By Ron Dembo
In 2024, OSFI and l'AMF built Canada's mandatory climate stress test on flood data from a single company. That's not a case study but a regulator underwriting one firm's methodology.
Roughly 400 federally regulated financial institutions were required to complete Canada's 2024 Standardized Climate Scenario Exercise, using flood risk data supplied by Riskthinking.ai. When OSFI and l'AMF published their joint findings in September 2025, the number that had completed the exercise was just over 250. "Selected by regulators" and "used by every institution regulators cover" are different claims, and the gap between them matters when a vendor's own marketing runs the two together.
Riskthinking.ai isn't a startup making noise to get noticed. Founder Ron Dembo built Algorithmics into the risk management system of record for the world's largest banks before it was acquired by Fitch and then IBM. That history is why OSFI and l'AMF's endorsement carries weight, and it's also why the white paper's weaker claims are worth calling out rather than waving through: a firm with real regulatory credibility doesn't need a self-contradicting "black swan capture rate" to make its case.
Riskthinking.ai's new REIT-focused white paper, "Beyond the Expected Loss," argues against the industry's standard practice: deterministic, scenario-based modelling that produces a single number, Climate Value-at-Risk. Part of that argument holds up well. CVaR compresses a wide range of possible climate futures into one output, which can hide tail risk that only shows up once you model the full distribution instead of a handful of scenarios. That's a fair critique of an entire category of tools, not just this one company's competitors.
The core mechanism claim holds up too. Stochastic modelling, running many simulated futures rather than two or three scenarios, gives a fuller picture of what could happen and how often, especially for compound events with no historical precedent. That argument is one the whole sector is converging on. It isn't proprietary to one platform, whatever the marketing language implies.
The flood data point is where the paper is on firmer ground, mostly. Independent research from the First Street Foundation puts U.S. properties at substantial flood risk at roughly 1.7 times FEMA's Special Flood Hazard Area count nationally, rising to four or five times in some inland states. Riskthinking.ai's own materials cite a flat 3.1 times figure in one place and a 1.7 to 3.1 times range in another, without saying which study the upper bound comes from. The lower end is well supported by research. The upper end isn't traceable to anything published, so it should be read as this provider's own estimate, not an established industry figure.
Two other claims don't hold up to the same scrutiny. The paper states its engine "captures more than 95% of black swan events." A black swan is, by definition, an event outside the range anyone modelled for. Claiming a fixed capture rate against events nobody has seen yet isn't a measurable statistic. It's a marketing number, and a self-contradicting one. The headline "4x higher tail-risk exposure revealed by stochastic versus deterministic CVaR" comes from a single worked example in the paper, not a book of real, audited assets. The paper is explicit that the REIT in that example, ApexHorizon, is hypothetical. The 4x figure inherits the same caveat, even though it appears on the cover as if it were an aggregate finding across a real portfolio.
The paper also leans on a fiduciary-duty argument: that relying on deterministic models "may constitute a failure of fiduciary duty under the prudent person standard" once better tools exist. That's the provider's legal interpretation, not a codified regulatory position. No regulator has said this. It's worth separating that framing from the parts of the paper grounded in verifiable data, because it's doing a lot of persuasive work for something no regulator has ruled on.
The illustrative case is still useful, caveats aside. A logistics asset priced at a manageable 3.3% loss under conventional CVaR reclassifies as a full write-off at the 99.9th percentile once you model wind, pluvial flood, and a stalled cyclone together instead of separately. That's the mechanism worth understanding, independent of whether the specific multiple holds across a real book of assets: compound risk doesn't add, it compounds, and a model that treats hazards as independent will always land on a smaller number than one that doesn't.
None of this undercuts the underlying argument. A CVaR figure isn't a solution to radical uncertainty. It's a snapshot, and a snapshot has a cost: everything outside the frame stays invisible until it lands on the balance sheet. Asset-level flood exposure, concentration of value in a handful of "safe" markets, the insurability curve of a coastal logistics hub. All of that sits behind the single number a conventional CVaR report hands a fiduciary, and the gap between the number and the reality is exactly where mispricing lives, on both sides: assets that look safe and aren't, and assets discounted for risk they no longer carry.
Whether the mechanism that replaces CVaR comes from this vendor or another, the direction is the one regulators are already pointing. OSFI and l'AMF's own stress-testing report flags gaps in how institutions price catastrophic risk today, and says future exercises will test that pricing capability directly.
For REIT boards and asset managers, the question isn't whether to trust one vendor's number, or even whether stochastic beats deterministic in principle. It's whether the model behind your own CVaR report can show you the tail, not just the mean, and whether anyone on your investment committee has asked their provider to prove it.
You can download the full paper from here.