Skip to content

Evidence request lists

SASB Standards

Evidence request list. 69 controls, 69 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Assurance

SASB-6
Assurance, Comparability, Integration with Financial Statements

Per SASB / IFRS Sustainability Disclosure: (a) Assurance and Internal Control over Sustainability Disclosures + (b) Comparability and Restatement Policies + (c) Connectivity with Financial Statements + (d) maintain documentation supporting third-party assurance + (e) align with ISSB framework + IFRS S1/S2.

Artefacts an auditor will ask for
  • SASB/IFRS S2 evidence for SASB-6
Where this commonly fails
  • industry metrics + assurance partial

Assurance, Comparability and Disclosure

SASB-ASR-01
Assurance and Internal Control over Sustainability Information

Establish and document internal controls over sustainability information of similar rigor to financial reporting controls, and obtain external assurance where required or beneficial.

Artefacts an auditor will ask for
  • ICFR style control matrix for ESG data
  • Engagement letter from assurance provider
  • Assurance report (limited or reasonable)
  • Walkthrough and testing workpapers
Where this commonly fails
  • No formal internal controls over sustainability data
  • Assurance limited to GHG only
  • Reconciliations not retained
SASB-ASR-02
Comparability and Restatement Policies

Disclose comparative information for prior periods, and disclose and explain any restatements of previously reported sustainability information.

Artefacts an auditor will ask for
  • Restatement policy document
  • Restated metric workbook with audit trail
  • Disclosure narrative explaining restatements
  • Approval log for restatements
Where this commonly fails
  • Restatements made without explanation
  • Prior period figures not restated when methodology changes
SASB-ASR-03
Connectivity with Financial Statements

Demonstrate connectivity between sustainability related financial disclosures and the general purpose financial statements, including consistent assumptions, estimates, and reporting boundary.

Artefacts an auditor will ask for
  • Reporting boundary reconciliation
  • Assumption consistency memo
  • Cross reference index between sustainability and financial reports
  • Reviewer sign off
Where this commonly fails
  • Different reporting entities used for sustainability and financial reporting
  • Inconsistent discount rates or useful lives
SASB-DISC-19
Disclosure Location and Comparability

Provide SASB disclosures in a manner that allows comparability over time and across peers, including a SASB index or appendix mapped to the reporting framework used.

Artefacts an auditor will ask for
  • SASB index in annual or sustainability report
  • Cross reference to TCFD and IFRS S2
  • Restatement disclosures
  • Peer benchmarking notes
Where this commonly fails
  • Index incomplete or out of date
  • Restatements not flagged
  • Year on year changes in scope unexplained

Business Model and Innovation

SASB-1
Business Model + Innovation (BMI)

Per SASB / IFRS S2 Standards Business Model and Innovation dimension: report material sustainability factors including (a) Product Design and Lifecycle Management + (b) Business Model Resilience + (c) Supply Chain Management + (d) Materials Sourcing and Efficiency + (e) integrate with broader sustainability strategy + (f) maintain documentation supporting industry-specific SASB metrics + IFRS S2 disclosures.

Artefacts an auditor will ask for
  • SASB/IFRS S2 evidence for SASB-1
Where this commonly fails
  • industry metrics + assurance partial
SASB-BMI-1
Product Design and Lifecycle Management

Disclose product design for sustainability, circular economy practices, and lifecycle environmental impact

Artefacts an auditor will ask for
  • Product lifecycle inventory and assessment
  • Supply chain ESG risk register
  • Materials sourcing and efficiency metrics
  • Climate physical risk impact study
Where this commonly fails
  • Lifecycle assessment narrow in scope
  • Suppliers beyond tier 1 not assessed
  • No quantitative materials efficiency targets
  • Climate physical risk not quantified
SASB-BMI-2
Business Model Resilience

Report on climate-related risks and opportunities, scenario analysis, and business model adaptation

Artefacts an auditor will ask for
  • Product lifecycle inventory and assessment
  • Supply chain ESG risk register
  • Materials sourcing and efficiency metrics
  • Climate physical risk impact study
Where this commonly fails
  • Lifecycle assessment narrow in scope
  • Suppliers beyond tier 1 not assessed
  • No quantitative materials efficiency targets
  • Climate physical risk not quantified
SASB-BMI-3
Supply Chain Management

Disclose supply chain sustainability metrics including supplier environmental and social performance

Artefacts an auditor will ask for
  • Product lifecycle inventory and assessment
  • Supply chain ESG risk register
  • Materials sourcing and efficiency metrics
  • Climate physical risk impact study
Where this commonly fails
  • Lifecycle assessment narrow in scope
  • Suppliers beyond tier 1 not assessed
  • No quantitative materials efficiency targets
  • Climate physical risk not quantified
SASB-BMI-4
Materials Sourcing and Efficiency

Management of risks associated with sourcing and efficiency of materials used in production processes.

Artefacts an auditor will ask for
  • Product lifecycle inventory and assessment
  • Supply chain ESG risk register
  • Materials sourcing and efficiency metrics
  • Climate physical risk impact study
Where this commonly fails
  • Lifecycle assessment narrow in scope
  • Suppliers beyond tier 1 not assessed
  • No quantitative materials efficiency targets
  • Climate physical risk not quantified
SASB-BMI-5
Physical Impacts of Climate Change

Management of risks and opportunities associated with the direct physical impacts of climate change on operations and assets.

Artefacts an auditor will ask for
  • Product lifecycle inventory and assessment
  • Supply chain ESG risk register
  • Materials sourcing and efficiency metrics
  • Climate physical risk impact study
Where this commonly fails
  • Lifecycle assessment narrow in scope
  • Suppliers beyond tier 1 not assessed
  • No quantitative materials efficiency targets
  • Climate physical risk not quantified

Climate Related Risks and Metrics

SASB-CLM-01
Climate Related Physical Risk Assessment

Identify and assess acute and chronic physical climate risks across owned assets, leased assets, and material parts of the value chain, including location specific hazard exposure.

Artefacts an auditor will ask for
  • Physical risk assessment report
  • Asset register with geographic coordinates
  • Hazard exposure modelling output
  • Insurance loss history aligned to climate hazards
Where this commonly fails
  • Asset register incomplete
  • Only headquarters assessed
  • Acute and chronic risks not separated
SASB-CLM-02
Climate Related Transition Risk Assessment

Identify and quantify transition risks arising from policy, legal, technology, market, and reputational drivers, including carbon pricing exposure and stranded asset risk.

Artefacts an auditor will ask for
  • Transition risk register
  • Carbon pricing exposure model
  • Stranded asset analysis
  • Policy and regulatory horizon scan
  • Customer or product mix sensitivity analysis
Where this commonly fails
  • No internal carbon price applied
  • Transition risk limited to direct operations
  • Reputational risk not quantified
SASB-CLM-03
Climate Scenario Analysis

Use climate related scenario analysis commensurate with the entity's circumstances to assess resilience of strategy and business model, including at least one scenario aligned with the latest international agreement on climate change.

Artefacts an auditor will ask for
  • Scenario analysis report
  • Assumptions log including temperature pathway
  • Sensitivity tables for revenue, cost, asset values
  • Internal review and challenge documentation
Where this commonly fails
  • Only a single 1.5C or 2C scenario tested
  • Assumptions undocumented
  • No quantitative output
SASB-CLM-04
GHG Emissions Inventory Scope 1

Measure and disclose absolute gross Scope 1 greenhouse gas emissions in metric tonnes of CO2 equivalent in accordance with the Greenhouse Gas Protocol Corporate Standard.

Artefacts an auditor will ask for
  • Scope 1 GHG inventory workbook
  • Activity data source documents (fuel invoices, refrigerant logs)
  • Emission factors log with version dates
  • Internal control walkthrough for GHG data
Where this commonly fails
  • Refrigerant or fugitive emissions omitted
  • Outdated emission factors
  • Organizational boundary not documented
SASB-CLM-05
GHG Emissions Inventory Scope 2

Measure and disclose absolute gross Scope 2 greenhouse gas emissions using both location based and market based methods where appropriate.

Artefacts an auditor will ask for
  • Scope 2 inventory workbook
  • Utility bills and metered consumption logs
  • REC or GO certificate registry extracts
  • Residual mix and grid factor documentation
Where this commonly fails
  • Only location based method used
  • Energy attribute certificates not retired or not verified
  • Leased space estimates not justified
SASB-CLM-06
GHG Emissions Inventory Scope 3

Measure and disclose absolute gross Scope 3 greenhouse gas emissions across the 15 GHG Protocol categories, identifying which categories are material and the methods used for estimation.

Artefacts an auditor will ask for
  • Scope 3 screening assessment
  • Category by category calculation workbooks
  • Supplier specific data collection records
  • Data quality scoring matrix
Where this commonly fails
  • Categories 1, 11, and 15 omitted without justification
  • Heavy reliance on spend based factors
  • No data quality scoring
SASB-CLM-07
Internal Carbon Price and Financial Impact

Disclose the internal carbon price used in decision making and the current and anticipated financial effects of climate related risks and opportunities on the financial position, performance, and cash flows.

Artefacts an auditor will ask for
  • Internal carbon pricing policy
  • Capital appraisal templates showing carbon price applied
  • Financial impact assessment memo
  • Sensitivity analysis tied to financial statements
Where this commonly fails
  • Internal carbon price disclosed but not applied to investment decisions
  • Financial impacts qualitative only
SASB-CLM-08
Climate Related Opportunities

Identify and disclose climate related opportunities including resource efficiency, low emission products and services, access to new markets, and resilience building, with associated financial effects.

Artefacts an auditor will ask for
  • Climate opportunity register
  • Product or revenue mapping to low carbon categories
  • Capital expenditure pipeline tagged for climate opportunities
  • Market sizing memos
Where this commonly fails
  • Opportunities described qualitatively without revenue or cost figures
  • No linkage to capital allocation

Environment

SASB-5
Environment (ENV)

Per SASB Environment dimension: GHG emissions + air quality + energy + water + waste + ecological impacts. Align with IFRS S2 climate-related disclosures.

Artefacts an auditor will ask for
  • SASB/IFRS S2 evidence for SASB-5
Where this commonly fails
  • industry metrics + assurance partial

Governance of Sustainability

SASB-GOV-01
Governance of Sustainability and Climate Matters

Disclose the governance processes, controls, and procedures the entity uses to monitor, manage, and oversee sustainability and climate related risks and opportunities, in alignment with IFRS S1 paragraphs 26 to 31.

Artefacts an auditor will ask for
  • Board charter referencing sustainability oversight
  • Sustainability committee terms of reference
  • Minutes of board or committee discussions of climate or sustainability risks
  • Org chart showing ESG accountable executives
  • Delegation of authority matrix for sustainability decisions
Where this commonly fails
  • No documented board level oversight of climate matters
  • Sustainability roles spread across departments with no single accountable owner
  • Minutes lack evidence of substantive sustainability discussion
SASB-GOV-02
Sustainability Skills and Competencies of Oversight Bodies

Demonstrate how the governance body or bodies determine that appropriate skills and competencies are available or will be developed to oversee strategies designed to respond to sustainability related risks and opportunities.

Artefacts an auditor will ask for
  • Board skills matrix including climate and ESG competencies
  • Director education and training logs
  • Sustainability briefings to the board
  • External advisor engagement letters for ESG topics
Where this commonly fails
  • Skills matrix omits sustainability competencies
  • No documented director training on climate science or ESG reporting
SASB-GOV-03
Governance of Sustainability Disclosures

Disclose the governance processes, controls, and procedures used to monitor and manage sustainability related risks and opportunities, including board oversight and management responsibility.

Artefacts an auditor will ask for
  • Board committee charter
  • Management responsibility matrix
  • Sustainability KPI dashboard
  • Skills and competencies disclosure
Where this commonly fails
  • Board oversight asserted without evidence
  • Competencies not disclosed
  • Reporting line conflicts with risk function

Human Capital

SASB-2
Human Capital (HC)

Per SASB Human Capital dimension: report labor + employee health/safety + diversity + community. Maintain industry-specific SASB metrics including workforce composition + safety incident rates.

Artefacts an auditor will ask for
  • SASB/IFRS S2 evidence for SASB-2
Where this commonly fails
  • industry metrics + assurance partial
SASB-HC-1
Labor Practices

Report on labor practices including fair wages, working conditions, and labor relations metrics

Artefacts an auditor will ask for
  • Labor practices policy and grievance log
  • Health and safety incident records (TRIR, LTIFR)
  • Diversity and inclusion data
  • Training and development records
Where this commonly fails
  • Contractor data excluded
  • Pay equity not analysed
  • Diversity metrics narrow
  • Grievances not closed timely
SASB-HC-2
Employee Health and Safety

Disclose occupational health and safety metrics including incident rates and prevention measures

Artefacts an auditor will ask for
  • Labor practices policy and grievance log
  • Health and safety incident records (TRIR, LTIFR)
  • Diversity and inclusion data
  • Training and development records
Where this commonly fails
  • Contractor data excluded
  • Pay equity not analysed
  • Diversity metrics narrow
  • Grievances not closed timely
SASB-HC-3
Employee Diversity and Inclusion

Report workforce diversity metrics and inclusion initiatives across management and employee levels

Artefacts an auditor will ask for
  • Labor practices policy and grievance log
  • Health and safety incident records (TRIR, LTIFR)
  • Diversity and inclusion data
  • Training and development records
Where this commonly fails
  • Contractor data excluded
  • Pay equity not analysed
  • Diversity metrics narrow
  • Grievances not closed timely

ISSB Integration (IFRS S1 and S2)

SASB-ISSB-S1
IFRS S1 General Sustainability Disclosure

Use SASB Standards as baseline for identifying sustainability-related risks and opportunities per IFRS S1

Artefacts an auditor will ask for
  • IFRS S1 disclosure index and management approval
  • IFRS S2 climate metrics and targets schedule
  • Materiality assessment workpapers
  • Scope 1, 2, 3 emissions inventory with assurance evidence
Where this commonly fails
  • Connectivity with financial statements not demonstrated
  • Scope 3 categories incomplete
  • Scenario analysis lacks quantitative inputs
  • Industry specific SASB metrics not mapped to S1
SASB-ISSB-S2
IFRS S2 Climate-Related Disclosures

Apply SASB industry-specific climate metrics for TCFD-aligned climate-related financial disclosures per IFRS S2

Artefacts an auditor will ask for
  • IFRS S1 disclosure index and management approval
  • IFRS S2 climate metrics and targets schedule
  • Materiality assessment workpapers
  • Scope 1, 2, 3 emissions inventory with assurance evidence
Where this commonly fails
  • Connectivity with financial statements not demonstrated
  • Scope 3 categories incomplete
  • Scenario analysis lacks quantitative inputs
  • Industry specific SASB metrics not mapped to S1

Leadership and Governance

SASB-3
Leadership and Governance (LG)

Per SASB LG dimension: governance + ethics + competitive behavior + regulatory compliance + risk management + critical incident management.

Artefacts an auditor will ask for
  • SASB/IFRS S2 evidence for SASB-3
Where this commonly fails
  • industry metrics + assurance partial
SASB-LG-1
Business Ethics

Report on anti-corruption, competitive behavior, and regulatory compliance metrics

Artefacts an auditor will ask for
  • Code of business conduct
  • Ethics training completion records
  • Systemic risk register
  • Critical incident management procedures
Where this commonly fails
  • Ethics training not annual
  • Systemic risk not stress tested
  • Incident criteria undefined
  • Whistleblower follow-up incomplete
SASB-LG-2
Systemic Risk Management

Disclose management of systemic risks including financial, technology, and geopolitical risks

Artefacts an auditor will ask for
  • Code of business conduct
  • Ethics training completion records
  • Systemic risk register
  • Critical incident management procedures
Where this commonly fails
  • Ethics training not annual
  • Systemic risk not stress tested
  • Incident criteria undefined
  • Whistleblower follow-up incomplete
SASB-LG-3
Critical Incident Risk Management

Report on management of critical incidents and enterprise risk management practices

Artefacts an auditor will ask for
  • Code of business conduct
  • Ethics training completion records
  • Systemic risk register
  • Critical incident management procedures
Where this commonly fails
  • Ethics training not annual
  • Systemic risk not stress tested
  • Incident criteria undefined
  • Whistleblower follow-up incomplete
SASB-LG-4
Critical Incident Risk Management

Company's ability to manage risks associated with incidents that may have wide-ranging health, environmental, and social impacts.

Artefacts an auditor will ask for
  • Code of business conduct
  • Ethics training completion records
  • Systemic risk register
  • Critical incident management procedures
Where this commonly fails
  • Ethics training not annual
  • Systemic risk not stress tested
  • Incident criteria undefined
  • Whistleblower follow-up incomplete
SASB-LG-5
Systemic Risk Management

Management of risks and contribution to or mitigation of systemic risks resulting from large-scale weakening or collapse of systems.

Artefacts an auditor will ask for
  • Code of business conduct
  • Ethics training completion records
  • Systemic risk register
  • Critical incident management procedures
Where this commonly fails
  • Ethics training not annual
  • Systemic risk not stress tested
  • Incident criteria undefined
  • Whistleblower follow-up incomplete

Metrics and Targets

SASB-MET-01
Industry Based Metrics Selection

Apply the relevant SASB industry standards to select and disclose industry specific metrics, or explain why a metric is not material or applicable to the entity.

Artefacts an auditor will ask for
  • List of selected SASB metrics by industry standard
  • Justification memo for excluded metrics
  • Data collection SOPs per metric
  • Source system extracts feeding metrics
Where this commonly fails
  • Industry standard not correctly mapped to NAICS codes
  • Excluded metrics lack documented rationale
  • Multiple operating segments not reported separately
SASB-MET-02
Activity Metrics and Normalization

Disclose activity metrics from the relevant SASB standards to give context to performance metrics and enable comparability across reporting periods.

Artefacts an auditor will ask for
  • Activity metric workbook
  • Reconciliation to audited financial statements
  • Normalization methodology document
  • Period over period variance analysis
Where this commonly fails
  • Activity metrics not reconciled to financial reporting
  • Units of measure inconsistent across periods
SASB-MET-03
Targets and Performance Tracking

Disclose any targets set to manage sustainability related risks and opportunities, including baseline year, scope, milestones, and progress against the target.

Artefacts an auditor will ask for
  • Approved target documentation
  • Baseline calculation memo
  • Annual progress report against targets
  • Internal dashboard or KPI scorecard
Where this commonly fails
  • Targets lack approved baseline
  • No interim milestones
  • Progress not independently reviewed
SASB-METRIC-06
Industry Standard Metrics and Activity Metrics

Disclose industry specific metrics and accompanying activity metrics from the applicable SASB standard, using prescribed units, scope, and calculation methodologies.

Artefacts an auditor will ask for
  • Metric calculation worksheets
  • Activity metric source data
  • Unit reconciliation
  • Variance to prior year
Where this commonly fails
  • Metric units customised
  • Activity metrics omitted
  • Restatement of prior period without explanation
SASB-METRIC-07
Greenhouse Gas Emissions Scope 1 and 2

Disclose gross global Scope 1 and Scope 2 greenhouse gas emissions following the GHG Protocol, with disaggregation as required by the applicable industry standard.

Artefacts an auditor will ask for
  • GHG inventory by scope
  • GHG Protocol consolidation approach
  • Activity data sources
  • Emission factor register
Where this commonly fails
  • Scope 2 market based and location based confusion
  • Boundary errors after acquisitions or divestments
  • Emission factors out of date
SASB-METRIC-08
Scope 3 Categories Where Material

Where Scope 3 emissions categories are identified as material under SASB or IFRS S2, disclose category specific emissions with methodology, exclusions, and uncertainty quantification.

Artefacts an auditor will ask for
  • Scope 3 screening across 15 categories
  • Selected category calculations
  • Data quality scoring
  • Exclusion rationale
Where this commonly fails
  • Screening skipped, defaulting to one or two categories
  • Data quality not disclosed
  • Use of sold products excluded for downstream goods producers
SASB-METRIC-09
Energy Management

Disclose total energy consumed, percentage grid electricity, percentage renewable, and where applicable energy intensity ratios using consistent boundaries and units.

Artefacts an auditor will ask for
  • Energy ledger
  • Utility bills sample
  • Renewable energy attribute certificates
  • Intensity calculation worksheet
Where this commonly fails
  • Renewable claims based on grid mix rather than instruments
  • Self generation double counted
  • Intensity denominator inconsistent
SASB-METRIC-10
Water Management in Water Stressed Regions

Where the industry standard requires, disclose total water withdrawn and consumed in regions of high or extremely high water stress, with source mapping and intensity.

Artefacts an auditor will ask for
  • Site level water data
  • Water stress overlay using WRI Aqueduct or equivalent
  • Permits and licences
  • Reduction targets
Where this commonly fails
  • Stress classification not applied
  • Withdrawal and consumption confused
  • Permits inventory missing
SASB-METRIC-11
Waste and Hazardous Materials Management

Disclose total waste generated, percentage hazardous, percentage recycled or recovered, and significant spills or releases in accordance with the applicable industry standard.

Artefacts an auditor will ask for
  • Waste manifests
  • Treatment classification per facility
  • Spill register
  • Material recovery contracts
Where this commonly fails
  • Hazardous waste classification per local law rather than Basel where required
  • Spill register missing minor events
  • Recycling claims without downstream evidence
SASB-METRIC-12
Data Privacy and Security Industry Topics

For industries with data privacy and security disclosure topics, report on policies, data handled, requests by law enforcement, monetary losses from breaches, and users affected.

Artefacts an auditor will ask for
  • Privacy policy and DPIA
  • Law enforcement request log
  • Breach register with monetary impact
  • Affected user count methodology
Where this commonly fails
  • Monetary loss limited to direct costs ignoring legal and remediation
  • Affected user count understated
  • Privacy policy not updated for new processing
SASB-METRIC-13
Employee Health and Safety

Where the industry standard requires, disclose total recordable incident rate, fatality rate, and near miss frequency rate for direct employees and where appropriate contractors.

Artefacts an auditor will ask for
  • Incident register
  • Hours worked records
  • TRIR and fatality calculation worksheets
  • Contractor inclusion methodology
Where this commonly fails
  • Contractors excluded inconsistently across years
  • Near miss reporting culture weak
  • Hours worked estimated rather than measured
SASB-METRIC-14
Diversity, Equity, and Inclusion Metrics

Where required by the industry standard, disclose workforce composition by gender and other categories, percentages at management and senior levels, and engagement results.

Artefacts an auditor will ask for
  • HRIS extract
  • EEO style reporting
  • Pay equity analysis
  • Engagement survey results
Where this commonly fails
  • Reporting limited to country of headquarters
  • Pay equity not adjusted for role grade
  • Engagement results selectively reported
SASB-METRIC-15
Supply Chain Management

Disclose percentage of suppliers assessed against social or environmental criteria, audits conducted, non conformances identified, and remediation completed where the industry standard prescribes.

Artefacts an auditor will ask for
  • Supplier code of conduct
  • Audit programme
  • Audit results dashboard
  • Remediation closure evidence
Where this commonly fails
  • Self assessment treated as equivalent to audit
  • Tier 2 visibility lacking
  • Remediation closed without verification
SASB-METRIC-16
Product Quality and Safety

Where applicable, disclose recalls, monetary losses associated with product safety incidents, and number of regulatory enforcement actions related to product quality and safety.

Artefacts an auditor will ask for
  • Recall register
  • Regulatory correspondence log
  • Loss accounting tied to recall
  • Root cause analyses
Where this commonly fails
  • Voluntary recalls excluded
  • Losses limited to direct cost
  • Regulatory actions not tracked centrally
SASB-METRIC-17
Business Ethics and Anti-Corruption

Disclose monetary losses from legal proceedings related to bribery or corruption and describe management of legal and regulatory environment as prescribed by the industry standard.

Artefacts an auditor will ask for
  • Litigation register
  • ABAC programme documentation
  • Training completion records
  • Whistleblower report metrics
Where this commonly fails
  • Settlements without admission excluded
  • Training not tracked by jurisdiction
  • Whistleblower metrics not disaggregated
SASB-METRIC-18
Systemic Risk Management for Financial Industries

For financial sector standards, disclose measures and exposures relating to systemic risk including global systemically important institution status, recovery and resolution planning, and capital metrics.

Artefacts an auditor will ask for
  • GSIB designation status
  • Recovery and resolution plan summary
  • Capital adequacy disclosures
  • Stress test results
Where this commonly fails
  • Subsidiary level disclosures missing
  • Stress test scope under disclosed
  • Recovery plan triggers undefined

Social Capital

SASB-4
Social Capital (SC)

Per SASB SC dimension: human rights + community relations + customer privacy + data security + product quality + customer welfare + selling practices + product labeling.

Artefacts an auditor will ask for
  • SASB/IFRS S2 evidence for SASB-4
Where this commonly fails
  • industry metrics + assurance partial
SASB-SC-1
Customer Privacy and Data Security

Disclose data security practices, data breach incidents, and customer privacy protection measures

Artefacts an auditor will ask for
  • Privacy notice and consent registers
  • Data security incident logs
  • Product safety and quality records
  • Community engagement records
Where this commonly fails
  • Consent retention inconsistent
  • Breach notification timelines missed
  • Quality issues not root-caused
  • Accessibility considerations absent
SASB-SC-2
Access and Affordability

Report on product/service access, affordability, and equity metrics relevant to the industry

Artefacts an auditor will ask for
  • Privacy notice and consent registers
  • Data security incident logs
  • Product safety and quality records
  • Community engagement records
Where this commonly fails
  • Consent retention inconsistent
  • Breach notification timelines missed
  • Quality issues not root-caused
  • Accessibility considerations absent
SASB-SC-3
Product Quality and Safety

Disclose product quality metrics, recalls, safety incidents, and customer welfare measures

Artefacts an auditor will ask for
  • Privacy notice and consent registers
  • Data security incident logs
  • Product safety and quality records
  • Community engagement records
Where this commonly fails
  • Consent retention inconsistent
  • Breach notification timelines missed
  • Quality issues not root-caused
  • Accessibility considerations absent

Society and Customer Topics

SASB-SOC-1
Human Rights and Community Relations

Management of relationships with communities in which the company operates, including indigenous rights and community impacts.

Artefacts an auditor will ask for
  • Privacy notice and consent registers
  • Data security incident logs
  • Product safety and quality records
  • Community engagement records
Where this commonly fails
  • Consent retention inconsistent
  • Breach notification timelines missed
  • Quality issues not root-caused
  • Accessibility considerations absent
SASB-SOC-2
Customer Privacy

Management of risks related to use of personally identifiable information (PII) and other customer/user data for secondary purposes.

Artefacts an auditor will ask for
  • Privacy notice and consent registers
  • Data security incident logs
  • Product safety and quality records
  • Community engagement records
Where this commonly fails
  • Consent retention inconsistent
  • Breach notification timelines missed
  • Quality issues not root-caused
  • Accessibility considerations absent
SASB-SOC-3
Data Security

Management of risks related to collection, retention, and use of sensitive, confidential, or proprietary customer/user data.

Artefacts an auditor will ask for
  • Privacy notice and consent registers
  • Data security incident logs
  • Product safety and quality records
  • Community engagement records
Where this commonly fails
  • Consent retention inconsistent
  • Breach notification timelines missed
  • Quality issues not root-caused
  • Accessibility considerations absent
SASB-SOC-4
Access and Affordability

Ability to ensure broad access to products and services, particularly for underserved markets or populations.

Artefacts an auditor will ask for
  • Privacy notice and consent registers
  • Data security incident logs
  • Product safety and quality records
  • Community engagement records
Where this commonly fails
  • Consent retention inconsistent
  • Breach notification timelines missed
  • Quality issues not root-caused
  • Accessibility considerations absent
SASB-SOC-5
Product Quality and Safety

Management of issues related to quality and safety of products, including impacts on customer health and safety.

Artefacts an auditor will ask for
  • Privacy notice and consent registers
  • Data security incident logs
  • Product safety and quality records
  • Community engagement records
Where this commonly fails
  • Consent retention inconsistent
  • Breach notification timelines missed
  • Quality issues not root-caused
  • Accessibility considerations absent
SASB-SOC-6
Customer Welfare

Management of issues related to customer welfare beyond quality and safety, including responsible use and responsible marketing.

Artefacts an auditor will ask for
  • Privacy notice and consent registers
  • Data security incident logs
  • Product safety and quality records
  • Community engagement records
Where this commonly fails
  • Consent retention inconsistent
  • Breach notification timelines missed
  • Quality issues not root-caused
  • Accessibility considerations absent
SASB-SOC-7
Selling Practices and Product Labeling

Ethical selling and labeling practices, transparent marketing, fair advertising, and product disclosure requirements.

Artefacts an auditor will ask for
  • Privacy notice and consent registers
  • Data security incident logs
  • Product safety and quality records
  • Community engagement records
Where this commonly fails
  • Consent retention inconsistent
  • Breach notification timelines missed
  • Quality issues not root-caused
  • Accessibility considerations absent

Strategy and Materiality

SASB-STR-01
Identification of Material Sustainability Topics

Identify sustainability related risks and opportunities that could reasonably be expected to affect the entity's prospects, using SASB industry specific standards as the starting point for identification per IFRS S1 paragraph 55.

Artefacts an auditor will ask for
  • Materiality assessment report
  • Mapping of SASB industry standards to entity operations
  • Stakeholder engagement logs
  • Materiality matrix or heatmap
  • Internal memo signing off material topics
Where this commonly fails
  • Materiality based only on financial impact ignoring impact materiality
  • No mapping of SASB industry standards to business units
  • Stakeholder input not documented
SASB-STR-02
Time Horizons for Sustainability Risk Assessment

Define and disclose the short, medium, and long term horizons used to assess sustainability related risks and opportunities, ensuring alignment with strategic planning cycles.

Artefacts an auditor will ask for
  • Documented definitions of short, medium, long term
  • Strategic plan timeline showing alignment
  • Risk register entries flagged by horizon
Where this commonly fails
  • Time horizons not defined or inconsistently applied
  • Long term horizon shorter than asset useful lives
SASB-STR-03
Business Model and Value Chain Impacts

Disclose where in the business model and value chain sustainability related risks and opportunities are concentrated, including upstream suppliers and downstream customers.

Artefacts an auditor will ask for
  • Value chain diagram
  • Supplier and customer concentration analysis
  • Geographic footprint map
  • Tier 1 and tier 2 supplier ESG screening logs
Where this commonly fails
  • Value chain limited to direct operations
  • No identification of upstream or downstream concentrations of climate risk
SASB-STRAT-04
Strategy and Business Model Integration

Describe the effects of sustainability related risks and opportunities on the business model, strategy, and decision making, including resilience over short, medium, and long term horizons.

Artefacts an auditor will ask for
  • Strategic plan referencing material topics
  • Scenario analysis outputs
  • Capital allocation decisions log
  • Resilience assessment
Where this commonly fails
  • Strategy statements not linked to financials
  • Scenario analysis qualitative only
  • Time horizons not defined

Sustainability Risk Management

SASB-RISK-05
Risk Management Process

Describe the processes used to identify, assess, prioritise, and monitor sustainability related risks and how they are integrated into the overall enterprise risk management.

Artefacts an auditor will ask for
  • ERM integration map
  • Sustainability risk taxonomy
  • Risk register extract
  • Monitoring cadence
Where this commonly fails
  • Sustainability risks tracked separately from ERM
  • Likelihood and impact rated qualitatively only
  • No risk owner assigned
SASB-RM-01
Sustainability Risk Identification Process

Describe the processes used to identify, assess, prioritize, and monitor sustainability related risks, including the inputs, scenarios, and tools applied.

Artefacts an auditor will ask for
  • Documented sustainability risk methodology
  • Scenario analysis report aligned to IFRS S2
  • Sustainability risk register
  • Heat maps and prioritization criteria
Where this commonly fails
  • Methodology not formalized
  • Climate scenarios limited to one pathway
  • Risks not integrated with enterprise risk management
SASB-RM-02
Integration of Sustainability Risks into Enterprise Risk Management

Demonstrate integration of sustainability and climate risks into the entity's enterprise risk management framework, including consistent rating scales and escalation paths.

Artefacts an auditor will ask for
  • ERM framework document with sustainability section
  • Integrated risk taxonomy
  • Risk committee minutes showing climate items
  • Escalation thresholds and approval matrices
Where this commonly fails
  • Climate risks tracked in a separate register from enterprise risks
  • Different rating scales used across ERM and ESG
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the SASB Standards framework page.