The framework's eleven published disclosures as a fixed spine — each carrying a state the app derives instead of asserting, and under every figure the four facts that make it defensible: source · vintage · scenario · method. If one of the four does not resolve, there is no figure.
And which recommendations to formally declare not compiled — with the reason and the remediation plan the regulator's own checklist asks for. That decision is made once a reporting cycle by the person whose name sits under the document.
The buyer of record is the ESG / disclosure lead, not the credit-risk desk. The artefact is a published document with a filing date, not a book of business, and the failure that keeps this person awake is a recommendation nobody can show evidence for — not an exposure nobody priced.
An app that concedes most of the framework is unusual. It is precisely what makes the four it does serve defensible — and not coverable is the state the regulator's checklist explicitly asks a filer to explain.
“132 locations… only 6 identified with a high critical score… 4 are owned with a total book value of approximately $8 million.” That is the standard's amount and percentage of assets vulnerable to physical risk, answered properly — offline, and reported as prose.
The report ends with a References and Supporting Documentation table — the filer knows they owe provenance. The physical-risk row reads “FEMA Data”. No dataset name, no version, no publication date, no return period, no scenario, no method.
It self-indexes A.1…D.2 — ten section labels against eleven recommended disclosures. One is folded into a table and nothing reconciles the index. The coverage claim is asserted by the author, not derived from state.
It says the data was used to map the risks. Sixteen pages, and the report contains no map — the geography exists only as place names in a table cell.
The market is not failing to do the spatial work. It is failing to make the spatial work evidential: unmapped, unsourced, undated, and indexed by hand.
Section 1 of the California Air Resources Board's checklist requires every climate-related financial risk report to state which framework is applied and — using it as the reference point — which recommendations and disclosures have been compiled and which have not, with the reasons and the plans for future disclosure.
So the app's headline artefact is not a design conceit. It is a named deliverable the statute's guidance asks for, and which the market is currently producing as a paragraph in a conclusion.
The Ninth Circuit stayed enforcement pending a First Amendment appeal and CARB has said it will set an alternate date. A budgeted, dated, publicly-scored obligation with a paused clock is exactly when a preparer audits their own coverage instead of filing.
ISSA 5000 applies to engagements on information reported for periods beginning on or after 15 December 2026, and requires estimates to be “supported by evidence and based on proper methods, assumptions”, with auditors “checking data sources”. The provenance strip is what an assurer will ask for.
28 jurisdictions had adopted IFRS S2 and requirements were in effect in 19 as of April 2026. The line-item rack is portable. The hazard layers, the boundaries and the statute behind them are not — a deployment elsewhere re-sources the data entirely and re-labels the statute.
| Tier | Organised by | What it delivers | Does it bite here? |
|---|---|---|---|
| Physical-risk data vendors | asset and peril | asset-level scores, damage ratios, hazard depth — some marketed against the standard's paragraph numbers | Partly — a dataset mapped to paragraphs, not a report state mapped to line items |
| Disclosure-management platforms | framework line item | completion trackers, XBRL tagging, collaboration — the completeness idea already exists and is sold | Partly — but it tracks has someone written something |
| Property peril / underwriting APIs | a single address at bind time | roof condition, per-peril scores, instant property intelligence | No — no framework, no reporting period, no document |
| Compliance mapping for another statute | assessment area | the one benchmark that ships a regulator-ready map inside a compliance file | No — different statute, different mandate, no completeness claim |
| The join | the figure itself | a figure that knows which line item it evidences and which dated source produced it | This is the product |
The vendors that know where the assets are publish no date on an output figure. The platforms that know which sections are written have no map, no coordinate, and no notion of a spatially-derived figure.
One third-party review of the data tier put the seam in a single clause: they deliver the physical-risk depth, “although additional tools may be needed for transition risk and disclosure workflows.” The real incumbent, of course, is a spreadsheet.
Eleven recommended disclosures, transcribed verbatim from the framework's own Figure 4 and shipped as a file. The app cannot flatter itself by choosing what to count — which is exactly what the filed report did by shipping ten labels for eleven disclosures.
A figure counts only when its source, vintage, scenario and method all resolve. Completion trackers count written. Physical-risk vendors count scored. Neither counts dated.
Incumbents report a completion percentage over items they chose to track. Publishing the excluded set — with reasons — is the move that makes the other two numbers trustworthy.
Every state pairs a glyph with a word, so the rack survives a greyscale print, a photocopied appendix and a colour-blind reader — colour is the second signal, never the only one. And the counter is computed from exactly those four resolutions, so it moves only when the evidence moves: null one source's vintage and its line item falls to unevidenced and the counts follow. Both are asserted in the suite.
Not “the report is 80 % complete”, and not “your assets score 7.2”, but this — computed from state, against a denominator the app did not choose:
That second line falls out of the same state, and no benchmark can produce it. One sentence, computed from the vintage fields, telling a signatory whether the document in front of them rests on current mapping — before they sign it.
The anchor figure underneath it is the standard's most spatial sentence — the amount and percentage of assets vulnerable to climate-related physical risks — computed at each position's own coordinates against the full-resolution published polygons: 247 of 1,400 positions, $129.6 m of $748.0 m, 17.3 %.
A source that publishes no retrievable publication date is disqualified as evidence, whatever else it offers — and the rule was written before we knew it would cost us three lanes.
The rule is not academic. A federal hazard index changed under reporters mid-cycle in the same twelve months a filed report cited it as “FEMA Data”. That report cannot be re-checked by its own reviewer, let alone by an assurer.
The federal index publishes “No Rating” for wildfire on ground where the state fire authority publishes High or Very High. Neither source is wrong; they answer different questions. A single-source report picks one silently — the app prints both and names the disagreement.
There is no single current statewide fire-hazard layer: the picture is the union of two services — 28,175 polygons, two vintages, two class schemes. Both dates print. The app never collapses them into one, and never prints a range.
Tracts no published surface speaks to are their own class, not the pale end of a ramp. Tracts with no index record are a different hue, not the lightest blue — painting an absence as the low end reads as least loss.
The mapping library's default tiler discards small features inside a tile. At statewide zoom the large rural tracts of the eastern desert drew and the small dense tracts of the coastal corridor did not — which is where the portfolio actually is.
3,526 features really were rendered, so every size, count and feature assertion passed while the map made a false spatial claim. Rendered features went 4,912 → 10,541 once fixed, and the guard is now geographic: the suite projects four named cities and asserts a tract is drawn at each of their coordinates.
A ring-orientation test written the wrong way round turns every subsequent part of a multipart polygon into a hole cut out of the first part. It throws nothing and looks correct on a simple shape.
1,000+ of 9,129 tract points fell “outside” a hazard surface that in fact covers them — and the counts still reconciled against the server. After the fix the seismic lane reproduces the recipe's independent measurement to the dollar. That is what validates the pipeline.
Blind every vintage and nothing is evidenced and all four in-reach items fall to unevidenced. Null one source's vintage and only the items citing it move. Add a twelfth line item and the denominator becomes 12 with no layout edit. All three are assertions, not claims.
The running app makes no request to any public host — asserted from the browser's own network log, not from reading the code. The map library is vendored; every public call happens at build time, behind the perimeter.
The pack is derived from the rack by the same resolver. There is no tray, nothing to add and nothing to remove — a line item's state decides whether its sheet is a figure or a declared gap, and the suite proves no control offers otherwise.
Reading the figures: the reporting geography, the hazard surfaces and the framework line items are real, published and probed — the line items transcribed verbatim from the standard's own figure. The collateral register is GENERATED (seed 20260817), anchored to published lending aggregates within 0.12 %, and labelled as such on every screen, in every popup and on every sheet of the pack.
Every one of these is written into the delivered application's own README. A tool that hides its edges costs you the project it cannot finish.
Your portfolio at position grain with coordinates, the framework your filing names, and an owner for each hazard lane you intend to cite. Two weeks, and this rack reads your draft instead of a generated one — and tells your signatory, four weeks out, exactly what is still unevidenced.
Swappable by configuration, not by code: the framework spine, the source registry and the reporting geography. The eleven line items are a file; the four facts a figure must resolve are a rule. Neither is hardcoded to a US statute.