77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide
Materiality analysis according to ESRS: template, methodology and auditor's perspective
Environmental Protection

Materiality analysis according to ESRS: template, methodology and auditor's perspective

2 September 202613 min readBy Stefan Möller
CIVAC

The dual materiality analysis decides which ESRS data points you need to report. We provide an auditor-proof template and show how the CIVAC workspace maps stakeholder dialogue, threshold values ​​and release loops in an audit-proof manner.

The double materiality analysis according to ESRS 1 Chapter 3, in the version of Delegated Regulation (EU) 2023/2772 of July 31, 2023, is the methodological foundation of all CSRD reporting. It determines which of the more than 1,000 ESRS data points are subject to reporting and thus decides on the scope of the management report and the audit activity.

This article provides a developed template logic, explains the requirements of the EFRAG Implementation Guidance IG 1 from May 2024, describes typical auditor questions and shows how the CIVAC workspace stakeholder dialogue, evaluation matrices and release loops are audit-proof depicts. You will find out which six building blocks an auditor-proof materiality analysis needs and why the written derivation decides whether the audit report passes or fails.

Key Takeaways

  • The double materiality combines impact materiality (external impact) with financial materiality (internal impact) and must derive both perspectives in a documented manner.
  • EFRAG Implementation Guidance IG 1 requires stakeholder surveys, defined thresholds and comprehensible assessments, not a pure self-assessment by the board.
  • The CIVAC workspace maps the analysis in an evaluation matrix, stakeholder protocol and release loop. Audit proof, documented, ESRS proof.

What distinguishes double materiality from classic materiality

Classic financial materiality according to IAS 1 assesses whether information influences the decision of users of the financial statements. She looks from the outside in. The double materiality of CSRD complements this view with impact materiality, i.e. the impact of the company on people and the environment. It looks from the inside out.

A topic is considered material if either the impact side or the financial side exceeds the threshold. Both sides have equal rights, both sides must be examined. ESRS 1 Chapter 3 (Double Materiality) defines the minimum standards, the Implementation Guidance IG 1 from May 2024 specifies the methodology.

In practice, this means a double burden of collection. For each of the ten topic standards (ESRS E1 to E5 Environmental, ESRS S1 to S4 Social, ESRS G1 Governance) check both perspectives. The cut creates the list of reportable data points. This list is the ticket to the management report.

Anyone who draws the analysis too narrowly risks taking stock without substance. If you are too broad, you will produce a report that no one reads. EFRAG recommends a risk-based approach that explicitly includes the supply chain and downstream value creation.

The materiality analysis is formally anchored via the role of the ESG sustainability officer. The appointment certificate should explicitly refer to ESRS 1 and stipulate responsibility for the analysis.

In this way, the methodological discipline of CSRD is institutionalized from the start.

The six building blocks of an auditor-proof template

A reliable materiality analysis needs six building blocks. Firstly, the business model mapping with value creation steps, products, markets and supply chain. Secondly, the stakeholder catalogue with internal and external grouping. Third, the list of topics related to ESRS. Fourth, the evaluation matrix with threshold values. Fifth, the stakeholder survey with minutes. Sixth, approval by management with date and signature.

The business model mapping is the basis. Without a clear view of your own activities and supplier structure, you can neither assess impact nor risk. EFRAG explicitly requires that the value chain be made visible upstream and downstream (ESRS 1 Chapter 5).

The stakeholder catalogue covers at least five groups: employees, customers, suppliers, affected communities, investors or lenders. Authorities and civil society can also be added. Each group receives communication formats, such as surveys, workshops or advisory boards.

The list of topics follows the ESRS structure. Climate change (E1), pollution (E2), water (E3), biodiversity (E4), resource use (E5), own workforce (S1), value chain employees (S2), affected communities (S3), consumers (S4), corporate governance (G1). This results in company-specific subtopics.

The evaluation matrix combines the dimensions of severity, scope, irreversibility and probability for impact. For Financial, the dimensions height and probability. Threshold values ​​should be anchored quantitatively, such as euro amounts or a scale of 1 to 5.

CIVAC provides the template with all six building blocks. The appointment certificate, signed, filed, verifiable.

Stakeholder dialogue: methods and minimum requirements

Without proven stakeholder dialogue, the materiality analysis is formally vulnerable. EFRAG IG 1 recommends a combination of quantitative surveys, qualitative interviews and workshops. The selection of stakeholders must be justified and representativeness verifiable.

In practice, online surveys with Likert scales for breadth and in-depth interviews with 5 to 10 key people per group for substance are proven. Workshops with mixed groups create cross-references. A minimum participation of 50 stakeholders is seen as a lower limit in auditor practice.

It is important to separate information and evaluation. Stakeholders evaluate materiality from their perspective, and the company aggregates and weights it. A pure board assessment with subsequent stakeholder survey as confirmation is recognised as pseudo-dialogue.

The documentation must include: selection logic of the stakeholders, survey instruments, raw data, evaluation, aggregation, derivation of the materiality assessment. Without this chain, the auditor will document a significant weak point.

A sensible link is created via the supply chain representative. LkSG also requires stakeholder involvement in risk analysis. An integrated survey saves effort and avoids contradictory statements to suppliers.

CIVAC supports the dialogue with templates for surveys, interview guides and workshop designs. The logging takes place in the workspace with a time stamp, participant list and versioning. The auditor calls, the evidence is ready.

Evaluation matrix and thresholds

The evaluation matrix is ​​the core of the analysis. This is where it is decided which topics are essential and which are not. A clean matrix uses four dimensions for the impact side and two for the financial side. The aggregation takes place via multiplication or additive models.

For Impact Materiality, ESRS 1 defines the dimensions Severity, Scale, Irreversibility and Likelihood. In the case of actual negative effects, the probability is eliminated because the effect has already occurred. It is included if there are potential impacts.

For financial materiality, ESRS 1 defines the dimensions height (magnitude) and probability (likelihood). The amount refers to financial effects, such as a decline in sales, an increase in costs, asset impairment or changes in the cost of capital. The probability is to be understood as the risk of occurrence over the reporting horizon.

Threshold values ​​must be determined company-specifically. Quantitative triggers are common, around 1 percent of total assets or 5 percent of EBITDA for Financial. Scale models from 1 (low) to 5 (very high) with definition of each level are suitable for impact. Anyone who only defines threshold values ​​after the evaluation becomes vulnerable.

The evaluation itself should be carried out by several people. A purely individual opinion is susceptible to distortion. CIVAC recommends a four-eye principle with the specialist department and management, documented in the workspace.

The results are visualized in a materiality matrix that maps both dimensions on two axes. Topics above the threshold are subject to the reporting requirement, the others are rejected for reasons.

Topic-specific depth: How far does the analysis have to go?

Materiality is checked on two levels. Firstly at the topic level (E1 to G1), secondly at the sub-topic or sub-subtopic level. ESRS 1 Appendix A provides a list of topics and subtopics to provide guidance. The list is not exhaustive, your own topics can be added.

An example: If E1 (climate change) is essential, check climate protection (mitigation), adaptation to climate change (adaptation) and energy at the sub-topic level. At the sub-subtopic level, you make further distinctions, such as Scope 1-2-3 emissions or specific adaptation measures.

The depth determines the scope of the report. An analysis that is too coarse leads to incomplete data points, and an analysis that is too fine leads to survey bureaucracy. EFRAG recommends a pragmatic depth that reflects operational relevance.

The connection to the company's risk management logic is important. Topics that arise in enterprise risk management should be reflected in financial materiality. Discrepancies indicate gaps and are addressed by the auditor.

A second bridge is created via the Compliance Officer Role. G1 (management) covers topics such as bribery, corruption and whistleblowing, which are traditionally anchored in the compliance program. Duplicate data storage should be avoided.

CIVAC maps the topic structure in the workspace with drill-down logic. Topic, sub-topic and sub-sub-topic are linked and linked to data points. Die Versionierung erlaubt jährliche Aktualisierung ohne Verlust der Historie. Others run compliance like a filing cabinet. We run it like software.

Common mistakes and how to avoid them

The five most common weaknesses in medium-sized businesses projects are, firstly, the lack of writing down the derivation. A matrix without a description of the methodology is worthless. The auditor needs the path from the list of topics via the assessment to the derivation of the data points.

Secondly, insufficient stakeholder dialogue. Three phone calls with the major customer are not a dialogue. At least 50 documented stakeholder interactions with representation of all key groups form the lower limit.

Third, missing threshold values. A scale of 1 to 5 without a definition is subjective. Thresholds must be anchored quantitatively, such as specific euro amounts or specific quantities.

Fourth, insufficient connection to risk management. If ESG issues do not appear in ERM, materiality remains isolated. Integration into existing processes (internal audit, compliance, controlling) is mandatory.

Fifth, missing update. Materiality is not static. EFRAG requires an annual review and a complete new edition at least every three years. Without an update mechanism, the analysis becomes outdated.

The same pattern emerges regarding the EU AI Act obligations: Anyone who does not check the group of obligations regularly will find themselves in compliance trouble. CIVAC addresses both topics with the same control principles: responsibility, cycle, escalation, documentation. Deadline expires as soon as we become aware of it.

Interface to LkSG, taxonomy and CSDDD

The materiality analysis does not stand alone. It is linked to three other sets of rules. Firstly, the Supply Chain Due Diligence Act, which requires risk analyses along the supply chain (Section 5 LkSG). Secondly, the EU taxonomy, which defines reportable metrics on ecologically sustainable activities. Thirdly, the Corporate Sustainability Due Diligence Directive (CSDDD), which will gradually come into effect from 2027.

The LkSG risk analysis addresses eight human rights risks plus two environmental risks. These overlap with the ESRS subtopics in S1, S2, E2 and E5. An integrated survey avoids duplication of effort and contradictory statements.

The EU taxonomy according to Regulation 2020/852/EU requires sales, CapEx and OpEx shares that are classified as taxonomy-compliant. The underlying technical assessment (Technical Screening Criteria) is closely linked to E1 and E5 data points.

The CSDDD tightens due diligence requirements and creates civil liability. German implementation is pending; Directive 2024/1760/EU has been in force since July 25, 2024. Early preparation is worthwhile because the materiality analysis serves as the starting point for risk identification.

CIVAC maps the four sets of rules integrated in the workspace. Data points are linked so that one survey serves multiple reporting requirements. The CIVAC FAQ answers the interface questions in detail.

This turns four sets of rules into a single data model that is audit-proof and revision-proof.

Auditor's view: What the auditors test

Auditors check the materiality analysis in three steps. Firstly, the methodological approach: Is the methodology written, does it conform to the Implementation Guidance IG 1, is it adapted to the company? Secondly, the implementation: Was the methodology actually used, are all steps documented, and are the stakeholders involved? Thirdly, the results: Are the conclusions plausible, are the derived data points consistent, is the list complete?

In the 2024 financial year (wave 1), Limited Assurance is sufficient, from 2028 Reasonable Assurance is expected. Limited Assurance checks for major errors, Reasonable Assurance requires active verification. The requirements for documentation increase accordingly.

Typical auditor questions are: Which stakeholders were surveyed and how was the selection justified? Which threshold values ​​apply and how are they derived? Which topics were excluded and why? What is the connection to Enterprise Risk Management? How is the update controlled?

All responses must be documented in the workspace. A PowerPoint slide is not enough. An Excel table without versioning is not enough. A written methodology description with attachments, protocols and approvals is standard.

You can see the link between ESG officers, compliance officers, data protection officers and supply chain officers via the Role overview. All four contribute to the materiality analysis, all four use the same workspace.

Audit-proof, documented, § 289b HGB-proof. In this way, the audit report becomes a formal confirmation, not a risk.

Use template, order officer, licence workspace

The template alone does not solve the problem. It is the map, not the terrain. In order for the materiality analysis to be created as an auditor-proof document, the discipline of execution, the writing of the derivation and the formal approval by the management are required.

CIVAC combines both: compliance platform and officer-as-a-service. The workspace provides 490 audit templates, including the full materiality analysis with stakeholder survey, evaluation matrix and approval loop. The EU data residency and the ISO/IEC 27001:2022 certified ISMS ensure confidentiality and integrity.

Licence the workspace for your internal representatives or have our representatives appointed. The officer-as-a-service model relieves the burden on the internal organisation by having an appointed ESG officer moderate the analysis, with an SLA of 2 working days instead of 2 to 6 weeks.

The time window remains tight for CSRD wave 2 (fiscal year 2025). The materiality analysis should be carried out before the end of 2025 so that the subsequent data collection generates comparative data. Anyone who starts in January 2026 will not have a year-on-year comparison.

The 25 representative roles that CIVAC displays in the workspace combine ESG responsibility with data protection, compliance, supply chain and IT security. This avoids duplicate work and inconsistency. The appointment certificate, signed, filed, verifiable.

Turn reading into a mandate. Write to info@civac.de or use the contact form on civac.de. We will set up the workspace within 2 working days and discuss which model is right for your size and level of maturity.

FAQ

Do we have to carry out double materiality every year?

An annual inspection is mandatory. EFRAG recommends a complete new edition at least every three years or in the event of significant changes to the business model. CIVAC controls the update frequency differently for each topic standard and automatically reminds you of the next exam.

How many stakeholders do we need to interview?

ESRS 1 does not give a specific number. The auditor's practice sees 50 documented stakeholder interactions as the lower limit, with representation of all key groups. Online surveys, interviews and workshops can be combined, each recorded and versioned.

Can we exclude topics that obviously don't concern us?

Yes, but every exclusion must be justified. The justification follows the methodology with threshold values ​​and stakeholder assessment. A blanket exclusion from E4 (biodiversity) for a service company is possible, but must be clearly documented.

How do we combine the materiality analysis with existing risk management?

The financial materiality assessment should mirror the ERM risk register. If ESG issues do not appear there, the connection must be made. CIVAC maps the link between risk IDs and ESRS topics in the workspace, with common escalation logic.

What thresholds are common in the industry?

For financial materiality, 1 percent of total assets or 5 percent of EBITDA are suitable. Scales from 1 to 5 with defined levels are used for Impact Materiality. Industry standards are just emerging; company-specific derivations with documented reasons currently apply.

Does CIVAC carry out the materiality analysis completely?

Yes, in the officer-as-a-service model, an appointed ESG officer moderates the entire analysis, from the methodology to the stakeholder dialogue to approval. In the licence model, the workspace provides the templates and the internal organisation carries out the work. Both paths result in audit-proof documentation.

No obligation

Sounds like a lot of work?

Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.

Turn this into a mandate.

Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.

Related articles