Aller à l’essentiel de l’information

Bibliothèque des disclosuresGuide pratique pour chaque information à publier

ESRS 2: General Disclosures·Disclosure Requirement GOV-4

Statement on Due Diligence

Guide pratique pour préparer cette information. Utilisez cette fiche pour identifier les données à préparer, vérifier les affirmations et organiser les preuves. Pour les exigences exactes, reportez-vous toujours à la source officielle European Commission.

Passeport publié

Révision en attente
··· En cours de révision Révision éditoriale en cours Élaboré à partir des sources officielles et de preuves issues de rapports publiés. Aucun approbateur n’est encore enregistré : cette page ne porte donc pas de signature. Utilisez-la avec la source officielle European Commission tant que cette révision est en cours.

Norme

ESRS 2: General Disclosures

Disclosure Requirement GOV-4 · 2026-5010-final

En vigueur

2027-01-01

Source officielle : Ouvrir ↗

Dernière révision

Support pédagogique LRA · Non publié ni approuvé par European Commission

Objet de l’information

This disclosure asks the organisation to explain whether, and how, it carries out due diligence as part of its governance and decision-making. In practice, that means describing the main processes used to identify, assess, prevent, mitigate and track material impacts, risks and opportunities, rather than simply stating that a policy exists.

The practical focus is on the real scope and consistency of those processes across the business. Report whether due diligence applies across the whole organisation and value chain, or only to selected activities, regions or flagship sites, and explain any important gaps, exceptions or differences in coverage.

Ce support pédagogique LRA aide à préparer l’information. Pour les exigences exactes, reportez-vous toujours à la source officielle European Commission.

Avant de commencer

Avant de commencer

Une courte liste de contrôle avant de préparer cette information — cochez chaque point une fois réglé.

Préparation

Informations clés à préparer

Champ à préparer Ce qu’il faut recueillir Indice de preuve Responsable
Control framework overview A plain description of how the reporting process is governed and controlled, including the main checks, approvals and responsibilities that sit around the data and reporting cycle. Process maps, control narratives, RACI or responsibility matrix, approval workflow, internal control documentation. Finance / Reporting Controls
Data checking process How reported data is reviewed for accuracy and consistency before it is published, including the checks performed, who performs them and when they happen. Validation checklists, review logs, exception reports, sign-off records, data quality rules. Data Management / Reporting
Risk control measures The controls used to manage reporting-related risks, covering the key risk areas identified and the actions in place to reduce or monitor them. Risk register, control matrix, mitigation plans, monitoring reports, issue logs. Risk Management / Internal Control
Estimation control methods The methods and checks used when reported figures are estimated rather than directly measured, including how assumptions are set, reviewed and updated. Estimation methodology, assumption papers, calculation files, review and approval records, model governance notes. Finance / Technical Accounting
+ Afficher les sous-éléments de GOV-4 (liste de travail LRA)

Comment le préparer

Set the reporting boundary first: decide which parts of the business, entities, systems and processes are in scope for the control narrative, and make that choice consistent across the four required areas.
Define the control content in plain business terms: describe how the organisation oversees controls, how it checks data quality, how it manages risk-related checks, and how it handles controls used where figures are estimated.
Gather the underlying support before drafting: collect the policies, procedures, sign-offs, reconciliations, review notes, exception logs and other records that show the controls actually operate.
Prepare the disclosure text or tables from the evidence: explain the control setup, the validation approach, the risk checks and the estimation approach in a way that matches the records you have assembled.
Record any limits, exclusions or changes clearly: note what was left out, why it was left out, and whether the control approach or evidence base changed during the reporting period.
Check the final draft against the official source and internal records: confirm the wording still reflects the source requirement, the evidence supports each statement, and nothing material has been missed or overstated.

Demander les données

Request the due diligence controls evidence

Traduisez l’information en une question métier interne, puis adaptez-la au vocabulaire de votre organisation.

How do we describe the checks, controls and review steps that sit behind our due diligence process, and who owns them?

Use your organisation’s own names for the process, control owners and review forums first, then map them to the disclosure wording. Keep the request in business language rather than framework terms, and check the source material before sign-off.

Demande faible

Please provide the ESRS 2:GOV-4 due diligence statement and all related controls, validation, risk and estimation controls.

Pourquoi elle échoue : This uses framework language that many teams do not use day to day, and it does not tell the owner what practical evidence to return. It also bundles several ideas together without asking for the underlying records, owners, dates or source systems.

Meilleure demande

Please share the evidence that shows how your team checks, reviews and signs off the information used in [process name] for [period]. Use your normal team terms, and include the control owner, source system or record set, latest version/date, and any logs, approvals or review notes.

Modèle d’e-mail formel
Subject: Request for due diligence controls evidence for [reporting period]

Hi [name/team],

We are preparing the sustainability reporting pack and need your help with the evidence behind our due diligence process for [reporting period].

Please send the following in your own team’s terms, using the names you normally use internally:
- a short description of the control set or review steps that support the process
- how data or information is checked before it is used in reporting
- the main controls used to manage identified risks
- the controls used where judgement or estimates are involved
- the owner for each control or review step
- any supporting records, logs, approvals or review notes

Please include the reporting boundary, the period covered, the source system or record set, and the latest version/date for each item.

If helpful, you can return this as a table or attach the relevant documents. Please adapt this to your organisation’s language and check the source material before sign-off.

Thanks,
[preparer name]
Version courte pour Teams / Slack
Hi [name/team] — could you share the evidence for the controls and review steps behind our due diligence process for [period]? Please use your team’s own terms, and include the owner, source record, latest version/date, and any supporting logs or approvals. Thanks.

Exemples sectoriels

Manufacturing

Contexte. The business uses a plant-level quality and compliance review process with manual sign-off on operational data.

Demande adaptée. Please share the evidence for the checks and sign-off steps used in the plant review process for [period]. Include the control owner, the line or site review step, the log or tracker used, and any exception notes.

Exemple de réponse. A site control matrix, monthly review log, exception tracker, and sign-off sheet showing the plant manager, quality lead and finance reviewer.

Financial services

Contexte. The business relies on a formal risk and controls framework with documented testing and escalation.

Demande adaptée. Please send the evidence behind the risk review and control testing process for [period]. Include the control owner, the testing method, the system of record, and any issues raised or closed.

Exemple de réponse. A controls register, testing results, issue log, escalation memo, and approval record from the risk committee secretary.

Rédigez votre information

Des notes qui transforment les données en information publiée

Modèles pédagogiques LRA — adaptez-les à votre organisation et vérifiez la source officielle avant validation.

Note méthodologique

Explain how the control framework is defined, what counts as a validation check, how risk controls are identified, and how estimation controls are applied in practice.

Note de contexte

Set out what the control information shows about how the reporting process is governed, checked, and managed, and why those controls matter for the reliability of the reported data.

Déclaration sur les variations

If the control picture has changed, point to updates in the framework, stronger or weaker validation, revised risk handling, or changes in how estimates are reviewed and supported.

Entrée de l’index de contenu

GOV-4 Statement on Due Diligence — [location / page] / [notes]

Centre de téléchargement

Outils et formulaires de préparation

Outils de préparation professionnels pour GOV-4 — gratuits avec l’adhésion à LRA Community. Inscrivez-vous une fois (c’est gratuit) et tous les téléchargements se débloquent, avec la Bibliothèque des informations, les modèles et l’assistant IA LRA.

Gratuit · Membres de la Community

Préparation à l’assurance

Pour chaque affirmation, vérifiez les preuves

Affirmation Risque Preuves à vérifier
We limited the figure to the parts of the business and reporting process we had actually defined for this report, and we documented where the boundary starts and ends.The assurer will test whether the boundary was set consistently, whether any material parts were left out without reason, and whether the stated scope matches the underlying reporting process.Reporting boundary memo; process maps showing included entities, sites, functions and data owners; scope approval notes; reconciliation between the reported boundary and the source population.
We checked that the underlying data set was complete and that the records had not been altered or lost between source systems and the final disclosure.The assurer will probe for missing records, duplicate entries, manual overrides, weak transfer controls, and whether the final figure can be traced back to source data without unexplained gaps.Data lineage and transfer logs; completeness checks; exception reports; access and change logs; reconciliation between source extracts, working papers and the published number.
We built the disclosure from a defined control set, including ownership, review steps, sign-off points and escalation routes before publication.The assurer will assess whether the control design is adequate, whether responsibilities were clear, whether reviews happened as described, and whether issues were escalated and resolved in time.Control framework documentation; RACI or role assignments; review and approval workflow records; issue logs; evidence of escalation and closure; publication sign-off pack.
Where the figure relied on estimates, we tested the assumptions, checked the calculation method and compared the result with available supporting evidence before we released it.The assurer will look for weak assumptions, unsupported inputs, calculation errors, bias in the estimate, and whether sensitivity or reasonableness checks were performed and documented.Estimation methodology; assumption papers; calculation sheets or model outputs; source evidence supporting inputs; sensitivity or reasonableness checks; reviewer comments and approval records.

Dossier de preuves à préparer

Lacunes fréquentes dans les rapports

The information is presented without a date or as-at point.
The scope or boundary of the statement is left undefined.
Key terms are used inconsistently across the report.
Material changes since the previous period are not disclosed.
Assertions are made without supporting detail or a source record.
Boilerplate is used that does not actually answer what is asked.

Lacunes fréquentes

Erreurs à éviter lors de la collecte des données

Wrong ownerChasing the board pack team for operational controls data leaves the evidence with people who do not run the checks in practice.
Framework words, not business termsAsking for the control framework in reporting jargon instead of the organisation’s own process names makes teams send the wrong files or summaries.
No clear boundaryCollecting information without fixing which business units, sites, or activities are in scope leads to a mixed set that cannot be used cleanly.
+ Afficher 5 de plus

Là où un jugement professionnel est souvent nécessaire

Acquisitions and disposals during the yearSet a clear cut-off for when a bought-in or sold business starts or stops feeding the control, checking and risk processes, then explain any mid-year boundary change and its effect on the figures or narrative.
Different local definitions for the same control topicWhere country teams use different legal or operational labels for the same issue, choose one group-wide interpretation, describe the mapping used, and note any local exceptions that affect the way the process is described.
Units that sit partly inside and partly outside scopeDecide how to treat shared services, joint operations or other mixed arrangements, state the inclusion rule you used, and explain any material exclusions or partial coverage.
+ Afficher 5 de plus

Exemples

Exemples illustratifs

Synthétiques, rédigés par LRA — ils ne proviennent ni d’un rapport d’entreprise ni du texte d’une norme.

Illustrative (synthetic) example — Consumer goods manufacturing

We keep our oversight model simple: the board sets the tone, the audit and risk committees review key controls, and management owns day-to-day checks across reporting, operations, and compliance.
- Before figures are reported, our finance team runs a documented review of source data, reconciles key balances to the ledger, and logs any corrections; in the latest cycle, 18 of 18 material data sets were checked, and 3 required adjustment before sign-off.
- We use a risk register and control testing plan to track the main threats to delivery and reporting quality; 12 of 12 priority risks had named owners, and 10 had active mitigation actions in place at period end.
- Where we rely on estimates, we apply approved assumptions, compare them with prior outcomes, and challenge unusual movements; 7 of 7 significant estimates were reviewed by a second person, and 5 were also tested against external benchmarks.

This example shows a plain-language description of how oversight is organised, how reported data is checked, how key risks are managed, and how estimates are reviewed and challenged.

Illustrative (synthetic) example — Renewable energy services

Our group uses a three-line approach: operational teams prepare the information, specialist functions test it, and the board and its committees receive escalation on matters that could affect reporting or delivery.
- We validate data through automated checks, manual review of exceptions, and reconciliation to underlying records; in the period, 24 of 24 critical data feeds were tested, 4 exceptions were found, and all 4 were cleared before publication.
- For major business and reporting risks, we maintain a control map, assign owners, and monitor whether actions are completed on time; 9 of 9 top risks were assigned, and 8 had controls operating as intended at the reporting date.
- For estimates, we document the basis used, compare assumptions with recent actual results, and require independent review for higher-judgement items; 6 of 6 material estimates were reviewed, and 2 were updated after challenge from the review team.

This example illustrates a different sector’s way of describing governance, data checking, risk management, and controls over judgement-based estimates.

Rapports d’entreprises

Comment les entreprises publient GOV-4 en pratique

Exemples de pratiques de publication complètes et partielles. Ce sont des analyses fondées sur des preuves, non des modèles à recopier.

Rapports réels publiés
Telecom Italia S.p.A.
Telecommunication Services · Italy · 2025
Ouvrir le rapport →
Telecom Italia S.p.A.'s 2025 Annual Report includes a statement on due diligence, describing how the TIM Group identifies, assesses, and manages actual and potential negative sustainability impacts and risks, with details on operational phases provided (p.125). The report also mentions controls to ensure the completeness, accuracy, consistency, and traceability of sustainability information, although this is not a clear disclosure of the specific datapoint GOV 4.4 (p.127). However, no evidence was found for GOV 4.2 and GOV 4.3 disclosures in the report.
Globalvia
Ground Transportation — Highways and Railtracks · Spain · 2025
Ouvrir le rapport →
Globalvia’s 2025 Sustainability Report provides detailed information on its management approach and policies related to due diligence procedures for identifying, assessing, preventing, and mitigating risks, as outlined on page 108. The report also references a due diligence procedure aimed at strengthening risk management and reinforcing ethical, compliance, and sustainability standards (p.30). However, the report offers only unclear or partial disclosures regarding the process for determining and assessing material impacts, risks, and opportunities (p.95), as well as the oversight and monitoring of strategic, financial, operational, and compliance risks by the Risk Department (p.32), with no clear evidence found for the methodology or narrative on this topic.
Pirelli & C. S.p.A.
Automobiles and Components · Italy · 2025
Ouvrir le rapport →
Pirelli & C. S.p.A.’s 2025 Annual Report provides clear evidence of established due diligence processes and systems, as stated on page 139. The report includes related context on validation and risk assessment processes (pp. 107, 142), though these do not clearly disclose specific details of the due diligence governance elements. There is no explicit information found regarding the methodology or narrative for one of the governance disclosure points.

Comparer côte à côte →

✓ Assistant IA LRA · Supervision humaine
Dr Ross Kurinko

Interrogez l’assistant IA de Study Studio sur cette information

Obtenez des réponses concrètes pour votre contexte de reporting. Les deux premières réponses sont gratuites — rejoignez gratuitement LRA Community pour continuer sans limite.

Essayez Comment préparer GOV-4 ? Quelles données dois-je collecter ? Où voir un exemple issu d’un rapport réel ? Quelles erreurs éviter ?
2 réponses gratuites

Vérifiez votre compréhension

Scénarios à travailler

An organisation uses models and estimates to fill gaps in supplier data and to approximate the scale of certain impacts. The team is unsure whether to mention those estimates because the numbers are not exact.

QWhat should the preparer include about estimation methods in the due diligence statement?
Afficher la réponse type →

The preparer receives partial evidence for ESRS 2:GOV-4 shortly before sign-off.

QWhat should they check before using it?
Afficher la réponse type →

A business unit sends data for ESRS 2:GOV-4 using labels that do not match the reporting workbook.

QHow should the preparer handle the mismatch?
Afficher la réponse type →

Références au référentiel

Exigences ESRS applicables et informations connexes

Références disponibles du référentiel et informations voisines utiles à la préparation de cette exigence.

ESRS

GOV-4

au sein de ESRS 2 : General Disclosures

Ouvrir la source officielle →

Connexes et exploration

Plus dans ESRS 2 → Parcourir le catalogue complet → Accueil de la Bibliothèque des informations → Rechercher dans toutes les informations →

FAQ

Questions auxquelles cette page répond

What do I need to gather for GOV-4 before I start drafting the disclosure?+
How do I use the GOV-4 step-by-step 'how to prepare' section in practice?+
Who should own the GOV-4 data and narrative in my organisation?+
What evidence do I need to build an assurance-ready GOV-4 pack?+
What are the four assurance claims in GOV-4 and how do I check them?+
What common mistakes should I avoid when preparing GOV-4?+
How do I use the GOV-4 workbook to prepare the disclosure?+
What is the printable Library Card for GOV-4 used for?+
Can I use the synthetic example disclosure on the GOV-4 page as a template?+
How do I turn GOV-4 data into a draft narrative and content index line?+

Autres questions auxquelles cette page peut aider

Aller plus loin · GOV-4

Apprenez à préparer cette information de bout en bout

This guide covers one Disclosure Requirement. The ESRS / CSRD Reporting course walks the full European workflow — double materiality, datapoints, evidence and assurance — with exercises on your own data.

Available as Guided Flex, Live Cohort, 1:1 Expert Mentorship or Corporate Programme.

Explore the ESRS / CSRD course →
Comment cette bibliothèque est construite 312 rapports publiés indexés 63 171 pages avec citations au niveau de la page 272 fiches disclosure conçues par des praticiens
/fr/knowledge-hub/disclosure-cards/esrs-gov-4/