Overview
Two Retail Business Models, One Consumer Relationship
A shopper walking into a big-box store and a shopper checking out on a phone are buying from businesses that SASB treats as genuinely different industries, not two channels of the same one. Multiline and Specialty Retailers & Distributors (SICS CG-MR) covers physical stores and the distribution centres that supply them; E-Commerce (SICS CG-EC) covers "pure-play" online marketplaces and web-based sellers, explicitly excluding any brick-and-mortar or manufacturing operations a company might also run. The two standards share a consumer-facing logic — both worry about how a company handles customer data and how it treats the people who fill orders — but the actual disclosure topics diverge sharply once you look past that shared framing, and both leave out content a reader familiar with retail's reputation for supply-chain and workplace-safety risk might expect to find. This guide works through what each standard actually requires and where the gaps are.
SASB — now maintained by the International Sustainability Standards Board (ISSB) as part of the IFRS Foundation — places both standards in its Consumer Goods sector. Multiline and Specialty Retailers & Distributors covers entities selling a broad or specialised assortment of merchandise through physical storefronts and the distribution centres behind them; SASB's own note under the standard flags that a retailer with meaningful food, drug, e-commerce, or apparel-manufacturing operations should also consult those industries' own standards, since CG-MR is written for the general-merchandise middle of the market. E-Commerce covers "pure-play" online marketplaces and web-based sellers only — the standard explicitly excludes the manufacturing or brick-and-mortar retail operations a company might also run, which means a large omnichannel retailer with a substantial online business may need both standards side by side rather than picking one. Both standards share the same underlying concern — a company that holds customer payment data and relies on a large hourly or specialised workforce — but express it through almost entirely non-overlapping disclosure topics, covered in the sections below.
The Two Standards at a Glance
Each standard organizes its material risks into a set of named disclosure topics, each with its own metrics (SASB's own terms: disclosure topics describe a specific sustainability-related risk or opportunity; metrics quantify or describe an entity's performance against a topic).
Multiline and Specialty Retailers & Distributors: Energy Management in Retail & Distribution, Data Security, Labour Practices, Workforce Diversity & Inclusion, Product Sourcing, Packaging & Marketing.
E-Commerce: Hardware Infrastructure Energy & Water Management, Data Privacy & Advertising Standards, Data Security, Employee Recruitment, Inclusion & Performance, Product Packaging & Distribution.
Five topics against five is an even count, and the topic names even rhyme in places — both have an energy topic, both have a data security topic, both have a workforce topic, both have a sourcing/packaging topic. But as with the utility and mining standards covered elsewhere in this series, matching topic counts hide diverging substance: the two standards' workforce topics measure entirely different things, E-Commerce splits data protection into two topics where CG-MR has one, and the standard named "Packaging & Distribution" turns out to be built around a climate metric, not a packaging-material one.
Energy Use: Store Footprint Versus Data Centre Load
Both standards open with an energy topic built on the same three-part metric — total energy consumed, percentage from grid electricity, percentage renewable (CG-MR-130a.1, CG-EC-130a.1) — but the underlying infrastructure driving that consumption is different. CG-MR's Energy Management in Retail & Distribution covers store and warehouse lighting, HVAC, and refrigeration load; the topic summary frames energy efficiency as a direct cost lever in a low-margin industry, not primarily a climate-risk one. CG-EC's Hardware Infrastructure Energy & Water Management covers the data centres that power an online marketplace, and adds a second dimension CG-MR has no equivalent for: total water withdrawn and consumed, broken out by whether the facility sits in a region of high or extremely high water stress (CG-EC-130a.2), because data centre cooling trades energy efficiency against local water demand. E-Commerce also adds a qualitative metric — discussion of how environmental considerations factor into data centre planning decisions (CG-EC-130a.3) — that CG-MR's topic doesn't carry, reflecting that a retailer's store footprint is mostly fixed while an online seller is continuously deciding whether to build, lease, or outsource compute capacity.
Data Security and Privacy: Where the Two Standards Split
Both standards require a description of how the entity identifies and manages data security risk, plus a breach count broken out by whether the breach involved personal data and how many customers or users were affected (CG-MR-230a.1/.2, CG-EC-230a.1/.2) — genuinely parallel metrics, unlike most of the rest of these two standards. Where they diverge is scope: CG-MR treats data security as one topic covering the whole of its customer-data handling, while E-Commerce splits it into two separate topics. Data Security in CG-EC is the same breach-and-vulnerability-management content as CG-MR's version. Data Privacy & Advertising Standards is a distinct topic CG-MR has no analogue for at all: the number of users whose information is used for a "secondary purpose" — meaning any use beyond what the data was originally collected for, such as selling targeted ads or transferring data to a third party (CG-EC-220a.1) — plus a qualitative description of the entity's targeted-advertising and privacy policies (CG-EC-220a.2). The split makes sense given the two business models: a store's data-security exposure is mostly about protecting payment-card information from breach, while an online marketplace's core business model depends on using behavioural and demographic data to target ads and recommendations, which raises a privacy-practice question a physical retailer's standard doesn't need to ask.
Workforce: Two Completely Different Labour Risk Profiles
This is the sharpest divergence between the two standards, and it's a genuine one rather than an artefact of different topic names. CG-MR's Labour Practices and Workforce Diversity & Inclusion topics are built around a large, hourly, in-store and distribution-centre workforce: average hourly wage and the percentage of workers earning at (not above) minimum wage, by region (CG-MR-310a.1); voluntary and involuntary turnover (CG-MR-310a.2); monetary losses from labour-law-violation litigation (CG-MR-310a.3); and gender/diversity representation across management tiers (CG-MR-330a.1), plus losses from employment-discrimination litigation (CG-MR-330a.2). The framing throughout is minimum-wage exposure and legal risk from a workforce whose compensation sits close to the wage floor.
CG-EC's Employee Recruitment, Inclusion & Performance describes an almost unrecognisably different workforce: employee engagement score from a survey (CG-EC-330a.1); voluntary and involuntary turnover, the one metric that maps directly onto CG-MR's version (CG-EC-330a.2); gender/diversity representation, but broken out with an added "technical employees" category alongside executive management, non-executive management, and all other employees (CG-EC-330a.3); and, with no CG-MR equivalent at all, the percentage of technical employees who require a work visa (CG-EC-330a.4), because the topic summary frames E-Commerce's labour risk as competition for scarce, specialised, often internationally-recruited technical talent — the opposite risk profile from a minimum-wage retail workforce. Neither standard's workforce topic carries a wage-floor metric and a technical-recruitment metric at once; each picked the one that matches its own industry's actual labour market.
Sourcing and Packaging: Chemicals, Certification, and Shipment Emissions
CG-MR's Product Sourcing, Packaging & Marketing is the standard's broadest single topic, bundling three distinct concerns under one heading: revenue from products third-party certified to an environmental or social sustainability standard (CG-MR-410a.1); a qualitative discussion of how the entity assesses and manages chemical hazards in both third-party-branded and private-label products, including whether its approach is hazard-based or risk-based (CG-MR-410a.2); and a qualitative discussion of strategies to reduce packaging's environmental impact, such as material substitution or weight reduction (CG-MR-410a.3).
CG-EC's nominally equivalent topic, Product Packaging & Distribution, is a narrower construction than its name suggests. Its one quantitative metric is the tank-to-wheels greenhouse gas footprint of outbound product shipments, calculated to the EN 16258:2012 methodology and covering both the entity's own fleet (Scope 1) and outsourced freight and logistics providers (Scope 3) (CG-EC-410a.1) — a genuine climate/logistics-emissions metric, not a packaging-material one. Packaging choices — recycled or renewable materials, weight optimisation, reusable formats — appear only as one discussion point folded inside a broader qualitative metric on reducing delivery's environmental impact, alongside route efficiency and fleet fuel choices (CG-EC-410a.2). A reader who expects "Product Packaging & Distribution" to be E-Commerce's answer to CG-MR's packaging-material disclosure will find that its real weight sits on shipment emissions instead.
What's Missing: No Supply-Chain Human Rights Topic, No Safety Metric
Two absences are worth naming directly rather than working around them. First, neither standard carries a supply-chain labour or human rights due diligence topic — nothing resembling factory audits, forced-labour screening, or supplier code-of-conduct compliance appears in either CG-MR or CG-EC, despite both industries selling globally-sourced merchandise (CG-MR's chemicals-in-products metric touches supplier engagement only on chemical safety, not labour conditions). A company wanting to build genuine supply-chain human rights evidence should work from Standard ESG's guide to human rights due diligence and the UN Guiding Principles rather than expecting either SASB standard to cover it. Second, neither standard includes a workforce injury or fatality-rate metric — a real gap for CG-MR in particular, given that its own scope names distribution-centre employees (forklift operators, freight handlers) as a covered workforce category without ever asking for a safety outcome metric on them. This is a genuine limitation in both standards, not a research gap in this article: retail and e-commerce workforce risk, as SASB defines it, is compensation and turnover risk, not physical safety risk.
Mapping to Standard ESG Subjects
Both energy topics map to E2 — Resource use, covering energy and, for E-Commerce, water consumption as well. CG-EC's shipment-GHG metric within Product Packaging & Distribution maps to E3 — Emissions & climate, a subject the original scope for this task didn't anticipate — the standard's one hard climate-accounting number turned out to be hiding inside a topic named for packaging rather than emissions. The packaging-material discussion within that same topic, plus CG-MR's own packaging-strategy metric, map to E4 — Waste, circularity & pollution prevention, as anticipated. Both standards' workforce topics map to S1 — Labour practices & decent work — wage, turnover, and diversity metrics on both sides, despite measuring different workforces. CG-MR's chemicals-in-products and certified-product-revenue metrics split across S5 — Consumer/end-user responsibility for the chemical-safety half and G4 — Sustainable procurement & supply-chain management for the certification half, the latter not anticipated in the original scope. Both data security topics and CG-EC's data privacy/advertising topic map to S5, as anticipated. S3 — Human rights & due diligence and S2 — Occupational health & safety, both anticipated in the original scope, drop out entirely — the previous section covers why.
Which SEIC Sectors This Deepens Coverage For
These two standards carry the most weight for exactly the SEIC groups their SICS codes name: general-merchandise and specialty physical retailers and their distribution operations (CG-MR), and pure-play online marketplaces and web-based sellers (CG-EC). Standard ESG's consumer and product responsibility starter guide already covers the consumer-protection ground — product safety, fair marketing, complaint handling, data protection — that both standards touch on generically across any consumer-facing industry; this guide is the sector-specific layer identifying exactly which of those concerns each standard actually turns into a disclosure metric, and which it leaves out.
Getting Started
A retailer or online seller building out its E2, E3, E4, S1, S5, and G4 evidence base can work through these two standards' shared and distinct ground roughly as follows.
Confirm which standard applies — Multiline and Specialty Retailers & Distributors for physical stores and distribution centres, E-Commerce for pure-play online operations, or both for a genuine omnichannel business.
Start with the topic each standard treats as materially larger — Product Sourcing, Packaging & Marketing for CG-MR; Employee Recruitment, Inclusion & Performance for CG-EC — since these carry the most metrics per topic.
Build data security evidence once, since the breach-count and risk-management-approach metrics are near-identical across both standards; E-Commerce sellers should build the separate data-privacy/advertising evidence alongside it, not as an afterthought.
Don't assume either standard covers supply-chain labour conditions or workforce safety — both are real gaps, not oversights in this guide, and a company with material exposure there should look outside these two standards for that evidence.
Standard ESG's Level 1 questionnaire draws on exactly this kind of standard-specific mapping to ask for evidence a retailer or online seller can actually produce, rather than generic ESG boilerplate; Level 2 verified documents and Level 3 on-site assessment build on the same subject foundation with progressively deeper evidence requirements.
Cette page vous a-t-elle été utile ?