Enhancing ERM in Banks with Riskthinking’s Climate Digital Twin

By RiskThinking Team

February 25, 2025MethodologyRegulation & Risk

A bank's enterprise risk management framework was built to price credit risk, market risk, liquidity risk, operational risk, and regulatory risk as largely independent problems. Climate change doesn't respect that separation. A single flood event can move all five at once — and most ERM frameworks have no mechanism for capturing that.

Market Risk

A property in a floodplain or wildfire corridor doesn't depreciate gradually. It depreciates the moment enough buyers and insurers reprice the hazard simultaneously — and that repricing shows up in mortgage-backed securities and real estate holdings before most banks' models have caught up. The failure isn't the direction of the risk. It's the speed: static valuation models assume slow-moving fundamentals, and climate-driven asset devaluation doesn't move slowly.

CDTexpress runs forward-looking, multi-scenario stress tests at the individual asset level — not a portfolio average — so a bank can see which specific holdings are exposed before the market repricing happens, not after.

Credit Risk

Climate damage to collateral doesn't just reduce what a bank recovers in foreclosure. It changes the borrower's ability to pay in the first place — a damaged property means repair costs, business interruption, or both, and default risk moves accordingly. In high-risk regions, this compounds: even undamaged properties become harder to insure, which further constrains the borrower's cash flow.

Most credit models still price this off historical loss data. That data describes a climate that no longer applies. CDTexpress models the asset's exposure across multiple hazards and future horizons, so collateral risk can be priced against what's coming, not what already happened.

Liquidity Risk

A regional climate disaster creates a liquidity problem before it creates a credit problem: households and businesses draw down deposits simultaneously to cover recovery costs, right as short-term funding markets get nervous about the same institutions' exposure. This is a correlated shock — multiple depositors and multiple counterparties responding to the same event at the same time — which is exactly the scenario most liquidity stress tests are weakest at capturing.

By modelling the same climate scenarios against a bank's deposit base and funding structure, CDTexpress supports contingency planning built around the specific disasters a bank's own geographic footprint is exposed to.

Operational Risk

Physical infrastructure — branches, data centres, ATM networks — sits in the same geography as the climate hazards being modelled for lending purposes, but it is rarely assessed with the same rigour. The exposure doesn't stop at owned infrastructure either: a bank's third-party vendors and cloud providers carry their own geographic risk, and an outage at a vendor's facility becomes the bank's outage.

CDTexpress maps hazard exposure across both direct infrastructure and the vendor and supply-chain network, so recovery planning is built against known points of failure, not generic disaster-recovery assumptions.

Regulatory Compliance Risk

OSFI's Guideline B-15 sets governance and risk-management expectations for federally regulated financial institutions in Canada, including climate scenario analysis, stress testing, and disclosure. The European Central Bank's supervisory expectations and the UK Prudential Regulation Authority's climate framework are moving in the same direction. None of these are compliance exercises to be completed once. They are a standing requirement to produce and defend a methodology on demand.

An institution using stochastic, multi-hazard modelling has a defensible answer when a regulator asks how a given exposure was calculated. An institution using a historical scalar does not.

The Structural Point

These five risk types are usually managed in separate teams, with separate models, on separate timelines. Climate risk cuts across all five at once, which means the institutions that will be fine are not the ones with the most sophisticated model in any single category — they're the ones running the same climate data and the same methodology across market, credit, liquidity, operational, and regulatory risk simultaneously. That's the difference between managing five risks and managing one system.