The thing clients bought
Senior specialists framing what mattered, interpreting the result, and standing behind the recommendation when a board pushed back.
The firm had the expertise and the models. Too much of that value stayed locked inside bespoke client work. I spent time with the analysts working out which parts of a job were the same every time, and which parts were the reason clients paid in the first place. That question turned out to be the product.
An independent, regulated investment manager working on climate and market risk. Around ten senior people, most of them out of global banks, serving two quite different buyers: institutions allocating capital, and asset-heavy operators in industry, energy and agriculture.
They did not sell climate data. They sold the financial consequence of it, worked out against a specific company's own accounts. The analysis was genuinely good. What they could not do was produce it twice without spending the same senior week again.
Senior specialists framing what mattered, interpreting the result, and standing behind the recommendation when a board pushed back.
A financial analytics library, a simulation engine, geospatial intelligence from earth observation, and a deliberately reusable component architecture.
A working platform and dashboards, real, in use, and positioned as evidence of sophistication rather than as the offer itself.
The engineering team had already built one architecture designed to support separate deployments, with shared components they had deliberately made reusable. That only pays back if a family of products is coming. No such family had been defined. The architecture was answering a product question nobody had asked out loud, and that gap turned out to be the whole engagement.
Before I could codify anything I had to understand it properly. A hazard, a policy change or a price move only matters to a finance function once someone has carried it all the way to a number on their own accounts.
Every chain here ends in a decision. An analysis that stops one box short is interesting rather than useful. I think that is why so many climate products never change anything.
Elevation and flow structure is what makes a hazard field location-specific rather than regional. Resolution here determines whether an answer is actionable.
Satellite-derived layers are a data foundation. They only become a risk product once joined to an asset register and a valuation model.
The lattice is the honest bit: exposure is only as good as the link between a legal entity and a physical coordinate.
I did not run a discovery sprint and hope an AI roadmap fell out of it. I ran a cognitive work analysis on the domain, and the automation opportunities came out of that analysis rather than a separate ideas session.
The order matters more than people expect. You need to know what the domain is for before you decompose what the experts do, and you need the cues behind their judgement before you can say what a machine should carry.
Establishes purpose before mechanism. Stops a team building the artefact nobody asked for.
You cannot allocate a function you have not named.
Turns codifiability from an opinion into an evidenced finding.
Per processing stage, never per task. This is what produces a nuanced answer.
Answered by hazard filters, the basemap, and the acute-versus-chronic split.
Answered by the asset register, exposure resolution and vulnerability scoring.
Answered by scenario controls, the loss figure and the forward curves.
Automating the easy cases makes the residual ones rarer and harder. The exceptions have to surface somewhere a person is actually looking.
Trust has to be calibrated rather than assumed. A number without its confidence invites exactly the wrong kind of reliance.
Retrofitting an evidence trail is not possible. If it is not captured at the moment of computation, the answer is undefendable later.
I designed the programme backwards from the decisions that had to be made, not forwards from a discovery template. Each session had one question, one set of instruments, and could not begin until the previous one had produced an answer.
One rule, set at the start: no session ends without a decision written on the wall. If we ran out of time we cut scope, never the decision.
If we cannot name the decision, we cannot build for it.
Eleven capabilities resolved to six claims. The five that failed had no decision above them — which told us more than the six that passed.
The evidence threshold, not the persona.
Both segments needed the same object: a defensible figure attached to their own operations, with a range and a date. The shortcut became the design constraint for every output surface.
Draw it before judging it.
Ten stages. Three manual bottlenecks consumed most of the elapsed time and all sat below the line of visibility, where no client had ever been able to object to them.
Elicit the cues, not the opinions.
Codifiability stopped being a matter of opinion. If the cues could be represented, the step could be assisted. If they could not, it stayed human.
Allocate per stage, never per task.
Under a fifth survived. Almost everything died on auditability or on data that did not exist at the resolution assumed — never on ambition.
Design the human touchpoints first, then fill in the machine.
Three delivery tiers with different economics, and an explicit written list of the moments that stay human on purpose.
Sessions one and two exist because the productisation question is unanswerable without them, you cannot decide what to codify until you know which decision the output serves and what would make someone act on it. Session three produces the instrument the whole engagement turns on. Session four is the one most programmes skip, and it is the one that converts opinion into evidence. Five is deliberately destructive. Six puts the service back together with the people still inside it.
The mixed room was the method, not the logistics. Almost every disagreement that mattered lived between quantitative research and commercial, or between engineering and advisory, never inside a single function. Separate interviews would have produced four internally coherent and mutually incompatible views. One room forced the trade-offs to close in the session. The single exception was session four, run one-to-one, because cue elicitation does not survive an audience.
A consulting framework is really a decision procedure that happens to live in people's heads. Writing it down was most of the work. Deciding what a machine should carry was the rest.
Two artefacts did the heavy lifting. The blueprint pair shows what moved. The ladder gave every capability a current rung and a next one, which finally ended an argument that had been going in circles.
One engine, many futures. The parameterisation is what turns a bespoke study into a product — inputs become controls a buyer can turn.
Shared infrastructure serving one bespoke service is over-engineering. Serving a family pays for itself several times over. Same investment, opposite verdict.
Intelligence, deterministic engine and human accountability. Anything that blurs them is a liability wearing the costume of a feature.
Whenever a new market or sector question came in, the firm treated it as its own study. Same analysis, different inputs, another senior week gone. Nobody thought of this as a problem. It was just how the work got done.
What I proposed instead was one engine with a defined set of variables the user controls. A fixed set of combinations turned out to cover most of the questions people actually asked. It was also the cheapest way to test whether any of this held: if a configured analysis could not answer what a bespoke engagement had answered, nothing further down the roadmap was worth starting.
Candidates came out of the blueprint rather than a technology menu. Every manual step became one, and each had to get through four gates before it went anywhere near a roadmap.
In regulated advice, an inference you cannot explain is a liability. So I built the screen to be failed. The rejections tell you more about the position than the survivors do.
Once the repeatable middle was isolated, the components underneath turned out not to be specific to any one kind of risk. The same core answers several quite different commercial questions.
The clearest evidence of the whole engagement is a menu. Where a capability sits in the navigation encodes what the firm believes it sells.
Serving two very different buyers normally costs focus. Here it did the opposite. Analysing asset-heavy operators, their sites, their inputs, their exposure to policy and weather, generates something that did not previously exist: granular, bottom-up intelligence about which real operations are fragile.
That is precisely what institutional investors need to judge which companies and assets are safe to hold. The operator business produces the raw material that makes the investor business defensible. One improves as the other grows, which turns an apparent lack of focus into a data flywheel, and it is the reason the roadmap's third horizon exists at all.
Four surfaces redesigned from the working product, three proposed for capabilities the analysis defined but the platform had not yet reached. Anonymised throughout; every figure illustrative, computed on published mechanisms.
These are the human factors instruments cashed out. The situation-awareness split, the decision-ladder shortcut, the function allocation and the countermeasures for automation's ironies each appear here as concrete design decisions.
Hazard filter, geospatial field, scenario controls and asset-level scoring on one surface
| Asset | ACUTERiver flooding | ACUTESurface flooding | ACUTEStorm surge | ACUTEWildfire | ACUTEDrought | ACUTEWind | CHRONICCoastal flooding | CHRONICSubsidence | CHRONICExtreme heat |
|---|---|---|---|---|---|---|---|---|---|
| SITE-023941 | 56 | 92 | 40 | 30 | 23 | 54 | 54 | 54 | 54 |
| SITE-122452 | 51 | 86 | 45 | 30 | 30 | 30 | 53 | 56 | 30 |
| SITE-121234 | 56 | 89 | 12 | 53 | 15 | 54 | 54 | 54 | 54 |
| SITE-121442 | 60 | 95 | 86 | 24 | 20 | 54 | 54 | 54 | 54 |
| SITE-121344 | 54 | 92 | 34 | 30 | 45 | 53 | 53 | 53 | 53 |
| SITE-434345 | 54 | 85 | 65 | 65 | 54 | 49 | 49 | 49 | 49 |
Commodity, energy, macro and financial exposure with the cashflow schedule underneath
| Date | Total notional | Fixed notional | Aggregate | Market | CF (PV) |
|---|---|---|---|---|---|
| 2026-01 | 40,713 | 15,396 | 56.70 | 55.74 | -2,300,964 |
| 2026-02 | 39,705 | 15,312 | 56.66 | 55.71 | -2,238,026 |
| 2026-03 | 40,965 | 15,857 | 56.65 | 55.62 | -2,303,995 |
| 2026-04 | 40,209 | 14,818 | 56.58 | 55.64 | -2,254,553 |
| 2026-05 | 38,907 | 12,811 | 60.61 | 55.44 | -1,131,657 |
| 2026-06 | 40,020 | 14,370 | 56.35 | 55.32 | -2,223,306 |
The bespoke country study, turned into a configurable analysis. Same screen, four parameter sets.
Base parameters only. One country, cost as a share of import value.
| Origin | Levy cost |
|---|---|
| Global avg | 6,860 |
| Origin B | 5,096 |
Base material cost switched on — the levy is now shown against what the goods themselves cost.
| Origin | Base material | Levy cost |
|---|---|---|
| Global avg | 17,056 | 6,860 |
| Origin B | 15,416 | 5,096 |
Seven origins compared on the same basis. This is the state that changes a procurement decision.
| Origin | Base material | Levy cost |
|---|---|---|
| Global avg | 17,056 | 6,860 |
| Origin A | 15,416 | 1,960 |
| Origin B | 16,400 | 5,096 |
| Origin C | 17,384 | 5,096 |
| Origin D | 18,368 | 5,880 |
| Origin E | 19,352 | 7,448 |
| Origin F | 20,336 | 8,624 |
Phase-in applied across the compliance period, all origins, cost per year.
| Origin | 2026 | 2028 | 2031 | 2034 |
|---|---|---|---|---|
| Origin A | 2,500 | 10,000 | 61,000 | 100,000 |
| Origin B | 6,500 | 26,000 | 158,600 | 260,000 |
| Origin C | 7,500 | 30,000 | 183,000 | 300,000 |
| Origin D | 9,500 | 38,000 | 231,800 | 380,000 |
| Origin E | 11,000 | 44,000 | 268,400 | 440,000 |
Forward-curve bumps on FX and carbon price, with the resulting cost path
Every disclosure clause mapped to the capability that answers it, and the ones deliberately left to the client
| Processes to identify and assess climate riskDescribe the process, own operations and value chain, under multiple pathways including a high-emissions one | Core platformCost engine | Covered |
| Hazard identificationIdentify hazards, define short, medium and long horizons | Core platform | Covered |
| Exposure assessmentAssess exposure of assets and activities, considering location and hazard likelihood and severity | Core platform | Covered |
| PoliciesDescribe policies to manage material climate impacts, risks and opportunities | — | Client-authored |
| Actions and resourcesDisclose mitigation and adaptation actions and the resources allocated | Adaptation module | Partial |
| TargetsDescribe targets for adaptation and physical risk mitigation | Adaptation module | Partial |
| Anticipated financial effectsMonetary amount and share of assets at material physical risk, split acute and chronic | Core platformCost engine | Covered |
| Location of significant assetsDisclose location of significant assets at material physical risk | Core platform | Covered |
| Net revenue at riskNet revenue from activities at material physical risk, monetary and proportional | Cost engine | Covered |
| Methodology disclosureScope, horizons, calculation methodology, critical assumptions and limitations | Cost engine | Covered |
| Reconciliation to the accountsReconcile to the relevant financial statement line items | — | Client-authored |
The same exposure priced three ways over one horizon
| Revenue disruption | 0.0 |
| Adaptation CAPEX | −2.9 |
| Residual damages | −50.8 |
| Insurance premium | −28.0 to −112.1 |
| Revenue disruption | 0.0 |
| Replacement CAPEX | −41.1 |
| Residual damages | −50.8 |
| Insurance premium | −28.0 to −112.1 |
| Revenue disruption | −9.7 |
| CAPEX | 0.0 |
| Total damages | −169.3 |
| Insurance premium | −93.5 to −373.8 |
The exception surface that makes automation defensible
| Type | Why it was raised | Context | Confidence | |
|---|---|---|---|---|
| Entity match | Operator name on the site licence differs from the registry parentTwo candidate parents share a trading name | Site 12442 · rolling mill | 0.62 | AcceptCorrect |
| Scope classification | Production route ambiguous between two eligible codesRoute determines whether upstream inputs are in scope | Consignment 8841 | 0.58 | AcceptCorrect |
| Anomaly | Cost per tonne 3.4× the sector median for this originDirection and magnitude both outside expected band | Origin D · Q3 batch | rule | AcceptCorrect |
| Entity match | Registry shows dissolution mid-periodOwnership transferred, coordinates unchanged | Site 09813 | 0.71 | AcceptCorrect |
| Extraction | Threshold value absent from the published textFalls back to the prior period value pending review | Regulatory update · clause 14 | 0.44 | AcceptCorrect |
None of it deserves engineering time until the load-bearing assumptions have been tested. Four carry the weight, and each has a decision attached, including the decision to stop.
| What has to be true | How you would test it | What counts as a pass | What it means if it fails |
|---|---|---|---|
| A configured analysis answers what previously needed a bespoke engagement. | Re-run three completed engagements through the parameterised version. Put both outputs in front of the original clients, unlabelled. | Clients cannot reliably tell which is which, and act on the configured one. | The repeatable middle is narrower than the allocation suggested. Re-score and shrink scope before building further. |
| Buyers will pay for a figure they can act on without an advisor attached. | Sell the configured analysis alone, at a price the underserved segment can carry, before it is fully built. | Paid commitments from buyers outside the existing advisory relationships. | The product is a lead generator for advisory, not a business line. Price it as one. |
| Automated resolution is accurate enough to be trusted at the boundary. | Blind-test against a hand-matched set from past engagements. Measure false matches and missed matches separately — they have different costs. | False matches near zero; missed matches acceptable provided every one is flagged. | Keep it as an internal accelerator behind the line of visibility rather than a client-facing capability. |
| Self-service does not erode the advisory revenue beside it. | Track advisory engagement value among the clients who adopt the product first. | Advisory value holds or rises — the product opens the conversation rather than closing it. | Tier the access so the product deepens the relationship instead of substituting for it. |
The domain expertise was theirs. The financial models, the risk knowledge, the architecture and the science existed long before I arrived, and I could not have produced any of it.
What I brought was a way of taking an expert service apart.
Six sessions structured as decision engines rather than information gathering, with a deliberately mixed technical and commercial room, and one deliberately individual session where a group would have destroyed the data.
Abstraction hierarchy, hierarchical task analysis, and critical decision method interviews producing the cognitive demands table. The sequence that turned “which bits can we automate” from an argument into a finding.
Five lanes, ten stages, every handoff and manual step surfaced, including the monitoring gap that nobody had noticed because it was an absence rather than a problem.
Levels of automation assigned per processing stage rather than per task, which is what produced a defensible answer instead of a binary one.
Candidates derived from the blueprint, then killed through a four-gate screen weighted towards auditability and data reality over ambition.
The separation between intelligence, deterministic engine and human accountability, the principle that makes the AI position survive both a regulator and a technical investor.
Built outward from the human touchpoints worth protecting, with three delivery tiers on deliberately different economics and three horizons anchored to the compliance calendar.
The navigation move from internal systems taxonomy to risk taxonomy, the parameterisation states, the scenario controls, the asset register, and the public-facing site.
Most of it was working out which parts a machine could carry and which genuinely could not, then turning that into something the firm could build, price and sell. The part I am most pleased with is that nobody had to pretend the experts were the problem.