All articles
ESRS G1business conductgovernanceCSRDanti-corruptionwhistleblowing

ESRS G1 Business Conduct: A Complete Guide to Governance Disclosures Under CSRD

The definitive guide to ESRS G1 — corporate culture, anti-corruption and bribery, whistleblowing, political engagement, supplier relationships, and payment practices. Learn what CSRD requires, where the data comes from, and how consultants price this work.

João Aguiam

João Aguiam

· 15 min read

ESRS G1 Business Conduct: A Complete Guide to Governance Disclosures Under CSRD

Ask any CSRD project lead which ESRS standard gets the least airtime and you'll almost always hear the same answer: ESRS G1 — Business Conduct. Climate (E1) dominates the boardroom conversation. Own workforce (S1) absorbs the HR team. Value chain (S2) triggers the most panic. G1 sits quietly at the end of the standard list, often assumed to be a rebadging of the existing Code of Conduct.

That assumption is wrong — and expensive. G1 is where auditors are finding the most disclosure gaps in early CSRD reports, where the legal function suddenly discovers it owns half the datapoints, and where consulting scope tends to explode once the double materiality assessment lands.

This guide walks through everything G1 actually requires, why it's harder than it looks, how the disclosures connect to work you're already doing under other regulations, and how experienced CSRD consultants approach this workstream.

What Is ESRS G1?

ESRS G1 is the single governance standard in the first set of European Sustainability Reporting Standards. While the environmental pillar has five standards (E1–E5) and the social pillar has four (S1–S4), the governance pillar has just one — but it covers a lot of ground.

G1 is officially titled "Business Conduct", which signals its scope: it's not about board composition or executive pay (those sit inside general disclosures under ESRS 2 and in financial reporting), but about how the company actually behaves in the market and in its relationships with the ecosystem around it.

The standard groups its requirements into six sub-topics:

  1. Corporate culture — the tone from the top and how ethical behaviour is embedded in the organisation
  2. Protection of whistleblowers — channels for raising concerns and how the company treats people who use them
  3. Animal welfare — where relevant to the business model (this is genuinely unusual for a governance standard)
  4. Political engagement and lobbying — including transparency on political contributions and representation of interests
  5. Management of relationships with suppliers, including payment practices — how the company treats the businesses it buys from
  6. Corruption and bribery — prevention, detection, incidents, and outcomes

Each sub-topic is mandatory to consider in your double materiality assessment, but only material sub-topics require full disclosure. In practice, corruption and bribery, whistleblowing, and payment practices are material for almost every company, which is where most first-time reporters focus.

Why G1 Is Not Just a Rebadged Code of Conduct

The single most common mistake in early G1 reporting is treating the standard as a documentation exercise: attach the existing Code of Conduct, list the training completion rate, and move on. That approach produces a report that fails on multiple counts.

G1 asks for evidence of how ethical behaviour is actually operationalised, not just what the policy says. That means:

  • How is the corporate culture defined, communicated, and reinforced through concrete practices (onboarding, performance reviews, leadership behaviour, escalation channels)?
  • How does the whistleblowing system actually protect people — including the specific measures against retaliation, the independence of the investigation process, and outcomes over the reporting period?
  • What is the prevention architecture for corruption and bribery — training rates by function and geography, third-party due diligence, high-risk role coverage, incident response protocols?
  • How does the company treat suppliers commercially — average payment terms, actual payment days, late payment rates, and specifically for SME suppliers?

None of this comes out of a single document. It requires pulling data from HR, legal, compliance, procurement, treasury, and often internal audit — many of which have never contributed to a sustainability report before.

The G1 Disclosures, in Detail

GOV-1 and IRO-1: Governance and Materiality Foundations

G1 inherits the governance disclosures from ESRS 2, which means your report needs to explain which body or role has oversight of business conduct matters and how they are informed. For most companies this is the audit and risk committee or a dedicated ethics/compliance committee.

You also need to explain how you assessed business conduct topics in your materiality assessment, including which internal and external inputs shaped the conclusions. Regulators, enforcement history, and stakeholder concerns are all valid inputs.

G1-1: Corporate Culture and Business Conduct Policies

This disclosure asks you to describe how you promote a culture of ethical business conduct, including:

  • The mechanisms for identifying and reporting concerns about unlawful behaviour or behaviour contradicting your Code of Conduct
  • How you assess and monitor the effectiveness of those mechanisms
  • Anti-corruption and anti-bribery policies aligned with the UN Convention against Corruption
  • Training coverage, including for at-risk functions

For most companies, the interesting work here is showing effectiveness — not just existence — of the policies. Audit teams routinely challenge companies that report "100% training completion" with no evidence of behaviour change, incident detection improvement, or updated risk assessment.

G1-2: Management of Relationships with Suppliers

This disclosure requires you to describe your approach to your supplier base, including:

  • How social and environmental criteria are integrated into supplier selection
  • Fair payment practices, especially towards small and medium enterprise suppliers
  • Whether you have policies to prevent late payments to SMEs

This connects strongly to G1-6 on payment practices below. Consultants working on this disclosure typically pull directly from procurement and accounts payable systems, and the results are often uncomfortable.

G1-3: Prevention and Detection of Corruption and Bribery

This is one of the most detailed disclosures in the whole ESRS set. You need to describe:

  • The procedures in place to prevent, detect, and address allegations of corruption and bribery
  • Whether investigators or an investigating committee are separate from the chain of management involved in the matter
  • How outcomes are reported to administrative, management, and supervisory bodies
  • The plans for training on anti-corruption, including target groups, frequency, and depth

The "separate from the chain of management" language matters. If your Head of Compliance reports to a functional leader whose team is being investigated, that's a structural weakness the disclosure will surface.

G1-4: Confirmed Incidents of Corruption or Bribery

A quantitative disclosure covering:

  • The number of confirmed incidents of corruption or bribery in the reporting period
  • The number resulting in convictions or fines
  • The amount of fines paid for violations of anti-corruption and anti-bribery laws
  • Actions taken to address breaches (contract terminations, dismissals, legal proceedings)
  • Details of any public legal cases brought against the undertaking or its employees

Reporting zero incidents is allowed and common — but it needs to be defensible. If you have a whistleblowing system that produced zero reports on corruption-related concerns and no internal investigation activity, auditors will ask why.

G1-5: Political Influence and Lobbying Activities

Companies must disclose:

  • Their approach to political engagement, including internal accountability
  • Total monetary value of financial and in-kind political contributions, broken down by country and recipient
  • Whether the company is registered in the EU Transparency Register or an equivalent US register
  • Lobbying activities and the main topics addressed

For many companies this is the disclosure that triggers the loudest debate — because political engagement data has historically lived in public affairs, has often not been quantified centrally, and is politically sensitive. Consultants regularly spend meaningful engagement time just designing the internal governance to collect these numbers.

G1-6: Payment Practices

The most concretely quantitative G1 disclosure. Companies must report:

  • The average time to pay an invoice, in days, from the date the contractual or statutory term of payment starts to be calculated
  • Whether standard payment terms are respected and, if not, the proportion of payments made outside those terms
  • The number of legal proceedings currently outstanding for late payments
  • Contextual information required to understand the data

This disclosure comes straight from the accounts payable ledger — which sounds simple until you realise that most large companies have multiple ERPs, inconsistent invoice date fields, and no historical view of payment terms by supplier segment. In many engagements, data collection for G1-6 alone becomes a several-week workstream.

Why G1 Is Materially Important for Almost Every Company

A pattern we see repeatedly across consultant engagements: companies enter the materiality assessment expecting G1 to be "not material" and come out with at least three material sub-topics.

The reason is the impact materiality lens in double materiality. Even if your company has never had a corruption incident, the sector, geographies, or supplier profile may create material corruption risk from an impact perspective. The same logic applies to whistleblowing (any large workforce) and payment practices (any company with SME suppliers).

The other factor is regulatory concentration risk. Business conduct topics are increasingly regulated in parallel with CSRD:

  • The EU Whistleblower Directive already requires internal reporting channels for companies with 50+ employees
  • The Corporate Sustainability Due Diligence Directive (CSDDD) overlays additional obligations on human rights and environmental due diligence, connecting with G1-2 on supplier management
  • The EU Late Payment Regulation revision tightens rules on payment terms, feeding directly into G1-6
  • National anti-bribery laws (UK Bribery Act, US FCPA, French Sapin II) create additional disclosure expectations

A consultant thinking about materiality holistically will treat these as reinforcing signals: if regulators consider a topic important enough to legislate, that's evidence of stakeholder salience under ESRS 1.

The Data Nobody Owns

G1's practical challenge is not the standard — it's the org chart. In a typical large company, the datapoints in G1 are spread across at least six functions:

G1 areaWhere the data actually lives
Corporate cultureHR, internal communications, leadership development
Whistleblowing channelCompliance, legal, internal audit, external hotline provider
Anti-corruption trainingCompliance, HR learning systems, function-specific training platforms
Corruption incidentsCompliance, legal, internal audit, external counsel
Political contributionsPublic affairs, government relations, corporate secretariat
LobbyingPublic affairs, trade association memberships, external agencies
Supplier managementProcurement, category management, ESG procurement
Payment practicesAccounts payable, treasury, finance shared services

None of these functions has historically produced a sustainability disclosure. Most have never seen an ESRS datapoint list. Almost none of them share a common data model or definition.

This is why G1 tends to be the workstream where a consultant's operating model expertise pays for itself. The consulting work is less about the standard and more about designing the data collection and governance — writing the definitions, building the reporting templates, standing up the cross-functional working group, and defining who is accountable for each datapoint on an ongoing basis.

How Consultants Typically Price G1 Work

G1 tends to show up in consulting proposals in three shapes:

  1. As part of a full CSRD readiness engagement, where G1 is one of several ESRS workstreams. Typically 5–10% of the overall proposal budget — but often the workstream that generates the most out-of-scope requests once data collection begins.

  2. As a standalone G1 module, sold separately when the compliance or legal function drives the CSRD project independently of the sustainability team. Common in financial services, regulated industries, and companies with a mature ethics and compliance function.

  3. As a data infrastructure sub-project, where the deliverable is a governance model, data collection template, and calculation methodology for the quantitative G1 datapoints — particularly G1-4 (incidents), G1-5 (political engagement) and G1-6 (payment practices).

Pricing depends heavily on company complexity. A single-entity SME with a mature Code of Conduct might address G1 in 40–60 consulting hours. A multinational with legacy acquisitions, decentralised procurement, and no consolidated compliance data can easily run to 400+ hours. See our breakdown of typical CSRD consulting costs for context on how these ranges compare across ESRS workstreams.

Common Pitfalls

Treating G1 as a legal review. Legal and compliance are essential partners, but G1 is a sustainability disclosure and needs to be produced under the ESRS narrative and quantitative structure. A legal team that copy-pastes a policy document will fail the assurance review.

Underestimating G1-6 payment practices. This is the disclosure most companies discover late. Extracting accurate average payment days from a fragmented ERP landscape is genuinely hard, and the resulting number is often uncomfortable enough that leadership wants to change the reporting boundary — which is not permitted once materiality has been set.

Reporting zero incidents without evidence of an active detection system. Auditors are trained to challenge zero-incident claims. If your whistleblowing hotline has generated zero reports over the year, that's a control weakness to explain, not a strength.

Treating political engagement as a US-only topic. ESRS G1-5 applies at group level. If your parent is European but you have public affairs activity anywhere in the world, that scope applies. This surprises non-EU parent companies especially — see our guidance on how CSRD applies to non-EU groups for the broader context.

Missing the connection to CSDDD. If your group is in scope for the CSDDD, the supplier management datapoints in G1-2 and G1-6 will need to align with the human rights due diligence you build for CSDDD. Doing these workstreams sequentially wastes budget; a consultant who understands both should be doing them in parallel.

How G1 Connects to the Rest of the Standard

G1 does not sit alone in the ESRS architecture:

  • ESRS 2 (General Disclosures) carries the governance and IRO disclosures that also apply to G1 — GOV-1, GOV-2, IRO-1
  • ESRS S1 and ESRS S2 overlap on whistleblowing (worker channels), grievance mechanisms, and corporate culture
  • ESRS E1–E5 connect through supplier management: procurement decisions affect environmental disclosures on climate, water, and pollution
  • EU Taxonomy minimum safeguards require adherence to anti-corruption and human rights standards that align closely with G1
  • CSRD assurance obligations apply to G1 quantitative disclosures the same way they apply to E1 emissions data

Companies that plan their reporting architecture around this map avoid duplicated data requests and inconsistent numbers across sections of the same annual report.

A Practical Checklist for G1

If you're building out your G1 workstream from scratch, this is the starting sequence we see work well:

  1. Confirm materiality of each G1 sub-topic — including animal welfare, which surprises companies in food, retail, cosmetics, pharma, and logistics
  2. Map existing artefacts — Code of Conduct, whistleblowing policy, anti-corruption manual, procurement policy, supplier code, political engagement policy
  3. Identify data owners for each quantitative datapoint — especially G1-4 (incidents), G1-5 (political contributions), G1-6 (payment practices)
  4. Design the payment practices measurement — this is the disclosure most likely to slip; agree on invoice date methodology, currency treatment, and SME segmentation early
  5. Assess the independence of the investigation process — G1-3 requires you to show separation between investigators and the management chain being investigated
  6. Stress-test the "zero incidents" claim — if you're reporting zero, produce the audit trail that shows the detection system works
  7. Align G1-2 with CSDDD — if you're in scope for both, run them as one programme, not two
  8. Bring in specialist support if needed — G1 is often where boutique compliance consultants add more value than generalist Big 4 CSRD teams, because the underlying subject matter (anti-corruption, whistleblowing, procurement compliance) is a distinct discipline

When to Get a Consultant Involved

The right time to bring in external CSRD expertise on G1 is usually before the materiality assessment, not after. The materiality decisions on G1 sub-topics shape the scope of the work — get them wrong and you either over-invest in immaterial topics or under-invest in disclosures that will fail assurance.

Look for consultants who can show:

  • Experience running the G1-6 payment practices measurement in a large ERP environment
  • A track record of designing cross-functional governance for compliance-adjacent data (not just ESG data)
  • Working knowledge of the CSDDD, EU Whistleblower Directive, and Late Payment Regulation — G1 does not live in isolation
  • Assurance experience specifically on G1 — the auditors have distinct expectations for governance disclosures

The CSRD Experts directory includes consultants and firms who list business conduct, compliance, and governance among their specialisations. Filter by expertise or location to shortlist a few options for a discovery call.

Final Thoughts

ESRS G1 is the standard most likely to be underestimated in year one — and the most likely to generate audit findings, restated numbers, and uncomfortable board conversations if it's rushed. The material is not conceptually difficult, but the data lives in six functions that have never worked together on a sustainability report.

The companies that handle G1 well treat it as an operating model project, not a documentation exercise. They start with the payment practices data because that's the hardest, they use the whistleblowing disclosure to genuinely stress-test their reporting culture, and they align political engagement disclosure with public affairs early enough for the leadership conversation to happen before the report is drafted.

Governance is where sustainability reporting stops being a marketing exercise and starts being an accountability system. Done properly, ESRS G1 is one of the parts of CSRD that actually improves the way the business is run — not just how it's described in the annual report.

Need Help with CSRD Compliance?

Browse our directory of vetted CSRD and sustainability consultants to find the right expert for your organisation.

Find CSRD Experts →

Join the CSRD Experts Directory

Get discovered by organizations seeking CSRD and sustainability expertise. Join a growing community of verified consultants.

🔍

Visibility

Get found by companies actively searching for CSRD consultants.

🤝

Networking

Connect with peers and discover collaboration opportunities.

📈

Lead Generation

Receive qualified inquiries from organizations that need your expertise.

Submit Your Profile →