September 10, 2026

How climate risk assessments finally scale

Luc Machiels
CEO
Karel Verhaeghe
Head of Product

Ask a COO today which of their sites are exposed to climate hazards, how badly, and what it looks like in 2050, and you'll get an honest shrug. Not because nobody has looked. Because everything they were offered forced them to choose.

Done properly, a single site is the better part of a week's work. Multiply that by your footprint and you have a project measured in months and six figures. Done cheaply, five thousand addresses can be screened overnight, and what comes back is a colour per pin.

Depth or coverage. Never both. And that choice is exactly why so many climate risk exercises end up in a drawer.

The facts

  1. The disclosure requirement is site-level. ESRS E1 asks for physical climate risk. CSRD and VSME both ask you to disclose where your sites are, with coordinates and surface area. The EU Taxonomy asks the same question again for DNSH climate adaptation.
  2. But compliance is no longer what drives the request. What reaches us now is business continuity, capex planning, investment screening and insurance. The disclosure falls out as a by-product.
  3. The volume needed varies enormously. An investment company assesses 10 to 20 locations a year, at the moment of investing. An industrial group has 70 assets. A bank has asked us about thousands of locations. A network operator asked about millions. A method that only works at one of those scales isn't a method.
  4. Careful assessments go out of date faster than they can be redone. One manufacturing group showed me a thorough physical risk study, done site by site, exactly the way you would want it done. Two acquisitions and a reshuffle later, it described a company that no longer existed. Nothing was wrong with the work. It simply couldn't be repeated at the pace the business changed.
  5. Screening tools fail for a simpler reason: a pin has no surface. A modelled flood depth of 60 cm at the front gate says nothing about the loading bay 200 metres away that sits half a metre lower. A site that is 85% sealed with three halls and two tanks behaves nothing like a meadow of the same size. Point tools score them identically.
  6. In Belgium the good data is already public. Flanders, Wallonia and Brussels publish flood hazard mapping at roughly two-metre resolution, plus high-resolution terrain models, groundwater vulnerability, erosion and karst inventories. That is one to three orders of magnitude finer than the global grids most tools default to. It's free. It's just laborious to work with.
The accuracy problem was never a modelling problem. It was a labour problem.

Why nobody solved both

Because the accurate version was manual. Someone had to find the sites, establish what each one actually occupies, read the building data, pick the right hazard layer for that region and write down where every number came from. Careful work, done by people who knew what they were doing, and there was no way to do it faster.

But every one of those steps is a rule. And anything you can write down as a rule, you can run ten thousand times.

What we built

Karomia Peril turns a company name into a site-by-site picture of physical climate risk. It runs end to end from public authoritative sources, on fixed rules, so the same company assessed twice gives the same answer. Six questions, in order, because each one constrains the next.

  1. Where does the company actually operate? --> The site register
  2. What is the site, on the ground? --> A risk-area geometry per site
  3. What stands on it, and how much is built? --> The physical inventory
  4. Which protected or regulated zones does it touch? --> The designation screen
  5. What do the hazards measure here, now and in 2050? --> The measurement record
  6. How severe is that, on a comparable scale? --> The 0 to 5 score matrix

"Which sites?" turns out to be the hard question. Sites open, close, get acquired, and sit under a different legal entity than the one on the lease. Most companies can't produce a clean list on request, and the ones that can are often wrong. So we don't ask for yours. We build it from the legal entity itself, out of public records, and hand it back for you to correct. Nearly every assessment surfaces something: a site the ESG team never had, or one that closed two years ago and is still on the books.

A hazard score is only meaningful over a surface. An address is a point. A business is a perimeter. Before measuring anything, we establish what each site actually occupies on the ground, anchored in the land register rather than in a radius we invented. This is the step other tools skip, and it's why two plants on the same street can come out with genuinely different numbers. You see the perimeter on a map, and you can adjust it if we got it wrong.

Exposure is not the same as risk, and what stands on the site is the difference. Sixty centimetres of water across a hard-standing yard with three halls on it is a different event from sixty centimetres across a meadow. So we take stock of what physically occupies each perimeter, from official building and topography data rather than from assumptions about building type. That is what turns a rainfall figure into a statement about a site that can't drain.

Regulators ask two different questions about a location, so we answer both. Alongside the hazards, we screen each site's regulatory and environmental surroundings: biodiversity, water protection, pollution, heritage, geohazards. Whether you sit inside a designated zone, or how far you are from the nearest one. That's what E2, E3, E4 and your EU Taxonomy DNSH answers need, and it comes out of the same run.

You need a number you can plan against, not a weather report. Every hazard is measured over the perimeter at three horizons: today, 2050 under SSP2-4.5, and 2050 under SSP5-8.5. Where a region publishes better data than the world does, we use the regional data. Where nobody does, we fall back on the standard international reference sets, and on multi-model projections rather than a single model, because a single model is an opinion.

The point of a scale is comparison. Everything lands on one 0 to 5 scale, Negligible to Extreme, so hazards, sites, countries and time horizons can be lined up against each other and rolled up to portfolio level. The translation from measurement to score is deterministic: same input, same score, no judgement in the middle. The rules are ours, and we'll open them for review under the right agreement. That's a different thing from not having any.

On real sites, this is what changes

A distribution group asked us to run a European plant and a US Midwest facility side by side. Same company, same scale, same standards.

The European site is a water story. Fluvial flooding and extreme rainfall dominate today, and precipitation change is what moves by 2050. The Midwest site is a storm and heat story. Severe storm is already at the top of the range and stays there, heat stress climbs sharply under the high-emissions pathway, and cold stress, currently a real operating constraint, fades.

Two sites. Two completely different capex conversations. A portfolio average would have hidden both.

It's also why we ship the raw metrics next to the scores. One CFO didn't want to discuss her score at all. She wanted to know what it costs in lost workdays. You can only answer that from the measurements underneath.

A score you can't take apart is a score you can't defend.

Automated, and still yours to challenge

Everything in the assessment is machine-produced. That's what buys the scale. It's also exactly why the review path matters.

In the portal you can raise a point of attention on any site, any measurement, any score, so the question sits against the figure instead of disappearing into an email thread. You can correct what a finding depends on: drop a site, add one we missed, change the parcels that make up a perimeter, and everything downstream recomputes, with the change and its author on the record. And the AI assistant holds the full evidence trail, so you can ask why one site scores higher than another and get an answer grounded in the data rather than a confident sentence.

You get every site with its cadastral references and the source it came from, the protected-zone screen, the score matrix, and every raw metric behind every score. On request, the site geometries as GeoJSON for your own GIS or your insurance file, the physical inventory per site, and a written risk narrative per site you can use as the drafting basis for E1.

Frequently asked questions

What is a physical climate risk assessment?
An assessment of how exposed a company's locations are to hazards such as flooding, heat, drought, wind and wildfire, under current climate and future scenarios. Required for ESRS E1 under CSRD, and it feeds the EU Taxonomy DNSH climate adaptation criteria.

Which scenarios and horizons do you use?
Current climate, plus 2050 under IPCC AR6 scenarios SSP2-4.5 and SSP5-8.5.

Which hazards are covered?
Fluvial, pluvial and coastal flooding, extreme precipitation, heat stress including urban heat island, winter weather, chronic wind and windstorm gusts, drought, groundwater stress, erosion, subsidence and karst, landslide, earthquake, wildfire. Screened per site and kept where physically relevant.

Do I need to give you my site list?
No. We build it from the legal entity and you correct it.

Does it work outside Belgium?
Yes. Belgian sites benefit from two-metre regional data; elsewhere we use international reference datasets and note the coverage per country. The methodology has been applied in the US, Canada and India, among others.

Can I see the methodology?
The full method, thresholds included, is available for review under the appropriate agreement. Every number in the output already names the dataset behind it.

Give us a company name

The data is public. The scenarios are published. What made this expensive was never the knowledge. It was the hours.

Send us your legal entity and we'll show you the sites we find, the perimeter we resolve for each one, and what the hazards measure there today and in 2050.

Book a demo β†’

‍

‍

Sign up for our newsletter

Receive updates and best practices on all things ESG reporting each month.

Read More

CSRD
Here

How sustainability data collection finally works

The hardest part of a group ESRS report is not writing it. It is getting the numbers out of 32 entities in four languages. Here is how Karomia collects and consolidates them.

View
View
Here

The underestimated cost of the energy crisis

Gas prices up 85% in Belgium. Do you know what the Middle East energy crisis costs your business? Calculate your fossil fuel exposure and run your own energy cost scenarios.

View
View
Karomia
Here

Karomia’s sustainability intelligence

Turn sustainability into a competitive advantage. Discover Karomia’s sustainability intelligence system for sustainability reporting, risk mapping, decarbonization, and real business impact.

View
View