Which Sites, Suppliers, and Routes Belong in Your Climate Risk Screen?


Most climate risk screens run on a list nobody can justify: the sites someone happened to have addresses for. This is a method for deciding what belongs in a climate risk screen, how to rank what makes the list, and how to defend the choice a year later when an auditor asks why those places and not others.

In July 2026, midway through a peak e-commerce sale season, persistent rain across Maharashtra cut the roads into warehouse estates around Pune. Buildings that took no water at all stopped dispatching anyway, because their approach roads had. Inventory movement and last-mile delivery slowed across the state, at operators whose own premises were never touched. The disruption was regional, and it ran through the routes rather than the sites.

Read that closely, because it is a pattern and not a one-off. The rain did not need a river. A saturated slope damaged a building, and standing water on the surrounding roads stopped the goods that survived. For anyone running a screening program, the uncomfortable question is not whether Pune had a hard monsoon. It is whether your own program would have had those roads, that slope, and those warehouses on its list at all.

Every climate risk screen starts with a list of places. Forty sites, two hundred suppliers, a handful of ports. Ask the team who built the list why those places and not others, and the answer is usually some version of “those are the ones we had addresses for.”

That answer fails twice. It fails the CFO who is asked to fund the screening program and wants to know the money is pointed at the exposure that matters. And it fails the assurance practitioner who, a year later, samples the disclosed figure and asks how the scope was set. “The addresses we had” is not a scoping method. It is an accident of data availability.

The scoping method in six rules

  • Scope the node, not the counterparty. Climate risk attaches to coordinates and to the connective tissue between them, not to a legal entity. One supplier is several nodes; one node can serve many suppliers.
  • Owned sites are a sequencing problem. Include all of them. The framework sets escalation order, not inclusion.
  • The value chain is a discovery problem. Walk the bill of materials to the producing plant, not the vendor master to a billing address.
  • Priors order the queue; they never shorten the list. Excluding a node on hazard intuition pre-decides the answer the climate risk screen exists to give.
  • Routes fail differently from sites. A facility fails at a point; a route fails at its worst 200 metres.
  • A result that never becomes a risk register entry is shelfware. File it as a continuity risk, not an environmental one. An environmental risk gets a policy; a continuity risk gets capex.

This piece is a method for building the list. It sits upstream of the screening itself: how to run a screen across a supply chain is covered in our screening guide. Here the question is narrower and comes first. Which places belong on the list, in what order, and how do you defend the choice in writing?

Climate risk attaches to places, not counterparties

Supplier due diligence has a mature playbook, and it is built around the counterparty. You assess the legal entity: its financial health, its quality system, its certifications, its answers to a questionnaire. You organize the work by contractual proximity, Tier 1 first, then as far down the tiers as visibility allows.

Climate risk does not attach to the counterparty. It attaches to coordinates and to the connective tissue between them: the access road, the port, the rail corridor, the last kilometer between a warehouse and the highway. No questionnaire tells you whether a supplier’s access road sits in a low spot that fills with water.

This shifts the unit of analysis. The object you scope is not a supplier but a node: a specific place your operation depends on. The mapping between the two is many-to-many. One supplier is several nodes, its plant, its warehouse, its outbound port. And one node can serve many suppliers: a shared container terminal may carry more of your continuity exposure than any single supplier on your list, while appearing in no supplier file at all, because nobody’s due diligence owns it.

Standard screening tools miss this in two distinct ways, and it is worth keeping them separate:

  • The maps miss the mechanism. River and coastal flood layers model rivers and coasts. Surface-water flooding, where intense rain overwhelms local drainage and ponds on the terrain, is not in them. A location can sit outside every mapped floodplain and still flood in an intense storm. In one United States test grid, a riverine flood projection rated every one of ten Texas locations Low, including Houston, a city with 178 recorded flood episodes in a research dataset of 2.6 million flood events compiled from news reports. That is not a data error. Riverine projection metrics track discharge on mapped rivers, and most urban flooding is not that.
  • Point screens miss the geometry. A facility fails at a point, so screening its coordinate works. A route is a line, and its exposure is the worst 200 meters along it: the underpass, the low causeway, the culvert crossing. Roads are graded, paved, and deliberately routed through the terrain features that flood first. Screening the endpoints of a route and calling it covered is like checking both ends of a bridge and vouching for the middle.

The combined effect is the scenario every operations lead recognizes: the supplier’s warehouse is fine, and the goods still do not move, because the entry and exit are under water. In an internal modelling experiment on an industrial estate near Pune, we rained a 100 millimeter design storm onto open terrain data with building footprints added. The warehouse location itself stayed dry and roughly 95 percent of the water drained away. The remaining water collected in one pond, about 1.4 meters deep, sitting 130 meters from the warehouse on its approach. A point screen at the warehouse reads clean. The route to it stands well over a meter under water.

Climate risk screen: a 100-year design storm rained onto Houston lidar terrain, water collecting in the streets while buildings stand clear
A 1-in-100-year design storm (NOAA Atlas 14) rained onto measured lidar terrain in a Houston neighbourhood, with building footprints represented. The water collects in streets and low points while most structures stand clear. River and coastal flood maps say nothing about this mechanism. Model output is a screening-grade experiment: it conserves every drop of rainfall but assumes drains are overwhelmed, and it has not been validated against observed flood footprints. Terrain: USGS 3DEP. Rainfall: NOAA Atlas 14. Building footprints: OpenStreetMap contributors. Source: Continuuiti.

Owned sites are a sequencing problem; the value chain is a discovery problem

A risk-based approach to scoping sounds like one principle, but it is two different problems wearing one name.

For the sites you own, screening is cheap. You have the addresses, the asset registers, and the authority to act. There is no good reason to leave an owned site out of a screen, so the framework’s job for owned sites is not inclusion. It is sequence and depth: which sites get escalated first when the screen flags them.

The value chain is different, because there the cost comes before the screen. You cannot screen a node you have not identified, and identifying value-chain nodes takes real work: finding out which supplier plant actually makes your part, which port your inbound freight actually clears, which distribution center actually serves your largest market. Every node costs discovery effort before it costs a screening fee. Nobody can enumerate the whole world, so for the value chain the framework governs inclusion itself: which nodes earn a place on the list at all.

Generic advice to “take a risk-based approach” skips this asymmetry, and programs built on it drift into the failure mode from the opening: the list becomes the addresses that were easy to get, not the places that can stop the line.

Walk the bill of materials, not the vendor master

The node list does not exist in any single system, and it cannot be exported. The vendor master gives you legal entities and billing addresses, which are neither nodes nor, often, even the right city. The list has to be assembled, and the assembly is cross-functional by nature:

  • Procurement holds the supplier relationships, the contracted plants, and the delivery terms.
  • Logistics holds the carriers, the lanes, and the ports and terminals freight actually moves through.
  • Business and sales teams know which customer commitments a given lane serves, which is what turns a node into money.

The method that makes this tractable is to walk backwards from value, not forwards from the supplier list:

  1. Rank your products by margin contribution and take the top set.
  2. Walk each product’s bill of materials to its sole-source and hard-to-substitute components. These are the parts that stop the product.
  3. For each such component, identify the actual producing site. Not the supplier’s headquarters: the plant.
  4. Trace the lane from that plant to yours: the port of export, the port of entry, the corridor, the distribution center.
  5. Validate the trace against records that do not rely on anyone’s memory: customs and import filings show the real ports of entry, and freight-forwarder data shows the real lanes.

Delivery terms deserve one specific note, because they mislead people in exactly this exercise. Incoterms, the standard trade terms that assign freight responsibility, determine who manages a shipping leg and who insures the goods in transit. They do not change whose production line stops when the leg is blocked. A component bought delivered-duty-paid still does not arrive when the port is flooded. Scope the node by dependency, not by whose name is on the freight contract.

There is a side effect of doing this properly, and it is worth noticing: the exercise forces procurement, logistics, and the business into one room around one artifact. That table will matter again later in this piece.

Classify nodes with the criticality rubric you already have, plus two columns it lacks

Once the nodes are on the list, rank them. Our screening guide sets out a five-dimension criticality rubric for exactly this: substitutability, spend and revenue dependence, tier and recovery lead time, strategic input, and buffer, scored on a disclosed zero-to-two scale, with priority set by criticality times exposure. That rubric carries over to scoping unchanged, and there is no need to reinvent it. If your business-continuity team has run a business impact analysis, an assessment of which processes matter most and how fast they must recover, much of the substitutability and recovery data already exists. Ingest it; do not rebuild it.

Scoping adds two columns the supplier-oriented rubric does not carry:

  • Route criticality. A route scores like a node, with one geometric difference: its exposure is the maximum along the path, not the value at either end. In practice a route audit that simply enumerates the underpasses, low causeways, and river crossings on a corridor captures much of the risk, because those are the engineered low points that flood first. Pair the path maximum with the route’s own substitutability: is there an alternate corridor, and at what cost and delay?
  • Decision timing. A screen is worth more where a decision is live. A lease renewal, a pending capital investment, an insurance renewal, or a new-supplier qualification is a moment when screening information can actually change an outcome. Nodes attached to live decisions move up the queue.

Here is the shape of the output, using a stylized manufacturer’s footprint as the worked illustration. The company is not real, and the figures are illustrative. Its footprint of ten locations already spans the layers: seven owned plants, one just-in-time Tier-1 supplier in Thailand, one vehicle export terminal in Germany, and one Gulf Coast logistics distribution center. The scoping pass adds routes, and the table below shows five representative rows:

Node Layer Criticality (0 to 2) Why Screen tier
Casting plant, coastal India Owned site 2.0 Sole casting source; six-month requalification Screen now, escalate first
JIT supplier, Thailand Tier-1 supplier 2.0 Just-in-time; hours of buffer; prior regional flood history Screen now, escalate first
Vehicle export terminal, Germany Logistics node 1.5 All European finished vehicles ship through it; alternate port adds days Screen now
Plant-to-port road corridor, western India (illustrative, constructed for this example) Route 1.5 Path crosses two low causeways; alternate corridor adds a day Route audit + screen the waypoints
Regional sales office Owned site 0.5 Fully substitutable within days Screen in the annual batch

The two top-priority rows are not the highest-hazard rows. Nobody has run a hazard screen yet. They are the highest-criticality rows, and that is the point of scoping: criticality is decided before the hazard data arrives, so the hazard data cannot quietly become the reason a node was left out.

Sample Climate Risk Assessment

See what a screened site actually looks like

We’ll email you a complete worked example for a manufacturing site: 12 hazards, multiple scenarios, and value-at-risk out to 2050. It shows what lands on a node once it clears your scoping list.



Priors can order the queue; they must never shorten the list

There is a strong temptation, once the list is built, to prune it with geography: skip the inland sites for flood, skip the temperate sites for heat, screen only the coasts. Resist it. Using hazard intuition to exclude nodes is pre-deciding the answer the screen exists to give, and it is precisely the move a skeptical reviewer, or an assurance practitioner, will catch. The Texas example above is the cautionary tale: the intuition “no river, no flood risk” is wrong for much of the flooding the observed record actually contains.

Priors have a legitimate job, and it is ordering, not exclusion. If the queue must be sequenced, sequence it with the terrain features that predict exposure:

  • Slope and relief, first. Flat terrain is the single strongest predictor of surface-water ponding. In our modelling experiments, the share of a storm’s volume that stayed on the terrain ranged from roughly a third on a flat former lakebed to about one part in twenty on a high-relief plateau, under the identical storm and method.
  • Local depressions. Low points hold water by definition. On flat urban terrain, a surprising share of a large storm stays ponded even when every edge of the model drains freely.
  • Underpasses and grade-separated crossings, for routes. They are engineered low points and they flood first, every time.
  • Impervious cover. Pavement and rooftops shed water faster than it can drain, and dense building fabric creates additional small basins between structures.
  • Drainage capacity is real but unknowable at screening grade. The age and capacity of a city’s storm drains decide real outcomes, and no screening dataset contains them. State that as an unmodeled uncertainty. Do not pretend to score it.

For surface-water flooding specifically, the defensible screening posture is a flag and a comparison, not a depth. The flag is susceptibility from the priors above. The comparison is a trend: projected extreme-rainfall intensity set against the rainfall that has actually flooded the area in the observed record. If the projections push more days past the observed trigger, that is a concrete escalation signal. What no screen can defensibly give you at this grade is a surface-water flood depth or a loss figure, which is why:

Modelled flood depths and any loss figures built on them cover river and coastal flooding only. Surface-water flooding, where intense rain overwhelms local drainage, is screened as a susceptibility flag rather than a depth, because a defensible surface-water depth needs finer terrain and local drainage detail than a portfolio-grade screen can support.

Escalate past the flag when one of four things is true: you need a depth or a loss number; you need a segment-level route decision, such as which of two gates or corridors to invest in; a high-consequence node shows conflicting priors; or the node sits in a dense city where the engineered drainage network, not terrain, decides the outcome. Escalation means fine-terrain surface-water modelling and a local drainage study, which is a site deliverable, not a screening one.

A screen result becomes a risk register entry, or it becomes shelfware

The output of scoping and screening is not a report. Reports get filed. The output that survives is a set of entries in the corporate risk register, one per material node, each carrying:

  • The classification: the node, its layer, its criticality score, and the hazard flags against it.
  • An owner. A named person whose register it is, not a function.
  • A review cadence, and a trigger clause: re-review after any major event near the node, and on the node’s decision dates (the lease, the renewal, the qualification).
  • Treatment options priced in advance, so the review is a decision and not a research project: qualify an alternate supplier, pre-position inventory buffer, secure an alternate route or port, invest in site defense, or exit the exposure.

The register is also where the scoping work pays back a second time. The business impact analysis you ingested for substitutability data has a natural return path: the climate screen gives the continuity team a hazard-aware reason to update recovery time assumptions they may have set years ago.

Reclassify climate risk from environmental to continuity, and the budget changes

Now the organizational question, because method without an owner is a document.

At most manufacturers, the climate screen is produced by the sustainability team, because that is where the data capability and the disclosure deadline live. The risk register is owned by risk management or the continuity function. In between sits a filing decision that quietly determines whether any of this work matters: what kind of risk is a flooded access road?

Filed as an environmental risk, it lands in the register’s compliance neighborhood: owned by the environment, health and safety function, scored low, reviewed annually, and answered, if at all, with a policy. Filed as a continuity risk, the same hazard reads as days of line-down and margin at risk, and it competes for the same attention and capital as any other threat to production. An environmental risk gets a policy. A continuity risk gets capex.

The reclassification is the chief sustainability officer’s move to make, and it does not require claiming a seat at the enterprise-risk table. It requires arriving with the register’s native currency. A sustainability team that hands risk management a report has produced information. A sustainability team that hands risk management classified nodes, each with an owner candidate, a criticality score, treatment options, and an escalation trigger, has produced register entries, and register entries are the format in which the risk function can actually act. That, concretely, is how a sustainability function stops being a reporting cost center and becomes an input to how the company allocates capital.

Make it operational, not aspirational: the cross-functional table that built the node list reconvenes twice a year; the artifact that changes hands is the classified node list with its screen results; and the register owner, not the sustainability team, presents the climate entries to the risk committee, because risks presented by their owners get funded.

Free Climate Risk Report

Run a free climate risk report on one node

Pick the node at the top of your list. 12 hazards across multiple emission scenarios and four time horizons, for any location. Start free, no call required.



Write down why you chose the scope

Everything above is a chain of judgments: which products anchored the walk-back, where discovery stopped, what threshold separated the screen-now tier from the annual batch, which priors ordered the queue. Judgments are defensible. Undocumented judgments are not.

The disclosure standards themselves expect a scoped, proportionate approach, which means the scope rationale is not an apology, it is the method working as designed. IFRS S2 asks preparers to use reasonable and supportable information available without undue cost or effort (paragraphs 11 and 30), states that greater exposure warrants more sophisticated analysis (paragraph B4), and treats publicly available authoritative data as the expected first pass (paragraph B11). It also asks where risks are concentrated by geography, facility, and asset type (paragraph 13(b)), which a criticality-ranked node list answers directly.

The European standard reaches a similar shape by a different mechanism: ESRS requires the physical-risk process to cover own operations and the upstream and downstream value chain, limits value-chain disclosure to what is material, and allows estimation with proxies after reasonable efforts. The two regimes are not interchangeable, and it is worth not blurring them in a disclosure: the ISSB test is undue cost or effort; the ESRS mechanism is reasonable efforts plus proxies plus a phase-in. But both endorse the same practical posture: a defensible scope, screened broadly, escalated where material.

So write the scope memo at decision time, not at audit time. One page: the perimeter, the discovery method, the criticality threshold, the nodes excluded at the boundary and why, the priors used for sequencing, and the standing rule that priors never exclude. Dated, owned, and revised when the scope changes. A year later, when someone asks “why those forty sites,” the answer is a document instead of a reconstruction.

The one-page scoping worksheet

The method, compressed. Run it once a year and at every acquisition, footprint change, or major sourcing shift.

  1. Perimeter: list the four layers: owned sites, suppliers Tier 1 to N, logistics nodes, and non-substitutable external dependencies.
  2. Owned sites: include all of them. The framework sets escalation order, not inclusion.
  3. Discovery: take the top products by margin; walk each bill of materials to sole-source components; identify producing plants, not headquarters; trace lanes to ports of entry; validate against customs and forwarder records.
  4. Routes: for each critical lane, enumerate underpasses, low causeways, and crossings; note the alternate corridor and its cost.
  5. Classify: score every node on the five criticality dimensions plus route geometry and decision timing; ingest the business impact analysis rather than rebuilding it.
  6. Tier: criticality sets the screen-now, screen-annually, and monitor tiers. Hazard data has not entered yet, by design.
  7. Sequence with priors, never exclude with them: slope, depressions, underpasses, impervious cover. Drainage capacity is an unmodeled uncertainty, stated.
  8. Screen the list; treat surface-water risk as a flag plus a trigger-exceedance trend, never a screening-grade loss figure.
  9. Register: convert material results into risk register entries with owners, cadences, triggers, and pre-priced treatments. File them as continuity risks.
  10. Scope memo: one page, dated, recording the judgments above. Revise on change.

A screen is only as defensible as its list. Build the list on dependency rather than data availability, write down the judgments, and the screening program stops being an exercise you hope nobody examines and becomes one that survives examination.

If you want to see what the screen itself looks like once the scope is set, our screening guide walks the method end to end, and the manufacturing worked example applies it to a full portfolio from coordinates to value-at-risk.

Sources

  • IFRS S2 Climate-related Disclosures (ISSB). Paragraphs 11 and 30 (reasonable and supportable information without undue cost or effort), 13(b) (concentration by geography, facility and asset type), B4 (analysis proportionate to exposure) and B11 (publicly available authoritative data).
  • ESRS E1 under the Corporate Sustainability Reporting Directive (EFRAG). Physical-risk process across own operations and the upstream and downstream value chain; estimation with proxies after reasonable efforts.
  • NOAA Atlas 14 Precipitation-Frequency Atlas of the United States (NOAA National Weather Service). Design-storm depths used in the Houston experiment.
  • USGS 3D Elevation Program (3DEP) (United States Geological Survey). Lidar terrain used in the Houston experiment.
  • Building footprints from OpenStreetMap contributors, available under the Open Database License (ODbL).
  • Groundsource flood-event dataset (Google Research, preprint). The source of the 2.6 million flood events and the 178 Houston episodes cited above.

Frequently asked questions

How do you decide which sites to include in a climate risk assessment?

Include every site you own, without exception, because screening a location you already have an address for is cheap and leaving one out is hard to defend. For the value chain, work backwards from value rather than forwards from the supplier list: rank products by margin, walk each bill of materials to its sole-source components, identify the plant that actually makes them, and trace the lane from that plant to yours. Inclusion is decided on dependency, not on which addresses happened to be available.

What is a risk-based approach to climate screening?

It means ranking nodes by how much damage their loss would do before any hazard data arrives, then letting that ranking decide screening order and depth. Criticality covers substitutability, revenue dependence, recovery lead time and buffer. The common mistake is to use hazard intuition to shorten the list instead, skipping inland sites for flood or temperate ones for heat, which pre-decides the answer the climate risk screen exists to give.

Should suppliers be included in a physical climate risk assessment?

Yes, and so should the logistics nodes between them. Climate risk attaches to places rather than to counterparties, so the object you scope in a climate risk screen is the node, not the legal entity. A supplier’s plant, its warehouse and its outbound port are three nodes. A shared container terminal can carry more of your continuity exposure than any single supplier while appearing in no supplier file at all, because nobody’s due diligence owns it. Both IFRS S2 and ESRS E1 extend physical-risk identification across the value chain.

Who owns climate risk, sustainability or risk management?

In most manufacturers the screen is produced by the sustainability team and the risk register is owned by risk management, and the filing decision in between determines whether anything happens. Filed as an environmental risk it is scored low, reviewed annually and answered with a policy. Filed as a continuity risk it reads as days of line-down and margin at risk, and competes for capital like any other threat to production. Handing over classified nodes with owners, criticality scores and pre-priced treatments, rather than a single composite score or a report, is what makes the risk function able to act.

Govind Balachandran
Govind Balachandran

Govind Balachandran is the founder of Continuuiti. He writes extensively on climate risk and operational risk intelligence for enterprises. Previously, he has worked for 7+ years in enterprise risk management, building and deploying third-party risk management and due diligence solutions across 100+ enterprises.