金管會2025年開始要求上市櫃公司依GRI準則做ESG報告書,可能大家對GRI 還不是很熟悉,因此各式各樣的呈現方式都有。
GRI準則中比較需要留意的是GRI 3 有關重大主題揭露這一部份。台灣證交所每年會抽查 ESG 報告書,常見的缺失項目之一就是「重大主題的揭露不完整」。許多企業在索引表中標註 3-3,但點進內文卻發現只是舊內容的拼湊,沒有對應到 2021 版要求的「管理流程」。
當證交所發現這類缺失時,通常不會立即開罰(除非是完全未編製),但會採取以下行動:發函要求補正: 要求企業在「公開資訊觀測站」補充說明,或在下一年度報告書中限期改善。納入公司治理評鑑扣分: 在「公司治理評鑑」中有關於永續資訊揭露質量的評分指標,若 GRI 揭露不完整,該項分數會被扣除。
GRI條文中的揭露項目 3-3 重大主題管理的原文是:
對於每個根據揭露項目3-2報導之重大主題,組織應:要求
a. 描述對於經濟、環境和人群(包含其人權)的實際與潛在的、負面與正面的衝擊;
b. 報導組織活動或其商業關係是否涉及負面衝擊,並描述該活動或商業關係;
c. 描述組織與重大主題相關的政策或承諾;描述管理重大主題以及相關衝擊所採取之行動,包括:
i. 預防或減緩潛在負面衝擊之行動;
ii. 處理實際負面衝擊之行動,包含提供或以合作方式進行補救;
iii. 管理實際與潛在正面衝擊之行動;
d.報導下列關於追蹤所採取之行動有效性的資訊:
i. 用以追蹤行動有效性之流程;
ii. 用以評估流程的目標、標的與指標;
iii. 行動之有效性,包含向目標與標的邁進的流程;
iv. 汲取的經驗,以及如何將這些經驗納入組織的營運政策和程序中;
e. 報導下列關於追蹤所採取之行動有效性的資訊:
i. 用以追蹤行動有效性之流程;
ii. 用以評估流程的目標、標的與指標;
iii. 行動之有效性,包含向目標與標的邁進的流程;
iv. 汲取的經驗,以及如何將這些經驗納入組織的營運政策和程序中;
f.描述與利害關係人的議合如何影響採取之行動(3-3-d),以及如何說明行動是否有效(3-3-
e)。
為什麼說GRI 3 有關重大主題揭露這一部份最需要留意?因為會做完整報導的公司不多,多數會做重大主題揭露、列表,好一點的會有管理行動、目標等,但是對於上面GRI 3-3的d、e、f這些點,看到有公司報導的機率就很低。
也就是說你鑑別出重大主題,有採取行動、有目標了,你還需要追蹤你所採取之行動是不是有效性的;還需要揭露你從這些過程吸收了什麽經驗,以及如何將這些經驗納入組織的營運政策和程序中;另外這些行動可能影響了到利害關係人,你要去跟利害關係人做議合,之後要報導這些議合如何影響採取之行動。
ESG報告書應該是有連續性的,不會說今年報導的重大主題,明年全部換了題目,既然去年處理實際負面衝擊採取了一些行動,這些行動是不是有效,是不是向目標與標的邁進了?這些追蹤就納入明年的報告書內報導;ESG報告書如果每年都要做,它最好是要跟公司管理綁在一起的,這應該是是GRI 3設計的用意。
你可能説這也太複雜了,沒做到有什麼關係?有時可能就會碰到:各大驗證機構(如 DNV、SGS)在執行 AA1000 Assurance Standard(AA1000AS)或 ISAE 3000(International Standard on Assurance Engagements 3000)驗證時,會嚴格審核組織是否符合 GRI 1 的 9 項要求(見GRI 1: Foundation 2021),特別是 GRI 3 的完整性。這包括評估報告的原則遵守(AA1000 強調包容性、重大性、回應性與影響;ISAE 3000 聚焦證據蒐集與程序公正)。若發現 GRI 3-3 缺失,機構通常會:
要求更正:建議組織補充缺失資訊、強化管理流程(如進行盡職調查 due diligence),以確保符合 GRI 的重大議題管理要求。解釋與改進:在驗證報告中註明缺失,並要求組織提供詳細解釋(如為何遺漏、未來改善計劃)。這有助維持報告的透明度與可信度。
當要符合的規範愈來愈多時,人的時間是有限的,建議企業可建置一些AI工作流,例如GRI工作流式,把 GRI 1/2/3, 200/300/400條文都建置在裡面了,它有Excel 檔案提醒你要輸入那些資料,就會產生相對應的合規內容來放入ESG報告書,這樣遺漏的機會就降低了。
ISAE 3000(全稱 International Standard on Assurance Engagements 3000 (Revised),國際確信業務準則第3000號(修訂版))是由 IAASB(國際審計與確信準則理事會,International Auditing and Assurance Standards Board)發佈的國際標準,主要適用於非歷史性財務資訊的確信(assurance)案件。這包括 ESG 報告、永續報告書、溫室氣體排放聲明、資訊安全、GDPR 合規、內部控制等非財務領域的第三方確信。
AA1000 是由英國非營利組織 AccountAbility(責任機構)開發的一系列永續性與問責標準(AA1000 Series of Standards),最早於1999年推出AA1000 Framework,之後逐步演進成模組化標準系列。
Starting from 2025, the Financial Supervisory Commission (FSC) requires all listed and OTC companies in Taiwan to prepare ESG sustainability reports in accordance with the GRI Standards. Since many people are still unfamiliar with GRI, reports are presented in various formats. One particularly important part of the GRI Standards to pay attention to is **GRI 3: Material Topics 2021**, especially the section on disclosures for material topics. The Taiwan Stock Exchange (TWSE) conducts annual spot checks on ESG reports, and one of the most common deficiencies is **"incomplete disclosure of material topics"**. Many companies mark "3-3" in their content index, but when you click into the text, it's often just patched-together old content that doesn't correspond to the "management approach" requirements of the 2021 version. When the TWSE identifies such deficiencies, it usually does not impose immediate fines (unless the report is completely missing). Instead, it takes the following actions: - **Issues a letter requiring supplementation**: The company is asked to provide supplementary explanations on the Market Observation Post System (MOPS), or to make improvements by a deadline in the next year's report. - **Deducts points in the corporate governance evaluation**: The corporate governance evaluation includes scoring indicators related to the quality of sustainability information disclosure. Incomplete GRI disclosures will result in deductions for that item. The original text of Disclosure 3-3 "Management of material topics" in the GRI Standards is as follows: For each material topic reported under Disclosure 3-2, the organization shall: a. describe the actual and potential, negative and positive impacts on the economy, environment, and people (including their human rights); b. report whether the organization's activities or business relationships are involved with negative impacts, and describe those activities or business relationships; c. describe its policies or commitments related to the material topic; describe the actions taken to manage the material topic and related impacts, including: i. actions to prevent or mitigate potential negative impacts; ii. actions to address actual negative impacts, including providing for or cooperating in remediation; iii. actions to manage actual and potential positive impacts; d. report the following information about tracking the effectiveness of the actions taken: i. processes used to track the effectiveness of the actions; ii. targets, goals, and indicators used to evaluate progress; iii. the effectiveness of the actions, including progress toward the targets and goals; iv. lessons learned and how these lessons have been incorporated into the organization's policies and procedures; e. report the following information about tracking the effectiveness of the actions taken: *(Note: This appears to be a duplication in the provided text; the official standard combines tracking under one point, but the intent is the same as d – processes, targets/indicators, effectiveness/progress, lessons learned, and integration into policies/procedures.)* f. describe how stakeholder engagement has influenced the actions taken (see 3-3-d), and how it informs the organization about the effectiveness of its actions (see 3-3-e). Why is the material topics disclosure section in GRI 3 the one that needs the most attention? Because very few companies provide complete reporting. Most companies disclose material topics, list them out, and better ones include management actions and targets. However, the probability of seeing companies report on points d, e, and f above is very low. In other words, after identifying material topics and taking actions with targets, you still need to track whether those actions are effective; disclose what lessons have been learned from the process and how those lessons have been incorporated into the organization's operational policies and procedures; additionally, if those actions affect stakeholders, you need to engage with them and then report how that engagement influenced the actions taken. ESG reports should be continuous — you can't have completely different material topics every year. If actions were taken last year to address actual negative impacts, report whether those actions were effective, whether progress was made toward targets and goals — include that tracking in next year's report. Since ESG reports must be prepared annually, it's best if they are tied to the company's actual management systems. This is the intended design of GRI 3. You might say this is too complicated — what happens if it's not done? Sometimes you run into issues when major assurance providers (such as DNV, SGS) perform assurance under **AA1000 Assurance Standard (AA1000AS)** or **ISAE 3000 (International Standard on Assurance Engagements 3000)**. They strictly review whether the organization complies with the 9 requirements in GRI 1: Foundation 2021, particularly the completeness of GRI 3. This includes assessing adherence to reporting principles (AA1000 emphasizes inclusivity, materiality, responsiveness, and impact; ISAE 3000 focuses on evidence collection and procedural fairness). If GRI 3-3 deficiencies are found, the firm typically: - **Requires corrections**: Recommends that the organization supplement missing information and strengthen management processes (e.g., conduct due diligence) to ensure compliance with GRI's material topic management requirements. - **Notes explanations and improvements**: Documents the deficiencies in the assurance report and requires the organization to provide detailed explanations (e.g., why omitted, future improvement plans). This helps maintain the transparency and credibility of the report. As more regulations need to be complied with and human time is limited, companies are advised to build AI workflows — for example, a GRI workflow that incorporates GRI 1/2/3 and the 200/300/400 series standards. It can include Excel files to remind you what data to input, then automatically generate corresponding compliant content for the ESG report, reducing the chance of omissions. **ISAE 3000** (full name: International Standard on Assurance Engagements 3000 (Revised), International Standard on Assurance Engagements No. 3000 (Revised)) is an international standard issued by the IAASB (International Auditing and Assurance Standards Board). It primarily applies to assurance engagements on non-historical financial information. This includes ESG reports, sustainability reports, greenhouse gas emissions statements, information security, GDPR compliance, internal controls, and other non-financial areas requiring third-party assurance. **AA1000** is a series of sustainability and accountability standards developed by the UK non-profit organization AccountAbility (AccountAbility). It began with the AA1000 Framework in 1999 and has since evolved into a modular series of standards.
留言
張貼留言