Short answer
The answer, before the reasoning
A TNFD-aligned risk and impact management process should cover both direct operations and the upstream and downstream value chain, while making the differences between them visible. Direct operations can normally be assessed using asset, site, permit, production and incident data.
Value-chain assessment more often needs risk-based screening, commodity and geography analysis, traceability, supplier or customer engagement, contractual controls and governed estimates. The resulting process should prioritise material issues, apply the mitigation hierarchy, connect nature-related risks to enterprise risk management and retain evidence showing how decisions, actions and monitoring changed over time.
Technical status
TECHNICAL STATUS
The TNFD Recommendations are final voluntary recommendations. Risk and Impact Management recommended disclosures A(i), A(ii), B and C distinguish direct operations, value chains, management responses and integration into overall risk management. LEAP and other TNFD guidance support implementation but are not a separate mandatory alignment test. Source set checked 3 August 2026.
Rule
LIMITATION
Educational implementation guidance. It does not determine a particular organisation's materiality, legal obligations, due-diligence duties, ecological outcome or assurance conclusion.
Why the process has to be split before it can be integrated
Nature-related issues are often managed through existing environmental, procurement, operational and enterprise-risk systems. Reuse is sensible, but an unchanged risk process can miss two central features of nature: the importance of location and the distinction between dependencies, impacts, risks and opportunities.
Control also differs. At an owned facility, the organisation may control equipment, land management, water abstraction, pollution controls and restoration. In an upstream commodity chain, it may have influence only through specifications, sourcing choices, commercial terms, engagement and collective action. Downstream, the interface may arise during product use, disposal, customer behaviour, financed activities or infrastructure operated by another party. One governance model can oversee the programme, but the evidence, levers and escalation points should differ.
Quick orientation: four connected disclosure questions
Figure 1. A controlled nature process moves from interfaces and causal pathways to decisions, action, ERM integration and monitoring.
In practice
| TNFD process question | What the organisation should explain | Typical controlled evidence |
|---|---|---|
| Direct operations | How dependencies, impacts, risks and opportunities are identified, assessed and prioritised at assets, sites and projects. | Asset and location register, permits, monitoring data, incidents, ecological studies and operating controls. |
| Upstream and downstream value chain | How material issues are screened and assessed where data and control are more limited. | Commodity and geography screening, traceability, supplier/customer data, estimates, contracts and engagement records. |
| Management | How material issues are managed and monitored, including response sequencing and progress. | Action plans, mitigation-hierarchy decisions, budgets, target and metric registers, issue logs and monitoring reports. |
| Integration | How the process connects to enterprise risk, strategy, capital allocation and decision-making. | ERM taxonomy, risk appetite, committee papers, financial pathways, escalation criteria and management reporting. |
What TNFD expects - and what it does not prescribe
TNFD asks an organisation to describe its processes, not merely state that a generic risk policy exists. A reader should be able to understand what is assessed, which boundaries and locations are covered, how material issues are prioritised, how responses are chosen and monitored, and how the process connects to overall risk management.
TNFD does not prescribe one universal scoring matrix, supplier questionnaire, software platform or organisational model. Nor does it require every internal assessment metric to be published. An organisation may use LEAP, an environmental and social management system, an ERM methodology, a due-diligence process or a combined approach. The control is whether the process can identify location-specific dependencies and impacts and translate them into material risks and opportunities under the stated materiality approach.
An eight-step operating model
Step 1 - lock governance, scope and terminology
Define the reporting objective, materiality approach, entity boundary, value-chain segments, time horizons, nature realms and priority sectors. Establish a controlled glossary for dependency, impact, risk, opportunity, response and residual impact. Assign owners for direct operations, procurement, product or portfolio exposures, risk integration, finance and disclosure.
The minimum output is an approved methodology and RACI. It should state what is assessed in detail, what is screened, what is excluded, how the scope will expand and which committee approves material judgements.
Step 2 - build the interface and location population
For direct operations, reconcile the asset register to sites, projects, permits, production processes and land or water interfaces. Record coordinates, biome or ecosystem context, basin, sensitive-location indicators, nearby communities and rights holders, and data quality.
For value chains, begin with a decision-useful population: commodities, purchased materials, supplier groups, sourcing geographies, product families, use phases, disposal routes or portfolio sectors. Screening may use spend or volume, but spend is not a substitute for ecological relevance. A low-cost commodity can carry high conversion, water or pollution exposure.
Step 3 - identify dependency and impact pathways
A useful pathway connects the business activity or relationship; the ecosystem service or natural input on which it depends; the impact driver created or influenced; the resulting change in the state of nature or ecosystem services; affected people and rights holders; and the evidence and confidence supporting the conclusion.
This prevents the register becoming a list of labels such as water, biodiversity and deforestation. A factory may depend on reliable basin flows while also contributing to water stress or pollution. Both pathways may matter, but they lead to different responses and disclosures.
Step 4 - translate pathways into risks and opportunities
Assess how dependencies and impacts could affect operations, strategy, reputation, legal exposure, market access, capital expenditure, financing or cash flows. Classify physical, transition and systemic risks where useful, and record opportunities without treating every environmentally themed initiative as an opportunity.
The record should identify the time horizon, location or value-chain node, affected business line, likelihood or uncertainty, magnitude, financial pathway, existing controls and decision owner. Where quantitative financial effects are not robust, a controlled qualitative pathway is stronger than unsupported precision.
Step 5 - prioritise with separate but connected criteria
Do not collapse impact importance and financial risk into one unexplained score. Under a financial-materiality approach, the organisation prioritises nature-related information relevant to primary users. Under an impact or double-materiality approach used for another reporting purpose, significant impacts may require a separate test. Evidence can be shared, but the criteria and approvals should remain traceable.
Priority can reflect ecological sensitivity, severity and likelihood of impacts, dependency criticality, exposure, vulnerability, control effectiveness, financial consequence, rights-holder concerns and ability to influence outcomes. Explain thresholds, qualitative overrides and escalation for high-severity or highly uncertain issues.
Step 6 - choose and sequence responses
For negative impacts, apply the mitigation hierarchy: avoid first, then minimise, restore or regenerate, and consider offsets only for significant residual impacts after prior steps. For dependencies and risks, responses can also include resilience, diversification, monitoring, supplier development, product redesign, insurance, capital investment and strategic transformation.
Each response needs an owner, location and boundary, timetable, budget, expected outcome, metric, target where applicable, dependencies and evidence. Separate activity completion from ecological or risk outcome. A supplier workshop is an action; it is not evidence that conversion or pollution declined.
Step 7 - integrate into enterprise risk management
Create a crosswalk between nature-related issue types and the enterprise taxonomy. Decide which items become enterprise risks, which remain operational or project risks, and which are monitored through sustainability or due-diligence processes.
Integration should cover common risk owners and committees; appropriate time horizons; risk appetite or tolerance where relevant; financial and strategic consequence fields; control assessment and residual risk; scenario or sensitivity analysis for selected issues; capital-allocation and business-planning links; and escalation for incidents, regulatory changes or ecological deterioration.
Integration does not mean erasing impact information that does not yet meet an enterprise financial-risk threshold. Preserve the underlying impact and dependency records and explain how they inform other decisions.
Step 8 - monitor, challenge and disclose
Monitor leading indicators, operational outputs, outcome indicators, incidents, control performance and external changes. Reassess after acquisitions, new sites, major supplier changes, severe events, material complaints, regulatory developments or deteriorating state-of-nature indicators.
A reviewer should be able to trace each material statement from report wording to the issue register, evidence, decision, action, metric and approval. Findings should remain open until correction evidence is independently retested.
Direct operations and value chains require different controls
Figure 2. Common governance can oversee both boundaries, but the evidence and management levers differ.
In practice
| Control dimension | Direct operations | Upstream and downstream value chains |
|---|---|---|
| Population completeness | Reconcile legal entities, assets, permits, equipment and projects. | Reconcile commodities, suppliers, tiers, geographies, products, customers or portfolio exposures. |
| Location evidence | Precise coordinates and local ecological context are usually possible. | Origin may be known only at country, region, landscape or supplier level; uncertainty must be visible. |
| Primary data | Meters, monitoring, inspections, incidents and production data. | Supplier/customer submissions, traceability, certification, models and proxies. |
| Control leverage | Procedures, engineering, capex and land management. | Sourcing, specifications, contracts, engagement, incentives, collaboration and exit. |
| Verification | Site checks, calibration, sampling and specialist surveys. | Chain-of-custody tests, sample audits, supplier evidence and plausibility checks. |
| Remediation | Direct corrective action and restoration may be available. | Leverage, collective action and remedy depend on the relationship and facts. |
Practical value-chain safeguards
A risk-based process should avoid claiming complete knowledge when origins are uncertain, but poor traceability is not a reason to exclude a potentially material issue. Useful safeguards include a controlled origin-confidence scale; commodity- and geography-specific screening; supplier population and response-rate reconciliations; criteria for requesting primary data; validation of certification and chain-of-custody claims; treatment of non-response and estimates; contractual requirements; corrective-action routes; rights-holder inputs; and a plan for deeper tiers or unresolved origins.
Hypothetical example - diversified building-materials group
A group owns quarries and processing plants and buys timber packaging, fuel, explosives and outsourced transport. Direct operations can be mapped to exact sites, water sources, dust and noise controls, rehabilitation areas and sensitive habitats. The upstream timber chain initially has only country-level origin for part of the volume, while downstream transport impacts depend on contractors and route choices.
The group creates one governance methodology but three evidence routes. Site teams assess direct impacts and dependencies using permits, coordinates, monitoring and rehabilitation plans. Procurement screens timber species, origin and supplier traceability, then prioritises high-risk gaps for primary evidence and corrective action. Logistics maps sensitive routes and contractor controls. Material issues are linked to ERM through interruption, licence, legal, market and cost pathways, while significant impacts remain visible where financial quantification is incomplete.
Illustrative scenario only; it does not establish a materiality conclusion for a real organisation.
In practice
Weak versus stronger disclosure
| Weak wording | More defensible wording |
|---|---|
| "We assess nature risk throughout our value chain." | "Detailed assessment covered the specified direct-operation sites and named upstream commodities and regions. Other value-chain segments were screened using the stated sector and geography criteria, with origin limitations described separately." |
| "Nature risks are integrated into ERM." | "Material nature-related risks are mapped to the enterprise taxonomy, assigned to risk owners and escalated through stated thresholds. Impact records below the enterprise-risk threshold remain in the nature and due-diligence registers." |
| "We mitigate all material impacts." | "Responses are sequenced using the mitigation hierarchy. The report identifies avoidance decisions, minimisation controls, restoration actions, residual impacts and separately governed offset proposals." |
Common mistakes and corrections
Reusing the climate-risk register without location or impact pathways. Add nature interfaces, ecosystem-service dependencies, impact drivers, state-of-nature context and affected stakeholders before financial assessment.
Applying one score to direct operations and every value-chain tier. Retain common governance but tailor evidence, confidence, leverage and control tests.
Using spend as the sole value-chain priority method. Combine commercial data with commodity, geography, ecological sensitivity and rights-related evidence.
Treating supplier non-response as not material. Record the gap, use a controlled proxy where justified, escalate high-risk cases and define an improvement plan.
Calling an activity impact reduction without outcome evidence. Distinguish inputs and activities from pressure reduction, restoration outcomes, state-of-nature change and risk reduction.
Claiming ERM integration because nature appears in a policy. Evidence taxonomy mapping, ownership, thresholds, committee reporting, controls and capital decisions.
Closing findings after receiving a revised spreadsheet. Require independent retest of the corrected population, method, evidence and disclosure.
Readiness
Evidence checklist
- approved risk and impact management methodology;
- reporting, assessment and value-chain boundaries;
- asset, site, commodity, supplier, product or portfolio population reconciliations;
- location and sensitive-location evidence;
- dependency and impact pathway register;
- materiality and prioritisation decisions;
- risk and opportunity register with financial pathways;
- mitigation-hierarchy decision records and action plans;
- ERM crosswalk, ownership and escalation evidence;
- value-chain estimates, non-response and data-quality records;
- monitoring, incidents, complaints and corrective actions; and
- disclosure matrix, reviewer findings and final approval.
Self-check
- Can every material risk be traced to a dependency or impact pathway and a location or value-chain node?
- Does the methodology explain why direct-operation and value-chain evidence differ?
- Are impact importance and financial-risk prioritisation separately traceable where both are used?
- Can the organisation show how management action changed a pressure, outcome, control or risk?
Related TNFD disclosures and guidance
Risk and Impact Management A(i): direct operations.
Risk and Impact Management A(ii): upstream and downstream value chains.
Risk and Impact Management B: management processes.
Risk and Impact Management C: integration into overall risk management.
Strategy D: priority locations, where relevant.
Metrics and Targets A-C: metrics, targets and performance generated by the process.
Selected official sources
SRC-01 - TNFD Recommendations v1.0: https://tnfd.global/wp-content/uploads/2023/08/Recommendations_of_the_Taskforce_on_Nature-related_Financial_Disclosures_September_2023.pdf
SRC-02 - TNFD Recommendations webpage: https://tnfd.global/recommendations/
SRC-03 - LEAP approach guidance v1.1: https://tnfd.global/publication/additional-guidance-on-assessment-of-nature-related-issues-the-leap-approach/
SRC-04 - TNFD metrics resources: https://tnfd.global/metrics/
SRC-05 - TNFD engagement guidance: https://tnfd.global/publication/guidance-on-engagement-with-indigenous-peoples-local-communities-and-affected-stakeholders/
Take it with you
The checklists as a working spreadsheet
Every checklist and table on this page, with empty status, owner and evidence columns for your team to fill in and keep.
✓ LRA AI Assistant · Human-in-the-loop
Ask about this guide
It answers from this page, and reaches into the linked disclosure cards when your question is about the standard itself. Your first two answers are free without signing in.
Go deeper · TNFD
ESG Reporting Full Stack
There is no standalone LRA course for this framework yet. The Full Stack programme covers the reporting system it sits in — materiality, data, drafting and assurance — with exercises on your own data.
Available as Guided Flex, Live Cohort, 1:1 Expert Mentorship or Corporate Programme.
