Glossary›AASB S2 disclosure requirements / AASB S2 mechanics›Risk management disclosures (AASB S2)

Glossary term

Cluster C · C15

Tier 1 · differentiator

Risk management disclosures (AASB S2)

Definition

Risk management is the third AASB S2 pillar. It requires disclosure of the processes the entity uses to identify, assess, prioritise and monitor climate-related risks and opportunities, the inputs and parameters those processes use, and the extent to which they are integrated into the entity’s overall risk management. It discloses process, not outcome.

· paragraphs 24 to 26, with Aus26.1 ·

In force

In practice

This pillar is short in the standard and disproportionately revealing in practice, because a process either ran or it did not and the evidence is dated.

Paragraph 24 sets the objective: users must be able to understand the processes used to identify, assess, prioritise and monitor climate-related risks and opportunities, including whether and how those processes are integrated into and inform overall risk management. Paragraph 25 sets out what that means in three parts.

25(a), for risks, requires the processes and related policies, and specifically: the inputs and parameters used, including data sources and the scope of operations covered; whether and how the entity uses climate-related scenario analysis to inform its identification of risks; how it assesses the nature, likelihood and magnitude of effects, including whether it uses qualitative factors, quantitative thresholds or other criteria; whether and how it prioritises climate risks relative to other types of risk; how it monitors them; and whether and how the processes changed compared with the previous reporting period.

25(b), for opportunities, requires the same process disclosure, including whether and how scenario analysis informs their identification. This is a separate limb and it is routinely left out.

25(c) requires the extent to which, and how, those processes are integrated into and inform the entity’s overall risk management process.

Paragraph 26 then requires the entity to avoid unnecessary duplication, cross-referring to Appendix D paragraph B42(b): an Appendix D citation, not Appendix B. Aus26.1 clarifies that this matters particularly where an entity voluntarily applies AASB S1 as well, so that integrated risk management disclosures replace separate ones for each sustainability topic.

Three things follow for a private business.

Integration is a disclosure, so non-integration is disclosed too. Paragraph 25(c) does not require climate risk to be inside enterprise risk management. It requires the entity to say to what extent it is. A climate risk process running separately from ERM is a compliant answer and an unflattering one, and most boards would rather fix it than publish it.

Two limbs are comparative and only appear from year two. Paragraph 25(a)(vi) asks whether and how the processes changed compared with the previous period. In a first report there is no previous period; from the second, the entity must be able to describe changes, which means the year-one process has to have been documented well enough to compare against.

Prioritisation criteria are the hardest limb. Paragraph 25(a)(iv) asks whether and how climate risks are prioritised relative to other types of risk. Answering it requires a common rating scale across climate and non-climate risks, which is precisely what an entity does not have if its climate risks live in a separate spreadsheet with its own bespoke scoring.

What the assurer does with it

Risk management is not inside the year-one review scope under ASSA 5010 paragraph 10(a), which covers governance, strategy risks and opportunities, Scope 1 and 2, and any no-material-risk statement. It comes into scope from the second reporting year under paragraph 10(b), when the review extends to all disclosures, and moves to audit from the fourth year under paragraph 10(c). That deferral is a planning opportunity, not a reprieve: the year-two review will ask what the process was in year one.

Because the subject matter is a process, the assurer tests operation rather than design. They accept a written process description matched by dated artefacts showing it ran inside the reporting period: workshop records, a risk register with review dates and named owners, minutes recording that climate risks were considered, a rating scale applied consistently across climate and non-climate risks, and a documented data source list matching what the disclosure claims. They reject a process described in the present tense with no evidence it operated during the period, a register created after year end for the engagement, a disclosure claiming integration where the climate risks appear in no document the audit and risk committee ever saw, a prioritisation claim with no criteria behind it, and silence on the opportunities limb at 25(b). The recurring finding is a beautifully documented process that was written for the report rather than used to run the business, and the tell is that every artefact carries a date after year end.

Commonly confused with

The climate risk register, which is a working document most entities use to evidence this pillar and which no standard requires by name. Also confused with the strategy pillar: risk management discloses how risks are found and monitored, strategy discloses what they are and what is being done about them. And confused with internal controls over sustainability reporting, which are the controls over the accuracy of the reported information rather than the processes for managing the underlying business risk. Both matter, and they are tested by different procedures.

Timing and relief

No Appendix C transitional relief applies to the risk management pillar. The practical phasing is in the assurance timetable rather than the standard: reviewed from the second reporting year under ASSA 5010 paragraph 10(b), audited from the fourth under paragraph 10(c). The comparative limbs at paragraph 25(a)(vi) apply only once a previous period exists.

Sources

1

AASB S2 Climate-related Disclosures, compiled to December 2025

AASB

2

ASSA 5010 (January 2025)

AUASB

3

ASSA 5010 Timeline for Audits and Reviews of Information in Sustainability Reports under the Corporations Act 2001

AUASB

Review status

Review required

Last reviewed

15 September 2026

Editorial pass, unsigned

Reviewer required

Registered company auditor

Next scheduled review

1 July 2027

Part of

Cluster C, AASB S2 disclosure requirements / AASB S2 mechanics

25 terms on what the climate disclosure standard actually requires, pillar by pillar, plus the reliefs and the effort standard.

Where this sits commercially

Carbonhalo documents the process while it runs, so the artefacts carry dates inside the reporting period.