Glossary term

Cluster E · E9

Tier 2

Climate risk register

Definition

A climate risk register is the documented list of an entity’s climate-related risks and opportunities, each with its description, category, time horizon, assessed significance, owner and mitigation. It is not required by name in any standard. It is the working record most entities use to evidence the risk management and strategy disclosures AASB S2 does require.

No governing instrument

· practice ·

Evidences AASB S2 paragraphs 24 and 25

In practice

AASB S2 does not ask for a register. It asks, in paragraph 25, for disclosure of the processes the entity uses to identify, assess, prioritise and monitor climate-related risks and opportunities, and in paragraph 24 for how those processes integrate with the entity’s overall risk management. A register is how most entities show that those processes exist and ran.

The four verbs in paragraph 25 are the register’s column headings, and a register missing any of them fails to evidence the disclosure:

Requirement

What the register must carry

Identify

The risk, described specifically enough to be tested, with its source

Assess

Likelihood, consequence, and the basis for each

Prioritise

A ranking or rating, and the criteria that produced it

Monitor

Owner, review date, and evidence the review happened

Three design decisions determine whether a register survives contact with an assurer.

Integration, not separation. Paragraph 24 asks how climate risk identification integrates with overall enterprise risk management. A climate register maintained by the sustainability function in a separate file, never appearing in the enterprise risk register that goes to the audit and risk committee, is evidence of non-integration. The stronger position is climate risks sitting in the enterprise register, flagged as climate, with the same rating scale as every other risk.

Gross and net. A register that records only residual risk after mitigation hides the exposure. Recording gross risk, the mitigation, and net risk shows the work and matches how the disclosure is expected to read.

Time horizons defined. Short, medium and long term must be defined by the entity and the definitions disclosed. A register with risks assigned to horizons that are never defined cannot support the strategy disclosures.

What the assurer does with it

The register is usually the first document requested for the risk management pillar, because it is the fastest route to whether the process is real. The assurer reads the register against the disclosure and looks for symmetry in both directions: a risk in the register that does not appear in the disclosure, and a risk in the disclosure that is not in the register.

They then test operation, not just existence: version history showing the register changed during the period, review dates that fall inside the period, named owners who can describe their risk when asked, and a board or committee minute recording that the register was considered.

They accept a register integrated into enterprise risk management, with dated reviews, gross and net ratings, and defined horizons. They reject a register created after year end for the engagement, one with no evidence of review, one where every entry is rated identically, and one whose risks are generic enough to belong to any entity in the country.

The tell is specificity: “extreme weather may disrupt operations” is a placeholder; a named site, a named hazard, a defined horizon and a quantified consequence is a risk.

Commonly confused with

The enterprise risk register, where climate risks should ideally live rather than sitting beside it, and with a materiality assessment, which decides what gets disclosed rather than what gets managed. Also confused with the significant judgement register, which records accounting and measurement judgements rather than business risks.

Sources

1

AASB S2 Climate-related Disclosures

AASB

2

ASSA 5010 Timeline for Audits and Reviews of Information in Sustainability Reports under the Corporations Act 2001

AUASB

Review status

Review required

Last reviewed

15 September 2026

Editorial pass, unsigned

Reviewer required

Company secretary and registered company auditor

Next scheduled review

1 July 2027

Part of

Cluster E, Measurement and governance / Governance, board and directors

10 terms on what the board must be able to evidence, what personal exposure directors carry, and how the audit and risk committee engages with the assurer. Governance disclosures sit inside the year-one assurance scope.