
In brief: Start with people who may be affected by the organisation’s operations and value chain. Identify potential harm, integrate prevention into employment and procurement, provide safe grievance channels and verify whether remediation addresses the harm.
The social pillar is broader than staff volunteering or employee benefits. It includes working conditions, discrimination, safety, privacy, community effects and human rights across business relationships. Effective management needs information from affected people and an ability to act, not only policies and annual activity counts.
Map affected groups and operating contexts
Distinguish employees, agency and contract workers, supplier workers, customers and communities. Examine where vulnerable groups, hazardous work, recruitment fees, excessive hours, discrimination or restricted voice may occur. Severity should matter even when the number of people is small.
Integrate prevention into business processes
Translate commitments into recruitment, scheduling, safety, purchasing, supplier and project controls. Assign owners and escalation. Training is useful only when supported by clear decisions, resources and consequences.
Design accessible grievance channels
Offer channels appropriate to language, literacy, disability, location and employment status. Protect confidentiality and prohibit retaliation. Explain how reports are received, investigated, escalated and communicated, while respecting personal data and due process.
Measure remedy and outcomes
Track time, recurrence, affected groups and whether the remedy restored rights or addressed root causes. Closing a ticket does not prove the harm was resolved. Use aggregated findings to change policies, contracts, supervision and training.
A practical implementation sequence
Choose one workforce or supply-chain context with meaningful risk and walk through the full process from prevention to remedy. Involve relevant worker or stakeholder perspectives when testing accessibility and trust.
- Map affected groups, locations and severe risks.
- Embed controls in HR, safety, procurement and operations.
- Provide confidential, accessible and non-retaliatory channels.
- Define investigation, escalation and remediation responsibilities.
- Track outcomes, recurrence and root-cause action.
For every step, retain the owner, source, reporting period, method, version, reviewer and known limitations. Estimates can be useful during transition, but they should never be presented as measured data.
Decision risks to control
- Measuring social performance only by volunteering hours.
- Providing a channel that contractor or supplier workers cannot use.
- Closing cases without checking whether harm was remedied.
Retain risk assessments, policies, training and control records, anonymised grievance data, investigation governance, remedy decisions and outcome reviews. Limit personal data and protect complainants.
Frequently asked questions
Is an employee hotline enough?
Not if affected contractors, supplier workers or communities cannot access it safely or in an appropriate language and format.
Should all grievances be reported publicly?
Public reporting should protect privacy and safety, using meaningful aggregated information on themes, process and outcomes.
What is effective remedy?
It aims to address the harm and restore affected people where possible, while correcting root causes to reduce recurrence.
How can an SME influence suppliers?
Use clear expectations, collaboration, customer leverage, sector initiatives and focused follow-up on the most severe risks.
Authoritative sources
- The Ten Principles of the UN Global Compact
- OECD Guidelines for Multinational Enterprises on Responsible Business Conduct 2023
- GRI 3 Material Topics 2021
This article is for general information and education only. It is not legal, investment, financial, assurance, certification, compliance or other professional advice.