How to Design a Board-Level Climate Risk Governance Framework That Withstands Supervisory Scrutiny
This guide sets out how to build a board-level climate risk governance framework that holds up under PRA, FCA, ECB or equivalent supervisory review. After reading, you will know where most frameworks fail on inspection and how to structure yours so it does not.
Start with what supervisors actually test
Supervisors are not grading your climate ambition. They are testing whether your board understands the material risks, has embedded them into decision-making, and can evidence that embedding under challenge. SS3/19, the ECB Guide on climate-related and environmental risks, and equivalent frameworks all converge on the same four questions: Does the board own it? Is it integrated into risk appetite? Can you quantify exposure? Are you acting on what you find?
Most frameworks fail because they answer the first question with a committee mandate, the second with a paragraph in the RAS, the third with a scenario deck, and the fourth with a roadmap. That is compliance theatre. Supervisors know the difference.
Get the board accountability structure right first
One named board director must own climate risk. Not the Chair of Risk by default: pick the director whose portfolio makes the ownership credible. If your Chief Risk Officer is the executive lead, the board owner should not be someone who will simply defer to them.
Avoid creating a standalone Climate Committee unless you are large enough to justify it. For most firms, climate risk should sit within the existing Risk Committee, with a clear reporting cadence, defined escalation triggers, and time on the agenda that is protected, not squeezed. Supervisors read minutes. Thin minutes on climate, month after month, tell them everything.
The SMF holder for climate risk (typically SMF4 or the CRO under SMF2) must have a role profile that names it explicitly. If it is not in the statement of responsibilities, it is not owned.
Integrate into risk appetite, not alongside it
The most common weakness supervisors flag is a climate risk appetite that reads as a parallel document. It should not be. Climate should appear inside your existing appetite statements for credit, market, operational, underwriting, and strategic risk, with metrics that connect to the same tolerance framework.
Good looks like: financed emissions thresholds tied to sector concentration limits; physical risk exposure metrics in property and infrastructure books with defined trigger points; transition risk overlays in credit models with documented assumptions. Bad looks like: a separate climate scorecard with green, amber and red RAG ratings that no one uses to make decisions.
Build the evidence chain before you need it
Assume a supervisor will ask: show me a decision where climate risk changed the outcome. If you cannot produce three or four concrete examples, credit decisions declined, pricing adjusted, capital allocated differently, product design changed, your framework is decorative.
Document the chain from data to decision. This means:
- Data sources and their limitations, acknowledged in writing
- Scenario analysis assumptions, with sensitivity testing
- Management information that reaches the board with sufficient granularity to challenge, not just receive
- Board challenge itself, captured in minutes with substance, not attendance
If your board papers on climate consistently produce no recorded challenge, that is a red flag to any supervisor reading them.
Handle the data problem honestly
Everyone has data gaps. Supervisors know this. What they penalise is pretending you do not. State your data limitations explicitly in the framework itself, describe your proxies, and set out a credible remediation plan with owners and dates. A framework that admits its weaknesses and shows a plan is more defensible than one that overclaims.
Anticipate the second-order questions
Once a supervisor is satisfied the basics are in place, they move to harder ground: How does climate risk interact with your ICAAP or ORSA? Have you stress-tested your business model, not just your balance sheet? What is your position on litigation risk and greenwashing exposure? How does client engagement feed back into risk assessment?
Most frameworks stop at the first-order level. Building the second-order answers into your framework, even as work in progress, signals maturity.
What to do this quarter
Commission an internal gap analysis against the specific expectations of your lead supervisor, not against a generic maturity model. Have it done by someone who has sat on the regulator's side of the table. Then take the three weakest areas to your Risk Committee with a remediation plan and named owners. That agenda item, minuted properly, is itself the beginning of the evidence chain you will need.
Related guides
Building a Cross-Jurisdictional Governance Case for Operational Resilience
This guide sets out how to construct a governance case for an operational resilience framework that holds up across multiple supervisory regimes at a global bank. After reading, you will know how to sequence the work, resolve regime conflicts, and present a coherent story to your board and lead regulators.
Stakeholder Risk Management for FCA Regulated Firms: A Practical Guide
This guide sets out how senior leaders at FCA regulated firms should identify, assess and manage stakeholder risk in a way that stands up to supervisory scrutiny. After reading, you will know how to structure a stakeholder risk framework that connects to Consumer Duty, SM&CR accountability and board-level reporting.
Positioning a Consumer Duty Review for Board and Regulator Audiences
This guide sets out how to structure a Consumer Duty implementation review so it works for both your board and the FCA without compromising either audience. You will finish with a clear approach to framing, evidence, and sequencing that avoids the common trap of producing two conflicting narratives.
Regulated Industry Governance Best Practice: A Practical Guide
This guide sets out what good governance actually looks like in a regulated business, covering board composition, decision records, regulator relationships, and the failure modes that trigger enforcement. After reading, you will be able to pressure-test your current governance model against the standards regulators now apply in practice.
How to Prepare for an FCA Supervisory Visit
A practical guide to preparing for an FCA supervisory visit, from interpreting the scoping letter to managing the day itself and the follow-up. After reading, you will know what good preparation looks like, where firms typically slip, and how to position your firm to come out of the visit stronger.
Polar Insight helps senior leaders in financial services understand what their key stakeholders actually think before significant decisions are made.
Book a conversation