Glossary›Measurement and governance / Governance, board and directors›Audit and risk committee (climate oversight)
Glossary term
Cluster E · E1
Tier 1
Audit and risk committee (climate oversight)
Definition
The audit and risk committee is the body where climate disclosures are challenged before they reach the board: the emissions numbers, the judgements behind them, the state of the control environment and the assurance findings. Its charter, papers and minutes are among the first documents an assurance provider requests.
On this page
In practice
AASB S2 does not require an audit and risk committee, and this is the first thing to say to a private company board that assumes it must build one. Paragraph 6(a) requires disclosure about the governance body or individual responsible for oversight of climate-related risks and opportunities, and it expressly contemplates that this can be a board, a committee or an equivalent body, or an individual. A board that retains climate oversight itself discloses that and is compliant.
What the standard does require, once the body is identified, is a specific set of facts about it. Paragraph 6(a)(i) to (v) requires disclosure of how responsibilities are reflected in terms of reference, mandates, role descriptions and related policies; how the body determines whether appropriate skills and competencies are available or will be developed; how and how often it is informed; how it takes climate into account when overseeing strategy, major transactions and risk management, including whether it has considered trade-offs; and how it oversees target setting and monitors progress, including whether and how related performance metrics are included in remuneration policies.
Read as a checklist, that is a demanding list, and each item implies a document. Terms of reference that name climate. A skills assessment. A meeting calendar with a stated frequency. Minutes showing climate was considered in a strategy or transaction discussion. And a stated position on remuneration linkage.
For most Australian private companies at this scale the audit and risk committee is the natural home, for a practical reason rather than a governance-theory one: climate disclosure is a reporting and controls problem before it is a strategy problem, and the committee that already challenges the financial report is the committee that knows how to challenge a number.
The committee failure mode in year one is almost uniform. The climate file arrives once, at the meeting that approves the report, as a completed document, with the assurance conclusion already drafted. At that point the committee can approve or delay, and nothing else. A committee that sees the basis of preparation in the first quarter, the data collection status mid-year and the draft figures before they are final can actually change the outcome.
What the assurer does with it
The assurer treats the committee as a source of evidence about the governance disclosure, and the test is documentary. They request the charter or terms of reference, the meeting calendar, the papers and the minutes for the period.
They read the charter against the disclosure. Where the report says the audit and risk committee oversees climate-related risks, the charter must say so. A disclosure asserting a responsibility that no constitutional document assigns is unsupported, and it is the most common governance finding in a first-year engagement, not because entities are being untruthful, but because the practice started before the paperwork caught up.
They then read the minutes for evidence the responsibility was exercised. A charter is capability; minutes are performance. What they look for is a record of the committee being informed, asking something, and a consequence following. “The climate report was noted” evidences attendance, not oversight.
They accept a charter that assigns the responsibility, dated before or during the period, supported by minutes showing climate matters were considered at the disclosed frequency. They reject a charter amended after year end and presented as covering the period, a disclosed meeting frequency the minutes do not support, minutes that record only noting, and any disclosure of skills and competencies with no underlying assessment behind it.
One procedural point specific to sustainability engagements. Under ASSA 5000 paragraph Aus 42.2 the practitioner must not use internal auditors to provide direct assistance on a sustainability assurance engagement, and that prohibition extends to the use of internal auditors for direct assistance for components in a group engagement. Committees that are used to offering internal audit resource to the financial auditor to reduce fees cannot do the same here. It is a firm prohibition, not a judgement, and it should be factored into the engagement budget rather than discovered during it.
Commonly confused with
A sustainability committee or an ESG committee. Many entities have one, and they typically own strategy, targets and stakeholder positioning. That is a different function from challenging the disclosed numbers and the control environment behind them, and where both exist the split of responsibility needs to be written down, because paragraph 6(a) requires the responsible body to be identified. Two bodies with overlapping mandates and no documented boundary is a governance disclosure the assurer cannot verify.
Sources
1
2
ASSA 5010 Timeline for Audits and Reviews of Information in Sustainability Reports under the Corporations Act 2001
AUASB
3
ASSA 5000 General Requirements for Sustainability Assurance Engagements, full text (January 2025)
AUASB
Review status
Review required
Last reviewed
15 September 2026
Editorial pass, unsigned
Reviewer required
Company secretary and registered company auditor
Next scheduled review
1 July 2027
Part of
Cluster E, Measurement and governance / Governance, board and directors
10 terms on what the board must be able to evidence, what personal exposure directors carry, and how the audit and risk committee engages with the assurer. Governance disclosures sit inside the year-one assurance scope.
Related terms
The AASB S2 disclosure requirement the committee’s evidence supports
The documented structure that indexes the charters, calendars and minutes
What the assurer must communicate to the committee, and when
Related questions
What will our audit and risk committee ask us?
−
The same questions they ask about the financial report, applied to information the committee has never seen before. Expect them on capture and scope, where each number comes from and what controls sit over it, the significant judgements and materiality, who your assurance provider is and whether they are independent of the preparer, and what liability protection applies and until when. It works as a self-test: anything you cannot answer today is a work item.
What governance evidence does the assurance provider look for?
+
Evidence that the governance you described actually happened: board and committee minutes and papers showing climate was considered, terms of reference allocating oversight, the delegation to management, and dated records of the decisions you disclose. Governance disclosures are assured from year one, so the paper trail matters immediately.
What will our auditor actually ask for?
+
In year one they ask for evidence behind the disclosures that are actually assured: Scope 1 and Scope 2 emissions, your governance disclosures, and the specified strategy paragraphs on climate risks and opportunities. In practice that means source documents, a calculation they can rebuild from those documents, and minutes showing the governance you described actually happened.
Other terms in this cluster
Audit and risk committee (climate oversight)