OECD Guidelines for Multinational Enterprises on Responsible Business Conduct (2023 Update)
Environment

OECD Guidelines for Multinational Enterprises on Responsible Business Conduct (2023 Update) OECDMNE-5: Environment, Climate, and Biodiversity

Adhere to OECD MNE Guidelines Chapter VI (Environment) covering environmental management + climate + biodiversity per the 2023 Update reinforcement. MNEs should (a) establish and maintain a system of environmental management appropriate to the enterprise including collection and evaluation of adequate and timely information regarding the environmental + climate + and biodiversity impacts of their activities + (b) align greenhouse gas emission targets with the goal of limiting global warming to 1.5 degrees Celsius above pre-industrial levels + (c) take appropriate action to address actual and potential adverse impacts on biodiversity + (d) provide the public and workers with adequate + measurable + and verifiable information on the potential environment + health and safety impacts of the activities of the enterprise + (e) consult and communicate with the communities directly affected by the environmental + health and safety + (f) maintain contingency plans for preventing + mitigating + and controlling serious environmental + health and safety damage including accidents and emergencies + (g) continually seek to improve corporate environmental performance + (h) provide adequate education and training to workers in environmental + health and safety matters + (i) contribute to the development of environmentally meaningful and economically efficient public policy. Climate and biodiversity must address (a) science-based targets + transition plans + (b) Scope 1 + 2 + 3 emissions accounting per GHG Protocol + (c) disclosure aligned with TCFD + IFRS S2 + ESRS E1, (d) biodiversity impact assessment + dependency analysis + (e) just transition planning for workforce and communities.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 177 controls across 79 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 6 controls

API 1164 · 5 controls

  • API1164-07 Remote Access
  • API1164-21 TSA Pipeline Security Directive Alignment
  • API1164-22 Configuration management for OT systems
  • API1164-23 Change management procedures
  • API1164-24 Vulnerability assessment for critical systems
  • Ene 01 Reduction of Energy Use and Carbon Emissions
  • Hea 02 Indoor Air Quality
  • LE 03 Ecological Value and Biodiversity
  • Man 03 Responsible Construction Practices
  • Mat 03 Responsible Sourcing of Materials

IEC 62443 · 5 controls

  • IEC62443-07 Personnel risk assessment
  • IEC62443-21 Supply chain risk management for critical components
  • IEC62443-22 Configuration management for OT systems
  • IEC62443-23 Change management procedures
  • IEC62443-24 Vulnerability assessment for critical systems
  • NIST-CSF-GV.RM-07 Strategic opportunities (i.e., positive risks) are characterized and are included in organizational cybersecurity risk discussions
  • NIST-CSF-GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders
  • NIST-CSF-ID.AM-04 Inventories of services provided by suppliers are maintained
  • NIST-CSF-ID.RA-09 The authenticity and integrity of hardware and software are assessed prior to acquisition and use
  • NIST-CSF-ID.RA-10 Critical suppliers are assessed prior to acquisition
  • ISO-20400-7.2 Integrating sustainability into specifications
  • ISO-20400-7.3 Supplier selection
  • ISO-20400-7.4 Contract management and review
  • ISO-20400-7.5 Reviewing and learning

ISO 26000:2010 · 4 controls

  • ISO-26000-6.5.1 Prevention of pollution
  • ISO-26000-6.5.3 Climate change mitigation and adaptation
  • ISO-26000-6.5.4 Protection of the environment and biodiversity
  • ISO-26000-6.6 Fair operating practices

ISO/IEC 23894:2023 · 4 controls

  • ISO23894-6.3 AI Risk Assessment
  • ISO23894-6.3.1 AI Risk Identification
  • ISO23894-6.3.3 AI Risk Evaluation
  • ISO23894-A.6 AI System Security

ISO/IEC 27003:2017 · 4 controls

  • ISO27003-4.2 Understanding the needs and expectations of interested parties
  • ISO27003-6.1 Actions to address risks and opportunities
  • ISO27003-8.1 Operational planning and control
  • ISO27003-8.2 Information security risk assessment

ISO/IEC 27019:2024 · 4 controls

  • ISO27019-07 Personnel risk assessment
  • ISO27019-22 Configuration management for OT systems
  • ISO27019-23 Change management procedures
  • ISO27019-24 Vulnerability assessment for critical systems

NIST SP 1800-32 · 4 controls

  • C13 Target Recalculation
  • C18 No Offsetting of Targets
  • C19 BVCM Reporting
  • SBTONE-5 Beyond Value Chain Mitigation (BVCM) and No Offsetting
  • CPS230-11 Identification, Assessment and Management of Operational Risk
  • CPS230-27 Identification and Escalation of Incidents and Near Misses
  • CPS230-49 Internal Audit Review of Proposed Critical Operation Outsourcing

BSI IT-Grundschutz · 3 controls

  • BSI-13 Risk assessment procedures
  • BSI-15 Security categorization
  • BSI-17 Continuous monitoring strategy
  • ISO-14064-3-5 Selecting the validator/verifier
  • ISO-14064-3-8 Assessing GHG data and information
  • ISO-14064-3-9 Evaluating GHG assertions

ISO/IEC 29134:2023 · 3 controls

  • 29134-1 Scope
  • 29134-3 Terms and definitions
  • 29134-9.1 PIA report structure

South Korea ISMS-P · 3 controls

  • ISMSP-MS-02 Risk Management
  • ISMSP-PI-03 Third-Party Provision and Outsourcing
  • ISMSP-SYS-04 Vulnerability Management
  • AEO-2 Demonstrated Compliance with Customs Requirements
  • AEO-4 Financial Viability
  • CPG-6.A Vendor and Supplier Incident Reporting
  • CPG-6.B Supply Chain Incident Reporting
  • IS.D.OR.205 Information Security Risk Assessment
  • IS.I.OR.205 Information Security Risk Assessment
  • CJIS-17 Risk Assessment
  • CJIS-19 Supply Chain Risk Management
  • Sapin2-Pillar3-Risk-Mapping Pillar 3 - Corruption Risk Mapping (Cartographie des Risques)
  • Sapin2-Pillar4-ThirdParty-DueDiligence Pillar 4 - Third-Party Due Diligence (Clients, Suppliers, Intermediaries, M&A)
  • ICAO-ANX17-Chap2-ThreatAssessment-RiskManagement-Cyber-GASeP ICAO Annex 17 Chapter 2 - Threat Assessment + Risk Management + Cyber Threats to Critical Aviation Systems (Amendment 17/18)
  • ICAO-ANX17-Chap4-Cargo-Mail-Catering-Stores-Supplies-RegulatedAgent-KnownConsignor ICAO Annex 17 Chapter 4 - Cargo + Mail + Catering + Stores + Supplies Security + Regulated Agent + Known Consignor + Supply Chain
  • A.1 Point-of-Care Testing Additional Requirements
  • ISO-15189-6.8 Externally provided products and services
  • ISO28001-PC-03 Supply Chain Incident Reporting
  • ISO28001-PC-04 Supply Chain Continuity Planning
  • 27557-4.3 Individual impact consideration
  • 27557-6.3 Privacy risk assessment
  • OECDAI24-1 Updated AI System Definition, Foundation Models, and Generative AI Scope
  • OECDAI24-3 Frontier Model Risk Management, Capability Disclosure, and Independent Evaluation
  • DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management
  • DSOMM-4 Test and Verification - SAST, DAST, IAST, SCA, Penetration Testing
  • ASTWO-1 Audit Planning, Scaling, Risk Assessment, and Integration
  • ASTWO-3 Entity-Level Controls and Period-End Financial Reporting Process
  • 2.4.4 Hazard Analysis and Risk Assessment
  • 2.7.2 Food Fraud Plan
  • IM8-SEC.4 Vulnerability Management
  • IM8-TPM.4 Supply Chain Risk Management
  • CH-FADP-21 Data protection impact assessments
  • FADP-7 Data Protection Impact Assessment (Articles 9-10)
  • CRM-1 AML/CFT Compliance
  • CRM-4 Business Risk Assessment
  • CFR211-J-184 Section 211.184 - Component, Drug Product Container, Closure, and Labeling Records
  • AMLCTF-PartA-RiskAssess ML/TF Risk Assessment
  • AS9100D-8.4 Control of Externally Provided Processes, Products, Services
  • 4.3.1 Risk Assessment and Impact Analysis
  • ACQ.4 Supplier Monitoring

Bahrain PDPL · 1 control

  • BB-DPA-20 Sections 50-60 - Registration and Responsibilities
  • FLA-Principle.7 Health, Safety, and Environment (FLA Workplace Code Principle 7)
  • UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21)

GDPR · 1 control

  • 60601-1.13 Hazardous situations and fault conditions
  • ISO-22313-8.2 Business impact analysis and risk assessment

ISO 22316 · 1 control

  • ISO22316-14 Supply chain continuity
  • ISO-26262-3-7 Hazard analysis and risk assessment (HARA)

ISO 27799:2025 · 1 control

  • ISO27799-06 Security management process and risk analysis
  • ISO-41001-8.4 Control of outsourced processes and services
  • ISO-50001-8.3 Procurement

ISO/IEC 27010:2015 · 1 control

  • 27010-15.1 Incident Management

ISO/IEC 27011:2024 · 1 control

  • 27011-5.6 Supplier relationships and telecom supply chain

ISO/IEC 27031:2011 · 1 control

  • 27031-7.2 Resource Requirements

ISO/IEC 29147:2018 · 1 control

  • 29147-5.11 Researcher Safe Harbour and Legal Posture

ISO/TS 22317:2021 · 1 control

  • ISO22317-14 Supply chain continuity

ISO/TS 22318:2021 · 1 control

  • ISO22318-14 Supply chain continuity

NIST SP 800-190 · 1 control

  • NRFCS-2 Risk Assessment, Customer Data Inventory, Classification, and Retail Threat Model
  • OWASPLLM-4 Supply Chain and Vector/Embedding Weaknesses (LLM03 + LLM08)

OWASP Top 10:2025 · 1 control

  • OWASPTOP10-3 A03:2025 Injection Including Cross-Site Scripting
  • AODACAN-2 Accessible Procurement of Goods, Services, Facilities
  • NORWAY-4 DPIA, Privacy by Design, Records of Processing
  • AUPRV-6 Sensitive Information, PIA, Privacy by Design, Children

Privacy Act 2020 · 1 control

  • NZPRV-6 IPP 13 Unique Identifiers, Privacy Impact Assessment, Privacy by Design

South Korea PIPA · 1 control

  • PIPA-CPO-DPO-Privacy-Officer-PIA-Personal-Information-Impact-Assessment-Articles-31-33 Korea PIPA CPO + DPO + Privacy Officer + PIA + Personal Information Impact Assessment + Articles 31-33

Turkey KVKK · 1 control

  • TURKEYKVKK-3 Special Categories and Sensitive Data
  • CPSC-RA.3 Lifecycle Risk Assessment
  • USMCADIGITAL-4 Government Data, Cybersecurity, Interoperability
  • VERMONTAICDA-4 Vermont AG Enforcement and Cure
  • VIETNAMCYBER-4 Incident Reporting and Cooperation

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 177 it maps to, and the evidence behind each claim, over MCP and REST.