Next Article in Journal
Beyond Optimization: Legaliform (Law-like) Principles and Bounded Rationality in Lithic Technology
Previous Article in Journal
Study on the Kinetics of Vitamin U Release from a Cosmetic Formulation
 
 
Font Type:
Arial Georgia Verdana
Font Size:
Aa Aa Aa
Line Spacing:
Column Width:
Background:
Article

Toward a Public-Sector Resilience Reporting Standard for Low-Probability, High-Impact Systemic Risks: A Pre-Standard Architecture for Government Preparedness Under Deep Uncertainty

Department of Business Administration, Lewis Bear Jr. College of Business, University of West Florida, Pensacola, FL 32514, USA
Standards 2026, 6(3), 28; https://doi.org/10.3390/standards6030028
Submission received: 21 June 2026 / Revised: 20 July 2026 / Accepted: 23 July 2026 / Published: 28 July 2026
(This article belongs to the Special Issue Sustainability Reporting Standards for the Public Sector)

Abstract

Public-sector sustainability and climate reporting increasingly address environmental exposure, governance, and financial effects, yet existing frameworks do not adequately disclose preparedness for low-probability, high-impact systemic risks whose probabilities, timing, thresholds, and transmission channels remain deeply uncertain. This article develops a Public-Sector Resilience Reporting Standard (PSRRS) as a pre-standard architecture for government preparedness disclosure. The design has three bounded objectives: diagnose cross-framework disclosure gaps, translate these gaps into a theoretically grounded capability-to-disclosure architecture, and demonstrate its analytical use through an illustrative Florida application and two hazard-neutral stress tests. The documentary corpus includes international sustainability and public-sector reporting standards, ISO and UNDRR resilience and continuity instruments, three Florida resilience documents, and peer-reviewed literature on resilience governance, decision-making under deep uncertainty, critical infrastructure interdependency, catastrophic uncertainty, climate-risk disclosure, public finance, climate-risk pricing, local-government credit risk, investor attention, and ransomware service disruption. A structured interpretive coding protocol classifies each framework as explicit, partial, or not explicit across nine disclosure dimensions; a codebook appendix identifies the assessment criteria, the a priori and inductively refined dimensions, and the validation boundaries. Florida is not treated as a basis for statistical or jurisdictional generalization. Instead, it illustrates how a comparatively developed resilience architecture may disclose statutory continuity, critical-asset data, project ranking, and output metrics while leaving systemic dependencies, adaptive triggers, long-horizon fiscal exposure, residual service risk, distributional effects, and assurance mechanisms insufficiently visible in the reviewed reporting corpus. AMOC and case-grounded cyber-fiscal stress tests show how the PSRRS shifts reporting from hazard inventories and funded projects toward auditable evidence of institutional capacity, adaptive readiness, and public-value protection. The article specifies mandatory, recommended, and optional clauses, evidence requirements, indicator examples, a disclosure index, a sample report structure, and a three-tier pilot conformity model. The contribution is conceptual and operational, but not yet a validated formal standard; cross-jurisdictional piloting, inter-rater coding, cost testing, assurance testing, and stakeholder consultation are identified as the next stage of standardization.

1. Introduction

Public institutions do more than manage their own organizational footprints. They maintain drinking-water systems, transportation networks, emergency operations, health protection, land-use controls, public finance, public safety, permitting, public works, social services, and the legal and administrative arrangements through which communities absorb disruption. Failure in this setting differs from failure in a private organization because essential services, statutory duties, territorial equity, fiscal stability, ecological stewardship, and democratic accountability may be impaired at the same time. Public-sector sustainability reporting therefore requires a broader theory of preparedness than ordinary organizational disclosure.
Reporting architecture is entering an important period of institutional change. The International Public Sector Accounting Standards Board issued IPSASB SRS 1, Climate-related Disclosures, in 2026, with application to general-purpose financial reports for annual reporting periods beginning on or after 1 January 2028, with earlier adoption permitted [1]. IFRS S1 and IFRS S2 organize sustainability and climate disclosure around governance, strategy, risk management, and metrics and targets [2,3]. The Global Reporting Initiative (GRI) Standards permit public and private organizations to report impacts on the economy, environment, and people [4]. The Task Force on Climate-related Financial Disclosures (TCFD) established a decision-useful framework organized around the same four pillars and oriented toward forward-looking information in mainstream reporting [5]. These frameworks strengthen transparency, comparability, and accountability. Their principal disclosure logics, however, remain grounded in identifiable risks, entity-level exposure, reporting periods, and material information for specified users. They offer less direct guidance for risks whose probabilities, thresholds, timing, transmission mechanisms, and public-service consequences are not stable enough to fit ordinary risk registers or expected-value calculations.
The central argument is that public-sector resilience reporting should disclose not only whether risks exist, but whether the government has the capacity to maintain essential public services and correct course under disruptive conditions. Conventional reporting often shows funded projects, hazard exposure, completed assessments, and compliance activities. Those outputs matter, but they do not necessarily reveal whether governing bodies sense emerging signals, translate them into service implications, mobilize cross-sector authority, shift among pathways, finance contingent action, protect vulnerable populations, and learn from exercises or events. A government may appear prepared because it has many resilience projects, while its adaptive decision system, dependency mapping, fiscal reserves, continuity objectives, and assurance mechanisms remain opaque.
This distinction is especially important for low-probability, high-impact (LPHI) systemic risks. LPHI conditions may be rare, contested, hard to quantify, or temporally distant, yet their consequences may include cascading infrastructure failure, fiscal stress, service interruption, loss of insurability, displacement, ecological damage, or erosion of public trust. Resilience originated as the capacity of a system to absorb disturbance without losing its defining functions [6], and later expanded to include adaptation, learning, and transformation in social–ecological systems [7]. Public-management research similarly distinguishes recovery after an event from precursor resilience, meaning the ability to detect and correct latent vulnerabilities before failure [8]. Reporting that emphasizes exposure and project completion alone misses this precursor capacity.
Florida offers an analytically useful case because its Resilient Florida architecture is substantial, statutory, data-driven, and recurring. The state’s resilience materials include statewide flooding and sea-level-rise planning, critical asset data, local vulnerability assessment requirements, project eligibility rules, scoring criteria, grant funding, and public reporting [9,10,11,12]. These features make Florida a comparatively developed subnational resilience architecture for the limited purpose of this study. The case therefore serves as a demanding illustrative application of the proposed reporting logic; it is not treated as a statistically representative case or as a basis for claiming that the same gaps occur with equal significance in other jurisdictions.
The Atlantic Meridional Overturning Circulation (AMOC) is used as one stress-test scenario, not as a deterministic forecast. Scientific assessments agree that the AMOC is very likely to weaken during the twenty-first century, while the magnitude, timing, and possibility of abrupt collapse remain debated [13,14,15,16,17,18]. For the purposes of this article, the policy question is not whether a particular collapse date should be reported. The question is whether a public-sector resilience report would disclose how emerging, contested, and potentially systemic scientific information is monitored, translated into public-service consequences, connected to adaptive triggers, financed, coordinated, and reviewed. A second stress-test domain, a case-grounded cyber-fiscal disruption affecting essential services and municipal finance, is added to show that the proposed standard is hazard-neutral rather than climate-specific [19,20,21,22,23].
This article makes six contributions. First, it defines resilience materiality as a public-sector reporting principle based on potential impairment of essential services, statutory obligations, public finances, ecological systems, or distributional protection, rather than probability or financial materiality alone. Second, it reorganizes the standards literature around three debates: risk management versus resilience governance, indicator disclosure versus capability disclosure, and financial materiality versus public-value materiality. Third, it develops a theoretical model of reporting-standard elaboration through four translation moves: normative boundary-setting, capability specification, evidentiary operationalization, and recursive assurance and learning. Fourth, it develops a structured interpretive coding protocol and codebook for comparing standards, guidance, and governmental documents. Fifth, it operationalizes the Public-Sector Resilience Reporting Standard (PSRRS) through mandatory, recommended, and optional clauses, evidence requirements, indicator examples, and a disclosure index. Sixth, it proposes a staged conformity model that distinguishes disclosure presence, operational integration, and externally assured adaptive resilience.
The article is intentionally framed as a pre-standard architecture rather than as a completed international standard. This framing addresses the evidentiary boundary of the study. The PSRRS is developed to a draft-clause level sufficient for academic scrutiny and pilot application, but its formal standardization would require stakeholder consultation, inter-rater validation, field testing, cost assessment, cross-jurisdictional comparison, and iterative revision. The objective is to provide a credible architecture for that next stage and to identify why current public-sector reporting may leave essential preparedness information hidden.
The study objectives are therefore deliberately bounded. The first objective is diagnostic: to identify disclosure gaps that emerge across a broader corpus of reporting, resilience, continuity, risk, and adaptation frameworks. The second is theoretical and constructive: to explain how public-value obligations may be translated into auditable capability disclosures and then into a coherent pre-standard architecture. The third is illustrative: to apply that architecture to Florida and to two stress-test scenarios in order to examine whether the proposed categories expose information that project- and hazard-centered reporting may leave invisible. The architecture is not derived from Florida alone, and the Florida case is not used to estimate the prevalence of reporting gaps across countries or regions. Claims of transferability are therefore analytical propositions for future testing, not empirical findings of this single-case application.
The paper proceeds as follows. Section 2 develops the literature and conceptual foundations. Section 3 explains the research design, corpus, coding protocol, Florida case logic, stress-test protocol, and validation boundaries. Section 4 presents the comparative findings, Florida coding results, AMOC stress test, and cyber-fiscal stress test. Section 5 specifies the PSRRS clauses, evidence requirements, indicators, reporting index, sample structure, conformity tiers, assurance logic, and implementation sequence. Section 6 discusses the theoretical contribution, decision-use channels, political economy, feasibility, and limitations. Section 7 concludes. Appendix A, Appendix B and Appendix C provide the codebook, draft clauses, and sample report structure.

2. Literature Review and Conceptual Foundations

2.1. Three Reporting Debates: Risk, Capability, and Public-Value Materiality

The literature and standards landscape is best understood through three debates rather than through a catalog of instruments. The first debate concerns risk management versus resilience governance. ISO 31000 treats risk management as coordinated activities to direct and control an organization with regard to risk [24]. This logic is valuable because public entities need systematic identification, analysis, evaluation, treatment, monitoring, and communication. Resilience governance asks a further question: how does the public system perform when knowledge is incomplete, events propagate across systems, or the initiating disruption changes during the response? Risk management organizes knowledge about threats; resilience governance organizes institutional capacity under surprise, ambiguity, and cascade [8,25,26,27].
The second debate concerns indicator disclosure versus capability disclosure. ISO 37120, ISO 37123, and ISO 37125 provide city-service, resilient-city, and ESG indicators for communities [28,29,30]. Indicators support benchmarking and comparability. The UNDRR Disaster Resilience Scorecard and Climate Resilience Addendum also support structured assessment of local resilience capacity [31,32]. Yet a high-quality indicator set does not necessarily disclose whether an institution has authority, resources, triggers, redundancy, cross-sector agreements, exercise evidence, or corrective-action closure. Indicator reporting measures attributes, outputs, or outcomes; capability disclosure explains whether the public entity is prepared to act under changing conditions. The PSRRS treats indicators as necessary but insufficient.
The third debate concerns financial materiality versus public-value materiality. IFRS S1 and IFRS S2 focus on sustainability-related risks and opportunities likely to affect an entity’s prospects [2,3]. TCFD similarly emphasizes decision-useful climate-related information for financial filings [5]. IPSASB SRS 1 adapts climate disclosure for public-sector general-purpose financial reports and explicitly serves accountability and decision-making [1]. These are major advances. Public-sector resilience, however, also depends on material effects that may not be adequately expressed as investor-relevant financial information. A low-confidence scenario may not generate a credible expected value, yet it may threaten emergency response, drinking-water reliability, wastewater treatment, public health, public safety, housing stability, ecological function, or intergenerational fiscal capacity.
This article defines resilience materiality as follows: information is resilience-material when its omission, misstatement, or obscuration could reasonably prevent users from understanding whether a public entity is prepared to maintain, adaptively restore, or transform essential services, statutory obligations, public-value outcomes, ecological functions, fiscal stability, or equitable protection under plausible disruptive conditions. This definition is intentionally disciplined. It does not require disclosure of every imaginable catastrophe. The condition must be plausible, decision-relevant, and linked to public function, service continuity, fiscal exposure, systemic dependency, or distributional consequences. The definition therefore protects against both under-disclosure and performative over-disclosure.
Public-sector sustainability reporting research supports this extension. Sustainability accounting and reporting have been linked to public-value co-creation and multi-actor accountability [33]. Structured reviews of nonfinancial reporting in public organizations show diverse formats, uneven practices, and incomplete integration [34]. The problem is not only technical inconsistency. Fragmentation separates budgets from risk, infrastructure from equity, emergency management from sustainability, and strategic commitments from assurance evidence. Systemic disruptions do not respect those reporting boundaries. A resilience standard should reconnect them.

2.2. Public Administration Resilience and Critical Infrastructure Interdependency

Public administration scholarship provides a second foundation. Resilience in public organizations concerns more than recovery speed. It includes institutional memory, cross-boundary coordination, professional competence, learning, redundancy, discretion, adaptation, and trust. Boin and van Eeten’s distinction between precursor resilience and recovery resilience is especially important because it shows why many public capacities remain invisible until they fail [8]. A recent meta-narrative review from Public Administration Review further emphasizes the increasing centrality of resilience in public administration under environmental complexity and uncertainty [35].
The governance literature emphasizes institutional diversity and multilevel coordination. Duit et al. argue that resilience governance requires attention to complexity, institutional arrangements, and the politics of adaptation [25]. Public entities rarely control all assets and actors on which services depend. Water utilities, electric utilities, ports, hospitals, emergency management agencies, school systems, transportation agencies, private contractors, state regulators, federal grant programs, insurers, and bond markets may all shape service continuity. A resilience report that lists only internal projects therefore leaves a major part of preparedness undisclosed.
Critical infrastructure research explains why dependency disclosure is essential. Rinaldi et al. classify interdependencies among infrastructure systems as physical, cyber, geographic, and logical, showing how one infrastructure disruption may cascade into another [36]. Ouyang’s review of interdependent critical infrastructure systems documents a wide range of modeling approaches and emphasizes that interdependency changes both vulnerability and recovery dynamics [37]. The OECD similarly treats critical infrastructure resilience as a governance problem involving coordination, investment incentives, ownership arrangements, and risk-sharing across sectors [38].
A reporting standard should therefore shift the unit of analysis from individual assets to essential public services and the systems supporting them. A pump station, road segment, emergency facility, or seawall has reporting value only in relation to the service it protects, the populations served, the acceptable downtime, the dependencies required for operation, the residual risk after investment, and the alternatives available when the asset fails. This service-centered orientation is the core of PSRRS-SYS.
Empirical work on local climate adaptation planning reinforces this concern. Studies of municipal adaptation plans find wide variation in plan quality, monitoring, implementation, and equity attention [39,40,41]. Adaptation plans often identify hazards and projects more effectively than they establish finance, implementation authority, monitoring, and evaluation. The gap between planning and operational capacity is therefore not limited to one jurisdiction. It reflects a broader challenge in translating resilience ambition into auditable governance evidence.

2.3. Deep Uncertainty, Catastrophic Risk, and Decision Use

Decision-making under deep uncertainty (DMDU) offers a third foundation. Deep uncertainty exists when decision-makers do not know, or do not agree on, the models describing a system, the probability distributions of key variables, or the values attached to outcomes [42,43]. Robust decision-making evaluates strategies across many plausible futures rather than optimizing for a single forecast [42]. Dynamic Adaptive Policy Pathways identify sequences of actions, monitor signposts, and shift pathways when adaptation tipping points are reached [44].
These methods imply reporting requirements. A public entity should disclose not only a planning assumption, but also the range of plausible conditions considered, the confidence basis, the signposts monitored, the threshold at which a strategy no longer meets public objectives, the contingent action prepared, the lead time needed, the financing source, and the authority responsible for acting. Without those elements, a plan described as adaptive may be only rhetorically flexible.
Catastrophic-risk economics also supports the need for caution in ordinary decision models. Weitzman argues that catastrophic climate uncertainty challenges conventional cost–benefit analysis because fat-tailed uncertainty and model limits make simplified policy conclusions fragile [45]. This does not mean that every catastrophic scenario dictates immediate maximum expenditure. It means that reporting should disclose how institutional systems handle model limits, tail risk, and uncertainty over consequences. In public-sector settings, the users of this information include fiscal authorities, auditors, emergency managers, insurers, municipal bond investors, credit-rating analysts, utility regulators, infrastructure planners, grant administrators, legislators, residents, and intergovernmental partners.
Public finance and asset-pricing research supplies a further decision-use channel. Painter finds that counties more exposed to climate change pay higher underwriting fees and initial yields for long-maturity municipal bonds, with the effect concentrated among lower-rated bonds [46]. Goldsmith-Pinkham et al. find that sea-level-rise exposure began to be priced in municipal bond yields after 2013, especially for longer maturities, and that uncertainty contributes to the premium [47]. Mishra et al. argue that physical climate risk creates challenges and opportunities for U.S. municipal finance because municipal debt finances essential infrastructure while climate exposure, insurance retreat, property values, and tax bases interact [48]. Research on investor sentiment and salient events offers a related mechanism: sports outcomes and high-salience cultural events may affect market attention, mood, and returns [49,50]. These studies do not make the manuscript a finance paper. They justify treating resilience disclosure as decision-useful information for bond pricing, insurance access, capital sequencing, reserve policy, grant allocation, infrastructure financing, and public confidence before a disruptive event becomes fully observable.
The PSRRS therefore treats disclosure as a decision-use instrument. A report that identifies residual service risk, unfunded adaptation pathways, loss of insurance availability, deferred maintenance, or untested dependencies provides information relevant to budgeting, pricing, procurement, capital planning, and oversight. A report that lists projects without those connections supports accountability only in a limited sense.

2.4. Rationale for the Quadruple Bottom Line and a Theory of Reporting-Standard Elaboration

The Quadruple Bottom Line (QBL) is used as the normative structure because public-sector resilience is not adequately represented by economic, environmental, or social dimensions alone. The QBL adds governance as a fourth dimension that binds the other three through authority, accountability, transparency, participation, monitoring, and enforcement [51,52]. Public value is produced when economic stewardship, social protection, ecological integrity, and governance legitimacy reinforce one another. A resilience standard requires this architecture because systemic disruption often begins in one dimension and cascades across the others.
Alternative frameworks are useful but less directly suited to the standard-building objective of this article. Public-value theory clarifies the normative purpose of public action, but it does not by itself specify reporting clauses, evidence requirements, or conformity assessment. Adaptive governance explains learning and flexibility, but it does not supply a reporting index or assurance model. DMDU provides methods for scenario and pathway analysis, but it does not define public-sector disclosure responsibilities. ISO management-system standards specify processes but are not designed as public-facing integrated reports. The QBL is therefore selected not because these frameworks are irrelevant, but because it offers a standards-oriented bridge from normative public purposes to operational disclosure modules.
The five PSRRS modules form a reporting chain rather than a list. PSRRS-GOV asks who is responsible and how authority is exercised. PSRRS-STR asks what future conditions are being addressed and how strategies change across pathways. PSRRS-SYS asks which essential services, dependencies, and failure pathways are material. PSRRS-MET asks what resources, indicators, fiscal exposures, and distributional consequences are disclosed. PSRRS-ASS asks how claims are verified, revised, and improved. The logic is sequential and recursive: responsible governance defines scenarios; scenarios identify service risks; service risks determine metrics and resources; assurance tests whether capacities exist; learning revises governance and strategy. This chain is the core conceptual proposition of the article and supplies the theoretical warrant for the architecture depicted later in Figure 1.
The relationship between the QBL and the five PSRRS modules is direct. The governance dimension of QBL is operationalized primarily through PSRRS-GOV and PSRRS-ASS, which require accountable ownership, oversight, verification, and learning. The economic dimension is operationalized through PSRRS-MET and PSRRS-STR, which require disclosure of resources, contingent finance, lifecycle costs, fiscal exposure, and pathway choices. The environmental dimension is operationalized through PSRRS-STR and PSRRS-SYS, which connect scenarios, ecological functions, physical hazards, dependencies, and service continuity. The social dimension is operationalized through PSRRS-SYS and PSRRS-MET, which require disclosure of essential services, vulnerable populations, residual risk, participation, and distributional burdens. The modules therefore translate QBL from a normative frame into a disclosure architecture with assigned authority, auditable evidence, and recursive assurance.
The theoretical contribution extends beyond selecting five reporting modules. This article proposes a capability-to-disclosure translation model for elaborating public-sector reporting standards. The model contains four moves. Normative translation identifies the public values, duties, and materiality thresholds that create a legitimate disclosure claim. Capability translation identifies the latent institutional capacities required to protect those values under disruption. Evidentiary translation converts those capacities into observable disclosures, documentation, indicators, and decision rules. Recursive translation uses assurance, exercises, corrective action, and learning to revise the preceding three layers. A proposed standard is theoretically underdeveloped when any one of these translations is missing: values without capabilities remain aspirational; capabilities without evidence remain opaque; evidence without assurance remains unverifiable; and assurance without learning becomes static compliance [53].
The PSRRS operationalizes this model in a specific domain. QBL and public-value reasoning establish the normative boundary; resilience governance, critical-infrastructure interdependency, and DMDU specify the relevant capacities; the PSRRS clauses and indicators provide evidentiary translation; and PSRRS-ASS closes the recursive loop. The model therefore explains how a reporting standard may be elaborated from theory rather than assembled as an arbitrary checklist. Its portability beyond resilience remains a proposition for future research, but the logic is potentially relevant to other public-sector domains in which latent institutional capacity must be converted into auditable disclosure.

3. Materials and Methods

3.1. Research Questions and Design

This study has three bounded objectives. The diagnostic objective is to examine whether existing sustainability, resilience, continuity, risk, and public-sector planning frameworks disclose the institutional capabilities required for LPHI systemic risks. The theoretical-constructive objective is to translate identified gaps and public-value obligations into a capability-to-disclosure architecture with draft clauses, evidence requirements, indicators, a reporting index, and conformity tiers. The illustrative objective is to apply the architecture to Florida and two stress-test domains without treating one jurisdiction as a representative sample of governments generally.
Four research questions guide the analysis:
RQ1: What reporting elements remain insufficiently specified across existing public-sector sustainability, resilience, continuity, and risk frameworks for LPHI systemic risks?
RQ2: To what extent does Florida’s resilience architecture disclose preparedness for systemic risks under deep uncertainty?
RQ3: What auditable requirements follow from the identified cross-framework gaps and the proposed capability-to-disclosure translation logic?
RQ4: How should conformity assessment distinguish disclosure presence, operational integration, and resilience outcomes?
The research design combines conceptual framework development with qualitative documentary analysis. The analytical sequence is cross-framework diagnosis, theoretical translation, draft-clause construction, illustrative Florida application, and stress testing. This design is appropriate when a governance problem is emerging across several standards families and the research objective is to synthesize those materials into a testable architecture rather than to estimate causal effects or population parameters. The proposed architecture is therefore derived from the international standards and scholarly corpus as a whole; Florida is used only for illustrative application under RQ2. The coding results should be read as structured interpretive analysis, not as neutral measurement produced by independent coders or as evidence of cross-jurisdictional prevalence.

3.2. Documentary Corpus and Selection

The corpus was selected to represent the reporting, resilience, continuity, infrastructure, and case-specific materials directly relevant to the research questions. The standards corpus includes public-sector sustainability reporting, investor-oriented sustainability disclosure, impact reporting, community indicators, organizational resilience, continuity management, risk management, conformity assessment, and disaster-resilience self-assessment instruments. The Florida corpus includes current statewide resilience planning and critical-asset data materials. The AMOC corpus includes authoritative assessment and peer-reviewed studies representing both elevated concern and more conservative interpretations. The literature corpus includes public administration resilience, critical infrastructure interdependency, deep uncertainty, catastrophic-risk economics, investor attention, and empirical adaptation planning. The unit of evidence for RQ1 and RQ3 is the wider standards and literature corpus; the Florida documents constitute one illustrative application for RQ2 rather than the empirical foundation for universal standard claims. The documentary corpus and its analytical role are summarized in Table 1.
The corpus was not selected to be exhaustive. It was selected to represent the major standards families and case materials necessary for the proposed reporting architecture. Full copyrighted ISO standards are not reproduced, and the study does not claim a clause-by-clause legal interpretation of the proprietary ISO text where full standards were not part of the public corpus. The ISO-related analysis relies on publicly stated scopes, abstracts, known standard functions, cited requirements where publicly available, and scholarly interpretation. ISO classifications were therefore coded conservatively: a dimension was treated as explicit only when a public source or cited literature clearly supported that classification. This boundary is stated because the objective is to identify disclosure gaps across standards families, not to reproduce proprietary standards text.

3.3. Coding Protocol and Codebook Logic

Each framework was coded across nine dimensions: (1) governance responsibility; (2) materiality or risk boundary; (3) multiple scenarios and time horizons; (4) cascading dependencies; (5) essential-service continuity; (6) adaptive triggers and policy pathways; (7) fiscal and resource capacity; (8) equity and distributional effects; (9) assurance, verification, or conformity assessment. Coverage was classified as explicit (E), partial (P), or not explicit (N). Explicit coverage required a stated requirement, defined method, operational indicator, or required disclosure. Partial coverage indicated relevance without a complete or integrated disclosure requirement. Not explicit indicated that the element was outside the framework’s principal scope or not identifiable in the reviewed material.
The coding is functional rather than evaluative. A classification of partial or not explicit does not mean that a framework fails within its intended purpose. IFRS S2 is not a municipal continuity standard; ISO 22301 is not a public sustainability report; UNDRR self-assessment is not an audited financial disclosure framework. The comparison identifies the interoperability gap that emerges when governments rely on several frameworks without a common resilience-reporting layer.
The nine coding dimensions were not produced in a single circular step. Six dimensions were specified before the documentary analysis from the study’s resilience-materiality proposition and the prior literature on public administration resilience, critical infrastructure interdependency, continuity management, and DMDU: governance responsibility; materiality or risk boundary; multiple scenarios and time horizons; cascading dependencies; essential-service continuity; and fiscal and resource capacity. Three dimensions were refined during the documentary review because they recurred as under-specified disclosure problems across the corpus: adaptive triggers and policy pathways; equity and distributional effects; and assurance, verification, or conformity assessment. After this refinement, the nine-dimension codebook was fixed before the Florida coding and stress-test application. The PSRRS modules were then constructed by grouping the final dimensions into a capability-to-disclosure architecture, rather than by treating the coding dimensions as proof of the standard’s validity. Appendix A provides the codebook, including examples of explicit, partial, and not explicit classifications. The study does not report Cohen’s kappa because the corpus was not independently coded by two researchers; inter-rater reliability remains a future validation requirement rather than completed work.

3.4. Florida Case and Stress-Test Protocol

Florida’s resilience architecture was analyzed in two steps. First, the analysis identified reporting strengths: statutory continuity, statewide assessment, critical-asset identification, project eligibility, ranking, project metrics, cost sharing, nature-based solutions, public engagement, and attention to disadvantaged communities. Second, the analysis assessed whether the reviewed documents disclose the five capacities of the PSRRS chain: accountable governance, scenario/pathway strategy, systemic dependencies and essential-service continuity, metrics/resources/equity, and assurance/learning/revision. Each Florida judgment followed a bounded evidence chain: documentary content, observable reporting feature, coding judgment, and limited inference. A gap was recorded only when an integrated disclosure corresponding to the predefined dimension was not visible in the reviewed corpus. Such a finding does not establish that the underlying operational capability is absent elsewhere in state agencies, utilities, emergency systems, or unpublished internal processes.
The AMOC stress test was applied through five questions. Signal: Does the reporting system identify and disclose emerging systemic signals whose probability remains uncertain? Translation: Does it translate those signals into Florida-relevant service, infrastructure, fiscal, ecological, and social consequences? Coordination: Does it identify cross-sector and cross-jurisdictional dependencies and accountable decision authorities? Adaptation: Does it specify signposts, thresholds, contingent pathways, lead times, and funding? Disclosure: Would an external user understand readiness, limitations, and unresolved vulnerabilities?
A second stress-test domain, a cyber-fiscal disruption, was added to demonstrate hazard neutrality through documented experience rather than a purely hypothetical scenario. The domain draws on real-world ransomware and cyber-disruption evidence involving state and local governments, including federal assessments of ransomware impacts on state, local, tribal, and territorial entities [19], Atlanta’s 2018 municipal ransomware disruption [20], Baltimore’s 2019 ransomware recovery and water-billing disruptions [21,22], and research documenting social, operational, and financial harms from ransomware incidents [23]. The stress test abstracts from those cases to ask how a ransomware attack, prolonged digital-service outage, utility billing disruption, emergency communication failure, vendor-payment delay, or fiscal liquidity shock would be disclosed under PSRRS. It tests the same reporting architecture without relying on climate science or AMOC-specific assumptions.

3.5. Validation Boundaries and Limitations of the Method

The method supports analytical replication through a stated corpus, coding dimensions, three-value coding scale, case criteria, stress-test protocol, and codebook. Another researcher could apply the same protocol to a different state, country, infrastructure sector, or systemic-risk scenario. The intended generalization is analytical rather than statistical: the study proposes concepts, disclosure dimensions, and testable relationships that may travel across settings, but it does not estimate how often the identified Florida gaps occur elsewhere. Construct validity is strengthened by triangulation across reporting, ISO, UNDRR, public-administration, infrastructure, DMDU, climate-disclosure, and finance literature.
The method has six limitations. First, the coding was conducted by a single researcher and remains interpretive. Second, the Florida case is illustrative rather than statistically representative and does not support universal claims about other regions or countries. Third, absence of an integrated disclosure in the reviewed Florida corpus should not be equated with absence of an operational capability outside that corpus. Fourth, the AMOC stress test evaluates institutional visibility rather than physical impacts or probabilities. Fifth, the proposed clauses and indicators have not been tested for cost, user burden, inter-rater reliability, cross-jurisdictional applicability, or predictive validity. Sixth, formal standardization would require field pilots, public consultation, technical committee deliberation, assurance testing, and revision. These limitations do not defeat the article’s contribution; they define the evidentiary boundary and the next stage of development.

4. Results

4.1. Comparative Standards and Reporting Gap

The comparative analysis shows that no reviewed framework integrates all nine resilience-reporting dimensions into a public-facing, auditable disclosure architecture. Reporting standards are strongest on governance, strategy, risk, materiality, and metrics. City and resilience standards are strongest on indicator definition, community baselines, and self-assessment. Continuity and organizational-resilience standards are strongest on preparedness and recovery processes. DMDU methods are strongest on scenarios, signposts, triggers, and adaptive pathways. Critical infrastructure literature is strongest on dependencies and cascading failures. The missing function is integration. The comparative findings are summarized in Table 2.
Four cross-framework findings follow. First, governance is widely addressed, but responsibility for integrated systemic-risk disclosure is rarely assigned. A finance office may own annual reporting, an emergency-management agency may own operational planning, a resilience office may own adaptation, and utilities may own continuity. Without a designated reporting authority, important information remains institutionally dispersed.
Second, scenarios are increasingly recognized, but scenario disclosure often lacks adaptive decision architecture. A high, medium, and low scenario does not tell users what the entity will do differently, when it will act, who has authority, what funding is available, or which pathway remains feasible. Scenario analysis and adaptive pathways should therefore be distinguished.
Third, systemic dependencies are acknowledged unevenly. Continuity and disaster-resilience instruments recognize dependencies more directly than sustainability reports, but public disclosures rarely identify cross-sector cascades in a decision-useful format. A wastewater system depends on electricity, fuel, chemicals, transport access, communications, workforce, financial liquidity, receiving waters, and emergency contracting. Asset-by-asset reporting understates this risk.
Fourth, assurance is fragmented. Financial and sustainability reporting increasingly use external assurance, while management-system standards support conformity assessment. Resilience claims are often based on plan existence or project completion. The analysis identifies a need to verify whether triggers, exercises, data, authorities, dependencies, and contingent resources function as reported.

4.2. Florida Case Evidence

Florida’s resilience architecture contains advanced features. The Resilient Florida Program is statutory and recurring rather than ad hoc. The Statewide Plan uses a three-year project horizon, ranks eligible projects, links projects to flooding or sea-level-rise risks identified in vulnerability assessments, and includes coastal and inland communities [9]. The 2026–2027 plan reports a broad project portfolio spanning flood control, wastewater, drinking water, emergency facilities, land acquisition, natural resources, and living shorelines. It also collects project-cost, match, location, asset, task, and output-metric information.
The statewide assessment architecture improves consistency. DEP compiled critical-asset information from state, federal, regional, and local sources and linked this information to vulnerability assessments [10,11]. This reduces a common problem in decentralized resilience programs: incomparable local baselines. The project-ranking process also contains elements relevant to public value, including regional significance, community need, nature-based solutions, innovation, readiness, and reduced cost-share eligibility. These features make Florida an appropriate foundation for a reporting standard because many raw materials for PSRRS already exist. The resulting strengths and gaps are summarized in Table 3.
The Florida case demonstrates a practical point: PSRRS does not require a government to discard existing systems. Florida already has statutory authority, project data, geospatial information, vulnerability assessment materials, and ranking criteria [9,10,11]. The reviewed corpus, however, does not integrate those materials into a single public account of capability. The bounded reporting questions are therefore: Which essential services are protected? What service interruption remains acceptable? Which dependencies are unresolved? What observed condition changes the pathway? Who acts? What is funded? Who remains exposed? What evidence verifies readiness? These are disclosure questions about the reviewed documents, not assertions that Florida lacks every underlying capacity to answer them.
The governance judgment is supported by a specific distinction between assigned program responsibility and integrated disclosure responsibility. The Statewide Plan identifies DEP’s statutory planning, project-ranking, and program-administration functions [9], while the reviewed documents do not designate one reporting owner responsible for presenting systemwide preparedness across finance, emergency management, utilities, transportation, insurance, local government, and other interdependent actors [9,10,11]. The coded gap is therefore integrated reporting ownership, not an absence of agency responsibility.
The strategy and systemic-risk judgments follow the same evidence rule. The Statewide Plan provides a recurring three-year project horizon and links projects to flood and sea-level-rise vulnerability evidence [9], but it does not use a standardized disclosure field for signposts, adaptation thresholds, pathway switching, or pre-authorized contingent actions. The statewide critical-asset and vulnerability materials identify infrastructure categories and exposed assets [10,11], yet the reviewed corpus does not consistently report service-level dependency maps, common-mode failures, tolerable downtime, or cross-sector cascade pathways. These findings justify a partial or not-explicit coding only within the documentary boundary of the study.
The metrics and assurance judgments are similarly documentary. Florida’s materials report project costs, matching funds, locations, assets, tasks, and physical outputs [9], but those fields do not consistently disclose residual service risk, distributional outcomes, lifecycle maintenance burden, or long-horizon fiscal exposure. Recurring plans and datasets support procedural accountability [9,10,11], while integrated publication of exercise results, corrective-action closure, trigger testing, or independent operational-effectiveness assurance is not visible in the reviewed reporting corpus. This evidence chain converts the Florida analysis from a general impression into a bounded comparison between predefined disclosure requirements and observable documentary content.

4.3. AMOC Disruption Stress Test

The AMOC case illustrates the difference between a contested scientific scenario and an unreportable scenario. The IPCC assesses that AMOC weakening during the twenty-first century is very likely, while abrupt collapse before 2100 is assessed with medium confidence not to occur [13]. The subsequent literature remains contested. Ditlevsen and Ditlevsen report statistical early-warning evidence consistent with the possibility of a forthcoming collapse [14], while Baker et al. find continued overturning in a set of extreme-forcing model experiments [15]. Bonan et al. use observational constraints to narrow projected weakening and conclude that future decline may be more limited than some model projections [16]. Studies on U.S. East Coast sea level and Gulf Stream transport caution against simple local translation from basin-scale circulation changes to a specific coastal water-level outcome [17,18].
The reporting implication is not that Florida should state an expected collapse. It is that a mature resilience report should disclose how authoritative evidence is monitored, when assumptions are reviewed, how uncertainty is translated into service consequences, and which adaptive pathways remain available. The AMOC stress test asks whether Florida’s existing reporting architecture would make those institutional capacities visible. The implications in Table 4 are therefore conditional deductions from a defined mismatch: each stress-test question specifies information needed for adaptive preparedness disclosure, and the Florida corpus is then examined for observable evidence of that information. They are not forecasts of physical outcomes or declarations about undisclosed internal capacities.
The stress test supports the article’s central proposition within the stated documentary boundary. Florida’s reviewed architecture is comparatively strong on data, assets, funding, and recurring project reporting [9,10,11]. It is weaker on public disclosure of signal governance, cross-system translation, adaptive triggers, contingent financing, residual service risk, and integrated assurance. This conclusion follows from the absence of standardized fields or integrated disclosures addressing those functions in the reviewed documents; it does not establish that no agency possesses relevant internal procedures. An AMOC scenario would likely enter the existing reporting architecture indirectly through revised flood or sea-level assumptions, yet the reviewed materials do not clearly show who decides that a scientific change becomes resilience-material, how rapidly planning assumptions are revised, which dependencies are reprioritized, or what contingent actions are prepared if conditions depart from the current planning basis.

4.4. Second Stress Test: Cyber-Fiscal Service Disruption

The second stress test demonstrates hazard-neutral application through a case-grounded cyber-fiscal domain. Local-government ransomware incidents show that cyber disruption is not only an information-technology problem; it may impair courts, permitting, utility billing, public communications, procurement, records access, emergency workarounds, and financial administration. The City of Atlanta publicly reported a 2018 ransomware event that disabled applications and required restoration measures [20]. Baltimore’s 2019 ransomware attack required manual workarounds and disrupted services, including water-billing functions and employee access to systems [21,22]. GAO reports similarly identify ransomware as a threat to state, local, tribal, and territorial government operations and services [19]. The scenario in Table 5 is therefore a structured abstraction from documented cyber-fiscal disruptions rather than a free-standing hypothetical example.
This second scenario reinforces the generality of the PSRRS architecture. Climate-related hazards, cyber disruptions, fiscal shocks, public-health crises, supply-chain failures, and geopolitical disturbances differ in cause, but they share reporting needs: responsible authority, scenario range, service dependencies, resources, distributional consequences, adaptive triggers, and assurance. The cyber-fiscal evidence also shows why the PSRRS should disclose both technical controls and service consequences. Ransomware harms may emerge through delayed public services, inaccessible records, payment disruption, staff burden, reputational damage, unplanned recovery costs, insurance limitations, and unequal effects on residents who depend on in-person or digitally mediated services [19,20,21,22,23].

5. Proposed Public-Sector Resilience Reporting Standard

5.1. Purpose, Scope, and Normative Language

The purpose of the PSRRS is to enable governments and public-sector entities to disclose comparable, decision-useful, and auditable information about preparedness for disruptive conditions that may materially impair essential services, public value, ecological functions, fiscal stability, or equitable protection. The standard is hazard-neutral. It applies to environmental, technological, fiscal, public-health, cyber, supply-chain, geopolitical, and compound risks when their consequences may become systemic.
The PSRRS is designed as an interoperable overlay rather than a replacement for existing systems. Entities should cross-reference IPSASB, GRI, IFRS-derived jurisdictional requirements, ISO management systems, UNDRR assessments, emergency plans, capital plans, financial reports, and statutory resilience plans when those sources satisfy a disclosure requirement. Cross-referencing reduces duplication, but the reporting entity remains responsible for completeness, consistency, accessibility, and clear statement of omissions.
To address standardization concerns, the PSRRS uses three levels of normative language. “Shall” identifies mandatory disclosures required for a PSRRS alignment claim. “Should” identifies recommended disclosures expected unless the entity explains why they are not applicable, not material, or not yet feasible. “May” identifies optional or advanced disclosures appropriate for higher-capacity entities, sensitive sectors, or Tier 3 assurance. The same clause numbering and normative status are used in Table 6, as well as in Appendix B and Appendix C. This distinction clarifies that the PSRRS is a draft standard architecture and not only an academic recommendation, while also preserving proportionality for smaller entities.
Figure 1 is not intended as an arbitrary taxonomy of desirable topics. Each module is derived from a distinct theoretical and analytical requirement identified in the preceding sections and comparative corpus. PSRRS-GOV follows from public-value accountability and the need to assign authority. PSRRS-STR follows from DMDU and adaptive-pathway theory, which require multiple futures, signposts, triggers, and contingent decisions. PSRRS-SYS follows from resilience governance, continuity management, and critical-infrastructure interdependency, which shift attention from isolated assets to essential services and cascading dependencies. PSRRS-MET follows from resilience materiality, fiscal stewardship, outcome measurement, and distributional protection. PSRRS-ASS follows from organizational learning, conformity assessment, and the need to distinguish documentary presence from operational effectiveness. The central node—public-value and essential-service resilience—identifies the normative object protected by the architecture; the connections among modules represent dependence and feedback rather than a simple linear sequence.
Six principles govern application: (1) resilience materiality; (2) public-value orientation; (3) systemic interdependency; (4) multiple time horizons; (5) adaptive readiness; (6) proportionality with comparability. Resilience materiality requires disclosure of plausible conditions that may impair essential functions even when probability is not reliably quantifiable. Public-value orientation connects preparedness to services, rights, ecological systems, fiscal stewardship, and distributional protection. Systemic interdependency requires dependencies, common-mode failures, and cascading effects. Multiple time horizons distinguish operational, strategic, and intergenerational exposure. Adaptive readiness requires signposts, triggers, contingent pathways, authority, lead time, and financing. Proportionality permits scaled evidence while preserving a common minimum disclosure set. Together, these principles explain why no single module is sufficient: governance without scenarios leaves change unassigned; scenarios without service dependencies do not identify what fails; metrics without resource and equity information obscure feasibility and burden; and disclosures without assurance do not establish reliability.
Scope inclusion criteria discipline the treatment of LPHI risks. A risk should enter the PSRRS reporting scope when five criteria are sufficiently present: (1) plausible evidence exists from authoritative science, official risk assessment, comparable events, or credible expert judgment; (2) the potential impact could materially impair essential services, statutory duties, public finances, ecological systems, or equitable protection; (3) the entity has jurisdictional exposure through territory, infrastructure, population, supply chain, fiscal position, or delegated service responsibility; (4) the decision lead time is long enough that monitoring, contingency planning, financing, procurement, or adaptation choices remain meaningful; (5) at least one mitigation, preparedness, transfer, monitoring, or adaptive pathway is available for disclosure. A risk should normally remain outside the detailed PSRRS scope when it is speculative, has no plausible jurisdictional exposure, offers no decision-useful action, or would create only theatrical disclosure. Exclusions should be briefly explained in the disclosure index when the risk is salient enough that users would reasonably expect the entity to consider it.

5.2. Minimum Disclosure Architecture

The PSRRS architecture consists of five linked modules. PSRRS-GOV establishes who is responsible for resilience disclosure, how governing bodies exercise oversight, how cross-functional responsibilities are assigned, and how emerging systemic risks are escalated. PSRRS-STR requires the entity to explain how resilience affects strategy across multiple time horizons, including scenarios, assumptions, confidence, signposts, adaptation thresholds, contingent actions, lead times, and financing. PSRRS-SYS shifts reporting from assets to essential services, minimum service levels, tolerable downtime, recovery objectives, dependencies, single points of failure, common-mode vulnerabilities, and cascading effects. PSRRS-MET reports resources, fiscal exposure, funding gaps, service outcomes, residual risk, and distributional effects. PSRRS-ASS requires data provenance, quality controls, internal or external review, exercises, after-action learning, corrective-action closure, and revision of scenarios and pathways.
The minimum architecture is deliberately selective. It does not require every entity to model all dependencies quantitatively, purchase advanced software, or perform external assurance in the first cycle. It requires a disciplined baseline: name the accountable authority; identify material essential services; describe plausible scenarios and time horizons; screen dependencies; disclose core metrics and resources; report residual risk and distributional effects; explain limitations; and describe how evidence will be verified and improved. Higher tiers deepen rather than replace the baseline.

5.3. Operational Clauses and Evidence Requirements

The clauses are cumulative. GOV-1 and GOV-2 make the reporting owner and cross-functional responsibilities visible. STR-1 and STR-3 connect future uncertainty to decisions. SYS-1 and SYS-2 identify essential services and continuity objectives. SYS-3 and SYS-4 identify dependencies, cascades, and residual service risk. MET-1 and MET-3 reveal whether the strategy is resourced and who remains exposed. ASS-1, ASS-3, and ASS-4 determine whether disclosure claims rest on reliable methods, internal controls, and appropriate assurance. The “should” and “may” clauses preserve proportionality while identifying the maturity path for Tier 2 and Tier 3 pilot alignment.

5.4. Reporting Index and Sample Structure

An entity claiming PSRRS alignment shall publish a disclosure index identifying the location of each requirement, the reporting boundary, the period covered, omissions, reasons for omission, sensitive-information limitations, and planned remediation. The index should distinguish “prepared with reference to PSRRS” from formal conformity. A public entity should not claim conformity when material modules are excluded without an authorized scope limitation.
A concise resilience profile should precede detailed evidence. The profile should identify material essential services; top systemic dependencies; principal scenarios; unresolved high-consequence vulnerabilities; adaptation triggers; current and contingent financing; populations facing residual risk; exercise and assurance status; and changes since the previous period. This profile provides decision-makers, residents, investors, auditors, insurers, infrastructure partners, and oversight bodies with a navigable summary while detailed evidence remains available through annexes or cross-references. The proposed report structure is summarized in Table 7.

5.5. Conformity, Assurance, and Implementation

Conformity assessment follows the logic of ISO/IEC 17000, under which specified requirements are evaluated through structured evidence [57]. The PSRRS model uses three cumulative tiers. The tiers are proposed as a roadmap for future standardization rather than as a validated certification regime. The permitted claims in Table 8 therefore use “prepared with reference” and “pilot alignment” language, not final certification language. Future pilots should test whether the clauses are applied with acceptable reliability across entities before any formal conformity or certification claim is authorized.
Implementation should be phased. In the first cycle, a resource-constrained local government could prepare a Tier 1 disclosure by using existing plans, budgets, vulnerability assessments, emergency operations materials, capital improvement programs, insurance records, and service inventories. The first cycle should prioritize essential-service identification, accountability, known dependencies, core metrics, limitations, and a remediation plan. In the second cycle, entities should validate dependency maps, connect pathways to budgets, formalize triggers, and complete tabletop exercises. Independent assurance should follow only after data definitions, controls, and evidence expectations become stable enough for reliable review.
Costs and burdens are real. Smaller governments may lack GIS staff, grant writers, internal auditors, continuity planners, cyber specialists, or fiscal analysts. The PSRRS therefore uses proportionality, cross-referencing, tiers, and qualitative evidence where quantitative models are unavailable. State agencies, regional planning councils, water management districts, universities, insurers, professional associations, and federal grant programs could support templates, shared data, technical assistance, and pooled assurance. Adoption incentives may include grant eligibility, bond-market credibility, insurance access, legislative oversight, public trust, and reduced duplication across reporting systems.
Political feasibility also matters. Some actors may support PSRRS because it improves transparency, investment discipline, and fiscal stewardship. Others may resist it because it reveals unfunded liabilities, service vulnerabilities, distributional inequities, or dependence on outside actors. The standard should therefore avoid partisan framing and focus on continuity, essential services, public finance, risk management, and accountable stewardship. This framing is particularly appropriate for Florida, where resilience language, flood planning, infrastructure protection, critical assets, and public finance already provide administrative entry points.

6. Discussion

6.1. Theoretical and Standards Contributions

The study advances resilience scholarship by defining resilience reporting as a distinct governance function. Resilience has often been treated as a property, process, strategy, or outcome. Reporting adds a second-order capacity: the ability of an institution to make preparedness claims visible, comparable, contestable, and correctable. An organization may possess some resilience without reporting it, and it may report resilience without possessing it. A standard narrows that gap.
The concept of resilience materiality extends sustainability reporting into the public-value domain. Financial materiality asks whether information affects economic decisions by investors, lenders, or other financial users. Impact materiality asks whether the organization significantly affects people, the environment, or the economy. Resilience materiality asks whether omitted information obscures the capacity to sustain essential public functions, statutory obligations, fiscal stability, ecological integrity, and equitable protection under plausible disruptive conditions. The three materiality lenses overlap but are not identical.
The PSRRS also clarifies the relationship between standards families. IPSASB and sustainability disclosure standards provide accountability architecture; GRI provides impact orientation; ISO 371xx standards provide community indicators; ISO 223xx standards provide resilience and continuity management; ISO 31000 provides risk-management logic; ISO/IEC 17000 provides conformity-assessment vocabulary; UNDRR provides city resilience self-assessment; DMDU provides adaptive pathways. PSRRS translates these inputs into a public-sector resilience disclosure layer.
The principal theoretical contribution is the capability-to-disclosure translation model. Existing reporting approaches often begin with material topics, indicators, risks, or impacts. Resilience reporting faces a different epistemic problem: the most consequential object is frequently a latent institutional capacity that becomes observable only through evidence of authority, redundancy, decision thresholds, resources, exercises, corrective action, and service outcomes. The model therefore theorizes standard elaboration as a sequence of translations from normative obligation to capability, from capability to evidence, and from evidence to recursively assured learning. This explains why the mere presence of a plan, metric, or project is an incomplete proxy for preparedness.
The model also identifies four predictable failure modes in reporting-standard design. Normative aspiration without capability specification produces broad commitments that are difficult to evaluate. Capability language without evidentiary rules produces untestable claims. Evidence without assurance leaves users unable to distinguish documentation from operational effectiveness. Assurance without a learning loop converts resilience into static compliance. PSRRS addresses these failure modes by linking QBL and resilience materiality to the five capability modules, draft clauses, evidence requirements, conformity tiers, and revision processes. In this sense, the article contributes not only a proposed resilience instrument but also a theoretically explicit account of how a public-sector reporting standard may be elaborated from public values into auditable institutional claims.

6.2. Decision-Use Channels and Political Economy

A clearer decision-use channel strengthens the article’s relevance beyond public administration. Municipal bond investors may use PSRRS information to assess long-term capital maintenance, contingent liabilities, and service reliability because climate exposure and sea-level-rise risk have already been linked to municipal bond yields, underwriting costs, maturity effects, ratings, and uncertainty premia [46,47]. Recent municipal-finance research also emphasizes that physical climate risk affects infrastructure, insurance, property values, and local tax bases in ways directly relevant to credit quality and capital access [48]. Insurers may use PSRRS information to evaluate risk controls, exposure reduction, and residual vulnerability. Fiscal authorities may use it to set reserves, prioritize capital plans, or identify grant needs. Auditors may use it to examine controls over resilience claims and data quality. Utility regulators and infrastructure planners may use it to coordinate investments across dependent systems. Residents and community organizations may use it to understand who receives protection and who remains exposed.
The political economy of adoption is mixed. PSRRS creates value by making hidden dependencies, funding gaps, and residual risk visible before disruptions occur. It also creates discomfort because those same disclosures may expose deferred maintenance, unfunded mandates, fragmented authority, or unequal protection. Adoption therefore requires incentives, legal authority, professional norms, and staged implementation. A phased model allows governments to begin with existing evidence rather than wait for perfect models.
Florida illustrates this balance. The state already maintains a substantial resilience planning and data architecture. A PSRRS layer would not require a new climate-policy identity. It would ask the state and participating local governments to disclose how existing data, projects, plans, fiscal resources, continuity objectives, and accountability mechanisms fit together. The AMOC stress test would be reported as one uncertainty stress test, not as a prediction. The cyber-fiscal stress test shows that the same architecture protects against non-climate disruption.

6.3. Jurisdictional Applicability, Feasibility, and Future Validation

The PSRRS is not proposed as a universal legal requirement for every government, and this study does not establish that any country is obligated to adopt it. Applicability should follow institutional conditions rather than geography alone. The strongest case arises where four conditions coincide: essential public services depend on interdependent systems; resilience information is fragmented across plans, budgets, agencies, utilities, and reporting regimes; disruptive conditions involve material uncertainty or cascading consequences; and public entities bear territorial, fiscal, or statutory responsibility for continuity. Global variation in adaptation governance and the cross-sector character of critical-infrastructure resilience support a contextual rather than one-size-fits-all approach [38,61].
Table 9 identifies four jurisdictional archetypes in which pilot use would be especially defensible. The examples are illustrative contexts, not claims of current legal necessity or empirical proof of PSRRS effectiveness. Jurisdictions adopting or aligning with public-sector climate disclosure frameworks such as IPSASB SRS 1 could use PSRRS as a resilience-specific overlay, while lower-capacity jurisdictions could begin with a proportionate Tier 1 profile and shared technical assistance [1,61].
The typology also clarifies the limits of generalization from Florida. Florida illustrates one federated, coastal, subnational context with a mature statutory program, but it does not validate the architecture for the other archetypes. The purpose of Table 9 is to identify falsifiable next-stage settings for comparative pilots. A credible validation program should test whether the same disclosure dimensions are understandable, feasible, and decision-useful across at least one jurisdiction from each archetype before any claim of broad standard applicability is made.
Standardization has risks. A rigid checklist may encourage minimum compliance and suppress local knowledge. Quantification may privilege measurable infrastructure over social trust, informal capacity, administrative judgment, and community relationships. Scenario disclosure may be misunderstood as prediction. Public release of dependency information may create security concerns. Assurance may become expensive or formalistic. These risks require careful design.
The proposed design addresses those concerns through proportionality, tiered conformity, qualitative evidence where quantitative methods are unavailable, explicit uncertainty disclosure, protected annexes for sensitive details, and mandatory reporting of capacity limitations. Standards should create disciplined comparability without erasing contextual judgment. The PSRRS therefore emphasizes minimum architecture, disclosure of limitations, cross-references to existing systems, and staged assurance.
Future research should proceed in five directions. First, a Delphi or technical-committee process should refine the clauses with public managers, auditors, emergency professionals, infrastructure operators, fiscal officers, community representatives, insurers, and standard-setting experts. Second, at least two independent coders should apply the codebook to a larger standards and case corpus, with inter-rater reliability reported. Third, field pilots should test costs, burden, data availability, and usability across small, medium, and large governments. Fourth, assurance pilots should test whether reviewers apply conformity tiers consistently. Fifth, longitudinal studies should examine whether higher PSRRS maturity is associated with improved corrective-action closure, reduced service disruption, better capital maintenance, lower fiscal volatility, or more equitable resilience outcomes.

7. Conclusions

Public-sector sustainability reporting is entering a new phase, yet transparent reporting of systemic preparedness remains underdeveloped. Existing frameworks disclose important elements of governance, risk, impacts, indicators, continuity, and assessment, while the comparative corpus analyzed here does not reveal one integrated public-sector reporting architecture that connects LPHI systemic risk, essential-service continuity, adaptive triggers, resources, equity, and assurance under deep uncertainty.
This article proposes a Public-Sector Resilience Reporting Standard organized around five modules: governance and accountability; strategy, scenarios, and adaptive pathways; systemic risk and essential-service continuity; metrics, resources, and equity; and assurance, learning, and revision. The theoretical contribution is a capability-to-disclosure translation model that explains how normative public-value obligations may be converted into capability domains, evidentiary requirements, and recursive assurance. The PSRRS operationalizes that logic as a pre-standard architecture with mandatory, recommended, and optional clauses; evidence requirements; indicators; a disclosure index; a sample report structure; and a three-tier conformity model.
Florida’s resilience architecture provides an illustrative application rather than a basis for universal generalization. The reviewed corpus contains strong statutory, data, asset, project, and funding foundations [9,10,11], while integrated disclosure of systemic dependencies, adaptive triggers, long-horizon fiscal exposures, residual service risks, distributional effects, and preparedness assurance remains partial. The AMOC and cyber-fiscal stress tests demonstrate hazard-neutral analytical use, but they do not validate PSRRS across countries, regions, or institutional systems. Table 9 therefore identifies candidate jurisdictional archetypes for comparative piloting rather than asserting a universal requirement.
The ultimate standard of resilience is not whether government anticipated one specific event. It is whether governance systems remain prepared to protect public value when the future departs from the planning assumption. Reporting should make that preparedness visible before disruption occurs, while future cross-jurisdictional pilots determine where, how, and at what proportional level the proposed architecture is genuinely useful.

Funding

This research received no external funding.

Institutional Review Board Statement

Not applicable.

Informed Consent Statement

Not applicable.

Data Availability Statement

No new datasets were generated. All documentary materials analyzed are publicly available and are cited in the article. The comparative coding protocol, draft clause set, and disclosure index template are contained in the manuscript appendices.

Acknowledgments

The author thanks the reviewers for constructive comments that strengthened the manuscript.

Conflicts of Interest

The author declares no conflicts of interest.

Abbreviations

AbbreviationDefinition
AMOCAtlantic Meridional Overturning Circulation
DAPPDynamic Adaptive Policy Pathways
DMDUDecision-Making under Deep Uncertainty
GRIGlobal Reporting Initiative
IFRSInternational Financial Reporting Standards
IPSASBInternational Public Sector Accounting Standards Board
ISOInternational Organization for Standardization
LPHILow-Probability, High-Impact
PSRRSPublic-Sector Resilience Reporting Standard
QBLQuadruple Bottom Line
TCFDTask Force on Climate-related Financial Disclosures
UNDRRUnited Nations Office for Disaster Risk Reduction

Appendix A. Codebook for Comparative Coding

Table A1. Coding dimensions and explicit/partial/not explicit criteria.
Table A1. Coding dimensions and explicit/partial/not explicit criteria.
DimensionExplicit (E)Partial (P)/Not Explicit (N)
Governance responsibilityA named body, official, role, or process is required for oversight and reporting.P: governance is discussed but not tied to integrated resilience disclosure. N: no identifiable governance responsibility.
Materiality or risk boundaryA materiality or risk boundary defines what conditions enter the report.P: relevant risks appear but without a public-value resilience threshold. N: no boundary relevant to resilience reporting.
Multiple scenarios and time horizonsMultiple scenarios or time horizons are required or operationalized.P: scenarios are permitted or implied. N: no identifiable scenario/horizon requirement.
Cascading dependenciesDependencies, interdependencies, or cascades are explicitly required or measured.P: dependencies are acknowledged but not required as disclosure. N: not addressed.
Essential-service continuityServices, continuity objectives, recovery objectives, or tolerable disruption are specified.P: assets or activities are discussed without service objectives. N: not addressed.
Adaptive triggers and pathwaysSignposts, thresholds, adaptation tipping points, or contingent pathways are specified.P: adaptation is discussed without triggers. N: not addressed.
Fiscal and resource capacityCosts, funding gaps, reserves, liabilities, or resources are required.P: resource references are general. N: not addressed.
Equity and distributional effectsDifferentiated exposure, benefits, burdens, access, or residual risk must be reported.P: equity or stakeholders are mentioned without operational measures. N: not addressed.
Assurance, verification, or conformityInternal control, external assurance, conformity, or verification is specified.P: review or monitoring appears without assurance criteria. N: not addressed.
Borderline cases were classified conservatively. A dimension was coded as explicit only when the reviewed framework contained a requirement, defined method, operational indicator, or clear disclosure expectation. General language about resilience, sustainability, or risk was coded partial unless linked to a reporting requirement. This codebook is intended for replication and future inter-rater validation.

Appendix B. Draft PSRRS Clause Set

Table A2. Draft PSRRS clauses by module and normative status.
Table A2. Draft PSRRS clauses by module and normative status.
ModuleClause SetNormative Status
PSRRS-GOVGOV-1 identifies accountable governing body and executive owner; GOV-2 discloses cross-functional roles; GOV-3 discloses oversight frequency, key decisions, and unresolved escalations; GOV-4 discloses intergovernmental and critical-partner responsibilities.GOV-1 and GOV-2 shall; GOV-3 should; GOV-4 should, and GOV-4 shall for entities responsible for critical services.
PSRRS-STRSTR-1 discloses material scenarios and time horizons; STR-2 discloses assumptions, uncertainty ranges, confidence, evidence sources, and limitations; STR-3 discloses adaptive pathways, signposts, triggers, lead time, authority, and funding; STR-4 discloses alternative pathway costs, lock-in risks, maladaptation risks, and decision points.STR-1 and STR-3 shall; STR-2 should; STR-4 may for Tier 1 and should for Tier 2 or higher.
PSRRS-SYSSYS-1 identifies material essential services, populations served, public-value functions, and statutory continuity obligations; SYS-2 discloses minimum service levels, tolerable disruption, recovery objectives, degraded-service modes, and prioritization rules; SYS-3 discloses dependencies, interdependencies, common-mode failures, and cross-jurisdictional cascades; SYS-4 discloses residual service risk.SYS-1 and SYS-2 shall; SYS-3 should for Tier 1 and shall for Tier 2 or higher; SYS-4 should.
PSRRS-METMET-1 discloses resources, fiscal exposure, reserves, funding gaps, lifecycle costs, and maintenance burden; MET-2 discloses inputs, processes, outputs, outcomes, and capability metrics; MET-3 discloses equity, participation, accessibility, distributional burdens, and residual risk.MET-1 and MET-3 shall; MET-2 should.
PSRRS-ASSASS-1 discloses data provenance, methods, assumptions, limitations, and quality-review status; ASS-2 discloses exercises, after-action findings, and corrective-action closure; ASS-3 discloses internal review, control testing, management sign-off, and assurance readiness; ASS-4 discloses independent assurance scope and findings where obtained or required.ASS-1 shall; ASS-2 should; ASS-3 should and shall for Tier 2 or higher; ASS-4 may for Tier 1, should for Tier 2, and shall for Tier 3.

Appendix C. Minimum PSRRS Disclosure Index Template

Table A3. Illustrative disclosure index template.
Table A3. Illustrative disclosure index template.
PSRRS ClauseLocation/Cross-ReferenceOmissions, Limitations, and Remediation
GOV-1 Accountable ownerAnnual report section, ordinance, administrative directive, or resilience plan page.If owner is not formally designated, disclose interim owner and date for formal designation.
STR-1 Scenarios and horizonsVulnerability assessment, capital plan, fiscal forecast, emergency plan, or resilience annex.If only one scenario exists, disclose limitation and timeline for multi-scenario review.
SYS-1 Essential servicesService inventory, continuity plan, utility plan, emergency operations plan.If service inventory is incomplete, identify priority services and completion schedule.
MET-1 Fiscal resourcesBudget, capital improvement plan, reserves policy, insurance schedule, grant plan.If lifecycle or contingent costs are unavailable, disclose method-development plan.
MET-3 Equity and residual riskVulnerability assessment, community engagement report, benefit–cost analysis, public-health or housing data.If disaggregation is limited, identify data gaps and interim qualitative evidence.
ASS-1 Data quality and methodsData documentation, methodology appendix, internal control report.If no formal quality review exists, disclose planned controls and responsible office.
ASS-2 Exercises and corrective actionAfter-action reports, continuity exercises, cyber tabletop, emergency management records.If exercise evidence is sensitive, disclose sanitized summary and protected annex procedure.
SYS-3 Dependencies and cascadesDependency map, continuity plan, infrastructure partner records, utility or vendor annex.If publication creates security risk, disclose sanitized summary and protected annex procedure.
ASS-4 Independent assuranceAssurance statement, scope description, sampling protocol, management response.If independent assurance is not obtained, disclose tier limitation and planned assurance pathway.

References

  1. International Public Sector Accounting Standards Board (IPSASB). IPSASB SRS 1: Climate-Related Disclosures; International Federation of Accountants: New York, NY, USA, 2026; Available online: https://www.ipsasb.org/publications/ipsasb-srs-1-climate-related-disclosures (accessed on 6 July 2026).
  2. International Sustainability Standards Board (ISSB). IFRS S1: General Requirements for Disclosure of Sustainability-Related Financial Information; IFRS Foundation: London, UK, 2023; Available online: https://www.ifrs.org/issued-standards/ifrs-sustainability-standards-navigator/ifrs-s1-general-requirements/ (accessed on 14 June 2026).
  3. International Sustainability Standards Board (ISSB). IFRS S2: Climate-Related Disclosures; IFRS Foundation: London, UK, 2023; Available online: https://www.ifrs.org/issued-standards/ifrs-sustainability-standards-navigator/ifrs-s2-climate-related-disclosures/ (accessed on 14 June 2026).
  4. Global Reporting Initiative (GRI). GRI Universal Standards 2021; Global Reporting Initiative: Amsterdam, The Netherlands, 2021; Available online: https://www.globalreporting.org/standards/ (accessed on 14 June 2026).
  5. Task Force on Climate-Related Financial Disclosures. Recommendations of the Task Force on Climate-Related Financial Disclosures; Financial Stability Board: Basel, Switzerland, 2017; Available online: https://www.fsb-tcfd.org/recommendations/ (accessed on 6 July 2026).
  6. Holling, C.S. Resilience and Stability of Ecological Systems. Annu. Rev. Ecol. Syst. 1973, 4, 1–23. [Google Scholar] [CrossRef] [Scilit]
  7. Folke, C. Resilience: The Emergence of a Perspective for Social–Ecological Systems Analyses. Glob. Environ. Change 2006, 16, 253–267. [Google Scholar] [CrossRef] [Scilit]
  8. Boin, A.; van Eeten, M.J.G. The Resilient Organization. Public Manag. Rev. 2013, 15, 429–445. [Google Scholar] [CrossRef] [Scilit]
  9. Florida Department of Environmental Protection. Statewide Flooding and Sea Level Rise Resilience Plan, Fiscal Year 2026–2027; Office of Resilience and Coastal Protection: Tallahassee, FL, USA, 2025. Available online: https://floridadep.gov/rcp/resilient-florida-program/documents/2026-2027-statewide-resilience-plan-awards (accessed on 14 June 2026).
  10. Florida Department of Environmental Protection. Comprehensive Statewide Flood Vulnerability and Sea Level Rise Data Set: Statewide Assessment; Florida Department of Environmental Protection: Tallahassee, FL, USA, 2025. Available online: https://floridadep.gov/rcp/resilient-florida-program/content/resilient-florida-program-statewide-assessment (accessed on 14 June 2026).
  11. Florida Department of Environmental Protection. Florida Statewide Resilience Dataset—Statewide Critical Assets: Final Report on Dataset; Florida Department of Environmental Protection: Tallahassee, FL, USA, 2025. Available online: https://floridadep.gov/rcp/resilient-florida-program/documents/comprehensive-statewide-flood-vulnerability-and-sea-level (accessed on 14 June 2026).
  12. Alibašić, H. Enhancing Local Resilience to Climate Change: An Evaluation of the Resilient Florida Grants Program. Int. J. Clim. Change Impacts Responses 2024, 17, 83–106. [Google Scholar] [CrossRef] [Scilit]
  13. Fox-Kemper, B.; Hewitt, H.T.; Xiao, C.; Aðalgeirsdóttir, G.; Drijfhout, S.S.; Edwards, T.L.; Golledge, N.R.; Hemer, M.; Kopp, R.E.; Krinner, G.; et al. Ocean, Cryosphere and Sea Level Change. In Climate Change 2021: The Physical Science Basis; Masson-Delmotte, V., Zhai, P., Pirani, A., Connors, S.L., Péan, C., Berger, S., Caud, N., Chen, Y., Goldfarb, L., Gomis, M.I., et al., Eds.; Cambridge University Press: Cambridge, UK, 2021; pp. 1211–1362. [Google Scholar] [CrossRef] [Scilit]
  14. Ditlevsen, P.; Ditlevsen, S. Warning of a Forthcoming Collapse of the Atlantic Meridional Overturning Circulation. Nat. Commun. 2023, 14, 4254. [Google Scholar] [CrossRef] [Scilit] [PubMed]
  15. Baker, J.A.; Bell, M.J.; Jackson, L.C.; Vallis, G.K.; Watson, A.J.; Wood, R.A. Continued Atlantic Overturning Circulation Even under Climate Extremes. Nature 2025, 638, 987–994. [Google Scholar] [CrossRef] [Scilit] [PubMed]
  16. Bonan, D.B.; Thompson, A.F.; Schneider, T.; Zanna, L.; Armour, K.C.; Sun, S. Observational Constraints Imply Limited Future Atlantic Meridional Overturning Circulation Weakening. Nat. Geosci. 2025, 18, 479–487. [Google Scholar] [CrossRef] [Scilit]
  17. Little, C.M.; Hu, A.; Hughes, C.W.; McCarthy, G.D.; Piecuch, C.G.; Ponte, R.M.; Thomas, M.D. The Relationship Between U.S. East Coast Sea Level and the Atlantic Meridional Overturning Circulation: A Review. J. Geophys. Res. Oceans 2019, 124, 6435–6458. [Google Scholar] [CrossRef] [Scilit] [PubMed]
  18. Chi, L.; Wolfe, C.L.P.; Hameed, S. Reconsidering the Relationship Between Gulf Stream Transport and Dynamic Sea Level at U.S. East Coast. Geophys. Res. Lett. 2023, 50, e2022GL102018. [Google Scholar] [CrossRef] [Scilit]
  19. U.S. Government Accountability Office. Ransomware: Federal Coordination and Assistance Challenges; GAO-23-106279; U.S. Government Accountability Office: Washington, DC, USA, 2022. Available online: https://www.gao.gov/products/gao-23-106279 (accessed on 20 July 2026).
  20. City of Atlanta. Mayor Keisha Lance Bottoms Provides Update on City of Atlanta Ransomware Cyberattack; City of Atlanta: Atlanta, GA, USA, 2018. Available online: https://www.atlantaga.gov/Home/Components/News/News/11524/ (accessed on 20 July 2026).
  21. City of Baltimore. City Provides Update on Baltimore Ransomware Attack; City of Baltimore: Baltimore, MD, USA, 2019. Available online: https://content.govdelivery.com/accounts/MDBALT/bulletins/2459686 (accessed on 20 July 2026).
  22. City of Baltimore. City Provides Update on Baltimore Ransomware Attack; City of Baltimore: Baltimore, MD, USA, 2019. Available online: https://content.govdelivery.com/accounts/MDBALT/bulletins/249f7d3 (accessed on 20 July 2026).
  23. Pattnaik, N.; Nurse, J.R.C.; Turner, S.; Mott, G.; MacColl, J.; Huesch, P.; Sullivan, J. It’s More Than Just Money: The Real-World Harms from Ransomware Attacks. arXiv 2023, arXiv:2307.02855. [Google Scholar] [CrossRef] [Scilit]
  24. ISO 31000:2018; Risk Management—Guidelines. International Organization for Standardization: Geneva, Switzerland, 2018.
  25. Duit, A.; Galaz, V.; Eckerberg, K.; Ebbesson, J. Governance, Complexity, and Resilience. Glob. Environ. Change 2010, 20, 363–368. [Google Scholar] [CrossRef] [Scilit]
  26. Linkov, I.; Bridges, T.; Creutzig, F.; Decker, J.; Fox-Lent, C.; Kröger, W.; Lambert, J.H.; Levermann, A.; Montreuil, B.; Nathwani, J.; et al. Changing the Resilience Paradigm. Nat. Clim. Change 2014, 4, 407–409. [Google Scholar] [CrossRef] [Scilit]
  27. Aven, T. Risk Assessment and Risk Management: Review of Recent Advances on Their Foundation. Eur. J. Oper. Res. 2016, 253, 1–13. [Google Scholar] [CrossRef] [Scilit]
  28. ISO 37120:2018; Sustainable Cities and Communities—Indicators for City Services and Quality of Life. International Organization for Standardization: Geneva, Switzerland, 2018.
  29. ISO 37123:2019; Sustainable Cities and Communities—Indicators for Resilient Cities. International Organization for Standardization: Geneva, Switzerland, 2019.
  30. ISO 37125:2024; Sustainable Cities and Communities—Environmental, Social and Governance (ESG) Indicators for Cities. International Organization for Standardization: Geneva, Switzerland, 2024.
  31. United Nations Office for Disaster Risk Reduction (UNDRR). Disaster Resilience Scorecard for Cities; UNDRR: Geneva, Switzerland, 2017; Available online: https://mcr2030.undrr.org/disaster-resilience-scorecard-cities (accessed on 14 June 2026).
  32. United Nations Office for Disaster Risk Reduction (UNDRR). Disaster Resilience Scorecard for Cities: Climate Resilience Addendum; UNDRR: Geneva, Switzerland, 2023; Available online: https://mcr2030.undrr.org/climate-resilience-scorecard (accessed on 14 June 2026).
  33. Tommasetti, A.; Mussari, R.; Maione, G.; Sorrentino, D. Sustainability Accounting and Reporting in the Public Sector: Towards Public Value Co-Creation? Sustainability 2020, 12, 1909. [Google Scholar] [CrossRef] [Scilit]
  34. Manes-Rossi, F.; Nicolò, G.; Argento, D. Non-Financial Reporting Formats in Public Sector Organizations: A Structured Literature Review. J. Public Budg. Account. Financ. Manag. 2020, 32, 639–669. [Google Scholar] [CrossRef] [Scilit]
  35. Li, J.; Tang, S.-Y.; Wen, B. Unpacking Resilience in Public Administration: Insights from a Meta-Narrative Review. Public Adm. Rev. 2026, 1–20, advance online publication. [Google Scholar] [CrossRef] [Scilit]
  36. Rinaldi, S.M.; Peerenboom, J.P.; Kelly, T.K. Identifying, Understanding, and Analyzing Critical Infrastructure Interdependencies. IEEE Control Syst. Mag. 2001, 21, 11–25. [Google Scholar] [CrossRef] [Scilit]
  37. Ouyang, M. Review on Modeling and Simulation of Interdependent Critical Infrastructure Systems. Reliab. Eng. Syst. Saf. 2014, 121, 43–60. [Google Scholar] [CrossRef] [Scilit]
  38. Organisation for Economic Co-Operation and Development (OECD). Good Governance for Critical Infrastructure Resilience; OECD Publishing: Paris, France, 2019. [Google Scholar] [CrossRef] [Scilit]
  39. Araos, M.; Berrang-Ford, L.; Ford, J.D.; Austin, S.E.; Biesbroek, R.; Lesnikowski, A. Climate Change Adaptation Planning in Large Cities: A Systematic Global Assessment. Environ. Sci. Policy 2016, 66, 375–382. [Google Scholar] [CrossRef] [Scilit]
  40. Reckien, D.; Salvia, M.; Heidrich, O.; Church, J.M.; Pietrapertosa, F.; De Gregorio-Hurtado, S.; D’Alonzo, V.; Foley, A.; Simoes, S.G.; Krkoška Lorencová, E.; et al. How Are Cities Planning to Respond to Climate Change? Assessment of Local Climate Plans from 885 Cities in the EU-28. J. Clean. Prod. 2018, 191, 207–219. [Google Scholar] [CrossRef] [Scilit]
  41. Woodruff, S.C.; Stults, M. Numerous Strategies but Limited Implementation Guidance in U.S. Local Adaptation Plans. Nat. Clim. Change 2016, 6, 796–802. [Google Scholar] [CrossRef] [Scilit]
  42. Lempert, R.J.; Popper, S.W.; Bankes, S.C. Shaping the Next One Hundred Years: New Methods for Quantitative, Long-Term Policy Analysis; RAND Corporation: Santa Monica, CA, USA, 2003. [Google Scholar]
  43. Marchau, V.A.W.J.; Walker, W.E.; Bloemen, P.J.T.M.; Popper, S.W. (Eds.) Decision Making Under Deep Uncertainty: From Theory to Practice; Springer: Cham, Switzerland, 2019. [Google Scholar] [CrossRef] [Scilit]
  44. Haasnoot, M.; Kwakkel, J.H.; Walker, W.E.; Ter Maat, J. Dynamic Adaptive Policy Pathways: A Method for Crafting Robust Decisions for a Deeply Uncertain World. Glob. Environ. Change 2013, 23, 485–498. [Google Scholar] [CrossRef] [Scilit]
  45. Weitzman, M.L. On Modeling and Interpreting the Economics of Catastrophic Climate Change. Rev. Econ. Stat. 2009, 91, 1–19. [Google Scholar] [CrossRef] [Scilit]
  46. Painter, M. An Inconvenient Cost: The Effects of Climate Change on Municipal Bonds. J. Financ. Econ. 2020, 135, 468–482. [Google Scholar] [CrossRef] [Scilit]
  47. Goldsmith-Pinkham, P.; Gustafson, M.T.; Lewis, R.C.; Schwert, M. Sea-Level Rise Exposure and Municipal Bond Yields. Rev. Financ. Stud. 2023, 36, 4588–4635. [Google Scholar] [CrossRef] [Scilit]
  48. Mishra, A.; Arun, A.; Kodra, E.; Smull, E.; Woolcock, O.; Doe, T.; Marlowe, J.; Ganguly, A.R. Physical Climate Risk Creates Challenges and Opportunities in US Municipal Finance. Nat. Cities 2026, 3, 11–21. [Google Scholar] [CrossRef] [Scilit]
  49. Edmans, A.; García, D.; Norli, Ø. Sports Sentiment and Stock Returns. J. Financ. 2007, 62, 1967–1998. [Google Scholar] [CrossRef] [Scilit]
  50. Abudy, M.; Mugerman, Y.; Shust, E. The Winner Takes It All: Investor Sentiment and the Eurovision Song Contest. J. Bank. Financ. 2022, 137, 106432. [Google Scholar] [CrossRef] [Scilit]
  51. Alibašić, H. Sustainability and Resilience Planning for Local Governments: The Quadruple Bottom Line Strategy; Springer: Cham, Switzerland, 2018. [Google Scholar]
  52. Alibašić, H. Strategic Resilience and Sustainability Planning; Springer: Cham, Switzerland, 2022. [Google Scholar]
  53. Alibašić, H. Toward a Standards Framework for Hybrid Intelligence Governance: Integrating Human Judgment and AI Decision Support. Standards 2026, 6, 20. [Google Scholar] [CrossRef] [Scilit]
  54. ISO 37101:2016; Sustainable Development in Communities—Management System for Sustainable Development—Requirements with Guidance for Use. International Organization for Standardization: Geneva, Switzerland, 2016.
  55. ISO 22316:2017; Security and Resilience—Organizational Resilience—Principles and Attributes. International Organization for Standardization: Geneva, Switzerland, 2017.
  56. ISO 22301:2019; Security and Resilience—Business Continuity Management Systems—Requirements. International Organization for Standardization: Geneva, Switzerland, 2019.
  57. ISO/IEC 17000:2020; Conformity Assessment—Vocabulary and General Principles. International Organization for Standardization: Geneva, Switzerland, 2020.
  58. National Research Council. Disaster Resilience: A National Imperative; National Academies Press: Washington, DC, USA, 2012. [Google Scholar] [CrossRef] [Scilit] [PubMed]
  59. Cutter, S.L.; Burton, C.G.; Emrich, C.T. Disaster Resilience Indicators for Benchmarking Baseline Conditions. J. Homel. Secur. Emerg. Manag. 2010, 7, 51. [Google Scholar] [CrossRef] [Scilit]
  60. Meerow, S.; Newell, J.P.; Stults, M. Defining Urban Resilience: A Review. Landsc. Urban Plan. 2016, 147, 38–49. [Google Scholar] [CrossRef] [Scilit]
  61. Chan, T.; Surminski, S.; Neaman, A. Climate Change Adaptation Laws and Policies: A Global Assessment; Grantham Research Institute on Climate Change and the Environment, London School of Economics and Political Science: London, UK, 2026; Available online: https://www.lse.ac.uk/granthaminstitute/ (accessed on 6 July 2026).
  62. Zarapkar, N. Introducing the International Public Sector Accounting Board’s Sustainability Reporting Standards for Public Sector Disclosure; Governance Brief No. 61; Asian Development Bank: Manila, Philippines, 2026. [Google Scholar]
  63. ISO 14090:2019; Adaptation to Climate Change—Principles, Requirements and Guidelines. International Organization for Standardization: Geneva, Switzerland, 2019.
Figure 1. Public-Sector Resilience Reporting Standard (PSRRS) architecture. The five modules operationalize the capability-to-disclosure translation logic around the normative object of public value and essential-service resilience; their connections represent functional dependence and recursive learning rather than a simple linear sequence.
Figure 1. Public-Sector Resilience Reporting Standard (PSRRS) architecture. The five modules operationalize the capability-to-disclosure translation logic around the normative object of public value and essential-service resilience; their connections represent functional dependence and recursive learning rather than a simple linear sequence.
Standards 06 00028 g001
Table 1. Documentary corpus, selection rationale, analytical purpose, and linked research questions.
Table 1. Documentary corpus, selection rationale, analytical purpose, and linked research questions.
Corpus ElementReason for SelectionAnalytical Purpose/RQ Link
IPSASB SRS 1, Climate-related Disclosures (2026) [1]First international public-sector climate disclosure standard; directly relevant to accountability and decision-use in general-purpose financial reports.Tests whether public-sector climate disclosure includes systemic preparedness, service continuity, adaptive triggers, and assurance (RQ1, RQ3).
IFRS S1 and IFRS S2 (2023) and TCFD recommendations (2017) [2,3,5]Core global sustainability and climate financial-disclosure architecture organized around governance, strategy, risk management, and metrics.Clarifies decision-use channels and the distinction between financial materiality and public-value resilience materiality (RQ1, RQ3).
GRI Universal Standards (2021) [4]Major impact-reporting framework applicable to multiple organization types.Assesses impact orientation, stakeholder relevance, and limits of impact disclosure for systemic preparedness (RQ1).
ISO 37101, 37120, 37123, 37125 [28,29,30,54]Community management and indicator standards for sustainable, resilient, and ESG-oriented cities.Identifies strengths and limits of indicator-based city reporting (RQ1, RQ3).
ISO 22316, ISO 22301, ISO 31000, ISO/IEC 17000 [24,55,56,57]Organizational resilience, continuity management, risk management, and conformity-assessment foundations.Supports continuity, assurance, and conformity elements of PSRRS (RQ1, RQ3, RQ4).
UNDRR Disaster Resilience Scorecard and Climate Resilience Addendum [31,32]Structured city resilience assessment instruments linked to disaster risk reduction.Assesses cross-sector resilience, local government readiness, and the boundary between self-assessment and public reporting (RQ1, RQ3).
Florida Statewide Flooding and Sea Level Rise Resilience Plan and statewide critical-asset/data materials [9,10,11]Current subnational resilience architecture with statutory continuity, critical-asset data, project ranking, and recurring reporting.Illustrative application of the coding protocol and PSRRS gaps (RQ2).
AMOC assessment and peer-reviewed literature [13,14,15,16,17,18]High-consequence scenario with contested timing, probability, and local translation.Stress-test disclosure of uncertainty, signal governance, service translation, triggers, and residual risk (RQ2, RQ3).
Public administration resilience, infrastructure interdependency, catastrophic uncertainty, municipal finance, climate-risk pricing, investor attention, cyber-fiscal disruption, and adaptation planning studies [8,19,20,21,22,23,25,26,27,35,36,37,38,39,40,41,45,46,47,48,49,50,58,59,60,61,62,63]Theoretical and empirical foundations for adaptive capacity, cascading dependencies, decision-use, public finance, credit-risk transmission, cyber-fiscal service disruption, and local implementation constraints.Strengthens conceptual validity, decision-use logic, stress-test evidence, and implementation logic (RQ1–RQ4).
Table 2. Functional coverage of resilience-reporting dimensions across the reviewed frameworks.
Table 2. Functional coverage of resilience-reporting dimensions across the reviewed frameworks.
Framework FamilyExplicit or Relatively Strong CoveragePartial or Weakly Integrated CoveragePrincipal Gap for PSRRS
IPSASB SRS 1Climate-related governance, strategy, risk, metrics, public-sector accountability, decision-use.Scenario depth, essential-service continuity, equity distribution, systemic dependencies, assurance of preparedness.Needs a service-centered resilience layer that connects climate disclosure to public functions and adaptive capacity.
IFRS S1/S2 and TCFDGovernance, strategy, risk management, metrics and targets, decision-useful financial disclosure.Public-sector statutory obligations, service continuity, public-value materiality, vulnerable populations.Financial materiality does not fully disclose public-service capacity or territorial equity.
GRI Universal StandardsImpact materiality, stakeholder effects, economic/environmental/social impacts.Adaptive triggers, continuity objectives, assurance of systemic preparedness.Impact disclosure does not necessarily reveal readiness to maintain essential services.
ISO 37101/37120/37123/37125Community indicators, city services, resilient-city measurement, ESG city profiles.Adaptive pathways, fiscal exposure, dependency chains, external assurance.Indicator completeness does not equal capability disclosure.
ISO 22316/22301Organizational resilience attributes, continuity planning, operational controls, exercises, continual improvement.Public-value materiality, sustainability impacts, intergenerational horizons, whole-of-community dependencies.Continuity systems require translation into public-service and jurisdictional disclosure.
ISO 31000Risk principles, structured assessment, monitoring, communication.Deep uncertainty, adaptive pathways, public reporting, conformity assessment.Risk management requires a resilience supplement for surprises and cascades.
UNDRR Scorecard and AddendumCity resilience self-assessment, disaster risk reduction, multi-sector orientation, climate addendum.Audited disclosure, fiscal exposure, formal conformity claims, adaptive trigger protocols.Self-assessment needs a public reporting and assurance layer.
Florida resilience architectureStatutory plan, statewide data, critical assets, project ranking, funded investments, output metrics.Systemic dependencies, adaptive triggers, long-horizon fiscal exposure, residual service risk, assurance.Project reporting needs integration into a whole-system preparedness report.
Table 3. Florida resilience-reporting strengths and remaining PSRRS gaps.
Table 3. Florida resilience-reporting strengths and remaining PSRRS gaps.
PSRRS DimensionEvidence of Strength in Florida ArchitectureRemaining Disclosure Gap
Governance and accountabilityStatutory program, recurring statewide plan, agency responsibility, project eligibility and ranking [9].The reviewed corpus does not identify a single cross-system resilience disclosure owner responsible for integrated reporting across agencies, utilities, fiscal authorities, emergency systems, and local governments [9,10,11].
Strategy, scenarios, and pathwaysStatewide planning cycle and vulnerability-assessment requirements link projects to flooding and sea-level-rise conditions [9].The reviewed plan emphasizes a three-year project horizon and statutory hazard categories; multi-horizon adaptive pathways, signposts, and formal trigger thresholds are not standardized disclosure fields [9].
Systemic risk and service continuityCritical assets are identified across infrastructure categories, including water, wastewater, transportation, emergency facilities, and public assets [10,11].The reviewed asset and vulnerability materials do not consistently publish dependency maps, acceptable downtime, common-mode failure, service-continuity objectives, or regional cascade pathways [10,11].
Metrics, resources, and equityProject cost, match, output metrics, cost-share provisions, nature-based criteria, and community need are visible [9].Project outputs do not consistently disclose service-level outcomes, residual risk, distributional benefits, lifecycle maintenance burden, or integrated long-horizon fiscal exposure [9,10,11].
Assurance, learning, and revisionRecurring plans, data updates, project documentation, and statewide datasets support procedural accountability [9,10,11].Independent operational-effectiveness review, exercise results, after-action closure, trigger testing, and integrated assurance of preparedness are not visible as standardized disclosures in the reviewed corpus [9,10,11].
Table 4. Systematic AMOC stress-test application to Florida reporting architecture.
Table 4. Systematic AMOC stress-test application to Florida reporting architecture.
Stress-Test QuestionWhat PSRRS Would RequireCurrent Florida Visibility and Gap
SignalIdentify authoritative monitoring sources, confidence level, responsible horizon-scanning office, review frequency, and threshold for formal reassessment.Florida’s reviewed materials use flood and sea-level-rise evidence, but they do not clearly assign AMOC-specific horizon scanning or define when a scientific update triggers formal plan review [9,10,11].
TranslationTranslate scientific signals into service, infrastructure, fiscal, ecological, and social consequences without forcing one deterministic forecast.Current reporting translates flooding and sea-level rise into critical-asset exposure and projects, but less clearly into multi-sector service continuity, insurance, supply chains, migration, and public-finance consequences [9,10,11].
CoordinationIdentify agencies, utilities, local governments, regulators, fiscal authorities, emergency managers, and infrastructure partners responsible for cross-system action.The architecture includes state and local planning roles, but the reviewed corpus does not disclose cross-sector dependency governance as one statewide service-continuity chain [9,10,11].
AdaptationPublish signposts, trigger thresholds, lead times, contingent pathways, funding mechanisms, and authority for pathway change.Project ranking and funding are visible, while standardized adaptive triggers, pathway switching, and pre-authorized contingent actions remain weakly disclosed in the reviewed documents [9].
DisclosureProvide users with a clear account of readiness, limitations, residual risk, data quality, and unresolved vulnerabilities.Users see projects, datasets, and rankings; they receive less integrated information on residual service risk, dependency fragility, fiscal exposure, and assurance of adaptive capacity [9,10,11].
Table 5. Case-grounded cyber-fiscal disruption stress test showing hazard-neutral application of PSRRS.
Table 5. Case-grounded cyber-fiscal disruption stress test showing hazard-neutral application of PSRRS.
PSRRS ModuleDisclosure Required Under Cyber-Fiscal DisruptionWhy Ordinary Reporting May Be Insufficient
Governance and accountabilityIdentify executive owner, cyber incident command linkage, finance authority, procurement authority, legal counsel, communications lead, and intergovernmental partners.Atlanta and Baltimore show that cyber incident command, finance, communications, billing, and public-service decisions may be dispersed across different offices unless an integrated owner is disclosed [20,21,22].
Strategy, scenarios, and pathwaysReport severe but plausible outage durations, degraded-service modes, manual workarounds, trigger points for emergency procurement, and recovery priorities.Preparedness may be described generically without disclosure of operational thresholds, manual-workaround capacity, lead times, emergency procurement triggers, or pathway changes.
Systemic risk and service continuityMap dependencies among digital identity, payment systems, utility operations, public safety, communications, payroll, vendors, cloud services, and mutual aid.An IT asset inventory does not reveal public-service dependencies or common-mode failure across departments, vendors, payment systems, utility billing, courts, emergency communications, and public records.
Metrics, resources, and equityDisclose cyber reserves, insurance coverage limits, recovery costs, critical staffing, service downtime objectives, and populations harmed by digital exclusion or service interruption.Budget and insurance disclosures rarely show who bears residual service risk, which services receive priority during degraded operations, or how recovery costs and billing interruptions affect liquidity.
Assurance, learning, and revisionReport tabletop and live exercises, backup restoration tests, penetration or control reviews, after-action findings, and corrective-action closure.Plan existence does not show whether backups restore, vendors respond, manual processes function, residents receive service, or lessons are closed after real incidents.
Table 6. Core PSRRS clauses, status, evidence requirements, and illustrative indicators.
Table 6. Core PSRRS clauses, status, evidence requirements, and illustrative indicators.
CodeRequired, Recommended, or Optional DisclosureEvidence and Illustrative Indicators
GOV-1 SHALLIdentify the governing body or senior official accountable for resilience disclosure and the executive owner responsible for preparation of the report.Charter, ordinance, administrative directive, reporting schedule; percentage of scheduled resilience reviews completed.
GOV-2 SHALLDisclose cross-functional roles for risk sensing, infrastructure, finance, continuity, legal authority, public communication, community engagement, and assurance.Roles matrix, escalation protocol, interagency agreements; critical partners with current agreements.
GOV-3 SHOULDDisclose oversight frequency, key resilience decisions, unresolved escalations, and governing-body review of material residual risk.Meeting calendar, minutes, decision log, unresolved-risk register; overdue escalations.
GOV-4 SHOULD; SHALL for critical-service entitiesDisclose intergovernmental, utility, contractor, and critical partner responsibilities for material services.Mutual-aid agreements, memoranda of understanding, service-level agreements, partner readiness attestations.
STR-1 SHALLDisclose material scenarios and time horizons used to evaluate resilience-material risks.Scenario assumptions, evidence sources, confidence levels; material services tested across operational, strategic, and long-horizon conditions.
STR-2 SHOULDDisclose assumptions, uncertainty ranges, confidence levels, evidence sources, and known limitations for each material scenario.Scenario evidence register, assumption log, confidence statement, method notes, review dates.
STR-3 SHALLIdentify adaptive pathways, signposts, trigger thresholds, contingent actions, decision authority, lead time, and funding sources.Trigger register; proportion of material triggers with named owner and funded or pre-authorized response.
STR-4 MAY; SHOULD for Tier 2+Disclose alternative pathway costs, lock-in risks, maladaptation risks, and decision points where strategies should shift.Pathway map, adaptation tipping points, avoided-lock-in analysis, contingent procurement or finance options.
SYS-1 SHALLIdentify material essential services, populations served, public-value functions, and legal or statutory continuity obligations.Service register, statutory duty map, service population profile, essential-service ownership record.
SYS-2 SHALLDisclose minimum service levels, maximum tolerable disruption, recovery objectives, degraded-service modes, and prioritization rules.Continuity objectives, recovery-time objectives, manual-workaround protocols, service-priority matrix.
SYS-3 SHOULD for Tier 1; SHALL for Tier 2+Disclose dependencies, interdependencies, common-mode failures, single points of failure, and cross-jurisdictional cascades for material services.Dependency maps or qualitative matrices; material services with validated dependency maps.
SYS-4 SHOULDDisclose residual service risk after existing projects, controls, and planned investments.Residual-risk statement, unfunded dependency list, services with remaining high-consequence exposure.
MET-1 SHALLReport resources, fiscal exposure, reserves, contingent liabilities, lifecycle costs, maintenance burden, and funding gaps linked to material resilience pathways.Capital/operating costs, reserves, insurance limits, unfunded requirements; unfunded resilience requirement as share of planned investment.
MET-2 SHOULDReport inputs, processes, outputs, outcomes, and capability metrics linked to the PSRRS modules.Indicator register, baseline and target values, service-level metrics, capability maturity measures.
MET-3 SHALLReport distributional exposure, benefits, participation, accessibility, residual risk, and cost burdens where effects differ materially across populations or places.Disaggregated exposure and benefit analysis; high-vulnerability population with residual material exposure.
ASS-1 SHALLDisclose data provenance, estimation methods, model limitations, methodology changes, internal controls, and quality-review status.Data inventory, version history, limitations statement; material indicators passing quality review.
ASS-2 SHOULDReport exercises, after-action findings, corrective-action owners, due dates, closure status, and scenario or pathway revisions.Exercise records, after-action plans, corrective-action tracking; corrective actions closed on time.
ASS-3 SHOULD; SHALL for Tier 2+Disclose internal review, control testing, management sign-off, and readiness for assurance of material disclosures.Internal audit memo, management representation, control-test sample, remediation log.
ASS-4 MAY; SHOULD for Tier 2; SHALL for Tier 3Obtain independent assurance of selected disclosures, dependency evidence, trigger governance, and operational effectiveness.External assurance statement, sampling protocol, exercise validation; assured modules and scope limitations.
Table 7. Sample PSRRS report structure.
Table 7. Sample PSRRS report structure.
Report ComponentMinimum ContentUser Value
Resilience profileEssential services, material risks, top dependencies, residual vulnerabilities, assurance status.Provides a short decision-use summary for governing bodies and external users.
Disclosure indexPSRRS clauses, page or document reference, omissions, limitations, remediation plan.Supports comparability, auditability, and burden reduction through cross-referencing.
Governance statementAccountability, oversight, roles, escalation, coordination, legal authority.Shows whether responsibility and authority exist.
Scenario and pathway statementScenarios, assumptions, confidence, triggers, contingent actions, lead times, funding.Shows whether the entity is prepared to change course.
Service continuity statementEssential services, tolerable downtime, recovery objectives, dependencies, cascades.Links assets and projects to public-service outcomes.
Metrics, resources, and equity statementInputs, outputs, outcomes, fiscal exposure, residual risk, distributional effects.Connects preparedness to budgets, benefits, burdens, and public value.
Assurance and learning statementData quality, methodology, exercises, after-action items, correction closure, assurance scope.Shows reliability and continuous improvement.
Table 8. Proposed PSRRS conformity tiers.
Table 8. Proposed PSRRS conformity tiers.
TierMinimum RequirementsAssessment Approach and Permitted Claim
Tier 1—Foundational DisclosureAll material modules addressed; governance owner; service register; scenarios; dependency screening; basic metrics; limitations; disclosure index.Document review and management attestation with internal control confirmation. Permitted claim: “Prepared with reference to PSRRS—Tier 1 foundational disclosure.”
Tier 2—Operational Pilot AlignmentTier 1 plus validated dependency maps for material services, exercises, adaptive triggers, budget links, corrective-action tracking, and data-quality controls.Internal audit or qualified independent review with sampling of controls and records. Permitted claim: “Pilot operational alignment with PSRRS—Tier 2.”
Tier 3—Assured Pilot AlignmentTier 2 plus independent assurance, multi-system exercises, pathway tests, equity evaluation, longitudinal outcome evidence, and corrective-action validation.Independent third-party assurance and operational effectiveness testing. Permitted claim: “Pilot assured alignment with PSRRS—Tier 3.”
Table 9. Jurisdictional applicability archetypes for PSRRS pilot use. Examples are illustrative and do not imply an existing legal requirement to adopt PSRRS.
Table 9. Jurisdictional applicability archetypes for PSRRS pilot use. Examples are illustrative and do not imply an existing legal requirement to adopt PSRRS.
Applicability Archetype and Illustrative ContextsWhy the Reporting Gap May Be MaterialProportionate Implementation Pathway
Federated or highly decentralized public systems (illustrative contexts: U.S. states and local governments; Canadian provinces and municipalities; Australian states and local councils)Infrastructure, emergency management, finance, land use, utilities, and adaptation responsibilities are dispersed across levels and organizations, increasing the risk that dependencies and contingent authority remain fragmented across reports.Tier 1 pilots through state or provincial guidance, grant conditions, voluntary consolidated reporting, or regional coordination platforms.
Multilevel systems with established sustainability or climate-disclosure architecture (illustrative contexts: European Union member-state and local public bodies; United Kingdom public bodies)Existing reporting systems create a strong institutional base, but essential-service continuity, adaptive triggers, systemic dependencies, and preparedness assurance may still be distributed across separate instruments.Use PSRRS as an interoperable overlay that cross-references existing climate, financial, capital, continuity, and risk reports rather than duplicating them.
Coastal, island, and climate-exposed jurisdictions (illustrative contexts: Caribbean and Pacific island states and highly exposed coastal regions)Infrastructure concentration, fiscal constraints, insurance stress, supply dependencies, and compound climate hazards may turn local disruption into systemwide service and fiscal consequences.Begin with a proportionate Tier 1 disclosure supported by regional data platforms, development partners, pooled technical assistance, and shared assurance resources.
Rapidly urbanizing or infrastructure-constrained metropolitan systems (illustrative contexts in Asia, Africa, and Latin America)Fast growth and service interdependencies may outpace integrated reporting, while capacity constraints make visibility of priorities, dependencies, funding gaps, and residual risk especially valuable.Pilot at city or utility level, focus initially on essential services and highest-consequence dependencies, and phase metrics and assurance as data capacity matures.
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content.

Share and Cite

MDPI and ACS Style

Alibašić, H. Toward a Public-Sector Resilience Reporting Standard for Low-Probability, High-Impact Systemic Risks: A Pre-Standard Architecture for Government Preparedness Under Deep Uncertainty. Standards 2026, 6, 28. https://doi.org/10.3390/standards6030028

AMA Style

Alibašić H. Toward a Public-Sector Resilience Reporting Standard for Low-Probability, High-Impact Systemic Risks: A Pre-Standard Architecture for Government Preparedness Under Deep Uncertainty. Standards. 2026; 6(3):28. https://doi.org/10.3390/standards6030028

Chicago/Turabian Style

Alibašić, Haris. 2026. "Toward a Public-Sector Resilience Reporting Standard for Low-Probability, High-Impact Systemic Risks: A Pre-Standard Architecture for Government Preparedness Under Deep Uncertainty" Standards 6, no. 3: 28. https://doi.org/10.3390/standards6030028

APA Style

Alibašić, H. (2026). Toward a Public-Sector Resilience Reporting Standard for Low-Probability, High-Impact Systemic Risks: A Pre-Standard Architecture for Government Preparedness Under Deep Uncertainty. Standards, 6(3), 28. https://doi.org/10.3390/standards6030028

Article Metrics

Back to TopTop