What is a climate risk assessment under AASB S2?
A climate risk assessment (CRA) is the structured process by which you identify, rate and document the physical and transition climate risks and opportunities facing your business. AASB S2 does not use the term and does not require you to run one. What it requires is a set of disclosures that you cannot produce without something like it, which is why the CRA is the workstream that sets the timetable for the whole ASRS report. It is also the workstream that most differs from what an existing enterprise risk process already produces, because of two layers a standard risk register does not have.
What this means in practice
Nothing in AASB S2 mandates a climate risk assessment as an artefact. The obligations are to disclose the climate-related risks and opportunities (CRROs) that could reasonably be expected to affect your prospects, to describe the process by which you identify and assess them, and to disclose exposure metrics against them. A CRA is the way those obligations get satisfied in practice, and calling it out as its own workstream is a planning convenience rather than a requirement.
What the CRA actually feeds. This is the part worth internalising, because it explains why the CRA cannot be run as an isolated exercise:
- Strategy. The list of CRROs, each classified as a risk or an opportunity and as physical or transition, with the time horizons over which effects could occur. Then the business model and value chain effects, the strategy response, the anticipated financial effects and the resilience assessment.
- Risk Management. The description of the process itself: the inputs and parameters, the information sources, the scope of operations covered, how likelihood and magnitude are assessed, how climate risks are prioritised relative to other risks, and how they are monitored.
- Metrics. The exposure disclosures at 29(b), (c) and (d), being the amount and percentage of assets or business activities vulnerable to transition risk, vulnerable to physical risk, and aligned with climate opportunities.
So one process produces content for three pillars, and an inconsistency between them is visible. The specific trap: a material risk disclosed under Strategy that the identification process you described under Risk Management would not plausibly have found. Assurance finds that, because the two disclosures are read together.
Two layers a standard risk register does not have.
Scenario dependency. Each risk is assessed under more than one climate pathway, and the ratings are expected to move between them. A register with one rating per risk cannot support the disclosure. Which scenarios to use, and over what horizons, is covered here.
Financial effect. Each material risk needs a financial mechanism attached, not just a likelihood and consequence rating.
Adding a climate row to an existing enterprise register gives you neither of these. That is the single most common reason a first-year CRA has to be redone.
What the process has to produce, whatever method you use. Four things, and these are obligations rather than anyone's methodology. A set of CRROs, each classified as risk or opportunity and physical or transition, with time horizons. A rating for each under more than one climate pathway. A materiality determination you can articulate, covered here. And, for every risk you determine to be material, a resilience response and a financial effect. Any method that gets you those four is compliant. How Trace sequences the work, and how long to allow, is set out in the approach section below.
The document that records all of this, with assumptions, management sign-off and a methodology appendix, is the thing an assurance provider actually works from.
Year 1 assurance covers the risk list, not the process, and this catches people out. In your first reporting year, limited assurance covers governance, the identification and classification of CRROs, and Scope 1 and 2 emissions. The Risk Management process disclosures are outside that scope. In practice an assurance provider cannot get comfort on your list of risks without understanding how you produced it, so expect questions about method, inputs, and who did the rating, even though the process disclosure itself is not being assured this year. Plan the CRA as though the method is in scope.
What evidence you need
Built from what assurance providers actually ask for on a CRA walkthrough:
- The long list of risk, and an explanation of how these candidate risks were generated
- Your rating scale, written down. What "possible" and "likely" actually mean, and what each consequence level is in dollar, operational, safety or reputational terms. Without the scale defined, a rating is an opinion rather than an assessment, and nobody can check whether it was applied consistently across the register
- The reasoning behind each rating. For every risk, the inputs you relied on and how they produced the score: which climate projection or dataset, which assumption about the business, whether likelihood came from a single central view or from several reference scenarios. If a rating exists only inside a system, export it, because an assurer will ask to be walked through a derivation and a screen they cannot navigate does not answer the question
- The narrowing from long list to short list, and the materiality overlay applied, stated as a method rather than an outcome
- A risk register with separate likelihood and consequence columns, shown before the final materiality rating so the derivation can be followed
- The basis for the likelihood rating, including whether a single house view or several reference scenarios informed it
- A record of when and how the business was involved, and of the validation and review steps: workshop attendance, the review round, who signed off
- A minuted or otherwise documented record of management validating the risk list and the outcome. This matters more, not less, where the risks are rated low, because a low-rated risk would not normally reach a governance body through the usual process and the disclosure is what takes it there
- A methodology document covering scenarios, horizons, threshold and rationale, attached as an appendix
Common mistakes
- Starting the CRA less than three months before lodgement. The analysis is not the constraint. Getting senior people into a room, and getting the outputs reviewed, is.
- Running it as a sustainability team exercise. If business unit owners did not rate the risks, the disclosure describes a process the business does not recognise, and the validation evidence does not exist.
- Reusing the enterprise risk register unchanged. No scenario dimension and no financial mechanism means it cannot support the Strategy or Metrics disclosures.
- A material risk that your stated process would not have found. This puts Strategy and Risk Management in conflict, and it is the inconsistency assurance is most likely to surface.
- Ratings that exist alone. If you cannot walk someone through how a rating was derived, the rating is hard to assure regardless of whether it is right.
- Disclosing something rated below your own threshold. An assurer reading the register against the report will ask why it is there. Either the rating is wrong or the inclusion is.
- No record of management validating the list. The most commonly missing single artefact, and the cheapest to create at the time.
Trace's viewpoint and approach
Treat the CRA as an evidence-generating process. What determines whether the disclosure survives assurance is whether the derivation is visible: long list, ratings, narrowing, threshold, validation, sign-off, each recorded as it happened.
How we sequence it. Six phases, and we allow three to four months for a first assessment. The elapsed time is driven by getting the right people in a room rather than by the analysis itself, which is why compressing it usually costs you the validation evidence rather than the answer.
- Desktop review. Company documents, strategy, existing risk registers, peer disclosures and sector risk sources.
- Long list generation and contextualisation. A broad set of candidate risks and opportunities derived from the business model, the sector and climate science, before any filtering. Each one is then contextualised to your business rather than left generic, by pairing your own operating data with external climate metrics for the places you actually operate.
- Stakeholder validation. A workshop or structured review with business unit owners and senior management, to rate the risks and to establish that the business owns the assessment.
- Scenario overlay. Mapping each risk across the chosen pathways and time horizons.
- Materiality determination. Applying the risk appetite statement or the agreed threshold, and documenting the rationale for every risk, including those below it.
- Risk register finalisation. The full register with ratings, and resilience and financial effect documented for every material risk.
The order matters more than it looks. Generating a long list before any filtering, rather than starting from the risks people already have in mind, is what produces coverage. Filtering first feels efficient and it is how an assessment ends up describing the risks the business was already worried about.
For a physical risk that means figures such as days per year above the heat threshold at which labour productivity starts to fall, modelled productivity loss, fire season length and extreme fire weather days, drought index, extreme five-day rainfall, river discharge and surface runoff, for the specific state or region rather than for Australia as a whole. For a transition risk it means carbon price, the national emissions reduction trajectory, electricity price movement, technology uptake rates and the trend in climate litigation. The regional physical projections come from bodies such as CSIRO and the Bureau of Meteorology and the Climate Impact Explorer; the transition and policy figures from sources including the NGFS scenarios, AEMO, the IEA and the Climate Change Authority.
The effect is that a risk arrives at the workshop with numbers against it. Rather than asking whether heat is a risk, the question becomes whether a move from the present number of high-heat days to the projected number at 2050 changes what you would do, which is a question the business can actually answer.
What contextualising a risk means in practice. A generic risk statement cannot be rated, because there is nothing in it to rate. So each candidate risk is attached to the business data that makes it real, being the sites, regions, asset types, workforce and supply chain it actually bears on, and then to quantified climate metrics for those locations. Each metric carries a present-day value and a projected value under both pathways at each time horizon, with the source named and a commentary recording the assumptions and any extrapolation.
Why the process is worth facilitating rather than self-serving. Two parts of it are genuinely hard without someone who does this repeatedly. The first is coverage: knowing which risks a business in your sector is exposed to but has not thought of, which is a knowledge problem rather than an effort problem, and a gap here is invisible to you by definition. The second is rating consistently across pathways and horizons, which requires a working sense of what actually changes between a 1.5°C world and a 3°C one, for your assets, in your region.
The contextualisation step is where that shows most. Choosing which metric a given risk actually turns on, finding it at the right geographic resolution, and reading whether its movement between now and 2050 is material for your operations is judgement work, and it is also where the projections have to be handled carefully, because units and baselines differ between sources and a metric misread produces a rating that is confidently wrong.
Both are exactly where assurance probes. An assurance provider will ask how the universe of risks was generated and how you narrowed it, and a long list that looks like the contents of a management meeting invites the question of what was missed. A facilitated process gives the people rating the risks the climate and sector context to rate them properly, and it produces a derivation that answers the coverage question before it is asked.
Get the business to rate the risks, not just the sustainability function. That single choice produces the validation evidence, the internal consistency and the resilience content, and no amount of later documentation substitutes for it.
Plan on the method being examined even though the process disclosure is not assured in year one. The cost of assuming otherwise is a walkthrough you cannot answer.
Frequently asked questions
Q: We already have a TCFD report. Can we use it? Often yes, at least as a foundation. The test is whether it covers pathways consistent with what AASB S2 requires, whether the horizons and scope of operations match what you intend to disclose, and whether it goes to financial effect rather than stopping at a risk list. Where it does, map each identified risk to the relevant findings, add analysis for risks it did not cover, and document why the existing work is appropriate. Where it does not, it is still a strong starting long list. There is more on reusing third-party analysis here.
Q: Do we need to redo the full CRA every year? No. AASB S2 requires annual disclosure, not an annual reassessment from scratch. From year two the normal approach is to review and update: confirm the risks are still the right ones, check whether ratings should move given new climate data or a changed footprint, add anything new, and update the resilience content. The Risk Management disclosures also ask whether and how your process has changed since the prior period, so keep a record of what you altered and why.
Q: How long does a CRA actually take? Allow 4-8 weeks for a first one. Compressing it is possible and the thing that gets sacrificed is the stakeholder validation, which is the part that generates the evidence. If you have less time than that, the better trade is a narrower scope of operations, clearly disclosed, rather than the same scope assessed without the business in the room.
Q: Who needs to be involved from our side? Whoever can speak to the exposure: operations, property or assets, procurement or supply chain, finance, and risk or legal. Finance matters more than people expect, because the financial effect and exposure metrics come out of this process rather than being added later. The oversight body does not need to be in the workshop, but it does need to see the output.
Q: Does a low-rated risk go in the report? Not as a disclosed material risk. Keep it on the register with the rationale for why it sits below the threshold, because assurance providers commonly ask for the full long list with a determination against each item. Where something below the threshold is genuinely being pursued or managed, the place for it is the strategy narrative rather than the material risk table.