← Back to blog

Five Step ERM Playbook for Climate Risk: IFRS S2, NGFS & TCFD Mapped

October 1, 2026
Five Step ERM Playbook for Climate Risk: IFRS S2, NGFS & TCFD Mapped

Climate risk belongs in enterprise risk management as a material, board-level risk category, not a sustainability side project. The practical approach classifies exposures as physical or transition risk, runs scenario analysis on two clocks, a near-term stress view and a long-term pathway view, and references IFRS S2, NGFS, and TCFD as the mechanisms that keep the process accountable. This guide sets out the register fields, scenario outputs, and governance changes needed to make that integration disclosure-ready.


TL;DR:

  • Climate risk should be integrated into enterprise risk management with the same lifecycle as other risks, starting with identifying, assessing, and prioritizing exposures.
  • Use both near-term and long-term scenario analysis, applying NGFS short-term and Phase V scenarios to understand immediate portfolio stress and strategic climate pathways.
  • A climate risk register must trace from cause to control to evidence and only escalate into the corporate risk register when material thresholds are crossed.
  • Practical implementation involves specific governance changes, clear thresholds, and operational controls tied directly to scenario outputs and materiality.
  • Building the necessary skills requires targeted training in scenario modeling, data documentation, and disclosure procedures, ideally supported by credentialed programs.

Esgtraininginstitute
Build Stronger Climate Risk Capability
Develop the ESG competencies needed for climate strategy, carbon accounting, sustainable finance, and credible disclosure planning.
Explore ESG training

Table of Contents

A concise operational framework for integrating climate risk into ERM

Climate risk becomes manageable once it moves through the same lifecycle every other enterprise risk follows: identify, assess, prioritize, respond, monitor. Treating it as a parallel process, run by a sustainability team with its own register and its own language, is the single most common reason climate work stalls before it reaches the board.

The lifecycle mapping looks like this in practice:

  • Identify: scan physical and transition exposures across assets, counterparties, and revenue lines, using sector and geography screens as a first filter.
  • Assess: score likelihood and consequence using the same scales as operational or credit risk, adjusted for the longer horizons climate risk introduces.
  • Prioritize: rank items by materiality to strategy and capital, not by stakeholder interest or reporting convenience.
  • Respond: assign owners, controls, and risk appetite thresholds, exactly as you would for a liquidity or credit risk.
  • Monitor: track triggers and metrics on a cadence tied to the risk's own clock, quarterly for near-term stress items, annually for long-term pathway items.

A climate item earns a place on the corporate risk register the moment it meets the organization's existing materiality threshold, whether that is measured in capital at risk, revenue exposure, or reputational consequence. Before that point, it can sit on a sustainability watch list. After that point, keeping it off the corporate register creates a disclosure gap, because IFRS S2 asks how climate risks are identified, assessed, prioritized, and monitored within the overall risk management process, not alongside it.

Governance changes needed to support this are modest but specific. The risk committee needs a standing climate risk agenda item, tied to scenario review cadence rather than an annual update. The chief risk officer needs sign-off authority on climate risk appetite statements, the same as any other risk category. And someone, typically a second-line risk function, needs ownership of the register's evidence trail: methodology notes, data sources, assumptions, and the audit log of decisions taken in response to triggers.

This structural shift changes real decisions. A few examples:

  1. Capital allocation to carbon-intensive sectors gets a formal review trigger when transition-risk scores cross an appetite threshold, rather than a discretionary annual check.
  2. Underwriting terms tighten automatically for property exposed to acute physical risk once a defined loss-ratio or hazard-score threshold is breached.
  3. Credit review cycles shorten for counterparties whose sector faces a policy or technology transition timeline inside the institution's medium-term horizon.

Pro Tip: Start by mapping your five largest exposures against both physical and transition risk before building the full register. It reveals where scoring gaps exist faster than a full inventory does.

Climate risk taxonomy: physical vs transition risk and time horizons

Consistent scoring across an enterprise risk register depends on using the same taxonomy every time, because a physical risk and a transition risk behave on different timelines and respond to different controls.

Physical risk splits into two categories. Acute physical risk covers discrete events, floods, wildfires, storms, that damage assets or disrupt operations within days. Chronic physical risk covers gradual shifts, sea-level rise, heat stress, changing precipitation patterns, that erode asset value or productivity over years. Transition risk covers the financial consequences of moving toward a lower-carbon economy, and it runs through several channels:

  • Policy risk: carbon pricing, emissions regulations, and phase-out mandates that raise compliance costs or strand assets.
  • Technology risk: displacement of existing processes or products by lower-carbon alternatives.
  • Market risk: shifting demand patterns and changing input costs as preferences and supply chains adjust.
  • Legal risk: litigation exposure tied to disclosure failures or contribution to climate harm.
  • Reputational risk: stakeholder and investor reaction to perceived inaction or greenwashing.

Horizon mapping keeps these risks comparable. Near-term exposure runs 0 to 5 years and covers immediate portfolio stress, insurance repricing, and liquidity strain from acute events. Medium-term exposure runs roughly 3 to 10 years and captures policy and technology shifts already in motion. Long-term exposure extends beyond 10 years and captures chronic physical risk and structural transition pathways. Financial organizations need both clocks running at once: a near-term stress view protects current portfolios and liquidity, while a long-term pathway view protects strategic positioning and capital planning.

For a financial institution, this taxonomy translates directly into portfolio terms. A mortgage book concentrated in a flood-prone coastal region carries acute physical risk with a near-term horizon. A loan book to combustion-engine component manufacturers carries policy and technology transition risk with a medium-term horizon. A long-dated infrastructure investment in a region facing chronic heat stress carries a long-term horizon that outlives most current risk models.

Designing a climate risk register that feeds ERM and disclosures

A climate risk register earns its place in ERM only when every entry can trace a straight line from cause to consequence to control to evidence. IFRS S2 requires exactly this kind of traceability: documented processes for identifying, assessing, prioritizing, and monitoring climate risks, tied to how those processes feed the overall risk management framework.

The register needs these fields for every entry:

  • Risk statement: a plain description of what could happen and to what.
  • Cause and exposure: the physical or transition driver and the specific asset, portfolio, or activity affected.
  • Vulnerability: why the exposure translates into loss, damage, or disruption.
  • Consequence: the financial, operational, or reputational impact if the risk materializes.
  • Scenario and horizon: which scenario and time frame the assessment is based on.
  • Controls, owner, and appetite threshold: existing mitigations, the accountable person, and the limit that triggers action.
  • Trigger, action, and metric: the specific signal that activates a response, what that response is, and how progress is measured.
  • Escalation path and evidence: who is notified when thresholds are breached and where the supporting documentation lives.

A short example entry illustrates the structure:

FieldExample entry
Risk statementFlood damage disrupts a regional distribution center
Cause and exposureAcute physical risk, single-site logistics asset
VulnerabilityNo flood defenses, located in a designated floodplain
Consequenceoperational disruption, revenue and insurance cost impact
Scenario and horizonNGFS short-term scenario, 0 to 5 year horizon
Controls and ownerSite relocation review, owned by operations risk lead
Appetite threshold and triggerFlood-probability score exceeding internal limit
Escalation and evidenceEscalates to corporate register, evidence held in risk system log

Escalation to the corporate risk register happens when an item crosses the organization's existing materiality threshold, whether that is expressed in capital at risk, percentage of revenue, or a qualifying reputational or legal exposure. Items below that line stay on a departmental or sustainability log, reviewed on a longer cycle. This distinction matters because IFRS S2's traceability requirement extends to explaining how the escalation decision itself was made, not only to the final register entry.

Scenario analysis for ERM: near-term stress and long-term pathway testing

Scenario analysis in ERM answers two different questions, and conflating them is one of the most common practical mistakes. A near-term stress scenario asks whether current portfolios and liquidity positions can absorb a plausible shock within the next few years. A long-term pathway scenario asks whether the organization's strategy remains viable as the economy transitions over decades. Both are necessary, and neither substitutes for the other.

Two climate scenario testing pathways

The NGFS guide to climate scenario analysis frames scenario analysis as a structured test of resilience under plausible combinations of physical and transition conditions, producing decision-useful outputs such as vulnerable exposures, capex needs, and valuation sensitivity, never a forecast. A common implementation failure is relying on a single distant scenario, often a 2050 or 2100 vintage, and treating it as sufficient. NGFS Phase V and the NGFS short-term scenarios exist precisely because financial institutions need both a near-term stress view for current portfolios and a longer-term pathway view for strategic resilience.

A practical scenario program for an ERM function should follow this sequence:

  1. Select scenario vintages for both clocks. Use NGFS short-term scenarios for a 5-year stress view and NGFS Phase V long-term scenarios for pathways extending beyond 10 years.
  2. Apply scenarios to material exposures first. Run the largest portfolio concentrations and highest-consequence register items before attempting full coverage.
  3. Produce decision-useful outputs. Target vulnerable counterparties, capex or repricing needs, and valuation sensitivity, not high-level macroeconomic summaries alone.
  4. Translate outputs into appetite and control adjustments. A scenario result showing a sector's default rate rising under a delayed-transition pathway should move that sector's concentration limit, not sit in a report.
  5. Refresh on a defined cadence. Near-term scenarios warrant more frequent review than long-term pathway scenarios, given how quickly policy and market conditions shift.

One useful output financial institutions can draw from a well-run program is a loss-range and default-rate uplift estimate for the most exposed segment of a credit or investment portfolio, the kind of forward-looking metric the FSB's climate vulnerabilities framework recommends for monitoring financial stability risk. That single output, tied to a named portfolio segment and a named scenario, does more for a risk committee than a dozen pages of narrative.

Two clarifications keep scenario work credible. First, scenarios are not forecasts. TCFD's own framing treats them as a way to test strategic resilience across plausible futures precisely because climate risk involves deep uncertainty and long horizons that a single-point forecast cannot capture. Second, NGFS itself describes scenario analysis as an evolving toolkit: vintages, data, and policy assumptions change, and risk teams need to design their framework to match their own exposure and capability rather than copying another institution's setup wholesale.

Integrating climate risk into governance, appetite and controls

Scenario outputs and register signals only matter once they change appetite language, limits, and controls that staff actually use day to day.

A climate-aware risk appetite statement should name specific thresholds rather than general intent. Instead of stating an intention to manage transition risk, a workable statement sets a maximum percentage of the loan book in sectors scoring above a defined transition-risk threshold, reviewed annually against the latest scenario outputs. Sector concentration limits follow the same logic: a cap on exposure to a single high-carbon sector, tied to the scenario-derived loss range for that sector rather than a static percentage set once and left unreviewed.

Operational controls translate these limits into daily practice:

  • Underwriting triggers: automatic referral to senior underwriting review when a property's physical-hazard score crosses a defined threshold.
  • Credit review triggers: shortened review cycles for counterparties in sectors facing near-term policy or technology transition.
  • Procurement clauses: supplier contracts that require disclosure of transition plans for high-exposure categories.

Internal audit and assurance functions need a clear mandate here too. Their priority should be testing whether register entries actually trace to the controls and evidence they claim, whether appetite breaches trigger the escalation the register describes, and whether the data behind scenario outputs is documented well enough to survive external scrutiny. This is where ISAE 3000-aligned assurance practices intersect directly with ERM: assurance is not a separate exercise bolted on at year-end, it is a test of the same traceability the register is meant to provide.

Pro Tip: Write appetite thresholds as numbers tied to a named metric, never as qualitative intent. A threshold nobody can breach in practice is not a control.

Metrics, targets and disclosure traceability

ERM's job is not finished when a risk is scored and controlled. It has to produce evidence that maps cleanly onto disclosure requirements, and IFRS S2 organizes that evidence around four headings: governance, strategy, risk management, and metrics and targets.

Governance evidence documents who has oversight of climate risk and how often it reaches the board. Strategy evidence shows how scenario outputs have shaped business decisions. Risk management evidence is the register itself: identification, assessment, prioritization, and monitoring processes, and how they connect to the organization's broader risk framework. Metrics and targets evidence quantifies exposure and progress.

Practical metrics worth tracking include:

  • Exposure proxies: percentage of assets or portfolio value located in high physical-hazard zones.
  • Financed emissions: a standard metric for lenders and investors assessing transition exposure across a portfolio.
  • Scenario loss ranges: the output ranges generated by near-term and long-term scenario runs, tied to named portfolio segments.
  • Target progress: measured movement against any stated transition or resilience target, reported on a consistent cadence.

The documentation behind these metrics matters as much as the numbers themselves. IFRS S2's risk-management disclosure objective is explicit: it asks how climate-related processes are integrated into overall risk management, which means methodology, data lineage, scenario assumptions, model limitations, and assurance evidence all need to sit alongside the metric, not in a separate file nobody can find during an audit.

Climate information should change governance, strategy, and risk decisions, not just fill a reporting template. Adapted from ISSB S2 guidance for practitioners

Teams building this traceability from scratch often find it easier to start with the TCFD to ISSB transition, since most existing climate disclosure work already sits closer to the TCFD structure than to IFRS S2's format.

Data, models and evidence: practical limits and documentation

Climate data and models come with limits that ERM teams need to plan around rather than pretend away. Granularity is the most common problem: asset-level hazard data is rarely available for every counterparty, and portfolio-level proxies introduce error that widens as exposure concentrates in a smaller number of large positions. Counterparty data gaps are just as common, particularly for private companies and smaller suppliers with no public climate disclosure at all.

Practical mitigations exist for both. Tiered data approaches, using the best available data for the largest exposures and reasonable proxies for the long tail, keep the effort proportional to materiality. Engaging directly with the largest counterparties for primary data closes gaps that public sources cannot fill.

Model choice matters just as much as data quality. NGFS combines hazard and damage functions with economic models to translate physical events into financial impact, and NGFS Phase V's updated damage function shows how sensitive outputs are to that choice: chronic physical risk estimates increased materially in some scenarios purely from the updated methodology, with no change in the underlying climate trajectory.

Documentation needs to capture, for every scenario run and every register entry that depends on it:

  • Data lineage: where every input came from and how it was processed.
  • Vintage: the exact scenario version and publication date used.
  • Assumptions: every material judgment made when data was incomplete.
  • Sensitivity results: how outputs shift under alternative model or data choices.

Without this record, a scenario output is a number nobody can defend under scrutiny, which defeats the purpose of running the analysis at all.

Prioritization and implementation roadmap for risk teams

Teams starting from a limited base can build a credible program in phases rather than waiting for a complete framework before acting.

  1. Phase 1, months 0 to 12: inventory existing climate-related risk activity across the organization, run a materiality scan against the current risk appetite framework, make the governance tweaks described earlier (standing committee agenda item, named register owner), and pilot a single scenario run on the organization's largest exposure.
  2. Phase 2, months 12 to 36: deploy the full climate risk register with all required fields, build out the scenario program across both near-term and long-term horizons, and align metrics and evidence with IFRS S2's four disclosure headings.
  3. Phase 3, month 36 onward: embed climate risk outputs directly into capital planning cycles, bring internal audit and external assurance into a regular review cadence, and treat the whole program as a continuous improvement cycle rather than a project with an end date.

A simple RACI helps keep phase 1 moving: the chief risk officer is accountable for the overall program, a named risk analyst is responsible for the register and scenario runs, the sustainability function is consulted for exposure identification, and the board risk committee is informed at each phase gate. KPIs worth tracking from the start include the percentage of material exposures with a completed register entry, the number of appetite breaches correctly escalated, and the time from data update to register refresh.

Pro Tip: Resist the urge to build the perfect register before running a single scenario. A rough pilot on your largest exposure teaches more in a month than a year of framework design.

Building capability: training, certification and practical exercises

Running this framework well depends on skills that most risk teams have not needed until recently: scenario workshop facilitation, data lineage mapping, and disclosure drafting that connects governance, strategy, and metrics into one coherent record. Targeted training closes that gap faster than learning through trial and error on live reporting cycles.

ESG Training Institute's Certificate in Climate Risk Management and Certified Climate Risk Professional (CCRP) programs are built around exactly the tasks this guide describes:

  • Designing and facilitating scenario workshops using NGFS-aligned inputs.
  • Mapping data lineage and documenting model assumptions for audit-ready evidence.
  • Drafting IFRS S2-ready disclosure content across governance, strategy, risk management, and metrics and targets.
  • Building and maintaining a climate risk register that escalates correctly into the corporate risk framework.

Course content is mapped to ISSB and related international standards, with server-validated assessments designed to test real competence rather than attendance alone, which matters for risk officers who need credentials that hold up under regulatory scrutiny.

Author perspective: lessons from practice

The biggest mistake I keep seeing is treating climate risk as a sustainability team's project that occasionally briefs the risk committee. It belongs inside the same architecture as credit, market, and operational risk from day one, scored on the same scales and escalated through the same paths.

The two-clock approach is not optional. Teams that only build a long-term pathway view end up with a beautiful strategy document and no answer when a board member asks what happens to the property portfolio next year. Start with near-term portfolio stress. It is more tractable, more decision-useful in the short term, and it builds the credibility needed to fund the longer-term pathway work.

One more lesson: a board will forgive an imperfect number far more readily than it forgives a number nobody can explain. Document the assumptions before you present the figure, not after someone asks.

— Ransford

Training and certification to speed capability building

Building the register, scenario program, and disclosure evidence described in this guide takes time when a team is learning the standards and the templates at the same time. Structured training compresses that curve: rather than assembling scenario methodology and IFRS S2 mapping from scratch, teams can work through material already aligned to ISSB, TCFD, and NGFS conventions.

Esgtraininginstitute

ESG Training Institute's Certificate in Climate Risk Management, priced at $149 one-off, and the Certified Climate Risk Professional (CCRP) credential, priced at $399 one-off, both build directly toward the register design, scenario interpretation, and disclosure drafting skills this article covers. Teams that need ongoing access to updated IFRS S1 and S2 material can use the All-Access CPD Pass, priced at $599 per year, which includes modules such as Mastering IFRS S1 & S2 Sustainability Reporting. Participants leave with a working template for the risk register, practice designing a scenario run, and a documented understanding of what disclosure-grade evidence looks like before they build it under deadline pressure.

Sources

FAQ

What is climate risk in ERM?

Climate risk in enterprise risk management means treating physical and transition climate risks as material enterprise risks, identified, assessed, prioritized, responded to, and monitored through the same processes used for credit, market, or operational risk. IFRS S2 requires organizations to show how these processes are integrated into overall risk management rather than run as a separate exercise.

What is the difference between physical and transition climate risk?

Physical risk covers direct damage or disruption from climate events, split into acute risks like floods and storms and chronic risks like sea-level rise or heat stress. Transition risk covers financial consequences of moving to a lower-carbon economy, driven by policy, technology, market, legal, and reputational channels.

Which climate scenarios should risk teams use for ERM?

The NGFS Phase V long-term scenarios and NGFS short-term scenarios are a practical starting point, covering both a long-term pathway view for strategy and a near-term stress view for current portfolios and liquidity. Scenario outputs are not forecasts, they test resilience under plausible alternative futures.

How does a climate risk register connect to disclosure requirements?

A climate risk register that documents cause, exposure, vulnerability, consequence, scenario, controls, owner, and evidence directly supports IFRS S2's requirement to show how climate risks are identified, assessed, and monitored within overall risk management. Material entries escalate into the corporate risk register once they cross the organization's existing materiality threshold.

How can risk teams build the skills needed for climate risk integration?

Structured training in scenario design, data lineage mapping, and disclosure drafting shortens the learning curve compared to building these skills through trial and error on live reporting cycles. Programs such as ESG Training Institute's Certificate in Climate Risk Management are built around these specific practical tasks.