Human Rights
Why organisations are focusing on this now
For many organisations, human rights rise up the agenda through one of three routes.
The first is proactive, through sustainability strategies, materiality assessments and responsible business commitments. The second is regulatory, as companies seek to understand which requirements apply to them and what compliance entails in practice. The third is reactive, triggered by customer expectations, identified risks, allegations, grievances or whistleblower reports.
Regardless of the trigger, the underlying challenge is the same: organisations need a clear understanding of where the most significant risks of harm to people exist across their operations and supply chains, what the UNGPs refer to as salient human rights issues, and whether those risks are being effectively managed in practice.
Risks are not the same as controls
A common reason due diligence programmes underperform is that they focus heavily on controls, such as policies and procedures, without clearly identifying and prioritising the most significant risks of harm.
This distinction matters. A missing policy or weak procedure may indicate a control gap, but it does not necessarily reveal where harm is most likely to occur or which issues deserve immediate attention. Risk-based due diligence starts by identifying where there are risks of adverse impacts to people or the environment and then determining what controls are needed to prevent, mitigate or address those impacts.
Prioritisation is not arbitrary. Under the UNGPs and the OECD Guidelines, the most significant risks are assessed based on their severity and likelihood. Severity is judged by scale (how serious the harm is), scope (how many people are affected) and remediability (how difficult the harm is to reverse). Severity takes precedence over likelihood. This means that a severe risk may warrant immediate attention even where it is less likely to occur, particularly where a delayed response could result in irreversible harm
How organisations identify and address risk in practice
In practice, organisations build their understanding of risk in stages, responding to the specific challenges, decisions and obligations they face.
For many organisations, the process begins with supply chain mapping and risk prioritisation. Sector, country and operational context are used to identify where the most significant actual and potential impacts on people are likely to occur. Human Rights Risk Assessments (HRRAs) then provide a structured view of those risks, identify the rights most at risk, and evaluate the effectiveness of existing controls.
Where greater insight is needed, organisations may undertake Human Rights Impact Assessments (HRIAs) or targeted on-site due diligence. These approaches help organisations better understand complex risks, validate assumptions from desk-based analysis, and assess impacts directly with affected stakeholders. Enhanced due diligence may also be required in heightened-risk contexts, such as conflict-affected areas or situations involving vulnerable groups, in line with OECD recommendations.
In other cases, the starting point is a specific allegation, grievance or incident. In these situations, investigations and incident response processes may be needed to understand what happened, address any harm that has occurred, and identify the root causes.
These activities are not standalone exercises. Together, they form part of an ongoing due diligence process that helps organisations identify risk, prioritise action, strengthen controls and improve outcomes over time.
What Kumi does differently
Human rights risk work can become overly academic. The result is often a long report that is difficult to translate into decisions and next steps; a salience assessment that names the issues but stops short of what to do about them.
Kumi brings both a business and rights‑holder perspective and looks for the crossover: what are the risks and impacts that matter the most, and what the organisation needs to do to manage those risks and impacts effectively.
We also help organisations connect this to wider decision-making, so human rights risk can be understood alongside existing governance, procurement, and risk processes, without losing the focus on impacts to people.
FAQs: human rights risk, due diligence, and assessments
-
What is a Human Rights Risk Assessment (HRRA)?
A Human Rights Risk Assessment identifies where human rights risks are most likely to arise across your operations and supply chain and helps you prioritise the most significant risks to people – your salient human rights issues – so you can decide what to do next.
-
What is the difference between HRRA and HRIA?
An HRRA is typically used to build a prioritised view of risk across your footprint, identifying the salient issues that warrant closer attention. A Human Rights Impact Assessment (HRIA) is used to conduct a deeper analysis of specific actual or potential impacts on affected rightsholders, such as workers or communities, and usually involves direct engagement with them.
-
When is on-site due diligence needed?
On-site due diligence is often needed when desk-based insight is not enough to understand how risks arise in practice, or when issues need to be validated through direct engagement and observation.
-
What triggers this work most often?
Common triggers include regulation, customer expectations, investor scrutiny, or a specific incident such as a whistleblower allegation.
-
How does an assessment relate to due diligence and the CSDDD?
An assessment is one part of due diligence, not the whole of it. Under the UNGPs and the OECD Guidelines, due diligence is a continuous cycle: assessing impacts, acting on them, tracking whether the response works, and communicating about it. The same logic runs through the CSDDD. An HRRA gives you the prioritised picture that the rest of the cycle depends on, which is why it is usually where the work starts rather than where it ends.