__MK__tabaqat · StrataFinancial Services
The Evidence Rack — Climate-Risk Regulatory Reporting

Which line items can you
actually prove?

The framework's eleven published disclosures as a fixed spine — each carrying a state the app derives instead of asserting, and under every figure the four facts that make it defensible: source · vintage · scenario · method. If one of the four does not resolve, there is no figure.

California reference implementation · 9,129 census tracts · 559 assertions green On-prem · no keyed provider · no runtime call to any public host
© 2026 Tabaqat · Built on Strata — sovereign geospatial applications. The collateral register is GENERATED (seed 20260817) and illustrative — not any institution's. Public layers are shown exactly as published.
The decision this drives

What the disclosure team chases in the four weeks that are left.

And which recommendations to formally declare not compiled — with the reason and the remediation plan the regulator's own checklist asks for. That decision is made once a reporting cycle by the person whose name sits under the document.

The buyer of record is the ESG / disclosure lead, not the credit-risk desk. The artefact is a published document with a filing date, not a book of business, and the failure that keeps this person awake is a recommendation nobody can show evidence for — not an exposure nobody priced.

Preparer — what is still unevidenced? Reviewer — where did this figure come from? Signatory — can each number be traced to a source and a date?
4of the framework's eleven recommended disclosures are within a spatial product's reach — and the app declares the other seven not coverable, with the reason, rather than implying coverage

An app that concedes most of the framework is unusual. It is precisely what makes the four it does serve defensible — and not coverable is the state the regulator's checklist explicitly asks a filer to explain.

The finding that shaped the app

We read a filed report. Its physical-risk provenance is one word: “FEMA”.

The spatial work was done

“132 locations… only 6 identified with a high critical score… 4 are owned with a total book value of approximately $8 million.” That is the standard's amount and percentage of assets vulnerable to physical risk, answered properly — offline, and reported as prose.

The provenance row is one word

The report ends with a References and Supporting Documentation table — the filer knows they owe provenance. The physical-risk row reads “FEMA Data”. No dataset name, no version, no publication date, no return period, no scenario, no method.

Ten labels for eleven disclosures

It self-indexes A.1…D.2 — ten section labels against eleven recommended disclosures. One is folded into a table and nothing reconciles the index. The coverage claim is asserted by the author, not derived from state.

It says the data was used to map the risks. Sixteen pages, and the report contains no map — the geography exists only as place names in a table cell.

The market is not failing to do the spatial work. It is failing to make the spatial work evidential: unmapped, unsourced, undated, and indexed by hand.

Why that is expensive, on a date

The completeness statement is the regulator's own ask.

Section 1 of the California Air Resources Board's checklist requires every climate-related financial risk report to state which framework is applied and — using it as the reference point — which recommendations and disclosures have been compiled and which have not, with the reasons and the plans for future disclosure.

So the app's headline artefact is not a design conceit. It is a named deliverable the statute's guidance asks for, and which the market is currently producing as a paragraph in a conclusion.

Statute California Health & Safety Code § 38533 (SB 261, 2023)
Who companies over $500 m revenue doing business in California
Frameworks TCFD (or any successor), IFRS S2, or another government's law
Docket public, CARB-hosted, open 1 Dec 2025 → 1 Jul 2026
Penalty up to $50,000 per reporting year — enforcement stayed, not cancelled

The clock is paused, which is the window

The Ninth Circuit stayed enforcement pending a First Amendment appeal and CARB has said it will set an alternate date. A budgeted, dated, publicly-scored obligation with a paused clock is exactly when a preparer audits their own coverage instead of filing.

And assurance arrives on a date

ISSA 5000 applies to engagements on information reported for periods beginning on or after 15 December 2026, and requires estimates to be “supported by evidence and based on proper methods, assumptions”, with auditors “checking data sources”. The provenance strip is what an assurer will ask for.

The spine travels; the substrate does not

28 jurisdictions had adopted IFRS S2 and requirements were in effect in 19 as of April 2026. The line-item rack is portable. The hazard layers, the boundaries and the statute behind them are not — a deployment elsewhere re-sources the data entirely and re-labels the statute.

Ten products, read one by one

The market split cleanly in two. Nobody owns the join.

TierOrganised byWhat it deliversDoes it bite here?
Physical-risk data vendorsasset and perilasset-level scores, damage ratios, hazard depth — some marketed against the standard's paragraph numbersPartly — a dataset mapped to paragraphs, not a report state mapped to line items
Disclosure-management platformsframework line itemcompletion trackers, XBRL tagging, collaboration — the completeness idea already exists and is soldPartly — but it tracks has someone written something
Property peril / underwriting APIsa single address at bind timeroof condition, per-peril scores, instant property intelligenceNo — no framework, no reporting period, no document
Compliance mapping for another statuteassessment areathe one benchmark that ships a regulator-ready map inside a compliance fileNo — different statute, different mandate, no completeness claim
The jointhe figure itselfa figure that knows which line item it evidences and which dated source produced itThis is the product

The vendors that know where the assets are publish no date on an output figure. The platforms that know which sections are written have no map, no coordinate, and no notion of a spatially-derived figure.

One third-party review of the data tier put the seam in a single clause: they deliver the physical-risk depth, “although additional tools may be needed for transition risk and disclosure workflows.” The real incumbent, of course, is a spreadsheet.

How the finding is rendered

Four states — and the fourth one is stated out loud.

The denominator is published

Eleven recommended disclosures, transcribed verbatim from the framework's own Figure 4 and shipped as a file. The app cannot flatter itself by choosing what to count — which is exactly what the filed report did by shipping ten labels for eleven disclosures.

“Evidenced” is earned by the data

A figure counts only when its source, vintage, scenario and method all resolve. Completion trackers count written. Physical-risk vendors count scored. Neither counts dated.

The excluded set is published

Incumbents report a completion percentage over items they chose to track. Publishing the excluded set — with reasons — is the move that makes the other two numbers trustworthy.

evidencedevery figure resolves all four facts
partialsome figures resolve; the rest are named
unevidencedno complete figure — a declared gap, never a blank
not coverablea boundary this product declares, with the reason

Every state pairs a glyph with a word, so the rack survives a greyscale print, a photocopied appendix and a colour-blind reader — colour is the second signal, never the only one. And the counter is computed from exactly those four resolutions, so it moves only when the evidence moves: null one source's vintage and its line item falls to unevidenced and the counts follow. Both are asserted in the suite.

The application, first paint

The counter comes first, because the counter is the product.

The evidence pack at first paint: the counters and the rack of eleven line items on the left, the pinned map stage on the right showing the California tract choropleth with the legend open, and the provenance strip beneath the figure.
Shipped build, 2026-08-17 — a browser screenshot taken by the automated driver, not a mock-up. On a 1280×800 laptop the counters must be readable without scrolling, or the app's argument is invisible on first paint. The browser suite measures that.
  • An editorial column under a pinned map stage. Deliberately not a console — the reader is a preparer, a reviewer or a signatory reading a document.
  • The rack, derived not authored. Eleven rows, four states, one resolver. Add a twelfth requirement to the spine file and the denominator becomes 12, with no edit to any layout.
  • Read down, open a section, press Show this figure. The stage applies that item's map state and the strip prints all four facts.
  • If one of the four does not resolve, there is no button — the section renders a gap block naming which fact is missing, why, and the remediation.
  • A persistent notice, separate from the status line. Assembled draft, not reviewed, not filed · the register is synthetic and never mixed into a measured figure.
50 behaviours specified and tested
The number that is new

Coverage, gated on provenance — not on authorship.

Not “the report is 80 % complete”, and not “your assets score 7.2”, but this — computed from state, against a denominator the app did not choose:

11 recommended disclosures — published, fixed, transcribed
4 within this product's reach · 7 declared not coverable, each with its reason
of the four: 1 evidenced · 1 partial · 2 unevidenced
oldest source behind any figure in the pack: 1 January 2022

That second line falls out of the same state, and no benchmark can produce it. One sentence, computed from the vintage fields, telling a signatory whether the document in front of them rests on current mapping — before they sign it.

The anchor figure underneath it is the standard's most spatial sentence — the amount and percentage of assets vulnerable to climate-related physical risks — computed at each position's own coordinates against the full-resolution published polygons: 247 of 1,400 positions, $129.6 m of $748.0 m, 17.3 %.

The rack11 disclosures · 4 in reach
Governance (a)not coverable by a spatial product Board oversight is a governance record. Nothing in a map can evidence it.
Strategy (a)unevidenced (0/1) missing: vintage, scenario, method — the horizon dimension needs a pathway, and the pathway lane disqualified itself.
Strategy (b)evidenced (1/1) National Risk Index, census tracts: Data Version December 2025 (1.20.0) · reporting geography: 1 January 2022 — two boundary sets, both printed.
Strategy (c)unevidenced (0/1) missing: vintage, scenario, method.
Metrics & Targets (a)partial (2/4) wildfire and multi-peril resolve; flood and earthquake do not, and are named.
Six more not coverable — Governance (b) · Risk Management (a) (b) (c) · Metrics & Targets (b) (c)
The rack as shipped. A state is never typed by a person: not coverable is a declared boundary, and every other row is decided by whether four facts resolve.
The gate, applied to ourselves

Three of this app's own lanes disqualified themselves on probe.

The context figure: the state's unevaluated seismic surface drawn over California, with a warning beneath it declaring that the lane is context and evidences no line item.
The seismic surface is drawn and declared context — 54.9 % of California's published building value sits inside the state's own unevaluated areas, which is worth seeing and evidences nothing.
Flood no California flood surface reachable from inside a perimeter publishes an effective date. No flood layer is drawn and no flood number is computed.
Scenario the citable record carries zero files; the data sits behind a login and a licence restricting redistribution. No pathway is named, and two line items are declared not compiled.
Seismic the source publishes no retrievable date at any level. Drawn as context. Evidences nothing.

A source that publishes no retrievable publication date is disqualified as evidence, whatever else it offers — and the rule was written before we knew it would cost us three lanes.

The rule is not academic. A federal hazard index changed under reporters mid-cycle in the same twelve months a filed report cited it as “FEMA Data”. That report cannot be re-checked by its own reviewer, let alone by an assurer.

What a map catches that a table cannot

Two published authorities, disagreeing on the same ground.

77 tracts · $38.7 bn

The federal index publishes “No Rating” for wildfire on ground where the state fire authority publishes High or Very High. Neither source is wrong; they answer different questions. A single-source report picks one silently — the app prints both and names the disagreement.

Two vintages, never merged

There is no single current statewide fire-hazard layer: the picture is the union of two services — 28,175 polygons, two vintages, two class schemes. Both dates print. The app never collapses them into one, and never prints a range.

“Mapped and low” ≠ “never mapped”

Tracts no published surface speaks to are their own class, not the pale end of a ramp. Tracts with no index record are a different hue, not the lightest blue — painting an absence as the low end reads as least loss.

The bug that proves the thesis

The mapping library's default tiler discards small features inside a tile. At statewide zoom the large rural tracts of the eastern desert drew and the small dense tracts of the coastal corridor did not — which is where the portfolio actually is.

3,526 features really were rendered, so every size, count and feature assertion passed while the map made a false spatial claim. Rendered features went 4,912 → 10,541 once fixed, and the guard is now geographic: the suite projects four named cities and asserts a tract is drawn at each of their coordinates.

And one in our own arithmetic

A ring-orientation test written the wrong way round turns every subsequent part of a multipart polygon into a hole cut out of the first part. It throws nothing and looks correct on a simple shape.

1,000+ of 9,129 tract points fell “outside” a hazard surface that in fact covers them — and the counts still reconciled against the server. After the fix the seismic lane reproduces the recipe's independent measurement to the dollar. That is what validates the pipeline.

Proof, not promises

Built, driven and measured — 2026-08-17.

559assertions green — 270 live · 124 offline · 165 in real headless Chrome, stable over three consecutive rounds
50behaviours specified, each mapped to the suite that exercises it — the floor is 3
6.13worst informational contrast ratio, in both light and dark — the floor is 4.5, measured against the ground actually painted
9,129census tracts measured at their own published interior points, at full resolution — no sampling, no cap

The counter cannot be flattered

Blind every vintage and nothing is evidenced and all four in-reach items fall to unevidenced. Null one source's vintage and only the items citing it move. Add a twelfth line item and the denominator becomes 12 with no layout edit. All three are assertions, not claims.

The on-prem rehearsal is a test

The running app makes no request to any public host — asserted from the browser's own network log, not from reading the code. The map library is vendored; every public call happens at build time, behind the perimeter.

Nothing can be added to the pack

The pack is derived from the rack by the same resolver. There is no tray, nothing to add and nothing to remove — a line item's state decides whether its sheet is a figure or a declared gap, and the suite proves no control offers otherwise.

Reading the figures: the reporting geography, the hazard surfaces and the framework line items are real, published and probed — the line items transcribed verbatim from the standard's own figure. The collateral register is GENERATED (seed 20260817), anchored to published lending aggregates within 0.12 %, and labelled as such on every screen, in every popup and on every sheet of the pack.

Stated as boundaries, not caveats

What this application will not do.

  • It never asserts compliance. It assembles and evidences. Nothing in it is reviewed, approved or filed — and the suites fail if any of those words ever appears outside its own denial.
  • It covers four of eleven, and says so. Governance, risk-management process and emissions are declared not coverable by a spatial product, with the reason. Carbon accounting is a different product.
  • An analytics layer, never a system of record. Read-only end to end: no write path, no per-user entitlements, no live feed.
  • On-prem, behind the perimeter. No keyed provider and no external call it cannot make from inside a bank's network.
  • No figure without a date. A lane whose source publishes no retrievable vintage renders empty, with its citation — never estimated, and never quietly filled from a neighbouring source.
  • A coverage statistic is not a property verdict. Statewide figures are measured at tract interior points; register figures at each position's own coordinates. They agree in sign and order of magnitude and are not expected to be equal. Both print their method.
  • No headline recomputes when the reader pans. A disclosure figure is as of a stated date — a decision, stated on the method sheet, not an omission.
  • A California demo, not a California pipeline. The obligation and the substrate are Californian and page-verifiable; the spine is portable, the substrate is not.

Every one of these is written into the delivered application's own README. A tool that hides its edges costs you the project it cannot finish.

Point it at your report

One register.
One framework choice.

Your portfolio at position grain with coordinates, the framework your filing names, and an owner for each hazard lane you intend to cite. Two weeks, and this rack reads your draft instead of a generated one — and tells your signatory, four weeks out, exactly what is still unevidenced.

Swappable by configuration, not by code: the framework spine, the source registry and the reporting geography. The eleven line items are a file; the four facts a figure must resolve are a rule. Neither is hardcoded to a US statute.

tabaqat.net → Solutions → Financial Services info@tabaqat.net
© 2026 Tabaqat · Built on Strata. Reference implementation over California census tracts; the collateral register is GENERATED (seed 20260817). Assembled draft — not reviewed, not filed, and not an assertion of compliance.
1 / 13