Overview
You're probably in the middle of two parallel jobs right now. Compliance is asking for a defensible double materiality assessment, product teams are being pulled into ESG data requests, and someone has realized the same supplier file will need to support both the CSRD file and the product record. That's why this topic stopped being a reporting exercise and became a governance problem.
For brands selling into the EU, the practical question isn't whether double materiality matters. It's how to turn it into a repeatable evidence process that survives audit scrutiny and still feeds product-level compliance. The teams that do this well stop treating materiality as a once-a-year PDF and start using it as the backbone for disclosure, supplier follow-up, and product data governance.
Table of Contents
- Why Double Materiality Is Now a Board-Level Discipline
- Impact Materiality and Financial Materiality Explained
- Regulatory Drivers and Timelines You Cannot Ignore
- The Six Phases of a Defensible Assessment
- Scoring IROs With Scale, Scope, and Likelihood
- Operationalising Results in a Digital Product Passport
- Pitfalls That Get Assessments Rejected by Auditors
- First-90-Days Plan and Common Reader Questions
Why Double Materiality Is Now a Board-Level Discipline
A sustainability director at a mid-sized apparel brand doesn't get to run this work in isolation anymore. She's preparing the first CSRD submission, while the product manager is trying to map data points for the same collections, and both of them are being asked for evidence that can stand up later. The same supplier record may need to support a disclosure note, a risk decision, and a product passport field.

The regulatory shift is real. The CSRD entered into force on 5 January 2023, and EFRAG's guidance says companies must assess both impact materiality and financial materiality when deciding what to disclose, with the assessment acting as a gatekeeper for audited reporting under the first wave of in-scope large public-interest entities that started reporting for fiscal years beginning on or after 1 January 2024. That alone moves the work from a policy discussion into a board-relevant control process, because the output determines which ESG topics enter disclosure and which don't, and the assessment itself has to show documented scoring, evidence trails, and stakeholder input. All of that is set out in EFRAG's double materiality guidance.
The governance shift brands keep underestimating
In practice, this isn't just about writing a better sustainability narrative. It's about deciding which issues become part of audited reporting, which supplier requests are justified, and which product attributes need a traceable evidence chain before anyone publishes them.
A board can't approve what the team hasn't defined, and a product manager can't publish what the evidence file doesn't support. That's why mature teams now treat double materiality as a shared control between compliance, sustainability, product, legal, and procurement.
Practical rule: if a topic can change what you disclose, what you buy, or what you print on a product-facing record, it belongs in the same governance process.
The bigger implication is that materiality now reaches down into item-level governance. A brand that uses a digital product passport needs the assessment output to do more than sit in a PDF folder. It has to tell the team which claims are material, which need assurance-ready evidence, and which can be held back until the data is real.
Impact Materiality and Financial Materiality Explained
Think of the two lenses as two cameras filming the same scene from opposite sides. One looks outward at the company's effects on people, the environment, and the economy. The other looks inward at how sustainability issues affect cash flows, resilience, access to finance, and other financial outcomes.
Impact materiality is the inside-out view. Under EFRAG's framework, a topic is material if the company's activities create actual or potential impacts across the value chain that matter by their severity, reach, and whether harm can be repaired. Financial materiality is the outside-in view. A topic is material if it can influence enterprise value through risk, opportunity, or cost effects over the relevant time horizon.
The key point is the union. If a topic is material from either lens, it can be reportable under CSRD. That's where many teams get caught out, because they stop after the financial side and assume the disclosure scope is smaller than it is.
For a practical explainer that keeps the terminology simple, simplified ESG reporting guidance is a useful companion read for teams trying to align internal language before they move into the formal ESRS process.
One lens tells you what you cause, the other what can hit you
A supply-chain lead usually understands impact materiality first, because it maps to sourcing, manufacturing, use, and end-of-life effects. A finance lead usually understands financial materiality first, because it maps to how sustainability issues affect performance, risk, and opportunity.
The mistake is treating them as separate checklists. They're not. The CSRD model asks for a combined view, so a brand can't ignore a topic just because the financial effect looks small today, and it can't ignore a risk just because the impact story is harder to quantify.
A topic that matters on either side has to be tested, evidenced, and defended.
That's the most useful sentence to give a finance colleague. For a supply-chain lead, the equivalent is simpler. If a sourcing practice or product attribute affects people, land, water, or working conditions in a meaningful way, the assessment has to capture it even if the P&L impact isn't obvious yet.
Regulatory Drivers and Timelines You Cannot Ignore
Brands often still split CSRD, ESRS, and product rules into separate workstreams, but that separation fails in practice. The same supplier questions, the same evidence set, and the same control process have to serve reporting and product governance at once. For double materiality, that means the regulatory timeline is not just a disclosure calendar, it is a build schedule for the data architecture behind the assessment.

CSRD creates the reporting obligation, EFRAG formalises the assessment logic, and the ESPR and related product rules push brands toward item-level data structures. For apparel and consumer brands, that usually means the topics identified in the assessment eventually need to appear as product attributes, supply-chain evidence, or passport-linked records. Compliance, product, sourcing, and data teams have to plan together from the start, because the output is not just a report, it is a record that can be traced back through products and suppliers.
For an implementation overview on the product side, the internal briefing on EU digital product passport requirements, timelines and business obligations is a strong reference point for teams mapping readiness milestones.
How to read the calendar without overcomplicating it
The first question is scope. If you are in the first CSRD wave, the assessment has to be ready early enough to support audited disclosure, not assembled after data collection has already started. The second question is operational. If ESPR sector rules are turning topic-level obligations into product-level disclosures, the passport structure needs to be in place before commercial teams start publishing claims or supplier data fields.
The milestone logic is practical:
- Before scoping: confirm which business units, product lines, and legal entities sit inside the reporting perimeter.
- Before supplier outreach: define which data points are needed for disclosure and which are needed for product records.
- Before publication: make sure every product-facing claim has a source, a confidence state, and an approval trail.
Rather than forcing one regulation into another, the goal is to prevent disconnected systems that ask suppliers for the same evidence twice. That approach reduces delay, cuts inconsistency, and avoids rework. It also turns the assessment output into something closer to an audited evidence record than a once-a-year PDF.
The Six Phases of a Defensible Assessment
The strongest assessments look less like a workshop and more like a controlled project with clear outputs at each step. Advisory guidance from BCG shows the now-common pattern, starting with a shortlisting of ESG themes, then stakeholder mapping, then scoring tools and surveys, and finally a materiality assessment return report. That method is no longer optional theater. It's what makes the work repeatable and auditable.
For teams working through messy source packs, a tool that can extract tables and images from PDF can save time when you're turning legacy policy documents, supplier packs, and technical annexes into a clean shortlist register.
1. Build the topic shortlist
Start with EFRAG topics, sector standards, prior assessments, and existing risk registers. Don't go broad for the sake of breadth. The aim is to create a shortlist that is specific enough to test, but not so narrow that you miss relevant subtopics.
The output here is a controlled register of candidate topics and subtopics. If the shortlist is vague, the rest of the process will be vague too.
2. Map the stakeholders
Internal functions matter, but external groups matter just as much. Procurement, product, legal, sustainability, finance, and operations will all see different parts of the same issue. Suppliers, workers, customers, investors, and local communities often surface different failure points.
A good stakeholder map doesn't just name the groups. It shows why each group is in scope, what knowledge they hold, and whether their feedback changes the scoring logic.
3. Collect structured evidence
Surveys and interviews are useful, but they shouldn't stand alone. Mature programs pair stakeholder input with auditable indicators, controls, and source documents. That is what makes the assessment usable for limited assurance later.
Practical rule: if a workshop note can't be traced to a source document, don't treat it like final evidence.
4. Score and test the matrix
The team turns opinions into a documented decision. A preliminary matrix helps test whether topics are crossing the threshold where they become material. This step also reveals weak assumptions quickly, especially if the team has treated the shortlist too generically.
5. Challenge the threshold
The threshold is not a magic line. It's a governance choice that has to be explained. Strong teams test whether they've underweighted certain stakeholder groups, missed a subtopic, or over-relied on one business function's view of the issue.
6. Issue the return report
The final output needs to be usable by the reporting team, the product team, and the assurance provider. It should show the process, the evidence, the scoring logic, the final topics, and the approvals.
That's what “defensible” means in practice. Not pretty. Traceable.
Scoring IROs With Scale, Scope, and Likelihood
The scoring model under ESRS is more demanding than a simple red, amber, green matrix. For impact materiality, the relevant dimensions are scale, scope, and irremediable character. For financial materiality, the model adds likelihood and the financial effect across the short, medium, and long term. Deloitte and Normative both emphasize that teams should use quantitative evidence where possible and document the decision trail, because the score has to be auditable, not just intuitive.
| Dimension | Lens | What it measures | Typical evidence |
|---|---|---|---|
| Scale | Impact materiality | How severe the effect is | Incident records, emissions data, labour findings |
| Scope | Impact materiality | How wide the effect reaches | Supplier coverage, workforce counts, geography |
| Irremediable character | Impact materiality | How hard the harm is to reverse | Remediation history, legal findings, technical recovery limits |
| Likelihood | Financial materiality | How probable the effect is | Risk assessments, scenario inputs, control testing |
| Financial effect | Financial materiality | How the issue may affect the business over time | Margin pressure, compliance cost, interruption risk, financing impacts |
Why value-chain mapping matters more than topic-level thinking
Deloitte and PwC both note that topic-level assessments can miss material subtopics, which is a real problem in fashion and consumer goods. A broad topic like “water” or “worker welfare” may look manageable, but the material issue might sit at a specific stage, such as raw material sourcing, wet processing, logistics, retail, use phase, or end of life.
That's why value-chain mapping is becoming the preferred way to avoid omission risk. It makes the assessment more decision-useful, because it shows where the issue arises and where it can be controlled.
A clothing example that usually changes the scoring
Take cotton sourcing. A team may start with the broad topic and score it generically. That often obscures the core issue. The material concern could lie in agricultural water use, farm labour, traceability, or chemical inputs, and each of those subtopics can score differently depending on location and sourcing model.
A microplastics-related release scenario can work the same way. The materiality isn't just “synthetics.” It may sit in fabric choice, wash behavior, care instructions, or downstream shedding across the use phase. If the team only scores the umbrella topic, it risks missing the subtopic that drives material impact.
The useful habit is to score the IRO, not just the theme. That means tying impacts, risks, and opportunities to a specific business activity and value-chain stage before the final threshold decision is made.
Operationalising Results in a Digital Product Passport
The assessment stops being a compliance memo and starts becoming a product record. Each material topic, and the evidence behind its score, can be attached to model, batch, and item records so the business has one governed source of truth instead of separate compliance and product files. That's the shift brands are trying to make in 2026, and it's the point where the assessment becomes operational.
For teams building the product layer, the digital product passport should be treated as the publication layer for approved product facts, not as a dumping ground for unreviewed claims. The same discipline that supports CSRD evidence also supports passport data, because both need a source, a confidence state, and a human approval before anything is published.
What belongs in the passport record
A useful passport record doesn't just store marketing language. It stores fields such as recycled content, repair options, take-back availability, conformity documents, and any other product-specific facts that need verification. Each field should carry the underlying evidence, the source date, and a clear approval state.
Supplier portals matter. Time-bound requests keep the data collection focused, and the platform should know whether a document is preparatory, required, optional, or under legal review. That prevents the common failure mode where a team publishes a claim before the evidence is stable.
Why the assessment and the passport should share the same trail
The assessment tells the team which topics are material. The passport tells the market what the product record says about those topics. If those two systems aren't connected, product teams end up re-asking the same question every quarter.
A better pattern is simple:
- Material topic identified: the assessment marks the issue as reportable.
- Evidence collected: supplier files, test reports, and internal approvals are attached.
- Claim published: only approved facts move into the passport record.
- Record maintained: version history and change control stay attached to the same identity.
That structure matters because it makes the output auditable. It also gives the brand a single evidence spine for reporting, product compliance, resale, repair, and after-sale updates.
Pitfalls That Get Assessments Rejected by Auditors
The easiest way to fail a review is to treat the assessment as a polished summary of internal opinions. Auditors don't need a better narrative. They need a documented process, a stable evidence set, and a clear rationale for why some topics were included and others were not.

The most common failure is missing subtopics at the topic level. A second failure is netting gross impacts against mitigation, which hides severity before controls are considered. PwC-aligned practice is to assess impacts, risks, and opportunities on a gross basis first, then evaluate controls or offsets separately, because mitigation can't erase the underlying impact score.
For teams checking the product side, the internal note on what evidence to record for a product passport is a good reminder that product records and sustainability assessments fail for similar reasons, weak provenance and weak version control.
The four mistakes that show up again and again
- Missing subtopics: the team scores the umbrella topic and never tests the material sub-issue.
- Netting away severity: mitigation is counted too early, so the reported impact looks weaker than it is.
- Splitting the lenses too far apart: impact and financial materiality are handled as unrelated exercises.
- Poor stakeholder documentation: the team can't show who was consulted, when, and what changed.
The root cause is usually the same. The process wasn't designed as a control. It was designed as a meeting.
If the assessor can't reconstruct the decision trail, the assessment is too fragile for assurance.
The control is equally simple. Keep versioned records, attach evidence to each scoring decision, document stakeholder dialogue, and separate gross assessment from mitigating actions. That's what turns the exercise into a record instead of a presentation.
First-90-Days Plan and Common Reader Questions
The first 90 days should be about building structure, not chasing perfection. The goal is to get to a governed scope, a usable shortlist, a credible evidence backbone, and a clear decision on where the passport and the reporting workflow will live. Anything beyond that can be improved in year two.
Days 1 to 30, define scope and ownership
Start by confirming CSRD applicability, the reporting perimeter, and the business units that need to participate. Then draft the topic longlist from EFRAG, prior ESG work, and current risk registers. Assign owners for sustainability, product, legal, procurement, finance, and data governance so the project doesn't drift between functions.
Days 31 to 60, collect evidence and stress-test the shortlist
Build the stakeholder map, begin structured interviews, and gather the source files that can support each candidate topic. At the same time, choose the tooling backbone that can host both assessment evidence and product records, because switching systems halfway through usually creates version confusion.
Days 61 to 90, lock the first defensible output
Run the scoring sessions, document the rationale, and issue the first approved materiality return report. Then align the material topics to the product data model so passport fields, supplier requests, and disclosure inputs are pointing at the same source of truth.
A few questions come up in almost every briefing.
Who has to do this? Companies in scope of CSRD have to do it, but brands outside CSRD often still need the same discipline if they sell into the EU and will need product-level evidence.
How is this different from single materiality? Single materiality looks only at one side of the equation. Double materiality requires both the impact lens and the financial lens, then takes the union.
Can the same work support ESPR product data? Yes, if the assessment is mapped to product attributes, supplier evidence, and item-level records. That's the practical bridge.
What if the company isn't in CSRD but sells into the EU? Then the reporting deadline may not be the trigger, but the product-data expectation still is. In that case, the assessment should be shaped around the products and markets that will need governed evidence.
Good by day 90 looks like this. The company has a controlled shortlist, a defensible scoring method, documented stakeholder input, and a product-data model ready to carry approved claims. The assessment isn't finished, but it is real.
If you want the assessment to produce something your compliance team and product team can use, DPP Grid is built for that handoff. It helps brands connect governed evidence, item-level product records, and approval workflows so the double materiality output doesn't die in a PDF. Visit DPP Grid to see how a single trusted record can support both reporting and product passport readiness.