If your business operates in Australia and you have not yet formed a position on the Australian Sustainability Reporting Standards (ASRS), 2026 is the year that changes.
Not because the regime is new — the largest entities have been reporting since January 2025 — but because 2026 is when the regime's centre of gravity shifts to the mid-market, the regulator starts publishing its reviews, and the wave of supply chain data requests from large customers becomes impossible to ignore.
Australia now operates one of the most consequential mandatory climate reporting regimes in the world. It is legally enforceable. It sits inside the Corporations Act. Directors sign declarations against it. And its reach extends well beyond the companies formally in scope — down into the suppliers, contractors, and subsidiaries that power them.
This guide covers what the ASRS is, who must report and when, what your first report must contain, the liability settings that are expiring, and, critically, why handing your sustainability reporting process to a general-purpose AI tool is one of the most dangerous shortcuts available, and what the correct operating model looks like instead.
Part 1: What ASRS Actually Is
The legislative foundation
In September 2024, the Australian Accounting Standards Board (AASB) finalised the Australian Sustainability Reporting Standards following a consultation process on Exposure Draft SR1. The standards were legislated through the Treasury Laws Amendment (Financial Market Infrastructure and Other Measures) Act 2024, embedding mandatory climate reporting into the Corporations Act 2001.
The regime takes a deliberately "climate-first" approach. The operative standard is AASB S2 Climate-related Disclosures, which incorporates the content of the ISSB's IFRS S2, adapted to the Australian legal and institutional environment. A companion standard, AASB S1, deals with general sustainability-related disclosures — but it is voluntary. AASB S2 is not.
This distinction matters more than many executives realise. ASRS reporting is not a glossy sustainability report produced by the marketing team. Under the Act, in-scope entities must prepare an annual 'sustainability report' consisting of:
a climate statement for the year;
notes to the climate statement; and
any other information prescribed by regulation.
It must be lodged with ASIC at the same time as the annual financial report, and it sits within the existing liability framework of the Corporations Act and the ASIC Act — including directors' duties, misleading and deceptive conduct provisions, and general disclosure obligations. Directors must declare that the climate statements comply with the standards.
In short: climate statements are now financial statements in every sense that matters — governance, assurance, liability, and enforcement.
What AASB S2 requires
AASB S2 is structured around the four pillars familiar from TCFD and ISSB architecture:
Pillar | What must be disclosed |
Governance | The governance body (board or committee) overseeing climate-related risks and opportunities, its processes, and how climate competence is built and maintained |
Strategy | Climate-related risks and opportunities over the short, medium, and long term; their effect on the business model and value chain; climate scenario analysis; and transition planning |
Risk Management | Processes for identifying, assessing, prioritising, and monitoring climate-related risks — and how they are integrated into the overall risk management system |
Metrics & Targets | Scope 1, Scope 2, and (from year two) material Scope 3 greenhouse gas emissions; industry-based metrics; and any climate-related targets, including progress against them |
Two emissions rules deserve special attention:
Scope 1 and Scope 2 (location-based) emissions must be disclosed from year one, including information on any eligible offsets or certificates accounted for.
Material Scope 3 emissions must be disclosed from the second reporting year onwards — with disclosure of which of the 15 GHG Protocol categories are included, the measurement approach, and information about data inputs and verification.
That second point is the one most organisations underestimate, and we will return to it.
Part 2: Who Must Report, and When
The regime phases in over three cohorts, based on entity size. Entities meet the threshold if they satisfy at least two of three size tests.
Cohort | First reporting period | Thresholds (two of three) | Additional capture |
Group 1 | Financial years commencing on or after 1 January 2025 | Consolidated revenue ≥ A$500m; gross assets ≥ A$1b; 500+ employees | Includes large asset owners |
Group 2 | Financial years commencing on or after 1 July 2026 | Consolidated revenue ≥ A$200m; gross assets ≥ A$500m; 250+ employees | Asset owners (super funds, managed investment schemes) with ≥ A$5b in assets |
Group 3 | Financial years commencing on or after 1 July 2027 | Consolidated revenue ≥ A$50m; gross assets ≥ A$25m; 100+ employees | Captures most ASX-listed companies not already covered |
Three things about this table that surprise people
1. Group status is assessed at the consolidated group level. It is not determined by the size of your Australian subsidiary alone. A modest Australian operation can be swept into Group 1 because its overseas parent group crosses the thresholds. ASIC's Regulatory Guide 280 makes clear that entities not currently in scope can also become in scope through acquisitions, changes in corporate structure, or simply growing. If you are not sure which group you fall into, the honest answer is that many boards don't know either — and that itself is a finding.
2. Group 2 entities are the 2026 story. Their first mandatory reporting period begins 1 July 2026. For a 30 June year-end entity, that means their first sustainability report will cover the 2026–27 financial year and be lodged in 2027. Preparation windows that looked generous eighteen months ago are now measured in months. Group 2 entities should already have their governance structures, data systems, and scenario analysis workstreams under way — not scheduled for a workshop "later this quarter."
3. Group 3 is still moving. The May 2026 Federal Budget proposed raising Group 3 entry thresholds and announced consultation on assurance settings and supplier information requests. The regime's edges are still being refined. But treating regulatory flux as a reason to wait is precisely the wrong read: every signal suggests the direction of travel is broader coverage and harder scrutiny, not less.
The trickle-down effect: even if you're not in scope, ASRS is coming for your data
Here is the point that matters most to the Australian mid-market. Every Group 1, 2, and 3 entity requires Scope 3 emissions data, climate risk information, and supplier commitments from its value chain. Suppliers of Groups 1–3 will therefore begin receiving requests for emissions data, climate risk disclosures, and procurement and tender requirements.
If you are a Tier 2 or Tier 3 supplier to a listed company, a large manufacturer, or a major retailer, you do not need to be formally in scope for ASRS to reshape your business. Your largest customers' compliance deadlines have just become your commercial deadlines. This mirrors the dynamic we have already seen with CSRD in Europe and TCFD in the UK — disclosure obligations cascade down the supply chain, and the businesses that are ready with credible numbers hold onto their contracts.
Part 3: The Assurance and Liability Clock
Assurance is phased — but starts immediately
The Australian Auditing and Assurance Standards Board (AUASB) has established the assurance framework under ASSA 5000, with phasing specified in ASSA 5010. In summary:
Year 1: limited assurance over Scope 1 and Scope 2 emissions disclosures.
Phasing: assurance requirements ratchet up for each of the three reporting groups under the AUASB's phased timeline, with earlier assurance permitted.
Full regime: from 1 July 2030, reasonable assurance is required for mandatory climate disclosures for all cohorts.
The practical implication is uncomfortable for unprepared organisations: your first report is not a draft nobody reads. From the very first year, its emissions data is subject to independent assurance.
An assurance provider must be able to trace your reported figures back to underlying evidence. If your emissions data lives in spreadsheets, inboxes, and tribal knowledge, that assurance process will be painful — and its findings will be instructive in ways you won't enjoy.
The safe harbour — and why it expires
The legislation includes transitional "modified liability" settings that provide civil penalty protection for three years for certain disclosures made in good faith — specifically:
Scope 3 greenhouse gas emissions statements;
scenario analysis; and
transition plans.
For financial years commencing during the three-year period from 1 January 2025, directors cannot face certain civil actions in relation to these specific disclosures. But the clock is running. From the 2028 financial years onwards, those protections progressively fall away — and disclosure of Scope 3, scenario analysis, and transition plans moves into the full liability regime.
ASIC has been explicit about how to read this: the modified liability settings provide breathing space, but they are not a shield for poor preparation. ASIC's Regulatory Guide 280 signals that directors are expected to act now to lift their organisation's capability — particularly around scenario analysis, emissions data, and transition planning. Boards that use the safe harbour window to do nothing, rather than to build controls, will find the expiry of those provisions lands as a cliff edge, not a gentle slope.
Enforcement and penalties
ASIC has stated it will begin reviewing sustainability reports lodged from 2026 and will publicly report its findings. It retains a directions power to require corrections where statements are incorrect, incomplete, or misleading.
The penalty framework mirrors financial reporting: false or misleading climate statements can attract penalties of up to $15 million or 10% of annual turnover, with directors personally liable. In an environment where greenwashing litigation and regulatory action are escalating globally, these are not theoretical risks.
Put plainly: the era of optimistic, unverified climate narratives in corporate reporting is over. Everything in your sustainability report must be defensible, traceable, and evidence-backed — because it will be read the way a regulator and an assurance practitioner read it, not the way a marketer wrote it.
Part 4: What Your First Report Actually Requires (Beyond the Headlines)
Compliance with AASB S2 requires much more than an emissions figure. Several elements routinely catch first-time preparers out:
Scenario analysis. AASB S2 requires the use of climate-related scenario analysis to assess resilience under at least two climate scenarios — typically including one aligned with a 1.5°C pathway and one with a warmer pathway (commonly modelled as SSP1-2.6, SSP2-4.5, and SSP5-8.5). This must connect to your business model, strategy, and financial planning. Doing this credibly requires methodological competence: choosing scenarios, defining time horizons (10, 20, and 30 years), and translating physical and transition risks into financial terms.
Quantification against financial thresholds. Climate-related risks and opportunities must be identified using disclosure thresholds consistent with how your organisation identifies material risks in financial statements. Climate risk is being assessed under the same materiality logic as any other financial risk. If your climate risk register and your enterprise risk management system don't speak the same language, that gap will be visible.
Scope 3 as a supply chain data programme. AASB S2 requires you to disclose which Scope 3 categories you include, your measurement approach, and information about data inputs and verification. Practically, this means supplier engagement, data collection processes, and documented methodology. The GHG Protocol notes that 83% of companies struggle to access accurate emissions data — and Scope 3 is where those struggles concentrate. CDP research puts supply chain emissions at 11.4 times higher than a company's own operational emissions on average, which is precisely why they are both unavoidable and difficult.
Governance integration. The regime expects demonstrated board oversight, defined escalation pathways, and a named accountable structure. "We discussed it at a board meeting once" is a Scope 1 score on any credible maturity assessment — and it will not survive assurance.
This is where it is worth pausing on a question we hear constantly from mid-market Australian businesses: surely AI can just do all this now?
The answer is no. And the reasons why reveal exactly what the correct operating model looks like.
Part 5: Why Using LLMs for Complete Sustainability Reporting Is a Bad Idea
Large language models are extraordinary tools. Everyone uses them. But there is a growing gap between what LLMs are good at and what ASRS compliance actually demands — and treating a general-purpose AI as your sustainability reporting engine sits squarely in that gap.
Here is the honest assessment, based on the current research and the structure of the regime itself.
1. LLMs generate fluent, confident falsehoods — and ESG data is exactly the wrong domain for that
AI hallucination is a well-documented phenomenon: models generate outputs that appear accurate but lack factual basis. In ESG workflows this is particularly dangerous, for a structural reason: ESG data is fragmented and full of gaps. It arrives from internal reports, third-party audits, supplier questionnaires, utility invoices, and regulatory filings — in inconsistent formats, with inconsistent quality.
What do LLMs do when source data is incomplete? They fill the gaps with plausible content. That is literally what they are trained to do. In an ESG context, gap-filling produces emissions figures, risk statements, and compliance claims that are fabricated but fluent — and because the output reads confidently, teams often fail to interrogate it.
Publishing an unverifiable sustainability claim is not an embarrassing typo. It is a false or misleading statement under the ASIC Act, exposed to the penalty regime described above, and it is precisely the pattern that greenwashing enforcement targets. The assurance provider who examines your data will not accept "the language model seemed confident" as an audit trail.
2. Black-box outputs are fundamentally incompatible with assurance
Australia's regime requires, from year one, limited assurance over your Scope 1 and 2 disclosures — with a legislated path to reasonable assurance by 2030. Assurance demands a traceable chain: every reported figure must be traceable to a documented source, a defined methodology, and a reproducible calculation.
Current requirements for sustainability reporting — in Australia under AASB S2 as much as under Europe's CSRD — centre on clean data, traceable processes, and verifiable results. That is the definition of what a "black box" generative model cannot provide. A technology whose functioning is not transparent, whose outputs are non-deterministic (the same prompt yields different answers), and which cannot reliably cite the provenance of every number in its output is structurally unsuited to producing information that must survive an audit.
Recent academic work on AI in sustainability assurance identifies the specific risk categories plainly: data quality risk, reliability and hallucination risk, explainability risk, and bias risk. Regulators — including guidance frameworks such as NIST's Generative AI Risk Profile — treat these as known, documented failure modes, not hypothetical ones.
3. Confidentiality and data governance risks
Emissions data, supplier information, energy contracts, and financial exposure estimates are commercially sensitive. Pasting them into consumer-grade AI tools — or even enterprise ones without appropriate data controls — creates a data governance problem your IT and legal teams have not signed off on. Under a regime that already scrutinises your climate-conscious data management, feeding your most sensitive operational data through an uncontrolled channel is a self-inflicted wound.
4. Standards interpretation requires accountability, not autocomplete
AASB S2 is subject to amendment, exposure drafts, transitional reliefs, and evolving AUASB guidance — 2026 alone brought amendments on Scope 3 Category 15 for financial institutions, Budget proposals on Group 3 thresholds, and new consultation processes. An LLM trained on last year's corpus will confidently answer today's question with yesterday's rules, silently, without telling you its knowledge is stale. When the consequence of getting it wrong is a director's personal declaration, "the AI said so" is not a defence that any board paper will survive.
What LLMs are legitimately useful for
None of this means generative AI has no place in the workflow. Used properly, it is excellent at:
Drafting and editing support — first-pass narrative text that a qualified professional then verifies, fact-checks, and owns.
Summarising long documents — with human confirmation against the source.
Structured retrieval assistance — surfacing what a standard says, where a human then confirms it against the current official text.
Notice the pattern: in every legitimate use case, the LLM proposes and a human expert disposes. The model never originates data, never calculates a reportable figure, and never signs anything.
Part 6: The Correct Operating Model — Platform Plus Science
If LLMs can't run the process end-to-end, what can? The mature answer — the one assurance practitioners, regulators, and serious sustainability teams converge on — is a division of labour between three distinct functions:
Function 1: A purpose-built ESG platform for data management
Your sustainability data is an asset with a regulatory lifecycle. It needs:
A single source of truth for emissions data, replacing fragmented spreadsheets with a governed repository.
Defined, versioned methodologies — measurement approaches, emission factor libraries, and calculation methods that are documented, dated, and repeatable year over year. Assurors test consistency; an ad-hoc calculation that cannot be reproduced fails.
Complete audit trails — every data point traceable from reported disclosure back to its source (invoice, meter reading, supplier submission), with evidence attached.
Data quality management — flags for gaps, estimates, and proxy data, because an undisclosed estimate presented as a measurement is a liability. Purpose-built platforms force the distinction that general tools blur.
Workflow and accountability — owner assignment, review cycles, and approvals that map to the governance disclosures you must make about your own processes.
This is why generic AI tools and even general-purpose databases fall short: ASRS compliance is not a content problem. It is a data integrity problem, and it demands infrastructure designed for it — the same reason you would not run your statutory financial accounts out of a group chat.
Function 2: Scientific expertise for interpreting the data
Then comes the part software cannot do: judgement. The data your platform aggregates does not speak for itself. It must be interpreted by people who understand the science and the standards — whether that expertise is internal or external. This is where experts:
Design and interpret scenario analysis — selecting pathways, defining horizons, and translating physical and transition risks into financially material exposures. Done poorly, scenario analysis becomes a compliance artefact nobody trusts; done well, it becomes strategic intelligence.
Determine Scope 3 materiality and methodology — deciding which of the 15 categories are material, selecting calculation methods, establishing baselines, and documenting the approach in a way that survives assurance scrutiny.
Connect the numbers to risk and value — the question your board actually cares about is not "what are our emissions" but "what is our exposure, what is driving it, what is it costing, and what does mitigation return?" Answering that requires understanding how climate variables propagate through assets, supply chains, and revenue.
Defend the disclosure — in front of auditors, regulators, and the board. Someone must be accountable for the claim that the methods were appropriate and the conclusions reasonable. That accountability is human, by design.
Function 3: People who own the outcome
Directors sign the declaration. Accountable executives own the process. The structure looks like this:
Function | Tool / capability | Owns |
Data management | Purpose-built ESG platform | Collection, calculation, audit trails, consistency, evidence |
Interpretation | Scientific / sustainability expertise (internal or external) | Materiality, methodology, scenario analysis, risk quantification, narrative grounded in evidence |
Assistance | LLMs (bounded, supervised) | Drafting, editing, summarising — never source data, never calculations, never sign-off |
The principle underneath it is simple: software manages the data; scientists interpret the risk; accountable humans own the disclosure. Confuse those layers — and in particular, ask a language model to do any of the three — and you have built your compliance position on a foundation that cannot be assured.
Part 7: Your Action Plan — By Cohort
If you are Group 1
Your first reports are already being lodged, with the September–October 2026 lodgement window closing for 30 June year-end entities. Note two things: Scope 3 reporting becomes mandatory in your second reporting year — for calendar-year entities, that means the year commencing 1 January 2026, so Scope 3 data collection should already be underway. And ASIC will begin reviewing lodged reports from 2026 and publishing its findings. Audit your first disclosure as if a regulator will read it — because they may well.
If you are Group 2 — your preparation window is now
With reporting periods commencing 1 July 2026, treat the following as this-financial-year priorities:
Confirm your scoping — including at the consolidated group level, and stress-test whether acquisitions, growth, or structural changes could change your status. Remember: you meet a group if you cross two of three thresholds.
Stand up governance now — board oversight, a named accountable owner, and defined escalation pathways. These are disclosable in year one and they take time to build credibly.
Select and implement an ESG data platform — get Scope 1 and 2 data into a governed system with audit trails. These figures are assured from year one; spreadsheet archaeology will not satisfy an assurance provider.
Begin Scope 3 groundwork immediately — even with one year of relief, you must disclose from year two. Start by screening suppliers by spend and emissions intensity, then prioritise engagement with your top 20–30 by estimated impact. Treat Scope 3 as a supply chain data programme, not a reporting task.
Commission scenario analysis — with competent methodology. If internal capability doesn't exist, engage external expertise now; capability queues form ahead of every deadline.
If you are Group 3 — or not in scope at all
Use the runway. The organisations that navigate reporting regimes best are those that treat the pre-reporting year as a build year: data foundations, governance, supplier readiness. And if you are a supplier to any large Australian entity, assume the request for climate data is coming regardless of your own formal scope — the earlier your numbers are credible, the stronger your position in procurement conversations.
The Bottom Line
The ASRS marks the moment climate risk reporting stopped being a discretionary narrative exercise and became a governed, assured, enforceable component of Australian corporate reporting. For Group 2 entities, the clock starts this financial year. For everyone else, the cascade through supply chains and the regulator's sharpening scrutiny are already reshaping what "prepared" means.
The organisations that emerge strongest from this regime will be the ones that treat it not as a compliance tax but as what it genuinely is: the first legislated mandate to finally quantify, in financial terms, risks that have been quietly sitting in their operations and supply chains all along.
But do it properly. A governed ESG platform for the data. Scientific expertise for the interpretation. Accountable humans for the disclosure. And general-purpose AI kept firmly in its lane — as a drafting assistant, never as your reporting engine.
Because a sustainability report that cannot survive assurance is not a compliance document. It is a liability with a cover page.
See Where You Stand Before the Deadline
Terran Industries' Climate Health Check is the fastest way to see your climate risk in financial terms — a high-level assessment across all 7 Lex Pillars that identifies your areas of highest exposure and financial exposure, mapped against the disclosure expectations of ASRS, ISSB, and CSRD. No jargon. No obligations. Just clarity.
Because when the numbers are defensible, the reporting is the easy part.
Sources & further reading: AASB S2 Climate-related Disclosures (September 2024); ASIC Regulatory Guide 280; AUASB Sustainability Assurance implementation guidance (ASSA 5000 / ASSA 5010); PwC Australia and BDO Australia analysis of the legislated regime; ASIC sustainability reporting guidance for preparers; GHG Protocol and CDP research on Scope 3 data access challenges. This article provides general information, not financial, legal, or compliance advice — directors should seek advice specific to their circumstances.