Skip to content

Evidence request lists

UN Guiding Principles on Business and Human Rights (UNGPs)

Evidence request list. 26 controls, 26 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Human Rights Due Diligence

UNGP-17
Human Rights Due Diligence

Business enterprises should carry out human rights due diligence to identify, prevent, mitigate and account for how they address adverse human rights impacts, covering impacts they may cause, contribute to, or be directly linked to.

Artefacts an auditor will ask for
  • Salient issues assessment
  • Integration of findings into business processes
  • Tracking metrics
  • External communication of due diligence efforts
Where this commonly fails
  • Due diligence conducted but not integrated
  • No tracking of effectiveness
  • Communication limited to a high level statement
UNGP-18
Assessing Actual and Potential Impacts

Enterprises should identify and assess actual and potential adverse human rights impacts with which they may be involved, drawing on internal or independent expertise and involving meaningful consultation with potentially affected groups.

Artefacts an auditor will ask for
  • Country and operation impact assessments
  • Expert engagement records
  • Stakeholder consultation records including affected groups
  • Refresh schedule
Where this commonly fails
  • Stakeholder consultation limited to large NGOs
  • Affected groups not directly engaged
  • Assessment not refreshed when context changes
UNGP-19
Integrating and Acting Upon Findings

Enterprises must integrate findings from impact assessments across relevant internal functions and processes, and take appropriate action including preventing or mitigating impacts and using leverage in relationships.

Artefacts an auditor will ask for
  • Cross functional steering committee minutes
  • Action plans with owners
  • Leverage strategy with partners
  • Documented use of leverage outcomes
Where this commonly fails
  • Findings stay within sustainability team
  • Actions lack owners and dates
  • Leverage rhetoric without practice
UNGP-20
Tracking Effectiveness of Responses

Enterprises should track the effectiveness of their response to adverse human rights impacts, based on appropriate qualitative and quantitative indicators and drawing on feedback from internal and external sources, including affected stakeholders.

Artefacts an auditor will ask for
  • KPI dashboard for human rights actions
  • Affected stakeholder feedback channels
  • Review meetings on effectiveness
  • Improvement actions tracked
Where this commonly fails
  • KPIs focus on activity not effectiveness
  • Feedback collected but not used
  • Reviews conducted but no actions follow
UNGP-21
Communicating Externally on Human Rights

Enterprises whose operations or operating contexts pose risks of severe human rights impacts should report formally on how they address them, providing information that is sufficient to evaluate the adequacy of the response.

Artefacts an auditor will ask for
  • Annual human rights report
  • Use of UNGP Reporting Framework or equivalent
  • Accessibility considerations for affected stakeholders
  • Assurance over reporting
Where this commonly fails
  • Reporting is high level marketing
  • Salient issues not identified or quantified
  • No external assurance

Pillar I: State Duty to Protect Human Rights

UNGP-1
State Duty to Protect Against Human Rights Abuses

States must protect against human rights abuses within their territory or jurisdiction by third parties including business enterprises, requiring effective policies, legislation, regulations and adjudication to prevent, investigate, punish and redress such abuse.

Artefacts an auditor will ask for
  • National Action Plan on Business and Human Rights
  • Mapping of relevant laws
  • Adjudication records relating to corporate abuses
  • Regulator coordination documentation
Where this commonly fails
  • No National Action Plan in place
  • Laws on paper without enforcement
  • No coordination across regulators
UNGP-2
State Expectations of Business Enterprises Abroad

States should set out the expectation that business enterprises domiciled in their territory or jurisdiction respect human rights throughout their operations, including those abroad.

Artefacts an auditor will ask for
  • Public policy statement of expectations
  • Embassy guidance to companies operating abroad
  • Trade promotion conditions referencing UNGPs
  • Export credit due diligence requirements
Where this commonly fails
  • No published expectation statement
  • Trade promotion silent on human rights
  • Embassies not briefed
UNGP-3
State Regulatory and Policy Functions

States should enforce laws that require business to respect human rights, ensure other laws do not constrain such respect, provide effective guidance, and encourage or require companies to communicate how they address human rights impacts.

Artefacts an auditor will ask for
  • Enforcement statistics for relevant laws
  • Published guidance for business
  • Reporting requirements such as modern slavery statements
  • Coherence review across regulations
Where this commonly fails
  • Reporting requirements without quality criteria
  • Guidance issued once and never updated
  • Conflicting laws limiting respect for rights
UNGP-4
State-Business Nexus

States should take additional steps to protect against abuses by business enterprises that are owned or controlled by the State, or that receive substantial support from State agencies such as export credit and investment insurance.

Artefacts an auditor will ask for
  • Human rights policies in state owned enterprises
  • Export credit agency due diligence procedures
  • Investment screening criteria
  • Reporting on state linked operations
Where this commonly fails
  • State owned firms held to lower standard
  • ECAs lack human rights conditionality
  • No reporting on portfolio impacts
UNGP-5
Privatised Public Services and Human Rights Oversight

When States contract with or legislate to private companies to provide services that may impact human rights, States should exercise adequate oversight to meet their obligations.

Artefacts an auditor will ask for
  • Procurement clauses on human rights
  • Service performance monitoring covering rights
  • Independent oversight body terms of reference
  • Routes for service users to raise concerns
Where this commonly fails
  • Contracts silent on human rights
  • Oversight focuses on cost not rights
  • No route for service user complaints
UNGP-6
Public Procurement and Human Rights

States should promote respect for human rights by business enterprises with which they conduct commercial transactions, including through public procurement decisions.

Artefacts an auditor will ask for
  • Public procurement human rights policy
  • Supplier human rights questionnaires
  • Award criteria including human rights performance
  • Monitoring of contracted suppliers
Where this commonly fails
  • Lowest price always wins regardless of rights record
  • Supplier checks limited to modern slavery only
  • No monitoring after award
UNGP-7
Supporting Business Respect in Conflict Affected Areas

States should help ensure that business enterprises operating in conflict affected areas are not involved with human rights abuses, including engaging with companies and providing adequate assistance.

Artefacts an auditor will ask for
  • Conflict area engagement guidance
  • Sanctions screening processes
  • Embassy reporting on human rights conditions
  • Specific advisories for conflict areas
Where this commonly fails
  • No conflict area specific guidance
  • Sanctions screening without human rights overlay
  • Embassies under resourced
UNGP-8
Policy Coherence Across Government

States should ensure governmental departments, agencies and other state based institutions that shape business practices are aware of and observe the State's human rights obligations, with cohesive policy across functions.

Artefacts an auditor will ask for
  • Inter ministerial committee on business and human rights
  • Awareness training for relevant officials
  • Reviews of policy coherence
  • Joint guidance
Where this commonly fails
  • Departments work in silos
  • Trade promotion contradicts human rights guidance
  • Officials lack training

Pillar II: Corporate Responsibility to Respect Human Rights

UNGP-11
Corporate Responsibility to Respect Human Rights

Business enterprises should respect human rights, meaning they should avoid infringing on the human rights of others and address adverse human rights impacts with which they are involved.

Artefacts an auditor will ask for
  • Board approved human rights policy
  • Human rights due diligence programme
  • Impact remediation cases closed
  • External communications
Where this commonly fails
  • Policy without operational integration
  • Due diligence one off rather than ongoing
  • No remediation pathway in practice
UNGP-12
Scope of Human Rights to Be Respected

The responsibility to respect human rights refers to internationally recognised human rights, understood at a minimum as those expressed in the International Bill of Human Rights and the ILO Declaration on Fundamental Principles and Rights at Work.

Artefacts an auditor will ask for
  • Rights inventory covering Bill of Human Rights and ILO core conventions
  • Salient rights for the business identified
  • Training on relevant rights
  • Mapping to operational risks
Where this commonly fails
  • Inventory limited to local law
  • Salient rights identified but not refreshed
  • Training generic
UNGP-13
Three Ways Businesses May Be Involved With Impacts

The responsibility to respect requires that enterprises avoid causing or contributing to adverse human rights impacts through their own activities, and seek to prevent or mitigate impacts directly linked to their operations, products or services through business relationships.

Artefacts an auditor will ask for
  • Analysis differentiating cause, contribute, linked
  • Action plans differentiated by involvement type
  • Leverage strategy with business partners
  • Records of business relationship reviews
Where this commonly fails
  • All impacts treated the same regardless of involvement
  • No leverage strategy with influential partners
  • Linked impacts ignored as not the company's problem
UNGP-14
Applies to All Enterprises Regardless of Size

The responsibility to respect human rights applies to all enterprises regardless of size, sector, operational context, ownership and structure, although the scale and complexity of means by which they meet that responsibility may vary.

Artefacts an auditor will ask for
  • Proportionality statement
  • SME tailored due diligence procedures
  • Scaling plan as the company grows
  • Sector specific considerations
Where this commonly fails
  • Smaller subsidiaries left out of programme
  • No tailoring leading to non-implementation
  • Sector context ignored
UNGP-15
Knowing and Showing - Policies and Processes

Business enterprises should have in place policies and processes appropriate to their size and circumstances including a policy commitment, human rights due diligence, and processes to enable remediation of any adverse impacts they cause or contribute to.

Artefacts an auditor will ask for
  • Public policy statement signed at senior level
  • Documented due diligence procedure
  • Grievance and remediation procedure
  • Annual programme review
Where this commonly fails
  • Policy exists without operational processes
  • Due diligence not documented
  • Remediation only available to direct employees
UNGP-16
Policy Commitment Standards

The policy commitment should be approved at the most senior level, informed by relevant expertise, stipulate expectations of personnel and partners, be publicly available, and reflected in operational policies and procedures.

Artefacts an auditor will ask for
  • Signed policy at board or CEO level
  • Records of expert consultation
  • Public posting on company website
  • Operational policy cross references
Where this commonly fails
  • Approval at functional rather than senior level
  • No expert input on salient issues
  • Operational policies not aligned

Pillar III: Access to Remedy

UNGP-22
Remediation Where Cause or Contribution Identified

Where enterprises identify that they have caused or contributed to adverse impacts, they should provide for or cooperate in their remediation through legitimate processes.

Artefacts an auditor will ask for
  • Remediation policy and procedure
  • Closed remediation cases with outcomes
  • Funding allocated for remediation
  • Affected stakeholder satisfaction information
Where this commonly fails
  • Remediation considered ad hoc
  • No outcome data collected
  • Procedures treat all impacts the same
UNGP-29
Operational Level Grievance Mechanisms

To make it possible for grievances to be addressed early and remediated directly, enterprises should establish or participate in effective operational level grievance mechanisms for individuals and communities who may be adversely impacted.

Artefacts an auditor will ask for
  • Operational grievance mechanism procedure
  • Accessibility assessment (language, channels, fear of reprisal)
  • Case logs with anonymised outcomes
  • Mechanism reviews
Where this commonly fails
  • Mechanism only available to employees
  • Channels are intimidating or inaccessible
  • Effectiveness criteria not met
UNGP-31
Effectiveness Criteria for Non-Judicial Grievance Mechanisms

Non-judicial grievance mechanisms, both state based and non state based, should be legitimate, accessible, predictable, equitable, transparent, rights compatible, a source of continuous learning, and based on engagement and dialogue.

Artefacts an auditor will ask for
  • Self assessment against the eight criteria
  • Stakeholder trust survey
  • Lessons learned from cases incorporated
  • External review of mechanism
Where this commonly fails
  • Self assessment never performed
  • Stakeholder trust low and unmonitored
  • Lessons not captured

Protect

UNGPBHR-1
Pillar I: State Duty to Protect Human Rights

Per UN Guiding Principles Pillar I (GP 1-10): State Obligation to Protect + state-business nexus + legal framework + access to remedy. Mostly state-directed but corporate cooperation expected.

Artefacts an auditor will ask for
  • UNGP evidence for UNGPBHR-1
Where this commonly fails
  • HRDD + grievance partial

Remedy

UNGPBHR-3
Pillar III: Access to Remedy

Per UNGPs Pillar III (GP 25-31): access to remedy + state-based + non-state-based mechanisms + operational-level grievance mechanism + effectiveness criteria.

Artefacts an auditor will ask for
  • UNGP evidence for UNGPBHR-3
Where this commonly fails
  • HRDD + grievance partial

Reporting

UNGPBHR-4
Reporting and Communication

Per UNGPs Reporting Framework: communicate human rights performance + integrate with sustainability reporting + ISSB + CSRD alignment.

Artefacts an auditor will ask for
  • UNGP evidence for UNGPBHR-4
Where this commonly fails
  • HRDD + grievance partial

Respect

UNGPBHR-2
Pillar II: Corporate Responsibility to Respect Human Rights

Per UNGPs Pillar II (GP 11-24): Responsibility to Respect + Policy Commitment + Human Rights Due Diligence (HRDD) including identification + integration + tracking + reporting + Avoid Causing Harm.

Artefacts an auditor will ask for
  • UNGP evidence for UNGPBHR-2
Where this commonly fails
  • HRDD + grievance partial
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the UN Guiding Principles on Business and Human Rights (UNGPs) framework page.