All work Climate finance risk management Financial services

Climate Finance Risk Management Intelligence Platform

The firm had the expertise and the models. Too much of that value stayed locked inside bespoke client work. I spent time with the analysts working out which parts of a job were the same every time, and which parts were the reason clients paid in the first place. That question turned out to be the product.

Human factors engineeringService designProduct definitionAI adoptionInterface design
Trace the chain A figure that cannot be traced back down every layer is not defensible when someone asks how it was produced.
01 / CONTEXT

A firm that could answer anything, one analyst at a time

An independent, regulated investment manager working on climate and market risk. Around ten senior people, most of them out of global banks, serving two quite different buyers: institutions allocating capital, and asset-heavy operators in industry, energy and agriculture.

They did not sell climate data. They sold the financial consequence of it, worked out against a specific company's own accounts. The analysis was genuinely good. What they could not do was produce it twice without spending the same senior week again.

Buyer oneInstitutional investorsAllocating capital against emissions targets without giving up return. Hover to see the holdings settle onto the frontier.
Buyer twoAsset-heavy operatorsIndustry, energy and agriculture. Sites, inputs and supply routes, each with its own exposure.
What sets the paceThe regulatory calendarReporting widens, then costs begin, then they scale. The deadlines are not ours to choose.
Layer 01 · advisory

The thing clients bought

Senior specialists framing what mattered, interpreting the result, and standing behind the recommendation when a board pushed back.

Layer 02 · capability

The thing that made it possible

A financial analytics library, a simulation engine, geospatial intelligence from earth observation, and a deliberately reusable component architecture.

Layer 03 · product

The thing nobody was selling

A working platform and dashboards, real, in use, and positioned as evidence of sophistication rather than as the offer itself.

The engineering team had already built one architecture designed to support separate deployments, with shared components they had deliberately made reusable. That only pays back if a family of products is coming. No such family had been defined. The architecture was answering a product question nobody had asked out loud, and that gap turned out to be the whole engagement.

02 / THE DOMAIN

Climate risk is not the product. Financial consequence is.

Before I could codify anything I had to understand it properly. A hazard, a policy change or a price move only matters to a finance function once someone has carried it all the way to a number on their own accounts.

Every chain here ends in a decision. An analysis that stops one box short is interesting rather than useful. I think that is why so many climate products never change anything.

Terrain and hazard morphology

Elevation and flow structure is what makes a hazard field location-specific rather than regional. Resolution here determines whether an answer is actionable.

Earth observation as an input, not a product

Satellite-derived layers are a data foundation. They only become a risk product once joined to an asset register and a valuation model.

Exposure resolution

The lattice is the honest bit: exposure is only as good as the link between a legal entity and a physical coordinate.

The transmission stack

STRUCTUREDrag to explore →
Decisionthe number that gets acted onFinancial enginevaluation · aggregation · P&LExposureentity → site → coordinateHazard & driver fieldacute · chronic · policy · priceData foundationEO · registries · customs · curves
Five layers, one question. Data resolves to a hazard field, the field meets an exposure lattice, the engine turns exposure into money, and the towers are the decisions taken as a result. The dashed pillars matter more than the planes: a figure that cannot be traced back down through every layer is not defensible when a regulator asks how it was produced.

Risk transmission chains

CHAIN
Drag to explore →
PHYSICAL RISK · HAZARD TO DECISION01Hazardriver & surfacefloodcoastal flood,storm surgewildfire,droughtextreme heat,windacute / chronic02Locationsite coordinatenot a postcodecentroidelevation &defencesgeospatial03Exposurewhat physicallysits therereplacementcostoutputdependencyasset register04Vulnerabilityconstructiontypecriticality tonetworkadaptationalready inplacedamage function05Physical impactdamage tostructuredowntime daysrecoveryprofileexpected annual loss06Business effectlost output &salessupplyinterruptionthird-partyinfrastructurerevenue at risk07Financial effectEBITDA impactassetrevaluationinsurability &premiumP&L line08Decisionadapt, insure,relocateprice the riskindisclose itactionA hazard map is not a risk assessment. Collapsing this chain into a single score destroys the four intermediate quantities a CFO needs to act — andis why physical risk products so often fail to change a decision.
TRANSITION RISK · POLICY TO VALUATION01Policy ortechnology shiftcarbon pricing& levy phase-infree-allowancewithdrawalelectrificationof process heatexternal driver02Productioneconomicsenergy mix &fuelprocess routethroughput &utilisationunit cost03Emissionspositiondirect &indirectintensitysectorbenchmarkfree allocationheldtCO₂e per tonne04Regulatory costexposed volumecertificateprice pathefficiencypenalty€ per year05Capitalrequirementabatement CAPEXbreak-evenenergy pricetiming of spendinvestment case06Cash flowoperating costmargincompressioncovenantheadroomEBITDA07Valuation &creditasset valuecost of capitalprobability ofdefaultenterprise value08Decisioninvest, hedge,repricereshape supplyoriginexit theproduct lineactionTransition risk is economic repricing, not an ESG score. Every box is a quantity the finance function already understands — which is precisely whythe analysis lands, and why an intensity rating does not.
Two chains, one discipline. Physical risk runs hazard → location → exposure → vulnerability → impact → cash flow. Transition risk runs policy → production economics → emissions position → regulatory cost → capital → valuation. Collapsing either into a single score destroys the intermediate quantities a CFO needs to act.

The regulatory cost engine

WORKED MECHANISMDrag to explore →
REGULATORY COST ENGINE · FROM A CUSTOMS CODE TO A LINE IN THE ACCOUNTS01 CLASSIFYcommodity code →product scopecode hierarchy governsscope, not the product name02 ATTRIBUTEorigin →embedded intensitytCO₂e per tonne, byproduction route and country03 BOUNDscope of emissionsdirect + purchased energy;selected upstream inputs only04 PRICEcertificate price pathforward curve, convertedat the FX forward05 PHASEpolicy scale-upphase-in againstfree-allowance withdrawal06 LANDcost → EBITDAannual and cumulative,by horizonPolicy phase-in — share of full cost appliedillustrative, on the published scale-up shape100%75%50%25%0%20262202752028102029222030482031612032732033862034100Same product, same year — cost varies by supply originembedded cost as % of import value at full phase-in · illustrativeOrigin A10%Origin B26%Origin C26%Origin D30%Origin E35%Origin F38%Origin G44%Ranking reshuffles once the policy lands — which is the actionablefinding, because procurement can move.
The sharpest asset in the firm, and the template for everything else. A customs code, an origin, an embedded intensity, a price path and a phase-in produce a figure that lands in the accounts. Both charts are computed on the published mechanism with illustrative values — the mechanics exact, the numbers analogues.

Second-order transmission

CHAIN 03Drag to explore →
SECOND-ORDER TRANSMISSION · HOW PHYSICAL RISK REACHES A BALANCE SHEET IT DOES NOT TOUCHLoss frequencyand severity riseinsuranceTechnical premiumrepricesinsuranceInsurer withdrawsfrom the perilinsuranceCoverage gapopensinsuranceCollateral valuefallscreditLoan-to-value anddefault risk movecreditCapital requirementand appetite shiftcreditA bank with no physical assets still carries physical risk — through the insurability of the collateral behind its loan book.
The chain that catches people out. A lender with no physical assets still carries physical risk, because it arrives through the insurability of the collateral behind the loan book. Understanding this is what lets one engine serve both an operator and an investor.
03 / METHOD

Human factors, applied to an expert financial workflow

I did not run a discovery sprint and hope an AI roadmap fell out of it. I ran a cognitive work analysis on the domain, and the automation opportunities came out of that analysis rather than a separate ideas session.

The order matters more than people expect. You need to know what the domain is for before you decompose what the experts do, and you need the cues behind their judgement before you can say what a machine should carry.

Step 01

Work domain analysis

Establishes purpose before mechanism. Stops a team building the artefact nobody asked for.

Step 02

Task decomposition

You cannot allocate a function you have not named.

Step 03

Cue elicitation

Turns codifiability from an opinion into an evidenced finding.

Step 04

Function allocation

Per processing stage, never per task. This is what produces a nuanced answer.

Work domain analysis

INSTRUMENT 01Drag to explore →
WORK DOMAIN ANALYSIS · ABSTRACTION HIERARCHYRead down for how, read up for whyFunctional purposeWhy the system existsProtect cash-flow predictabilityPreserve asset valueSatisfy regulatory disclosureValues & priority measuresHow good is judgedEBITDA volatilityExpected annual lossCost of capitalAudit defensibilityPurpose-related functionsWhat must happenCharacterise hazardResolve exposure toentity & assetValue the impactProject underscenariosDecide & actPhysical functionsWhat performs itEarth-observationingestEntity resolutionValuation librarySimulation engineReporting &evidencePhysical objectsWhat it is made ofSatellite rastersTrade & customsrecordsCompany registriesForward curvesPlant & sitecoordinatesWHY ↑HOW ↓
Read down for how, read up for why. This is the instrument that stops a team building a beautiful hazard map. A map sits in the bottom two rows. Nothing in the top two rows asks for one.

Hierarchical task analysis

INSTRUMENT 02Drag to explore →
HIERARCHICAL TASK ANALYSIS · EXPERT ENGAGEMENT0. Quantify a client's climate-driven costplan 0: 1 → 2 → 3 → 4 → 5 → 6, iterate 3–5 until materiality agreed1Framemateriality1.1 identify value drivers1.2 agree hazard scope1.3 set horizonsjudgement2Acquireinputs2.1 customs & trade2.2 registries & sites2.3 EO rasters2.4 forward curvesdata work3Resolveexposure3.1 entity → subsidiary3.2 subsidiary → site3.3 site → coordinate3.4 verify matchdata work4Computeimpact4.1 embedded intensity4.2 apply price path4.3 hazard × vulnerability4.4 aggregate to P&Lcomputation5Projectscenarios5.1 select pathway5.2 bump curves5.3 run alternativescomputation6Advise &sign off6.1 interpret6.2 recommend6.3 accept accountabilityjudgementSteps 2–5 executed identically on every engagement. Steps 1 and 6 varied completely — and consumed the accountability.
Goals, sub-goals and the plan that governs sequence. Decomposing to this level is what makes the next step possible. The colour split is the first hint of the finding: judgement clusters at the two ends.

Cognitive demands table

INSTRUMENT 03Drag to explore →
COGNITIVE DEMANDS TABLE · CRITICAL DECISION METHOD OUTPUTTASK ELEMENTWHY IT IS DIFFICULTCUES EXPERTS USEWHERE NOVICES FAILCODIFIABLE?Deciding what is materialMateriality is contextual — dependson the client's own cost base andcovenant structureShare of COGS; covenant headroom;whether the board already has a viewTreat every hazard as equallyrelevant; produce a list, not ajudgementNo — judgementMatching entity tophysical siteRegistry names, trading names andsite operators diverge; subsidiariesreorganiseOwnership chains; sector codes;plausibility of site size againstoutputAccept a fuzzy name match withoutchecking the operatorPartly — generate, humanverifiesClassifying goods intoscopeScope turns on code granularity andon production route, not on theproduct nameCode hierarchy; production route;whether upstream inputs are capturedClassify by product descriptionand miss the route distinctionPartly — extract, rulesverifyChoosing scenarioassumptionsPathway choice changes the answermore than the model doesClient's own planning assumptions;regulator's stated scenario; thefinancial statementsPick the headline pathway andnever reconcile it to theaccountsPartly — defaults, humanconfirmsSense-checking an outputThe dangerous error is plausible,not obviousOrder-of-magnitude against peers;direction of change; discontinuitiesin the curveAccept an output because themodel ran without errorYes — anomaly detectionflags, human adjudicatesRecommending an actionCarries consequence; must survivechallenge from a board and aregulatorWhat the client can actuallyfinance; what the counterparty willpriceRecommend the optimum rather thanthe executableNo — accountability
The output of critical decision method interviews, and the real input to automation. Cue-based elicitation surfaces what experts notice but do not say. The final column is not an opinion — it falls out of whether the cues in column three can be represented at all.

The decision ladder

INSTRUMENT 04Drag to explore →
DECISION LADDER · WHERE THE BUYER ACTUALLY ENTERSActivationa signal arrivesObservegather informationIdentify system statewhat is happeningInterpret consequencewhat it means for usEvaluate against goalswhich outcome do we wantDefine target statewhat should be trueDefine taskwhat must be doneFormulate procedurehow exactlyExecuteactSHORTCUT — the rule the CFO actually runs“A number attached to my operations, with a range and a date” → actThe product's job is to make the shortcut safe, not to walk the buyer up the ladder.
Nobody walks the whole loop. The CFO jumps from a cue straight to a decision, and the product's job is to make that jump safe rather than force the long way round. This one diagram ended up shaping every output surface we designed.

Situation awareness mapped to interface regions

INSTRUMENT 05
Level 1 · perception

What hazard is present here?

Answered by hazard filters, the basemap, and the acute-versus-chronic split.

Level 2 · comprehension

What of ours sits there, and how vulnerable?

Answered by the asset register, exposure resolution and vulnerability scoring.

Level 3 · projection

What will it cost, by when, under which pathway?

Answered by scenario controls, the loss figure and the forward curves.

Three cognitive tasks, three screen regions, in that order. An interface that blends perception with projection produces users who are confident and wrong — which in a regulated setting is the expensive failure mode, not the obvious one. The redesigned screen in section 08 is laid out to this mapping.

Function allocation across four processing stages

INSTRUMENT 06Drag to explore →
FUNCTION ALLOCATION · LEVELS OF AUTOMATION ACROSS FOUR INFORMATION-PROCESSING STAGESInformationacquisitionInformationanalysisDecisionselectionActionimplementationAcquire inputs9869Resolve exposure9746Classify scope8745Compute impact9958Project scenarios8847Sense-check output7633Frame materiality4311Recommend action3211Execute21118–10 full automation, human informed6–7 system acts, human can veto4–5 system proposes, human selects1–3 human decides, system supportsThe allocation is per stage, not per task. Acquisition and analysis automate hard; decision selection stays low everywhere; action implementation never leaves the human on the advisory path.
Not a list of what humans do better than machines. Each step is allocated separately for acquisition, analysis, decision selection and action implementation. That is what produces a nuanced answer — automate acquisition and analysis hard, hold decision selection low everywhere, and never let action implementation leave the human on the advisory path.
Countermeasure 01

An explicit queue, never silent auto-accept

Automating the easy cases makes the residual ones rarer and harder. The exceptions have to surface somewhere a person is actually looking.

Countermeasure 02

Visible confidence

Trust has to be calibrated rather than assumed. A number without its confidence invites exactly the wrong kind of reliance.

Countermeasure 03

Provenance retained on every automated path

Retrofitting an evidence trail is not possible. If it is not captured at the moment of computation, the answer is undefendable later.

04 / THE PROGRAMME

Six sessions, each built to close exactly one decision

I designed the programme backwards from the decisions that had to be made, not forwards from a discovery template. Each session had one question, one set of instruments, and could not begin until the previous one had produced an answer.

One rule, set at the start: no session ends without a decision written on the wall. If we ran out of time we cut scope, never the decision.

01Frame the offer
02Map the decisions
03Blueprint the work
04Elicit the cues
05Allocate function
06Rebuild the service
Session 01

What is this firm actually selling?

If we cannot name the decision, we cannot build for it.

InstrumentsAbstraction hierarchy · claim rewriting
In the roomChief executive · advisory leads · engineering lead · commercial
Inputs
  • Existing capability list
  • Two years of past engagement scopes
  • The firm's own materials
What we did
  1. Listed every computable capability without editing
  2. Rewrote each as one sentence — this lets a named person decide a named thing
  3. Built the abstraction hierarchy live on the wall
  4. Parked anything with no functional purpose above it
Artefacts
  • Capability inventory
  • Claim statements
  • Abstraction hierarchy
  • Parked wall
What it decided

Eleven capabilities resolved to six claims. The five that failed had no decision above them — which told us more than the six that passed.

Session 02

Who decides, and what makes them act?

The evidence threshold, not the persona.

InstrumentsDecision ladder · jobs-to-be-done · evidence thresholds
In the roomAdvisory leads · two client-facing partners · commercial
Inputs
  • Client conversation records
  • Sales objections
  • Lost-deal reasons
What we did
  1. Mapped both buyer types independently against the decision ladder
  2. Traced trigger, room, evidence used, and the deadline behind each
  3. Asked what they do when the evidence is missing — workarounds mark the real gap
  4. Located where each buyer enters the ladder rather than assuming they start at the bottom
Artefacts
  • Decision map per segment
  • Evidence thresholds
  • The shortcut path
What it decided

Both segments needed the same object: a defensible figure attached to their own operations, with a range and a date. The shortcut became the design constraint for every output surface.

Session 03

How does the work actually get done?

Draw it before judging it.

InstrumentsService blueprint · hierarchical task analysis
In the roomAnalysts · quantitative research · engineering
Inputs
  • One live engagement, walked through end to end
  • Time records
  • The analysts' own account
What we did
  1. Drew five lanes and ten stages, then walked it back through twice
  2. Decomposed each stage into a task hierarchy with its governing plan
  3. Marked every handoff, every wait, every manual intervention
  4. Placed the line of visibility where it actually sat, not where it should
Artefacts
  • Current-state blueprint
  • Task hierarchy
  • Bottleneck map
  • Touchpoint inventory
What it decided

Ten stages. Three manual bottlenecks consumed most of the elapsed time and all sat below the line of visibility, where no client had ever been able to object to them.

Session 04

What is actually hard about the hard parts?

Elicit the cues, not the opinions.

InstrumentsCritical decision method · cognitive demands table
In the roomSenior analysts — individually, never as a group
Inputs
  • A real completed engagement per interviewee
  • The task hierarchy from session three
What we did
  1. Walked each engagement backwards, incident-style
  2. Probed every decision point for the cues actually used
  3. Asked what a competent newcomer would get wrong, and why
  4. Ran these one-to-one because cue elicitation does not survive an audience
Artefacts
  • Cognitive demands table
  • Cue inventory
  • Novice failure modes
What it decided

Codifiability stopped being a matter of opinion. If the cues could be represented, the step could be assisted. If they could not, it stayed human.

Session 05

Which machine, for which stage?

Allocate per stage, never per task.

InstrumentsLevels of automation · four-gate candidacy screen
In the roomEngineering · quantitative research · compliance perspective · advisory
Inputs
  • Blueprint
  • Task hierarchy
  • Cognitive demands table
What we did
  1. Scored each step for acquisition, analysis, decision selection and action implementation separately
  2. Turned every manual step into an automation candidate
  3. Ran each through four gates designed to be failed
  4. Tracked how many died at each gate, deliberately
Artefacts
  • Allocation matrix
  • Candidate register
  • Rejection rationale with reasons
What it decided

Under a fifth survived. Almost everything died on auditability or on data that did not exist at the resolution assumed — never on ambition.

Session 06

What does the service look like afterwards?

Design the human touchpoints first, then fill in the machine.

InstrumentsFuture-state blueprint · tiering · irony countermeasures
In the roomFull group
Inputs
  • Everything above
  • Commercial constraints
  • Regulatory calendar
What we did
  1. Started from the moments worth protecting and built automation around them
  2. Designed the adjudication queue, visible confidence and retained provenance as service components
  3. Tiered delivery on deliberately different economics
  4. Sequenced the roadmap against the compliance clock rather than engineering preference
Artefacts
  • Future-state blueprint
  • Tiering model
  • Product definition
  • Three-horizon roadmap
What it decided

Three delivery tiers with different economics, and an explicit written list of the moments that stay human on purpose.

Why this shape

Sessions one and two exist because the productisation question is unanswerable without them, you cannot decide what to codify until you know which decision the output serves and what would make someone act on it. Session three produces the instrument the whole engagement turns on. Session four is the one most programmes skip, and it is the one that converts opinion into evidence. Five is deliberately destructive. Six puts the service back together with the people still inside it.

The mixed room was the method, not the logistics. Almost every disagreement that mattered lived between quantitative research and commercial, or between engineering and advisory, never inside a single function. Separate interviews would have produced four internally coherent and mutually incompatible views. One room forced the trade-offs to close in the session. The single exception was session four, run one-to-one, because cue elicitation does not survive an audience.

05 / TRANSFORMATION

From a consulting framework to a system

A consulting framework is really a decision procedure that happens to live in people's heads. Writing it down was most of the work. Deciding what a machine should carry was the rest.

Two artefacts did the heavy lifting. The blueprint pair shows what moved. The ladder gave every capability a current rung and a next one, which finally ended an argument that had been going in circles.

Service blueprint

BEFORE / AFTER
Drag to explore →
CURRENT STATE · WHERE THE EFFORT AND THE RISK ACTUALLY SIT01TRIGGER02FRAME03ACQUIRE04RESOLVE05CLASSIFY06COMPUTE07PROJECT08CHECK09DELIVER10MONITORClientevidence & decisionFrontstage · advisorwhat the client seesBackstage · analysthidden effortSystems & modelscomputationData & feedsinputsLINE OF VISIBILITYRegulation ormarket eventBrief theproblemChallengethe resultBoarddecisionFrame whatis materialInterpret &recommendPresentRe-engagenext yearHunt forthe dataMatch entityto siteRead theregulationConfigurethe modelSet scenarioby handEyeball theoutputWrite thereportRe-runmanuallyValuationlibrarySimulationengineStaticdashboardCustoms &registriesSitecoordinatesForwardcurvesNothingwatchesmanual bottleneckhuman judgementsystemdata sourceThree manual bottlenecks — data hunting, entity matching and report writing — sit entirely below the line of visibility. The client never sees thework that makes the engagement expensive, so nobody ever argues about it. And the final column is empty: the analysis was accurate on the day it wasdelivered and decayed from there.
FUTURE STATE · DESIGNED OUTWARD FROM THE TOUCHPOINTS WORTH KEEPING01TRIGGER02FRAME03ACQUIRE04RESOLVE05CLASSIFY06COMPUTE07PROJECT08CHECK09DELIVER10MONITORClientevidence & decisionFrontstage · advisorwhat the client seesBackstage · analysthidden effortSystems & modelscomputationData & feedsinputsLINE OF VISIBILITYRegulation ormarket eventBrief theproblemExplorescenariosChallengethe resultBoarddecisionFrame whatis materialInterpret &recommendPresentAdjudicateflagged matchesConfirm scopeclassificationApprovematerialityEdit thedraftContinuousingestionEntityresolutionRegulatoryextractionValuationlibraryScenariobuilderAnomalydetectionDraftgenerationChangedetectionCustoms &registriesSitecoordinatesForwardcurvesLivefeedsAI-assisted, human adjudicateshuman judgementdeterministic systemdata sourceThe analyst lane empties of assembly and keeps only adjudication — reviewing what was flagged, confirming a classification, approving materiality,editing a draft. The client gains a touchpoint rather than losing one. Every green cell is a machine acting under a human decision right next to it,never instead of one.
Switch between them and watch the analyst lane. In the current state the client touches four of ten stages and three manual bottlenecks sit below the line of visibility, where nobody could object to them. In the future state assembly work leaves and adjudication stays. The client gains a touchpoint rather than losing one. Every green cell is a machine acting with a human decision immediately adjacent to it.

The codification ladder

FRAMEWORK · CLICK A RUNG
BespokeRepeatableTemplatedParameterisedAutomatedProductised

This ended an argument nobody was going to win. Engineering wanted to automate. Advisory wanted to protect the craft. Both were right, and neither could prove it. Giving each capability a current rung and a next one turned a values dispute into a sequencing question, and a group can answer that.

Scenario divergence

One engine, many futures. The parameterisation is what turns a bespoke study into a product — inputs become controls a buyer can turn.

Layered reuse

Shared infrastructure serving one bespoke service is over-engineering. Serving a family pays for itself several times over. Same investment, opposite verdict.

Three bands, held apart

Intelligence, deterministic engine and human accountability. Anything that blurs them is a liability wearing the costume of a feature.

The move that changed everything else

Whenever a new market or sector question came in, the firm treated it as its own study. Same analysis, different inputs, another senior week gone. Nobody thought of this as a problem. It was just how the work got done.

What I proposed instead was one engine with a defined set of variables the user controls. A fixed set of combinations turned out to cover most of the questions people actually asked. It was also the cheapest way to test whether any of this held: if a configured analysis could not answer what a bespoke engagement had answered, nothing further down the roadmap was worth starting.

Build the repeatable middle. Protect the two ends. Price them differently.
06 / AI OPPORTUNITY

Found by analysis, then mostly rejected

Candidates came out of the blueprint rather than a technology menu. Every manual step became one, and each had to get through four gates before it went anywhere near a roadmap.

In regulated advice, an inference you cannot explain is a liability. So I built the screen to be failed. The rejections tell you more about the position than the survivors do.

The four-gate candidacy screen

METHODDrag to explore →
AI CANDIDACY SCREEN · DERIVED FROM THE BLUEPRINT, NOT FROM A TECHNOLOGY MENUGATE 01Generatedevery manual step in theblueprint becomes acandidate100%of candidates surviveGATE 02Acts on uncertaintycan the user act on aprobabilistic answer here?71%of candidates surviveGATE 03Survives auditdoes it hold when asupervisor asks how thefigure was produced?45%of candidates surviveGATE 04Data existsat the resolution andrefresh actually claimed28%of candidates surviveGATE 05Failure is visiblea wrong answer is caughtbefore it reaches a decision19%of candidates survivePercentages describe the shape of the screen, not a recorded tally. The value is in what it removes: most ideas die on auditability or on data that does not exist, never on ambition.
Generating candidates is easy. The screen is the work. Ideas that died at gate two were solving the wrong kind of problem. At gate three they would have created regulatory exposure. At gate four they were fantasies about data nobody had. Only the final gate is really about engineering.

AI capability map

DEFINITIONDrag to explore →
AI CAPABILITY MAP · WHAT EACH CAPABILITY IS FOR, AND WHAT IT IS FORBIDDEN FROM DOINGPerception & extractionRegulatory readingextract scope, dates, thresholds andaffected codes from legal textBOUNDARYclassify only — a rules engine verifies,the financial engine calculatesDocument intakepull site lists, ownership andproduction data from unstructuredfilingsBOUNDARYnever infers a value that is absent fromthe sourceResolution & linkageEntity resolutioncompany → subsidiary → operating site →coordinate, at portfolio scaleBOUNDARYevery match is evidenced and reversible;low-confidence goes to a queueAsset characterisationinfer construction type and criticalityfrom imagery and recordsBOUNDARYfeeds vulnerability, never overrides asurveyed valueReasoning & assistanceAnomaly detectionflag results that breakorder-of-magnitude or directionexpectationsBOUNDARYraises, never suppresses; the analystadjudicatesScenario translationturn a plain-language question intoengine parametersBOUNDARYproposes the parameter set; the user seesand confirms itGenerationNarrative draftingfirst draft of the client-facingexplanation from the computed resultBOUNDARYdrafts prose around numbers it did notproduceEvidence assemblyassemble the audit trail behind adisclosure figureBOUNDARYassembles provenance; never authors anumber
Every capability carries an explicit boundary. A capability defined only by what it does will drift into doing more. One defined by what it must not do survives contact with a compliance function. The boundaries are the load-bearing half of this diagram.

The architecture boundary

PRINCIPLEDrag to explore →
THE ARCHITECTURE BOUNDARY · THE SINGLE MOST CONSEQUENTIAL DECISION IN THE CASEINTELLIGENCE LAYERUnderstands, retrieves, draftsprobabilistic · always supervised · never authoritativeread and classify regulatory textresolve entities to physical assetsretrieve prior analysis and evidencedetect anomalies in inputs and outputstranslate intent into engine parametersdraft the first narrativeDETERMINISTIC ENGINECalculates, and is explainable by mandatereproducible · versioned · auditable line by lineembedded intensity and carbon costvaluation and risk metricshazard × vulnerability damage functionsscenario mathematicsportfolio aggregationeverything that gets signed offACCOUNTABILITY LAYERDecides, and carries the consequencecannot be delegated to either layer abovewhat is material for this businesswhether the result is crediblethe recommendation itselfnegotiation with counterpartiessign-off and its consequencesthe client relationshipA technical buyer does not test an AI position by what it promises. They test it by what it declines to promise.
The single most consequential decision in the case. Intelligence understands, retrieves and drafts. The engine calculates, and has to be explainable. People decide, and carry the consequence.

Three horizons against the regulatory clock

SEQUENCEDrag to explore →
AI ROADMAP · SEQUENCED AGAINST THE REGULATORY CLOCK, NOT ENGINEERING PREFERENCETHE CLOCK SETS THE ORDERReporting obligations widendisclosure of anticipatedfinancial effects becomes thebinding requirementBorder levy costs begin tobitereporting turns into payment; freeallowances start withdrawingCosts scale past thematerial thresholdthe figure becomes a board-levelnumber, not a compliance lineFull phase-inthe mechanism reaches 100% and theanswer must be defensible at auditHORIZON 1Prove the codificationParameterised regulatory-cost analysis replaces thebespoke studyEntity resolution as an internal analystaccelerator, behind the line of visibilityRegulatory extraction feeding a rules engine, not acustomer-facing claimEvidence trail captured from day one — retrofittingprovenance is not possibleTests the whole thesis at the lowest cost. If aconfigured analysis cannot answer what a bespokeengagement answered, nothing further is worth starting.HORIZON 2Extend the surfaceClient-facing scenario exploration with the analystin an approval roleAnomaly detection on every automated path, feeding areview queueNarrative drafting on computed results, analystedits and signsPhysical exposure joined to the transition engine onone asset spineOnly starts once Horizon 1 has produced an audit trailpeople trust. Each item widens who can use the systemwithout widening who is accountable for it.HORIZON 3Compound the intelligenceCross-client exposure intelligence feeding theportfolio-side productAdaptation and mitigation options priced against thesame cost engineContinuous monitoring replacing the annual snapshotAgentic assembly of disclosure packs, human sign-offunchangedThe flywheel. Serving asset-heavy operators generates thebottom-up intelligence that makes the institutionalproduct defensible — the strategic reason for twosegments.
The compliance calendar sets the order, not engineering preference. Regulation hands you the requirements and the deadline at the same time, which is unusually convenient. The sequencing argument comes from outside, so nobody has to win it internally every quarter.
07 / THE PRODUCT

One core, and a navigation that finally said what it sold

Once the repeatable middle was isolated, the components underneath turned out not to be specific to any one kind of risk. The same core answers several quite different commercial questions.

The clearest evidence of the whole engagement is a menu. Where a capability sits in the navigation encodes what the firm believes it sells.

Shared core and product family

ARCHITECTUREDrag to explore →
PRODUCT SYSTEM · ONE CORE, CONFIGURED FOR DIFFERENT DECISIONSPRODUCTRegulatory costwhat an incoming levy adds to thecost base, by year, product andsupply originBUILD FIRSTPRODUCTCorporate exposurecontinuous view of margin riskacross commodity, energy, FX andratesBUILD NEXTPRODUCTPhysical asset riskasset-level exposure and thecash-flow consequence of itBUILD NEXTPRODUCTTransition twinbusiness-as-usual against abatementalternatives, pricedLATERPRODUCTPortfolio climate viewholdings screened onclimate-adjusted risk, fed by theaboveLATERSHARED COREEntity & asset resolutioncompany → facility → coordinateHazard & driver layerphysical hazards, policy, pricesAnalytics & valuationturns exposure into moneyScenario & simulationalternative futures, consistentlyDelivery & evidenceinterface, API, provenance trailDATA FOUNDATIONearth observation · customs & trade · registries · forward curvesADVISORY LAYERmateriality · interpretation · recommendation · accountabilityShared infrastructure serving one bespoke service is over-engineering. Serving a family pays for itself several times over. Same investment, opposite verdict.
Reusable infrastructure serving one bespoke service is over-engineering. Serving a family pays for itself several times over. Same investment, opposite verdict. The difference is a product decision that engineering had been waiting on without knowing it.

Information architecture, before and after

RESTRUCTUREDrag to explore →
INFORMATION ARCHITECTURE · THE NAVIGATION IS WHERE THE PRODUCTISATION BECOMES VISIBLEBeforeorganised by the firm's own systemsMarketMarket overviewMarket detailedEarth observationPortfolio overviewPortfolio detailedTradeSwap pricerTrade draftsCommodity exposure+1 moreAnalysisCustom book managementCommodity position summaryRegulatory costBooksEnd of day summaryReturns analysis+2 moreInternalMarket fit monitorBook risk+3 moreAfterorganised by how risk and regulation decomposeGlobal riskOverviewScenario analysisTransition riskOverviewEmissions tradingBorder levyDeforestationSustainability reportingScenario analysisPhysical riskOverviewScenario analysisrestructureThe same capability moves from a lineitem inside an internal trading menu toa named branch of the risk taxonomy thatthe client, the auditor and theregulator all already use.That single move is the productisation,made visible.Navigation is not decoration. It encodes what the firm believes it sells — which is why restructuring it was a product decision, not a design refresh.
The productisation, made visible. A capability moves from a line item inside an internal trading menu to a named branch of the risk taxonomy the client, the auditor and the regulator all already use. Nothing about the underlying computation changed. Everything about what it was changed.

Two segments, and why that is a strategy rather than a compromise

Serving two very different buyers normally costs focus. Here it did the opposite. Analysing asset-heavy operators, their sites, their inputs, their exposure to policy and weather, generates something that did not previously exist: granular, bottom-up intelligence about which real operations are fragile.

That is precisely what institutional investors need to judge which companies and assets are safe to hold. The operator business produces the raw material that makes the investor business defensible. One improves as the other grows, which turns an apparent lack of focus into a data flywheel, and it is the reason the roadmap's third horizon exists at all.

08 / INTERFACE

Where the analysis becomes something a person can use

Four surfaces redesigned from the working product, three proposed for capabilities the analysis defined but the platform had not yet reached. Anonymised throughout; every figure illustrative, computed on published mechanisms.

These are the human factors instruments cashed out. The situation-awareness split, the decision-ladder shortcut, the function allocation and the countermeasures for automation's ironies each appear here as concrete design decisions.

Physical exposure — asset register

Hazard filter, geospatial field, scenario controls and asset-level scoring on one surface

REDESIGNEDDrag to explore →
Risk platform
Global risk
Overview
Scenario analysis
Transition risk
Overview
Emissions trading
Border levy
Deforestation
Sustainability reporting
Scenario analysis
Physical risk
Overview
Asset register
Scenario analysis
River floodingSurface floodingStorm surgeWildfire
592574
FLOOD DEPTHassets in extent
InsightData
Estimated loss p.a.5.8%of replacement value · expected annual loss
28% low52% medium20% high
Provenance · hazard layers dated Q1 · pathway per stated regulatory scenario · figures illustrative
Asset register — score 1–100, banded 1–49 low / 50–69 medium / 70+ high
AssetACUTERiver floodingACUTESurface floodingACUTEStorm surgeACUTEWildfireACUTEDroughtACUTEWindCHRONICCoastal floodingCHRONICSubsidenceCHRONICExtreme heat
SITE-023941569240302354545454
SITE-122452518645303030535630
SITE-121234568912531554545454
SITE-121442609586242054545454
SITE-121344549234304553535353
SITE-434345548565655449494949
Three situation-awareness levels, three regions. Hazard filters and the field answer what is present. The asset register answers what of ours sits there. The scenario controls and the loss figure answer what it costs us. The acute/chronic split is not a design choice — it is the taxonomy the disclosure standard uses, so the screen produces reportable output by construction.

Global exposure — four drivers on one surface

Commodity, energy, macro and financial exposure with the cashflow schedule underneath

REDESIGNEDDrag to explore →
Risk platform
Global risk
Overview
Scenario analysis
Transition risk
Overview
Emissions trading
Border levy
Deforestation
Sustainability reporting
Scenario analysis
Physical risk
Overview
Asset register
Scenario analysis
Commodity
€2.3M
1 day+9,1461 month+259,450Year to date−351,245
Energy
€3.5M
1 day−11,1561 month−263,130Year to date−361,211
Macro
€5.1M
1 day+22,2951 month+563,130Year to date+361,211
Financial
€22.5M
1 day−52,3561 month−1,004,000Year to date−1,200,000
Exposure summarybook · illustrative
Total exposure56,953,128
Total exposure NPV−55,434,734
Price differential−6,020,153
Company cost−61,454,887
Residual risk−748,926
Cashflow schedulenotional, price and present value by month
DateTotal notionalFixed notionalAggregateMarketCF (PV)
2026-0140,71315,39656.7055.74-2,300,964
2026-0239,70515,31256.6655.71-2,238,026
2026-0340,96515,85756.6555.62-2,303,995
2026-0440,20914,81856.5855.64-2,254,553
2026-0538,90712,81160.6155.44-1,131,657
2026-0640,02014,37056.3555.32-2,223,306
Notional calendarfixed against unfixed exposure
price fixednot fixed
Exposure against market curveaggregate price versus market
marketaggregate
The claim was “four business drivers in one place”. This is what that has to mean. Each driver carries a current mark and three deltas, because a CFO reads direction before magnitude. The schedule below is the audit trail for the number above — the same figure, decomposed to the month, which is what makes it defensible when challenged.

Regulatory cost — one engine, four states

The bespoke country study, turned into a configurable analysis. Same screen, four parameter sets.

REDESIGNED
A
Single origin

Base parameters only. One country, cost as a share of import value.

Analysis
Display
Benchmarking
Projection
20262034
Global avgOrigin B
OriginLevy cost
Global avg6,860
Origin B5,096
B
With base material

Base material cost switched on — the levy is now shown against what the goods themselves cost.

Analysis
Display
Benchmarking
Projection
20262034
Global avgOrigin B
OriginBase materialLevy cost
Global avg17,0566,860
Origin B15,4165,096
C
Benchmarked origins

Seven origins compared on the same basis. This is the state that changes a procurement decision.

Analysis
Display
Benchmarking
Projection
20262034
Global avgOrigin AOrigin BOrigin COrigin DOrigin EOrigin F
OriginBase materialLevy cost
Global avg17,0566,860
Origin A15,4161,960
Origin B16,4005,096
Origin C17,3845,096
Origin D18,3685,880
Origin E19,3527,448
Origin F20,3368,624
D
Forward projection

Phase-in applied across the compliance period, all origins, cost per year.

Analysis
Display
Benchmarking
Projection
20262034
202620272028202920302031203220332034
Origin AOrigin BOrigin COrigin DOrigin E
Origin2026202820312034
Origin A2,50010,00061,000100,000
Origin B6,50026,000158,600260,000
Origin C7,50030,000183,000300,000
Origin D9,50038,000231,800380,000
Origin E11,00044,000268,400440,000
This is the parameterisation, designed state by state. Dependent controls disclose progressively — origins stay inert until benchmarking is switched on, the date range until projection is. The output table recomposes with each state rather than showing empty columns. Four states cover the large majority of real questions, which is precisely why the study did not need to be rebuilt each time. Figures illustrative, computed on the published mechanism.

Scenario — fixing the moving parts

Forward-curve bumps on FX and carbon price, with the resulting cost path

REDESIGNEDDrag to explore →
Risk platform
Global risk
Overview
Scenario analysis
Transition risk
Overview
Emissions trading
Border levy
Deforestation
Sustainability reporting
Scenario analysis
Physical risk
Overview
Asset register
Scenario analysis
Scenario constructionwhat is being held, and what is being moved
Curve bumpsparallel shift applied to the forward curve
FX forward
+10%
Carbon price
+10%
Base commodity
0%
Bumping the curve is how a hedge gets sized. The screen exists because fixing the moving parts was the recommended action — so the control had to be in the product, not in a spreadsheet behind it.
Resulting cost pathillustrative, on the published phase-in shape
202620272028202920302031203220332034
with bump appliedunbumped baseline
Cumulative, 5-year horizon€246kper €1m of annual import value
Sensitivity to the bump+18%against the unbumped path
A written recommendation became an interaction control. The advisory finding was to hold the volatile inputs still by hedging the forward curves. Rather than leaving that as advice in a document, the parameter was put in the product — so the client can size the hedge themselves and see the path move. The dashed baseline stays on screen because a scenario without its counterfactual is not a scenario.

Regulatory coverage — requirement to capability

Every disclosure clause mapped to the capability that answers it, and the ones deliberately left to the client

NEW · PROPOSEDDrag to explore →
Risk platform
Global risk
Overview
Scenario analysis
Transition risk
Overview
Emissions trading
Border levy
Deforestation
Sustainability reporting
Scenario analysis
Physical risk
Overview
Asset register
Scenario analysis
RequirementCovered byStatus
Processes to identify and assess climate riskDescribe the process, own operations and value chain, under multiple pathways including a high-emissions one Core platformCost engine Covered
Hazard identificationIdentify hazards, define short, medium and long horizons Core platform Covered
Exposure assessmentAssess exposure of assets and activities, considering location and hazard likelihood and severity Core platform Covered
PoliciesDescribe policies to manage material climate impacts, risks and opportunities Client-authored
Actions and resourcesDisclose mitigation and adaptation actions and the resources allocated Adaptation module Partial
TargetsDescribe targets for adaptation and physical risk mitigation Adaptation module Partial
Anticipated financial effectsMonetary amount and share of assets at material physical risk, split acute and chronic Core platformCost engine Covered
Location of significant assetsDisclose location of significant assets at material physical risk Core platform Covered
Net revenue at riskNet revenue from activities at material physical risk, monetary and proportional Cost engine Covered
Methodology disclosureScope, horizons, calculation methodology, critical assumptions and limitations Cost engine Covered
Reconciliation to the accountsReconcile to the relevant financial statement line items Client-authored
Requirement wording paraphrased from the public disclosure standard. Coverage marks are a product decision, not a compliance opinion.
Proposed, not shipped — and the one I would build first. Regulation writes the requirements backlog and sets the deadline. Mapping clause to capability produces three artefacts at once: a roadmap, a sales asset, and an honest statement of what the product does not do. Marking two rows as client-authored is what makes the other nine credible.

Transition twin — act, divest, or do nothing

The same exposure priced three ways over one horizon

NEW · PROPOSEDDrag to explore →
Risk platform
Global risk
Overview
Scenario analysis
Transition risk
Overview
Emissions trading
Border levy
Deforestation
Sustainability reporting
Scenario analysis
Physical risk
Overview
Asset register
Scenario analysis
actInvest in adaptation
Revenue disruption0.0
Adaptation CAPEX−2.9
Residual damages−50.8
Insurance premium−28.0 to −112.1
Net 10-year impact−80.9 to −165.0
actDivest the exposure
Revenue disruption0.0
Replacement CAPEX−41.1
Residual damages−50.8
Insurance premium−28.0 to −112.1
Net 10-year impact−119.9 to −204.0
don't actDo nothing
Revenue disruption−9.7
CAPEX0.0
Total damages−169.3
Insurance premium−93.5 to −373.8
Net 10-year impact−272.4 to −552.8
Structure follows published adaptation-finance practice. Values illustrative — the point is the comparison, not the magnitude.
Proposed, not shipped. The engine already produced the cost of inaction; what it did not produce was the alternative. A decision-maker cannot act on one number — they act on the difference between options. Putting the counterfactual on the same screen turns an analysis into a decision object, and it is the shortest path from the existing calculation to a recurring commercial conversation.

Adjudication queue — where the human stays

The exception surface that makes automation defensible

NEW · PROPOSEDDrag to explore →
Risk platform
Global risk
Overview
Scenario analysis
Transition risk
Overview
Emissions trading
Border levy
Deforestation
Sustainability reporting
Scenario analysis
Physical risk
Overview
Asset register
Scenario analysis
17items awaiting adjudication
96% auto-resolved this run0 auto-accepted below thresholdfull provenance retained
TypeWhy it was raisedContextConfidence
Entity match Operator name on the site licence differs from the registry parentTwo candidate parents share a trading name Site 12442 · rolling mill
0.62
AcceptCorrect
Scope classification Production route ambiguous between two eligible codesRoute determines whether upstream inputs are in scope Consignment 8841
0.58
AcceptCorrect
Anomaly Cost per tonne 3.4× the sector median for this originDirection and magnitude both outside expected band Origin D · Q3 batch rule AcceptCorrect
Entity match Registry shows dissolution mid-periodOwnership transferred, coordinates unchanged Site 09813
0.71
AcceptCorrect
Extraction Threshold value absent from the published textFalls back to the prior period value pending review Regulatory update · clause 14
0.44
AcceptCorrect
Nothing on this screen has been applied. Every row is a machine proposal held behind a human decision, and every decision is written to the evidence trail.
Proposed, not shipped. Automating the easy cases makes the residual ones harder and rarer — the classic irony of automation. This screen is the countermeasure: the machine never applies a low-confidence result, it queues it with the reason it was raised and the evidence behind it. Confidence is shown because trust has to be calibrated, not assumed. The queue is also the training signal.
09 / VALIDATION

How you would know any of this is right

None of it deserves engineering time until the load-bearing assumptions have been tested. Four carry the weight, and each has a decision attached, including the decision to stop.

What has to be trueHow you would test itWhat counts as a passWhat it means if it fails
A configured analysis answers what previously needed a bespoke engagement.Re-run three completed engagements through the parameterised version. Put both outputs in front of the original clients, unlabelled.Clients cannot reliably tell which is which, and act on the configured one.The repeatable middle is narrower than the allocation suggested. Re-score and shrink scope before building further.
Buyers will pay for a figure they can act on without an advisor attached.Sell the configured analysis alone, at a price the underserved segment can carry, before it is fully built.Paid commitments from buyers outside the existing advisory relationships.The product is a lead generator for advisory, not a business line. Price it as one.
Automated resolution is accurate enough to be trusted at the boundary.Blind-test against a hand-matched set from past engagements. Measure false matches and missed matches separately — they have different costs.False matches near zero; missed matches acceptable provided every one is flagged.Keep it as an internal accelerator behind the line of visibility rather than a client-facing capability.
Self-service does not erode the advisory revenue beside it.Track advisory engagement value among the clients who adopt the product first.Advisory value holds or rises — the product opens the conversation rather than closing it.Tier the access so the product deepens the relationship instead of substituting for it.
Every test has a fallback, not just a threshold. A validation plan that describes only success is a plan to rationalise whatever happens.
10 / CONTRIBUTION

What I did, and what was already theirs

The domain expertise was theirs. The financial models, the risk knowledge, the architecture and the science existed long before I arrived, and I could not have produced any of it.

What I brought was a way of taking an expert service apart.

I designed and ran the discovery programme

Six sessions structured as decision engines rather than information gathering, with a deliberately mixed technical and commercial room, and one deliberately individual session where a group would have destroyed the data.

I ran the cognitive work analysis

Abstraction hierarchy, hierarchical task analysis, and critical decision method interviews producing the cognitive demands table. The sequence that turned “which bits can we automate” from an argument into a finding.

I built the current-state service blueprint

Five lanes, ten stages, every handoff and manual step surfaced, including the monitoring gap that nobody had noticed because it was an absence rather than a problem.

I ran the function allocation with the team

Levels of automation assigned per processing stage rather than per task, which is what produced a defensible answer instead of a binary one.

I built the codification ladder and screened the AI candidates

Candidates derived from the blueprint, then killed through a four-gate screen weighted towards auditability and data reality over ambition.

I defined the architecture boundary

The separation between intelligence, deterministic engine and human accountability, the principle that makes the AI position survive both a regulator and a technical investor.

I designed the future-state service, the tiering and the roadmap

Built outward from the human touchpoints worth protecting, with three delivery tiers on deliberately different economics and three horizons anchored to the compliance calendar.

I restructured the navigation and designed the product surfaces

The navigation move from internal systems taxonomy to risk taxonomy, the parameterisation states, the scenario controls, the asset register, and the public-facing site.

Most of it was working out which parts a machine could carry and which genuinely could not, then turning that into something the firm could build, price and sell. The part I am most pleased with is that nobody had to pretend the experts were the problem.