ESG risk management is the discipline of identifying, assessing, and controlling the environmental, social, and governance factors that could affect an organization’s financial performance, reputation, or ability to operate. Rather than functioning as a wholly separate discipline, ESG risk management is best understood as a set of environmental, social, and governance considerations integrated into an organization’s existing enterprise risk management processes, extending established risk practices to climate exposure, labor conduct, supply chain integrity, and governance quality.
In Malaysia, ESG risk management is increasingly shaped by financial-sector climate-risk requirements and sustainability-disclosure rules, although these instruments serve distinct purposes rather than forming one unified regime. Bank Negara Malaysia’s Climate Risk Management and Scenario Analysis (CRMSA) policy establishes climate-related risk management, scenario analysis and disclosure expectations for applicable BNM-supervised financial institutions, while the Securities Commission’s National Sustainability Reporting Framework (NSRF) establishes a phased sustainability reporting framework based on the IFRS Sustainability Disclosure Standards issued by the International Sustainability Standards Board (ISSB) for specified entities. Group 1 comprises Main Market listed issuers with market capitalisation, excluding treasury shares, of at least RM2 billion as at 31 December 2024, or at the date of listing for issuers listed after that date, with the requirements applying to annual reporting periods beginning on or after 1 January 2025. Other Main Market listed issuers form Group 2 and apply for annual reporting periods beginning on or after 1 January 2026, while ACE Market issuers and qualifying non-listed companies, defined as those with consolidated group revenue of at least RM2 billion for two consecutive financial years, form Group 3 and apply for annual reporting periods beginning on or after 1 January 2027.
The NSRF adopts a phased, climate-first approach and provides additional transition relief for Scope 3 emissions: Groups 1 and 2 are expected to disclose relevant Scope 3 greenhouse gas emissions information from annual reporting periods beginning on or after 1 January 2027 and 1 January 2028 respectively. Group 3’s applicable Scope 3 disclosure commencement date should be determined in accordance with the latest NSRF implementation requirements and transition relief. BNM’s separate Climate Change and Principle-based Taxonomy (CCPT) serves a different function by providing a principles-based framework for assessing and classifying economic activities according to climate-related characteristics and transition considerations, rather than functioning as a standalone climate-risk-management policy. Because CRMSA is specifically climate-focused, it should not be treated as a complete regulatory framework covering every social and governance risk.
This guide covers what ESG risk management actually means, how an ESG risk management framework and policy are typically structured, how ESG risk assessment works in practice, how ESG risks and opportunities relate to one another, how ESG risk varies by sector, and how ESG risk ratings are calculated and interpreted, including the meaningful differences between major rating providers.
Need Help Building an ESG Risk Management Approach?
Understand which ESG risks matter to your business and how to integrate them into your existing risk management processes.
What Is ESG Risk Management?
ESG risk management is the structured process organizations use to identify environmental, social, and governance exposures, evaluate their potential business impact, and implement controls to reduce that impact to an acceptable level.
What Is ESG Risk?
ESG risk is the potential for an environmental, social, or governance factor to negatively affect an organization’s financial performance, operations, or reputation. What counts as material ESG risk depends heavily on the organization’s sector, geography, time horizon, and the particular stakeholder or financial perspective being applied, which is why a risk considered severe for one company may be immaterial for another operating in a different context.
What Is the ESG Risk Model?
There is no single universal ESG risk model; rating providers and corporate risk functions apply different approaches. Morningstar Sustainalytics, for example, estimates unmanaged risk by assessing a company’s exposure to material ESG issues and the extent to which those issues are managed. The MSCI ESG Ratings methodology follows a broadly similar exposure-and-management logic but expresses the result differently, through an industry-relative letter rating rather than a numerical unmanaged-risk score, so the two should not be treated as the same underlying model.
What Are Examples of ESG Risk?
Common ESG risk examples include physical climate risk such as flooding or extreme heat affecting facilities, transition risk from carbon pricing or changing regulation, labor rights issues in extended supply chains, data privacy failures, board independence weaknesses, and anti-corruption control gaps. These risks are commonly considered ESG risks because their underlying drivers arise from environmental, social, or governance factors, although they may also interact with commercial, financial, operational, legal, and technical risks.
How Does ESG Risk Management Work in Practice?
ESG risk management works through a defined framework, policy, and set of guidelines that together translate the general concept into a repeatable organizational process rather than an ad hoc reaction to individual issues.
What Is an ESG Risk Management Framework?
An ESG risk management framework is the structural system an organization uses to identify, categorize, assess, and monitor ESG risks on an ongoing basis, typically integrating with existing enterprise risk management processes rather than operating as a fully separate system. A well-designed framework specifies risk categories, assessment methodology, escalation thresholds, and reporting lines, so that a significant ESG finding can receive a level of executive attention comparable to a major financial or operational risk.
What Is an ESG Risk Management Policy?
An ESG risk management policy is the formal document that establishes an organization’s risk appetite for ESG matters, assigns accountability for managing specific risk categories, and sets expectations for how risks should be identified and escalated. Depending on the organization’s governance and documentation structure, the policy may establish overarching principles and accountability, while the framework describes the processes and mechanisms used to implement those principles.
What Do ESG Risk Management Guidelines Typically Cover?
ESG risk management guidelines generally cover risk identification methods, assessment scoring criteria, data sources and verification requirements, escalation and reporting protocols, and review frequency, functioning as the practical instruction manual that sits beneath the policy and framework. Organizations new to ESG risk management often underestimate how much guideline detail is needed, since vague guidance tends to produce inconsistent risk scoring across different business units or geographies.
ALSO READ: ESG Framework in Malaysia: How Businesses Can Build, Govern and Implement an Effective ESG Framework
Develop a Practical ESG Risk Management Framework
Build a structured ESG risk framework, policy, and governance process that fits your organization’s operations.
How Is ESG Risk Assessed?
ESG risk assessment is the analytical process of evaluating identified risks for likelihood and potential impact, using structured tools and methodologies to produce comparable, defensible results rather than purely subjective judgment calls.
What Is ESG Risk Assessment?
ESG risk assessment is the systematic evaluation of environmental, social, and governance exposures against defined criteria. Depending on the organization and methodology used, this can produce a numerical risk score, a qualitative rating, a heat map, or a structured risk register, rather than always resulting in a single standardized number. Effective assessment depends on consistent methodology applied across the organization, since a risk scored differently by two different business units undermines the comparability the exercise is meant to provide.
What Risk Assessment Tools Are Used for ESG?
Common ESG risk assessment tools include structured questionnaires and scorecards for supplier and counterparty screening, GIS-based physical climate risk mapping tools for facility-level exposure, industry-based sustainability disclosure standards such as the SASB Standards, which can help organizations identify financially relevant sustainability-related risks, opportunities, disclosure topics and metrics, and dedicated ESG risk management software platforms that centralize data collection and scoring across business units. SASB Standards, now maintained within the IFRS Foundation structure, identify material topics and metrics rather than functioning as a risk-rating or scoring methodology in their own right. The right combination of tools depends on what is being assessed, since a supply chain labor risk questionnaire serves a different purpose than a physical climate exposure map.
What Is an ESG Risk Assessment Matrix?
An ESG risk assessment matrix plots identified risks along two axes, typically likelihood and impact, allowing an organization to visually prioritize which risks warrant immediate attention versus ongoing monitoring. This is a conventional enterprise risk management technique applied to ESG categories rather than a distinct, ESG-specific methodology, which is why organizations with mature enterprise risk functions often find ESG risk assessment easier to integrate than those building risk management capability from scratch.
What Is an ESG Risk Review?
An ESG risk review is the periodic reassessment of previously identified risks to confirm ratings remain accurate as business conditions, regulations, and stakeholder expectations evolve. There is no single universal review frequency applicable to all ESG risks; review frequency should reflect the organization’s risk framework, the nature and severity of the risk, applicable regulatory requirements, and material changes in the business or external environment. Provider methodologies and company-level assessments may similarly be updated when methodology changes, new information, or material events affect the assessment, rather than following a single fixed cycle.
Strengthen Your ESG Risk Assessment Process
Identify material ESG risks, prioritize them consistently, and support better business decision-making.
What Are ESG Risks and Opportunities?
ESG risk management increasingly frames environmental, social, and governance factors as a spectrum running from threat to advantage, rather than treating risk and opportunity as entirely separate exercises.
How Do ESG Risks and Opportunities Relate to Each Other?
ESG risks and opportunities can often represent the same underlying issue viewed from different angles; a company facing transition risk from carbon-intensive operations may simultaneously hold an opportunity to strengthen competitive positioning by investing in lower-carbon alternatives, new technologies, or transition strategies ahead of relevant market developments. This is best understood as a useful strategic framing principle rather than a guaranteed organizational outcome, since realizing the opportunity side still depends heavily on execution.
What Are Examples of ESG Governance Risks?
ESG governance risk examples include board composition lacking independent oversight, executive compensation structures that reward short-term performance at the expense of long-term risk management, weak whistleblower protections, and inadequate anti-corruption controls in high-risk markets. Governance risk is frequently the least visible of the three ESG pillars in public discussion, yet it can strongly influence whether environmental and social risks are actually managed effectively or simply documented on paper.
How Do ESG Risks Vary by Sector?
ESG risk is not uniform across industries; the material issues, and their relative significance, differ depending on a company’s sector, operations, and geographic footprint, though sector exposure alone does not determine an individual company’s final rating.
What ESG Risks Do Banks and Financial Institutions Face?
ESG risks for banks and other financial institutions include financed emissions, meaning the climate impact embedded in their loan and investment portfolios, as well as physical and transition risks transmitted through borrowers, counterparties, collateral, and investments, alongside conduct risk and the operational challenge of conducting credible climate scenario analysis for large exposures. Bank Negara Malaysia’s CRMSA policy reflects this reality, covering governance, strategy, risk appetite, risk management, scenario analysis, and climate-related disclosure expectations for BNM-supervised financial institutions.
What ESG Risks Arise in Supply Chains?
ESG risks in supply chains commonly include forced or child labor several tiers removed from direct oversight, deforestation-linked sourcing, and supplier safety failures that can affect the buying company’s reputation even without direct operational involvement. Malaysian exporters in sectors such as manufacturing, electronics, and palm oil may face heightened scrutiny from international customers, financiers, investors, and applicable market-specific regulatory requirements, since international customers, financiers, and applicable legal requirements may require or encourage greater visibility into supplier practices that were historically invisible to the buyer.
How Do ESG Risks Differ Across Industries?
ESG risk by industry varies according to which ESG issues are likely to be financially material for a given sector. Extractive and heavy manufacturing sectors are often exposed to significant sustainability-related risks involving emissions, pollution, resource use, biodiversity, occupational health and safety, and physical climate hazards, although the materiality of each issue depends on the company’s operations and geographic footprint. Certain textile and plantation activities may face significant labor, human rights, land-use, biodiversity, and supply-chain issues, though actual exposure varies by business model, geography, and existing controls. Financial services and technology sectors commonly face material governance and data-related issues, though this does not mean these issues automatically carry greater weighting in every individual company’s assessment.
Identify ESG Risks Relevant to Your Industry
Different industries face different ESG challenges. Assess the risks that are most relevant to your operations.
What Are ESG Risk Ratings?
ESG risk ratings are third-party assessments that translate an organization’s ESG risk exposure and management quality into a provider-specific rating or score, though methodology, scale, and interpretation vary meaningfully between providers and should not be treated as interchangeable.
What Do ESG Risk Ratings Measure?
ESG assessments from providers such as Morningstar Sustainalytics and MSCI are generally designed to evaluate financially relevant sustainability-related risks and, depending on the provider’s methodology, the extent to which a company manages or is resilient to those risks. They should not automatically be interpreted as comprehensive measures of a company’s overall social or environmental impact, an important distinction from separate product categories such as impact ratings, sustainability rankings, or climate-transition scores, which assess different concepts entirely. Sustainalytics specifically evaluates unmanaged ESG risk, while MSCI assesses relative resilience to financially relevant, industry-specific sustainability risks. Investors may use these ratings as one input among several in research, portfolio construction, or company engagement, though the extent of their use varies by investor and market.
How Is an ESG Risk Rating Calculated?
ESG risk rating calculation is provider-specific rather than governed by one common formula. Morningstar Sustainalytics’ ESG Risk Ratings assess a company’s unmanaged ESG risk by evaluating its exposure to material ESG issues and the quality of its management of those issues to estimate the level of ESG risk that remains unmanaged and express that residual unmanaged risk through an overall risk score. MSCI ESG Ratings use a different approach, assigning industry-relative ratings based on a company’s exposure to financially relevant, industry-specific sustainability risks and its ability to manage those risks relative to industry peers. Because the two methodologies differ structurally, a Sustainalytics score and an MSCI rating should not be compared directly or treated as equivalent measures.
What Does an ESG Risk Rating Scale and Score Mean?
Rating scales differ by provider and should always be read alongside the provider that produced them. Sustainalytics uses five overall risk categories, negligible, low, medium, high, and severe, with a lower numerical score indicating less unmanaged risk. MSCI uses a distinct industry-relative letter scale running from AAA to CCC, with AAA representing the strongest relative rating and CCC the weakest. Applying Sustainalytics’ “lower is better” logic to an MSCI letter rating, or vice versa, would misread the result, which is why identifying the specific provider is essential whenever an ESG risk rating is discussed.
Understand Your ESG Rating Readiness
 Evaluate how current disclosures and management practices align with selected publicly available ESG rating methodology criteria and identify potential areas for improvement.
How Can Wellkinetics Help
Wellkinetics provides advisory support for Malaysian organizations developing ESG risk management processes, preparing sustainability information, and identifying gaps against selected reporting or rating methodologies. The appropriate scope of support depends on the organization’s sector, regulatory status, reporting obligations, and risk profile:
1. ESG Risk Management Framework Development: Support for designing risk categorization structures, assessment methodologies, escalation thresholds, and integration with existing enterprise risk management processes.
2. ESG Risk Management Policy and Guidelines: Drafting support for risk appetite statements, accountability structures, and practical operating guidelines intended to support consistent day-to-day practice.
3. ESG Risk Assessment and Materiality Analysis: Facilitation support for sector-informed ESG risk assessment, development of risk assessment matrices, and identification of material ESG risk indicators relevant to specific industries.
4. Supply Chain ESG Risk Management: Support for assessing ESG risk across supplier networks, including risk-tiered assessment design and supplier engagement on identified findings.
5. Support for Regulated Financial Institutions: Advisory support for applicable BNM-supervised financial institutions and their advisers in interpreting and operationalising relevant CRMSA expectations, including assistance with governance documentation, risk management process design, and disclosure preparation; this support does not constitute legal or regulatory compliance certification, and organizations should confirm regulatory sufficiency through their own compliance and legal functions.
6. ESG Rating Gap Analysis: Analysis comparing an organization’s current disclosure and practices against publicly available methodology criteria from providers such as MSCI and Sustainalytics to identify potential improvement areas. This service identifies gaps against public methodology criteria and does not guarantee any specific rating outcome, as ratings are determined solely by the respective provider.
7. Ongoing ESG Risk Review: Support for periodic reassessment to help keep risk documentation current as regulations, business operations, and stakeholder expectations evolve.
By partnering with Wellkinetics, Malaysian organizations gain practical advisory support for building ESG risk management processes suited to their specific regulatory and operational context.
Learn more about our ESG consulting services.
References
- Bank Negara Malaysia. Climate Risk Management and Scenario Analysis (CRMSA) Policy Document (revised 17 March 2025). Kuala Lumpur: BNM. Available at: https://www.bnm.gov.my/documents/20124/938039/PD_Climate+Risk+Management+Scenario+Analysis_17+March+2025.pdf
- Bank Negara Malaysia and Joint Committee on Climate Change Sub-Committee 1. Climate Change and Principle-based Taxonomy (issued 30 April 2021), including the Climate Supporting, Transitioning and Watchlist classifications, together with updated implementation guidance and FAQs published 30 July 2026 (FAQ Version 2.0). Kuala Lumpur: BNM/JC3. Available at: https://www.bnm.gov.my/-/ccpt-update-2026
- Securities Commission Malaysia / Advisory Committee on Sustainability Reporting. National Sustainability Reporting Framework (NSRF) (2024), including applicable entities, adoption timeline, and Scope 3 transition relief provisions. Kuala Lumpur: SC Malaysia. Available at: https://www.sc.com.my/nsrf and https://www.investmalaysia.gov.my/media/swqntak1/national-sustainability-reporting-framework.pdf
- International Sustainability Standards Board. IFRS S1 and IFRS S2. London: IFRS Foundation.
- IFRS Foundation. SASB Standards. London: IFRS Foundation.
Further Reading
Malaysian Regulatory Resources:
- Bank Negara Malaysia Climate Risk Management and Scenario Analysis (CRMSA) Policy Document
- Bank Negara Malaysia Climate Change and Principle-based Taxonomy (CCPT)
- Securities Commission Malaysia National Sustainability Reporting Framework (NSRF)
International Frameworks and Rating Methodologies:
- IFRS Foundation SASB Standards
- ISSB IFRS S1 and IFRS S2
