Skip to content
9 min read

ISO 14091 in Practice: What Banks and Insurers Expect from a Climate Risk Assessment

Audited financial documents and report, illustrating ISO 14091 climate risk analysis audit

Supervisors and auditors no longer ask whether a bank or insurer has looked at climate risk. They ask which method produced the numbers, which scenarios and data went in, and why those and not others. ISO 14091:2021 is the reference most institutions reach for. It answers the process question well and the threshold question not at all.

What ISO 14091 is, who it is for, and how it sits in the 14090 family

What it is: EN ISO 14091:2021, "Adaptation to climate change, Guidelines on vulnerability, impacts and risk assessment", is a process standard for a climate risk and vulnerability assessment (CRVA). It frames the analysis, prepares it, carries it out, then documents it. Risk is modelled as the interaction of hazard, exposure and vulnerability, not as probability times severity, and impact chains carry that logic into business processes.

Who it is for: any organisation, but in regulated finance it lands on three desks at once. Risk management needs the hazard and exposure layer for credit and underwriting. Sustainability reporting needs the same output for ESRS E1-9. Internal audit needs the documentation trail.

Why it rather than a free framework: because it gives those three desks one vocabulary and an auditor recognises it. That is the whole advantage, and it is a real one.

Within the family, ISO 14090:2019 sets the adaptation principles, ISO 14091 operationalises the assessment, ISO/TS 14092 covers the municipal level. Where an ISO 14001 system exists, the climate amendment makes climate part of the organisational context and ISO 14091 docks in as the deep-dive module.

Live data: how flooding, drought and heat hit specific locations, in the Fiegenbaum Atlas climate risk dashboard.

Where ISO 14091 meets ESRS E1-9, the EU Taxonomy and IFRS S2

EFRAG prescribes no methodology, it asks for a robust one. That is why the crosswalk matters: each CRVA step answers a named regulatory datapoint, so one analysis serves three reporting duties.

CRVA step ESRS E1-9 Taxonomy DNSH, adaptation IFRS S2
Hazard identificationMaterial physical hazards per horizonScreening of all 28 hazards in Annex IPhysical risks identified
Exposure assessmentAssets and operations at material riskExposure over the activity lifetimeAssets vulnerable to physical risk
Vulnerability and adaptive capacityResilience of strategy and business modelAdaptation solutions where risk is materialClimate resilience assessment
Documentation and communicationMonetary amounts and revenue share at riskEvidence for the adaptation planScenario analysis disclosure

The last row is where the standard leaves you alone. ESRS E1-9 wants money, the CRVA delivers a ranked risk picture, and the translation is yours to defend. Scenario choice sits in the same place: pick the pair you can justify and document the RCP or SSP logic behind it.

What banks, insurers and their supervisors actually ask for

None of the supervisory texts name ISO 14091. All of them describe its three layers. The 7th amendment to BaFin's MaRisk requires sustainability risks to be measured with scientifically grounded scenarios (AT 2.2 and AT 4.1), fed into business and risk strategy and reflected in risk classification. The ECB guide on climate-related and environmental risks treats climate as a driver of existing risk categories, assessed for materiality over short, medium and long horizons. EBA Pillar 3 sorts physical risk into hazard, exposure and asset vulnerability, and the EBA's own reading is that the numbers barely compare because methods differ.

For insurers the hook is Solvency II. The ORSA has to consider long-term climate scenarios, and the CRVA feeds it directly: the hazard and exposure layer per location maps onto underwriting and asset exposure, so the scenario pair carries over instead of being rebuilt. That reuse is the strongest practical argument for the standard, and the same one that surfaces in talks about insurability and premiums.

My position: in a regulated balance sheet the value of ISO 14091 is not the method, it is the audit trail. An institution that can show which hazard set, which scenario and which data vintage went into a rating override wins that conversation. One that cannot loses it, however good its model. In the CSRD and ESRS reports I have analysed, the resilience analysis is described in prose and the method behind it is rarely named, which is exactly where a supervisor pushes.

What survives the auditor's question about method choice looks unglamorous. In one mid-sized manufacturing group I geocoded every site on the CORDEX EUR-11 grid at 12.5 km, ran RCP 4.5 and RCP 8.5 for 2031 to 2040 and 2041 to 2070, and screened all 28 Taxonomy hazards. Two scenarios, two horizons, one grid, fixed before the results were known. It held because the choice was justified in advance, not because the grid was the finest available.

Where the standard falls short, and what an assurance provider checks

ISO 14091 gives you a process, not a result. Everything a supervisor will argue about, the threshold, the scale, the data vintage, sits in the part you write yourself.

What the standard leaves open What I fix before the analysis starts
Scoring conventionFive-tier scale per parameter, thresholds written down first
Materiality threshold for a hazardTier at which a hazard enters reporting, agreed with the auditor
Data sourcesNamed set with version and horizon, one per parameter
Adaptive capacityScored against existing measures, not asserted
Financial quantificationSeparate module, because ESRS E1-9 needs a number

Under limited assurance a reviewer does not re-run the analysis. The reviewer checks whether it was done the way it says it was done, and asks to see:

  • the scenario and horizon decision, dated before the results
  • the data sources with version, resolution and provider
  • the materiality thresholds and who signed them off
  • the site or exposure list the analysis actually covered, against the consolidation scope
  • the same method applied to the prior year, or an explained change

Consistency beats sophistication. A coarse assessment repeated identically survives assurance, a refined one rebuilt every year does not. Method, data choice and monetisation as one package is what my climate risk analysis delivers, and it feeds financial planning rather than ending at a heat map.

Frequently asked questions

Is ISO 14091 mandatory or certifiable?

Neither. It is a guidance standard, so there is no ISO 14091 certificate and no accredited certification scheme. It is used voluntarily because ESRS E1-9 and the Taxonomy DNSH check both need a method that holds up in assurance.

Who is ISO 14091 for?

Any organisation, but in a bank or insurer it is used by risk management, sustainability reporting and internal audit at once, for own operations and, in reduced form, for a collateral or underwriting portfolio.

Where do I obtain the standard?

From ISO directly, or as EN ISO 14091 from the national standards body that adopted the European version, DIN in Germany. It is a paid document, and only the purchased text is authoritative.

How does a CRVA feed the ORSA?

The hazard and exposure layer per location is reused: it maps onto underwriting exposure and the asset side, and the scenario pair chosen for the CRVA carries into the ORSA's long-term climate scenarios instead of a separate scenario set being defined.

Johannes Fiegenbaum

Johannes Fiegenbaum

ESG and sustainability consultant based in Hamburg, specialised in VSME reporting and climate risk analysis. Has supported 300+ projects for companies and financial institutions, from mid-sized manufacturers to major banks and insurers.

More about