Ga naar inhoud

ISO 27001 ·

Climate change in your ISMS: the ISO 27001 amendment and what auditors now ask

Since February 2024, ISO/IEC 27001:2022 carries an amendment that explicitly names climate change in the context of your management system. In practice, clauses 4.1 (context) and 4.2 (interested parties) were extended: your organisation must determine whether climate change is a relevant issue for the scope, and whether interested parties have requirements related to it. A small text change with a clear audit question behind it — and a standard checkpoint since 2024.

What exactly changed?

The standard now requires that you demonstrably considered whether climate is relevant to your information security. That does not mean every company needs a climate chapter — it means the assessment must be on record. For many SMEs the conclusion is short: “assessed, limited relevance, justified”. For data centres, cloud-dependent services or organisations with physical sites in risk areas, the conclusion may weigh heavier.

Where does climate actually touch your ISMS?

It is not about your carbon footprint, but about how climate change can affect the confidentiality, integrity and availability of your information. The practical angles:

  • Availability: overheating, power loss and cooling of server rooms or colocation during heatwaves.
  • Continuity: suppliers and data centres in areas prone to heatwaves or flooding.
  • Physical security: sites increasingly exposed to extreme weather, flooding or power failure.
  • Supply chain: client requirements that already factor climate into their own risk assessment and pass it down.

Link these points to your existing risk assessment and to supplier management — no separate process required.

How do you record it concretely?

It really need not be elaborate. In your context analysis (clause 4.1) a paragraph along these lines often suffices: “Climate change has been assessed as a context factor. The main touchpoints are the availability of cloud/data-centre services and physical site risks. These are covered in the risk assessment (see risks X and Y); additional measures are currently not deemed necessary, to be reconsidered at the annual management review.” Such a paragraph makes the assessment explicit, traceable and auditable — exactly what the standard asks.

Interested parties (clause 4.2)

Do not forget the second half: do your interested parties have climate-related requirements? Think of clients with sustainability or continuity demands, insurers, or a parent organisation with a climate policy. If so, name it briefly and refer to how you meet it. If not, record that you assessed it and identified no specific requirements.

What do auditors ask now?

Since 2024, certification bodies check whether the topic has been addressed in your context analysis and, where relevant, in risk treatment. The most common mistake is silently ignoring the amendment: no sentence on climate in the context determination quickly means a minor. One justified paragraph in your context or management review prevents that. Record the source of the assessment (management, risk owner) so it stays traceable.

Common mistakes

  • Ignoring the amendment — the most common finding since 2024; it costs you a nonconformity for something you can fix in ten minutes.
  • Overshooting — building an elaborate climate report while your organisation is barely affected; keep it proportionate.
  • Naming without linking — if you deem climate relevant but it appears nowhere in your risk assessment, the assessment is incomplete.

Getting started

At your next management review, take five minutes to discuss climate as a context factor and record the conclusion — proportionate to your situation. That covers you at the next audit. Want to know more about the context and risk requirements? See the ISO 27001 route or take the free readiness scan.

Deep dive in the knowledge base

Continue in ISO Ready

Manage actions, risks and evidence in one line of sight toward certification.

Visit ISO Ready

← Back to overview