ICFR and Climate Disclosure Audit: A 2026 Practitioner Walkthrough
If your team is trying to figure out whether climate disclosures belong inside your SOX 404 program or outside it, you are not alone. The SEC's March 2024 final rule created two distinct control regimes for climate data, and most finance teams are still conflating them. Getting this wrong means either over-engineering controls for disclosures that don't require ICFR treatment, or leaving genuine ICFR-scope items without the testing cadence your auditor will expect.
This walkthrough maps exactly which climate items fall under ICFR, which fall under Disclosure Controls and Procedures (DCP), and what you need to build for each, including the GHG assurance track that runs parallel to both.
Key takeaway: Regulation S-X climate disclosures (financial statement footnotes) are inside ICFR scope and subject to management's assessment and external audit. Regulation S-K disclosures (GHG emissions, governance, strategy, targets) are outside ICFR but still require DCP and phased third-party assurance. Treating these as the same thing is the most common and most costly mistake.
What the Reg S-X vs. Reg S-K Split Actually Means for ICFR
The SEC's final rule (Release No. 33-11275) adds Article 14 to Regulation S-X and Subpart 1500 to Regulation S-K. These two additions carry fundamentally different control obligations, and the distinction is not just administrative.
Forvis Mazars' technical guidance puts it plainly: Reg S-X disclosures require ICFR controls; Reg S-K disclosures do not. But Reg S-K disclosures still require DCP, and the SEC expects those procedures to "enhance not only the reliability of the climate-related disclosures themselves, including both qualitative climate-related information and quantitative climate-related data, but also their accuracy and consistency."
Here is what each bucket contains:
| Disclosure type | Regulation | ICFR scope? | Assurance | Safe harbor? |
|---|---|---|---|---|
| Severe weather expenditures footnote | S-X (Article 14) | Yes | Financial statement audit | No |
| Carbon offset / REC roll-forward footnote | S-X (Article 14) | Yes | Financial statement audit | No |
| Material impact on financial estimates and assumptions | S-X (Article 14) | Yes | Financial statement audit | No |
| Scope 1 and Scope 2 GHG emissions | S-K (Subpart 1500) | No | Phased third-party assurance | Limited |
| Governance, strategy, risk management, targets | S-K (Subpart 1500) | No | DCP only | Yes (for forward-looking) |
The safe harbor distinction has real consequences for control design. Reg S-X footnote disclosures carry no safe harbor protections, which means errors in those items carry the same legal exposure as errors in any other audited financial statement line. Your RACM must treat them accordingly.
What Triggers the Reg S-X Footnote Disclosure
The materiality threshold for Reg S-X climate items is 1% of pretax income or total shareholders' equity, subject to a de minimis threshold. Deloitte's analysis of the final rule confirms that disclosure is required when aggregate amounts reflected directly in the financial statements exceed that threshold.
Three specific items go into the footnote:
- Expenditures related to severe weather events (physical risk costs charged to the income statement or capitalized).
- Whether estimates and assumptions used in the financial statements were materially impacted by climate-related risks or transition plans, including asset useful life assumptions, impairment estimates, and insurance recoverable assumptions.
- A roll-forward of carbon offsets and RECs if those instruments are a material component of meeting the company's climate targets.
For most industrial, energy, and real estate companies, items 1 and 2 are the live risk right now. A company with significant coastal or flood-exposed assets that has already recorded storm-related write-downs needs to evaluate whether those amounts cross the 1% threshold and, if so, whether the controls around that calculation are ICFR-grade.
How to Integrate Climate Controls into Your Existing SOX 404 Program
This is where most programs stall. The Reg S-X items are not a separate compliance workstream. They belong inside your existing SOX 404 infrastructure, which means updating three things: your risk and control matrix, your IT general controls population, and your sub-certification structure.
Step 1: Update the Risk and Control Matrix
Add the Reg S-X climate footnote disclosures as new significant accounts or disclosures within your existing financial reporting process framework. For each new disclosure:
- Identify the financial statement assertion at risk (completeness, accuracy, valuation, presentation).
- Document the data source (which system, which team, which calculation methodology).
- Design a key control that addresses the risk, assign an owner, and set a testing frequency.
- Add the control to the RACM and flag it for both management testing and external auditor consideration under PCAOB AS 2201.
The completeness assertion deserves special attention for severe weather expenditures. Unlike revenue, where the population of transactions flows through a single ERP, storm-related costs may be scattered across multiple cost centers, capitalized in different asset registers, or partially offset by insurance recoveries. Your control needs to capture the full population, not just what the sustainability team flagged.
Step 2: Establish IT General Controls for Climate Data Systems
GHG calculation platforms (tools like Salesforce Net Zero Cloud, Watershed, or Persefoni) and climate risk scenario analysis systems are not traditional finance systems. They typically lack the change management, access control, and data integrity documentation that auditors expect for ICFR-relevant systems.
For any system that feeds data into a Reg S-X footnote disclosure, you need:
- Change management controls: documented approval workflows for methodology changes, emission factor updates, and calculation logic changes.
- Access controls: role-based access with segregation of duties between data entry, calculation, and approval.
- Data integrity controls: reconciliation procedures between source data (utility bills, fuel purchase records, operational data) and the GHG platform output.
- SOC report review: Forvis Mazars recommends reviewing SOC reports for significant GHG reporting systems to confirm that user entity controls are implemented and that the service organization's controls are designed and operating effectively. If your GHG platform does not have a SOC 1 or SOC 2 report, that is a gap to raise with the vendor now.
Step 3: Clarify Cross-Functional Ownership and Sub-Certifications
This is the organizational problem that no one wants to solve. Sustainability teams own the GHG data. Finance teams own the controls. Neither has full expertise in the other's domain, and when the auditor asks who is responsible for the completeness of the severe weather expenditure footnote, the answer cannot be "both."
A workable structure:
- CFO or Controller owns the Reg S-X footnote disclosures and signs the SOX 302 and 906 certifications. These are financial statement items; finance owns them.
- Chief Sustainability Officer (CSO) or equivalent owns the Reg S-K GHG data and the underlying measurement methodology, but provides a formal representation to the CFO confirming data completeness and accuracy before the filing.
- Internal audit provides independent assurance over both the ICFR controls (Reg S-X) and the DCP effectiveness (Reg S-K), and reports findings to the audit committee.
Document this ownership in your disclosure committee charter and update your sub-certification templates to include a specific representation from the sustainability function.
The GHG Assurance Track: Limited vs. Reasonable Assurance
GHG emissions (Scope 1 and Scope 2) for large accelerated filers and accelerated filers are subject to phased third-party assurance, but this engagement is entirely separate from the financial statement audit. Deloitte's analysis confirms that the assurance provider can be a different firm from the financial statement auditor.
The phased timeline under the final rule (before the stay) gave large accelerated filers approximately three years to begin providing GHG emission information and six years to obtain limited assurance. Accelerated filers follow a later schedule. Smaller reporting companies, emerging growth companies, and nonaccelerated filers are exempt from GHG disclosure and assurance requirements entirely.
The practical difference between limited and reasonable assurance:
- Limited assurance (negative assurance): the assurance provider performs inquiry and analytical procedures and concludes that nothing has come to their attention indicating the GHG data is materially misstated. Standards used include AICPA AT-C 105/210 or ISAE 3000.
- Reasonable assurance (positive assurance): the provider performs a full examination, including testing of underlying data and controls, and positively concludes the GHG data is fairly stated. This is closer in rigor to a financial statement audit.
One decision your team needs to make now: whether to use your financial statement auditor or a specialist sustainability assurance firm for GHG assurance. Using the same firm simplifies coordination and reduces the risk of conflicting findings on items that straddle both regimes (for example, carbon offset accounting that appears in both the Reg S-X footnote and the Reg S-K GHG disclosure). Using a specialist firm may bring deeper GHG methodology expertise. Either way, the two assurance relationships need a clear coordination protocol before fieldwork begins.
Key takeaway: The GHG assurance engagement is not an audit. It runs on different standards, can use a different provider, and has a different scope than your financial statement audit. But the DCP controls you build for Reg S-K will be tested by the assurance provider, so they need to be real controls, not paper procedures.
Does the SEC Stay Mean You Can Pause?
No. The SEC voluntarily stayed the climate disclosure rule in April 2024 pending judicial review by the Eighth Circuit Court of Appeals. As of mid-2026, that stay remains in place and the rule's ultimate fate is uncertain. But three parallel obligations continue regardless of the federal outcome.
California SB 253 (the Climate Corporate Data Accountability Act) requires large companies doing business in California to disclose Scope 1, Scope 2, and Scope 3 emissions, with reporting obligations that are already in motion for covered entities. Our California SB 261 compliance guide covers the related climate risk reporting requirement. The control infrastructure needed for California compliance substantially overlaps with what the SEC rule would require.
ISSB IFRS S2 applies to companies reporting under IFRS in jurisdictions that have adopted the standard. IFRS S2 requires climate-related disclosures including scenario analysis, and our IFRS S2 scenario analysis walkthrough covers what auditors accept for that requirement.
CSRD/ESRS applies to EU-in-scope operations of multinationals, including many U.S. parent companies with significant European subsidiaries. The control documentation required for ESRS E1 (climate) overlaps substantially with what the SEC rule would require for Reg S-X footnotes.
For a full picture of where the SEC climate rule stands in 2026 alongside other regulatory changes, see our SEC 2026 regulatory update.
The build-vs-wait decision is effectively resolved: build. The state and global mandates are live, investor expectations are not paused, and the control infrastructure takes 12 to 18 months to mature to audit-ready status. Companies that wait for Eighth Circuit certainty will be building under time pressure.
ICFR Climate Control Readiness Checklist
Use this to assess your current state and prioritize remediation. Items marked [ICFR] are required for Reg S-X footnote disclosures. Items marked [DCP] apply to Reg S-K disclosures.
Scoping and risk assessment
- Determined whether severe weather expenditures exceed 1% of pretax income or shareholders' equity [ICFR]
- Assessed whether financial estimates and assumptions (asset useful lives, impairment, insurance recoverables) are materially impacted by climate risks [ICFR]
- Evaluated whether carbon offsets or RECs are a material component of meeting climate targets (triggering roll-forward disclosure) [ICFR]
- Identified all Scope 1 and Scope 2 emission sources across all locations and legal entities [DCP]
- Confirmed filer category (large accelerated, accelerated, SRC/EGC/nonaccelerated) and applicable GHG assurance timeline [DCP]
Control design and documentation
- Added Reg S-X climate footnote items to the RACM with assertions, risks, and key controls [ICFR]
- Assigned a named control owner in finance (not sustainability) for each Reg S-X control [ICFR]
- Documented the data flow from source systems to the footnote disclosure [ICFR]
- Established DCP for all Reg S-K climate disclosures with documented review and approval workflows [DCP]
- Updated disclosure committee charter to include climate disclosure review [ICFR/DCP]
- Updated sub-certification templates to include sustainability function representations [ICFR/DCP]
IT systems and SOC reports
- Inventoried all systems used for GHG calculation and climate risk scenario analysis [ICFR/DCP]
- Obtained and reviewed SOC reports for significant GHG platforms; documented user entity controls [ICFR/DCP]
- Confirmed change management, access controls, and data integrity controls are in place for GHG systems [ICFR/DCP]
- Implemented a GRC system or equivalent to consolidate control documentation, testing results, and risk assessments [ICFR/DCP]
Assurance and audit readiness
- Briefed external auditor on Reg S-X climate footnote controls and planned testing approach [ICFR]
- Selected GHG assurance provider and confirmed assurance standard (AT-C 105/210 or ISAE 3000) [DCP]
- Established coordination protocol between financial statement auditor and GHG assurance provider [ICFR/DCP]
- Briefed audit committee on climate control readiness, open gaps, and remediation timeline [ICFR/DCP]
- Internal audit has scoped climate disclosure controls into its annual plan [ICFR/DCP]
FAQ
Are Scope 3 emissions subject to ICFR under the SEC rule? No. The SEC eliminated the Scope 3 GHG disclosure requirement from the final rule, a significant scaling back from the 2022 proposed rule. Scope 3 is not required under the SEC framework, though it may be required under California SB 253 and CSRD/ESRS for companies with those obligations.
Can our GHG assurance provider be a different firm from our financial statement auditor? Yes. The SEC rule explicitly permits a different assurance provider for GHG emissions. The assurance engagement is separate from the financial statement audit and operates under different standards (AICPA AT-C 105/210 or ISAE 3000 rather than PCAOB standards). Coordination between the two providers is essential where disclosures overlap.
What does the external auditor actually do with our Reg S-X climate footnote? The financial statement auditor audits the Reg S-X footnote disclosures as part of the integrated audit under PCAOB AS 2201. That means testing the design and operating effectiveness of the controls you have built, evaluating the completeness and accuracy of the underlying data, and assessing whether the disclosure is fairly presented. Auditors will also consider whether climate-related estimates and assumptions embedded in other financial statement line items (impairment, useful lives) are reasonable, which is a separate but related scope question.
What if our climate data lives entirely in a sustainability platform with no SOC report? That is a control gap. For any system that feeds a Reg S-X footnote disclosure, you need either a SOC report from the service organization or compensating controls at the user entity level that provide equivalent assurance over data integrity, access, and change management. Raise this with your GHG platform vendor and with your external auditor before year-end fieldwork begins.
How does the IIA view internal audit's role in climate disclosure? The IIA has flagged climate disclosure as a new area of review and assurance for internal auditors. As IIA President and CEO Anthony Pugliese noted, "publicly traded companies face unique and often complex reporting requirements, which create added risks, given the responsibility they have to their shareholders." Internal audit should be scoping climate disclosure controls into its annual plan and providing the audit committee with an independent view of control readiness, distinct from the external audit and GHG assurance engagements.
Does the SEC stay affect our obligation to maintain ICFR for climate items already in our financial statements? No. If your financial statements already include severe weather expenditures or carbon offset disclosures that cross the 1% materiality threshold, those items are in your audited financial statements regardless of the SEC rule's status. The ICFR obligation for those items flows from your existing SOX 404 obligations, not from the stayed rule. The stay affects the prospective disclosure requirements, not the controls over items already in the statements.
The audit committee briefing on climate control readiness is not a future agenda item. It belongs on the next meeting's agenda, with a clear gap analysis and a remediation timeline that accounts for both the federal uncertainty and the state and global mandates that are already running.







