> For the complete documentation index, see [llms.txt](https://urd.gitbook.io/compass/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://urd.gitbook.io/compass/evaluating/commitment-4.md).

# Commitment 4

## <mark style="color:orange;">DO PEOPLE AND COMMUNITIES ACCESS SUPPORT THAT DOES NOT CAUSE HARM TO PEOPLE OR THE ENVIRONMENT?</mark>

Evaluating this commitment means assessing whether the organisation identified and managed risks of harm to people and the environment, and whether it practised responsible data and information management to reduce risks (including risks introduced by digital tools and AI-supported processes).

#### **Key evaluative questions:**

1. <mark style="background-color:blue;">**To what extent were potential and actual harms to people identified, prevented, mitigated and addressed?**</mark>

* Risk analysis covering protection, safety, dignity, exclusion, retaliation, stigma, conflict sensitivity, and SEA/harassment risks.
* Evidence of mitigation actions
* Community perceptions of safety and dignity in accessing support.
* Incident data and response actions (including safeguarding incidents, security incidents, and harmful unintended effects.

2. <mark style="background-color:blue;">**To what extent were environmental harms identified, prevented, mitigated and addressed?**</mark>

* Environmental risks screening and mitigation measures (waste, water, energy, procurement impact, biodiversity/land impacts).
* Evidence of monitoring environmental risks and adapting operations.&#x20;
* Community perceptions of environmental impacts (where relevant).

3. <mark style="background-color:blue;">**To what extent were data and information managed safely, ethically, and effectively to minimise risk to people and communities?**</mark>

* Evidence of data minimisation (only collected what was needed).
* Safeguards for sensitive data (access control, encryption where feasible, safe sharing)
* Practical consent/notice and accountability, people know what data is collected and why, and how to raise concerns.
* Documentation of where AI/digital tools influenced decisions, checks for bias and exclusion, and mitigation measures.
