1. Introduction
Public institutions do more than manage their own organizational footprints. They maintain drinking-water systems, transportation networks, emergency operations, health protection, land-use controls, public finance, public safety, permitting, public works, social services, and the legal and administrative arrangements through which communities absorb disruption. Failure in this setting differs from failure in a private organization because essential services, statutory duties, territorial equity, fiscal stability, ecological stewardship, and democratic accountability may be impaired at the same time. Public-sector sustainability reporting therefore requires a broader theory of preparedness than ordinary organizational disclosure.
Reporting architecture is entering an important period of institutional change. The International Public Sector Accounting Standards Board issued IPSASB SRS 1, Climate-related Disclosures, in 2026, with application to general-purpose financial reports for annual reporting periods beginning on or after 1 January 2028, with earlier adoption permitted [
1]. IFRS S1 and IFRS S2 organize sustainability and climate disclosure around governance, strategy, risk management, and metrics and targets [
2,
3]. The Global Reporting Initiative (GRI) Standards permit public and private organizations to report impacts on the economy, environment, and people [
4]. The Task Force on Climate-related Financial Disclosures (TCFD) established a decision-useful framework organized around the same four pillars and oriented toward forward-looking information in mainstream reporting [
5]. These frameworks strengthen transparency, comparability, and accountability. Their principal disclosure logics, however, remain grounded in identifiable risks, entity-level exposure, reporting periods, and material information for specified users. They offer less direct guidance for risks whose probabilities, thresholds, timing, transmission mechanisms, and public-service consequences are not stable enough to fit ordinary risk registers or expected-value calculations.
The central argument is that public-sector resilience reporting should disclose not only whether risks exist, but whether the government has the capacity to maintain essential public services and correct course under disruptive conditions. Conventional reporting often shows funded projects, hazard exposure, completed assessments, and compliance activities. Those outputs matter, but they do not necessarily reveal whether governing bodies sense emerging signals, translate them into service implications, mobilize cross-sector authority, shift among pathways, finance contingent action, protect vulnerable populations, and learn from exercises or events. A government may appear prepared because it has many resilience projects, while its adaptive decision system, dependency mapping, fiscal reserves, continuity objectives, and assurance mechanisms remain opaque.
This distinction is especially important for low-probability, high-impact (LPHI) systemic risks. LPHI conditions may be rare, contested, hard to quantify, or temporally distant, yet their consequences may include cascading infrastructure failure, fiscal stress, service interruption, loss of insurability, displacement, ecological damage, or erosion of public trust. Resilience originated as the capacity of a system to absorb disturbance without losing its defining functions [
6], and later expanded to include adaptation, learning, and transformation in social–ecological systems [
7]. Public-management research similarly distinguishes recovery after an event from precursor resilience, meaning the ability to detect and correct latent vulnerabilities before failure [
8]. Reporting that emphasizes exposure and project completion alone misses this precursor capacity.
Florida offers an analytically useful case because its Resilient Florida architecture is substantial, statutory, data-driven, and recurring. The state’s resilience materials include statewide flooding and sea-level-rise planning, critical asset data, local vulnerability assessment requirements, project eligibility rules, scoring criteria, grant funding, and public reporting [
9,
10,
11,
12]. These features make Florida a comparatively developed subnational resilience architecture for the limited purpose of this study. The case therefore serves as a demanding illustrative application of the proposed reporting logic; it is not treated as a statistically representative case or as a basis for claiming that the same gaps occur with equal significance in other jurisdictions.
The Atlantic Meridional Overturning Circulation (AMOC) is used as one stress-test scenario, not as a deterministic forecast. Scientific assessments agree that the AMOC is very likely to weaken during the twenty-first century, while the magnitude, timing, and possibility of abrupt collapse remain debated [
13,
14,
15,
16,
17,
18]. For the purposes of this article, the policy question is not whether a particular collapse date should be reported. The question is whether a public-sector resilience report would disclose how emerging, contested, and potentially systemic scientific information is monitored, translated into public-service consequences, connected to adaptive triggers, financed, coordinated, and reviewed. A second stress-test domain, a case-grounded cyber-fiscal disruption affecting essential services and municipal finance, is added to show that the proposed standard is hazard-neutral rather than climate-specific [
19,
20,
21,
22,
23].
This article makes six contributions. First, it defines resilience materiality as a public-sector reporting principle based on potential impairment of essential services, statutory obligations, public finances, ecological systems, or distributional protection, rather than probability or financial materiality alone. Second, it reorganizes the standards literature around three debates: risk management versus resilience governance, indicator disclosure versus capability disclosure, and financial materiality versus public-value materiality. Third, it develops a theoretical model of reporting-standard elaboration through four translation moves: normative boundary-setting, capability specification, evidentiary operationalization, and recursive assurance and learning. Fourth, it develops a structured interpretive coding protocol and codebook for comparing standards, guidance, and governmental documents. Fifth, it operationalizes the Public-Sector Resilience Reporting Standard (PSRRS) through mandatory, recommended, and optional clauses, evidence requirements, indicator examples, and a disclosure index. Sixth, it proposes a staged conformity model that distinguishes disclosure presence, operational integration, and externally assured adaptive resilience.
The article is intentionally framed as a pre-standard architecture rather than as a completed international standard. This framing addresses the evidentiary boundary of the study. The PSRRS is developed to a draft-clause level sufficient for academic scrutiny and pilot application, but its formal standardization would require stakeholder consultation, inter-rater validation, field testing, cost assessment, cross-jurisdictional comparison, and iterative revision. The objective is to provide a credible architecture for that next stage and to identify why current public-sector reporting may leave essential preparedness information hidden.
The study objectives are therefore deliberately bounded. The first objective is diagnostic: to identify disclosure gaps that emerge across a broader corpus of reporting, resilience, continuity, risk, and adaptation frameworks. The second is theoretical and constructive: to explain how public-value obligations may be translated into auditable capability disclosures and then into a coherent pre-standard architecture. The third is illustrative: to apply that architecture to Florida and to two stress-test scenarios in order to examine whether the proposed categories expose information that project- and hazard-centered reporting may leave invisible. The architecture is not derived from Florida alone, and the Florida case is not used to estimate the prevalence of reporting gaps across countries or regions. Claims of transferability are therefore analytical propositions for future testing, not empirical findings of this single-case application.
The paper proceeds as follows.
Section 2 develops the literature and conceptual foundations.
Section 3 explains the research design, corpus, coding protocol, Florida case logic, stress-test protocol, and validation boundaries.
Section 4 presents the comparative findings, Florida coding results, AMOC stress test, and cyber-fiscal stress test.
Section 5 specifies the PSRRS clauses, evidence requirements, indicators, reporting index, sample structure, conformity tiers, assurance logic, and implementation sequence.
Section 6 discusses the theoretical contribution, decision-use channels, political economy, feasibility, and limitations.
Section 7 concludes.
Appendix A,
Appendix B and
Appendix C provide the codebook, draft clauses, and sample report structure.
2. Literature Review and Conceptual Foundations
2.1. Three Reporting Debates: Risk, Capability, and Public-Value Materiality
The literature and standards landscape is best understood through three debates rather than through a catalog of instruments. The first debate concerns risk management versus resilience governance. ISO 31000 treats risk management as coordinated activities to direct and control an organization with regard to risk [
24]. This logic is valuable because public entities need systematic identification, analysis, evaluation, treatment, monitoring, and communication. Resilience governance asks a further question: how does the public system perform when knowledge is incomplete, events propagate across systems, or the initiating disruption changes during the response? Risk management organizes knowledge about threats; resilience governance organizes institutional capacity under surprise, ambiguity, and cascade [
8,
25,
26,
27].
The second debate concerns indicator disclosure versus capability disclosure. ISO 37120, ISO 37123, and ISO 37125 provide city-service, resilient-city, and ESG indicators for communities [
28,
29,
30]. Indicators support benchmarking and comparability. The UNDRR Disaster Resilience Scorecard and Climate Resilience Addendum also support structured assessment of local resilience capacity [
31,
32]. Yet a high-quality indicator set does not necessarily disclose whether an institution has authority, resources, triggers, redundancy, cross-sector agreements, exercise evidence, or corrective-action closure. Indicator reporting measures attributes, outputs, or outcomes; capability disclosure explains whether the public entity is prepared to act under changing conditions. The PSRRS treats indicators as necessary but insufficient.
The third debate concerns financial materiality versus public-value materiality. IFRS S1 and IFRS S2 focus on sustainability-related risks and opportunities likely to affect an entity’s prospects [
2,
3]. TCFD similarly emphasizes decision-useful climate-related information for financial filings [
5]. IPSASB SRS 1 adapts climate disclosure for public-sector general-purpose financial reports and explicitly serves accountability and decision-making [
1]. These are major advances. Public-sector resilience, however, also depends on material effects that may not be adequately expressed as investor-relevant financial information. A low-confidence scenario may not generate a credible expected value, yet it may threaten emergency response, drinking-water reliability, wastewater treatment, public health, public safety, housing stability, ecological function, or intergenerational fiscal capacity.
This article defines resilience materiality as follows: information is resilience-material when its omission, misstatement, or obscuration could reasonably prevent users from understanding whether a public entity is prepared to maintain, adaptively restore, or transform essential services, statutory obligations, public-value outcomes, ecological functions, fiscal stability, or equitable protection under plausible disruptive conditions. This definition is intentionally disciplined. It does not require disclosure of every imaginable catastrophe. The condition must be plausible, decision-relevant, and linked to public function, service continuity, fiscal exposure, systemic dependency, or distributional consequences. The definition therefore protects against both under-disclosure and performative over-disclosure.
Public-sector sustainability reporting research supports this extension. Sustainability accounting and reporting have been linked to public-value co-creation and multi-actor accountability [
33]. Structured reviews of nonfinancial reporting in public organizations show diverse formats, uneven practices, and incomplete integration [
34]. The problem is not only technical inconsistency. Fragmentation separates budgets from risk, infrastructure from equity, emergency management from sustainability, and strategic commitments from assurance evidence. Systemic disruptions do not respect those reporting boundaries. A resilience standard should reconnect them.
2.2. Public Administration Resilience and Critical Infrastructure Interdependency
Public administration scholarship provides a second foundation. Resilience in public organizations concerns more than recovery speed. It includes institutional memory, cross-boundary coordination, professional competence, learning, redundancy, discretion, adaptation, and trust. Boin and van Eeten’s distinction between precursor resilience and recovery resilience is especially important because it shows why many public capacities remain invisible until they fail [
8]. A recent meta-narrative review from Public Administration Review further emphasizes the increasing centrality of resilience in public administration under environmental complexity and uncertainty [
35].
The governance literature emphasizes institutional diversity and multilevel coordination. Duit et al. argue that resilience governance requires attention to complexity, institutional arrangements, and the politics of adaptation [
25]. Public entities rarely control all assets and actors on which services depend. Water utilities, electric utilities, ports, hospitals, emergency management agencies, school systems, transportation agencies, private contractors, state regulators, federal grant programs, insurers, and bond markets may all shape service continuity. A resilience report that lists only internal projects therefore leaves a major part of preparedness undisclosed.
Critical infrastructure research explains why dependency disclosure is essential. Rinaldi et al. classify interdependencies among infrastructure systems as physical, cyber, geographic, and logical, showing how one infrastructure disruption may cascade into another [
36]. Ouyang’s review of interdependent critical infrastructure systems documents a wide range of modeling approaches and emphasizes that interdependency changes both vulnerability and recovery dynamics [
37]. The OECD similarly treats critical infrastructure resilience as a governance problem involving coordination, investment incentives, ownership arrangements, and risk-sharing across sectors [
38].
A reporting standard should therefore shift the unit of analysis from individual assets to essential public services and the systems supporting them. A pump station, road segment, emergency facility, or seawall has reporting value only in relation to the service it protects, the populations served, the acceptable downtime, the dependencies required for operation, the residual risk after investment, and the alternatives available when the asset fails. This service-centered orientation is the core of PSRRS-SYS.
Empirical work on local climate adaptation planning reinforces this concern. Studies of municipal adaptation plans find wide variation in plan quality, monitoring, implementation, and equity attention [
39,
40,
41]. Adaptation plans often identify hazards and projects more effectively than they establish finance, implementation authority, monitoring, and evaluation. The gap between planning and operational capacity is therefore not limited to one jurisdiction. It reflects a broader challenge in translating resilience ambition into auditable governance evidence.
2.3. Deep Uncertainty, Catastrophic Risk, and Decision Use
Decision-making under deep uncertainty (DMDU) offers a third foundation. Deep uncertainty exists when decision-makers do not know, or do not agree on, the models describing a system, the probability distributions of key variables, or the values attached to outcomes [
42,
43]. Robust decision-making evaluates strategies across many plausible futures rather than optimizing for a single forecast [
42]. Dynamic Adaptive Policy Pathways identify sequences of actions, monitor signposts, and shift pathways when adaptation tipping points are reached [
44].
These methods imply reporting requirements. A public entity should disclose not only a planning assumption, but also the range of plausible conditions considered, the confidence basis, the signposts monitored, the threshold at which a strategy no longer meets public objectives, the contingent action prepared, the lead time needed, the financing source, and the authority responsible for acting. Without those elements, a plan described as adaptive may be only rhetorically flexible.
Catastrophic-risk economics also supports the need for caution in ordinary decision models. Weitzman argues that catastrophic climate uncertainty challenges conventional cost–benefit analysis because fat-tailed uncertainty and model limits make simplified policy conclusions fragile [
45]. This does not mean that every catastrophic scenario dictates immediate maximum expenditure. It means that reporting should disclose how institutional systems handle model limits, tail risk, and uncertainty over consequences. In public-sector settings, the users of this information include fiscal authorities, auditors, emergency managers, insurers, municipal bond investors, credit-rating analysts, utility regulators, infrastructure planners, grant administrators, legislators, residents, and intergovernmental partners.
Public finance and asset-pricing research supplies a further decision-use channel. Painter finds that counties more exposed to climate change pay higher underwriting fees and initial yields for long-maturity municipal bonds, with the effect concentrated among lower-rated bonds [
46]. Goldsmith-Pinkham et al. find that sea-level-rise exposure began to be priced in municipal bond yields after 2013, especially for longer maturities, and that uncertainty contributes to the premium [
47]. Mishra et al. argue that physical climate risk creates challenges and opportunities for U.S. municipal finance because municipal debt finances essential infrastructure while climate exposure, insurance retreat, property values, and tax bases interact [
48]. Research on investor sentiment and salient events offers a related mechanism: sports outcomes and high-salience cultural events may affect market attention, mood, and returns [
49,
50]. These studies do not make the manuscript a finance paper. They justify treating resilience disclosure as decision-useful information for bond pricing, insurance access, capital sequencing, reserve policy, grant allocation, infrastructure financing, and public confidence before a disruptive event becomes fully observable.
The PSRRS therefore treats disclosure as a decision-use instrument. A report that identifies residual service risk, unfunded adaptation pathways, loss of insurance availability, deferred maintenance, or untested dependencies provides information relevant to budgeting, pricing, procurement, capital planning, and oversight. A report that lists projects without those connections supports accountability only in a limited sense.
2.4. Rationale for the Quadruple Bottom Line and a Theory of Reporting-Standard Elaboration
The Quadruple Bottom Line (QBL) is used as the normative structure because public-sector resilience is not adequately represented by economic, environmental, or social dimensions alone. The QBL adds governance as a fourth dimension that binds the other three through authority, accountability, transparency, participation, monitoring, and enforcement [
51,
52]. Public value is produced when economic stewardship, social protection, ecological integrity, and governance legitimacy reinforce one another. A resilience standard requires this architecture because systemic disruption often begins in one dimension and cascades across the others.
Alternative frameworks are useful but less directly suited to the standard-building objective of this article. Public-value theory clarifies the normative purpose of public action, but it does not by itself specify reporting clauses, evidence requirements, or conformity assessment. Adaptive governance explains learning and flexibility, but it does not supply a reporting index or assurance model. DMDU provides methods for scenario and pathway analysis, but it does not define public-sector disclosure responsibilities. ISO management-system standards specify processes but are not designed as public-facing integrated reports. The QBL is therefore selected not because these frameworks are irrelevant, but because it offers a standards-oriented bridge from normative public purposes to operational disclosure modules.
The five PSRRS modules form a reporting chain rather than a list. PSRRS-GOV asks who is responsible and how authority is exercised. PSRRS-STR asks what future conditions are being addressed and how strategies change across pathways. PSRRS-SYS asks which essential services, dependencies, and failure pathways are material. PSRRS-MET asks what resources, indicators, fiscal exposures, and distributional consequences are disclosed. PSRRS-ASS asks how claims are verified, revised, and improved. The logic is sequential and recursive: responsible governance defines scenarios; scenarios identify service risks; service risks determine metrics and resources; assurance tests whether capacities exist; learning revises governance and strategy. This chain is the core conceptual proposition of the article and supplies the theoretical warrant for the architecture depicted later in
Figure 1.
The relationship between the QBL and the five PSRRS modules is direct. The governance dimension of QBL is operationalized primarily through PSRRS-GOV and PSRRS-ASS, which require accountable ownership, oversight, verification, and learning. The economic dimension is operationalized through PSRRS-MET and PSRRS-STR, which require disclosure of resources, contingent finance, lifecycle costs, fiscal exposure, and pathway choices. The environmental dimension is operationalized through PSRRS-STR and PSRRS-SYS, which connect scenarios, ecological functions, physical hazards, dependencies, and service continuity. The social dimension is operationalized through PSRRS-SYS and PSRRS-MET, which require disclosure of essential services, vulnerable populations, residual risk, participation, and distributional burdens. The modules therefore translate QBL from a normative frame into a disclosure architecture with assigned authority, auditable evidence, and recursive assurance.
The theoretical contribution extends beyond selecting five reporting modules. This article proposes a capability-to-disclosure translation model for elaborating public-sector reporting standards. The model contains four moves. Normative translation identifies the public values, duties, and materiality thresholds that create a legitimate disclosure claim. Capability translation identifies the latent institutional capacities required to protect those values under disruption. Evidentiary translation converts those capacities into observable disclosures, documentation, indicators, and decision rules. Recursive translation uses assurance, exercises, corrective action, and learning to revise the preceding three layers. A proposed standard is theoretically underdeveloped when any one of these translations is missing: values without capabilities remain aspirational; capabilities without evidence remain opaque; evidence without assurance remains unverifiable; and assurance without learning becomes static compliance [
53].
The PSRRS operationalizes this model in a specific domain. QBL and public-value reasoning establish the normative boundary; resilience governance, critical-infrastructure interdependency, and DMDU specify the relevant capacities; the PSRRS clauses and indicators provide evidentiary translation; and PSRRS-ASS closes the recursive loop. The model therefore explains how a reporting standard may be elaborated from theory rather than assembled as an arbitrary checklist. Its portability beyond resilience remains a proposition for future research, but the logic is potentially relevant to other public-sector domains in which latent institutional capacity must be converted into auditable disclosure.
3. Materials and Methods
3.1. Research Questions and Design
This study has three bounded objectives. The diagnostic objective is to examine whether existing sustainability, resilience, continuity, risk, and public-sector planning frameworks disclose the institutional capabilities required for LPHI systemic risks. The theoretical-constructive objective is to translate identified gaps and public-value obligations into a capability-to-disclosure architecture with draft clauses, evidence requirements, indicators, a reporting index, and conformity tiers. The illustrative objective is to apply the architecture to Florida and two stress-test domains without treating one jurisdiction as a representative sample of governments generally.
Four research questions guide the analysis:
RQ1: What reporting elements remain insufficiently specified across existing public-sector sustainability, resilience, continuity, and risk frameworks for LPHI systemic risks?
RQ2: To what extent does Florida’s resilience architecture disclose preparedness for systemic risks under deep uncertainty?
RQ3: What auditable requirements follow from the identified cross-framework gaps and the proposed capability-to-disclosure translation logic?
RQ4: How should conformity assessment distinguish disclosure presence, operational integration, and resilience outcomes?
The research design combines conceptual framework development with qualitative documentary analysis. The analytical sequence is cross-framework diagnosis, theoretical translation, draft-clause construction, illustrative Florida application, and stress testing. This design is appropriate when a governance problem is emerging across several standards families and the research objective is to synthesize those materials into a testable architecture rather than to estimate causal effects or population parameters. The proposed architecture is therefore derived from the international standards and scholarly corpus as a whole; Florida is used only for illustrative application under RQ2. The coding results should be read as structured interpretive analysis, not as neutral measurement produced by independent coders or as evidence of cross-jurisdictional prevalence.
3.2. Documentary Corpus and Selection
The corpus was selected to represent the reporting, resilience, continuity, infrastructure, and case-specific materials directly relevant to the research questions. The standards corpus includes public-sector sustainability reporting, investor-oriented sustainability disclosure, impact reporting, community indicators, organizational resilience, continuity management, risk management, conformity assessment, and disaster-resilience self-assessment instruments. The Florida corpus includes current statewide resilience planning and critical-asset data materials. The AMOC corpus includes authoritative assessment and peer-reviewed studies representing both elevated concern and more conservative interpretations. The literature corpus includes public administration resilience, critical infrastructure interdependency, deep uncertainty, catastrophic-risk economics, investor attention, and empirical adaptation planning. The unit of evidence for RQ1 and RQ3 is the wider standards and literature corpus; the Florida documents constitute one illustrative application for RQ2 rather than the empirical foundation for universal standard claims. The documentary corpus and its analytical role are summarized in
Table 1.
The corpus was not selected to be exhaustive. It was selected to represent the major standards families and case materials necessary for the proposed reporting architecture. Full copyrighted ISO standards are not reproduced, and the study does not claim a clause-by-clause legal interpretation of the proprietary ISO text where full standards were not part of the public corpus. The ISO-related analysis relies on publicly stated scopes, abstracts, known standard functions, cited requirements where publicly available, and scholarly interpretation. ISO classifications were therefore coded conservatively: a dimension was treated as explicit only when a public source or cited literature clearly supported that classification. This boundary is stated because the objective is to identify disclosure gaps across standards families, not to reproduce proprietary standards text.
3.3. Coding Protocol and Codebook Logic
Each framework was coded across nine dimensions: (1) governance responsibility; (2) materiality or risk boundary; (3) multiple scenarios and time horizons; (4) cascading dependencies; (5) essential-service continuity; (6) adaptive triggers and policy pathways; (7) fiscal and resource capacity; (8) equity and distributional effects; (9) assurance, verification, or conformity assessment. Coverage was classified as explicit (E), partial (P), or not explicit (N). Explicit coverage required a stated requirement, defined method, operational indicator, or required disclosure. Partial coverage indicated relevance without a complete or integrated disclosure requirement. Not explicit indicated that the element was outside the framework’s principal scope or not identifiable in the reviewed material.
The coding is functional rather than evaluative. A classification of partial or not explicit does not mean that a framework fails within its intended purpose. IFRS S2 is not a municipal continuity standard; ISO 22301 is not a public sustainability report; UNDRR self-assessment is not an audited financial disclosure framework. The comparison identifies the interoperability gap that emerges when governments rely on several frameworks without a common resilience-reporting layer.
The nine coding dimensions were not produced in a single circular step. Six dimensions were specified before the documentary analysis from the study’s resilience-materiality proposition and the prior literature on public administration resilience, critical infrastructure interdependency, continuity management, and DMDU: governance responsibility; materiality or risk boundary; multiple scenarios and time horizons; cascading dependencies; essential-service continuity; and fiscal and resource capacity. Three dimensions were refined during the documentary review because they recurred as under-specified disclosure problems across the corpus: adaptive triggers and policy pathways; equity and distributional effects; and assurance, verification, or conformity assessment. After this refinement, the nine-dimension codebook was fixed before the Florida coding and stress-test application. The PSRRS modules were then constructed by grouping the final dimensions into a capability-to-disclosure architecture, rather than by treating the coding dimensions as proof of the standard’s validity.
Appendix A provides the codebook, including examples of explicit, partial, and not explicit classifications. The study does not report Cohen’s kappa because the corpus was not independently coded by two researchers; inter-rater reliability remains a future validation requirement rather than completed work.
3.4. Florida Case and Stress-Test Protocol
Florida’s resilience architecture was analyzed in two steps. First, the analysis identified reporting strengths: statutory continuity, statewide assessment, critical-asset identification, project eligibility, ranking, project metrics, cost sharing, nature-based solutions, public engagement, and attention to disadvantaged communities. Second, the analysis assessed whether the reviewed documents disclose the five capacities of the PSRRS chain: accountable governance, scenario/pathway strategy, systemic dependencies and essential-service continuity, metrics/resources/equity, and assurance/learning/revision. Each Florida judgment followed a bounded evidence chain: documentary content, observable reporting feature, coding judgment, and limited inference. A gap was recorded only when an integrated disclosure corresponding to the predefined dimension was not visible in the reviewed corpus. Such a finding does not establish that the underlying operational capability is absent elsewhere in state agencies, utilities, emergency systems, or unpublished internal processes.
The AMOC stress test was applied through five questions. Signal: Does the reporting system identify and disclose emerging systemic signals whose probability remains uncertain? Translation: Does it translate those signals into Florida-relevant service, infrastructure, fiscal, ecological, and social consequences? Coordination: Does it identify cross-sector and cross-jurisdictional dependencies and accountable decision authorities? Adaptation: Does it specify signposts, thresholds, contingent pathways, lead times, and funding? Disclosure: Would an external user understand readiness, limitations, and unresolved vulnerabilities?
A second stress-test domain, a cyber-fiscal disruption, was added to demonstrate hazard neutrality through documented experience rather than a purely hypothetical scenario. The domain draws on real-world ransomware and cyber-disruption evidence involving state and local governments, including federal assessments of ransomware impacts on state, local, tribal, and territorial entities [
19], Atlanta’s 2018 municipal ransomware disruption [
20], Baltimore’s 2019 ransomware recovery and water-billing disruptions [
21,
22], and research documenting social, operational, and financial harms from ransomware incidents [
23]. The stress test abstracts from those cases to ask how a ransomware attack, prolonged digital-service outage, utility billing disruption, emergency communication failure, vendor-payment delay, or fiscal liquidity shock would be disclosed under PSRRS. It tests the same reporting architecture without relying on climate science or AMOC-specific assumptions.
3.5. Validation Boundaries and Limitations of the Method
The method supports analytical replication through a stated corpus, coding dimensions, three-value coding scale, case criteria, stress-test protocol, and codebook. Another researcher could apply the same protocol to a different state, country, infrastructure sector, or systemic-risk scenario. The intended generalization is analytical rather than statistical: the study proposes concepts, disclosure dimensions, and testable relationships that may travel across settings, but it does not estimate how often the identified Florida gaps occur elsewhere. Construct validity is strengthened by triangulation across reporting, ISO, UNDRR, public-administration, infrastructure, DMDU, climate-disclosure, and finance literature.
The method has six limitations. First, the coding was conducted by a single researcher and remains interpretive. Second, the Florida case is illustrative rather than statistically representative and does not support universal claims about other regions or countries. Third, absence of an integrated disclosure in the reviewed Florida corpus should not be equated with absence of an operational capability outside that corpus. Fourth, the AMOC stress test evaluates institutional visibility rather than physical impacts or probabilities. Fifth, the proposed clauses and indicators have not been tested for cost, user burden, inter-rater reliability, cross-jurisdictional applicability, or predictive validity. Sixth, formal standardization would require field pilots, public consultation, technical committee deliberation, assurance testing, and revision. These limitations do not defeat the article’s contribution; they define the evidentiary boundary and the next stage of development.
5. Proposed Public-Sector Resilience Reporting Standard
5.1. Purpose, Scope, and Normative Language
The purpose of the PSRRS is to enable governments and public-sector entities to disclose comparable, decision-useful, and auditable information about preparedness for disruptive conditions that may materially impair essential services, public value, ecological functions, fiscal stability, or equitable protection. The standard is hazard-neutral. It applies to environmental, technological, fiscal, public-health, cyber, supply-chain, geopolitical, and compound risks when their consequences may become systemic.
The PSRRS is designed as an interoperable overlay rather than a replacement for existing systems. Entities should cross-reference IPSASB, GRI, IFRS-derived jurisdictional requirements, ISO management systems, UNDRR assessments, emergency plans, capital plans, financial reports, and statutory resilience plans when those sources satisfy a disclosure requirement. Cross-referencing reduces duplication, but the reporting entity remains responsible for completeness, consistency, accessibility, and clear statement of omissions.
To address standardization concerns, the PSRRS uses three levels of normative language. “Shall” identifies mandatory disclosures required for a PSRRS alignment claim. “Should” identifies recommended disclosures expected unless the entity explains why they are not applicable, not material, or not yet feasible. “May” identifies optional or advanced disclosures appropriate for higher-capacity entities, sensitive sectors, or Tier 3 assurance. The same clause numbering and normative status are used in
Table 6, as well as in
Appendix B and
Appendix C. This distinction clarifies that the PSRRS is a draft standard architecture and not only an academic recommendation, while also preserving proportionality for smaller entities.
Figure 1 is not intended as an arbitrary taxonomy of desirable topics. Each module is derived from a distinct theoretical and analytical requirement identified in the preceding sections and comparative corpus. PSRRS-GOV follows from public-value accountability and the need to assign authority. PSRRS-STR follows from DMDU and adaptive-pathway theory, which require multiple futures, signposts, triggers, and contingent decisions. PSRRS-SYS follows from resilience governance, continuity management, and critical-infrastructure interdependency, which shift attention from isolated assets to essential services and cascading dependencies. PSRRS-MET follows from resilience materiality, fiscal stewardship, outcome measurement, and distributional protection. PSRRS-ASS follows from organizational learning, conformity assessment, and the need to distinguish documentary presence from operational effectiveness. The central node—public-value and essential-service resilience—identifies the normative object protected by the architecture; the connections among modules represent dependence and feedback rather than a simple linear sequence.
Six principles govern application: (1) resilience materiality; (2) public-value orientation; (3) systemic interdependency; (4) multiple time horizons; (5) adaptive readiness; (6) proportionality with comparability. Resilience materiality requires disclosure of plausible conditions that may impair essential functions even when probability is not reliably quantifiable. Public-value orientation connects preparedness to services, rights, ecological systems, fiscal stewardship, and distributional protection. Systemic interdependency requires dependencies, common-mode failures, and cascading effects. Multiple time horizons distinguish operational, strategic, and intergenerational exposure. Adaptive readiness requires signposts, triggers, contingent pathways, authority, lead time, and financing. Proportionality permits scaled evidence while preserving a common minimum disclosure set. Together, these principles explain why no single module is sufficient: governance without scenarios leaves change unassigned; scenarios without service dependencies do not identify what fails; metrics without resource and equity information obscure feasibility and burden; and disclosures without assurance do not establish reliability.
Scope inclusion criteria discipline the treatment of LPHI risks. A risk should enter the PSRRS reporting scope when five criteria are sufficiently present: (1) plausible evidence exists from authoritative science, official risk assessment, comparable events, or credible expert judgment; (2) the potential impact could materially impair essential services, statutory duties, public finances, ecological systems, or equitable protection; (3) the entity has jurisdictional exposure through territory, infrastructure, population, supply chain, fiscal position, or delegated service responsibility; (4) the decision lead time is long enough that monitoring, contingency planning, financing, procurement, or adaptation choices remain meaningful; (5) at least one mitigation, preparedness, transfer, monitoring, or adaptive pathway is available for disclosure. A risk should normally remain outside the detailed PSRRS scope when it is speculative, has no plausible jurisdictional exposure, offers no decision-useful action, or would create only theatrical disclosure. Exclusions should be briefly explained in the disclosure index when the risk is salient enough that users would reasonably expect the entity to consider it.
5.2. Minimum Disclosure Architecture
The PSRRS architecture consists of five linked modules. PSRRS-GOV establishes who is responsible for resilience disclosure, how governing bodies exercise oversight, how cross-functional responsibilities are assigned, and how emerging systemic risks are escalated. PSRRS-STR requires the entity to explain how resilience affects strategy across multiple time horizons, including scenarios, assumptions, confidence, signposts, adaptation thresholds, contingent actions, lead times, and financing. PSRRS-SYS shifts reporting from assets to essential services, minimum service levels, tolerable downtime, recovery objectives, dependencies, single points of failure, common-mode vulnerabilities, and cascading effects. PSRRS-MET reports resources, fiscal exposure, funding gaps, service outcomes, residual risk, and distributional effects. PSRRS-ASS requires data provenance, quality controls, internal or external review, exercises, after-action learning, corrective-action closure, and revision of scenarios and pathways.
The minimum architecture is deliberately selective. It does not require every entity to model all dependencies quantitatively, purchase advanced software, or perform external assurance in the first cycle. It requires a disciplined baseline: name the accountable authority; identify material essential services; describe plausible scenarios and time horizons; screen dependencies; disclose core metrics and resources; report residual risk and distributional effects; explain limitations; and describe how evidence will be verified and improved. Higher tiers deepen rather than replace the baseline.
5.3. Operational Clauses and Evidence Requirements
The clauses are cumulative. GOV-1 and GOV-2 make the reporting owner and cross-functional responsibilities visible. STR-1 and STR-3 connect future uncertainty to decisions. SYS-1 and SYS-2 identify essential services and continuity objectives. SYS-3 and SYS-4 identify dependencies, cascades, and residual service risk. MET-1 and MET-3 reveal whether the strategy is resourced and who remains exposed. ASS-1, ASS-3, and ASS-4 determine whether disclosure claims rest on reliable methods, internal controls, and appropriate assurance. The “should” and “may” clauses preserve proportionality while identifying the maturity path for Tier 2 and Tier 3 pilot alignment.
5.4. Reporting Index and Sample Structure
An entity claiming PSRRS alignment shall publish a disclosure index identifying the location of each requirement, the reporting boundary, the period covered, omissions, reasons for omission, sensitive-information limitations, and planned remediation. The index should distinguish “prepared with reference to PSRRS” from formal conformity. A public entity should not claim conformity when material modules are excluded without an authorized scope limitation.
A concise resilience profile should precede detailed evidence. The profile should identify material essential services; top systemic dependencies; principal scenarios; unresolved high-consequence vulnerabilities; adaptation triggers; current and contingent financing; populations facing residual risk; exercise and assurance status; and changes since the previous period. This profile provides decision-makers, residents, investors, auditors, insurers, infrastructure partners, and oversight bodies with a navigable summary while detailed evidence remains available through annexes or cross-references. The proposed report structure is summarized in
Table 7.
5.5. Conformity, Assurance, and Implementation
Conformity assessment follows the logic of ISO/IEC 17000, under which specified requirements are evaluated through structured evidence [
57]. The PSRRS model uses three cumulative tiers. The tiers are proposed as a roadmap for future standardization rather than as a validated certification regime. The permitted claims in
Table 8 therefore use “prepared with reference” and “pilot alignment” language, not final certification language. Future pilots should test whether the clauses are applied with acceptable reliability across entities before any formal conformity or certification claim is authorized.
Implementation should be phased. In the first cycle, a resource-constrained local government could prepare a Tier 1 disclosure by using existing plans, budgets, vulnerability assessments, emergency operations materials, capital improvement programs, insurance records, and service inventories. The first cycle should prioritize essential-service identification, accountability, known dependencies, core metrics, limitations, and a remediation plan. In the second cycle, entities should validate dependency maps, connect pathways to budgets, formalize triggers, and complete tabletop exercises. Independent assurance should follow only after data definitions, controls, and evidence expectations become stable enough for reliable review.
Costs and burdens are real. Smaller governments may lack GIS staff, grant writers, internal auditors, continuity planners, cyber specialists, or fiscal analysts. The PSRRS therefore uses proportionality, cross-referencing, tiers, and qualitative evidence where quantitative models are unavailable. State agencies, regional planning councils, water management districts, universities, insurers, professional associations, and federal grant programs could support templates, shared data, technical assistance, and pooled assurance. Adoption incentives may include grant eligibility, bond-market credibility, insurance access, legislative oversight, public trust, and reduced duplication across reporting systems.
Political feasibility also matters. Some actors may support PSRRS because it improves transparency, investment discipline, and fiscal stewardship. Others may resist it because it reveals unfunded liabilities, service vulnerabilities, distributional inequities, or dependence on outside actors. The standard should therefore avoid partisan framing and focus on continuity, essential services, public finance, risk management, and accountable stewardship. This framing is particularly appropriate for Florida, where resilience language, flood planning, infrastructure protection, critical assets, and public finance already provide administrative entry points.
6. Discussion
6.1. Theoretical and Standards Contributions
The study advances resilience scholarship by defining resilience reporting as a distinct governance function. Resilience has often been treated as a property, process, strategy, or outcome. Reporting adds a second-order capacity: the ability of an institution to make preparedness claims visible, comparable, contestable, and correctable. An organization may possess some resilience without reporting it, and it may report resilience without possessing it. A standard narrows that gap.
The concept of resilience materiality extends sustainability reporting into the public-value domain. Financial materiality asks whether information affects economic decisions by investors, lenders, or other financial users. Impact materiality asks whether the organization significantly affects people, the environment, or the economy. Resilience materiality asks whether omitted information obscures the capacity to sustain essential public functions, statutory obligations, fiscal stability, ecological integrity, and equitable protection under plausible disruptive conditions. The three materiality lenses overlap but are not identical.
The PSRRS also clarifies the relationship between standards families. IPSASB and sustainability disclosure standards provide accountability architecture; GRI provides impact orientation; ISO 371xx standards provide community indicators; ISO 223xx standards provide resilience and continuity management; ISO 31000 provides risk-management logic; ISO/IEC 17000 provides conformity-assessment vocabulary; UNDRR provides city resilience self-assessment; DMDU provides adaptive pathways. PSRRS translates these inputs into a public-sector resilience disclosure layer.
The principal theoretical contribution is the capability-to-disclosure translation model. Existing reporting approaches often begin with material topics, indicators, risks, or impacts. Resilience reporting faces a different epistemic problem: the most consequential object is frequently a latent institutional capacity that becomes observable only through evidence of authority, redundancy, decision thresholds, resources, exercises, corrective action, and service outcomes. The model therefore theorizes standard elaboration as a sequence of translations from normative obligation to capability, from capability to evidence, and from evidence to recursively assured learning. This explains why the mere presence of a plan, metric, or project is an incomplete proxy for preparedness.
The model also identifies four predictable failure modes in reporting-standard design. Normative aspiration without capability specification produces broad commitments that are difficult to evaluate. Capability language without evidentiary rules produces untestable claims. Evidence without assurance leaves users unable to distinguish documentation from operational effectiveness. Assurance without a learning loop converts resilience into static compliance. PSRRS addresses these failure modes by linking QBL and resilience materiality to the five capability modules, draft clauses, evidence requirements, conformity tiers, and revision processes. In this sense, the article contributes not only a proposed resilience instrument but also a theoretically explicit account of how a public-sector reporting standard may be elaborated from public values into auditable institutional claims.
6.2. Decision-Use Channels and Political Economy
A clearer decision-use channel strengthens the article’s relevance beyond public administration. Municipal bond investors may use PSRRS information to assess long-term capital maintenance, contingent liabilities, and service reliability because climate exposure and sea-level-rise risk have already been linked to municipal bond yields, underwriting costs, maturity effects, ratings, and uncertainty premia [
46,
47]. Recent municipal-finance research also emphasizes that physical climate risk affects infrastructure, insurance, property values, and local tax bases in ways directly relevant to credit quality and capital access [
48]. Insurers may use PSRRS information to evaluate risk controls, exposure reduction, and residual vulnerability. Fiscal authorities may use it to set reserves, prioritize capital plans, or identify grant needs. Auditors may use it to examine controls over resilience claims and data quality. Utility regulators and infrastructure planners may use it to coordinate investments across dependent systems. Residents and community organizations may use it to understand who receives protection and who remains exposed.
The political economy of adoption is mixed. PSRRS creates value by making hidden dependencies, funding gaps, and residual risk visible before disruptions occur. It also creates discomfort because those same disclosures may expose deferred maintenance, unfunded mandates, fragmented authority, or unequal protection. Adoption therefore requires incentives, legal authority, professional norms, and staged implementation. A phased model allows governments to begin with existing evidence rather than wait for perfect models.
Florida illustrates this balance. The state already maintains a substantial resilience planning and data architecture. A PSRRS layer would not require a new climate-policy identity. It would ask the state and participating local governments to disclose how existing data, projects, plans, fiscal resources, continuity objectives, and accountability mechanisms fit together. The AMOC stress test would be reported as one uncertainty stress test, not as a prediction. The cyber-fiscal stress test shows that the same architecture protects against non-climate disruption.
6.3. Jurisdictional Applicability, Feasibility, and Future Validation
The PSRRS is not proposed as a universal legal requirement for every government, and this study does not establish that any country is obligated to adopt it. Applicability should follow institutional conditions rather than geography alone. The strongest case arises where four conditions coincide: essential public services depend on interdependent systems; resilience information is fragmented across plans, budgets, agencies, utilities, and reporting regimes; disruptive conditions involve material uncertainty or cascading consequences; and public entities bear territorial, fiscal, or statutory responsibility for continuity. Global variation in adaptation governance and the cross-sector character of critical-infrastructure resilience support a contextual rather than one-size-fits-all approach [
38,
61].
Table 9 identifies four jurisdictional archetypes in which pilot use would be especially defensible. The examples are illustrative contexts, not claims of current legal necessity or empirical proof of PSRRS effectiveness. Jurisdictions adopting or aligning with public-sector climate disclosure frameworks such as IPSASB SRS 1 could use PSRRS as a resilience-specific overlay, while lower-capacity jurisdictions could begin with a proportionate Tier 1 profile and shared technical assistance [
1,
61].
The typology also clarifies the limits of generalization from Florida. Florida illustrates one federated, coastal, subnational context with a mature statutory program, but it does not validate the architecture for the other archetypes. The purpose of
Table 9 is to identify falsifiable next-stage settings for comparative pilots. A credible validation program should test whether the same disclosure dimensions are understandable, feasible, and decision-useful across at least one jurisdiction from each archetype before any claim of broad standard applicability is made.
Standardization has risks. A rigid checklist may encourage minimum compliance and suppress local knowledge. Quantification may privilege measurable infrastructure over social trust, informal capacity, administrative judgment, and community relationships. Scenario disclosure may be misunderstood as prediction. Public release of dependency information may create security concerns. Assurance may become expensive or formalistic. These risks require careful design.
The proposed design addresses those concerns through proportionality, tiered conformity, qualitative evidence where quantitative methods are unavailable, explicit uncertainty disclosure, protected annexes for sensitive details, and mandatory reporting of capacity limitations. Standards should create disciplined comparability without erasing contextual judgment. The PSRRS therefore emphasizes minimum architecture, disclosure of limitations, cross-references to existing systems, and staged assurance.
Future research should proceed in five directions. First, a Delphi or technical-committee process should refine the clauses with public managers, auditors, emergency professionals, infrastructure operators, fiscal officers, community representatives, insurers, and standard-setting experts. Second, at least two independent coders should apply the codebook to a larger standards and case corpus, with inter-rater reliability reported. Third, field pilots should test costs, burden, data availability, and usability across small, medium, and large governments. Fourth, assurance pilots should test whether reviewers apply conformity tiers consistently. Fifth, longitudinal studies should examine whether higher PSRRS maturity is associated with improved corrective-action closure, reduced service disruption, better capital maintenance, lower fiscal volatility, or more equitable resilience outcomes.
7. Conclusions
Public-sector sustainability reporting is entering a new phase, yet transparent reporting of systemic preparedness remains underdeveloped. Existing frameworks disclose important elements of governance, risk, impacts, indicators, continuity, and assessment, while the comparative corpus analyzed here does not reveal one integrated public-sector reporting architecture that connects LPHI systemic risk, essential-service continuity, adaptive triggers, resources, equity, and assurance under deep uncertainty.
This article proposes a Public-Sector Resilience Reporting Standard organized around five modules: governance and accountability; strategy, scenarios, and adaptive pathways; systemic risk and essential-service continuity; metrics, resources, and equity; and assurance, learning, and revision. The theoretical contribution is a capability-to-disclosure translation model that explains how normative public-value obligations may be converted into capability domains, evidentiary requirements, and recursive assurance. The PSRRS operationalizes that logic as a pre-standard architecture with mandatory, recommended, and optional clauses; evidence requirements; indicators; a disclosure index; a sample report structure; and a three-tier conformity model.
Florida’s resilience architecture provides an illustrative application rather than a basis for universal generalization. The reviewed corpus contains strong statutory, data, asset, project, and funding foundations [
9,
10,
11], while integrated disclosure of systemic dependencies, adaptive triggers, long-horizon fiscal exposures, residual service risks, distributional effects, and preparedness assurance remains partial. The AMOC and cyber-fiscal stress tests demonstrate hazard-neutral analytical use, but they do not validate PSRRS across countries, regions, or institutional systems.
Table 9 therefore identifies candidate jurisdictional archetypes for comparative piloting rather than asserting a universal requirement.
The ultimate standard of resilience is not whether government anticipated one specific event. It is whether governance systems remain prepared to protect public value when the future departs from the planning assumption. Reporting should make that preparedness visible before disruption occurs, while future cross-jurisdictional pilots determine where, how, and at what proportional level the proposed architecture is genuinely useful.