Skip to the answer

Disclosure GuidesPillar guides, articles, FAQ and expert notes

Level 2 · Decision guide·GRI · Disclosure guides

GRI Materiality Assessment without Reliable Data: Expert Judgement, Assumptions and Uncertainty

How to use qualitative evidence, external sources, scenarios and precautionary logic when quantitative data are incomplete — with confidence anchors, an uncertainty register and reviewer questions

Who this is for A 18-minute read for reporting teams working through Impact materiality and determining material topics, and for reviewers testing whether the evidence behind it holds.

Published passport

Current as at 11 August 2026
RK Reviewed by Dr Ross KurinkoLinkedIn Strategic ESG Advisor · IFRS S1 & S2 / GRI / ESRS expert GRI Certified Global Trainer · PhD, University of Cambridge · ESG-AI expert 15+ years on FTSE 100 & Fortune Global 500 disclosures Canary Wharf, London LRA educational guidance · Not issued or endorsed by GRI

Edition written against

This article provides an evidence and judgement framework, not a scientific, engineering, human-rights, medical, legal or …

Published

12 Aug 2026

Knowledge Hub guide

Last reviewed

11 Aug 2026

Short answer

The answer, before the reasoning

A GRI materiality assessment does not have to stop because quantitative data are incomplete. GRI 3 allows significance to be assessed through quantitative and qualitative analysis and recognises that subjective judgement may be necessary.

The organisation should use the best available evidence — operational records, incidents, stakeholder and rights-holder input, expert knowledge, authoritative external sources, proxies, scenarios and reasonable estimates — while documenting assumptions, source limitations, confidence and bias controls. Missing data must not be converted into a zero score. Plausible severe human-rights or irreversible environmental impacts should be escalated for further investigation and governance attention even where likelihood or measurement confidence is uncertain.

ANSWER | EXPLAIN | APPLY | EVIDENCE | CONNECT | PUBLISH

Article map

This Knowledge Card gives a direct answer, explains the technical logic, shows how to apply it, identifies the evidence needed, and provides a controlled publishing package. Requirements, recommendations, implementation practice and expert interpretation are kept distinct.

In practice

Stage What the reader will get
1 Direct answer and why it matters
2 Technical explanation and distinctions
3 Practical method, mapping and examples
4 Common mistakes, myth correction and reviewer checklist
5 Related standards, source status and update triggers
6 Editorial, SEO, visual and CMS package

Why “we do not have data” is not a materiality conclusion

The least visible impacts are often the ones for which organisations have the weakest data: labour conditions beyond tier-one suppliers, effects on informal workers, biodiversity change around remote sourcing areas, community displacement, product misuse or impacts affecting people who cannot safely use grievance channels. Treating a missing number as evidence of low significance can systematically exclude the most vulnerable groups.

At the same time, expert judgement can be abused. An undocumented workshop opinion, a vendor risk score or a generic country ranking should not be presented as proof. The objective is controlled judgement: define the impact, assemble diverse evidence, distinguish fact from assumption, assess significance, rate confidence separately, challenge bias, approve the decision and improve the evidence base over time.

GRI 1 reinforces this discipline through the reporting principles. Estimated data, assumptions, techniques and limitations should be explained; decisions, calculations and original sources should be documented so the information can be examined. Uncertainty is therefore not a reason to hide the process. It is information that the process and disclosure should manage.

In practice

Quick orientation

Question Practical answer
Can qualitative evidence support materiality? Yes. GRI 3 refers to quantitative and qualitative analysis and to input from stakeholders and experts. The evidence and judgement must be documented.
Does low data confidence mean low impact significance? No. Confidence describes the evidence base; significance describes the impact. They should be recorded separately.
Can we use estimates or proxies? Yes where reasonable and controlled. Record the method, assumptions, coverage, limitations and improvement plan.
What if external sources indicate severe harm but company data show no incidents? Investigate the plausible pathway and whether internal systems are capable of detecting the harm. Absence of recorded incidents may reflect underreporting or weak coverage.
Should likelihood be used for actual impacts? No. Under GRI 3, actual negative impact significance is determined by severity; potential negative impact significance uses severity and likelihood.
What deserves escalation? Plausible severe or irremediable impacts, vulnerable or marginalised groups, major evidence disagreement, and conclusions sensitive to a single unsupported assumption.

In practice

The source-grounded basis for judgement under uncertainty

Layer What it means in practice
GRI 3 guidance The organisation uses quantitative and qualitative analysis to understand the significance of impacts and can use stakeholder and expert input. Subjective judgement may be needed.
GRI 3 guidance Actual negative impact significance is determined by severity; potential negative impact significance is determined by severity and likelihood.
GRI 3 guidance The organisation should document the process, including decisions, assumptions, subjective judgements, sources and evidence, and use a systematic, replicable approach.
GRI 3 resource constraint guidance Where resources are limited, the organisation should first identify negative impacts. Initial scoping can use internal and external information and should not become a permanent blind spot.
GRI 1 accuracy Identify estimated data and explain assumptions, techniques and limitations.
GRI 1 verifiability Document decisions and sources, support assumptions and calculations, and retain evidence that allows the reported information to be examined.
LRA implementation practice Maintain separate significance and confidence ratings, an uncertainty register, severe-impact escalation rules and documented bias challenge.

1. Separate three questions that teams often collapse

A low-confidence but plausible severe impact may require priority investigation and may still be significant. A high-confidence dataset about a minor operational inconvenience does not make that impact severe. Recording significance and confidence in separate fields prevents evidence weakness from silently lowering the materiality score.

In practice

Question What it asks What it must not be confused with
What is the impact? Who or what may be affected, through which activity or business relationship, where and over what time horizon? A topic label such as “human rights” or “biodiversity”.
How significant is it? For negative impacts: severity, and likelihood for potential impacts; for positive impacts: scale and scope, with likelihood for potential impacts. How confident the team is in the available data.
How strong is the evidence? Coverage, source quality, directness, consistency, recency, independence and uncertainty. The significance conclusion itself.

2. Build an evidence ladder, not an evidence hierarchy that excludes qualitative sources

Direct verified data are valuable, but they are not the only legitimate evidence. Worker testimony may reveal recruitment fees that payroll data do not show. Satellite and scientific datasets may identify habitat conversion before a supplier audit occurs. A grievance mechanism with no complaints may say little where workers fear retaliation. The assessment should triangulate sources and explain what each source can and cannot establish.

Figure 1. Evidence can range from observed data to scenarios and expert judgement. Confidence should increase with directness and traceability, but severe-impact escalation remains separate.

In practice

Evidence category Examples Strengths — Limitations to record
Observed operational data Incidents, measurements, inspection results, payroll, production, health and safety, environmental monitoring. Direct connection to activities and periods; often reproducible. — Coverage gaps, underreporting, system boundaries, measurement error and incentives.
Stakeholder and rights-holder evidence Worker interviews, community consultations, grievances, union or civil-society evidence. Shows lived effects, affected groups and issues hidden by systems. — Safety, representation, sampling, confidentiality, corroboration and potential retaliation.
Business-relationship evidence Supplier audits, contracts, corrective actions, traceability, customer complaints, distributor records. Connects impacts beyond operations. — Audit quality, announced visits, tier coverage, conflict of interest and incomplete traceability.
Authoritative external sources Regulators, courts, scientific studies, sector reports, geographic risk data, international organisations. Provides context where company data are weak and supports scoping. — May be general, historical, modelled or not specific to the organisation.
Expert judgement Environmental, engineering, human-rights, health, product or local-context specialists. Interprets complex pathways and sparse evidence. — Qualifications, independence, assumptions, disagreement and scope.
Proxy or modelled data Industry factors, satellite data, representative samples, extrapolation, scenarios and risk models. Provides an analytical bridge until direct data improve. — Model fit, spatial/temporal resolution, uncertainty, sensitivity and potential bias.

3. Define the impact before choosing the evidence

A vague request for “better data on forced labour” or “more biodiversity data” rarely solves the assessment. The impact record should identify the activity or relationship, affected people or environmental component, mechanism of harm, geography, time horizon and whether the impact is actual or potential. Evidence can then be collected for the specific pathway.

In practice

Impact field Illustrative prompt
Activity / relationship Which operation, supplier tier, product, customer use or disposal route is connected to the impact?
Affected people or environment Which workers, communities, consumers, species, habitats or ecosystem services may be affected?
Mechanism How could the activity create the change — exposure, displacement, recruitment debt, pollution, extraction, land conversion or product failure?
Actual or potential Has harm occurred, or is there a plausible pathway that could lead to harm?
Geography and time Where could it occur, over what period, and could the effect be delayed or cumulative?
Involvement Does the organisation cause, contribute to or remain directly linked through a business relationship?
Existing evidence What directly observed, stakeholder, external or modelled information supports or challenges the pathway?
Decision need What significance, management, disclosure or data-improvement decision must be made?

4. Use explicit qualitative scoring anchors

GRI does not prescribe a numerical scoring scale. An organisation may use qualitative anchors, numerical scales or a combination, provided the method reflects the relevant significance dimensions and does not hide judgement. Under weak data conditions, qualitative anchors are often more honest than invented precision.

The anchors should be supported by examples and reviewer questions relevant to the organisation. They should not mechanically average away an extreme severity dimension. The method should also explain how positive impacts are assessed and how actual and potential impacts are kept distinct.

In practice

Dimension Lower anchor Middle anchor — Higher anchor
Scale Limited or minor change to well-being or environment. Serious impairment, material loss or significant degradation. — Life-threatening, fundamental rights affected, extensive or catastrophic environmental harm.
Scope Small, contained group or area. Multiple groups, sites, communities or a substantial ecosystem area. — Widespread population, value-chain or landscape/seascape effect.
Irremediable character Restoration is timely and reasonably complete. Recovery is difficult, lengthy or only partial. — Restoration is impossible, highly uncertain, generational or cannot restore affected rights/lives.
Likelihood for potential impact Plausible but limited exposure or weak pathway. Credible pathway with meaningful exposure or repeated sector evidence. — Expected, frequent, imminent or supported by strong exposure and control-failure evidence.

5. Rate confidence separately

Confidence is an implementation control rather than a GRI-prescribed score. A simple High / Medium / Low classification can be effective when it has defined anchors and is not used to downgrade significance.

In practice

Confidence level Illustrative anchor Required response
High Multiple current, direct and consistent sources; good coverage; method and ownership clear; no material contradiction. Proceed with the conclusion and retain normal monitoring and verification.
Medium Evidence is credible but incomplete, partly indirect, modelled, uneven across sites or subject to explainable disagreement. Document limitations, test sensitivity, seek corroboration and set a focused improvement action.
Low Sparse or old data; weak coverage; one unverified source; major disagreement; detection systems may be ineffective. Do not treat as zero. Escalate plausible severe impacts, use precautionary scoping, commission additional evidence and schedule early review.

6. Apply a controlled uncertainty workflow

Figure 2. Uncertainty workflow from defining the impact through evidence, confidence, severe-impact escalation, approval and disclosure of limitations.

1. Define the impact precisely and classify it as actual or potential.

2. Describe the data gap: missing population, supplier tier, geography, measurement, period, incident detection or methodology.

3. Assemble diverse evidence: internal records, stakeholders, business relationships, external sources, experts, proxies and scenarios.

4. Assess significance using the relevant GRI dimensions and qualitative or quantitative anchors.

5. Rate evidence confidence separately and identify the assumptions on which the conclusion depends.

6. Escalate plausible severe, irremediable or human-rights impacts for specialist and governance review even where data are weak.

7. Record the materiality decision, rationale, dissent, monitoring, management and data-improvement actions.

8. Disclose methods, estimates, assumptions, incomplete coverage and limitations where they affect the reported information.

7. Create an uncertainty register

The uncertainty register should sit beside the impact inventory, not in a separate file that reviewers never see. It makes assumptions and improvement actions part of the decision trail.

In practice

Field What to record
Uncertainty ID Stable identifier linked to the impact and topic.
Gap statement Exactly what is unavailable, incomplete, inconsistent or modelled.
Affected decision Impact existence, actual/potential status, severity, likelihood, scope, boundary or topic aggregation.
Available evidence Sources, dates, owners, directness and coverage.
Assumption / proxy The temporary analytical bridge and why it is reasonable.
Confidence High, Medium or Low using approved anchors.
Sensitivity How the significance conclusion changes under plausible alternative assumptions.
Severe-impact flag Human-rights, vulnerable-group, catastrophic or irreversible harm requiring escalation.
Decision and rationale Material, not material, monitor, investigate or unable to conclude — with basis.
Improvement action Data request, audit, stakeholder engagement, site study, model validation or system change.
Owner and date Accountable person, deadline, reviewer and next assessment date.
Disclosure effect Estimate note, limitation, reason for omission where applicable or no public consequence.

In practice

8. Control common sources of bias

Bias How it appears Control
Availability bias Only impacts with internal metrics appear significant. Use sector, geographic, stakeholder and scientific sources to identify hidden impacts.
Management optimism Existing policy is treated as proof that harm is unlikely or minor. Assess inherent impact and control effectiveness separately; require outcome evidence.
Complaint bias No grievance is interpreted as no impact. Test access, trust, retaliation risk, language, worker status and alternative channels.
Aggregation bias Average group data hide severe site or supplier conditions. Assess disaggregated locations, groups and relationships before consolidation.
Expert dominance One senior or technical voice determines the conclusion. Record qualifications, conflicting views and independent challenge; include affected perspectives.
Precision bias A numerical score looks objective despite weak assumptions. Use explicit anchors, show uncertainty and avoid false decimal precision.
Confirmation bias Evidence is selected to preserve the prior topic list. Assign a red-team reviewer to seek disconfirming evidence and near-threshold impacts.
Commercial bias A topic is downgraded because disclosure is inconvenient. Separate reporting consequence from significance assessment and record governance challenge.

In practice

9. Apply different evidence strategies to different gaps

Scenario Reasonable interim evidence Do not conclude
Supplier labour risk Country/sector evidence, recruitment model, worker interviews, audit quality, grievance accessibility and supplier traceability. “No forced labour” merely because no confirmed case exists.
Biodiversity around remote sourcing Geospatial datasets, ecosystem sensitivity, land-use change, commodity drivers, supplier origin and expert review. Low impact because site-level ecological measurements are unavailable.
Workforce incident underreporting Medical data, absenteeism, near misses, worker representatives, contractor records and safety-culture evidence. Low frequency based only on the formal incident log.
Downstream product impact Complaints, recalls, user testing, vulnerability analysis, market surveillance and scenario pathways. Low significance because the organisation does not control customer use.
Community displacement risk Project plans, land tenure, community consultation, rights-holder evidence, legal records and independent social assessment. Low likelihood because permits were granted or compensation is budgeted.

10. Know what to disclose about uncertainty

The materiality methodology should explain the main sources and evidence, how qualitative and quantitative information were used, the role of stakeholders and experts, and the decision process. Where estimates or incomplete data affect reported metrics or narrative, the disclosure should state the coverage, assumptions, method and limitations. The organisation should avoid implying a level of precision that the evidence does not support.

Identify which data are estimated or modelled and the reporting boundary they cover.

Explain why the proxy or scenario was selected and how it was tested.

State material limitations, uncertainty and known exclusions.

Distinguish absence of evidence from evidence that an impact is absent.

Describe the role of experts, affected stakeholders and rights-holders without exposing confidential information.

Explain how severe impacts were escalated and how disagreements were resolved.

Provide a time-bound data-improvement or verification action where the gap is material.

Use reasons for omission only where the GRI conditions are met; do not use narrative uncertainty to disguise missing required information.

In practice

Hypothetical case: recruitment-fee risk in an apparel supply chain

Element Illustrative case
Organisation An apparel brand buys from 120 factories and has verified worker-level evidence for only 25 factories. Several production countries rely on labour recruiters.
Potential impact Migrant workers may pay recruitment fees, incur debt and face restrictions that create a risk of forced labour. The brand is directly linked through supplier relationships and may contribute where purchasing practices intensify pressure.
Data gap Supplier self-assessments report no confirmed cases; worker grievance use is very low; tier-two recruitment channels are largely untraced.
External and qualitative evidence Authoritative sector evidence, recruiter practices, NGO information, anonymous worker interviews, audit-quality review and purchasing-practice analysis indicate a credible severe pathway.
Significance assessment Potential severity is high because fundamental rights and freedom may be affected and remedy can be difficult. Likelihood is assessed as at least credible in exposed corridors, despite low company-data confidence.
Confidence Medium for the existence of exposure; Low for group-wide prevalence. The confidence gap does not reduce the severity conclusion.
Decision The impact is prioritised as significant. The company expands worker voice, recruiter due diligence, fee-repayment controls and traceability, and commissions targeted investigation.
Disclosure and protection The methodology explains data limitations and external evidence without identifying workers or active cases. Effectiveness is not claimed until outcome evidence exists.

In practice

Illustrative methodology and uncertainty wording

Annotation Why it matters
Reason for qualitative evidence Explains why the assessment did not rely solely on metrics.
Source diversity Reduces dependence on one internal system or expert.
Separate confidence Prevents weak evidence from mechanically downgrading significance.
Severity escalation Shows a safeguard for hidden severe impacts.
Controlled improvement Connects uncertainty to an owner and action rather than vague future ambition.

In practice

Weak versus stronger uncertainty wording

Weak wording / approach Why it is weak Stronger direction
“No data were available, so the impact was scored zero.” Missing information is treated as proof that no impact exists. Record the gap, use available evidence, assess plausible significance and assign a confidence and investigation action.
“Expert judgement confirmed the topic was not material.” The expert, evidence, criteria, assumptions and challenge are invisible. Identify the expertise, sources, judgement rationale, dissent, limitations and approval.
“No complaints were received.” The statement ignores access, fear, representation and detection-system quality. Explain channel coverage and triangulate with worker/community and external evidence.
“Industry data were used.” No source, relevance, period or transfer assumption is given. Name the authoritative source, explain why it applies and describe sensitivity and limitations.
“The estimate is reliable.” Reliability is asserted without method or uncertainty. Describe the estimation technique, assumptions, coverage, validation and limitations.

In practice

Common mistakes and corrections

Mistake Risk Correction
Entering zero for missing data Systematically suppresses hidden or under-monitored impacts. Use unknown status, qualitative evidence, confidence and escalation.
Treating no grievance as no harm Weak or unsafe mechanisms create false reassurance. Assess accessibility and use alternative evidence.
Averaging confidence into severity A severe impact can disappear because measurement is difficult. Maintain separate fields and decision rules.
One expert decides without challenge Personal bias becomes an undocumented rule. Record qualifications, assumptions, dissent and independent review.
Using generic country risk as the final answer External context is not organisation-specific proof. Use it for scoping and likelihood, then connect it to activities, relationships and controls.
Hiding estimates in polished narrative Readers cannot understand accuracy or limitations. Label estimates, assumptions, techniques and coverage.
No improvement owner The same uncertainty repeats every reporting cycle. Assign action, budget, owner, deadline and review trigger.

Rule

Myth: “A topic cannot be material until we have reliable quantitative data.”

Reality: GRI materiality concerns the significance of impacts, not the maturity of the measurement system. Qualitative evidence, stakeholder and expert input, external sources, scenarios and reasonable estimates can support the decision. The organisation must document judgement and uncertainty and improve material evidence gaps. Why the confusion arises: Metrics feel objective and assurance-ready, so teams mistake measurability for significance. This can exclude human-rights, biodiversity and value-chain impacts precisely because they are difficult to measure.

Readiness

Reviewer checklist

  • Is each impact defined at the level of affected people or environment, activity/relationship, geography and pathway?
  • Have actual and potential impacts been kept distinct?
  • For actual negative impacts, is significance based on severity rather than likelihood?
  • For potential negative impacts, are severity and likelihood supported by available evidence?
  • Is missing information recorded as a gap rather than a zero?
  • Does the evidence base include relevant stakeholder, rights-holder, expert and authoritative external sources?
  • Are proxies, estimates, models and scenarios documented with assumptions and limitations?
  • Is confidence rated separately from impact significance?
  • Are plausible severe human-rights and irreversible environmental impacts escalated?
  • Have vulnerable or underrepresented groups and detection-system weaknesses been considered?
  • Has an independent reviewer sought disconfirming evidence and challenged bias?
  • Does the uncertainty register include sensitivity, owner, action and review date?
  • Does public wording explain material limitations without exposing confidential cases?
  • Are reasons for omission applied only where the GRI requirements allow them?

In practice

Related standards and next steps

Relationship Reference Practical use
Direct GRI 3: Material Topics 2021 Quantitative and qualitative analysis, significance, documentation and stakeholder/expert input.
Direct GRI 1: Foundation 2021 Accuracy, completeness and verifiability; estimates, assumptions and limitations.
Application Actual versus potential impacts under GRI Correct use of likelihood.
Application Scale, scope and irremediable character Severity assessment anchors.
Application Human-rights impacts: severity can override likelihood Escalation for severe harm and vulnerable groups.
Next step Build an uncertainty register Operational template for gaps, confidence and actions.
Advanced Assurance review of estimates and materiality judgement Prepare evidence and challenge documentation.

Do not convert missing supplier data into a zero score or treat absence of evidence as proof that an impact is absent. Use the best available qualitative and quantitative evidence, such as worker or rights-holder input, external sources, proxies, scenarios and reasonable estimates; document coverage, assumptions, limitations and confidence separately, escalate plausible severe impacts, and set a time-bound improvement action.

Questions

Questions people ask

Can GRI materiality use qualitative evidence?

A GRI materiality assessment does not have to stop because quantitative data are incomplete. GRI 3 allows significance to be assessed through quantitative and qualitative analysis and recognises that subjective judgement may be necessary. The organisation should use the best available evidence — operational records, incidents, stakeholder and rights-holder input, expert knowledge, authoritative external sources, proxies, scenarios and reasonable estimates — while documenting assumptions, source limitations, confidence and bias controls.

Can we use estimates?

GRI 3 allows significance to be assessed through quantitative and qualitative analysis and recognises that subjective judgement may be necessary. The organisation should use the best available evidence — operational records, incidents, stakeholder and rights-holder input, expert knowledge, authoritative external sources, proxies, scenarios and reasonable estimates — while documenting assumptions, source limitations, confidence and bias controls.

Does low confidence mean low materiality?

Confidence is an implementation control rather than a GRI-prescribed score. A simple High / Medium / Low classification can be effective when it has defined anchors and is not used to downgrade significance.

What if supplier data are missing?

Do not convert missing supplier data into a zero score or treat absence of evidence as proof that an impact is absent. Use the best available qualitative and quantitative evidence, such as worker or rights-holder input, external sources, proxies, scenarios and reasonable estimates; document coverage, assumptions, limitations and confidence separately, escalate plausible severe impacts, and set a time-bound improvement action.

How should expert judgement be documented?

Qualitative evidence, stakeholder and expert input, external sources, scenarios and reasonable estimates can support the decision. The organisation must document judgement and uncertainty and improve material evidence gaps.

Take it with you

The checklists as a working spreadsheet

Every checklist and table on this page, with empty status, owner and evidence columns for your team to fill in and keep.

Download .xlsx

✓ LRA AI Assistant · Human-in-the-loop

Ask about this guide

It answers from this page, and reaches into the linked disclosure cards when your question is about the standard itself. Your first two answers are free without signing in.

Try
2 free answers Automated · the LRA team is one click away

Go deeper · GRI

GRI Standards Certified Training

A full reporting cycle with a mentor: impact inventory, threshold, Topic Standard selection, Content Index and assurance readiness.

Available as Guided Flex, Live Cohort, 1:1 Expert Mentorship or Corporate Programme.

See course formats
/en/knowledge-hub/disclosure-guides/gri/gri-impact-materiality/gri-materiality-assessment-without-reliable-data-expert-judgement-assu/