Skip to main content
Climate Risk Fundamentals

Climate Risk Assessment Methodology and Frameworks

Published on July 2026

A climate risk assessment is only as credible as its methodology. This guide sets out the standard four-step method, the frameworks that govern it, and the characteristics that make an assessment defensible to an auditor or regulator.

The Four-Step Methodology

Rigorous physical climate risk assessment follows four steps, in order:

  • Hazard identification: determine which perils apply to the asset's precise location.
  • Exposure analysis: identify what is at risk - the asset, its value, and its operations.
  • Vulnerability assessment: apply damage functions specific to construction and use type.
  • Financial quantification: convert damage into Expected Annual Loss and Climate VaR under named scenarios.

The Role of Scenario Analysis

Because climate risk depends on an uncertain future, assessments are run across multiple scenarios rather than a single forecast. Scenario analysis stress-tests the asset under different warming and policy pathways, so the output is a range with explicit assumptions rather than a false-precision point estimate.

The Key Frameworks

Several frameworks govern how climate risk is assessed and disclosed. Aligning your methodology to them from the start avoids rework:

  • TCFD: the foundational framework structuring disclosure around governance, strategy, risk, and metrics.
  • ISSB IFRS S2: the global baseline standard that builds on and consolidates TCFD.
  • CSRD / ESRS E1: the EU standard requiring physical and transition risk plus financial effects.
  • NGFS scenarios: the reference climate scenarios used for financial stress testing.
  • EU Taxonomy: the classification system for environmentally sustainable activities.

Bottom-Up vs Top-Down Data

The data feeding an assessment can be built bottom-up from activity data and emissions factors, or measured top-down from independent observation such as satellite data. The most defensible methodologies combine both, using independent measurement to verify bottom-up estimates. Floodlight's emissions methodology applies exactly this hybrid approach.

What Makes a Methodology Defensible

An auditor or regulator looks for three things: provenance (every figure traceable to a source and model version), independence (data not solely dependent on the entity being assessed), and quantified uncertainty (an explicit confidence band, not a bare point estimate). A methodology that provides all three can support a limited-assurance opinion.

See a methodology built for audit.

Get a sample assessment with full provenance and confidence bands.

Climate Risk Assessment Methodology and Frameworks | Floodlight