What are the four pillars of AASB S2, and what does each require?
The four pillars of ASRS climate reporting are Governance, Strategy, Risk Management, and Metrics and Targets. Governance covers who oversees climate and how that oversight is exercised. Strategy covers your climate-related risks and opportunities and their effect on your business model, your financial position and your resilience. Risk Management describes the process you use to identify, assess, prioritise and monitor those risks. Metrics and Targets carries the numbers. All four are required in your first report, and they are best treated as one disclosure with four sections rather than four separate projects, because the sections have to agree with each other.
What each pillar requires
AASB S2, the climate standard within the Australian Sustainability Reporting Standards (ASRS), organises what you disclose into four pillars. Reading them beside each other is the fastest way to see where each piece of work lands, and why climate risk ends up being its own body of work rather than a paragraph in the risk report.
Governance.
Who oversees climate-related risks and opportunities (CRROs), and how. Beyond naming the responsible body and pointing to its charter, four items get missed more than the rest:
- how the body ensures it has the right skills,
- how and how often it is informed,
- how it takes climate into account in major transactions and target-setting, and
- management's role including any supporting controls.
Governance is the least elastic of the four, because it is tested on evidence rather than analytical sophistication and the evidence has to exist while the reporting period is running. It also sits inside the limited assurance subset in your first reporting year, alongside parts of Strategy and your Scope 1 and 2 emissions.
Strategy.
Strategy is the pillar, a climate risk assessment (CRA) is how you satisfy it. It has five parts:
- your CRROs and the time horizons over which they could take effect;
- where those CRROs concentrate in your business model and value chain;
- how climate has affected and will affect your strategy, decision-making, resource allocation and any transition plan;
- the effects on your financial position, performance and cash flows; and an assessment of your climate resilience using scenario analysis.
The assessment supplies the analysis. The strategic response, including capital allocation and any targets, has to come from your board and executive rather than from the assessment.
Risk Management.
The processes and policies you use to identify, assess, prioritise and monitor CRROs, and how those processes sit inside your broader enterprise risk management (ERM) framework.
Three of its requirements are the ones that catch people out:
- how climate risks are prioritised against your other risk types,
- how they are monitored between reporting periods, and
- whether the process has changed since the prior period. This is a description of a process, not a second assessment, which is exactly why it is the pillar most often left out altogether: the underlying work has already happened in Governance and the CRA, so writing it up feels like repeating yourself.
Metrics and Targets.
The numbers behind what the other three pillars describe:
- absolute gross Scope 1, Scope 2 and Scope 3 emissions,
- the cross-industry metrics,
- industry-based metrics,
- and the full requirement set for each target you have.
Those cross-industry metrics run wider than the three exposure metrics most often quoted, being transition risk exposure, physical risk exposure and opportunities, commonly called 29B, 29C and 29D. They also cover capital deployment, internal carbon price and the percentage of executive remuneration linked to climate. Scope 3 can be deferred to your second reporting year. Scope 1 and 2 cannot.
How the pillars depend on each other
The dependencies run in one direction, and that is what makes the four pillars one piece of work rather than four.
Governance comes first, because an assessment with no named owners and nobody to take the decisions is not credible and cannot be evidenced later. The CRA then feeds both Strategy and Risk Management: the same exercise produces the risk and opportunity disclosures in one pillar and the process description in the other. Strategy determines what you have to quantify in Metrics and Targets, because a risk you have named needs either an exposure figure or a stated reason it does not have one. Targets and transition planning sit on top of all of it.
Two consequences are worth planning for from the outset.
A pillar that is strong while the one next to it is thin attracts scrutiny. An assurance provider reads across the pillars, not down one. A detailed scenario analysis sitting beside a two-line process description raises the obvious question of how the risks were found, and a named material risk that carries no exposure metric and no explanation raises the question of whether it was assessed at all. Depth that is uneven for a reason is fine, provided the reason is on the page.
The pillars are rarely held by one team, and that is the mechanism behind most inconsistencies. Governance usually sits with the company secretary, emissions with finance or operations, risk with the risk function, and drafting with whoever is available. The split itself is workable. What is not workable is finding out late in the year that the risk register and the metrics section describe different risks.
What evidence you need
Each pillar carries its own evidence requirements, and they are dealt with pillar by pillar. What belongs alongside all four is the evidence that they were treated as one disclosure.
- A compliance index mapping every applicable AASB S2 paragraph to where it is addressed in your report, including a deliberate statement wherever your position is nil
- A single named owner for the whole climate disclosure, not one owner per pillar, with the cross-pillar review recorded
- A documented check that the risks named under Strategy are consistent with the identification and assessment process described under Risk Management
- A documented check that the risks named under Strategy are reflected in the exposure metrics, with a stated reason wherever a named risk carries no quantified exposure
Common mistakes
- Treating the disclosure document as a checklist. You have to cover every applicable paragraph of AASB S2, but the report is written for investors, not for the standard. Organise around the four pillars, write a concise narrative, and use a compliance index to evidence coverage rather than structuring the document paragraph by paragraph.
- Omitting a disclosure because you cannot evidence a strong position. The requirement is to disclose your position, not to prove it is a good one. Describing a process as immature, or stating that you have no transition plan, satisfies the standard. Saying nothing does not.
- Treating the pillars as four separate documents owned by four separate teams. Governance, strategy, risk and metrics usually sit with different functions, and with no single owner for the disclosure the sections stop agreeing with each other.
- Running the climate risk assessment before governance is settled. The assessment needs named owners and a body to take the decisions, and the point of the exercise is to embed CRROs into your normal risk processes rather than to produce a standalone report.
- Disclosing risks under Strategy that your Risk Management process description would not have found. The two pillars then contradict each other inside the same document, and it is one of the easier findings for an assurance provider to raise.
- Reading transition relief as pillar-level relief. The reliefs apply to specific requirements inside pillars, notably Scope 3 emissions and quantitative financial effects. No relief removes a pillar.
Trace's viewpoint and approach
Treat the four pillars as one disclosure with four sections. The reason is that most serious findings in a climate statement are inconsistencies between pillars rather than gaps inside one, and those are only visible to someone reading all four.
Someone needs to own the whole disclosure rather than a pillar of it. Four competent owners with no single owner above them produce four competent sections that do not agree, and that is an accountability gap rather than a resourcing one.
Proportionality scales depth, not coverage. Minimum viable compliance means every pillar addressed and none of them padded, because voluntary content beyond the standard expands your assurance surface area and sits outside the modified liability protections.
Our support is modular, and whether we run all four pillars with you or some of them, the dependencies between them get mapped before the work starts so the handovers do not become the gap.
We have mapped the four pillars to discrete workstreams, and they are modular by design. You can run all of them with us or take only the ones where you need support, with the rest sitting inside your own team or with your existing advisers.
- Governance Review
- Climate risk and scenario analysis, which feeds both Strategy and Risk Management
- Transition planning, which sits within Strategy
- Emissions measurement
- Metrics and targets, some of which are derived from the other workstreams
- Disclosure drafting, pulling everything together and drafting the report.
Frequently asked questions
Q: Which pillar takes the longest? In Year 1 it is consistently Strategy, because of the climate risk assessment: its stages are sequential rather than parallel, so it cannot be compressed the way a data exercise can, and the timing is set out. In Year 2 the load shifts to emissions, because Scope 3 becomes mandatory and value chain data takes longer to obtain than internal data.
Q: Do we need to disclose all four pillars in Year 1? Yes. Transition relief applies to specific requirements within pillars, notably Scope 3 emissions and quantitative financial effects, not to entire pillars. Proportionality lets a smaller entity address a pillar briefly and qualitatively, with an explanation of why, and that is compliant. A missing pillar is not.
Q: Isn't Risk Management just a repeat of our climate risk assessment? No, and it is the most common misreading of the four. Strategy discloses what your risks and opportunities are and what they mean for the business. Risk Management discloses how you find, rank and monitor them, how climate ranks against your other risks, and how all of that sits inside your existing risk framework. The assessment is evidence for both, but the process description is a separate disclosure and it is frequently left out entirely.
Q: We have limited resources. Which pillar should we prioritise? Governance, because it is the only one that cannot be recovered later. Board and committee records have to be contemporaneous, so oversight that was not documented during the reporting period cannot be evidenced after year end. Emissions data can be reconstructed at a cost, and a risk assessment can be run in a compressed window, but missing governance evidence stays missing.