Climate Risk: A New Regulatory Requirement or a New Managerial Responsibility?

Climate Risk: un nuovo obbligo normativo o una nuova responsabilità manageriale?

Abstract

Has climate risk truly become a regulatory requirement, or does it remain merely a best practice? The answer is becoming increasingly clear: European regulations, ISO standards, and supervisory authorities are converging toward an approach that requires organizations to integrate climate change into their governance, risk management, and business continuity processes. In this in-depth analysis, we examine the key regulatory references—from the CSRD to the ESRS, from ISO standards to the guidelines issued by the ECB, EBA, Banca d’Italia, and DORA—highlighting what this actually means for risk managers and resilience managers.

—-

For many years, climate change was viewed primarily as an environmental issue, addressed within the context of sustainability policies and corporate social responsibility.

In recent years, however, the European and international regulatory framework has changed significantly.

Climate risk has gradually become an integral part of financial regulation, ISO standards, management systems, the expectations of regulatory authorities, and corporate reporting processes.

There is still no regulation that generally requires all companies to prepare a specific climate risk assessment.

However, there is an increasingly coherent set of guidelines, regulations, and standards that all point in the same direction: identifying climate risks, understanding their impact on business, and incorporating them into decision-making processes.

From Sustainability to Resilience

One of the most significant changes concerns the very role of climate risk.

With the introduction of theCorporate Sustainability Reporting Directive (CSRD)and theEuropean Sustainability Reporting Standards (ESRS), climate change is no longer just an environmental indicator.

Companies subject to the CSRD are required to assess how climate-related risks and opportunities may affect their strategy, business model, value chain, and economic and financial performance.

The concept ofdual materialityrepresents a true cultural shift. It is no longer enough to assess the impact an organization has on the climate; we must also understand how climate change might affect the organization’s ability to create value over time.

This is, in every sense, an assessment of resilience.

ISO standards are moving in the same direction

The ISO world is also evolving rapidly.

StandardsISO 14090andISO 14091are currently the leading international standards for climate change adaptation and climate vulnerability assessment. Even more significant is the amendment published in 2024 by ISO and IAF, which affects all major management systems, includingISO 22301for Business Continuity.

The amendment requires organizations to assess whether climate change is a significant factor in their operational context. This may seem like a minor change. In reality, it introduces a principle that is bound to have significant consequences: climate change can no longer be considered an issue outside the management system.

If it is relevant to the organization, it must be taken into account when defining the context, assessing risks, planning, and pursuing continuous improvement.

The financial sector is already a few steps ahead

Banks and financial intermediaries have been navigating this path for several years.

TheEuropean Central Bank,the European Banking Authority, andthe Bank of Italyhave published expectations and guidelines requiring the integration of climate and environmental risks into governance, strategy, internal control systems, and enterprise risk management processes. The goal is not to create a new category of risk, but to understand how climate change can affect existing risks, such as credit, operational, market, reputational, and business continuity risks.

Also, theDORA Regulation, although not specifically dedicated to climate risk, offers an interesting perspective. Financial organizations must, in fact, ensure digital operational resilience even in the face of physical events that could compromise ICT infrastructure, data centers, telecommunications networks, and technology providers. A flood, a wildfire, or a heat wave can therefore quickly turn into a digital resilience issue.

Beyond Compliance

However, limiting oneself to regulatory compliance would be a mistake. The most mature organizations are using these guidelines not simply to meet new documentation requirements, but to genuinely improve their ability to adapt. Assessing climate risk, in fact, means examining very concrete issues:

  • Will the facilities continue to be suitable over the next twenty years?
  • Is the supply chain exposed to the same climate scenarios?
  • Are Recovery Time Objectives still achievable during extreme events?
  • Will today’s investments still be appropriate in the future climate context?
  • Does the insurance program truly reflect the new levels of exposure?

The Real Challenge

The standards are therefore sending a common message: climate risk does not “belong” exclusively to the sustainability function. It is not merely an environmental issue. It is an issue that involves Business Continuity, Enterprise Risk Management, Property Risk Engineering, Health and Safety, the Supply Chain, Risk Transfer, and, increasingly, the strategic decisions of the Board of Directors.

For the Resilience Manager, this represents an important opportunity.

Those who can successfully integrate these different languages will be able to turn a set of regulatory requirements into a genuine competitive advantage, helping to build organizations that are not only compliant but, above all, more resilient and better prepared to face the climate challenges of the coming decades.

This post is also available in: ItalianFrench

Would you like to find out more about our training programmes?

Discover the official international certification courses offered by DRI Italy and DRI France on Business Continuity and Cyber Resilience, or the NFPA courses on fire protection systems and all the other Continuitaly courses.

Discover our courses →

Vuoi approfondire la nostra offerta formativa?

Scopri i corsi ufficiali di certificazione internazionale DRI Italy e DRI France dedicati alla Business Continuity e alla Cyber Resilience, oppure i corsi NFPA dedicati ai sistemi antincendio e tutti gli altri corsi Continuitaly.

Scopri i nostri corsi →