By: Johannes Fiegenbaum on 5/14/26, 11:36 AM · Last updated September 4, 2026
Supervisors and auditors no longer ask whether a bank or insurer has looked at climate risk. They ask which method produced the numbers, which scenarios and data went in, and why those and not others. ISO 14091:2021 is the reference most institutions reach for. It answers the process question well and the threshold question not at all.
Table of contents
What it is: EN ISO 14091:2021, "Adaptation to climate change, Guidelines on vulnerability, impacts and risk assessment", is a process standard for a climate risk and vulnerability assessment (CRVA). It frames the analysis, prepares it, carries it out, then documents it. Risk is modelled as the interaction of hazard, exposure and vulnerability, not as probability times severity, and impact chains carry that logic into business processes.
Who it is for: any organisation, but in regulated finance it lands on three desks at once. Risk management needs the hazard and exposure layer for credit and underwriting. Sustainability reporting needs the same output for ESRS E1-9. Internal audit needs the documentation trail.
Why it rather than a free framework: because it gives those three desks one vocabulary and an auditor recognises it. That is the whole advantage, and it is a real one.
Within the family, ISO 14090:2019 sets the adaptation principles, ISO 14091 operationalises the assessment, ISO/TS 14092 covers the municipal level. Where an ISO 14001 system exists, the climate amendment makes climate part of the organisational context and ISO 14091 docks in as the deep-dive module.
Live data: how flooding, drought and heat hit specific locations, in the Fiegenbaum Atlas climate risk dashboard.
EFRAG prescribes no methodology, it asks for a robust one. That is why the crosswalk matters: each CRVA step answers a named regulatory datapoint, so one analysis serves three reporting duties.
| CRVA step | ESRS E1-9 | Taxonomy DNSH, adaptation | IFRS S2 |
|---|---|---|---|
| Hazard identification | Material physical hazards per horizon | Screening of all 28 hazards in Annex I | Physical risks identified |
| Exposure assessment | Assets and operations at material risk | Exposure over the activity lifetime | Assets vulnerable to physical risk |
| Vulnerability and adaptive capacity | Resilience of strategy and business model | Adaptation solutions where risk is material | Climate resilience assessment |
| Documentation and communication | Monetary amounts and revenue share at risk | Evidence for the adaptation plan | Scenario analysis disclosure |
The last row is where the standard leaves you alone. ESRS E1-9 wants money, the CRVA delivers a ranked risk picture, and the translation is yours to defend. Scenario choice sits in the same place: pick the pair you can justify and document the RCP or SSP logic behind it.
None of the supervisory texts name ISO 14091. All of them describe its three layers. The 7th amendment to BaFin's MaRisk requires sustainability risks to be measured with scientifically grounded scenarios (AT 2.2 and AT 4.1), fed into business and risk strategy and reflected in risk classification. The ECB guide on climate-related and environmental risks treats climate as a driver of existing risk categories, assessed for materiality over short, medium and long horizons. EBA Pillar 3 sorts physical risk into hazard, exposure and asset vulnerability, and the EBA's own reading is that the numbers barely compare because methods differ.
For insurers the hook is Solvency II. The ORSA has to consider long-term climate scenarios, and the CRVA feeds it directly: the hazard and exposure layer per location maps onto underwriting and asset exposure, so the scenario pair carries over instead of being rebuilt. That reuse is the strongest practical argument for the standard, and the same one that surfaces in talks about insurability and premiums.
My position: in a regulated balance sheet the value of ISO 14091 is not the method, it is the audit trail. An institution that can show which hazard set, which scenario and which data vintage went into a rating override wins that conversation. One that cannot loses it, however good its model. In the CSRD and ESRS reports I have analysed, the resilience analysis is described in prose and the method behind it is rarely named, which is exactly where a supervisor pushes.
What survives the auditor's question about method choice looks unglamorous. In one mid-sized manufacturing group I geocoded every site on the CORDEX EUR-11 grid at 12.5 km, ran RCP 4.5 and RCP 8.5 for 2031 to 2040 and 2041 to 2070, and screened all 28 Taxonomy hazards. Two scenarios, two horizons, one grid, fixed before the results were known. It held because the choice was justified in advance, not because the grid was the finest available.
ISO 14091 gives you a process, not a result. Everything a supervisor will argue about, the threshold, the scale, the data vintage, sits in the part you write yourself.
| What the standard leaves open | What I fix before the analysis starts |
|---|---|
| Scoring convention | Five-tier scale per parameter, thresholds written down first |
| Materiality threshold for a hazard | Tier at which a hazard enters reporting, agreed with the auditor |
| Data sources | Named set with version and horizon, one per parameter |
| Adaptive capacity | Scored against existing measures, not asserted |
| Financial quantification | Separate module, because ESRS E1-9 needs a number |
Under limited assurance a reviewer does not re-run the analysis. The reviewer checks whether it was done the way it says it was done, and asks to see:
Consistency beats sophistication. A coarse assessment repeated identically survives assurance, a refined one rebuilt every year does not. Method, data choice and monetisation as one package is what my climate risk analysis delivers, and it feeds financial planning rather than ending at a heat map.
Neither. It is a guidance standard, so there is no ISO 14091 certificate and no accredited certification scheme. It is used voluntarily because ESRS E1-9 and the Taxonomy DNSH check both need a method that holds up in assurance.
Any organisation, but in a bank or insurer it is used by risk management, sustainability reporting and internal audit at once, for own operations and, in reduced form, for a collateral or underwriting portfolio.
From ISO directly, or as EN ISO 14091 from the national standards body that adopted the European version, DIN in Germany. It is a paid document, and only the purchased text is authoritative.
The hazard and exposure layer per location is reused: it maps onto underwriting exposure and the asset side, and the scenario pair chosen for the CRVA carries into the ORSA's long-term climate scenarios instead of a separate scenario set being defined.
ESG and sustainability consultant based in Hamburg, specialised in VSME reporting and climate risk analysis. Has supported 300+ projects for companies and financial institutions, from mid-sized manufacturers to major banks and insurers.
More aboutClimate data is the key to improving business decisions, minimizing risks, and meeting regulatory requirements. With programs like Copernicus, you can access detailed data for ...
Read more →