Being asked to produce a climate risk assessment is now a routine experience for finance and operations teams the request arrives from a lender, an insurer, a regulator or a major customer, usually with a deadline attached. What is often missing is a clear picture of what the exercise involves, how long it takes and what it should produce. This guide walks through a climate risk assessment end to end, so it can be scoped properly rather than assembled reactively.

Step One: Define Scope and Purpose

Assessments vary enormously depending on why they are being done. A disclosure-driven exercise needs breadth across the whole portfolio at moderate depth. A single-asset acquisition review needs depth at one location. A lender’s requirement will specify particular scenarios and horizons. Establishing the purpose first prevents the common outcome of commissioning an expensive study that answers a different question from the one being asked. Write down the decision the assessment must support before approaching any provider.

Step Two: Build the Asset Register

Nothing works without an accurate list of what you own and where it sits. Coordinates matter more than addresses, since hazard exposure can differ materially across a few hundred metres. The register should record asset type, replacement value, revenue dependency, criticality to operations, and any existing protective measures. Leased premises belong on the list alongside owned ones, because operational disruption does not care about tenure. Most organisations find this step takes longer than expected and delivers value independently of the assessment itself.

Step Three: Choose Scenarios and Horizons

Physical risk analysis is scenario-based, and the choices here shape everything downstream. Common practice runs a moderate and a high-emissions pathway across two or three time horizons typically near-term, mid-century and end-century chosen to match the useful life of the assets and the tenure of the financing. Selecting only a distant horizon makes the results feel abstract; selecting only a near one understates exposure for long-lived assets. Aligning horizons with actual hold periods keeps the output decision-relevant.

Step Four: Model Hazards at Asset Level

This is the technical core. Each site is assessed against the perils relevant to it riverine and surface flooding, coastal inundation, extreme heat, drought, water stress, wildfire and wind. Resolution is the quality test, analysis averaged across a region will misrepresent individual sites badly. Alongside hazard intensity, the assessment should evaluate local capacity to cope, since drainage investment, grid redundancy and institutional strength materially change outcomes. Data on the global adaptation capacity of specific locations is what distinguishes a place that will manage from one that will not.

Step Five: Translate Into Financial Terms

Hazard scores do not survive contact with an investment committee. The assessment should convert exposure into expected annual loss, projected downtime, incremental operating cost, insurance premium trajectory and, where relevant, an adjustment to asset value or discount rate. This is also the stage where vulnerability functions matter the same flood depth produces very different losses in a distribution shed and a clean room, and an assessment that ignores asset type will be wrong in both directions.

Step Six: Identify and Cost Responses

An assessment that stops at quantification is only half useful. For each material exposure, the next question is what can be done and what it costs, physical protection, relocation, redundancy, operational changes, insurance restructuring, or accepting the risk explicitly. Costing these allows straightforward comparison against the modelled loss, turning the output into a prioritised investment list rather than a catalogue of concerns. Some exposures will be rationally accepted, and documenting that decision is as important as documenting the mitigations.

Step Seven: Report in a Usable Form

The deliverable should work for several audiences. Executives need a short summary of material exposures, financial magnitude and recommended actions. Technical teams need site-level detail and methodology. External parties need documentation of scenarios, data sources and assumptions. Building all three from one analysis avoids the situation where a study satisfies a regulator but never influences an internal decision, which is the most common way these exercises waste money.

What Good Providers Do Differently

Ask any prospective provider how their models are built and validated, what spatial resolution they deliver, whether outputs are financial or categorical, how often data is refreshed, and whether a specific result can be explained on request. Transparency matters more than sophistication analysts will not act on a number they cannot interrogate. Reviewing published climate risk methodology and case work before engaging is a quick way to judge whether a provider’s approach will withstand scrutiny from your own auditors.

Keeping It Alive

Treat the assessment as a baseline rather than a conclusion. Reassess on a defined cycle, update when the portfolio changes materially, and revisit when hazard models are revised. Assign ownership to a named individual and set a reporting rhythm. An assessment that is refreshed and referenced becomes part of how the business makes decisions; one that is filed after publication becomes an expensive document that nobody reads twice. The practical test is simple: a year after delivery, can someone name a decision that went differently because of it? If not, the problem is usually scoping rather than analysis, and the next cycle should start by fixing that.