Skip to main content

Responsible Business: Prioritising When You Don’t Have the Resource to Assess Everything

· By Claire Lynch

CLC In the Weeds series illustration

In the Weeds is a series addressing the real, operational challenges faced by the people responsible for human rights due diligence (HRDD), ESG and ethical trade inside organisations. If you have a problem you’d like addressed in a future post, share it via our contact form.


This post follows directly from the first in the series, which addressed the challenge of limited budget and resource. One of the most common follow-up questions that comes with that territory is this: if I’m supposed to take a risk-based approach and focus where the risks are most severe – how do I know where that is when I don’t have enough resource to do a proper assessment in the first place?

It’s a genuine catch-22. And before getting to the practical answer, it’s worth addressing a conceptual point that often gets in the way, because understanding what risk-based prioritisation actually means in the HRDD context changes how you approach the problem.


HRDD Is Basically a Risk Management System – With One Critical Difference

Most organisations already have risk management systems – operational risk, financial risk, reputational risk, regulatory risk. The logic is familiar: identify what could go wrong, assess how likely and how serious it is, prioritise accordingly, put mitigation in place, monitor.

HRDD follows the same basic architecture. It is, at its most fundamental, a risk management system. The tools, the logic, the escalation structures – these are all recognisable to anyone who has worked with enterprise risk management (ERM). Which means that for a practitioner trying to make the case internally for HRDD, or trying to integrate it into existing business processes, the ERM framing is genuinely useful. You are not asking the business to do something alien. You are asking it to apply a familiar discipline to a different question.

And that is where the critical difference lies. In standard enterprise risk management, the question being asked is: what is the risk to the business? Prioritisation is determined by the severity of harm to the business, balanced against the likelihood of that harm occurring. In HRDD, the primary question is different: what is the risk to people? Severity is measured by the scale, scope and irremediability of harm to workers, communities and individuals in or connected to the value chain, not by financial exposure for the company.

This is not a subtle distinction. It is a fundamental re-orientation of what you are measuring and why. And it has direct practical consequences for how you prioritise.


Why the Difference Matters

Risk to people and risk to business are not unrelated (the first post in the HRDD 2026 series made the commercial case at length find it here). Litigation exposure, regulatory liability, supply chain disruption, reputational damage – these are all, ultimately, business consequences of human rights harm. Understanding HRDD as a resilience and risk management tool is both legitimate and useful.

But the sequence matters. In HRDD, you identify and assess risk to people first. The business risk implications are considered afterwards, as a consequence of what the human rights risk/impact assessment finds and to inform the proportional response; not as the primary filter through which you decide where to look.

Why does this matter in practice? Because if you start with “what is the risk to us,” you will systematically underassess impacts on people that don’t immediately translate into visible business exposure. And those are precisely where the most serious harms tend to sit – in lower tiers of the supply chain, in geographies with weak enforcement, in communities with limited access to legal remedy, among workers with no channel to raise concerns. The harms that are hardest for the business to see are often the most severe for the people experiencing them.

The mindset shift — from risk to business to risk to people — is not just a values question. It is a methodological one. It determines what you find.


The Four Dimensions of Severity

Once you have made that shift, the next question is: how do you assess severity of harm to people in practice? The UN Guiding Principles give us four dimensions that together form the prioritisation filter.

These four dimensions together are your prioritisation framework. When you are working through available evidence about where risks exist, the question you are asking about each one is: what do I know about the scale, scope, irremediability and connection to this issue — and what does that tell me about where to focus first?


What This Means for Prioritising With Limited Resource

With that framework in mind, here is how to start building a severity assessment when you don’t have the budget or capacity for a comprehensive original assessment.

(This won’t give you a complete picture – nothing replaces genuine engagement with affected people and direct assessment of your specific value chain – but it will give you a principled, evidence-based starting point. And a documented, reasoned starting point is considerably more defensible – legally, ethically and operationally – than either paralysis or guesswork.)

Here is what that looks like in practice:

1. Start With What the Evidence Already Tells You

2. Document Your Reasoning

Whatever conclusions you arrive at from your severity assessment, document how you got there. Record what sources you used, what they told you about potential scale, scope, irremediability and connection,, what assumptions you made, and where the gaps in your knowledge are. This matters for three reasons:


Finally

There is no clean solution to this catch-22…and it is worth being direct about why. A risk assessment, however well-resourced and carefully constructed, is always an informed estimate. It is based on the best available evidence at a point in time, in this case filtered through the four dimensions of severity, and subject to the limitations of what you can know from the outside looking in. No risk assessment is complete. No prioritisation is final.

What matters is that you apply a principled framework in good faith to the information you have, focus your limited resource on addressing the issues where the evidence suggests harm is most severe, most widespread and hardest to remedy, and document your reasoning transparently. An imperfect, evidence-informed prioritisation that is honest about its limitations is not a failure of HRDD. It is HRDD working as it is designed to work under real-world constraints.

Prioritisation is also not a one-off exercise. The UNGPs explicitly acknowledge that where it is not possible to address all identified risks simultaneously, you begin with those that are most severe – and you return to the others as capacity allows and as your understanding develops. Your first prioritisation is the beginning of an iterative process, not a definitive answer. It will be refined as you engage more deeply with affected stakeholders, build your evidence base, and learn more about what is actually happening in your value chain.

That next step – genuine engagement with the people most likely to be affected – is where the picture becomes more accurate and where the real work begins. It is also the subject of a future post in this series.


What’s your biggest operational challenge as a practitioner responsible for HRDD, ESG or ethical trade? Share it with us at info@clairelynchconsulting.com (or via the contact form) and it may become the subject of a future post in this series.


Claire Lynch Consulting is a business and human rights advisory practice specialising in social impact, human rights due diligence and responsible sourcing. We help organisations move from insight to impact.

Need support with human rights due diligence or responsible business practices?

Contact us

start a conversation

Ready to move from understanding human rights risk to practical action in your supply chain?

Contact us