Purpose and Scope
The protocol defines how Standard ESG evaluates, scores, and certifies an organization's sustainability and ethical impact across Environmental, Social, and Governance criteria. In practical terms, it governs seven things: the assessment methodology and scoring model; documentation and evidence requirements; the three certification levels and how a company moves through them; the on-site verification framework used at the highest level; how suppliers and third parties factor into a company's rating; how certificates are issued, expire, and can be revoked; and the governance of the scheme itself — impartiality, auditor competence, and appeals.
It applies to any legal entity, in any industry, that registers with Standard ESG. What changes by industry is not the protocol's structure but its content: industry-specific questions, document lists, and on-site checklists are delivered through assessment templates, so a manufacturer and a software company are held to the same architecture but asked different, appropriately weighted questions.
Built on Standards the Market Already Trusts
Standard ESG did not invent a new taxonomy of what "responsible business" means. The protocol is ISO 20400-compatible at its core — ISO 20400:2017's guidance on sustainable procurement supplies the backbone of the assessment structure: the subjects it covers, its approach to due diligence, its expectations of the supply chain, and its underlying logic of drivers leading to policy, enablers, and process.
Around that backbone, the protocol draws on complementary standards exactly where they align, rather than inventing overlapping criteria:
- ISO 20400:2017 — Sustainable procurement: backbone of the assessment structure.
- ISO 26000:2010 — Social responsibility guidance: source of the seven core subjects used to organize criteria.
- ISO 14001:2015 — Environmental management systems: environmental pillar — policy, planning, operational control, monitoring, the PDCA improvement cycle.
- ISO 45001:2018 — Occupational health & safety: social pillar — workplace safety criteria and on-site inspection points.
- SA8000:2014 — Social accountability: social pillar and the Level 3 on-site framework — child labour, forced labour, working hours, remuneration, freedom of association, discrimination, disciplinary practices.
- GRI Standards (GRI 2, 3, 200/300/400 series): disclosure structure, materiality approach, and evidence expectations for reported data.
- IFRS Integrated Reporting Framework (⟨IR⟩): governance pillar — value-creation narrative, capitals thinking, board oversight of sustainability.
One point matters enough to state plainly: Standard ESG certification is not an ISO certification, and the protocol does not claim conformity assessment against any ISO standard. It is a proprietary protocol that is compatible with, and informed by, the standards above — built so that a company's existing ISO 14001 or SA8000 evidence base translates directly into Standard ESG evidence, rather than requiring parallel compliance efforts.
The Assessment Architecture: Pillars, Subjects, Criteria, Indicators
Every assessment is organized into three pillars, each subdivided into core subjects adapted from ISO 26000 and ISO 20400:
- Environmental — E1: environmental management system & policy (ISO 14001 alignment).
- Environmental — E2: resource use — energy, water, materials.
- Environmental — E3: emissions & climate (GHG Scope 1–2 required; Scope 3 encouraged).
- Environmental — E4: waste, circularity & pollution prevention.
- Environmental — E5: biodiversity & land use (industry-dependent).
- Social — S1: labour practices & decent work (SA8000 core elements).
- Social — S2: occupational health & safety (ISO 45001 alignment).
- Social — S3: human rights & due diligence.
- Social — S4: community involvement & development.
- Social — S5: consumer/end-user responsibility (industry-dependent).
- Governance — G1: organizational governance & board oversight (⟨IR⟩ alignment).
- Governance — G2: ethics, anti-corruption & fair operating practices.
- Governance — G3: transparency & reporting (GRI alignment).
- Governance — G4: sustainable procurement & supply-chain management (ISO 20400 core).
- Governance — G5: risk management & compliance.
Below the fifteen core subjects, the schema gets granular. Each subject contains criteria, and each criterion is measured by one or more indicators — the actual questionnaire items a company answers. Every indicator carries a defined shape: an answer type (boolean, single-choice, multi-choice, numeric, percentage, text, or file-reference), a relative weight within its criterion, an evidence requirement that varies by certification level, applicability tags by industry and company size, and a scoring rule mapping the answer to a 0–100 indicator score.
An indicator tagged as non-applicable to a given company or industry is excluded from scoring — not scored as zero. This matters: a manufacturing company isn't penalized for lacking a consumer-data-protection policy that a software company needs, and vice versa.
Industry Templates: One Protocol, Many Industries
Because a single fixed questionnaire cannot fairly represent every industry, Standard ESG operators maintain three template components per industry — manufacturing, finance, technology, and others as the scheme expands:
- A questionnaire template — the indicator set, with weights and applicability for that industry.
- A document requirements list for Level 2 verification.
- An on-site checklist for Level 3 assessment.
Templates are versioned, and an assessment is bound to whichever template version was active when it started — so a company's score stays reproducible and comparable even as templates evolve over time.
Each template version, once published, is immutable. At the moment it locks, Standard ESG computes a content hash — a SHA-256 hash over the canonical serialized template, covering the indicator set, weights, applicability rules, document lists, and checklist — and freezes that hash alongside the version number. That version number and hash are then stamped on every certificate and report produced from an assessment bound to it, so anyone — the company, an investor, a regulator — can verify exactly which template content a given certificate was scored against, permanently. This is the protocol's answer to a quiet but real risk in any scoring scheme: that criteria could shift silently after the fact. They can't.
How the Score Is Calculated
Scoring proceeds in a straightforward hierarchy, aggregating upward:
- Each indicator scores 0–100 according to its scoring rule.
- Each criterion score is the weighted mean of its applicable indicator scores.
- Each subject score is the weighted mean of its criterion scores.
- Each pillar score is the weighted mean of its subject scores.
- The composite score (0–100) is the weighted mean of the three pillar scores, using default weights of Environmental 40% / Social 35% / Governance 25% — overridable per industry template where an industry's risk profile warrants it.
That composite maps linearly to the public 1–10 score printed on every certificate: score10 = max(1, round(composite / 10)).
The same 1–10 scale is used at every certification level. This is a deliberate design choice: the level describes how the underlying data was verified; the score describes how the company actually performed. A Level 1 company and a Level 3 company can both score 7/10 — the difference is that the Level 3 company's 7 has been checked against documents and, ultimately, physical reality, while the Level 1 company's 7 is self-reported and reviewer-approved. Reading a certificate means reading level and score together.
Minimum Requirements: The Gates
Averages can hide serious problems, so the protocol applies hard gates that override the arithmetic entirely. Certification at any level is denied, regardless of composite score, if any of the following are true:
- Credible evidence or admission of child labour or forced labour.
- An active, material legal sanction for environmental crime or corruption that was undisclosed at the time of assessment.
- Any single pillar scoring below 20, even if the composite average looks acceptable.
- Failure to complete all applicable mandatory indicators.
No amount of strength in one pillar can compensate for a serious failure in another, and no average can launder a disqualifying fact. This is what separates a certification gate from a rating average.
The Assessment Lifecycle
Every assessment moves through the same sequence, though a company may stop at any level and still hold a valid certificate for the level it completed:
Registration → industry template binding → Level 1 questionnaire → internal review (approve or reject with comments) → optional Level 2 document submission → document verification queue → optional Level 3 on-site scheduling → visit → findings → report → final review → certificate issuance (per level) → 12-month validity → renewal.
Higher levels build on lower ones: Level 2 requires an approved Level 1 dataset; Level 3 requires verified Level 2 documents. A company cannot skip straight to an on-site audit without first having its self-declared answers checked against paperwork. Renewal repeats the assessment for the level currently held, against whatever template version is active at renewal time — so a certificate never drifts indefinitely from current standards.
Evidence: What Counts, and How It's Checked
Evidence rules are deliberately concrete, not aspirational. Documents must be dated, attributable to the specific legal entity under assessment, and no older than 24 months — unless the document type is inherently long-lived, such as articles of incorporation or a certification with its own stated validity period. Evidence can be submitted in any language, though the review team may request translation of key passages. All evidence is stored per-tenant, with access restricted to the submitting company and Standard ESG staff.
The typical Level 2 document set is organized by pillar, and its shape is industry-managed rather than fixed:
- Legal & registration — business registration, ownership structure.
- Environmental — ISO 14001 certificate, energy bills/audits, GHG inventory, waste transfer notes, environmental permits.
- Social — payroll samples (anonymized), working-hours records, H&S risk assessments, accident logs, training records, grievance-mechanism description.
- Governance — code of conduct, anti-corruption policy, board/oversight charters, supplier code of conduct, procurement policy.
- Reporting — sustainability/GRI report, integrated report, third-party audit reports.
Each submitted document moves through a defined status path: submitted → in-review → verified, rejected (with reason), or clarification-requested. Only a verified status lifts a scoring discount — a document sitting un-reviewed, or rejected, does not silently count in the company's favor.
Level 1 — Self-Assessment
The company completes the industry-specific questionnaire. Submission enters an internal approval queue, where a Standard ESG reviewer checks plausibility, completeness, and the minimum-requirement gates before approving or rejecting with comments. The certificate is explicit about what it claims and doesn't: "Based on self-declared data, not independently verified." It carries the entry-tier visual identity.
Level 2 — Verified Documents
The company uploads the industry-specific document set substantiating its Level 1 answers. The internal team verifies each document, and scores are recomputed with a verification adjustment: an indicator whose required document is missing, expired, or rejected is scored at only 50% of its declared value, or flagged for clarification, rather than taken at face value. The certificate reads: "Data substantiated through documentation reviewed and verified by Standard ESG." Level 2 also grants the website badge — a digital collectible the company can display.
Level 3 — On-Site Assessment
Conducted by Standard ESG trained auditors or an approved partner auditor, Level 3 includes cross-examination of the Level 2 data and documents, physical inspection, and interviews on site. On completion, the company receives a Findings & Recommendations Report documenting on-site observations and corrective-action guidance. The certificate reads: "Data verified through documentation review and independent on-site assessment." This is the highest tier — the strongest visual identity, and it also grants the badge.
Inside a Level 3 On-Site Assessment
Level 3 is a practical framework extending ISO 20400 with elements of SA8000, ISO 14001/45001, and GRI, delivered as a configurable checklist across eight default domains:
- Site & operations walkthrough — do production or office areas match declared activities, and are environmental controls physically present and functioning?
- Health & safety inspection — emergency exits, fire equipment, PPE, machine guarding, chemical storage and labelling, first-aid provision.
- Labour records cross-check — sampled personnel files against payroll and working-hours records; age verification; contract terms.
- Worker interviews — confidential, off-management interviews on a sampled basis, covering freedom of association, discrimination, disciplinary practices, and access to grievance mechanisms.
- Management interviews — governance oversight of ESG, risk processes, and corrective-action history.
- Document authenticity spot-checks — originals of key Level 2 documents sighted on site; permits and certificates checked against issuing registers where possible.
- Supply-chain due diligence — supplier selection criteria, the supplier code of conduct in practice, evidence of supplier assessments.
- Data trail verification — declared quantitative indicators (energy, water, waste, accident rates) traced back to meters, invoices, or logs.
Each checklist item declares a domain, a method (observation, interview, or record-review), a severity if it fails (minor, major, or critical), the questionnaire indicators it cross-examines, and applicability tags. Critical non-conformities trigger the certification gates directly.
A visit's minimum duration is guided by workforce size — from half a day up to three auditor-days — and follows an opening meeting, execution, and a closing meeting where preliminary findings are shared. Findings are classified minor, major, or critical: majors require a corrective-action plan within 30 days before a certificate is issued, while criticals block certification outright.
Every discrepancy between what the company declared and what the auditor observed is recorded as a finding against the affected indicators, and the corrected value feeds back into re-scoring — the on-site finding overrides the earlier declared answer. Following the closing meeting, the company receives a Findings & Recommendations Report covering every finding with its severity and linked indicators, corrective-action recommendations with the 30-day deadline where applicable, the auditor(s) of record and visit dates, and the template version and checksum the assessment was scored against. The report is delivered alongside the certificate and retained in the company's dashboard for the life of the tenant relationship.
Suppliers and the Extended Enterprise
Consistent with ISO 20400, an organization's rating reflects its supply-chain stewardship, not only its own four walls. Subject G4 specifically scores the maturity of sustainable procurement — policy, a supplier code of conduct, risk-based supplier segmentation, actual supplier assessment practice, and corrective-action follow-up — and companies may be asked, from Level 2 onward, for anonymized evidence of how they evaluate their own suppliers.
One boundary is firm: Standard ESG does not certify a company's suppliers through that company's certificate. If a supplier wants its own certification, it registers and is assessed independently. A certificate always describes the entity that earned it.
Certificates and Public Verification
A Standard ESG certificate is a PDF generated from a system template, with a distinct visual identity per level. It states the company's legal name, industry, certification level, 1–10 score, issue date, expiry date, a unique certificate ID, a QR code, and the template version and checksum the assessment was scored against. Any accompanying report — such as the Level 3 Findings & Recommendations Report — carries that same version and checksum, so certificate and report are always traceable to the identical assessment content.
Scanning the QR code opens a public verification page on standardesg.org. That page shows a strictly limited set of fields and nothing more: validity status (active, expired, or revoked), the score, the level, the company name, and the issue and expiry dates. No other assessment data — no indicator answers, no documents, no on-site findings — is ever public. This gives anyone checking a certificate a fast, trustworthy answer without exposing the company's confidential submission.
Certificates are valid for 12 months from issue. Expiry is automatic and immediately reflected as "Expired" on the verification page — no certificate silently outlives its truth. Standard ESG admins may also revoke a certificate at any time for cause: fraud, a gate violation discovered after issuance, or misuse of the badge or marks. Revocation is immediate and equally visible on the public page. Certificates are retained in the company's dashboard for the lifetime of the tenant relationship.
Governing the Scheme: Impartiality, Competence, Appeals
A certification scheme is only as trustworthy as the process that runs it, so the protocol governs itself on three fronts.
Impartiality: reviewers and auditors must declare conflicts of interest and may not assess companies where a conflict exists. Partner auditors operate under a signed agreement binding them to the protocol.
Auditor competence: Level 3 auditors must complete documented training on the protocol itself, plus demonstrate familiarity with ISO 20400, SA8000 auditing practice, and health-and-safety inspection basics. Training records are kept centrally.
Appeals and complaints: a company may appeal a rejection, a score, or a revocation within 30 days of the decision. Appeals are reviewed by a Standard ESG staff member who was not involved in the original decision — a structural separation, not just a policy statement. Third parties can also file complaints about a certified company through the public site; a substantiated complaint can trigger re-assessment or revocation. This means a certificate is not a one-time stamp that becomes unreviewable the moment it's issued — it remains answerable to ongoing scrutiny.
Data Protection and Tenant Isolation
All assessment data, uploaded documents, and on-site findings are confidential to the submitting company and to Standard ESG — full stop. That confidentiality is enforced at the system level through application-level tenant isolation: every document carries a tenant identifier, and every read or write is scoped to the caller's own tenant in the data-access layer, never relying on separate databases per customer as the only safeguard. Role separation reinforces this — Company Admin, Company User, Standard ESG Admin, Auditor, and Partner Auditor each see only what their role requires. As stated in the certificates and public verification section above, only the limited verification-page fields are ever public; everything else stays inside the tenant boundary.
Keeping the Protocol Honest Over Time
The protocol itself, and every template built under it, is versioned. Templates are additionally content-hashed at lock time, so any certificate or report generated from an assessment can be traced back to an exact, immutable snapshot of the criteria used — no retroactive rewriting of what a score meant. When the protocol changes materially, the change applies to new assessments only; assessments already in flight complete under the version they were bound to when they started. This is what lets a five-year-old certificate and a five-day-old certificate both be read with confidence about exactly what they represent.
Where to Go Next
This overview describes the whole architecture at a summary level. For a closer look at specific parts of it:
- The Three Certification Levels Explained — a deeper, practical walkthrough of choosing and preparing for Level 1, 2, or 3.
- How the Standard ESG 1–10 Score Works — worked numeric examples of the scoring pipeline from indicator to composite.
- Verify a Certificate — how to read a certificate, use the QR verification page, and confirm a template hash.
- What is ESG? A Complete Introduction — the broader context of ESG as a concept, for readers arriving without prior background.
Standard ESG (standardesg.org) operates the certification protocol described here — an ISO 20400-compatible methodology with three verification levels, a public 1–10 score, and public certificate verification. Registration begins with a Level 1 self-assessment.
Cette page vous a-t-elle été utile ?