Quick answer
A climate risk assessment identifies how a changing climate affects your organisation, how significant each effect is, and what you intend to do about it. It covers two categories: physical risk, meaning heat, fire, flood, drought, storm and sea level acting on your sites and supply chain, and transition risk, meaning the market, regulatory, technology and reputational shifts that come with the response to climate change. Most assessments take a few weeks. The output is a register of risks with ratings, owners and treatments, plus a short report your board, insurer, lender or certification auditor can read.

Why this is being asked for now
Three separate pressures have arrived at once, and they land on the same document.
Large listed companies now report climate risk under Australia’s mandatory climate reporting regime, and they ask their suppliers for the underlying data. If you have received a questionnaire asking about emissions or climate resilience, that is the mechanism at work. We have covered how that reaches suppliers in a separate article on Scope 3 questionnaires.
Insurers and lenders have started pricing physical exposure directly, site by site, rather than treating it as a general economic condition.
And climate change is now an explicit consideration inside the ISO management system standards. Since 2024, clause 4.1 has required organisations to determine whether climate change is a relevant issue for them, and clause 4.2 notes that interested parties may have climate-related requirements. That wording applies across the management system standards, not only ISO 14001.
Physical risk and transition risk
The distinction matters because the two need different evidence and different treatments.
Physical risk is the climate acting on you. Extreme heat affecting outdoor work and worker health, bushfire threatening a site or an access road, flooding of premises or transport routes, drought affecting water-dependent processes, storm damage and coastal inundation. Physical risk is assessed by location, so it needs a site list before anything else.
Transition risk is the response to climate change acting on you. Customers imposing procurement conditions, regulators changing disclosure or licensing obligations, insurers repricing or withdrawing cover, capital becoming harder to access, technology shifts stranding equipment, and reputational exposure. Transition risk is assessed by market and by dependency rather than by postcode.
An assessment that covers only one of the two is incomplete, and it is usually transition risk that gets left out.
A worked example, and what it cost
In August 2026, EVT wrote down the value of Thredbo Alpine Resort from $292 million to $143 million, a reduction of $149 million. The company attributed the decline to an unseasonably warm start to the 2026 winter and to the capital investment now needed in chairlifts and snowmaking. Its own annual results describe the resort as “structurally exposed to a warming climate” because the business model depends on natural snow cover.
The context around that number is worth noting. A 2024 study by the Australian National University and Protect Our Winters found the Australian ski season had already contracted by up to 28 per cent across most resorts. Andrew Watkins, an adjunct professor in climate science at Monash University, told the ABC that a further 30 per cent decline in season length is plausible by 2050. Smaller resorts including Selwyn in New South Wales and Baw Baw in Victoria closed early in 2026.
Here is the part that applies to organisations that have nothing to do with skiing.
None of this was secret. The trend was published, the mechanism was understood, and the exposure was specific to an identifiable asset. The risk did not become real when the valuer wrote it down. It became recognised when the valuer wrote it down. The gap between those two moments is where a climate risk assessment does its work, because a risk you have identified, rated and started treating is one you are managing. A risk you have not is one that eventually gets priced by somebody else, on their timetable rather than yours.
Substitute your own dependency for snow cover. Water availability for a processor, road access for a transport operator, ambient temperature for outdoor construction, growing season for an agricultural supplier, cold chain integrity for a food business. The structure of the problem does not change.
Where climate risk sits in an ISO management system
If you hold or are pursuing certification, this is not a separate exercise bolted on the side.
Clause 4.1, context of the organisation. You determine whether climate change is a relevant external issue. For most Australian organisations with physical sites, outdoor work or a weather-exposed supply chain, it is, and the assessment is your evidence for that determination.
Clause 4.2, interested parties. Customers, insurers, lenders, regulators and communities may all hold climate-related requirements. Those requirements need capturing alongside everything else you record about interested parties.
Clause 6.1, risks and opportunities. Identified climate risks feed your existing risk process. They do not need a parallel register.
A point worth being clear about, because it is a common misreading. The requirement is about climate change as an issue affecting your organisation. It is not a requirement to calculate your carbon footprint, publish a climate action plan or reduce emissions. Those may be sensible things to do and your customers may ask for them, but they come from elsewhere. Clause 4.1 asks a narrower question, and you can answer it fully without taking a position on anything contested.
ISO 14001:2026, published in April 2026, replaced both ISO 14001:2015 and the 2024 climate change amendment, so organisations transitioning to the current edition will find climate handled within the standard itself. We cover the equivalent transition for ISO 9001 separately.
What the work involves
A typical assessment runs in five steps.
Scope and site list. Which entities, which locations, which parts of the supply chain, and over what time horizon. Most organisations look at the present, the medium term and roughly 2050.
Hazard and exposure screening. For each location, which physical hazards are credible and how they are projected to change. Publicly available climate projection data covers most of what a general business needs, so this rarely requires commissioned modelling.
Transition risk workshop. A structured session with the people who understand your markets, customers, capital and regulatory position. This is the step most often skipped and the one that usually surfaces the material findings.
Rating and treatment. Each risk is rated using your existing risk criteria, not a separate climate scale, then assigned an owner and a treatment. Where you decide to accept a risk, the reasoning is recorded.
Report and register. A short report suitable for the board or a customer, and a live register that feeds your management system.
How long it takes
For a single-site organisation, a few weeks from scoping to report. Multi-site or multi-entity organisations run longer, mostly because assembling the site list and getting the right people into the transition workshop takes time rather than because the analysis is harder.
The register should be reviewed at least annually and whenever you add a site, change a major supplier or enter a new market. A climate risk assessment that is three years old and untouched carries very little weight with an auditor, an insurer or a customer.
Common mistakes
Assessing physical risk only. It is the easier half and the data is readily available, so it gets done and transition risk quietly does not. Transition risk is where the commercial surprises tend to live.
Building a separate register. Climate risks belong in the risk process you already run. A standalone climate register drifts out of date and nobody reads it.
Using someone else’s risk criteria. If the climate assessment rates risks on a different scale from the rest of your management system, the ratings cannot be compared and the whole thing sits awkwardly.
Confusing the assessment with a reduction commitment. Identifying that heat exposure threatens your outdoor workforce is a risk finding. Committing to an emissions target is a strategic decision. Keeping them separate makes both easier to defend.
Stopping at the report. The report satisfies the person who asked for it. The register, the owners and the review cycle are what make the finding useful the following year.
Questions we get asked
Do we need one if we are not a reporting entity?
Not by law. But if you supply a company that is, expect the question to reach you through procurement, and expect it to arrive with a deadline attached.
Is this the same as an environmental aspects and impacts assessment?
No, and the difference is worth holding onto. An aspects and impacts assessment under ISO 14001 looks at your effect on the environment. A climate risk assessment looks at the climate’s effect on you. They complement each other and use different methods.
Can we do it ourselves?
Yes. The method is not exotic and the projection data is public. Organisations most often bring someone in for the transition risk workshop, where an outside perspective on market and regulatory exposure adds the most, and for structuring the register so it survives contact with an audit.
Will an auditor ask for it?
An auditor will ask how you determined whether climate change is a relevant issue under clause 4.1. A documented assessment answers that in one document. A verbal assertion generally leads to more questions.
Getting it done
Streamline builds climate risk registers that sit inside your existing management system rather than beside it, using your risk criteria and your review cycle, so the output holds up in front of an auditor, a customer or an insurer.
Scott Bishop is a lead auditor across ISO 9001, 14001, 45001 and 27001, and has run this work for organisations in construction, manufacturing, transport and professional services.
If you have received a climate questionnaire from a customer, or you are preparing for a transition to ISO 14001:2026 and want clause 4.1 handled properly, get in touch for a conversation about scope. We also offer full ISO 14001 consulting and environmental auditing.











