How to Build an Esg Policy That Works for UK Businesses

Alex Solo
byAlex Solo12 min read

Many UK businesses know they should say something about ESG, but they get stuck between vague promises and documents that nobody actually uses. A common mistake is copying a global template that does not match the business’s size, sector or risks. Another is treating ESG as a marketing exercise, then making claims the business cannot evidence. A third is leaving legal and operational details out, so the policy never connects with supplier terms, privacy processes, health and safety, or board decision-making.

A useful ESG policy should do more than sound impressive. It should explain what matters to your business, who is responsible, what standards apply, how progress is checked, and what the business will do when problems come up. This guide answers how to build an ESG policy that works for businesses in the UK, including what ESG means in practice, when founders and SMEs usually need one, the legal and commercial issues to think about before you sign contracts or publish public claims, and the mistakes that most often cause trouble.

Overview

An ESG policy is a practical framework for how your business approaches environmental, social and governance issues in day-to-day decisions. For UK businesses, the policy works best when it reflects real legal obligations, genuine operational priorities and clear accountability, rather than broad statements that cannot be measured or followed.

  • Define what ESG covers for your business, based on your sector, size, customers, supply chain and growth plans.
  • Align the policy with existing legal and business documents, such as supplier contracts, employment policies, privacy notices, health and safety procedures and board approvals.
  • Set realistic commitments with evidence behind them, especially if you plan to use ESG messaging in tenders, investor updates or marketing.
  • Assign ownership, reporting lines and review dates so the policy is actually used.
  • Check whether any part of the policy creates extra obligations for your business or promises that could be challenged later.

What This Means For Your Business

For UK businesses, building an ESG policy that works means creating a document that matches how the business really operates and what it can genuinely deliver. It is not just about values. It is about putting legal, commercial and operational expectations into a format your team can use.

ESG usually stands for environmental, social and governance. In practice, those three areas can cover very different issues depending on the business.

  • Environmental issues might include energy use, packaging, waste, emissions, procurement choices or travel practices.
  • Social issues might include workplace culture, equality, health and safety, anti-harassment, modern slavery checks, customer treatment, accessibility or supply chain standards.
  • Governance issues might include decision-making, conflicts of interest, whistleblowing, anti-bribery controls, record keeping, board oversight, data handling and policy compliance.

A small software startup and a manufacturer will not need the same ESG policy. A business selling online across the UK may focus on privacy, supplier due diligence and governance controls. A food producer may need stronger environmental and supply chain sections. A growing employer may need more detailed social commitments around recruitment, employment contracts, workplace conduct and reporting concerns.

This is where founders often get caught. They assume ESG is mainly for large listed companies. That is not really how it plays out in the market. Even where a smaller business is not subject to formal mandatory reporting, ESG still shows up through customers, procurement processes, investor questions, lender due diligence, recruitment expectations and supply chain pressure.

An ESG policy can also affect legal risk. If your policy says you vet suppliers for labour standards, reduce environmental impact, protect whistleblowers or handle personal data in a certain way, those statements should line up with what your business actually does. If they do not, the gap can create problems in a few different places.

  • Customers or commercial partners may rely on your statements in tenders or contracts.
  • Investors may ask for evidence before investing or during due diligence.
  • Employees may expect internal processes promised by the policy.
  • Public claims can raise misleading advertising or greenwashing concerns if they are exaggerated.

A good policy therefore sits alongside other core business documents. Depending on the business, that may include:

  • your business structure and internal approvals, especially where directors need to sign off on policy commitments;
  • employment contracts and staff handbook provisions dealing with conduct, equality, whistleblowing, disciplinary issues and health and safety;
  • supplier agreements and procurement terms that require certain standards or reporting;
  • customer terms and contracts, especially where service levels or sourcing claims are part of the deal;
  • privacy notices and internal data procedures if governance commitments include data ethics, cybersecurity or transparency;
  • trade mark and brand strategy if you plan to market ESG-related products, labels or campaigns.

The aim is not to turn one policy into a huge rulebook. The aim is to make the policy clear enough to guide decisions, but grounded enough that the business can stand behind it before you print it, publish it or attach it to a contract.

When This Issue Comes Up

This issue usually comes up when a business is growing, entering new commercial relationships, or making public promises about standards and impact. Many founders do not think about ESG until someone external asks for it.

When customers or procurement teams ask for ESG documents

A common trigger is a tender, supplier onboarding pack or procurement questionnaire. Larger customers often ask SMEs about environmental practices, modern slavery controls, anti-bribery measures, diversity commitments, data handling and governance arrangements.

If you do not have a settled position, teams often rush to produce a policy overnight. That is when generic language and inaccurate promises creep in.

When investors or lenders start due diligence

Investment rounds, funding applications and strategic partnerships often involve questions about governance, decision-making, policies, risk controls and workforce practices. Even if ESG is not the headline issue, weak governance or unsupported claims can undermine confidence.

Before you sign a term sheet or send diligence responses, it helps to know what your policy says and whether the business can evidence it.

When the business wants to market itself as sustainable or responsible

Businesses often create ESG statements when launching greener products, changing packaging, refreshing branding or updating website copy. The legal risk here is not the existence of an ESG policy. The risk is making claims that are too broad, too absolute or impossible to verify.

Words like “sustainable”, “ethical”, “carbon neutral” or “responsibly sourced” should not appear without real support behind them. A policy should help control those claims, not encourage overstatement.

When hiring and culture become more complex

Once a business grows beyond a very small founding team, social and governance commitments need more structure. That can include fair recruitment, equality expectations, reporting channels for concerns, management accountability, flexible working approaches, training and health and safety processes.

An ESG policy is not a substitute for employment contracts or internal workplace policies, but it often acts as the umbrella statement that ties those issues together.

When supply chain risk becomes harder to monitor

Importing goods, outsourcing production, using multiple subcontractors or relying on overseas suppliers can all raise ESG questions. Founders may need to decide what supplier checks are realistic, what contractual standards should apply, and how far the business can responsibly make claims about sourcing.

This matters before you spend money on setup, before you commit to large orders, and before you agree service levels with customers that depend on supplier performance.

Practical Steps And Common Mistakes

The best ESG policy starts with a realistic assessment of what your business does, what risks matter most, and what the business is prepared to monitor. You do not need every possible ESG topic. You need the right ones, expressed clearly and backed by action.

1. Decide the policy’s scope

Start by deciding what the policy is for. Some businesses need a short public-facing ESG statement. Others need a more detailed internal policy that supports tenders, supplier management and board oversight. Sometimes you will need both, with the public version kept shorter and more cautious.

The scope should answer:

  • which parts of the business the policy applies to;
  • whether it covers group companies, contractors and suppliers, or only direct employees;
  • whether it is an internal governance document, an external statement, or both;
  • who approves it and who can update it.

A common mistake is mixing broad aspirations with binding-looking promises. If the policy says every supplier will meet strict standards, but you have no process to check that, the wording needs to be revised or the process needs to be built.

2. Identify the ESG issues that actually matter

Your policy should reflect the business’s real impact and risk profile. A founder-led consultancy may have a modest environmental footprint but significant governance and privacy considerations. A retailer may need stronger supply chain and waste sections. A tech business handling user data may need governance language that connects closely with privacy and cybersecurity controls.

Think about:

  • how the business makes money;
  • where goods or services come from;
  • how many staff you employ and how quickly you are hiring;
  • whether you sell online or through major platforms;
  • whether customers ask for ESG information during registration or contracting;
  • whether your sector has particular licence-style requirements, standards or expected codes of conduct.

Another common mistake is trying to cover everything equally. That usually creates a policy full of general statements and no clear priorities.

An ESG policy should not sit alone. It needs to line up with the documents and processes your business already uses. This is especially important in the UK, where a lot of ESG-related risk appears through ordinary legal documents rather than a single ESG law.

Review whether the policy is consistent with:

  • employment contracts, handbooks and workplace policies;
  • supplier terms, manufacturing agreements and codes of conduct;
  • customer contracts and tender responses;
  • privacy notices, data processing arrangements and internal security procedures;
  • board minutes, shareholder arrangements or delegated authority rules;
  • health and safety documents and incident reporting processes.

If your policy says the business has whistleblowing channels, anti-bribery controls or modern slavery checks, there should be a corresponding process somewhere in the business. It does not need to be complicated, but it does need to exist.

4. Use careful language for public claims

If the policy is public, or likely to be shared with customers, investors or potential hires, wording matters. The main risk is making absolute claims that cannot be proven, or statements that overstate future intentions as current facts.

Safer drafting often means:

  • describing current practices accurately;
  • stating targets as aims rather than guaranteed outcomes, unless they are firmly adopted and measurable;
  • avoiding vague superlatives such as “fully ethical” or “100% sustainable” unless they are genuinely supportable;
  • explaining limitations where relevant, especially around supply chain visibility or evolving data.

Founders sometimes worry that careful wording sounds less impressive. In reality, specific and accurate language usually carries more weight with customers and investors than sweeping claims.

5. Give someone real responsibility

An ESG policy only works when responsibility is allocated. In a smaller business, that might mean one director owns the policy, with team leads responsible for specific sections. In a larger SME, HR, operations, procurement and legal or compliance staff may each own part of the picture.

The policy should spell out:

  • who approves the policy;
  • who monitors compliance;
  • who signs off public ESG statements;
  • who staff can raise concerns with;
  • how often the policy is reviewed.

Without named ownership, the policy often becomes stale within a few months.

6. Make supplier expectations realistic

Many ESG policies talk about responsible sourcing, but supplier controls are only useful if they are practical. A startup placing small orders may not be able to audit every supplier in detail. That does not mean you should say nothing. It means your policy should reflect what you actually require and check.

That might include:

  • basic due diligence before onboarding key suppliers;
  • contract clauses requiring compliance with certain standards;
  • rights to ask questions or request information;
  • escalation steps if concerns arise;
  • a refusal to work with suppliers involved in certain high-risk practices.

This is often where businesses need to align policy language with contracts. If the contract says nothing about labour standards, anti-bribery or data security, the policy may not have much practical effect.

7. Connect ESG with data, privacy and governance

Governance is often the least understood part of ESG, but for many UK businesses it is the section with the most direct legal impact. If your business collects customer or employee data, sells online, uses analytics tools or shares data with third party providers, governance should include realistic statements about data handling and oversight.

That can involve:

  • clear internal accountability for privacy and data protection;
  • staff training on appropriate use of personal data;
  • reporting and escalation for incidents;
  • approval controls for new high-risk tools or vendors;
  • alignment between ESG statements and your privacy notice.

Businesses sometimes publish ambitious governance statements while their internal records, notices and contracts say something different. That inconsistency can create avoidable risk.

8. Review the policy before major growth steps

An ESG policy should not be drafted once and forgotten. Review it when the business changes direction, enters a new market, launches online in a new way, takes on a major customer, hires rapidly, or changes suppliers.

Moments that often justify a review include:

  • before you sign a major customer agreement with ESG warranties;
  • before you respond to a tender or investment due diligence request;
  • before you rebrand around sustainability messaging;
  • before you expand into a higher-risk supply chain;
  • before you adopt new workforce or governance commitments publicly.

A final common mistake is treating ESG as separate from the rest of the business. The policy works best when it is built into contracts, internal approvals, recruitment, privacy and procurement, not left as a stand-alone document on a shared drive.

FAQs

Does every UK business need an ESG policy?

No, not every business is legally required to have a stand-alone ESG policy. But many SMEs still benefit from one because customers, investors, lenders and procurement teams increasingly ask for ESG information and evidence.

Can I copy an ESG policy from another business?

You can use examples for structure, but copying wording is risky. A policy needs to reflect your own operations, contracts, workforce, supply chain and actual practices, otherwise it may create promises you cannot keep.

Is an ESG policy the same as a sustainability policy?

No. Sustainability is usually narrower and often focuses on environmental issues. ESG also covers social and governance topics, such as workplace standards, anti-bribery, whistleblowing, privacy, decision-making and accountability.

Should an ESG policy be public or internal?

It depends on the business. Some businesses keep the detailed policy internal and publish a shorter external statement. If the document will be shared publicly, the wording should be especially careful and evidence-based.

What documents should I check alongside an ESG policy?

Check your supplier contracts, customer terms, employment documents, privacy notices, internal governance approvals, health and safety processes and any public marketing claims. The policy should support those documents, not conflict with them.

Key Takeaways

  • A workable ESG policy for a UK business should reflect real risks, practical operations and clear ownership.
  • The policy should align with your contracts, employment documents, privacy processes, governance arrangements and public claims.
  • Generic wording is a common problem, especially where it creates promises about suppliers, sustainability or internal controls that the business cannot evidence.
  • ESG issues often arise before you sign contracts, respond to tenders, raise investment, hire at scale or publish sustainability messaging.
  • Regular review matters, because the policy should evolve as the business grows, changes suppliers, launches online or enters more regulated markets.

If your business is dealing with how to build an ESG policy that works and wants help with policy drafting, supplier contracts, privacy compliance, and governance documents, you can reach us on 08081347754 or team@sprintlaw.co.uk for a free, no-obligations chat.

Alex Solo
Alex SoloCo-Founder

Alex is Sprintlaw’s co-founder and principal lawyer. Alex previously worked at a top-tier firm as a lawyer specialising in technology and media contracts, and founded a digital agency which he sold in 2015.

Need legal help?

Get in touch with our team

Tell us what you need and we'll come back with a fixed-fee quote - no obligation, no surprises.

Need support?

Need help with your business legals?

Speak with Sprintlaw to get practical legal support and fixed-fee options tailored to your business.