Gains:
- Ability to establish an eight-step ESG workflow from materiality to publication with quality gates with the rhythm of 'artificial intelligence produces → human verifies → passes through the gate'
- Ability to protect personal and undisclosed financial data by classifying ESG data as free/internal/confidential
- Ability to assume ultimate responsibility and attach responsible names and approval records to each publication without relying on the 'AI said' defense
In the previous ten units we have covered each part of the ESG and sustainability business separately: entry and boundaries, materiality, data collection, carbon accounting, reporting frameworks, supply chain, stakeholder communications, report writing, assurance and greenwashing. In this final unit, we will put the pieces together and establish an end-to-end workflow: where, how and with what security gate to use artificial intelligence (AI) at every step from the definition of a sustainability mission to its publication. We will also bring data governance, privacy and ethical responsibility into a single framework.
Let's repeat once again the constant backbone of the module: AI; It is an assistant that writes code, organizes data, produces drafts and summarizes. The accuracy of the number, confirmation of the factor, control of the standard, proof of the claim and final responsibility always rest with the competent expert. This unit turns this principle into a daily workflow and checklist.
End-to-end ESG workflow
Consider a sustainability reporting cycle in eight steps:
- Scope and materiality — Which topics are material? (Unit 2)
- Data collection — Sources, units, audit trail. (Unit 3)
- Calculation — Carbon and other metrics with verified factors. (Unit 4)
- Framework matching — GRI/ESRS/ISSB substances, confirmation by official text. (Unit 5)
- Supply chain — Scope 3 and due diligence. (Unit 6)
- Writing and communication — Balanced, evidenced report and stakeholder message. (Unit 7-8)
- Assurance preparation — Chain of evidence and audit preparation. (Unit 9)
- Claim auditing — Greenwashing screening and release approval. (Unit 10)
At every step, AI is an accelerator; But at the exit of each step, there is a quality gate — a checkpoint that must be passed before moving on to the next step. The output that does not pass through the door does not progress.
step
What does AI do?
Quality gate
materiality
Topic candidate, theme analysis
Impact+finance aspect human approval
Data
Configuration, unit conversion
Source and volume verification
account
Formula, code scaffolding
The factor is confirmed from the official source
Matching
Article suggestion
Check the image with its standard text
spelling
draft, summary
Sorting out claims without evidence
claim
Greenwashing scan
Human-certified publication
Tip: Set up the workflow in the rhythm of “AI produces → human verifies → walks through the door.” Before moving each AI output to the next step, ask: “What part of this output cannot proceed without validation?” That part is the quality gate of that step.
Data governance and privacy
ESG data is often sensitive: employee gender and salary data, supplier contract terms, financial impacts not yet disclosed, facility-level production data. It is necessary to classify these before giving them to a public AI tool. Data governance is “who can use which data, how and with what tool?” The question is tied to the rule.
A simple classification:
- Free: Data already publicly available (published report). It can be given to AI.
- Internal use: Internal data of no commercial value. Carefully in corporate vehicle.
- Confidential: Trade secret, undisclosed financial impact, personal data (KVKK/GDPR). It is not given to the AI without anonymization or institutional (non-leaking) means.
Your role: data governance advisor. Task: classify the following data items as "free / internal use / confidential" and write the recommended action for each confidential item (anonymize / aggregate / enterprise tool / do not give at all). Rule: if unsure, put in more protective class. Items: [PERSONAL AND FINANCIAL DATA ITEMS]
Weak prompt / Strong prompt
The way you delegate a task to a tool radically changes the privacy risk.
Weak prompt:
Analyze that employee salary and facility production table, come up with an ESG summary.
Exports raw personal and trade secret data directly to an open tool; There is no classification, anonymization and confirmation step.
Powerful prompt:
Your role: ESG analyst sensitive to data governance. I gave you ONLY aggregated, personal/trade secret-free data. Task: analyze the following summary indicators. Rules:- NO individual names, salaries, IDs or undisclosed financial impact in the data; If you see such a field, say "CONFIDENTIAL DATA - do not process, warn". - Do not add a new number to the result; just go with the summary I gave. - Add a "human approval required" note at the end of the output. Data (aggregated): [SUMMARY INDICATORS]
Caution: "AI said" is not a defense. Responsibility for an incorrect number, unsubstantiated claim, or leaked confidential data in an ESG report lies with the organization and the person who approved it. When you use AI, you do not transfer responsibility; You will only speed up the work.
End-to-end quality gate prompt
The following prompt runs all steps through a single check before publishing.
Your role: ESG quality assurance officer. Task: pass the following report section through the end-to-end quality gate. Give "pass / FAIL" for each item and write the reason if it fails: 1) Are the source and unit of each number stated? 2) Are the emission factors from the official source? 3) Are the standard item numbers verified? 4) Are proxies/estimates marked? 5) Are there any statements containing greenwashing? 6) Is there any leakage of confidential/personal data? 7) Responsible name for final approval assigned?Section: [CHAPTER]
The following prompt converts the entire module into an enterprise policy.
Your role: sustainability team leader. Task: write a 1-page internal policy governing the team's use of AI in ESG work. Include:- Tasks where AI can be used freely (draft, summary, code, theme analysis)- Tasks that require human verification (factor, standard, claim, scope)- Data types that will never be given to AI (personal, undisclosed financial)- Quality gate steps to be passed before each release Tone: clear, bullet point, applicable.
three mini cases
Case 1 — Report returned from the door. One team thought they had completed all the steps and the report was ready for publication. The final quality gate prompt captured an unsourced “78% recovery” claim and a “carbon neutral” statement in one section. Publication was stopped before either was corrected; The door held the bug before it became public.
Case 2 — Confidential data leakage prevented. An analyst would paste the yet-to-be-released quarterly financial impact data into a publicly available tool for analysis. The data classification prompt flagged it as “confidential—undisclosed financial.” The data was first aggregated and then processed in the enterprise tool; A possible violation of legislation was prevented.
Case 3 — Taking responsibility. After a report was published, a stakeholder questioned a number. The team didn't say "AI calculated"; opened the audit trail, cited the source, made a minor correction, and explained transparently. This attitude, which did not rely on the "AI said" defense, preserved trust.
Common mistakes
- Moving forward without the door of quality. If verification is not performed at the exit of each step, errors will accumulate until the end.
- Giving data to the vehicle without classifying it. Confidential and personal data cannot be entered into public AI without anonymization.
- Transferring responsibility to AI. “AI said” is not a legal or professional defense.
- Thinking steps isolated. Materiality, data, calculation and claim are interconnected; If one is damaged, all are affected.
- Not assigning a person responsible for publication approval. Behind every public claim there must be a human being.
In summary
The ESG business is a chain of eight interconnected steps, and AI is an accelerator at each step; But there is a door of quality at the exit of every step. The rhythm of “AI produces → human verifies → passes through the door” combines all the lessons of this module into a single study discipline. Classify data and protect confidentiality, confirm factor and standard from official source, link claim to evidence, weed out greenwashing before publication, and give final responsibility to a human. AI speeds up work; You assume accuracy, honesty and responsibility. The criterion of this profession is not "appearing fluent", but "passing the audit and being proven".
Application task
Combine the deliverables you produced in previous units (a materiality list, a carbon account, a report section) into a single mini-report. Go through this mini report in 7 items with the above end-to-end quality gate prompt from AI. Then: (1) correct each item marked "RELEASE", (2) classify and take action on all confidential/personal data, (3) add a responsible name and approval note for publication.
checklist
- [ ] I set up the workflow with the rhythm of “AI produces → human verifies → passes through the door.”
- [ ] I implemented a quality gate at the exit of each step.
- [ ] I classified all data as free/internal/confidential and protected the confidentiality.
- [ ] I have confirmed the factors and standard items from the official source.
- [ ] I backed every claim with evidence, eliminating greenwashing before publication.
- [ ] I took responsibility without relying on the "AI said" defense.
- [ ] I have set a responsible name and approval record for the publication.
Module Exam
1. Which of the following is the best positioning for AI in the ESG and sustainability business?
- A) Artificial intelligence is an assistant of code, data and blueprints; The responsibility for factors, standards, evidence and ethical decisions lies with people ✔
- B) Artificial intelligence is an auditor and the ESG values it provides are a substitute for independent assurance
- C) Artificial intelligence only works in writing reports, it has nothing to do with data and calculations
- D) Since AI is more impartial than humans, all ESG decisions should be left to it
Description: Artificial intelligence; It is an assistant that writes code, organizes data, produces drafts and summarizes. However, the final responsibility for confirming the emission factor, checking the standard substance number, proving each claim lies with the competent expert. The big language model is not a calculator, regulatory/standards database, or checker; is a text generator that produces the 'next most likely word' and its unverified output may lead to a false report or claim.
2. What does the 'impact materiality' aspect of an issue mean in double materiality analysis?
- A) The impact of the issue on the company's profit and share value
- B) The financial risk of the issue only for investors
- C) Performance of rival companies on the same subject
- D) Impact of the company's activities on the environment and society ✔
Description: Double materiality looks through two lenses. Financial materiality is the impact of an issue on a company's cash flows and value ('outside-in'). Impact materiality is the impact of the company's activities on the environment and society ('inside out'). CSRD/ESRS enforces both aspects; Since artificial intelligence often shifts only to the financial direction, the impact direction must be additionally controlled by the human.
3. What is the correct approach when collecting energy data in kWh, MWh and GJ from different facilities?
- A) Ignore units and add all numbers directly
- B) Relying on artificial intelligence to collect the long list in your head
- C) Converting all values into a single unit and making the conversion and sum with code/formula ✔
- D) Selecting the largest unit and not reporting other facilities
Explanation: Unit churn is ESG's most frequent and dangerous mistake; Since 1 MWh = 1,000 kWh, if the unit is omitted, the result can deviate by a factor of 1,000. The correct approach is to convert all values into a single unit and have the artificial intelligence do this conversion and sum with an executable code/formula, not manually; thus the result is deterministic and verifiable.
4. What scope includes emissions resulting from the production of purchased electricity according to the GHG Protocol?
- A) Scope 1
- B) Scope 2 ✔
- C) Scope 3
- D) It is not included in any scope and is not reported
Description: Scope 1 is direct emissions from the organization's own sources (boiler, company vehicle, generator). Scope 2 is indirect emissions from the production of purchased energy (electricity, steam, heating, cooling). Scope 3 covers all other indirect emissions in the value chain (supply, travel, product use, waste). Electricity does not come out of the company's chimney, but the power plant that produces it emits emissions; so it is Scope 2.
5. What concept is used when converting a greenhouse gas such as methane (CH₄) to CO₂e and why is it important?
- A) GWP (global warming potential); if omitted, methane/N₂O effect will be greatly underestimated ✔
- B) AQI (air quality index); determines the color of the gas in the air
- C) GRI (reporting initiative); determines the substance in which the gas will be reported
- D) No coefficients required; methane counts 1 to 1 directly like CO₂
Description: GWP (Global Warming Potential) is the coefficient that converts the heating effect of different greenhouse gases into a common unit relative to CO₂. The 100-year GWP of methane is approximately 28; So 1 ton of methane means approximately 28 tons of CO₂e. If GWP is omitted, the impact of strong gases such as methane and N₂O will be greatly underestimated and the inventory will be completely inaccurate; It should also be stated which GWP set (e.g. IPCC AR6, 100 years) is used.
6. Which approach is correct for calculating 'activity data × emission factor' in a greenhouse gas inventory?
- A) Using the factor that the artificial intelligence remembers and having it do the total manually
- B) Counting all gases as CO₂ and skipping factor and GWP conversion
- C) Using a default factor exactly for each country, year and fuel
- D) Confirming the factor from the official source according to country and year and making the calculation scaffolding and total with code ✔
Description: Emission factors vary by country, year and fuel; 'Reminding' the AI creates the risk of making things up (hallucinations). The factor should always be confirmed from an official table (IPCC, DEFRA/EPA, IEA, national inventory); Only scope separation, accounting scaffolding and total code should be done by artificial intelligence. Multi-row totals are done by executable code, not manually.
7. What is the correct behavior for a GRI/ESRS standard substance number (e.g. 'GRI 305 for water consumption') suggested by the AI?
- A) Writing the number directly into the report because artificial intelligence suggests it
- B) Item numbers are unimportant; any can be written
- C) Verifying the number and its content with the official standard text, confirming it in case it is fake/outdated ✔
- D) Since water and air emissions are similar, reporting them in the same article
Description: Artificial intelligence can generate standard numbers that appear real but whose content is false or completely fabricated; Also, standards are updated and the version the model knows may be outdated. For example, water is reported under GRI 303, while GRI 305 is air emissions. Therefore, each substance number and content cannot be used without being verified with the official standard text (GRI/EFRAG/ISSB).
8. If most suppliers in the supply chain do not have real carbon data, what is the right and honest approach for Scope 3?
- A) Directly using the numbers made up by artificial intelligence for suppliers
- B) Skipping Scope 3 entirely because it's 'hard to measure'
- C) Using those with real data, clearly marking the proxy for those without ✔
- D) Applying proxy to all suppliers and hiding it in the report
Description: Scope 3 is most companies' largest but most difficult to measure item. For suppliers that provide actual data, that data is used; For those who do not provide it, an expenditure-based proxy (estimate) can be used. The critical thing is not to hide the proxy: the report should clearly state the portion and proportion of the estimate used. Obfuscated proxy may lead to denial of independent assurance; It is also wrong to skip Scope 3 entirely on the grounds that it is 'difficult to measure'.
9. AI flagged a supplier as 'possible forced labor' based solely on the country average. What is correct behavior?
- A) Accept the signal as evidence and immediately publicly cut off the relationship with the supplier
- B) Writing the claim directly into the report because the artificial intelligence said it
- C) Completely ignoring risk signals and not examining them at all
- D) Considering the signal as a 'warning to be investigated' and confirming it with field inspection and a reliable source ✔
Explanation: Serious allegations such as human rights violations cannot be proven with a signal produced by artificial intelligence. Such a signal is merely a 'warning to be examined'; Using it as a definitive accusation is both unfair and legally risky. Such claims are only confirmed by a reliable source, field inspection and legal process. Artificial intelligence generates signals; The human being assumes the judgment and responsibility.
10. What is the most critical precaution when analyzing hundreds of free-text responses from a stakeholder survey with AI?
- A) Requiring rare but high importance (safety/ethical/environmental) signals separately and not overshadowing them ✔
- B) Picking only the highest frequency themes, eliminating minority views
- C) Reduce all answers to a single positive summary and leave out the details
- D) Accepting the summary of artificial intelligence instead of raw answers
Description: Artificial intelligence amplifies the voice of the majority and suppresses the voice of the minority in thematic analysis. However, the most valuable signal in sustainability is sometimes a serious safety, ethical or environmental problem voiced by a single person. So the analysis asks 'what was said most often?' It does not end with; 'rare but high significance' signals should be requested separately and raw responses should be used in addition to, rather than in place of, the summary.
11. What is the most effective way to prevent fake numbers and targets from leaking into the text when writing a report section to artificial intelligence?
- A) Having the entire report produced at once by saying 'write a suitable text'
- B) Providing only verified data and explicitly prohibiting generating new numbers/claims ✔
- C) Check how fluent and impressive the text is and publish it
- D) Allowing AI to fill in missing data with reasonable guesses
Description: Artificial intelligence generates numbers and targets you don't actually have, using the logic 'this is what similar reports said' in an empty prompt. The most effective precaution is to give it only verified data and 'add no numbers, percentages, dates, or claims other than the data I have given you; It is to clearly state the rule of 'write [DATA REQUIRED] in the missing place'. In addition, the report should be printed section by section, fed with data.
12. What does an independent assurance auditor look for first when reviewing a sustainability report?
- A) How fluently and professionally the report is written
- B) Each issue has a chain of evidence traceable to the source document ✔
- C) Artificial intelligence says 'the report is ready for audit'
- D) Make the report appear more assertive than competitors
Explanation: The examiner is not interested in the fluency of the text, but in the chain of evidence behind each claim; His first question is 'prove this number'. It is examined which source document a number comes from, which formula and factor it turns into a report, and whether it can be repeated independently. Therefore, each material metric must be traceable to its source, factors must be verified from the official source, and proxies must be specified; Artificial intelligence makes this preparation, but cannot provide assurance.
13. Which of the following environmental claims has the lowest risk of greenwashing?
- A) 'We reduced our production emissions by 18% by 2023 (with third-party verification)' ✔
- B) 'Our products are completely environmentally friendly and natural'
- C) 'Our company is carbon neutral' (without providing any documents or data)
- D) 'We are the most sustainable and near-zero impact company in the industry'
Explanation: A good environmental claim is measurable (contains a number), proven (based on evidence), and clear in scope (it is clear what is being compared to what and when). 'We reduced production emissions by 18% by 2023 (with third-party verification)' has these three features. Phrases such as 'eco-friendly', 'natural', uncertified 'carbon neutral' are unquantifiable or unsubstantiated and carry the risk of greenwashing.
14. What should be done before pasting undisclosed facility production and emissions data into a publicly available AI tool for analysis?
- A) Pasting the data as is; environmental data is always publicly available
- B) Giving without taking precautions as the responsibility passes to the artificial intelligence provider
- C) The risk is simply miscalculation; A confidentiality measure is unnecessary
- D) Classifying data as free/internal/confidential and anonymizing confidential data or using corporate tools ✔
Disclosure: Plant-level production and emissions data may be trade secrets; financial/environmental data that has not yet been disclosed may violate regulatory disclosure rules; Employee location/salary data is personal data within the scope of KVKK/GDPR. Before giving this type of data to an open tool, it is necessary to classify it as free/internal/confidential, anonymize it if necessary, or use a corporate (data-free) tool. 'AI said' is not a defence; The responsibility lies with the institution and the person who approves it.