Glossary›AASB S2 disclosure requirements / AASB S2 mechanics›Risk management disclosures (AASB S2)
Glossary term
Cluster C · C15
Tier 1 · differentiator
Risk management disclosures (AASB S2)
Definition
Risk management is the third AASB S2 pillar. It requires disclosure of the processes the entity uses to identify, assess, prioritise and monitor climate-related risks and opportunities, the inputs and parameters those processes use, and the extent to which they are integrated into the entity’s overall risk management. It discloses process, not outcome.
On this page
In practice
This pillar is short in the standard and disproportionately revealing in practice, because a process either ran or it did not and the evidence is dated.
Paragraph 24 sets the objective: users must be able to understand the processes used to identify, assess, prioritise and monitor climate-related risks and opportunities, including whether and how those processes are integrated into and inform overall risk management. Paragraph 25 sets out what that means in three parts.
25(a), for risks, requires the processes and related policies, and specifically: the inputs and parameters used, including data sources and the scope of operations covered; whether and how the entity uses climate-related scenario analysis to inform its identification of risks; how it assesses the nature, likelihood and magnitude of effects, including whether it uses qualitative factors, quantitative thresholds or other criteria; whether and how it prioritises climate risks relative to other types of risk; how it monitors them; and whether and how the processes changed compared with the previous reporting period.
25(b), for opportunities, requires the same process disclosure, including whether and how scenario analysis informs their identification. This is a separate limb and it is routinely left out.
25(c) requires the extent to which, and how, those processes are integrated into and inform the entity’s overall risk management process.
Paragraph 26 then requires the entity to avoid unnecessary duplication, cross-referring to Appendix D paragraph B42(b): an Appendix D citation, not Appendix B. Aus26.1 clarifies that this matters particularly where an entity voluntarily applies AASB S1 as well, so that integrated risk management disclosures replace separate ones for each sustainability topic.
Three things follow for a private business.
Integration is a disclosure, so non-integration is disclosed too. Paragraph 25(c) does not require climate risk to be inside enterprise risk management. It requires the entity to say to what extent it is. A climate risk process running separately from ERM is a compliant answer and an unflattering one, and most boards would rather fix it than publish it.
Two limbs are comparative and only appear from year two. Paragraph 25(a)(vi) asks whether and how the processes changed compared with the previous period. In a first report there is no previous period; from the second, the entity must be able to describe changes, which means the year-one process has to have been documented well enough to compare against.
Prioritisation criteria are the hardest limb. Paragraph 25(a)(iv) asks whether and how climate risks are prioritised relative to other types of risk. Answering it requires a common rating scale across climate and non-climate risks, which is precisely what an entity does not have if its climate risks live in a separate spreadsheet with its own bespoke scoring.
What the assurer does with it
Risk management is not inside the year-one review scope under ASSA 5010 paragraph 10(a), which covers governance, strategy risks and opportunities, Scope 1 and 2, and any no-material-risk statement. It comes into scope from the second reporting year under paragraph 10(b), when the review extends to all disclosures, and moves to audit from the fourth year under paragraph 10(c). That deferral is a planning opportunity, not a reprieve: the year-two review will ask what the process was in year one.
Because the subject matter is a process, the assurer tests operation rather than design. They accept a written process description matched by dated artefacts showing it ran inside the reporting period: workshop records, a risk register with review dates and named owners, minutes recording that climate risks were considered, a rating scale applied consistently across climate and non-climate risks, and a documented data source list matching what the disclosure claims. They reject a process described in the present tense with no evidence it operated during the period, a register created after year end for the engagement, a disclosure claiming integration where the climate risks appear in no document the audit and risk committee ever saw, a prioritisation claim with no criteria behind it, and silence on the opportunities limb at 25(b). The recurring finding is a beautifully documented process that was written for the report rather than used to run the business, and the tell is that every artefact carries a date after year end.
Commonly confused with
The climate risk register, which is a working document most entities use to evidence this pillar and which no standard requires by name. Also confused with the strategy pillar: risk management discloses how risks are found and monitored, strategy discloses what they are and what is being done about them. And confused with internal controls over sustainability reporting, which are the controls over the accuracy of the reported information rather than the processes for managing the underlying business risk. Both matter, and they are tested by different procedures.
Timing and relief
No Appendix C transitional relief applies to the risk management pillar. The practical phasing is in the assurance timetable rather than the standard: reviewed from the second reporting year under ASSA 5010 paragraph 10(b), audited from the fourth under paragraph 10(c). The comparative limbs at paragraph 25(a)(vi) apply only once a previous period exists.
Sources
1
2
3
ASSA 5010 Timeline for Audits and Reviews of Information in Sustainability Reports under the Corporations Act 2001
AUASB
Review status
Review required
Last reviewed
15 September 2026
Editorial pass, unsigned
Reviewer required
Registered company auditor
Next scheduled review
1 July 2027
Part of
Cluster C, AASB S2 disclosure requirements / AASB S2 mechanics
25 terms on what the climate disclosure standard actually requires, pillar by pillar, plus the reliefs and the effort standard.
Related terms
The working document most entities use to evidence this pillar
The pillar that owns what the risks are, as against how they were found
The controls over reported information, tested separately
Related questions
What will our audit and risk committee ask us?
−
The same questions they ask about the financial report, applied to information the committee has never seen before. Expect them on capture and scope, where each number comes from and what controls sit over it, the significant judgements and materiality, who your assurance provider is and whether they are independent of the preparer, and what liability protection applies and until when. It works as a self-test: anything you cannot answer today is a work item.
What governance evidence does the assurance provider look for?
+
Evidence that the governance you described actually happened: board and committee minutes and papers showing climate was considered, terms of reference allocating oversight, the delegation to management, and dated records of the decisions you disclose. Governance disclosures are assured from year one, so the paper trail matters immediately.
Do we need to integrate our systems to do this?
+
No. Nothing in AASB S2 or the Australian assurance standards requires system integration. The evidence an assurance practitioner wants already exists in your invoices, meter data, fuel card statements and general ledger, so extracting it once a year is a retrieval task rather than an IT project.
Where this sits commercially
Carbonhalo documents the process while it runs, so the artefacts carry dates inside the reporting period.
Other terms in this cluster
Risk management disclosures (AASB S2)