Criterion: Risk Identification and Assessment
Systematic process to identify, assess, prioritize, and manage ESG risks and adverse impacts, including scoping, in-depth assessment, stakeholder input, and periodic review.
Full Description
MSG06 Risk Identification and Assessment
Standard Section: 6.6 Category: Management Systems Scheme: Responsible Minerals Assurance Process (RMAP) Standard Version: 2.0 for Piloting (effective April 30, 2025)
Overview
Systematic process to identify, assess, prioritize, and manage ESG risks and adverse impacts, including scoping, in-depth assessment, stakeholder input, and periodic review.
Requirements
The Facility shall carry out an assessment to identify and address ESG risks and adverse impacts through implementation of the following requirements:
- 6.6.1 Conduct a scoping exercise to identify ESG risks associated with the Facility's activities, products, and services that can directly cause or contribute to an adverse impact, with consideration for the ESG risks identified in Sections 7 to 9 below. This shall include potential impacts of suppliers and contractors conducting activities related to the Facility's operations. Scoping shall result in initial prioritization of ESG risk areas that require further assessment.
- 6.6.2 Establish a documented methodical process for assessing, prioritizing, and managing ESG risks, that includes rationale and criteria for determining risk saliency, with consideration for compliance obligations, and stakeholder commitments.
- 6.6.3 Carry out an in-depth ESG risk assessment of relevant risk areas, starting with those defined as priorities, as an initial step in the Facility's risk assessment process. Risk assessments shall be conducted by competent professionals and draw on internal and/ or external expertise. Any limitations arising from these analyses shall be documented.
- 6.6.4 Facilities that are subject to carry out an environmental and social impact assessment (ESIA) as part of regulatory requirements, are encouraged to integrate the results of ESIAs into the ESG risk assessment process.
- 6.6.4.1 Where an ESIA has not been conducted, conduct studies carried out by qualified professionals to determine baseline conditions for relevant ESG risk areas.
- 6.6.5 Include evaluation of potential emergency scenarios within the scope of the risk assessment.
- 6.6.6 Seek relevant internal or external subject-matter expertise as needed to assess ESG risks and impacts.
- 6.6.7 Prioritize ESG risks based on saliency by means of evaluating severity and likelihood of adverse impacts associated with the risk. Identified risks may have adverse impacts tied to more than one risk area (e.g., there may be impacts to the human rights of stakeholders, business governance and reputation, as well as the environment). In circumstances where there are multiple categories of impact, significance should be evaluated based on the worst-case impact scenario.
- 6.6.8 Test the established list of salient issues with key external stakeholders (including rightsholders and/or their legitimate representatives) to verify the Facility's list of salient issues are credible.
- 6.6.9 Risk assessment and prioritization should be informed by perspectives of potentially affected stakeholders or their legitimate representatives, such as civil society organizations or trade unions.
- 6.6.10 Risk assessments shall take into account heightened risks for vulnerable and marginalized populations and with a gender perspective.
- 6.6.11 Periodically review and assess risks, annually at minimum, and any time there is new information on, or changes to, risks, including planned and unplanned changes to business processes and relationships with the Facility's suppliers and contractors.
- 6.6.12 Utilize a lifecycle approach to assess ESG issues associated with the Facility's operations by considering:
- 6.6.12.1 Any risks and impacts associated with legacy operations that require ongoing management.
- 6.6.12.2 Expansions, modifications, decommissioning and closure of current operations.
- 6.6.10 Establish and document internal channels of communication between top management and relevant departments for sharing information on ESG risks.
- 6.6.11 Embed ESG risk management into business and operational processes.
- 6.6.12 Determine opportunities for continual improvement and implement necessary actions to achieve the intended outcomes of the Facility's management of ESG risks.
Source: RMI Facility Standard for Social, Environmental, OHS and Governance Risks, Version 2.0 for Piloting (April 2025), Section 6.6
Profiles using this criterion
Responsible Minerals Assurance Process
Conformity Alignment
Meets
Pass: Yes
Definition: "Facility has conducted a documented ESG scoping exercise and in-depth risk assessment prioritized by saliency, using a defined methodology with documented rationale, informed by competent professionals and stakeholder input, updated at least annually and upon significant changes, applying a lifecycle approach including legacy and closure risks, and findings embedded in business processes."
Partially Meets
Pass: No
Definition: "ESG risk assessment has been conducted but is incomplete: e.g., scoping is partial, risk prioritization methodology is not documented, assessment has not been updated within the required period, stakeholder perspectives are not incorporated, or lifecycle risks are not considered."
Remediation: 180 days
Does Not Meet
Pass: No
Definition: "No documented ESG risk assessment or scoping exercise, no methodology for assessing and prioritizing risks, or risk assessment has never been conducted."
Remediation: 90 days
Priority
Pass: No
Definition: "Priority findings are not raised against this criterion. Risk assessment gaps are assessed under Does not Meet."
Remediation: 30 days
Not Applicable
Pass: Yes
Definition: "This criterion is not applicable to any facility - all facilities must conduct ESG risk assessments to identify and manage material risks."
Not Able To Assess
Pass: No
Definition: "The assessor was unable to access risk assessment documentation, methodology records, or interview personnel responsible for ESG risk management."
Change Log
1.0.0 (2026-06-24)
Initial release.