Overview
Anyone new to ESG quickly runs into a wall of acronyms — ISO 14001, GRI, ISSB, ESRS, SA8000, the International Integrated Reporting Framework — with little explanation of how they relate to one another, or whether they're competing or complementary. They're mostly complementary, each covering a different layer of the same underlying problem. This guide is the map.
Two Different Kinds of Standard
The confusion around ESG standards mostly dissolves once you separate them into two categories that answer two different questions:
- Conduct and management-system standards answer "how should we operate?" — they describe practices, processes, and controls an organization should have in place.
- Reporting and disclosure standards (and the laws increasingly built on them) answer "what should we tell people, and how?" — they describe what gets communicated externally, in what format, and against what materiality principle.
- An organization typically needs both: sound underlying practices (the first category) and honest, structured reporting of those practices (the second). A company can score well on disclosure format while having weak underlying practices, or vice versa — which is exactly why a serious assessment protocol checks both.
Conduct & Management-System Standards
- ISO 26000:2010 — guidance on social responsibility. Not certifiable itself, but foundational: it defines the seven core subjects (organizational governance, human rights, labour practices, the environment, fair operating practices, consumer issues, community involvement and development) that echo through nearly every other standard in this landscape, including Standard ESG's own pillar structure.
- ISO 20400:2017 — sustainable procurement guidance. Applies ISO 26000's core subjects specifically to purchasing and supply-chain decisions.
- ISO 14001:2015 — environmental management systems. The Plan-Do-Check-Act framework for managing environmental impact.
- ISO 45001:2018 — occupational health and safety management systems. The same PDCA logic applied to worker safety.
- SA8000:2014 — social accountability, covering child labour, forced labour, health and safety, freedom of association, discrimination, disciplinary practices, working hours, remuneration, and management system. Built for third-party auditable verification specifically.
Reporting & Disclosure Standards
- GRI Standards — the world's most widely used sustainability-reporting standards, organized as universal standards (foundation, general disclosures, management approach) plus topic-specific series covering economic, environmental, and social impacts. GRI reports impacts — how the organization affects the economy, environment, and society.
- The International Integrated Reporting Framework (now stewarded by the IFRS Foundation) — asks a related but different question: how does the organization create, preserve, or erode value over time across six capitals (financial, manufactured, intellectual, human, social and relationship, natural)? Where GRI centers impact, this framework centers value creation and board-level strategic narrative.
The Disclosure Regulation Layer
A third layer sits above the voluntary standards above: binding law requiring specific disclosures, increasingly built on or aligned with the ISSB baseline.
- ISSB (IFRS S1 & S2) — the International Sustainability Standards Board's global baseline, centered on financial materiality (information that could reasonably affect an investor's decisions). Adopted or signalled by 30+ jurisdictions.
- CSRD/ESRS (EU) — the Corporate Sustainability Reporting Directive and its European Sustainability Reporting Standards, centered on double materiality (both financial and impact materiality), covering roughly 50,000 companies.
- SEC climate rule (US, contested) — historically anchored in single materiality, narrower in scope than CSRD, and subject to significant legal and political uncertainty at the federal level.
- California SB 253/261 — state-level law requiring large companies to disclose full Scope 3 emissions and climate-related financial risk, filling much of the vacuum left by federal uncertainty in the US.
- See The Global ESG Disclosure Regulation Guide for the detailed jurisdiction-by-jurisdiction comparison, including the newer, narrower ESG-ratings-provider regulatory track (EU Regulation 2024/3005, UK FCA CP25/34) that sits alongside these broader disclosure regimes.
How These Layers Actually Interlock
The layers aren't competitors — they're designed, imperfectly, to build on one another. ISO 26000's seven core subjects supply the topic vocabulary that GRI's 200/300/400 series and ISSB/ESRS disclosure categories both largely echo. A company running a genuine ISO 14001 environmental management system naturally generates the monitoring data that a GRI 300-series environmental disclosure, or an ESRS climate disclosure, would require. SA8000's nine social-accountability elements map closely onto both GRI's 400 series and ISSB/ESRS social disclosure expectations. In practice, an organization that builds genuine conduct standards first finds the reporting-standard layer far easier to complete honestly, because the underlying data and practices already exist rather than needing to be manufactured for a report.
Quick Reference
- ISO 26000 (conduct guidance): what does responsible conduct cover? Applies to any organization.
- ISO 20400 (conduct guidance): how do we procure sustainably? Applies to procurement functions.
- ISO 14001 (management system): how do we manage environmental impact? Applies to any organization.
- ISO 45001 (management system): how do we manage worker safety? Applies to any organization.
- SA8000 (auditable social standard): are labour practices decent? Applies to any worksite.
- GRI (reporting standard): what impacts do we disclose? Applies to any organization.
- International Integrated Reporting Framework (reporting framework): how do we create value over time? Applies primarily to listed/large companies.
- ISSB / IFRS S1 & S2 (disclosure law/baseline): what sustainability information is financially material? Applies to companies in adopting jurisdictions.
- CSRD/ESRS (disclosure law, EU): what is both financially and societally material? Applies to roughly 50,000 EU-scope companies.
- California SB 253/261 (disclosure law, US state): what are our full emissions and climate risks? Applies to large companies operating in California.
How Standard ESG Synthesizes the Landscape
The Standard ESG Certification Protocol doesn't add a new, competing taxonomy to this already-crowded landscape — it's explicitly built as a synthesis of the standards above, mapped onto one ISO 20400-compatible assessment structure:
- ISO 20400: backbone of the assessment structure.
- ISO 26000: source of the seven core subjects organizing the criteria.
- ISO 14001: environmental pillar (subject E1).
- ISO 45001: social pillar, workplace safety (subject S2).
- SA8000: social pillar and Level 3 on-site labour framework (subject S1).
- GRI: disclosure structure and evidence expectations (subject G3).
- International Integrated Reporting Framework: governance pillar, value-creation narrative (subject G1).
- The result is fifteen core subjects across Environmental, Social, and Governance (E1–E5, S1–S5, G1–G5), each traceable back to a specific, recognized standard, scored through industry-specific templates and verified at up to three levels.
What Standard ESG Certification Is Not
One clarification is worth stating plainly, because the standards landscape invites confusion here: Standard ESG certification is not an ISO certification, and the protocol does not claim conformity assessment against any ISO standard. It is a proprietary methodology that is compatible with, and informed by, the standards described above — built so that evidence an organization already holds for genuine ISO 14001 or SA8000 practice translates directly into Standard ESG evidence, without requiring a separate, parallel compliance effort.
Where to Start If You're New to All of This
If this is your first time encountering the standards landscape:
- Read What is ESG? A Complete Introduction for the conceptual foundation.
- Identify which pillar (E/S/G) is most material to your organization, per Getting Started with ESG: A Practical Guide for SMEs.
- Read the primer for the specific standard closest to your most material topic — environmental management, health and safety, labour practices, procurement, reporting, or governance — rather than trying to absorb every standard at once.
- Consider a Level 1 self-assessment as a structured way to see, in one place, how your practices map across this entire landscape without having to read every underlying standard yourself.
- Standard ESG exists precisely to make this landscape actionable: one assessment, mapped to the standards above, producing one comparable 1–10 score.
Was this page useful?