Glossary›Measurement and governance / Governance, board and directors›Climate risk register
Glossary term
Cluster E · E9
Tier 2
Climate risk register
Definition
A climate risk register is the documented list of an entity’s climate-related risks and opportunities, each with its description, category, time horizon, assessed significance, owner and mitigation. It is not required by name in any standard. It is the working record most entities use to evidence the risk management and strategy disclosures AASB S2 does require.
No governing instrument
· practice ·
Evidences AASB S2 paragraphs 24 and 25
On this page
In practice
AASB S2 does not ask for a register. It asks, in paragraph 25, for disclosure of the processes the entity uses to identify, assess, prioritise and monitor climate-related risks and opportunities, and in paragraph 24 for how those processes integrate with the entity’s overall risk management. A register is how most entities show that those processes exist and ran.
The four verbs in paragraph 25 are the register’s column headings, and a register missing any of them fails to evidence the disclosure:
Requirement
What the register must carry
Identify
The risk, described specifically enough to be tested, with its source
Assess
Likelihood, consequence, and the basis for each
Prioritise
A ranking or rating, and the criteria that produced it
Monitor
Owner, review date, and evidence the review happened
Three design decisions determine whether a register survives contact with an assurer.
Integration, not separation. Paragraph 24 asks how climate risk identification integrates with overall enterprise risk management. A climate register maintained by the sustainability function in a separate file, never appearing in the enterprise risk register that goes to the audit and risk committee, is evidence of non-integration. The stronger position is climate risks sitting in the enterprise register, flagged as climate, with the same rating scale as every other risk.
Gross and net. A register that records only residual risk after mitigation hides the exposure. Recording gross risk, the mitigation, and net risk shows the work and matches how the disclosure is expected to read.
Time horizons defined. Short, medium and long term must be defined by the entity and the definitions disclosed. A register with risks assigned to horizons that are never defined cannot support the strategy disclosures.
What the assurer does with it
The register is usually the first document requested for the risk management pillar, because it is the fastest route to whether the process is real. The assurer reads the register against the disclosure and looks for symmetry in both directions: a risk in the register that does not appear in the disclosure, and a risk in the disclosure that is not in the register.
They then test operation, not just existence: version history showing the register changed during the period, review dates that fall inside the period, named owners who can describe their risk when asked, and a board or committee minute recording that the register was considered.
They accept a register integrated into enterprise risk management, with dated reviews, gross and net ratings, and defined horizons. They reject a register created after year end for the engagement, one with no evidence of review, one where every entry is rated identically, and one whose risks are generic enough to belong to any entity in the country.
The tell is specificity: “extreme weather may disrupt operations” is a placeholder; a named site, a named hazard, a defined horizon and a quantified consequence is a risk.
Commonly confused with
The enterprise risk register, where climate risks should ideally live rather than sitting beside it, and with a materiality assessment, which decides what gets disclosed rather than what gets managed. Also confused with the significant judgement register, which records accounting and measurement judgements rather than business risks.
Sources
1
2
ASSA 5010 Timeline for Audits and Reviews of Information in Sustainability Reports under the Corporations Act 2001
AUASB
Review status
Review required
Last reviewed
15 September 2026
Editorial pass, unsigned
Reviewer required
Company secretary and registered company auditor
Next scheduled review
1 July 2027
Part of
Cluster E, Measurement and governance / Governance, board and directors
10 terms on what the board must be able to evidence, what personal exposure directors carry, and how the audit and risk committee engages with the assurer. Governance disclosures sit inside the year-one assurance scope.
Related terms
The paragraph 24 and 25 disclosures the register exists to evidence
The body whose minutes must record the register was considered
The separate record of measurement judgements, often confused with this one
Related questions
What governance evidence does the assurance provider look for?
−
Evidence that the governance you described actually happened: board and committee minutes and papers showing climate was considered, terms of reference allocating oversight, the delegation to management, and dated records of the decisions you disclose. Governance disclosures are assured from year one, so the paper trail matters immediately.
What will our auditor actually ask for?
+
In year one they ask for evidence behind the disclosures that are actually assured: Scope 1 and Scope 2 emissions, your governance disclosures, and the specified strategy paragraphs on climate risks and opportunities. In practice that means source documents, a calculation they can rebuild from those documents, and minutes showing the governance you described actually happened.
What is the materiality threshold for climate disclosures?
+
There is no prescribed number. Under AASB S2, information is material if omitting or misstating it could reasonably be expected to influence users’ decisions. Separately, your assurance practitioner sets a quantitative materiality for testing, and the two are related but different.
Other terms in this cluster
Climate risk register