Climate Audit: What to Expect, Standards, and a Free Checklist

A climate audit is a structured review of an organization’s climate-related risks, emissions data, and environmental governance. Think of it as a health check for how well your company understands and manages its exposure to climate change. But the phrase “climate audit” is used loosely, and it can mean a few different things. This guide explains what each one is, the standards that govern them, the steps to run one, and it ends with a free checklist you can use.

A climate audit can mean three different things

It helps to keep three separate ideas apart, because they involve different people and different rules.

A financial audit that considers climate. The yearly audit of your financial statements may have to weigh climate risk, because climate can change the numbers in the accounts, such as the value of a flooded factory. Here climate is an input to the financial audit, not the subject of it. This is the one case where “audit” is the correct word.

External assurance of your climate disclosures. Separately, an independent practitioner can check the sustainability or climate report you publish. This work is called assurance, not audit, and it comes in two depths: limited assurance (a lighter review) and reasonable assurance (a deeper one). When people ask “who audits our climate report,” this is usually what they mean, and the standard that now governs it is ISSA 5000.

An internal climate review. A company can also check its own footprint, controls, and risk exposure. No external practitioner signs off, and no external standard governs it. This is useful preparation, but it should never be confused with the two above.

The rest of this guide focuses on the first two, because those are the ones tied to standards and to what investors and regulators actually ask for.

Regulators and investors are driving climate audits

Regulatory pressure is real, but the picture shifted in 2026. In the United States, the SEC finalized a climate disclosure rule and then rescinded it, so there is no active federal climate disclosure mandate today. The pressure now comes mainly from California’s climate disclosure laws. Two state laws set the pace. SB 253 requires large companies that do business in California and make more than $1 billion a year to report their greenhouse gas emissions. The first disclosures, covering Scope 1 (direct emissions) and Scope 2 (purchased energy), are due in 2026. SB 261 asks companies above $500 million to publish a climate-related financial risk report. SB 261’s start date is on hold while a court challenge plays out, and California has opened a voluntary filing option in the meantime.

In Europe, the EU’s Corporate Sustainability Reporting Directive (CSRD) pushes similar disclosure duties onto a much larger group of companies, and it requires those reports to be externally assured. Globally, the reference standards are the ISSB’s IFRS S1 and IFRS S2, which more and more countries are writing into local law.

Investors are pushing too, and their concern is trust in the numbers. A 2023 PwC investor survey found that 94% of investors believe corporate sustainability reporting contains at least some unsupported claims. That is the gap a climate audit is meant to close. It is also the foundation for credible CDP reporting and climate-related financial disclosure, where auditors and rating agencies look for consistency between what a company claims and what its data supports.

Climate risk shows up in the financial statements

This is where the first kind of climate audit fits in. Climate-related risk, in an audit context, is the financial and operational impact that climate change can have on your reported figures. In the financial-statement audit, existing auditing standards already require auditors to consider whether climate risk affects the numbers. The International Auditing and Assurance Standards Board (IAASB) has published a practice alert on this point. That is a different exercise from assuring the sustainability report itself, which the IAASB now covers directly in ISSA 5000 (more on that below).

These risks fall into two categories.

Physical risks include damage to assets from extreme weather like floods, wildfires, and heat waves. They also cover slower shifts, such as rising sea levels and changing rainfall, that wear down asset values over time. In the accounts, physical risk tends to show up as asset impairments (writing down the value of damaged assets), inventory write-downs (reducing the value of spoiled stock), and provisions, meaning money set aside, for cleanup or restoration after an event.

Transition risks arise from the shift to a low-carbon economy. Carbon pricing, regulation, and changing customer preferences can all affect revenue, asset values, and going-concern assumptions (whether the business can keep operating). The classic transition effect is a shortened useful life for assets that become obsolete, the “stranded asset” problem. A thorough physical climate risk assessment at the facility level helps size the physical side of this exposure.

ISSA 5000 is the standard for assuring climate disclosures

This is the second kind of climate audit from the start of this guide: the external check on the disclosures you publish. When a company wants that check, it runs under an assurance standard. ISSA 5000, General Requirements for Sustainability Assurance Engagements, is the first standard written specifically for this job. The IAASB approved it in September 2024, and it takes effect for reporting periods beginning on or after 15 December 2026, with earlier use permitted. It covers both limited and reasonable assurance in a single standard. The older, more general standard used before it, ISAE 3000, is still referenced during the transition.

Assurance requirements are already arriving in law. Under California’s SB 253, companies must have their greenhouse gas data checked by an independent third party: limited assurance on Scope 1 and Scope 2 emissions starting in 2026, rising to reasonable assurance in 2030. In the EU, CSRD reports must carry limited assurance now, a level the 2026 Omnibus directive made permanent.

One point matters for how you prepare. No dataset or software is “ISSA 5000 compliant,” and no vendor can be. Assurance standards govern the practitioner and the engagement, not the inputs. What a company can do is keep its climate data, and the judgments around it, in a form an assurer can test. For the detail, see our guides to presenting physical climate risk data for assurance and to who checks a CSRD report under limited assurance.

How to run a climate audit, step by step

Running a climate audit involves five core steps:

Climate audit: five-step process flow from scope definition to findings documentation
How to conduct a climate audit in five steps. Source: Continuuiti.

1. Define scope and boundaries

Decide which facilities, operations, and supply-chain segments the audit will cover. Decide whether you are covering Scope 1 (direct emissions), Scope 2 (purchased energy), or all three scopes including Scope 3 (your supply chain).

2. Resolve your sites, then gather the data

Before you can pull hazard data for a site, you need to turn its address into map coordinates and check the match quality. A wrong or imprecise location quietly corrupts every number that follows, so this step is worth getting right. Once your sites are resolved, collect emissions data from energy bills, fuel records, travel logs, and supplier surveys. Then pull physical-risk data for each location, covering hazards like floods, heat waves, and water stress.

3. Assess against the right standards

Compare your data and processes against the relevant framework. For climate disclosure, the reference is now IFRS S2. For emissions accounting, use the GHG Protocol. If your report will be assured, check it against what an assurer will test.

4. Identify gaps and material risks

Flag where data is incomplete, methods are inconsistent, or risks are not adequately disclosed. A screen shows you where exposure is concentrated, but materiality is still your company’s judgment to make, not the data’s. Prioritize the gaps that affect the financial statements or regulatory compliance.

5. Document findings and recommendations

Compile a report with findings, risk ratings, and specific fixes. Include a timeline for closing each gap and assign an owner to every action.

What makes a number assurance-ready

An assurer testing a climate figure does not just ask “what is the number.” They ask “show me how you got it, and show me it holds up.” A physical-risk number is assurance-ready when it carries:

  • Named, dated source datasets, so each value traces back to where it came from.
  • The emissions scenario and time horizon stated on every figure.
  • The basis made clear, for example whether a flood depth assumes no defenses.
  • Model limitations disclosed up front, not discovered later.
  • Preserved, reproducible outputs, so the same inputs reproduce the same result.

Sample Climate Risk Assessment

See a full climate risk assessment, end to end

We’ll email you a complete worked example for a site: 12 hazards, multiple scenarios, and value-at-risk out to 2050. It’s the kind of assessment output an assurer traces behind a climate disclosure.



Different standards govern each part of a climate audit

Several frameworks shape what a climate audit covers. Some tell you how to measure or what to disclose. Others govern how an independent practitioner assures the result.

Framework Focus When it applies
GHG Protocol Emissions accounting across Scope 1, 2, and 3 The baseline for any climate audit
IFRS S1 & S2 (ISSB) What to disclose about climate: governance, strategy, risk management, and metrics. It carries the former TCFD structure forward. A disclosure standard, not an assurance standard. Companies in countries adopting the ISSB standards; the growing global reference
CDP Annual climate questionnaire and scoring Companies answering investor or customer CDP requests
ISO 14064 GHG quantification and verification Organizations seeking third-party verified emissions
CSRD (EU) Mandatory sustainability reporting for in-scope EU companies EU-based or EU-listed companies over the size thresholds
ISSA 5000 (IAASB) The dedicated standard for assuring sustainability and climate disclosures. Covers both limited and reasonable assurance. Approved September 2024; effective for periods beginning on or after 15 December 2026. When an independent practitioner assures a climate or sustainability report
ISAE 3000 (IAASB) The older, general assurance standard used for sustainability engagements before ISSA 5000 The predecessor, still referenced during the transition
CSRD Article 26a (EU) The EU legal requirement that CSRD reports be externally assured, at a limited-assurance level EU CSRD reporters

Most climate audits touch several of these. A common setup uses the GHG Protocol for emissions, IFRS S2 for risk disclosure, and CDP as the reporting channel, with ISSA 5000 governing any external assurance. The CDP 2026 Corporate Health Check shows why auditing adaptation matters: it found a $1.47 trillion climate adaptation gap, with only 9% of companies investing in physical adaptation.

Climate audit: physical climate risk heatmap showing hazard ratings across scenarios and time horizons to 2050
A climate audit screens physical risk across many hazards and scenarios. Source: Continuuiti.

A climate audit checklist

Use this checklist to track progress through your climate audit. The final group, assurance readiness, is what an external checker looks for, so it matters most if your report will be assured.

Emissions data

  • Scope 1 emissions calculated and documented
  • Scope 2 emissions calculated, both location-based and market-based
  • Material Scope 3 categories identified and estimated
  • Base year set with a recalculation policy

Climate risk assessment

  • Site addresses geocoded, each with a match-quality score, and low-quality matches resolved
  • Physical hazard exposure screened for every site across the 12 hazards, emissions scenarios, and time horizons
  • Each figure states its scenario, time horizon, and basis, such as flood risk before any defenses
  • High-exposure sites flagged for closer analysis
  • Transition-risk scenarios assessed

Governance

  • Board oversight of climate risk documented
  • Management responsibilities for climate assigned
  • Climate risk built into enterprise risk management

Disclosure readiness

  • IFRS S2 disclosures drafted or updated
  • CDP responses checked against the current CDP scoring methodology
  • Figures consistent across every report and submission

Assurance readiness

What an assurer tests when your report is checked. For the Australian statutory timetable, see when an AASB S2 report is reviewed and when it is audited.

  • Every reported number traces back to a source you can show
  • Reported asset values reconcile to your financial accounts
  • A named person owns each figure
  • Methods and assumptions written down when they were decided
  • Data sources listed with version and date, and outputs preserved as dated records
  • Provider limitations recorded, with your response to each

Platforms like Continuuiti can speed up the risk-assessment part of a climate audit by delivering automated, screening-grade physical-risk data across 12 hazards for any location in minutes instead of weeks. The output is the identification layer: it flags where exposure is concentrated so deeper, site-specific work can focus on the sites that warrant it.

Frequently asked questions

What is a climate audit?

A climate audit is a systematic review of an organization’s greenhouse gas emissions, climate risk exposure, and environmental governance. In practice the phrase covers three things: a financial-statement audit that considers climate, external assurance of a climate or sustainability report, and an internal climate review.

Is a climate audit the same as assurance?

Not exactly. When an independent practitioner checks your climate disclosures, the correct term is assurance, not audit, and it comes in two depths, limited and reasonable. The standard written for it is ISSA 5000, which the IAASB approved in September 2024 and which takes effect for periods beginning on or after 15 December 2026.

What is climate-related risk in audit?

Climate-related risk in audit refers to financial and operational impacts from climate change that can affect reported figures. Physical risks such as floods and heat waves can drive asset impairments, inventory write-downs, and provisions. Transition risks such as carbon pricing and obsolescence can shorten asset useful lives and affect going-concern assumptions.

How often should organizations conduct a climate audit?

Most organizations conduct a climate audit annually, timed to align with their financial reporting cycle. Companies facing rapid regulatory change or operating in high-risk sectors may benefit from reviewing key risk indicators more often.

What is the difference between a climate audit and a carbon audit?

A carbon audit focuses narrowly on measuring and accounting for greenhouse gas emissions. A climate audit is broader, covering emissions plus physical and transition risk, governance, and disclosure readiness.

Who needs a climate audit?

Any organization reporting climate data to investors, regulators, or rating agencies benefits from a climate audit. Assurance is increasingly required by law, including under the EU’s CSRD and California’s SB 253, and disclosure frameworks such as IFRS S2 and CDP cover thousands of companies globally.

Govind Balachandran
Govind Balachandran

Govind Balachandran is the founder of Continuuiti. He writes extensively on climate risk and operational risk intelligence for enterprises. Previously, he has worked for 7+ years in enterprise risk management, building and deploying third-party risk management and due diligence solutions across 100+ enterprises.