Skip to main content
Category: Enterprise Risk Management

Climate-Related Risk

Also known as: Climate Risk, Climate Change-Related Risk
Simply put

Climate-related risk refers to the potential for climate change to cause negative effects on an organization, its assets, and its ability to operate, as well as on the wider environment and society. It captures harms that may be financial, social, or environmental in nature. In practice, it is often broken down into distinct categories to help organizations understand where the potential impacts come from.

Formal definition

Climate-related risk denotes the potential adverse effects arising from climate change on an organization's objectives, assets, operations, and financial position, and more broadly on economic and environmental systems. It is commonly categorized to separate distinct sources of uncertainty; frequently referenced groupings include physical risks and transition risks, while some frameworks further distinguish planetary, economic, and financial dimensions. The specific taxonomy, metrics, and assessment methodologies vary considerably across available tools and frameworks, and the applicable categorization may depend on the organization's sector, jurisdiction, and analytical purpose. This entry addresses the concept and its categorization only; it does not prescribe measurement methodologies, disclosure obligations, or specific tooling, which differ by framework and regulatory context.

Why it matters

Climate-related risk has moved from a peripheral environmental concern to a recognized source of uncertainty against organizational objectives, assets, and financial position. Its significance stems partly from the breadth of its potential effects: the same underlying phenomenon can generate financial, social, and environmental harm, and those harms may materialize through different channels. This makes climate-related risk difficult to isolate within a single risk register category and frequently relevant across strategy, operations, and reporting functions simultaneously.

A further reason the topic warrants careful treatment is that its assessment is still maturing. The available tools, metrics, and methodologies vary considerably, and no single taxonomy is universally adopted. Some frameworks separate physical from transition risks, while others distinguish planetary, economic, and financial dimensions. For risk and governance professionals, this variability means that comparability across organizations and across tools cannot be assumed, and that the categorization chosen may itself shape which impacts receive attention.

Because climate-related risk can affect both the organization and, more broadly, the economic and environmental systems within which it operates, it tends to draw the interest of multiple internal functions and external stakeholders. The appropriate depth of analysis, and the categories used, generally depend on the organization's sector, jurisdiction, and the analytical purpose at hand.

Who it's relevant to

Risk Managers
Risk managers may need to incorporate climate-related risk into enterprise and operational risk processes, recognizing that its effects can be financial, social, or environmental and may not map cleanly onto a single existing risk category. The choice of taxonomy, such as physical versus transition risks, or planetary, economic, and financial dimensions, can influence how these risks are identified and assessed.
Governance Professionals and Boards
Those responsible for governance structures and decision rights may find climate-related risk relevant because its potential effects span strategy, operations, and financial position. Given that categorization and analytical approaches vary by sector and jurisdiction, governance oversight typically involves understanding which framework and purpose underpin the organization's approach rather than assuming a universal standard.
Compliance and Regulatory Specialists
Compliance professionals may encounter climate-related risk where disclosure or reporting expectations apply, though such obligations differ by framework and regulatory context and are not addressed by this entry. The absence of a single standardized taxonomy means that comparability across organizations and tools cannot be assumed.
Internal Auditors and Assurance Functions
Assurance providers may assess how management identifies and categorizes climate-related risk, keeping their independent evaluation distinct from the management activities being reviewed. Because metrics and methodologies vary considerably across available tools, auditors commonly focus on the appropriateness and consistency of the chosen approach for the organization's sector, jurisdiction, and purpose.

Inside Climate-Related Risk

Physical risk
Risk arising from the direct effects of climate change, commonly divided into acute risks (such as discrete weather events) and chronic risks (such as longer-term shifts in climate patterns). Its materiality typically depends on an organization's geographic footprint, assets, and supply chains.
Transition risk
Risk stemming from the process of moving toward a lower-carbon economy, including policy and legal changes, technology shifts, market and reputational dynamics. The relevance of each driver varies by sector and jurisdiction.
Liability or litigation exposure
The potential for claims or legal actions connected to climate-related conduct, disclosures, or failure to act. This dimension is often treated as a component of transition risk and is highly dependent on jurisdiction and applicable law.
Governance dimension
The structures, roles, and decision rights through which a board and management oversee climate-related matters. This concerns who is accountable for setting and monitoring climate-related objectives rather than the assessment of the risk itself.
Risk management dimension
The processes for identifying, assessing, treating, and monitoring climate-related uncertainty against organizational objectives, commonly integrated into broader enterprise risk management rather than run as a wholly separate exercise.
Disclosure and compliance dimension
Adherence to applicable reporting obligations and voluntary reporting frameworks relating to climate-related risk. Specific requirements vary substantially across jurisdictions, sectors, and organization size, and should not be assumed to be universal.

Common questions

Answers to the questions practitioners most commonly ask about Climate-Related Risk.

Is climate-related risk a single, distinct risk category that can be managed on its own?
No. Climate-related risk is better understood as a driver that manifests across existing risk categories rather than a standalone category. It commonly influences credit, market, operational, liquidity, strategic, legal, and reputational risk, among others. In many frameworks it is broken into physical risk (arising from acute events and chronic shifts) and transition risk (arising from policy, legal, technological, and market changes associated with moving toward a lower-carbon economy). Because it operates through these existing exposures, it is typically integrated into an organization's overall risk management processes rather than isolated in a separate silo.
Does managing climate-related risk mean the same thing as reducing an organization's environmental impact?
Not necessarily. Climate-related risk management concerns identifying, assessing, and treating the uncertainty that climate factors pose to an organization's objectives. That is analytically distinct from an organization's impact on the climate and broader sustainability goals, which are sometimes described under concepts such as double materiality in certain reporting regimes. An entity may reduce its emissions for impact reasons while still carrying significant physical or transition risk, and vice versa. The two objectives can overlap but should not be treated as interchangeable, and the applicable framing depends on the jurisdiction and reporting regime involved.
How can climate-related risk be integrated into an existing enterprise risk management framework?
Integration commonly involves mapping climate drivers to existing risk categories rather than creating a parallel process. In practice this may include incorporating physical and transition factors into risk identification and assessment, considering both short- and longer-term time horizons, and reflecting climate considerations in risk appetite and tolerance statements where relevant. The specific approach varies by organization, sector, and jurisdiction, and any framework used, such as those referencing established ERM structures, should be applied according to its own guidance. This entry does not prescribe implementation specifics or tooling.
What is the role of scenario analysis in assessing climate-related risk?
Scenario analysis is commonly used to explore how an organization's exposures might behave under different plausible climate and transition pathways, given the long time horizons and deep uncertainty involved. It is typically treated as an exploratory tool for understanding potential vulnerabilities rather than a precise forecast, and it does not guarantee outcomes. The design of scenarios, time horizons, and assumptions varies considerably across organizations and jurisdictions, and expectations may differ for regulated sectors such as banking and insurance.
How do the three lines relate to climate-related risk responsibilities?
Under the three lines model associated with the IIA, responsibilities are commonly allocated so that management functions own and manage climate-related exposures as part of first line activities, risk and compliance functions provide oversight, challenge, and expertise in the second line, and internal audit provides independent assurance in the third line. It is important not to conflate assurance activities with the management of the risk itself; independence and objectivity distinctions between assurance and management functions should be preserved. Precise allocation of duties varies by organization.
What reporting and disclosure considerations apply to climate-related risk?
Disclosure expectations for climate-related risk depend heavily on jurisdiction, sector, and organization size, and they continue to evolve. Some regimes emphasize how climate factors affect the organization, while others also address the organization's impact on the climate. Because requirements differ across regions and are subject to change, organizations should determine the specific obligations applicable to them rather than assuming a universal standard. This entry does not constitute legal advice and does not detail the requirements of any particular regime.

Common misconceptions

Climate-related risk is a single, standalone risk category that requires a separate management framework.
It is more accurately understood as a driver that can manifest across multiple existing risk categories, such as credit, operational, market, strategic, and legal risk. In many frameworks it is integrated into enterprise risk management rather than managed in isolation.
Climate-related disclosure requirements apply uniformly to all organizations.
Obligations depend heavily on jurisdiction, industry, and organization size, and many regimes distinguish mandatory reporting from voluntary frameworks. What is required in one context may be voluntary or absent in another.
Climate-related risk concerns only physical hazards such as extreme weather.
Physical risk is one component; transition risk arising from policy, technology, market, and reputational change, along with associated liability exposure, can be equally or more material depending on the organization's sector and profile.

Best practices

Integrate climate-related risk into the existing enterprise risk management process rather than treating it as an entirely separate program, mapping it to the risk categories it actually affects.
Distinguish physical, transition, and liability dimensions explicitly when assessing exposure, since their drivers and time horizons differ.
Clarify board and management accountability for climate-related oversight, keeping governance decision rights distinct from the risk assessment activities themselves.
Confirm which disclosure obligations and voluntary frameworks apply to the organization's specific jurisdiction, sector, and size before assuming a reporting requirement exists.
Use qualified, scenario-based analysis to reflect the uncertainty and long time horizons involved, avoiding language that implies precise or guaranteed outcomes.
Maintain the independence of assurance functions when climate-related controls and disclosures are reviewed, keeping the audit of these processes separate from the management activities that produce them.
Promotional banner graphic asking if you are ready for PCI DSS 4.0 with a call-to-action to get the guide