What materiality threshold should you use?
AASB S2 prescribes no numeric threshold for deciding which climate-related risks and opportunities (CRROs) are material, so you choose one and document why. The strongest anchor is your board-approved risk appetite statement (RAS), because it is already approved, already documented, and it ties the climate assessment to the risk framework the business actually runs on. Where there is no RAS, a written qualitative threshold is fully compliant. What is not compliant is a threshold you cannot articulate, and the failure mode we see is not choosing the wrong threshold but being unable to evidence that a deliberate decision was made
What this means in practice
Information is material if omitting, misstating or obscuring it could reasonably be expected to influence the decisions of users of the general purpose financial report. That is a qualitative standard, and it is the same standard across the ASRS regime as a whole. There is no percentage, no dollar figure and no minimum count of risks, and there will not be one.
So the question is not what the right threshold is. It is which anchor you use, and whether the judgement is recorded.
Anchor 1: your risk appetite statement. Apply the board-approved RAS to the climate risk list. A risk that exceeds appetite is material for disclosure. This is the strongest option available, for a reason that has nothing to do with climate: the threshold was set by the board in advance, for the business as a whole, and applying it to climate risk is consistent rather than bespoke. It also directly supports the Risk Management requirement to explain how climate risks are prioritised relative to other risks.
Two practical points about using a RAS this way.
Most risk appetite statements contain categories where the stated appetite is none, phrased as no appetite or zero tolerance, usually for safety, compliance, or regulatory breach. Those bands need handling explicitly rather than being skipped, because read literally they make any risk touching them material. The usual resolution is to assess against the appetite for the consequence as it actually arises rather than the category label, and to record that reasoning. Do not leave it implicit.
If the RAS is in draft, you can still use it. Apply the version that was current at the time of the assessment and disclose its status.
Anchor 2: a documented qualitative threshold. Where there is no RAS at all, set a rating threshold, for example every risk rated high or above, and write down why that level. This is compliant. It is a weaker anchor than a board-approved RAS only in the sense that the threshold was set for this exercise rather than in advance, which an assurance provider may probe. A short written justification closes that gap.
The order of preference is: board-approved RAS, then draft RAS with its status disclosed, then a documented qualitative threshold. All three work. What does not work is applying a threshold nobody wrote down.
Handling risks at the boundary. Where a risk plausibly falls into two consequence categories, for example both reputational and regulatory, assess it against both and take the more conservative outcome. Then state the result, because the resolution is the part people omit:
"This risk was assessed against both the reputational and regulatory risk appetite categories. The more conservative regulatory threshold was applied, and the risk was classified as material."
A boundary case that records the reasoning but not the resulting classification leaves the reader to infer the answer, and it is the classification that the disclosure has to match.
How many material risks is normal. The number is an output of the threshold, not an input, so the thing to avoid is picking a count and working backwards to a threshold that produces it. For context: most Australian entities land somewhere between about three and eight material CRROs. Services businesses with small physical footprints sit at the lower end. Asset-heavy, property and agricultural businesses sit higher. A number well outside that range is not wrong, but it is worth re-reading the threshold and the long list before you commit to it.
Zero is the answer to avoid. Disclosing no material climate risks is hard to sustain, both because it is an unusual conclusion that will draw questions and because the surrounding disclosures then have nothing to describe. Assurance providers have said as much: a small number of genuinely medium-rated risks with credible resilience narrative is a stronger disclosure than none. For a small subset of later-cohort entities there is a formal route for a no-material-risk position, and it is narrow and separately reviewed.
Do not confuse materiality with the exposure metrics. Materiality decides which CRROs are disclosed under Strategy. The exposure metrics at 29(b), (c) and (d) are separate: an amount and percentage of assets or business activities vulnerable to transition risk, vulnerable to physical risk, and aligned with opportunities. They are not a loss calculation and they are not driven by your materiality threshold.
What to do with the risks below the line. They stay on the register with a rationale, and they stay out of the disclosed material risk table. Providing the full long list with a determination against each item is normal practice and it is the fastest way to answer assurance questions. Two things to avoid: including a sub-threshold item in the disclosure without explanation, and applying one threshold to risks and a different one to opportunities without saying so.
What evidence you need
- The RAS or threshold document as it stood at the time of the assessment, version-dated
- A written statement of the threshold applied and why it was chosen
- The risk register with separate likelihood and consequence columns, shown before the final materiality rating, so a reader can see how you got to the rating
- A one or two sentence rationale against every risk on the long list, including those below the threshold
- A longer note for each boundary case, ending with the resulting classification
- A documented record of management validating the risk list and the materiality outcome. Where risks are rated low, this matters more rather than less, because a low-rated risk would not otherwise reach a governance body
- Where risks and opportunities were assessed against different thresholds, the reason
Common mistakes
- Disclosing zero material risks without a compelling written basis. The hardest position to hold and the one most likely to attract questions.
- Targeting a number. Deciding you want three or four material risks and then working backwards to a threshold that delivers them. It shows, because the threshold cannot be justified independently.
- Disclosing something your own register rates below the threshold. Assurers read the register against the report and ask why it is there. It is a genuine internal inconsistency, and the fix is to correct one or the other before lodging, not to explain it afterwards.
- A combined rating with no separate likelihood and consequence columns. How the rating was arrived at is then invisible, and separating them is a specific and repeated assurance request.
- Skipping the no-appetite bands in the RAS. Read literally they make almost everything material. Address them and record the reasoning.
- Documenting the boundary-case reasoning but not the outcome. The classification is the part the disclosure has to be consistent with.
- Different thresholds for risks and opportunities, undisclosed. Defensible if explained, an inconsistency if not.
- Verbal management sign-off. The determination was made and nothing evidences it.
Trace's viewpoint and approach
Choose the anchor once, write down why, and apply it to every risk including the ones that fall below it. Almost every materiality finding we see is a documentation failure rather than a judgement failure: the decision was reasonable and cannot be evidenced.
Prefer the risk appetite statement wherever one exists, even an imperfect one. Its value is that the board set it before anyone was thinking about climate, which makes it much harder to characterise as reverse-engineered.
Where there is no RAS, do not treat that as a blocker to the assessment. A written qualitative threshold is compliant, and it is a better use of the time than pausing the CRA to build a risk appetite framework you were not otherwise going to build this year.
Keep the full long list with a determination against every item. It is the single document that answers the largest number of assurance questions without a meeting, and it costs nothing extra if it is maintained as you go rather than reconstructed.
Frequently asked questions
Q: We do not have a Risk Appetite Statement. What do we use? A documented qualitative threshold, for example every risk rated high or above, with a short written justification for why that level is appropriate given your business. This is compliant and it is what many first-year reporters do. If a basic RAS is achievable before the assessment, it is the stronger anchor and worth the effort, but its absence is not a reason to delay the CRA or to leave the threshold unstated.
Q: Our RAS was approved partway through the year. Which version applies? The version in place when the assessment was performed. If the assessment came after approval, use the approved version. If it came before, use the draft and disclose that it was in draft at the time, noting the later approval date. What creates a problem is describing a finalised framework when only a draft existed when the judgement was made.
Q: Can we conclude a risk is not material and leave it out entirely? Yes. Only material CRROs need to be disclosed. Keep the determination on the register with a rationale, because assurance providers routinely ask for the long list including sub-threshold items and the reasoning against each.
Q: How detailed does the rationale for each risk need to be? One or two sentences for a clear case. Two or three for a boundary case, naming the appetite category applied and stating the resulting classification. The point is to show a deliberate judgement was made, not to write an argument.
Q: Our auditor wants the full long list including the risks we determined were not material. Is that standard? Yes, and it is in your interest. It demonstrates that the threshold was applied consistently rather than selectively, and it usually replaces a walkthrough meeting.