The case described below is an anonymised synthesis of situations at two different companies that I was told about recently. Both are generic enough that they could happen at many businesses. And they probably do…
A certain company is carrying out a major development investment: it is expanding its logistics centre, financed in part by the EBRD. The bank, as we all know, has demanding requirements when it comes to due diligence processes. For the purposes of the investment, an ESMS (Environmental and Social Management System) had to be created, wrapped in numerous policies and procedures. The task landed in the sustainability department, and within it with the ESG manager. Not being a specialist in documentation for the EBRD, but having the bank's guidelines, the entire resources of the internet and a company subscription to Copilot at their disposal, they used AI to produce, among other things, a local community relations policy and incident response procedures. The documents were passed on by their superior to the management board office, which prepared a draft resolution adopting them, and the board duly adopted it.
Only nobody read the policy or the procedures. Even the company logo in the documents was an AI-generated image.
The general contractor signed a contract with the company including all its annexes and the supplier code of conduct, and obliged its own subcontractors to comply with them too. Construction of the logistics centre began. A few weeks later, the company received a phone call from a resident of the town where the works were under way. He reported a dangerous situation: the huge lorries delivering materials to the site regularly speed through the town, and that day there had almost been a collision with a passenger car at an intersection.
Only then did the AI-authored procedures come face to face with reality. It turned out that nobody knew what to do. What steps should the company take to get the general contractor to accept responsibility for the actions of its subcontractors? Should the subcontractors be given additional training? How to make sure their drivers drive safely? Who should be informed about the incident, and in what form? Who is to put forward recommendations, who is to take the decisions, and who is to carry them out? Everything was settled and resolved in the end, but it took numerous internal meetings and consultations, and frayed a lot of nerves among the people involved.
I see several issues in this case that are worth reflecting on:
- Policies and procedures as documents created only because somebody requires them. That was the approach taken by the ESG manager in question, and above all by everyone above them, right up to board level. I understand where it comes from (proceduritis is infecting more and more of almost every area of our lives), but sometimes it is worth going back to what actually matters: writing policies that are as short and simple as possible, and procedures that are specific and tailored enough to speed up what we do in recurring situations. An incident report from the local community, working out who should be notified and about what, who should take decisions and under what arrangements, and who is responsible for implementing them - all of that should be in the procedure, so that the work is faster and simpler when a specific case arises.
- No accountability for the impact on the outside world. In this case there was no accident. But a day or a week from now a child could be killed under the wheels of a lorry. In such a case the driver would certainly have to be regarded as the direct perpetrator. But to what extent did the subcontractor, the general contractor and the company contribute to increasing the likelihood of that accident? After all, nobody made sure that driving safely mattered to the driver just as much as (if not more than) delivering on time. And that falls directly on the decision-makers in every company in this value chain, starting with the company's own management board.
- No human oversight of the output of work done with AI. Nobody in the entire document creation process read the policy or the procedure. Even a single glance would have been enough to establish that the documents needed verifying (a generated picture instead of the logo). The ESG manager did not read what Copilot had produced, their superior passed the documents on to the management board office without a moment's thought, the person responsible for supporting the board prepared a resolution introducing the new rules without reading them, and the board simply adopted it without familiarising itself with the content. That is at least four control points, and not one of them worked. I wonder what conclusions will come out of the audit carried out by the internal control function, assuming the company has such a function at all.
Here is a short exercise for you: consider which of the factors described above are present in your own companies. If they cannot occur, what is it that prevents them? And if they do occur, what can you do to eliminate them? You can treat this as part of strengthening your due diligence processes 😊
P.S. (1) I wrote about this a week ago, but it does no harm to repeat it: entries for the Sustainability Reports competition organised by the Responsible Business Forumare open until 9 September. This is already the twentieth edition of the largest and oldest competition in Poland in which you can have your report assessed. It is well worth it!
P.S. (2) And one more reminder: in September, the UN Global Compact Network Poland is organizing four-day training course Sustainability in Practice. The individual sessions take place on 1, 2, 16 and 17 September. You can sign up for the whole course or for a selected day. The programme is excellent and packed with presentations and workshops delivered by outstanding speakers. As part of this course, on 16 September, together with Marta Kęsik, I will present a practical approach to the simplified ESRS.