Overview
Governance is the pillar that makes the other two mean anything. An environmental policy nobody's board reviews and a code of conduct nobody enforces are just documents; governance is what turns commitments into accountability. This guide covers the core of Standard ESG's Governance pillar outside procurement and reporting: board oversight, ethics, anti-corruption, and risk management.
Why Governance Is the Pillar That Enables the Others
An organization can have a strong environmental policy and a genuinely good labour record and still fail at governance if there's no real accountability structure behind either — no one reviewing performance, no one empowered to escalate a problem, no consequence for ignoring the policy when it's inconvenient. Governance is where environmental and social commitments either become durable practice or quietly erode the first time they conflict with short-term convenience. This is why governance carries real weight in Standard ESG's default pillar weighting (25%, alongside Environmental 40% and Social 35%) even though it produces no smokestacks or safety incidents of its own to point to — its role is structural, not directly observable in the same way.
Board Oversight and Value Creation: The ⟨IR⟩ Capitals Model
The IFRS Integrated Reporting (⟨IR⟩) Framework offers the clearest available model for what genuine board-level oversight of sustainability actually looks like — not as a compliance checkbox, but as core strategic thinking about how the organization creates value over time.
Its central idea is integrated thinking: the active consideration by an organization of the relationships between its various operating and functional units and the capitals it uses or affects. The Framework categorizes these capitals as financial, manufactured, intellectual, human, social and relationship, and natural — stocks of value that are increased, decreased, or transformed through the organization's activities and outputs. Value creation, in this model, isn't just financial return to shareholders; it's interrelated with the value the organization creates for stakeholders and society more broadly, and organizations are not required to report every one of these six capitals — the framework is principles-based, not a rigid checklist.
For governance specifically, the Framework's point is direct: a board that only reviews financial capital while ignoring how the organization uses and affects human, social, and natural capital isn't exercising complete oversight — and Standard ESG's subject G1 is aligned with exactly this expanded view of what board oversight should cover.
The Guiding Principles Behind Good Governance Disclosure
The ⟨IR⟩ Framework sets out seven Guiding Principles that underpin credible reporting and, by extension, credible governance practice generally: strategic focus and future orientation; connectivity of information (showing how different factors affecting value creation relate to one another, rather than presenting them as disconnected silos); stakeholder relationships; materiality; conciseness; reliability and completeness (disclosing material matters, positive and negative, in a balanced way); and consistency and comparability over time. These principles are worth internalizing even for an organization not producing a formal integrated report, because they describe what mature governance thinking looks like in practice — connected, honest about both strengths and gaps, and consistent rather than reinvented each year.
Codes of Conduct: What a Real One Contains
A code of conduct is the most basic governance document an organization can produce, and also the one most often written but least often actually used. A code that does real work typically covers: honesty and fair dealing in business relationships; conflicts of interest and how to disclose them; confidentiality and appropriate use of company information; fair treatment of colleagues, consistent with the anti-discrimination principles covered in Labour Practices and Decent Work; a clear statement on gifts, entertainment, and anti-corruption (Section 5); and — critically — a description of how concerns get raised and what happens next (Section 6). A one-page code that's actually read, understood, and referred to when a real situation arises outperforms an elaborate document that exists only in a policy folder.
Anti-Corruption Programmes
Corruption — bribery, facilitation payments, kickbacks in procurement, self-dealing — is one of the clearest governance failures because it directly corrupts the integrity of every other process it touches, including supplier selection (undermining sustainable procurement) and financial reporting. A working anti-corruption programme, proportionate to organizational size, typically includes: an explicit anti-bribery and anti-corruption policy, with a clear statement that facilitation payments are prohibited; risk assessment focused on higher-risk interactions (government dealings, high-value procurement, agents and intermediaries acting on the organization's behalf); training for staff in higher-exposure roles; and a due-diligence process for third parties who could expose the organization to corruption risk, consistent with ISO 26000's treatment of fair operating practices as a core social-responsibility subject in its own right.
Whistleblowing and Grievance Mechanisms
A code of conduct and an anti-corruption policy are only as good as the mechanism for raising a concern about a violation of either. A functioning whistleblowing or grievance channel needs three properties to actually work: it must be genuinely accessible (people need to know it exists and how to use it — see Labour Practices and Decent Work on how Standard ESG's on-site interviews specifically check whether workers actually know how to access one); it must protect the person raising a concern from retaliation, explicitly and in practice, not just on paper; and it must lead somewhere — a concern raised and never followed up on teaches everyone that the channel is theatre, which is worse than not having one at all, because it actively discourages future disclosure.
Risk Management and Compliance
Beyond ethics specifically, governance includes the broader discipline of systematically identifying, assessing, and managing risk — legal, operational, environmental, social, and financial — and maintaining genuine compliance with applicable law, not just awareness of it. This is the governance equivalent of the Plan-Do-Check-Act discipline found throughout the environmental and safety management-system standards: risks get identified, prioritized, addressed, and reviewed on a cycle, rather than handled only reactively after something has already gone wrong.
Mapping to Standard ESG Subjects G1, G2, and G5
This guide covers three of Standard ESG's five governance core subjects directly:
- G1 — Organizational governance & board oversight, aligned with the ⟨IR⟩ Framework's value-creation and capitals thinking (Section 2).
- G2 — Ethics, anti-corruption & fair operating practices, covering the code of conduct, anti-corruption programme, and whistleblowing mechanism described in Sections 4–6, and drawing on ISO 26000's treatment of fair operating practices.
- G5 — Risk management & compliance, covering the systematic risk discipline in Section 7.
(The remaining two governance subjects — G3, transparency and reporting, and G4, sustainable procurement — are covered in Sustainability Reporting with GRI and Sustainable Procurement and Supply-Chain Due Diligence respectively.)
Typical Level 2 evidence for this part of the Governance pillar includes your code of conduct, your anti-corruption policy, and your board or oversight charter — even a simple governance statement naming who is responsible for oversight functions as this for a smaller organization.
Building This at Small-Company Scale
Governance sounds like it requires a formal board, but the underlying disciplines scale down: a small company can name one person (even the owner) formally responsible for compliance oversight; write a one-page code of conduct covering honesty, conflicts of interest, and anti-corruption; set up a simple email address as a grievance channel and actually respond when it's used; and review risk and compliance status at least once a year, even informally. See Getting Started with ESG: A Practical Guide for SMEs for how these fit into a broader first-90-days plan.
Standard ESG (standardesg.org) draws Governance subjects G1, G2, and G5 from the ⟨IR⟩ Framework and ISO 26000's fair operating practices. See Sustainability Reporting with GRI and Sustainable Procurement and Supply-Chain Due Diligence for the rest of the Governance pillar.
Cette page vous a-t-elle été utile ?