The UK’s Prudential Regulatory Authority Found Most Firms Can't Quantify Their Own Climate Risk

By Ron Dembo

May 13, 2026Regulation & RiskMethodology

The Bank of England's Prudential Regulation Authority published Consultation Paper CP10/25, updating Supervisory Statement SS3/19 across seven chapters: governance, risk management, climate scenario analysis, data quality, disclosures, and sector-specific requirements for banks and insurers. The message is direct: climate risk is a driver of financial stability, and firms are expected to quantify it, not describe it.

The PRA's own supervisory review, set out in Box B of the paper, found most firms aren't there yet. Risk frameworks are immature. Scenario analysis leans on judgement-based overlays rather than quantification. Data governance is fragmented across external providers with inconsistent standards.

That is not a compliance gap. It is a measurement gap, and it will not close with a workshop or a narrative disclosure.

Identifying Risk at Asset Level

CP10/25 paragraphs 2.24 to 2.26 require firms to assess climate risk at three levels: firm-wide, counterparty, and asset. Box B notes many firms currently rely on judgement-based overlays without understanding the transmission channels involved.

Our Climate Digital Twin (CDT) Express API assigns every asset a specific geographic footprint using H3 spatial indexing, a hexagonal grid system built for consistent geospatial aggregation and audit. Rather than a single climate risk score, it quantifies exposure across dozens of specific hazard indices, grouped by category: rainfall extremes (rx1day, rx5day), temperature extremes (hot days, tropical nights), drought and water stress (SPEI), and fire weather (the Fire Weather Index).

For a London commercial property, the 1-in-100-year extreme daily rainfall (rx1day) value moves as follows across pathways:

The historic 100-year threshold was 33.5mm. Under the Stochastic View at 2050, it is 73.6mm — roughly double, and higher than the standard SSP5-8.5 pathway shows for the same horizon. That gap is the tail risk most firms are not yet modelling.

Setting Quantitative Limits, Not Narrative Ones

Paragraph 2.30 requires quantitative risk appetite metrics and limits for each material climate risk, cascading from board to business line under paragraph 2.17. The PRA wants numbers, not descriptions.

Four metrics do this work:

  • dcr_score is a standardised downside-likelihood score for screening portfolios and setting exposure rules — for example, no new exposure above a set threshold
  • expected_impact is a probability-weighted damage ratio: a value of 0.15 means climate-driven damage consumes 15% of asset value in the average scenario.
  • VaR at 95% and 99% confidence gives damage thresholds at 1-in-20-year and 1-in-100-year severity, feeding directly into ICAAP capital frameworks.
  • CVaR, the average loss in the worst 1% of outcomes, is the tail-risk metric Box B specifically flagged as weak in current firm practice.

A commercial real estate portfolio with a 99% CVaR of 35% damage under SSP5-8.5 by 2050, held against a £5 billion exposure at default, implies a materially different Pillar 2A capital charge than the same portfolio assessed on historical loss experience alone. That is the calculation the PRA is asking firms to run themselves.

Tail Risk Was the Explicit Gap

Chapter 3 requires multiple scenarios, tail-risk coverage, transparent assumptions, scenario analysis embedded in ICAAP or ORSA rather than run separately, and reverse stress-testing.

Standard IPCC pathways run from SSP1-2.6 through SSP5-8.5. Our proprietary Stochastic View adds ensemble uncertainty and tail-risk sampling on top of those pathways, capturing outcomes the standard deterministic scenarios can underrepresent. For London at 2050, the Stochastic View places the 1-in-100-year rx1day event at 73.6mm, against 67.7mm under SSP5-8.5. That gap is the tail risk the PRA's own review found most firms are not capturing.

Data Governance and the Audit Trail

Chapter 4, paragraphs 2.58 to 2.66, requires frameworks for sourcing and validating external data, governance over third-party providers, and consistent aggregation. Box B found firms heavily reliant on external data with inconsistent governance practices.

Every query against the CDT returns full metadata: timestamp, pathway, horizon, H3 hex ID, and methodology version, creating an auditable chain from data source to risk decision. The underlying models are built on CMIP6 GCM ensembles with documented downscaling and bias correction, addressing paragraph 2.51's requirement that firms understand their own model assumptions.

Where This Applies

For banks: collateral valuation through expected impact, capital charges through VaR and CVaR feeding ICAAP, and liquidity stress testing through climate event frequency projections.

For insurers: ORSA and SCR calibration — if 1-in-100-year wind speeds rise 15% under SSP3-7.0, nat cat loading needs to move with it — and underwriting, where forward-looking flood frequency replaces historical loss experience in pricing.

The Question CP10/25 Is Actually Asking

CP10/25 does not ask firms to agree that climate risk is financial. It asks them to prove they can quantify it, at asset level, with a number a supervisor can test. The firms that can already produce that number are having a different conversation with the PRA than the ones still building the framework to produce it.

You can download the full briefing paper here.