Climate risk programmes often begin in reporting teams because disclosure creates the first formal deadline. The danger is that the organisation becomes skilled at describing risk without changing the decisions that create or reduce exposure.
Practical situation: A group publishes a detailed climate section in its annual report but cannot show how flood exposure affects facility investment, how customer transition risk changes portfolio strategy or which supplier dependencies are outside tolerance. The narrative is mature; the operating decisions are not.
Climate risk becomes part of ERM when physical and transition drivers are translated into exposures, time horizons, scenarios, indicators and accountable actions across strategy, finance, operations, customers and suppliers.
Why this belongs on the ERM agenda now#
Physical risk is local and operational#
Heat, flood, storm, wildfire, drought and sea-level effects depend on location, asset condition, infrastructure and service dependency. For risk teams, the implication is operational rather than theoretical. The test is whether the issue changes a real decision on resources, controls, suppliers, customers or strategy.
Transition risk changes markets and economics#
Policy, technology, customer preference, energy price, finance and litigation can alter demand, cost, asset value and counterparty strength. That matters because traditional controls often react after the exposure has already moved. The ERM response should therefore define an owner, a decision trigger and evidence showing whether the organisation’s approach to climate risk in ERM is improving or deteriorating.
Disclosure and management use different levels of detail#
Public reporting may aggregate information, while decisions require entity, asset, customer, supplier and time-horizon detail. The practical consequence is easy to miss. A useful response converts the concern into observable signals, named decisions and time-bound actions rather than adding another narrative risk to the register.
What good looks like#
For climate risk in ERM, good governance means that the next decision is easier to make and defend. The organisation can identify the owner, find the current evidence, explain movement and act before the reporting cycle has passed. It does not ask every activity to carry the same control burden; scrutiny increases with authority, exposure and reversibility. The first visible sign of progress is: Climate drivers map to existing strategic, credit, operational, market and supplier risks.
Look for these five characteristics in the operating process:
-
Climate drivers map to existing strategic, credit, operational, market and supplier risks.
-
Exposure is analysed by location, sector, product and time horizon.
-
Scenarios inform business choices and risk appetite, not only disclosure text.
-
Indicators measure changing vulnerability, transition and adaptation progress.
-
Climate actions have business owners, funding, milestones and evidence.
A practical climate-risk integration model#
1. Translate climate drivers into enterprise risks#
This is where ownership becomes visible. Avoid a single generic climate risk. Identify how physical and transition drivers affect objectives through customers, assets, operations, suppliers, markets, regulation and reputation.
Minimum evidence should include driver, transmission channel, affected risk, owner, time horizon, geography and business objective. The result should be reusable in monitoring and reporting, not a one-off document that disappears after the Translate climate drivers into enterprise risks step is complete.
2. Map material exposure#
Design the step around the exception that management would need to understand quickly. Combine internal data on locations, assets, customers, sectors, suppliers and revenue with relevant hazard and transition information. Record data gaps and proxies explicitly.
A reviewer should be able to find exposure unit, location or sector, value, vulnerability, source, confidence and responsible data owner. This allows challenge to focus on the quality of the decision rather than on reconstructing the history of climate risk in ERM.
3. Assess across time horizons#
Start by making the decision explicit. Use short, medium and long horizons aligned to strategy, asset life, contracts and financing. A risk can be low today but material before an asset or product reaches the end of its planned life.
The practical output is horizon, assumptions, likelihood, impact, uncertainty and decision affected. Clear evidence also makes it easier to distinguish a genuine change in climate risk in ERM from a change in wording or presentation.
4. Use scenarios to challenge strategy#
Keep this step deliberately simple. Test plausible combinations of physical events, policy, technology, price and demand. Focus on strategic and operational decisions, including adaptation, pricing, portfolio change and supplier resilience.
Do not close the step without scenario, exposure, financial and service impact, decision options, trigger and action owner. The record should enable another qualified person to understand the decision, test it and continue the work without relying on personal memory.
5. Define appetite and indicators#
Treat this as an operating requirement, not a documentation exercise. Set tolerances for material exposure and adaptation gaps where decision-useful. Use leading indicators such as concentration in high-hazard locations, uninsured assets or customers without transition plans.
The control record should show appetite statement, metric, threshold, data, review frequency, escalation and response. Recording those elements shows how the Define appetite and indicators step supports the wider approach to climate risk in ERM and gives the next reviewer a usable starting point.
6. Connect actions and disclosure evidence#
The strongest programmes begin with a narrow, testable definition. Use the same governed records to support management decisions and external reporting. Ensure that statements about plans, controls and progress are supported by approved evidence.
The decision file should retain action, owner, funding, target, progress evidence, disclosure mapping and assurance status. That evidence keeps the judgement on climate risk in ERM traceable when ownership, assumptions or operating conditions change.
Ownership and decision rights#
Effective governance of climate risk in ERM requires more than a name in the risk register. The operating chain should connect the business decision, the controls and data used to support it, independent challenge and the forum that can accept or change the exposure. Five responsibilities deserve explicit treatment.
- Executive sponsor: owns the outcome and approves trade-offs that exceed a function’s authority. The sponsor should understand how climate risk in ERM affects the wider Climate, Nature and ESG Risk agenda and what delay would mean for customers, services, strategy or legal entities.
- First-line owner: runs the activity that creates or manages the exposure. This person should lead the work to translate climate drivers into enterprise risks, keep the conclusion current and translate it into operating choices.
- Control and data owners: operate the controls and produce the evidence behind measures such as Material assets and suppliers with location-level exposure. For climate risk in ERM, they should explain lineage, exceptions, manual intervention and the response when a control or feed fails.
- Second-line challenge: tests scope, assumptions, rating, appetite interpretation and proposed action. It should challenge the risk of creating one enterprise climate score, document disagreement and confirm when higher authority is required.
- Assurance and governance forums: assess whether the process works in practice and whether material conclusions reach the right committee. They should test whether the organisation can connect actions and disclosure evidence, whether open weaknesses are visible and whether prior decisions produced the expected result.
For climate risk in ERM, a responsibility matrix is only the beginning. The workflow should preserve who submitted, reviewed, challenged, approved, changed and closed each material record, together with the date and rationale. That history protects continuity when teams, suppliers or legal-entity leadership change.
A realistic maturity path#
Maturity in climate risk in ERM should be earned through better decisions, not declared because a new methodology has been approved. A three-level path keeps investment tied to operating value.
Level 1: establish visibility#
Start with discoverability: one place to see climate risk in ERM, its owner, status, evidence and next review. Track Material assets and suppliers with location-level exposure and resolve the largest gaps before adding more scoring detail.
Level 2: connect decisions and controls#
At the second level, climate risk in ERM becomes part of the operating rhythm. Controls, observations, incidents and actions update the same conclusion, while Revenue or portfolio exposure by transition sensitivity and High-risk exposures without adaptation or transition action show whether intervention is working.
Level 3: anticipate and optimise#
Use scenarios, dependencies, leading indicators and cross-entity comparison to identify where climate risk in ERM may move next. ESG risk register linked to enterprise risks, entities, assets, suppliers and locations should shorten the time from weak signal to decision while leaving judgement and approval visible.
The maturity test for climate risk in ERM is simple: can the organisation notice change, make a defensible decision and show whether the decision worked?
Measures that are useful in management meetings#
For climate risk in ERM, reporting should combine coverage, outcome and timeliness. Use Material assets and suppliers with location-level exposure as an initial indicator and add context on severity, concentration, overdue age and business effect. Leaders should be able to tell whether the number changed because the organisation found more records, because exposure worsened or because controls improved.
-
Material assets and suppliers with location-level exposure: Measures physical-risk visibility.
-
Revenue or portfolio exposure by transition sensitivity: Shows economic concentration.
-
High-risk exposures without adaptation or transition action: Identifies unmanaged vulnerability.
-
Climate actions overdue by financial or service impact: Focuses on delivery.
-
Scenario decisions implemented: Tests management use.
-
Disclosures supported by approved source evidence: Reduces reporting and greenwashing risk.
Common failure modes#
-
Creating one enterprise climate score: Aggregation can hide location, sector and horizon differences.
-
Treating disclosure as the control framework: Narrative reporting does not manage assets, suppliers or customers.
-
Using distant horizons only: Near-term physical and policy effects may be more actionable.
-
Ignoring adaptation already planned in the business: Risk may be overstated or actions may not be governed consistently.
-
Separating climate data from risk ownership: Specialist analysis never reaches decisions.
A 90-day implementation plan#
Days 1–30: establish the facts#
Identify the most material climate transmission channels for the business and map them to existing enterprise risks. Select two portfolios or services and assemble location, sector, asset, customer and supplier exposure data with stated limitations.
Days 31–60: test the operating model#
Run one near-term physical scenario and one transition scenario. Require business owners to identify decisions, triggers and actions. Review current appetite, insurance, continuity and capital-planning assumptions.
Days 61–90: embed the management rhythm#
Approve ownership, metrics and a climate-action register. Link evidence to management and disclosure workflows, and establish quarterly reporting focused on changing exposure, decisions and delivery rather than narrative volume.
How technology should support the process#
Good tooling for climate risk in ERM reduces hand-offs and improves traceability. It does not replace accountable judgement or turn uncertainty into an artificial decimal score. The first useful building block is ESG risk register linked to enterprise risks, entities, assets, suppliers and locations. From there, the platform should support:
-
ESG risk register linked to enterprise risks, entities, assets, suppliers and locations.
-
Scenario assessments with multiple time horizons and documented assumptions.
-
Climate metrics, targets, KRIs and breach escalation.
-
Action plans, evidence, approvals and disclosure mapping.
-
Dashboards by geography, sector, business unit and risk driver.
For climate risk in ERM, the closest Vilfora product workspace is /regquanta/model-esg-risk/esg-risk-register. A useful implementation should connect that workspace to the relevant risks, controls, obligations, incidents, actions and reports rather than treating it as an isolated register.
Global implementation lens#
International implementation of climate risk in ERM should distinguish the enterprise minimum from the local overlay. The group can standardise scenarios and time horizons, while legal entities document the jurisdiction, language, market structure and delegated authority that change how the control operates.
For this topic, common records should support location and value-chain exposure without forcing local teams to hide legitimate differences. The global view should report Material assets and suppliers with location-level exposure consistently, preserve the source evidence and show where data or terminology cannot be aggregated safely.
Local governance should then specify who will translate climate drivers into enterprise risks, which forum owns exceptions and how issues involving claims, targets and management action are escalated. This produces comparable governance across countries without turning the global framework into identical paperwork everywhere.
Questions senior management should ask#
-
Which climate exposures change a business decision in the next five years?
-
Where are location and supplier data too weak to support the current conclusion?
-
What adaptation or transition actions are unfunded or overdue?
-
How do climate assumptions affect strategy, credit, operations or capital?
-
Can each public statement be traced to approved evidence?
Frequently asked questions#
How should climate risk be integrated into ERM?#
Map physical and transition drivers to existing risk categories, owners, exposures, scenarios, appetite, indicators and actions. Avoid creating a disconnected climate register used only for reporting.
What is physical climate risk?#
It is risk arising from acute events such as storms and floods and chronic changes such as heat, drought or sea-level rise that affect assets, people, suppliers, customers and operations.
What is transition risk?#
It is risk arising from policy, technology, market, legal and behavioural change during the transition to a lower-carbon economy.
Who should own climate risk?#
Business and functional executives should own the exposures they control. Sustainability and climate specialists provide methods and data; risk functions integrate governance and challenge.
Final takeaway#
Climate risk is managed when it changes a real decision on assets, customers, suppliers, products, capital or strategy—and when that decision is tracked like any other material risk action. The aim is not to predict every outcome. It is to notice material change, compare exposure with appetite, choose an owner and preserve the evidence behind the decision. That is the practical standard for climate risk in ERM.
Vilfora ERM is designed to keep climate risk in ERM connected to the owners, controls, actions and approvals that determine the real outcome. Review the workflow around /regquanta/model-esg-risk/esg-risk-register against the steps above rather than evaluating the screen as an isolated register.




