How to Screen Climate Risk Across Your Supply Chain: A Practitioner’s Guide

A practitioner's method for screening physical climate risk across a supply chain: define the perimeter, rank by materiality, quantify the material subset, and read the output.


Climate Risk Across Your Supply Chain: A Practitioner’s Guide

Your factory has a roof, a fence, and an insurance policy. Your supply chain has none of those. It is a web of suppliers, ports, and routes you depend on but do not own, and a flood, a heatwave, or a cyclone at any node can stop your line as surely as one at your own gate. The uncomfortable truth for anyone running a global operation is simple: most of your climate risk lives in places you do not control and often cannot see.

This guide is a practitioner’s method for finding that risk before it finds you. It covers physical climate risk only, the direct hazards of a warming climate to the continuity of your operations. It is the inside-out question: how could climate change disrupt the suppliers, sites, and logistics you rely on. The outside-in question, your operations’ impacts on nature and the risk of deforestation in your sourcing, is a separate discipline with its own rules, and we treat it in a companion guide.

The method here is deliberately tool-agnostic. It names the best available science and datasets, but the discipline matters more than any single platform. Screen broad and cheap, escalate narrow and deep, and read the results like someone who knows where the models bend.

Screening is not assessment, and confusing them is the first mistake

You cannot deep-assess five thousand suppliers. Nobody can. A site-specific study, the kind an engineer signs, takes weeks and real money per location. Run that on your whole network and you will finish the first hundred sites after the climate has already moved.

So the practitioner does two different things, in order:

  • Screening is a broad, cheap, consistent first pass over every location that matters. It ranks. It tells you which suppliers and nodes deserve a closer look and which are, for now, quiet.
  • Assessment is the deep, site-specific study you commission for the handful of locations the screen flags as both material and highly exposed.

This is not a shortcut. It is what the disclosure standards themselves expect. IFRS S2 says the greater your exposure, the more sophisticated the analysis should be (paragraph B4), and it asks only for the information available without undue cost or effort (paragraphs 11 and 30). The European standard reaches the same place by a different route: it limits value-chain reporting to what is material (ESRS 1 paragraph 64) and lets you estimate with proxies where primary data is not reasonably available (paragraph 69). Screen-then-escalate is the standard-endorsed shape of the work, not a corner cut.

The rest of this guide is the screening method, step by step.

Screening Assessment
Scope Every location that matters, in one pass The handful the screen flags as material and highly exposed
Depth Broad, cheap, consistent first pass Deep, site-specific study, the kind an engineer signs
Cost and speed Cents to dollars a site, minutes Weeks and real money per location
Output A rank: which nodes deserve a closer look A defensible number for a single site
Data Coarse (~25 km) climate data plus global hazard layers Site survey, local hydrology, and the adaptation actually in place
When Across the whole network, first Only after screening, on the material subset

The short version

  • Screening is not assessment. Screen every location broadly and cheaply to rank them; commission a deep, site-specific study only for the few that are both material and highly exposed.
  • Define the real perimeter. Your risk lives past Tier 1: sub-tier suppliers, the logistics network, and external dependencies you cannot substitute.
  • Get the coordinates right first. A screen built on city centroids is a random one. Reject low-precision geocodes before spending anything downstream.
  • Rank by criticality, not just hazard. The priority is criticality times exposure. A Moderate rating at a single-source Tier 1 beats a Severe rating at a supplier you can replace in a week.
  • Flood runs to a dollar figure; heat runs to a flag. Flood prices to expected annual damage. Heat damages throughput, not structure, so it is an exposure flag at the screen and a business-interruption number only after escalation.
  • Read past the composite. An averaged score hides the one hazard that would shut a site down, and a zero can mean dry, unmapped, or a baseline carried forward. Know which.

Define the perimeter: your risk lives in places you do not own

Before you screen anything, decide what “your supply chain” actually includes. Most programs draw the line too tight and miss the risk that matters.

The real perimeter has three layers, and a fourth that people forget:

  1. Your own operating sites. Plants, warehouses, offices. The easy part, because you have the addresses and you control the assets.
  2. Your suppliers, Tier 1 to Tier N. Tier 1 are the suppliers you buy from directly. Tier N is the long tail behind them: your supplier’s supplier, and theirs. Visibility collapses fast past Tier 1, which is exactly why the risk hides there. The single mine, smelter, or specialty-chemical plant that half your industry depends on is usually three tiers deep.
  3. The logistics network. Ports, container terminals, airports, rail yards, inland waterway nodes, and the distribution centers between them. This is the layer most climate screens ignore entirely, and it is where a coastal flood or a cyclone does the most damage to flow.
  4. Critical external dependencies you cannot substitute. The power grid your Tier 1 runs on. The water utility that feeds a foundry. The one deep-water port your finished vehicles ship through. You do not own these, and you often cannot switch them, which makes their exposure yours.

The perimeter runs downstream too, not only upstream. If a flood closes the distribution center that serves your largest market, your revenue stops even though every plant is dry.

The frameworks agree the perimeter is this wide. IFRS S2 defines the value chain to include an entity’s “geographical, geopolitical and regulatory environments” and its distribution channels, not just its direct suppliers. The European standard is more explicit still: it asks you to assess physical risk using the geospatial coordinates specific to your “locations and supply chains” (ESRS E1, application requirement 11(c)). The outer boundary in both is materiality, which is the next step.

Supply chain climate risk screening perimeter: own operating sites, suppliers Tier 1 to Tier N, the logistics network, and critical external dependencies
The perimeter a screen has to cover: your own sites, suppliers from Tier 1 to Tier N, the logistics network, and the external dependencies you cannot substitute. Source: Continuuiti.

Get the coordinates right, or nothing downstream is real

Here is the failure mode nobody warns you about: the whole method rests on turning a list of supplier names and addresses into accurate map coordinates, and that step quietly breaks more screens than any model does.

Physical climate hazards are intensely local. A coastal warehouse and a site fifty kilometers inland face completely different flood, surge, and sea-level exposure even though they share a city name. If your geocoder resolves “Acme Components, Shenzhen” to the centroid of Shenzhen, you have screened a point in a downtown district that has nothing to do with the actual plant in an industrial zone by the water. The number you get back is confident and wrong.

So the practitioner treats geocoding as a gated first step, not a formality:

  • Reject low-precision matches before spending anything downstream. A match at city or region level is not a site. Flag it, send it back for a better address, and do not run the expensive hazard chain on a centroid. Good geocoders return a precision or match-type signal; use it as a hard gate.
  • Geocode the asset, not the name. For a port, terminal, or distribution center, you want the coordinates of the physical facility, not the administrative place it sits in. Named-facility geocoding matters more than street-address parsing for logistics nodes.
  • Check coverage and hygiene. Deduplicate the list, standardize country codes, and confirm you actually got a hit for every location. A silent geocoding failure drops a supplier out of the screen entirely, which reads as “no risk” when it means “no data.”

A screen built on bad coordinates is not a conservative screen. It is a random one. Spend the effort here first.

Supply chain climate risk screening: site elevation and terrain view showing 3D relief and the low-lying channels that drive local flood exposure
Physical hazards are intensely local: a 3D terrain view showing the low channels that drive flood exposure near a site. Illustrative single-site view; elevation from NASA SRTM. Source: Continuuiti.

Materiality first: rank by criticality, not just by hazard

Once you have clean coordinates, resist the urge to run every location and sort by hazard rating. Exposure alone is not a finding. A Severe flood rating at a substitutable Tier-3 commodity supplier you can replace in a week is not the same problem as a Moderate rating at your single-source Tier-1 whose part halts a production line worth a million dollars a day.

Materiality is the filter that turns a hazard list into a priority list. For each supplier or node, weight its criticality along the dimensions that actually drive business interruption:

  • Substitutability. Single-source or dual-source? How many qualified alternatives exist, and how fast could you switch?
  • Spend and revenue dependence. How much of your cost base or revenue flows through this node?
  • Tier and lead time to recover. A deep-tier input with a six-month requalification cycle is more dangerous than a Tier-1 you can re-source in days.
  • Strategic input. Does a small, cheap component gate a large, expensive output? A ten-dollar part that stops a car is a critical dependency regardless of its price.
  • Buffer. How much inventory or slack sits between this node and your customer?

Score criticality on a simple, disclosed scale, for example zero (not material) to two (critical dependency), and use it to weight the hazard screen. The priority that matters is criticality times exposure, not exposure by itself. A cheap, disclosed criticality rubric is what lets you screen ten thousand locations and still walk away with a defensible shortlist of the few dozen that deserve a real study.

Free Climate Risk Report

Run a free climate risk assessment for your location

12 hazards across multiple emission scenarios and four time horizons, for any site. Start free, no call required.



This criticality lens is also what the disclosure standards mean by concentration. IFRS S2 asks you to report where risks are concentrated by geography, facility, and type of asset (paragraph 13(b)). A criticality-weighted map across your suppliers and nodes is precisely that concentration view.

Supply chain climate risk screening materiality map: ten sites by twelve hazards, weighted zero to two by how much each site's operations depend on being spared each hazard
Rank by criticality, not just hazard: how much each site’s operations depend on being spared each of twelve hazards, scored zero to two. Illustrative manufacturing worked example, not a real company. Source: Continuuiti.

The hazards, mapped to supply-chain failure modes

A screen that reports “heat: High” is telling you almost nothing. The practitioner’s job is to translate each physical climate hazard into the specific way it breaks a supply chain. The mapping is the value.

Hazard How it stops your supply chain
Heat Worker productivity falls, outdoor and un-cooled indoor labor slows, process cooling and precision tolerances degrade, power demand spikes
Riverine flood Plant floor, inventory, and machinery inundated; road and rail access cut
Coastal flood and storm surge Ports, terminals, and coastal suppliers submerged; container operations halt
Sea level rise Chronic loss of low-lying coastal sites and port infrastructure over the asset’s life
Tropical cyclone and severe storm Direct damage plus multi-day shutdown of a coastal supplier or port
Water stress Process water rationed for foundries, semiconductors, food, and textiles; hydropower and canal-draft logistics constrained
Drought Agricultural inputs fail; inland waterway shipping loses draft
Extreme rainfall Pluvial (surface-water) flooding of sites that sit outside any river floodplain
Wildfire Direct loss plus road, rail, and air disruption; smoke shutdowns
Landslide The single mountain road or rail line to a supplier severed
Temperature and precipitation change Slow shifts in operating conditions, cooling loads, and input availability
Cold stress Cold-snap disruption at temperate and continental sites

Two of these deserve special attention because they behave differently from the rest, and most screens handle them badly: flood, because it is the one hazard you can put a credible dollar figure on at scale, and heat, because it is the most widespread hazard and the one a loss-based screen misses entirely. Both are the subject of the next section.

The underlying science for the hazard ratings is downscaled global climate projection, most commonly the CMIP6 generation (for example the NASA NEX-GDDP-CMIP6 dataset), combined with hazard-specific layers: tropical cyclone tracks from NOAA IBTrACS, water stress from WRI Aqueduct, and terrain and land cover from global elevation and land-cover products. You do not need to run these yourself to use a screen, but you should know what sits underneath the rating and attribute it correctly.

Scenarios and horizons matched to the decision

Climate risk is not one future, it is a range, and a screen that gives you a single number is hiding the uncertainty you most need to see. Run at least two emissions scenarios, framed in plain terms:

  • A moderate scenario (for example SSP2-4.5, a shared socioeconomic pathway landing near 2.7 degrees Celsius of warming by 2100) for central planning.
  • A high scenario (for example SSP5-8.5, near 4.4 degrees Celsius) for stress testing.
  • Optionally a low, Paris-aligned scenario (SSP1-2.6, near 1.8 degrees Celsius) where a framework or a lender asks for it.

Match the time horizons to the decision, not to a default. A baseline (today), 2030, and 2050 view covers most planning, capital, and disclosure cycles. Push to later horizons only for long-lived assets whose life runs past mid-century.

The point of multiple scenarios is not precision. It is to see which exposures are robust across futures (act on those) and which only appear under the high scenario (watch those). A supplier that is exposed under every pathway is a different decision from one that is only exposed if the world takes the worst road.

Supply chain climate risk screening: worst-case hazard ratings across a portfolio under three climate scenarios from baseline to 2050
Worst-case hazard ratings across the portfolio under three scenarios to 2050, so you can see which exposures are robust across futures and which appear only under the high scenario. Illustrative manufacturing worked example. Datasets: NASA NEX-GDDP-CMIP6, WRI Aqueduct. Source: Continuuiti.

From exposure to quantification: escalate the material subset

A hazard rating tells you where to look. It does not tell you what a hit would cost. For the material, highly exposed subset the screen surfaces, the practitioner escalates from a rating to a number. Two hazards carry most of the quantifiable loss, and they run on completely different tracks.

Flood runs to a loss figure

Flood is the one hazard the field can price at scale, because there is a mature, published chain from depth to dollars:

  1. A global flood layer (for example JRC GloFAS, a Fathom-class model, or WRI Aqueduct) gives you a flood depth at the site for a set of return periods. A return period is the average interval between events of a given size, so a 1-in-100-year flood (RP100) has a one percent chance of being equalled or exceeded in any year.
  2. A depth-damage function (the JRC Huizinga global curves, or FEMA HAZUS in the United States) converts that depth, plus the building type and value, into a damage ratio and a monetary loss.
  3. Integrating loss across the return periods gives expected annual damage (EAD), the average yearly loss you would book over the long run. The clean way to compute it is a trapezoidal integration of loss against annual exceedance probability (the yearly chance a loss level is passed), which is just the area under the loss-probability curve.

EAD is the headline number for a flood screen: one comparable figure per site, summable across a portfolio, usable in a disclosure. State the assumptions behind it every time, the building archetype, the return periods used, and the tail assumptions, because those choices move the number.

Heat runs to business interruption, and it does not fit in the flood column

Heat is the most widespread climate hazard across almost any global footprint, and a flood-loss screen is completely silent on it, because heat does not damage the structure. It damages throughput. That makes it the single largest blind spot in most climate screens.

Heat business interruption has its own quantification chain, parallel to flood but built on different physics:

  • The intensity metric is not air temperature. It is wet-bulb globe temperature (WBGT), an occupational heat-stress index defined in ISO 7243 that combines temperature, humidity, wind, and solar radiation. Humidity is the dominant driver: a humid 32-degree day is far more punishing than a dry one, because sweat cannot evaporate.
  • The damage function maps WBGT to the percentage of labor capacity lost, and it is two-dimensional: loss depends on WBGT and on how hard the work is. Onset comes earlier for heavy work (warehousing, foundry, construction) than for light indoor work (office, light assembly), by three to four degrees of WBGT. A cooled facility is not a separate curve, it is a lower effective WBGT.
  • Published labor-productivity curves (Foster et al. 2021, Parsons et al. 2021, and the Kjellstrom/Hothaps family adopted by the WHO and the Lancet Countdown) turn that capacity loss into lost labor-hours and then business-interruption cost. These curves disagree by a factor of 1.4 to 2 on where loss begins and how steeply it rises. Any heat number must travel with its method: which curve, which work intensity, which WBGT profile.

Here is the practitioner caution that catches most people: a count of hot days is the wrong input for a heat cost. Many screens report “days above a temperature threshold,” an air-temperature count. That cannot be converted into a productivity or business-interruption figure, for two reasons. It is indexed on air temperature, not WBGT (and temperature-only shortcuts to WBGT are unreliable). And it is a threshold count, not the distribution of hours at each WBGT that the curves integrate over.

So heat is a flag and a ranking signal at the screening level, and a dollar figure only after escalation. At the screen, use the heat rating and its trajectory to 2030 and 2050 to say which sites are most exposed and to flag that a flood-only screen is under-counting them. To put a number on it, escalate: derive WBGT from temperature, humidity, wind, and radiation (the Liljegren et al. 2008 method, with open-source implementations such as PyWBGT), then apply a disclosed labor-productivity curve with the site’s work-intensity mix, hours and shift pattern, and the headcount and labor value at risk. Never put a heat dollar figure in a screening table.

The clean way to hold both perils in one exhibit is a two-track view: flood gets a quantified EAD column, heat gets an exposure flag, a rank, and a pointer to escalate. Flood damages the structure; heat damages the throughput. A screen that only prices structure will systematically understate your heat-dominant sites, which on most footprints is nearly all of them.

Flood Heat
What it damages The structure and its contents The throughput: worker and process capacity
Intensity metric Flood depth at a set of return periods Wet-bulb globe temperature (WBGT), not air temperature
Method Depth-damage function turns depth plus value into loss WBGT maps to lost labor capacity by work intensity
Screening output A quantified expected annual damage (EAD) figure An exposure flag and a rank, no dollar figure
To quantify Integrate loss across return periods Derive WBGT, then apply a labor-productivity curve with the site’s headcount, work mix, and hours

Read the output like someone who knows where the models bend

A screen produces confident-looking ratings and numbers. The practitioner’s edge is knowing exactly how they mislead, and checking for it every time.

  • A composite score hides your worst risk. Averaging twelve hazards into one number is the most common and most dangerous move in the field. A site can be Extreme on the one hazard that would actually shut it down and still land at “Moderate” once you blend that with eleven quieter hazards. Never let a composite be the finding. Read the hazard that dominates, not the average.
  • Zero is not one thing. A location that screens “no flood loss” can mean three completely different things: the flood model has a coverage gap here (no data, not no risk), the site is dry, or the site floods but the projection carried the baseline forward without a climate signal. Only one of those is safe. A flag-aware read distinguishes them; a naive read treats all three as “fine” and misses real exposure.
  • Compare the projection to the record. For flood especially, cross-reference the forward-looking model against what has actually happened. If the rainfall that historically floods a site is, say, 25 millimeters in a day, and the projections push more days past that observed trigger, that is a concrete, defensible escalation line, not a vague “risk goes up.” The inverse is a flag too: a high modeled depth with zero recorded flood episodes deserves a second look before you act on it.
  • A portfolio loss number is not a climate-growth number. Most of a portfolio’s flood EAD is usually today’s baseline risk carried forward, not the increment from warming. Decompose it. Knowing that, say, most of your loss is static baseline and only a minority is climate-projected changes what you do: you defend the baseline exposure now and monitor the projected growth, rather than treating the whole figure as a future problem.
  • Watch model spread and confidence. A single-model projection has no uncertainty range. Where a screen reports model spread or a confidence level, read it, and treat wide-spread results as screening signal only.
Supply chain climate risk screening: a platform climate composite next to a materiality-adjusted score, where one site rises from Moderate to High once weighted by what it depends on
Why a composite hides risk: one site rises from Moderate to High once the score is weighted by what a foundry actually depends on. Illustrative manufacturing worked example, not a real company. Source: Continuuiti.

These are not reasons to distrust screening. They are the difference between a screen you can act on and a screen that quietly lies to you.

Extend the screen to ports and routes, with clear limits

Extending the screen to the logistics network is where a lot of vendors overclaim, so draw the lines clearly.

  • Points screen cleanly. A port, terminal, airport, or distribution center is a fixed location. Geocode it and it runs through the same hazard screen as any site. Do this: your ports and terminals are often your most exposed and highest-value coastal assets.
  • Routes are lines, and a point screen approximates them. A shipping lane, a highway, or a rail corridor is not a coordinate. The sound approach is to screen a corridor as a chain of waypoints and report its exposure as that of its most-exposed segment. Say plainly that this is an approximation and that cascading, network-level disruption is not captured by a point screen.
  • Chokepoints: physical climate yes, geopolitics no. You can screen the physical climate hazard at a named chokepoint, and it can be very real. The Panama Canal drought, where low water levels forced draft and transit restrictions, is exactly a water-stress and drought signal a climate screen surfaces. What a climate screen does not and should not do is score geopolitical or maritime-transit chokepoint risk. Keep that line bright, because blurring it is how a physical-risk screen loses its credibility.

From screen to action

A screen that does not change a decision was theater. The output is a triage, and each tier gets a different response:

  • Material and highly exposed: escalate to a site-specific study, and in parallel move on the obvious levers. Dual-source or qualify an alternate. Build inventory buffer ahead of the exposed node. Secure alternate routes or ports. Add climate and continuity clauses to the supplier contract. Engage the supplier on its own adaptation, because their flood wall is your risk reduction.
  • Material but moderate exposure: put it on a monitoring cadence and revisit at the next screen or on a trigger event.
  • Low materiality: periodic reassessment is enough. Do not spend a study on a substitutable node.
  • Relocation and redesign are the heavy levers for the small set of sites where the exposure is high, the dependency is deep, and adaptation cannot close the gap.

The effort you spend should scale with the severity and likelihood of the risk. That proportionality is the core of risk-based due diligence, and it is what keeps a program affordable and defensible at the same time.

Governance, cadence, and fitting it into enterprise risk

A supply-chain climate screen fails quietly when it lives in a spreadsheet owned by one analyst. Make it a program:

  • Own it cross-functionally. Procurement holds the supplier relationships, risk and continuity own the response, sustainability owns the disclosure. Name a lead and give the business-unit heads who own the assets a seat.
  • Set a cadence. An annual full re-screen, a check on the highest-risk nodes after any major event near them, and a screen built into new-supplier onboarding so you never add exposure blind.
  • Integrate with enterprise risk management. Climate risk should not sit in a silo. Feed the screen into your existing ERM framework (ISO 31000 or COSO), map it onto the same likelihood-and-impact scales and the same risk register the board already reads, so climate exposure competes for attention and capital alongside every other enterprise risk.

How the screen maps to disclosure

A supply-chain climate screen is not only a resilience tool. It is the evidence base for the physical-risk parts of your climate disclosure, and it maps cleanly onto the major frameworks. Keep one distinction straight throughout: this is inside-out reporting, the risk to your enterprise, which is what IFRS S2, ESRS E1, and TCFD ask for. It is not the outside-in impact due diligence that the EU’s CSDDD (Directive 2024/1760) and the EU Deforestation Regulation (Regulation 2023/1115) require, which concerns your operations’ adverse impacts on people and nature. Those are a different obligation, and we cover the nature side in the companion guide.

On the inside-out side, the screen speaks directly to the standards:

  • IFRS S2 requires disclosure of climate risks across the value chain, and its physical-risk metric asks for the amount and percentage of assets or business activities vulnerable to physical risks (paragraph 29(c)), plus where those risks are concentrated by geography, facility, and asset type (paragraph 13(b)). A location-resolved, materiality-weighted screen produces exactly that concentration view. Two notes for the disclosure itself: the vulnerable-asset figure is reconciled to the financial statements by the reporter (the screen is an input, not the filed number), and whether you report on a before-adaptation or after-adaptation basis is the reporter’s choice under IFRS S2. A hazard-at-location screen is inherently a before-adaptation view, which is a clean, conservative starting point.
  • ESRS E1 (the EU’s climate standard under CSRD) requires physical-risk identification across own operations and the upstream and downstream value chain, assessed using site geospatial coordinates, and disclosed for significant assets aggregated to NUTS-3 regions (the anticipated-financial-effects requirement, numbered E1-9 in the 2023 standard and renumbering to E1-11 in the amended standard expected to apply from 2027). The pattern is assess at the coordinate, disclose at the aggregate, which is exactly what screen-then-escalate produces.
  • Both standards endorse the proportionate, screen-then-escalate approach, but by different mechanisms, and it is worth not blurring them. IFRS S2 uses a “reasonable and supportable information without undue cost or effort” test. ESRS uses reasonable efforts plus proxy estimation plus a first-three-year value-chain phase-in. Same destination, different route.
Framework What it asks for on physical risk What a screen provides
IFRS S2 Assets and activities vulnerable to physical risk (29(c)), and where risk concentrates by geography, facility, and asset type (13(b)), with analysis proportionate to exposure (B4) A location-resolved, materiality-weighted concentration view, and a before-adaptation exposure baseline the reporter reconciles to the financial statements
ESRS E1 Physical-risk identification across own operations and the value chain, assessed at site coordinates and disclosed for significant assets aggregated to NUTS-3 regions (E1-9, renumbering to E1-11 from 2027) Assess at the coordinate, disclose at the aggregate, which is exactly what screen-then-escalate produces
TCFD Scenario-based physical-risk assessment across the value chain Multi-scenario, multi-horizon hazard exposure at every location

The screen, in short, is the machinery that turns a global supplier list into a defensible physical-risk disclosure, without pretending a screening-grade number is an engineering-grade one.

Sample Climate Risk Assessment

See a full climate risk assessment, end to end

We’ll email you a complete worked example for a manufacturing site: 12 hazards, multiple scenarios, and value-at-risk out to 2050. It shows what a full climate risk assessment output looks like.



Limits, and when to commission a real study

Screening is a triage tool. State its limits plainly, because a screen that oversells itself is worse than no screen:

  • It uses coarse, roughly 25-kilometer climate data. It captures regional signal, not the microclimate of a specific building.
  • It screens the site, not the enterprise. It does not see the supplier’s own flood wall, backup power, inventory buffer, or adaptation.
  • Most projections run on a single climate model, so there is no ensemble uncertainty range unless the screen reports one.
  • Compound and cascading events (a flood and a cyclone together, or a failure that ripples through a network) are not modeled by a point screen.
  • Screening-grade loss figures are order-of-magnitude, for ranking and aggregate exposure. They are not decision-grade for a single property.

When a site turns up material, highly exposed, and hard to substitute, that is the signal to commission the site-specific, engineering-grade study. The screen’s job is to find those sites cheaply. It has done its job when it hands you a short, defensible list.

Worked example: a manufacturer’s extended footprint

To make the method concrete, here is an illustrative worked example. It is not a real company.

Supply chain climate risk screening across a ten-site manufacturing footprint with annual flood loss, carried-versus-projected split, and the site map
A screened ten-site manufacturing footprint: annual flood loss, the carried-forward versus climate-projected split, and where the sites sit. Illustrative manufacturing worked example, not a real company (real: locations, hazards, scenarios; illustrative: company, values, materiality). Source: Continuuiti.

It is a stylized automotive manufacturer’s extended footprint of ten locations, screened across two scenarios and three horizons. The footprint deliberately spans all three perimeter layers: seven own plants (casting, machining, stamping, powertrain, components, electronics, and an HQ and R&D campus), one Tier-1 just-in-time supplier, one vehicle export terminal (a port), and one logistics distribution center. All figures below are illustrative and rounded.

What the screen surfaced, and why each finding matters:

  • The composite hid the worst site. Averaged across twelve hazards, nine of the ten locations landed at “Moderate” and only one rated “High.” Read as a portfolio average, the whole footprint looked unremarkable. Read hazard by hazard, the single High site and the specific hazards driving it were the actual story. This is why a composite is a starting point, never a finding.
  • Three different zeros. Three sites screened with no modeled flood loss, for three different reasons. One sat in a flood-model coverage gap (no data, and it happens to be one of the more exposed sites). Two were dry at the river. One coastal site showed its baseline flood carried forward with no climate signal. A naive read would have filed all of them as “safe.” Only one was.
  • Concentration was extreme. The top two sites carried about three-quarters of the modeled flood loss. A portfolio-average risk number would have completely masked that the exposure is concentrated in a couple of locations, which is exactly where the mitigation budget should go.
  • Most of the loss was not climate growth. Decomposed, roughly 70 percent of the portfolio’s expected annual flood damage was baseline risk carried forward and only about 30 percent was the climate-projected increment. The headline figure, roughly 23 million dollars of expected annual damage, is mostly a today problem, not a 2050 problem, which changes what you do first.
  • Heat was the quiet, universal risk. Heat rated High or worse at essentially every site, and after applying the criticality filter it remained a material exposure at nine of the ten. None of that showed up in the flood loss figure. On a flood-only screen, the most widespread hazard in the portfolio would have been invisible.

The lesson of the worked example is the lesson of the whole method: the screen is only as good as the practitioner reading it. The numbers are a starting point. The judgment about what they hide is the work.

Common mistakes to avoid

The failure modes repeat across programs. Watch for these:

  • Stopping at Tier 1. The risk that shuts you down is usually deeper in the chain. A Tier-1-only screen is a comfort blanket.
  • Trusting the composite. Averaging hazards into one score buries the single hazard that matters. Always read the dominant risk.
  • Treating zero as safe. Distinguish a coverage gap from a dry site from a carried-forward baseline. They are not the same finding.
  • Running one scenario. A single future hides the uncertainty you most need to plan against. Run at least a moderate and a high case.
  • Skipping the geocoding gate. A screen on city centroids is a random-number generator with good production values.
  • Confusing continuity screening with impact due diligence. Physical climate risk to your operations and your operations’ impact on nature are two different obligations with two different frameworks. Do not let one masquerade as the other.
  • Treating a screen as decision-grade. Screening ranks and triages. It does not replace the site-specific study for the sites that matter most.

Where this leaves you

Screening physical climate risk across a supply chain is not a data problem, it is a discipline problem. The data and the science are mature enough to rank ten thousand locations cheaply. The value is in doing it in the right order: define the real perimeter, get the coordinates right, rank by materiality before hazard, quantify the material subset, and read the output like someone who knows where it bends. Do that, and a sprawling, invisible web of dependencies becomes a short, defensible list of the places that actually threaten your continuity.

If you want to see the method applied end to end on a worked portfolio, our manufacturing worked example walks a full physical climate risk assessment from coordinates to value-at-risk. And if you would like to talk through screening your own footprint, book a walkthrough.


Frequently Asked Questions

How do you screen climate risk in a supply chain?

Screen in order: define the real perimeter (own sites, suppliers Tier 1 to N, the logistics network, and external dependencies), geocode every location and reject low-precision matches, rank each node by criticality times exposure, then run a hazard screen across at least two scenarios and three horizons. Flood prices to expected annual damage; heat is an exposure flag. Escalate only the material, highly exposed subset to a site-specific study.

What is the difference between climate risk screening and a climate risk assessment?

Screening is a broad, cheap, consistent first pass over every location that matters, and its output is a rank of which nodes need a closer look. Assessment is the deep, site-specific study you commission for the handful the screen flags as both material and highly exposed. You cannot deep-assess thousands of suppliers, so screening is what makes the assessment budget defensible.

Does IFRS S2 or CSRD require supply-chain physical-risk disclosure?

Yes, both extend to the value chain. IFRS S2 asks for the assets and activities vulnerable to physical risk and where that risk concentrates by geography and facility, proportionate to exposure. CSRD’s ESRS E1 requires physical-risk identification across own operations and the value chain, assessed at site coordinates and disclosed for significant assets aggregated to region. A location-resolved screen is the evidence base for both.

How do you quantify heat risk in a supply chain?

Not with a count of hot days. That is an air-temperature threshold, and it cannot be converted into a productivity or business-interruption cost. Heat quantification uses wet-bulb globe temperature (WBGT), which combines temperature, humidity, wind, and radiation, then maps WBGT to lost labor capacity by work intensity using a published curve, and applies the site’s headcount and hours. At the screening stage heat is a flag and a rank, and a dollar figure only after escalation.

How do you screen suppliers you cannot see, beyond Tier 1?

Visibility collapses fast past Tier 1, which is exactly where the risk hides: the single mine, smelter, or specialty-chemical plant half an industry depends on is usually several tiers deep. Where you lack addresses, screen what you can map (known sub-tier sites, the logistics nodes, and critical external dependencies), flag the unmapped tail as a data gap rather than as no risk, and prioritize mapping the deep-tier inputs with the longest requalification times.

Govind Balachandran
Govind Balachandran

Govind Balachandran is the founder of Continuuiti. He writes extensively on climate risk and operational risk intelligence for enterprises. Previously, he has worked for 7+ years in enterprise risk management, building and deploying third-party risk management and due diligence solutions across 100+ enterprises.