How to present physical climate risk data your assurer can actually test

Climate risk assurance turns your physical climate risk data into something an outside professional can test. Under ISSA 5000, that test is already published, and you can prepare for it from the preparer’s side of the table. This guide walks the evidence a practitioner checks, link by link, so the physical climate risk data behind a disclosed number holds up whether the check is a limited review or a full reasonable-assurance engagement.

TL;DR
  • Climate risk assurance is not a separate workstream. It is the same evidence you needed to trust a physical risk number yourself, kept in a form an assurance practitioner can follow.
  • A disclosed physical risk figure is a chain with at least six links. Only the hazard data comes from a provider; the asset register, the values, the vulnerability cut-off, the arithmetic and the tie-back to your accounts are all yours.
  • ISSA 5000 tests three kinds of link with three paragraphs: paragraph 90 for information from outside, paragraph 91 for information you produced, and paragraph 92 for a data provider treated as a management’s expert.
  • Assurance is layered on by each jurisdiction, not by the reporting standard. Build the evidence pack in the year you strike the number, when it is cheap to keep and expensive to reconstruct later.

The exam paper is already public

Somewhere in your climate report there is a physical risk number. Maybe it is the share of asset value exposed to flooding by 2050. Maybe it is a count of sites at high risk under a hot scenario. One day, an assurance practitioner, the independent professional who checks the report, will ask how that number was produced.

Most teams treat that conversation as unpredictable. It is not. The questions are published, and you can read them today.

They sit in ISSA 5000, the international standard that tells assurance practitioners how to check sustainability information. The IAASB, the board that writes the world’s audit and assurance standards, issued it in November 2024. It takes effect for reporting periods that begin on or after 15 December 2026, and earlier use is permitted. Some countries are ahead of that date. Australia adopted it with local adjustments and switched it on for annual reporting periods beginning 1 January 2025.

One thing the reporting standards do not do is order the check. IFRS S2 and the standards built on it tell you what to disclose. They do not require anyone to assure it. Whether your report is checked, when, and how deeply is decided by each jurisdiction’s law, and the last section of this piece covers that clock. The test itself, though, is converging on the same few paragraphs everywhere.

This piece walks those paragraphs from the preparer’s side of the table. Not how to run an assurance engagement, but how to organise the data, documents and judgments behind a physical risk number so the questions answer themselves. The work is not extra. It is the same evidence you needed in order to trust the number yourself, kept in a form someone else can follow.

Your disclosed figure is a chain, not a number

Take a typical disclosure: “14 percent of our asset value is vulnerable to physical climate risk.” The reporting standards ask for exactly this shape. IFRS S2 paragraph 29(c), for example, asks for the amount and percentage of assets or business activities vulnerable to climate-related physical risks. Australia’s AASB S2 carries the same paragraph. So does the UK version in substance, and European and Californian rules ask related questions in their own forms.

That single figure is the end of a chain with at least six links.

  1. A list of your assets: which sites, where, with usable coordinates.
  2. A value for each, which comes from your own ledger.
  3. Hazard information for each location: how exposed each site is to flood, heat, wind, fire and the other perils, now and under future climate scenarios. This link usually comes from a specialist data provider, because almost no reporting entity models climate hazards in house.
  4. A definition: how exposed does a site have to be before you call it “vulnerable”? The standards do not set that cut-off. You do.
  5. Arithmetic: apply the definition, add up the values, divide.
  6. A tie-back: the asset values inside the calculation should be the same values that sit in your financial statements.

Now look at the owners. The hazard data came from your provider. Every other link is yours. The register is yours. The values are yours. The vulnerability cut-off is a judgment only you can make, because it depends on your risk appetite and your view of what matters to your business. The arithmetic is yours, and so is the tie-back.

This is worth stating plainly, because vendors and buyers both blur it: no data provider can hand you a finished disclosure. A provider hands you an input. The judgments that turn that input into a disclosed figure belong to you, and so does the responsibility for them.

The chain view also tells you how to prepare. An assurance practitioner does not evaluate “the number.” They evaluate the chain, link by link, and the assurance standard assigns a different test to each kind of link. Information from outside gets one test. Information you produced gets another. Work done by an outside specialist gets a third. Prepare the answer for each link, file it next to that link, and the engagement becomes a walk down a documented path instead of an excavation.

Physical climate risk data for climate risk assurance: a six-link chain feeding the three ISSA 5000 evidence tests in paragraphs 90, 91 and 92
A disclosed physical risk figure is a six-link chain, and ISSA 5000 tests it with three paragraphs: 90 for outside information, 91 for information you produced, 92 for a data provider treated as a management’s expert. Source: Continuuiti.

ISSA 5000’s evidence rules run from paragraph 89 to paragraph 94. Three of them do the heavy lifting for physical risk data.

Paragraph 90 covers information from outside your organisation. When evidence comes from an external source, the practitioner must evaluate its relevance and its reliability. In ordinary words: is this the right information for the job, and can it be trusted given where it came from? Your provider’s hazard data, the public climate datasets behind it, and any purchased flood maps all sit under this test.

Paragraph 91 covers information you produced yourselves. When the practitioner uses information produced by the entity, they must check it is reliable enough for the purpose. That includes evidence that it is accurate and complete, and that it is precise and detailed enough for what it is being used for. Your asset register is the first thing this paragraph touches. If the register misses sites, carries stale values, or lists head-office addresses instead of plant locations, the weakness flows into every downstream link. No amount of good hazard data repairs it.

Paragraph 92 covers work performed by a management’s expert. A “management’s expert” is the standard’s term for an outside specialist whose work your organisation relies on in preparing its report. A climate data provider will often sit in this category. When it does, the practitioner applies a four-part test that covers both the provider and your use of it. Those four parts are the next section.

Two further paragraphs deal with what happens when the file is thin. Paragraphs 93 and 94 cover doubts. If the practitioner cannot resolve doubts about the reliability of a piece of evidence, they do not simply set it aside and move on. They must consider what the unresolved doubt means for the rest of the evidence, including whether it points to a risk that the disclosure is materially misstated. Read that from the preparer’s side: missing or shaky paperwork is not a neutral gap. It is a finding in the making.

Before going further, take one piece of comfort from the reporting side. The reporting standards expected you to use outside data and estimates. IFRS S1 lists “external ratings, reports and statistics” among legitimate data sources. It also says the use of reasonable estimates is an essential part of preparing sustainability disclosures, provided they are accurately described and explained. Estimates are not the problem. Undescribed estimates are.

The four questions your assurer must ask about your data provider

Paragraph 92 requires the practitioner to do four things when your disclosure leans on a specialist’s work. Each maps to a plain question, and each question has a document that answers it.

1. “Is this provider any good, and do they have a reason to tell you what you want to hear?” The standard’s words: evaluate the competence, capabilities and objectivity of the expert. The answering document is your own vendor evaluation memo, written by you, not supplied by the vendor. Cover what the provider’s methods are built on, whether its input data comes from named public science bodies, and what the commercial relationship looks like. Objectivity is usually the easy part for a data provider: a firm paid to deliver data, not to deliver a favourable rating, has little reason to flatter you. Write the reasoning down anyway. An unwritten evaluation is, for evidence purposes, an evaluation that did not happen.

2. “What did they actually do?” The practitioner must obtain an understanding of the work the expert performed. The answering documents are the provider’s methods description in plain language and its method version identifiers. The pass test is simple. Could a specialist reader take the provider’s documentation and describe, in their own words, how a flood depth or a hazard rating was derived? If the method is a black box, this question has no answer, and paragraph 94’s unresolved-doubt rule is waiting downstream.

3. “What did you do with what they gave you?” This question is aimed at you, not the provider. The practitioner must understand how the expert’s output was used in preparing the disclosure. The answering documents are your “how we used it” memo and your vulnerability threshold rationale. The provider classified your sites; you chose the cut-off, mapped the classifications to asset values, and computed the figure. If that path exists only inside a spreadsheet nobody documented, this question fails even where the provider’s work was flawless.

Of the four documents, this is the one most likely to be missing, because it falls between two owners. The provider assumes you are writing it; your team assumes the provider’s documentation covers it. It does not. Only you can write it.

4. “Does it hold up for this purpose?” The practitioner must evaluate whether the expert’s work is appropriate as evidence for this disclosure. The answering documents are the stated assumptions register, the provider’s known-limitations statement, and your recorded response to those limitations. Fitness here means matching the grade of the data to the grade of the claim. Screening-grade data supporting a screening-grade disclosure, limitations stated, holds up. The same data silently stretched into engineering-grade claims does not.

Some data providers now publish standing audit-support documentation built around exactly these questions. Continuuiti’s, for instance, pairs a register attributing every input dataset to its originating body with plain-language method descriptions, a stated-assumptions register, a known-limitations section, and versioned, reproducible outputs. Whoever your provider is, ask for the equivalent. If it does not exist, questions two and four are currently unanswered, and you are the one who will be sitting across the table when they are asked.

The cheapest time to get those answers is before you sign. Our guide on how to evaluate climate risk assessment tools turns the provider questions into a seven-test protocol you can run during vendor selection.

Sample Climate Risk Assessment

See a full climate risk assessment, end to end

We’ll email you a complete worked example for a manufacturing site: 12 hazards, multiple scenarios, and value-at-risk out to 2050. It shows what a full climate risk assessment output looks like, the kind of provider evidence an assurance file draws on.



The evidence pack: one folder, one table

Everything above condenses into a single working practice. In the same year you prepare the number, assemble one folder. Give every document in it an owner. Hand the practitioner a map instead of a scavenger hunt.

Three habits make the folder work. Freeze and date the version of every input actually used, especially the asset register, so nobody argues later about which extract fed the number. Put a person’s name against every row, because “the team” cannot answer questions. And record decisions when they are made, not at year end: a threshold rationale written the week the threshold was chosen reads very differently from one reverse-engineered eleven months later.

Here is the pack for a typical physical risk disclosure. The vendor rows describe the contents of a well-built provider audit-support document, which some providers already publish as a standing artifact. The entity rows, only you can write.

# What goes in the folder Who owns it Tested under What good looks like
1 Asset register extract used in the assessment: locations, coordinates, values, dated Entity Para 91 Ties to the fixed-asset ledger, covers the whole disclosed boundary, and the version used is frozen and dated
2 Mapping of assessed assets to carrying amounts, reconciled to the financial statements Entity Para 91 Every disclosed dollar traces to a ledger line, and the disclosed percentage recomputes from the mapping
3 Vulnerability threshold definition and the reason for it Entity Paras 91 and 92 Written down before the number was struck, with the cut-off and its rationale
4 Materiality assessment for physical risk Entity Para 91 Criteria stated, applied consistently, signed off
5 “How we used it” memo: provider output to disclosed figure, including any overrides Entity Para 92, third question Every step reproducible on paper, and each override justified in writing
6 Internal review and sign-off of the disclosed figure Entity Paras 89 and 91 A named reviewer checked the figure, and contradictory results were recorded rather than filtered out
7 Provider data source register: originator, version, date and resolution for every dataset Vendor Para 90 Every input dataset is attributed to its originating body with a version and date
8 Provider methods description in plain language Vendor Para 92, second question A specialist reader can follow input to output, with full technical detail available on request
9 Stated assumptions register: scenarios, horizons, building archetypes, replacement values Shared Para 92, fourth question No silent assumptions, and each item labelled as client-supplied or assumed
10 Known-limitations statement, plus your note on how you weighed each one Shared Paras 92 and 94 Limitations volunteered by the provider, and your file shows they were considered, not ignored
11 Method version identifiers and a dated change log Vendor Paras 90 and 92 Each delivered result names the method version that produced it, and changes between versions are dated and explained
12 Reproducibility record: preserved inputs, parameters and outputs Vendor Para 92, fourth question The same inputs and method version return the same outputs, available for the practitioner’s sampling
13 Vendor evaluation memo: competence, capabilities, objectivity, commercial relationship Entity Para 92, first question Your own written assessment, not the vendor’s brochure, with interests and relationships noted
Paragraph references in the Tested under column are all to ISSA 5000, the assurance standard. Source: Continuuiti.

Two rows deserve a highlight.

Row 13 sits last on purpose. Even the evaluation of the vendor is a document the entity owns. Six of the thirteen rows are yours alone, and the two shared rows each have an entity half. A pack that is all vendor paperwork is not an evidence pack. It is a brochure folder.

Row 2 is the single most testable row in the pack. Under IFRS S2’s application guidance, paragraph B65(e), the asset amounts behind a physical risk metric should connect to the amounts in your financial statements. That reconciliation is the one link a practitioner can recompute end to end using nothing but your own records. It is the link an assurance provider is structurally best placed to test. If one row gets gold-plated, make it this one.

Limited and reasonable assurance test the same chain at different depths

Assurance comes in two depths, and the standard is blunt about the difference. In a limited assurance engagement, the level of assurance obtained is, in ISSA 5000’s own words, “substantially lower” than in a reasonable assurance engagement. The procedures differ in nature, timing and extent.

The standard also says where the depth changes. In a limited engagement, the practitioner assesses the risk of material misstatement at the level of the disclosure as a whole: could this figure, as presented, be materially wrong? In a reasonable engagement, the practitioner digs down to the individual claims inside the disclosure, what the standard calls the assertion level. Is the register complete? Are the values accurate? Does the calculation do what it says it does?

Read that as a preparer and two consequences follow.

First, a limited engagement checks process and coherence. It does not re-perform your modelling or rebuild your number. Passing a limited review is therefore not evidence that your number would survive a reasonable engagement. If the assurance depth in your jurisdiction is rising over time, the standard your evidence pack must meet is the destination depth, not this year’s.

Second, do not write for a generalist reader only. Under paragraphs 56 to 58, the practitioner can bring in their own specialist to evaluate technical work; the standard calls this a practitioner’s expert. The practitioner must then weigh the relevance and reasonableness of that specialist’s findings. Assume your methods documentation, assumptions register and threshold rationale will be read by someone who models climate hazards for a living. Plain language and technical depth are not in tension here. The pack should read plainly, with full technical detail available behind it on request.

Where you are on the clock depends on where you file

The duty to obtain assurance is layered on by each jurisdiction, not built into the reporting standard. That is why the core of this piece is universal and this section is short. Three regimes show the full spread.

Australia: legislated, phased, already running. Australia adopted ISSA 5000 as ASSA 5000, operative for Corporations Act sustainability reports from 1 January 2025, nearly two years ahead of the international date. The evidence paragraphs carry over unchanged. A companion standard, ASSA 5010, sets the phasing. In a reporter’s first year, only governance, the identification of climate risks and Scope 1 and 2 emissions face a limited review. Climate metrics, including the physical risk metric, and scenario analysis face no assurance at all. Years two and three bring limited assurance over the whole report. Reasonable assurance follows from year four, and is mandatory by law for financial years commencing on or after 1 July 2030. The unassured first-year baseline later becomes the comparative that deeper engagements sit alongside.

European Union: limited assurance, now permanent. CSRD reporters face mandatory limited assurance over sustainability reporting. The Omnibus directive, Directive (EU) 2026/470, in force 18 March 2026, removed the planned escalation to reasonable assurance, so limited is the permanent depth. The European Commission’s limited-assurance standards were postponed to 1 July 2027, and until they arrive national frameworks fill the gap. A permanent limited depth fixes how deep the check goes. It does not shrink the evidence question.

California: a pointer, not a threshold. SB 261 climate-risk reports carry no assurance requirement. The statute’s one third-party check is permissive and covers greenhouse-gas claims only, not the risk analysis. Where a report describes emissions, the state board may consider those claims if an independent third-party verifier has verified them. Mandatory assurance in California climate law attaches to the separate SB 253 greenhouse-gas reporting regime, at a limited level from 2026 and a reasonable level from 2030. A review of the 57 first-wave SB 261 reports found about two thirds carried no assurance of any kind, and not one carried assurance scoped to its physical-risk analysis. Read SB 261 as a pointer to where scrutiny is heading, not as the level to build for.

Everyone else. If you report voluntarily against ISSB-based standards, your assurance obligation, if any, comes from local law or your own choice. When an engagement does happen, ISSA 5000 is the standard your practitioner is most likely to be working to.

Answer the test in the year you sit the number

The jurisdictional clocks differ, but they move one way. Australia steps from no assurance to a statutory audit inside four reporting cycles. Europe has locked in a permanent limited check. California asks for nothing today, and its first-wave reports show it. Across all three, one pattern holds: the evidence question does not change with the depth. Only how hard it is pressed changes.

That is why the timing advice is the same everywhere. Build the pack in the year you strike the number. Evidence is cheap to keep in the year it is created. The register extract exists, the provider documentation is current, the threshold debate is fresh, and the people who made the judgment are still in the room. The same evidence is expensive to reconstruct three years later. By then method versions have moved on, the spreadsheet’s author has left, and this year’s number has quietly become the comparative a deeper engagement checks against.

The test is published. Paragraph 90 will ask whether your outside data can be trusted. Paragraph 91 will ask whether your own records are accurate and complete. Paragraph 92 will ask four knowable questions about your provider and your use of its work. You can wait to hear them across a table, or you can answer them now, in one folder with thirteen documents and an owner’s name on each.

One of those options costs a great deal less. It is also the one that makes the number better, because a chain you can evidence is a chain you have actually checked.

Frequently asked questions

Does IFRS S2 require assurance?

No. IFRS S2 and the standards built on it tell you what to disclose, not whether anyone must check it. Whether a climate risk assurance engagement happens, when, and how deeply, is decided by each jurisdiction’s law. Australia has legislated it and phases in a full audit by 2030; the EU mandates permanent limited assurance; California asks for none today. When a check does happen, ISSA 5000 is the standard the practitioner is most likely to work to.

What is a management’s expert?

A management’s expert is the assurance standard’s term for an outside specialist whose work your organisation relies on in preparing its report. A climate data provider often sits in this category. When it does, ISSA 5000 paragraph 92 makes the practitioner run a four-part test: the provider’s competence and objectivity, what work it performed, how you used its output, and whether that work holds up as evidence for your disclosure.

What is the difference between limited and reasonable assurance?

The level of assurance. In ISSA 5000’s own words, a limited engagement gives assurance that is substantially lower than a reasonable engagement. A limited review assesses whether the disclosure as a whole could be materially wrong and checks process and coherence; it does not re-perform your modelling. A reasonable engagement digs down to the individual claims inside the disclosure, testing whether the register is complete, the values accurate, and the calculation sound.

Can climate data be ISSA 5000 compliant?

No. ISSA 5000 governs assurance practitioners and engagements, not datasets, so no dataset or provider can be ISSA 5000 compliant. What you can ask a provider for is the evidence the standard’s tests need: a register attributing every input dataset to its originating body, plain-language method descriptions, a stated-assumptions register, a known-limitations statement, and versioned, reproducible outputs.

Request a Demo

Build physical climate risk data your assurer can test

Continuuiti screens a site or a whole portfolio across 12 hazards and multiple scenarios, then hands you the provider-side evidence a climate risk assurance file leans on: every input dataset attributed to its originating body, plain-language methods, stated assumptions, known limitations, and versioned, reproducible outputs. Enter your email and we’ll set up a demo.



Sources

  • ISSA 5000, General Requirements for Sustainability Assurance Engagements, IAASB, November 2024. Paragraphs drawn on: 9, 15, 56 to 58, 89 to 94, 103L and 103R.
  • ASSA 5000, General Requirements for Sustainability Assurance Engagements, AUASB, made 28 January 2025, compiled 18 July 2025. Operative-date paragraphs Aus 0.3 and Aus 0.4.
  • ASSA 5010, Timeline for Audits and Reviews of Information in Sustainability Reports under the Corporations Act 2001, AUASB, January 2025. Paragraphs 7, 10 and 11 and the Appendix phasing table.
  • IFRS S1 paragraphs 79 and B9; IFRS S2 paragraphs 29(c) and B65(e), ISSB, June 2023.
  • Directive (EU) 2026/470 (the Omnibus directive), in force 18 March 2026, amending the CSRD assurance provisions.
  • California Health and Safety Code sections 38533 (SB 261) and 38532 (SB 253), as amended through AB 154, 2025; Continuuiti review of the 57 first-wave SB 261 reports.
Govind Balachandran
Govind Balachandran

Govind Balachandran is the founder of Continuuiti. He writes extensively on climate risk and operational risk intelligence for enterprises. Previously, he has worked for 7+ years in enterprise risk management, building and deploying third-party risk management and due diligence solutions across 100+ enterprises.