ISO 27001 Climate Amendment: What A1:2024 Actually Requires
Amendment 1:2024 to ISO/IEC 27001 is the shortest change the standard has ever received. It adds one sentence to clause 4.1 and one note to clause 4.2. It came into force in February 2024, applies to every organisation holding or seeking certification, and there is no transition period — it was effective immediately.
It is also the change most likely to be missing from the toolkit you bought. Most documentation sets on the market were written against the 2022 text and have not been revisited since. If your context analysis has no line about climate change, you have a gap, and it is the kind of gap a certification auditor finds in the first hour because it is in clause 4.1, the first requirement they read.
This article explains exactly what the amendment requires, what it does not require, and what evidence satisfies it. It is written against the European adoption, EN ISO/IEC 27001:2023+A1:2024. The same amendment was applied to ISO/IEC 42001 and to the other management system standards published under the harmonised structure, so if you run more than one system the answer below applies to all of them.

Checking whether your documentation predates the amendment? The ISO 27001 Compliance Suite is built against the European adoption 2023+A1:2024, with the climate determination in the context analysis and the interested-party register from the start. €590 excl. VAT.
What the amendment changes
Two things, and only two.
In clause 4.1, alongside the existing requirement to determine external and internal issues relevant to your ISMS, the standard now requires you to determine whether climate change is a relevant issue.
In clause 4.2, a note was added recording that relevant interested parties can have requirements related to climate change.
That is the entire amendment. No new control was added to Annex A. No new documented information is named. Nothing in clauses 5 to 10 changed.
The brevity is misleading, and it is why the amendment is so often dismissed. A requirement that takes one sentence to state can still take real work to satisfy, and this one has a property that catches people out: it is a requirement to make a determination, not a requirement to reach a particular conclusion.
”Not relevant” is a valid answer. “We never asked” is not.
This is the single most important thing to understand about A1:2024.
An organisation that considers climate change and concludes it is not a relevant issue for its information security management system satisfies the requirement, provided the conclusion is recorded and reasoned.
An organisation that never asked the question does not satisfy it, even where the honest answer would have been no.
The requirement is procedural. It obliges you to put the question on the table during your context analysis and to be able to show that you did. A software company running entirely on a major cloud platform, with a distributed team and no premises of its own, may well conclude that climate change does not materially affect the confidentiality, integrity or availability of the information it holds. That is a defensible conclusion. What is not defensible is an empty space where the consideration should be.
This makes the amendment unusually cheap to satisfy and unusually easy to fail. The work is half a day. The failure is a nonconformity in clause 4.1.
The question to ask, and the question not to ask
The question A1:2024 puts to you is narrow, and keeping it narrow is what makes it answerable:
Does climate change, or the response to it, affect the confidentiality, integrity or availability of the information within the scope of our ISMS?
The question it does not ask is whether your organisation has a climate policy, a carbon reduction target, or an environmental management system. Those are different subjects governed by different standards. Bringing them into your ISMS context analysis does not satisfy 4.1 and makes the analysis harder to read.
Environmental commitments belong in ISO 14001 if you run one. What belongs here is only the intersection between climate and information security — which is smaller than an environmental programme and larger than most people expect.
The five routes by which the answer turns out to be yes

In practice, when climate change is relevant to an ISMS, it reaches it through one of five routes. Working through them is how you turn an abstract question into a determination you can defend.
1. Availability of sites and people
Heat, flooding, storms and wildfire affect offices, equipment rooms and data centres, and they affect whether people can reach them. An organisation with a single office in a flood-prone area, or with equipment in a building whose cooling was specified for a climate that no longer applies, has an availability issue that belongs in the ISMS.
This route lands on business continuity and on physical and environmental security. If your continuity arrangements identify fire and power failure but not heat or flooding, this is where you find that out.
The threat analysis behind a business continuity plan is the natural place for this to land.
2. Availability of infrastructure
Power and cooling constraints, grid instability and water restrictions affecting data centres are increasingly real, and they are usually inherited rather than owned. You may not operate the facility, but you depend on it.
The practical question is not whether your provider has a sustainability report. It is whether their continuity arrangements account for the conditions their facilities will actually face, and whether you have asked.
3. Supply chain
Where your providers are located, and where their own providers are located, determines what a regional climate event does to your service. This is the route most often missed, because supplier assessments typically cover security posture and certification and stop there.
Concentration matters as much as location. Several suppliers resting on the same platform, or in the same region, is a single point of failure that no individual supplier assessment reveals.
4. Regulatory and reporting obligations
Sustainability reporting duties create new data sets, new systems to hold them, and new third parties processing them. Each of those has confidentiality and integrity requirements like any other information asset.
This is a genuinely information-security consequence of climate regulation, and it is often the reason the answer is yes for organisations that would otherwise have said no. The reporting itself is not your concern here; the data behind it is.
5. Customer and investor expectations
Requirements arriving through contracts and security questionnaires. This is the route by which the topic most often becomes mandatory in practice, before any regulator gets involved — a customer asks, you answer, and the answer becomes a commitment.
Note that this route runs through clause 4.2 rather than 4.1: it is an interested party requirement, which is exactly what the new note is about.
What evidence satisfies the requirement
There is no prescribed form. What an auditor needs to see is that the question was asked, by whom, when, and what was concluded.
In practice a single row in your context analysis does the job, provided it contains:
| Element | Why it matters |
|---|---|
| The determination | Yes or no, stated plainly |
| The basis for it | One or two sentences of reasoning. This is what turns a box-tick into a determination |
| Where the issues are dealt with, if yes | The reference that shows the answer went somewhere |
| Who determined it, and when | Attribution and date |
| Next review | It is a context issue, so it is reviewed with the rest of the context |
For clause 4.2, a column in your interested parties register marking which requirements are climate-related is sufficient. Most organisations will find one or two rows: a customer contract clause, or an investor expectation.
Where the determination is positive and a control follows from it, the Statement of Applicability carries the obligation as its justification.
The part that separates a real determination from a decorative one
This is also the trail an internal auditor should follow. How to run one that finds something covers sampling and criteria.
If your answer is yes, something downstream has to change.
An issue identified in clause 4.1 is an input to your risk assessment. If your context analysis says climate change is relevant, and your risk register contains nothing that came from it, and your continuity arrangements are unchanged, then the analysis was performed on paper. An experienced auditor will follow exactly that trail: 4.1 says yes, so where is it in clause 6.1?
The trace should be visible in at least one of three places:
- The risk register, where a climate-derived issue appears as a risk with an owner and a treatment decision, like any other.
- The continuity arrangements, where the availability consequences are reflected in the recovery objectives or the scenarios exercised.
- The supplier assessments, where location and provider continuity are considered rather than assumed.
Conversely, if your answer is no, nothing downstream needs to change — but the reasoning must be strong enough to survive the question “why not?”, and it must be revisited when the context changes. An organisation that concluded “not relevant” three years ago and has since moved its primary systems into a single region should look at that conclusion again.
Where this fits in your documentation
The same determination applies to an AI management system under ISO/IEC 42001, where the answer is often different — the availability and cost of computing resources is a route that does not exist on the security side. The readiness checklist covers what that system involves.
The amendment does not require a new document. It requires two additions to documents you already have:
- The context analysis gains a determination line for climate change, completed in every case including when the conclusion is negative.
- The interested parties register gains a way to mark climate-related requirements.
If your ISMS manual has neither, that is the gap, and closing it is a morning’s work — considerably less than the time spent arguing about whether the amendment applies.
Both are among the items ISO 27001 requires you to document, so neither is optional to hold.
If you are also implementing ISO/IEC 42001 for an AI management system, the same amendment applies there in the same words, and the answer is often different: the availability and cost of computing resources is a route that does not exist on the security side.
Common mistakes
Treating it as an environmental requirement. The most frequent error. The context analysis fills with carbon accounting and says nothing about information security. It satisfies nobody.
Leaving the determination blank because the answer is no. The blank is the nonconformity, not the no.
Answering yes to be safe, then doing nothing. Worse than answering no with a reason, because it creates a visible inconsistency between clause 4.1 and clause 6.1 that an auditor is trained to look for.
Assuming the toolkit covered it. Check. A documentation set written against the 2022 text and not revisited will not have it, and most on the market have not been revisited.
Frequently asked questions
Is the climate change amendment mandatory? Yes. Amendment A1:2024 came into force in February 2024 with no transition period. It applies to every organisation holding or seeking certification to ISO/IEC 27001.
Do I have to conclude that climate change is relevant? No. The requirement is to make and record the determination, not to reach a particular answer. A reasoned “not relevant” satisfies clause 4.1. An empty line does not.
What if we never considered it? That is the nonconformity. An organisation that never asked the question does not meet the requirement, even where the honest answer would have been no.
Does this mean we need an environmental policy? No. The amendment is confined to whether climate change affects the confidentiality, integrity or availability of information in scope. Carbon targets and environmental programmes belong to ISO 14001 and do not satisfy clause 4.1.
What evidence does an auditor want to see? A line in the context analysis with the determination, the reasoning behind it, who made it and when. If the determination is positive, they will also look for the issues appearing in the risk assessment or the continuity arrangements.
Does the same amendment apply to ISO 42001? Yes, in the same words. It was applied across the management system standards published under the harmonised structure. On the AI side the answer is often different, because the availability and cost of computing resources is a route that does not exist for information security alone.
Our toolkit was bought in 2023. Is it affected? Almost certainly. Documentation sets written against the 2022 text and not revisited since do not contain the determination. Check the context analysis before assuming it is there.
What to do this week
- Open your context analysis. Look for a line about climate change. If there is not one, that is your gap.
- Work through the five routes above. Twenty minutes with the person who knows your infrastructure and your supplier list is usually enough to reach a defensible answer.
- Record the determination with its reasoning, whichever way it goes.
- If the answer is yes, carry each issue identified into your risk assessment and, where it affects availability, into your continuity arrangements. Make the trail visible.
- Add the review of the determination to whatever cycle already reviews your context.
The amendment is small. The work is small. The reason to do it now is that it sits in the first clause an auditor reads, and an empty line there sets the tone for everything that follows.
Where to go from here
The amendment is half a day of work sitting in the first clause an auditor reads. The harder question it raises is whether the rest of your documentation was written against the current text or the previous one.
The ISO 27001 Compliance Suite is built against EN ISO/IEC 27001:2023+A1:2024: the climate determination is a mandatory row in the context analysis, the interested-party register has a column for climate-related requirements, and the risk source catalogue carries a line for it so that a positive determination has somewhere to go. 43 files, €590 excl. VAT.
If you also run an AI management system, the same amendment applies there and the answer is usually different — the ISO 42001 Compliance Suite handles that side.