Guide · Pakistan

From deadline to delivery: a board-ready climate-risk implementation plan

A decision-led reading of the SBP requirement for banks, DFIs and microfinance banks, with workstreams, challenge questions and evidence for the road to 2029.

Climate riskGovernanceBanking

The State Bank of Pakistan’s climate-risk framework applies to banks, microfinance banks and development finance institutions. It requires a board-approved, time-bound implementation plan and targets by 30 September 2026, with compliance to the framework by 30 June 2029.

The implementation plan is not the end-state. It is evidence that the institution understands the work, has assigned responsibility and can move from current capability to a defensible operating model.

What the framework requires the plan to cover

At minimum, SBP identifies four areas:

  1. establishment of a governance structure;
  2. development or update of relevant policies and procedures;
  3. integration into risk management and stress-testing frameworks; and
  4. capacity building for relevant staff, including board and senior management.

The wider framework also addresses internal controls, capital and liquidity adequacy, credit, market, liquidity and operational risks, data, monitoring, reporting and climate scenario analysis.

The board’s real decision

The board is not simply approving a project schedule. It is deciding:

  • how climate-related financial risk enters strategy and risk appetite;
  • which board committee and management structure hold oversight;
  • how roles work across the three lines of defence;
  • what the institution considers material over short, medium and long horizons;
  • which portfolios, sectors, geographies and counterparties require priority attention;
  • which data and proxy limitations are acceptable temporarily;
  • what resources and capability are required; and
  • what evidence will demonstrate progress through 2029.

A plan that lists training, policy updates and system changes without resolving these questions may look busy while leaving the operating model undefined.

Six connected workstreams

1. Governance and accountability

Map the board committee, senior-management committee, executive owner and working-level responsibilities. Define decisions, reporting frequency, escalation routes and how climate matters connect to existing governance.

Evidence might include: approved terms of reference, role descriptions, reporting templates, committee calendars and decision logs.

2. Materiality and risk identification

Define a repeatable method for identifying physical and transition risk drivers, assessing materiality and connecting them to traditional risk categories. State time horizons and thresholds.

Evidence might include: a documented methodology, priority sector/geography views, portfolio heatmaps, limitations and approval records.

3. Risk-process integration

Identify where climate considerations enter origination, due diligence, credit assessment, pricing, approval, portfolio monitoring, collateral, remedial management, investments, liquidity and operational resilience.

Evidence might include: revised policies, process maps, decision criteria, sample files, monitoring triggers and control testing.

4. Data and reporting

Create a data inventory: required decision, field, definition, owner, source, quality check, frequency and system location. Where proxies are used, document rationale, limitations, conservatism and the plan to improve.

SBP expects internal reporting capabilities that cover climate-related exposures and concentrations. The framework identifies examples including vulnerable sectors and geographies, climate-related non-performing financing, borrower emissions data and Green Taxonomy mapping where applicable.

Evidence might include: data dictionary, lineage, gap register, proxy methodology, quality controls and board reporting.

5. Stress testing and financial resilience

Connect the climate framework to the applicable SBP climate stress-testing guidance and to capital and liquidity adequacy processes. Define how severe but plausible scenarios inform decisions, limits and actions.

Evidence might include: scenario governance, modelling assumptions, validation, results, management actions and integration records.

6. Capability and change

Move beyond attendance counts. Identify what each role must know or be able to do, then connect learning to policies, decisions, cases and on-the-job application.

Evidence might include: role-based learning objectives, board challenge sessions, case exercises, assessment results and follow-up actions.

A practical current-state scale

Level Description Planning implication
0: Not established No clear owner, method or evidence Establish governance and immediate control priorities
1: Defined Requirement and owner identified; design incomplete Complete design, prioritise gaps and assign resources
2: Piloted Method tested on limited portfolios or processes Resolve limitations, validate and plan controlled expansion
3: Embedded Used in routine decisions with controls and reporting Improve coverage, quality and management use
4: Evidenced Outcomes, limitations and control performance are demonstrable Sustain, challenge and adapt as risks and rules evolve

This is not an SBP scoring model. It is a practical way to prevent “policy exists” from being confused with “capability works”.

Board challenge questions

  • Which climate-risk drivers are currently considered material, over which time horizons, and why?
  • Where can the institution show that climate information already changes a decision?
  • Which portfolios combine high exposure with weak borrower or location data?
  • How are transition-risk responsibilities treated for institutions and portfolios within the framework’s proportionality approach?
  • Which proxies are used, what could they miss and when will they be reviewed?
  • What changes by each milestone, and not only what activity occurs?
  • Which dependencies require budget, technology, borrower engagement or external expertise?
  • How will internal audit assess the adequacy of first- and second-line processes?
  • What will be reported to the board at least annually, and what should be more frequent?

What a credible roadmap looks like

A roadmap should show outcomes, owners, dependencies, evidence and decision gates. It should distinguish:

  • immediate governance and planning requirements;
  • near-term policy, data and pilot work;
  • controlled integration into risk and financial processes;
  • validation and independent challenge; and
  • maturity improvements through June 2029.

It should also record assumptions and limitations. A false appearance of precision is less useful than an honest plan for closing a known gap.

Before approval

The implementation plan should receive institution-specific review across risk, business, finance, compliance, legal, internal controls, technology and relevant specialist functions. The authoritative framework, not this guide, controls the requirement.

Primary sources

Use the original materials for authoritative requirements and context.

Review, independence and limits

Review: Institutional editorial review by NetSifr Foundation. Independent qualified banking-risk and regulatory review pending; institution-specific application requires professional risk, legal and regulatory advice

AI assistance: This resource was drafted with AI assistance and reviewed by a NetSifr Foundation editor accountable for the published text. See the trust standards.

Sponsorship: None. Client relationship: None. Conflicts: None identified.

Corrections: No corrections recorded.

This resource is educational and does not replace the cited source or organisation-specific financial, legal, engineering, assurance, investment, certification or verification advice.