Skip to main content

How Karomia generates your IROs

Goal

Understand where your IROs come from, what the AI scores mean and what they do not mean, so you can explain them to your colleagues and your auditor.

Introduction​

"The AI generated it" is not an explanation you can give an auditor. This page describes how the analysis works, at the level you need to answer for it. It follows the EFRAG implementation guidance: understand the context, identify the IROs, assess them, then decide. Every step leaves a trace you can show.

Three things are worth knowing before the detail:

  • The analysis does not start from a blank prompt. It starts from a curated knowledge base of what is already known to be material in your industries.
  • Impact and financial materiality are scored separately, from different evidence, so neither can influence the other.
  • No model decides what is material for you. A model matches your company's facts to defined criteria; the scores and the material-or-not conclusion are then calculated by formula.
Visual placeholder

A flow diagram of the six stages below, from the industry knowledge base and your documents on the left to the scored IRO register on the right.

The six stages​

StageWhat happensWhat comes out
1. ContextYour activities are mapped to industries and value chain stages; your documents are indexed.The ground the analysis covers.
2. Subtopic scoringEvery ESRS subtopic gets an impact score and a financial score.The a priori matrix, top-down.
3. IRO derivationEach relevant subtopic produces the impacts, risks and opportunities that apply to you.A first IRO register.
4. EnhancementYour documents and public sources are searched for matters the industry view would miss.Company-specific IROs added or enriched.
5. ValidationEvery IRO is checked against your company's reality before you see it.A cleaned register, with dropped IROs logged.
6. IRO scoringEach IRO is scored against the ESRS 1 criteria and rolled back up.Scored IROs and the a posteriori matrix, bottom-up.

For how the two matrices relate, see Top-down and bottom-up.

Stage 1: What the analysis starts from​

An industry knowledge base. Karomia maintains a curated registry of industries, mapped to the main sustainability and economic classification standards. For each one it records the sustainability matters already known to apply: how the industry affects people and the environment, and what financial risks and opportunities sustainability factors create for companies in it. This is what the analysis reasons from, rather than a model's general impression of your sector.

Your activities. Your business activities are mapped to those industries and tagged upstream, own operations or downstream. This decides which industry knowledge applies to you and through which part of your value chain. You can review it before generation; see Review your value chain map.

Your documents. Everything you upload is indexed and searched at three points: while scoring subtopics, while deriving IROs, and while looking for matters the industry view missed. See Upload documents.

Stage 2: A first score for every subtopic​

Each ESRS subtopic receives an impact score and a financial score from 1 to 5, forming the a priori materiality matrix. Subtopics are sorted into high, medium and low relevance relative to your own profile rather than against fixed cut-offs, so the labels describe your materiality landscape instead of an absolute standard.

Impact and financial are scored separately​

This is the part worth understanding, because it is what makes the two axes independent.

Scoring runs as two separate passes over each subtopic. The impact pass sees only evidence about effects on people and the environment; the financial risks and opportunities are withheld from it. The financial pass sees only the risks and opportunities; the impacts are withheld.

Neither pass can see what the other is working from, so a severe impact cannot inflate a financial score and a large financial exposure cannot inflate an impact score. Where the two scores do converge, that came from your company's facts rather than from one number following the other.

note

This is why you sometimes see a high impact score next to a low financial one on the same subtopic, and why that is a finding rather than an inconsistency.

Each pass is grounded in the industry evidence for that subtopic, your company profile, your value chain and extracts from your own documents. Calibration context is supplied so that scores spread across the scale instead of clustering in the middle.

Automated checks then flag subtopics whose two scores are suspiciously close, and cases where the scoring departs sharply from the underlying industry signal. These checks flag for review; they never silently adjust a score.

Alongside each score you get an impact rationale, a financial rationale and a description. Rationales have to cite the specific mechanism at work in your company, not generic ESG language.

Stage 3: Deriving the IROs​

Within each relevant subtopic, the impacts, risks and opportunities that apply to your company are generated. Each IRO is exactly one of four types: negative impact, positive impact, risk or opportunity.

Actual versus potential​

This classification has real scoring consequences — actual impacts are scored on severity alone, while potential impacts are weighted by likelihood — so the rules are strict:

  • Actual requires company-specific evidence that the impact is occurring now, in your operations or your supply chain. An industry-level assumption ("mining typically causes habitat destruction") is not sufficient.
  • Potential covers impacts that could occur given your activities, industry or supply chain structure, with no verified evidence that they are happening today. This includes deeper upstream impacts where you have no direct visibility.

When in doubt, the classification is potential, and a later validation check re-tests it.

The reasoning rules​

Generation is governed by a fixed set of rules encoding the double-materiality reasoning patterns of ESRS 1 Chapter 3, rather than left to a model's judgement. Among them: dependencies create financial exposure even where no impact precedes them; negative impacts transmit into financial risk through regulation, litigation or reputation, and positive impacts into opportunities; impact materiality stands on its own, whether or not there is any financial consequence; severity is recorded gross, before what you already do about it; and every IRO is placed in the value chain, split where the same matter manifests differently at different stages.

How many IROs​

The number generated per subtopic is proportional to its relevance — a few focused IROs for a low-relevance subtopic, a broader set across types, value chain stages and time horizons for a highly relevant one. Padding a subtopic with generic IROs is explicitly disallowed. This is what keeps the register proportionate under the simplified ESRS instead of producing the same depth everywhere.

Stage 4: Finding what the industry view misses​

The industry knowledge base tells you what is material for companies like yours. It cannot tell you what happened at your plant last year. A separate pass looks for that, searching your own documents and public sources for company-specific evidence — including controversies, incidents and supply chain human rights issues. The method looks for unflattering material about your company, not only for what you publish about yourself.

Each candidate it finds is then compared against the IROs you already have, and is either added as a new IRO, merged into the existing one it overlaps, or dropped as a restatement.

Stage 5: Quality checks before anything reaches you​

Every IRO passes a validation step before scoring. Each check either passes the IRO, reframes it, or drops it with an audit trail.

The checks catch IROs that cite a regulation not applicable at your size, contradict your own reporting, claim an impact is already occurring without evidence for it, describe a geography or sector you do not operate in, say nothing specific about your company, duplicate a matter already covered, or sit out of proportion to the activity behind them. Dropped IROs are recorded rather than deleted, so the register can be reconciled afterwards.

After validation, each IRO gets its stakeholder question: short, neutral in tone, one issue per question, phrased for the IRO type, and translated into your assessment languages. See Review questions and translations.

Stage 6: Scoring every IRO​

Each validated IRO is scored against the ESRS 1 criteria — the same criteria your stakeholders will later use.

The model matches facts; the formula does the arithmetic​

Scoring is deliberately split in two:

  1. A model matches your company's facts to defined criteria brackets and returns a score from 1 to 5 per dimension, with a rationale citing a specific fact. The brackets are defined by concrete criteria — a share of the affected population, a share of revenue — rather than by adjectives, so two assessments mean the same thing by a 4.
  2. Severity, the likelihood weighting, the final materiality score and the material-or-not classification are then computed deterministically in code, with no model involvement.

So no model decides whether a topic is material for you. It supplies the inputs; a fixed formula produces the result.

Proportionality and distance in the value chain​

Two calibration rules stop scores inflating. An IRO on a subtopic the first stage scored low should generally score low, unless strong company-specific evidence justifies otherwise. And upstream impacts are scored on your leverage, not on the raw severity of the upstream industry: your own operations at face value, direct suppliers discounted, and the indirect supply chain discounted further, reflecting how little influence you actually have there.

The formulas​

IRO categoryDimensions scoredMateriality score
Actual negative impactScale, scope, irremediabilitySeverity = average of the three
Potential negative impactScale, scope, irremediability, likelihoodSeverity weighted by likelihood
Actual positive impactScale, scopeAverage of the two
Potential positive impactScale, scope, likelihoodAverage weighted by likelihood
Risk or opportunityFinancial magnitude, likelihoodMagnitude weighted by likelihood

Severity is the average of its dimensions rather than the maximum, which gives more granular scores and reflects the overall profile better when the dimensions diverge.

For potential negative impacts on fundamental human rights at high severity, the score is the severity itself, with no likelihood weighting (ESRS 1, paragraph 41) — an unlikely but severe human rights impact stays material. This applies to fundamental violations such as forced or child labour, serious threats to life and safety, discrimination and violence, community displacement and land rights, and suppression of freedom of association. General working conditions and commercial matters are not flagged.

An IRO is material above a set threshold, which is configurable for your assessment.

Back to subtopic level​

The scored IROs aggregate back up into the a posteriori matrix that sits next to the a priori one.

  • Impact materiality of a subtopic is the highest severity among its impact IROs. Impacts are not summed, because one severe harm is not made worse by several mild ones elsewhere, and positive impacts are never netted against negative ones.
  • Financial materiality aggregates cumulatively across risks, or across opportunities, whichever side is larger. Financial exposure genuinely accumulates: three separate risks of a few percent of revenue each are a larger exposure than any one alone.

Comparing the two matrices is the point. A subtopic that moved a long way once the detail was scored, or that crossed into the material zone, is exactly where a stakeholder conversation is worth having. You see this in section 3.1 of the AI report.

Where every number comes from​

Every IRO carries its origin — derived from an industry signal, discovered in your documents or public sources, or derived then enriched — along with the subtopic and scores it came from, so any IRO can be traced back to its place in the materiality landscape. Evidence records are typed by source and traceable to where they came from, and a final check verifies that evidence cited by an IRO matches evidence actually retrieved.

A conclusion for every subtopic​

Your DMA report lists every ESRS subtopic with one of four statuses:

  • Assessed: it has IROs that go into the assessment.
  • Covered elsewhere: its substance is assessed within adjacent subtopics.
  • Not material, documented: with the rationale.
  • To be completed: you still owe a conclusion.

This is the answer to the auditor's question "why did you not assess biodiversity?". No subtopic is silently skipped.

How this maps to ESRS 1​

The method is built against ESRS 1 and can be walked through requirement by requirement: separate impact and financial assessment (para. 36), a top-down approach complemented by bottom-up enrichment (paras. 27–28), roll-up to topic level (para. 26), value chain scope (paras. 40, 63–66), time horizons (para. 80), evidence and sources (para. 32), entity-specific topics (para. 11), actual versus potential (paras. 41–42), the severity dimensions (AR 20), gross impact recording (para. 44), cross-topic cascades (para. 52), positive impacts never netted against negative (para. 45), and a documented materiality determination (para. 38).

Two areas are not fully covered today: IROs carry value chain tags but no geographic dimension, and cumulative effects are reasoned about but not automatically detected. Ask us through the chat if your auditor wants the full mapping; we can provide it and join the conversation.

Stakeholder engagement (para. 43) sits outside this method by design: the AI stage produces the questions, and your stakeholders' answers are what determine your final materiality. See Plan your engagement.

What this method does not do​

Said plainly, so you are not surprised and so you can answer for it:

  • AI scores are never an input to your results. They are an analytical baseline shown next to your results for comparison. Your materiality comes from stakeholder answers alone. See How results are calculated.
  • Scoring is not perfectly repeatable. Run the same assessment twice and individual scores may shift. Calibration and the proportionality rules constrain the spread, but the judgement layer retains some freedom.
  • Scores are not precisely comparable between companies. Do not read small differences across two companies' assessments as meaningful.
  • Discovery depends on what you give it. A company with few documents and little public disclosure yields fewer discovered IROs. This is the single biggest lever you control.
  • It can be wrong. Read the drivers and the sources before you rely on a score. That is what this step is for.

What arrives in the platform​

The IROs, their labels, their sources, the AI scores and a stakeholder question with context for each IRO. Everything is generated in your default language, and the questions and their context are translated into your other assessment languages.

You also receive the AI report: an HTML file with the long-form version of this analysis, from the scores per subtopic to the stakeholder engagement plan. Do not read it cover to cover. Use it when you want to understand or challenge a specific IRO. See The AI report for what is in it and how to use it.

Common questions​

Why do I see fewer subtopics than in the ESRS list? The AI only generates IROs for subtopics it considers relevant. The others still appear in your report with a documented conclusion.

Why does a subtopic score high in the pre-assessment while its IROs are not material? The pre-assessment is a broad, sector-driven estimate. The IRO scoring looks at your specific situation. When they disagree, that is exactly where your stakeholders should weigh in.

My documents gave a lot of weight to a small activity. Is that a problem? The AI reflects what you gave it. Deselect the IROs that are not proportional to the activity's weight in your company, and write down why.

Can I have entity-specific topics? Yes. Tell us before generation and we add custom topics or subtopics. Their IROs are treated like any other.

Which model do you use? We do not tie the methodology to a specific model, and we change models as better ones become available. What stays fixed is everything on this page: the rules, the criteria and the formulas.

Can I see the full methodology? We can walk your team or your auditor through it in more detail than this page goes into. Ask through the in-app chat.

Output​

  • An explanation of the method you can give a colleague or an auditor, and the vocabulary used everywhere else in this guide.
  • The AI report, to use when you want to understand or challenge a specific IRO.