The workflow, RACI and control matrix in this article are not mandatory GRI templates. They are a practical control design that helps an organisation apply the reporting principles and prepare information for internal or external review.

In practice

Eight questions every disclosure control should answer

Control question What a good record shows Failure symptom
What is being reported? Disclosure, sub-requirement, metric or narrative claim; exact period and boundary. One control is described for an entire topic, but several requirements are unsupported.
Who owns the source? Named business role responsible for the underlying process and source evidence. Sustainability team becomes the de facto owner of data it cannot validate.
Who prepared the disclosure? Person or role that extracted, calculated, drafted and documented the information. No record of who changed the final figure or wording.
Who independently reviewed it? Reviewer with sufficient competence and no dependence on the preparer’s undocumented knowledge. Review is limited to proofreading.
What evidence supports it? Source-system extract, policy, minutes, methodology, calculation file, external dataset or restricted evidence. Evidence consists of the previous report or an email assertion.
What judgement was applied? Boundary, estimate, threshold, classification, omission, confidentiality or methodological decision. Professional judgement is hidden in a formula or narrative sentence.
Who approved publication? Accountable owner confirms factual accuracy, limitations and public wording. Data owner approves the number but not the claim made around it.
How is change controlled? Version, date, change reason, restatement and final published location. Word, spreadsheet, Content Index and website contain different values.

In practice

Control objectives for GRI reporting

Objective Practical meaning Example control
Completeness All required disclosures, sub-requirements, entities, sites, topics and material data gaps have been addressed. Requirement-level checklist reconciled to the Content Index and source register.
Accuracy Reported facts, calculations and descriptions are sufficiently precise and free from material error. Recalculation, source-to-report reconciliation and reasonableness analysis.
Balance Positive and negative impacts, progress and setbacks, limitations and corrective actions are not selectively presented. Narrative reviewer challenges unsupported achievements and missing adverse outcomes.
Comparability Definitions, units, boundaries and methods remain stable or changes and restatements are explained. Method-version control and prior-period bridge.
Timeliness Data cut-off, late adjustments, approvals and publication occur under a controlled timetable. Close calendar, late-adjustment log and release gate.
Verifiability Evidence, assumptions and decisions can be reviewed independently of the preparer. Evidence index, calculation file, judgement log and sign-off.
Consistency Report, annual report, website, policies, questionnaires and Content Index do not contradict one another. Cross-publication consistency review.

Roles and accountability

A small organisation can combine roles, but it should not allow one person to create, review and approve a material claim without independent challenge. The most important distinction is between ownership of the underlying information, preparation of the disclosure and accountability for publication.

In practice

Role Core responsibility Should not do alone
Reporting owner Maintains reporting architecture, timetable, standards mapping, Content Index and release pack. Validate specialist source data or approve every claim without business-owner sign-off.
Data owner Owns the underlying process, system, policy or operational record. Assume the reporting definition is identical to the operational definition.
Preparer Extracts data, applies methodology, documents assumptions and drafts the disclosure. Provide the only review of their own work.
Technical reviewer Checks requirement, scope, method, evidence, calculation and caveats. Replace missing evidence with editorial judgement.
Business approver Confirms factual accuracy, business context and public wording within the function. Approve a result they have not reviewed or cannot explain.
Governance approver Approves material topics, significant judgements, report or statement of use as defined by governance arrangements. Rely on a presentation that omits critical gaps and unresolved findings.
Publisher / controller Locks version, references, links, files and publication package. Change approved content without re-opening review.
Internal audit / assurance readiness Tests design and operation of controls and reports findings. Become the preparer or management owner of the disclosures tested.

In practice

RACI for a typical disclosure cycle

Activity Reporting owner Data owner / preparer — Technical reviewer — Approver — Publisher
Define requirement and boundary A/R C — C — I — I
Provide source evidence C A/R — I — I — I
Calculate or draft A R — C — I — I
Document estimates and judgement A R — C — C — I
Perform independent review C I — A/R — I — I
Resolve findings A/R R — C — C — I
Approve disclosure C C — C — A/R — I
Map Content Index reference A/R I — C — I — C
Lock and publish version C I — I — A — R
Archive evidence and change log A/R C — C — I — R

Rule

SEPARATION PRINCIPLE

Where staffing is limited, the same person may be both data owner and preparer, or reporting owner and publisher. Material claims should still receive an independent technical or management review. The reviewer must have access to the source, method and assumptions—not only the final number.

A reusable control matrix

The matrix below can be adapted by disclosure. Controls should be specific enough to operate and evidence, but not so numerous that the team performs a ceremonial checklist without testing the real risk.

In practice

Control ID Risk Control activity — Evidence — Frequency / owner
C01 — Scope Entities, sites, workers or value-chain categories are omitted or included inconsistently. Reconcile the disclosure boundary to approved entity/site/population registers and document departures. — Boundary memo, reconciliation and approval. — Annual and on change / reporting owner.
C02 — Source completeness Expected source files or periods are missing. Expected-source checklist; automated or manual completeness flags; gap owner and due date. — Source register and gap log. — Each reporting close / data owner.
C03 — Calculation Formula, unit, factor or aggregation error changes the metric. Independent recalculation of material values; locked formula and approved factor tables. — Reviewer copy, formula check and sign-off. — Each disclosure / technical reviewer.
C04 — Estimate Estimate is used without method, coverage or uncertainty. Estimate register records method, assumptions, affected coverage, sensitivity and approval. — Estimate memo and approval. — Each estimate / data owner and reviewer.
C05 — Narrative claim Wording overstates policy, causality, effectiveness, alignment or achievement. Claim-to-evidence review; balance challenge; weak versus strong wording test. — Claim ledger, evidence links and reviewer comments. — Each draft / technical reviewer.
C06 — External data Dataset is outdated, inapplicable or used outside its licence or resolution. Dataset due diligence: source, version, geography, method, licence, limitations and extraction date. — External-data register. — At onboarding and update / specialist owner.
C07 — Consolidation Site/entity totals are duplicated, omitted or adjusted without traceability. Site-level sign-off, group reconciliation, duplicate check and consolidation-adjustment log. — Signed site packs and consolidation file. — Each close / group controller.
C08 — Consistency Report, website, annual report and Content Index contain contradictory information. Cross-publication reconciliation of material metrics, claims, dates and governance statements. — Consistency checklist and resolved findings. — Pre-publication / reporting owner.
C09 — Change / restatement Late edits or methodology changes bypass approval. Controlled change request; impact analysis; re-review; version lock; restatement assessment. — Change log and release approval. — On change / publisher.
C10 — Publication reference Content Index link or page reference does not lead to complete information. Requirement-level click-through test against final files and accessible links. — Final Content Index review pack. — Pre-release / reviewer and publisher.

Quantitative controls: more than checking arithmetic

A recalculation is necessary but not sufficient. A perfectly calculated figure can use the wrong population, period or definition. Quantitative review should therefore test the definition, source completeness, transformation, aggregation and final presentation.

• Definition test: the metric matches the applicable GRI requirement and the organisation’s disclosed methodology.

• Population test: all relevant entities, sites, workers, transactions or value-chain categories are included once.

• Cut-off test: records belong to the reporting period and late or accrued information is controlled.

• Unit test: original units, conversion factors and converted values are preserved and approved.

• Formula test: material calculations are independently recalculated or reproduced.

• Movement test: unusual trends and outliers have operational explanations and evidence.

• Aggregation test: site totals, group adjustments and published total reconcile.

• Presentation test: units, decimals, comparatives, estimates and restatements are labelled correctly.

Narrative-claim controls

Narrative disclosure is often the largest control gap. Statements about policy, due diligence, board oversight, effectiveness, stakeholder support, alignment or ‘zero incidents’ can be more reputationally sensitive than a metric. The reviewer should identify the factual propositions inside each sentence and test them separately.

In practice

Claim type Evidence expected Reviewer challenge
Existence of policy or commitment Current approved document, scope, effective date and owner. Does the policy cover the stated entities and business relationships?
Process or governance operation Terms of reference, workflow, reports, minutes and decisions during the period. Did the process actually operate, or is only the design described?
Effectiveness Outcome trend, target result, independent review, grievance resolution or other outcome evidence. Is the statement about outcomes, or only activity completed?
Causality Analysis showing that the stated action contributed to the observed outcome and alternative explanations were considered. Does the evidence support causation or only correlation?
Stakeholder support / consent Engagement record, representation, concerns, agreement terms and unresolved issues. Is attendance or absence of complaints being presented as support?
Alignment / compliance Defined criteria, scope, mapping, gap assessment and approval. Is the claim broader than the assessment performed?
Absence of incidents Reliable reporting channels, coverage, definitions and assurance over completeness. Does ‘no reported incidents’ mean no incidents occurred?

Take it with you

The checklists as a working spreadsheet

Every checklist and table on this page, with empty status, owner and evidence columns for your team to fill in and keep.

Download .xlsx

✓ LRA AI Assistant · Human-in-the-loop

Ask about this guide

It answers from this page, and reaches into the linked disclosure cards when your question is about the standard itself. Your first two answers are free without signing in.

Try
2 free answers Automated · the LRA team is one click away

Go deeper · GRI

GRI Standards Certified Training

A full reporting cycle with a mentor: impact inventory, threshold, Topic Standard selection, Content Index and assurance readiness.

Available as Guided Flex, Live Cohort, 1:1 Expert Mentorship or Corporate Programme.

See course formats
/en/knowledge-hub/disclosure-guides/gri/gri-evidence-controls-and-assurance/internal-controls-for-gri-reporting-data-owners-reviewers-and-approval/