Skip to content

Evidence request lists

TCFD Recommendations

Evidence request list. 20 controls, 20 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Governance

TCFD-GOV-A
Board Oversight of Climate-Related Risks and Opportunities

Describe the board's oversight of climate-related risks and opportunities, including the processes and frequency by which the board is informed, how climate considerations factor into board decisions, and how the board monitors progress against goals.

Artefacts an auditor will ask for
  • Board charter with climate mandate
  • Board and committee meeting minutes referencing climate items
  • Annual board climate briefing decks
  • Director climate competency matrix
  • Board calendar showing climate review cadence
Where this commonly fails
  • No documented frequency of board climate reviews
  • Climate items buried in general ESG updates
  • No evidence of board challenge or decisions taken
  • Director skills matrix omits climate competency
TCFD-GOV-B
Management's Role in Assessing and Managing Climate Risks

Describe management's role in assessing and managing climate-related risks and opportunities, including assigned positions or committees, reporting lines to the board, and the processes used by management to stay informed.

Artefacts an auditor will ask for
  • Org chart with climate roles highlighted
  • Climate steering committee terms of reference
  • Job descriptions for Chief Sustainability Officer or equivalent
  • Management reporting templates submitted to board
  • RACI matrix for climate risk decisions
Where this commonly fails
  • No single accountable executive owner
  • Climate committee meets but produces no minutes
  • Reporting lines to board unclear or informal
  • No KPIs tied to executive remuneration
TCFDREC-1
Governance - Board Oversight, Management Role

Per TCFD Recommendations Governance pillar: Board Oversight + Management's Role in assessing + managing climate-related risks and opportunities. Disclose: board oversight; management's role.

Artefacts an auditor will ask for
  • TCFD evidence for TCFDREC-1
Where this commonly fails
  • scenario analysis + Scope 3 + targets partial

Implementation and Assurance

TCFD-IMP-001
Disclosure Location and Reporting Cadence

Determine the location of TCFD-aligned disclosures within annual financial filings, sustainability reports, or standalone climate reports, and the frequency of update, ensuring information meets the principles of effective disclosure.

Artefacts an auditor will ask for
  • Most recent annual report with TCFD index
  • Climate report or sustainability report
  • TCFD content index mapping to recommendations
  • Disclosure controls memo
  • Audit committee approval record
Where this commonly fails
  • Disclosures scattered across multiple reports without index
  • No annual update cycle defined
  • Forward looking statements without caveats
  • Inconsistency between financial statements and sustainability report
TCFD-IMP-002
ISSB Transition and IFRS S2 Alignment

Assess the transition from standalone TCFD reporting to IFRS S2 Climate-related Disclosures, including jurisdictional adoption status, mapping of existing TCFD content, and any gap closure activities.

Artefacts an auditor will ask for
  • TCFD to IFRS S2 mapping document
  • Gap analysis against IFRS S2
  • Jurisdictional adoption tracker
  • Project plan for S2 readiness
  • Disclosure committee charter referencing ISSB
Where this commonly fails
  • No mapping performed
  • Assumption that TCFD coverage is sufficient
  • Local jurisdiction requirements ignored
  • Connectivity with financial statements weak
TCFD-IMP-003
Scenario Analysis Capability and Data

Establish internal capability and data infrastructure to perform recurring climate scenario analysis, including selection of scenarios, parameter calibration, modelling tools, and analyst training.

Artefacts an auditor will ask for
  • Scenario analysis methodology document
  • Data inventory for physical and transition risk inputs
  • Tool selection memo or vendor contracts
  • Training records for climate analysts
  • Validation and challenge logs
Where this commonly fails
  • Reliance on a single external vendor with limited transparency
  • No internal challenge function
  • Data refresh cadence undefined
  • Limited geographic granularity
TCFD-IMP-004
Connectivity with Financial Statements

Ensure climate-related disclosures are connected to amounts recognised, measured, and presented in the financial statements, including impairment assessments, useful life of assets, decommissioning provisions, and contingent liabilities.

Artefacts an auditor will ask for
  • Climate considerations in impairment workpapers
  • Decommissioning provision schedules with climate inputs
  • Auditor communications on climate assumptions
  • Disclosure of significant judgements
  • Note disclosures referencing climate
Where this commonly fails
  • Climate assumptions inconsistent between sustainability report and financial statements
  • Impairment models do not stress climate
  • Useful life of high-carbon assets not reassessed
  • No disclosure of significant judgements
TCFD-IMP-005
Internal Controls Over Climate Disclosures

Implement internal controls over the preparation, review, and approval of climate-related disclosures with the same rigour applied to financial reporting controls, including data lineage, version control, and review evidence.

Artefacts an auditor will ask for
  • Disclosure control matrix for climate items
  • Data lineage diagrams from source to disclosure
  • Version controlled workpapers
  • Sign off log for disclosures
  • Internal audit reports on climate data controls
Where this commonly fails
  • Spreadsheets without version control
  • No formal sign off prior to publication
  • Source systems not identified
  • Internal audit coverage absent

Metrics

TCFDREC-4
Metrics and Targets - GHG, Climate Metrics

Per TCFD Metrics and Targets pillar: metrics used to assess climate risks and opportunities + Scope 1 + Scope 2 + Scope 3 GHG emissions + targets for managing climate risks and performance against targets.

Artefacts an auditor will ask for
  • TCFD evidence for TCFDREC-4
Where this commonly fails
  • scenario analysis + Scope 3 + targets partial

Metrics and Targets

TCFD-MT-A
Metrics Used to Assess Climate-Related Risks and Opportunities

Disclose the metrics used by the organisation to assess climate-related risks and opportunities in line with its strategy and risk management process, including metrics on water, energy, land use, waste, and internal carbon pricing where applicable.

Artefacts an auditor will ask for
  • Metrics dashboard with definitions and methodologies
  • Internal carbon price policy and rate
  • Water and energy intensity reports
  • Climate-related revenue and capex tagging
  • Remuneration linkage to climate metrics
Where this commonly fails
  • Only GHG emissions reported, no other metrics
  • Internal carbon price not set or only nominal
  • Metrics inconsistent year over year
  • Methodology footnotes missing
TCFD-MT-B
Scope 1, 2, and 3 Greenhouse Gas Emissions Disclosure

Disclose Scope 1, Scope 2, and, if appropriate, Scope 3 greenhouse gas emissions and the related risks, with disclosure consistent with the GHG Protocol Corporate Accounting and Reporting Standard.

Artefacts an auditor will ask for
  • GHG inventory report by scope
  • Calculation workbooks with emission factors and sources
  • Organisational and operational boundary documentation
  • Third party limited or reasonable assurance statement
  • Scope 3 category screening and inclusion rationale
Where this commonly fails
  • Scope 3 omitted or only one or two categories disclosed
  • Boundary definitions inconsistent year over year
  • No assurance obtained
  • Emission factor sources undocumented
TCFD-MT-C
Targets and Performance Against Targets

Describe the targets used by the organisation to manage climate-related risks and opportunities and performance against targets, including a description of target type, scope, base year, time frame, interim milestones, and use of offsets.

Artefacts an auditor will ask for
  • Net zero or emissions reduction target statement
  • SBTi validation letter or equivalent
  • Target progress dashboard with milestones
  • Offset policy and inventory of credits used
  • Annual progress report
Where this commonly fails
  • No interim milestones between base year and target year
  • Heavy reliance on offsets without abatement first
  • Target methodology unclear
  • Performance not tracked or restated when boundaries change

Risk Management

TCFD-RM-A
Processes for Identifying and Assessing Climate-Related Risks

Describe the organisation's processes for identifying and assessing climate-related risks, including how relative significance is determined, how existing and emerging regulatory requirements are considered, and the definitions of risk terminology used.

Artefacts an auditor will ask for
  • Climate risk identification methodology
  • Risk taxonomy and definitions document
  • Regulatory horizon scan logs
  • Risk assessment workpapers
  • Materiality threshold criteria
Where this commonly fails
  • Methodology not formally documented
  • Inconsistent risk definitions across business units
  • Regulatory scanning ad hoc rather than systematic
  • Materiality thresholds undefined
TCFD-RM-B
Processes for Managing Climate-Related Risks

Describe the organisation's processes for managing climate-related risks, including decisions to mitigate, transfer, accept, or control those risks, and processes for prioritisation including how materiality determinations are made.

Artefacts an auditor will ask for
  • Risk treatment plans for top climate risks
  • Insurance and hedging documentation
  • Mitigation project portfolio
  • Risk acceptance memos signed by accountable executives
  • Prioritisation scoring rubric
Where this commonly fails
  • Risks identified but no treatment plans
  • Prioritisation logic undocumented
  • Insurance coverage for physical risks not analysed
  • No tracking of mitigation project outcomes
TCFD-RM-C
Integration of Climate Risks into Overall Risk Management

Describe how processes for identifying, assessing, and managing climate-related risks are integrated into the organisation's overall risk management framework, including the linkage between climate risk and enterprise risk taxonomy.

Artefacts an auditor will ask for
  • Enterprise risk management framework with climate references
  • Climate risks in enterprise risk register
  • ERM committee minutes discussing climate
  • Risk appetite statement covering climate
  • Integration diagram showing climate flow into ERM
Where this commonly fails
  • Climate risk register kept separate from ERM
  • Risk appetite silent on climate
  • No common scoring scale across climate and other risks
  • ERM committee never sees climate items
TCFDREC-3
Risk Management - Identification, Assessment, Integration

Per TCFD Risk Management pillar: processes for identifying + assessing + managing climate-related risks + integration into overall risk management.

Artefacts an auditor will ask for
  • TCFD evidence for TCFDREC-3
Where this commonly fails
  • scenario analysis + Scope 3 + targets partial

Strategy

TCFD-STR-A
Climate-Related Risks and Opportunities Identified Over Short, Medium, and Long Term

Describe the climate-related risks and opportunities the organisation has identified over the short, medium, and long term, including the specific time horizons used and how these align with planning cycles and asset lifetimes.

Artefacts an auditor will ask for
  • Climate risk register with horizon tags
  • Definition of short, medium, long term horizons document
  • Materiality assessment workpaper
  • Sector and geography heatmaps
  • Opportunities pipeline tracker
Where this commonly fails
  • Time horizons defined inconsistently across business units
  • Only physical or only transition risks considered
  • Opportunities omitted entirely
  • No linkage to capital allocation cycles
TCFD-STR-B
Impact of Climate Risks and Opportunities on Business, Strategy, and Financial Planning

Describe the impact of climate-related risks and opportunities on the organisation's businesses, strategy, and financial planning, covering products and services, supply chain, adaptation and mitigation activities, R&D investment, and operations.

Artefacts an auditor will ask for
  • Climate-adjusted financial forecasts
  • Capex and opex tagging for climate investments
  • Strategic plan extracts referencing climate
  • Supply chain climate exposure analysis
  • Product portfolio decarbonisation roadmap
Where this commonly fails
  • Qualitative narrative only, no quantified impacts
  • Climate not integrated into annual budget process
  • Supply chain Scope 3 hotspots not analysed
  • R&D spend on low-carbon solutions not tracked
TCFD-STR-C
Resilience of Strategy Under Different Climate Scenarios

Describe the resilience of the organisation's strategy, taking into consideration different climate-related scenarios, including a 2 degrees Celsius or lower scenario, and scenarios consistent with national or regional emissions pathways where relevant.

Artefacts an auditor will ask for
  • Scenario analysis report covering 1.5C, 2C, and higher warming pathways
  • Scenario assumptions and parameter documentation
  • Stress test results by business line and geography
  • Transition plan document
  • Sensitivity analysis tables
Where this commonly fails
  • Only one scenario tested
  • Scenarios pulled off the shelf without organisation-specific calibration
  • Results not used in strategy decisions
  • No transition plan published
TCFDREC-2
Strategy - Risks, Opportunities, Resilience

Per TCFD Strategy pillar: climate-related risks + opportunities over short/medium/long horizon + impact on business + strategy + financial planning + resilience under different climate scenarios (including 2C or lower scenario).

Artefacts an auditor will ask for
  • TCFD evidence for TCFDREC-2
Where this commonly fails
  • scenario analysis + Scope 3 + targets partial
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the TCFD Recommendations framework page.