Every nature risk model arrives with a number. Two questions decide whether that number belongs anywhere near a price: what did you test this against, and where did it fail?
Most vendors have a confident answer to the first. Very few volunteer the second unprompted, and almost none put it on the front page.
That asymmetry is the live problem in this category. Not that the models are bad — several are genuinely good, and the science underneath them is moving quickly. The problem is that a model with an unpublished error bar is indistinguishable, from the outside, from a model that has no error bar at all. An underwriter cannot tell them apart, so the rational move is to discount both to zero. The honest engines get punished alongside the sloppy ones, and the category stalls.
The fix is not more confidence. It is a habit: put an unvalidated grade beside the price, never inside it.
what a nature risk model is
A nature risk model is any quantitative system that converts ecological information — condition, dependency, hazard, degradation — into a financial expectation: an expected loss, a spread, a rating, a value at risk, a premium.
That definition covers more ground than it looks like, and the distinctions inside it are where most of the trouble starts. A model of condition ("this catchment scores 0.61 on ecological integrity") is not a model of dependency ("this catchment supplies a fifth of that region's water"), and neither one is a model of loss ("a 20% decline here costs this borrower £4m a year"). All three get sold under the same label. Only the third can price anything.
The third is also, where the loss runs through an ecosystem-service dependency rather than a physical hazard, the one that has almost never been validated against measured outcomes. Catastrophe modelling is the counter-example and the standard to beat: flood, wind, and wildfire models have been calibrated and recalibrated against decades of claims, and no insurer needs to be told otherwise. Nature-dependency loss models have no comparable record. That is the specific gap, and it is worth naming precisely rather than smearing it across the whole discipline.
So the first honest thing a nature risk model can do is say which of the three it is.
A nature risk model is only as underwritable as the part of it that has been tested against data it did not see.
The rest of this post is about what that habit looks like when someone actually practises it, using two engines whose authors publish their own failures in public. Both belong to Jay Gutierrez, who works at the intersection of ecological network science and nature-finance translation. We collaborate with him. Fluvion and the Upper Colorado corridor are his — his engines, his numbers, his caveats. Nothing here claims his model prices our instruments, and we are not offering it to you as a prudential rating. We are pointing at the disclosure habit, because the habit is the transferable part.
a backtest is not a forecast
The single most common category error in nature risk is treating historical reconstruction as forward skill.
Fluvion prices one atmospheric corridor — three standing forests in western Amazonas, 324,542 hectares, upwind of the South American soy belt — and backtests it across 22 harvest-years of IBGE crop statistics. The 2021–22 La Niña drought cut Rio Grande do Sul's soy by more than half while the cerrado held; the engine reproduces which regions fell and which held, and repeats that on 2024, a year held out in advance, at a correlation of r = 0.45.
Then the page says the part that matters: the skill is real but modest, it recovers the sign and rank of which regions fall rather than the exact loss, and this is a backtest, not a forecast. A season-ahead warning is described as a research path, with the specific validation gate named as not yet run, and the stated policy is to publish the skill before anything gets called a forecast.
Read as an underwriter, that paragraph does three things a confident number never does. It tells you the model reproduces a pattern, not a magnitude — so it can support triage and relative ranking, not a loss cost. It tells you the held-out test exists and gives you its score, so you can compare it to whatever a naive baseline would get. And it tells you which claim has not been made yet, so you know exactly where the vendor stops and your own judgement starts.
present tense and next tense, labeled separately
The second habit is boring and rare: label what the engine does today, and what it intends to do, in different sentences.
Fluvion takes moisture flow from a published tracking dataset and reconciles it to reanalysis. Running its own moisture-tracking model is described as the next milestone — explicitly not a claim being made today. The corridors are listed with their own status: the Amazon–La Plata soy corridor as priced and backtested, an Andean water tower as attributed but gated, a second one as attributed with mixed sources and no forced claim. The whole engine is stamped Phase 1B, and every figure is flagged as indicative rather than prudential grade.
None of that is modesty for its own sake. It is a roadmap that cannot be misread as a result. Anyone who has watched a pilot-stage metric walk into a term sheet and come out as a covenant knows why the distinction is load-bearing.
The same page also shows what happens when a finding gets tested against its own null models. Pointed at the soy belt, the moisture network returns a concentrated dependency: the top tenth of upwind source cells supply roughly 48% of the belt's imported moisture, and it is not simply the biggest evaporators doing the work. That is a good result. The page then reports that a shuffle preserving only each cell's distance from the belt nearly reproduces the same concentration, and that against randomly drawn equal-area patches the field sits near the middle of the pack. Verdict, in the author's words: decision-useful, not Nature-grade. A sharper map of where the load already sits, not a new law of nature.
Most vendors would have shipped the 48% and stopped.
condition moves the spread, not the headline
Here is the specific mechanic the title is about.
Ecological condition is the thing everyone wants to put in the price, because it is the thing conservation finance is actually trying to change. It is also the thing least likely to have a validated link to a cashflow.
Fluvion's treatment is the clean version. The evidence, as the page reads it, points to condition changing not how much rain a forest makes on average but how steadily it makes it: intact, diverse forest holds its transpiration through drought, while degraded forest wavers under the same heat. Condition is read from observed evaporation volatility and published resilience indicators — and then labelled for what it is, a descriptive, lagging correlate still being validated rather than a proven driver. So it moves the spread and the drought tail. It never moves the headline value. It sits beside the price, not inside it.
An actuary will push back on that last clause immediately, and correctly: a premium is expected loss plus a risk load, the load is driven by volatility and the tail, and anything that moves the tail is therefore in the price. Agreed. The distinction being drawn is narrower than "outside the price," and more useful. The validated headline carries only what has been tested. Everything the condition grade touches arrives as a labelled judgement — an underwriter's loading, set by a person who can defend it and change it — rather than an unvalidated condition score inherited from a model and wearing the same authority as the tested part. Beside the price means beside the validated number, visible as judgement, not dissolved into it.
The headline in that case is roughly $350 a hectare, the indicative value of the downwind soy harvest the corridor forest protects over thirty years, against about $295 a hectare the land itself trades for in Brazil's registry. Every one of the author's qualifiers travels with it: one corridor, one crop, water only, one place the rain lands, Phase 1B, indicative. It is not a RealValue figure from our natural capital accounting, it is not the price of any ensurance instrument, and it is not what the forest is worth. It is a floor on the harvest value one downwind beneficiary can defensibly attribute to that upwind source — an avoided loss, not a payable.
There is also a shape hiding under the headline, and the page shows it rather than smoothing it: the belt's dependency on that moisture swings by a factor of about 3.3 between wet season and dry, heaviest when the belt is wettest, while the Amazon's share of the rain runs the other way and peaks near 27% in the dry season when little else falls. An annual average that hides a 3.3× seasonal swing is not wrong. It is just not the whole risk object, and saying so is part of the job.
| may be inside the number | must sit beside it |
|---|---|
| an attribution reconciled to an independent dataset and benchmarked against published literature | a tracking model you have not run yet |
| a mechanism with a held-out skill score you publish | a mechanism you believe in but have not tested against measured reality |
| the historical pattern the engine reproduces on years it never saw | the forward scenario under continued degradation |
| the boundary of the claim — one corridor, one crop, one service, one place the rain lands | the plan to extend past that boundary |
| a confidence band the evidence actually supports | a condition grade that is a lagging correlate under validation |
| what the number is a floor on | what the number is not a ceiling on |
The right-hand column is not a disclaimer page. It is content the buyer needs in order to size the claim, and it belongs at the same reading distance as the number.
the rarest move: leading with the failure
The Upper Colorado corridor is the harder example, because there the model lost.
The engine screens parcels along the Colorado from the Eagle headwaters to the Moab canyon, resolving which land holds up water for whom, and routing 16 named beneficiaries — transmountain diversions, Grand Valley farms, a Moab hospital — to parcels by hydrology rather than proximity. Every input is public government data: USGS, EPA, USDA, GBIF. And the page refuses to let that sound like more than it is — it states that this first run used modeled stand-ins rather than live per-watershed pulls, and stamps the result screening-grade. The pass marks were set in advance, at 0.72 for keystone and 0.80 for investable, and the method and success bar were sealed in a hashed, timestamped record before anyone saw a result, so the test could not be quietly bent afterward.
Then it was checked against real monitoring stations. The signal was real — catchments that hold back more sediment do run cleaner — but plain forest cover on its own did better than the full model, the effect nearly disappeared once elevation and development were accounted for, and on watersheds it had never seen, a two-variable baseline of elevation and percent developed beat the whole custom engine.
That is the sentence on the page. Not in an appendix. In the narrative, as the story.
What happened next is the part underwriters should care about most. The model had been borrowing its confidence from an assumed reliability number that flattered it. That was replaced: confidence is now tied to how well each mechanism actually held up on unseen data, so a mechanism with almost no measured skill can no longer pretend to any, and a parcel's estimate slides back toward a cautious prior of 0.54 as the noise widens. Widening uncertainty can only pull an estimate toward caution — it cannot manufacture confidence the data does not support.
And the ledger stays honest downstream. No cap rate is computed. No mechanism yet clears validated-incremental. The delivery pack ships with an automated check that fails the pack the moment it asserts validated value for a mechanism that has not earned it. The settlement rail on that page is where our side of the collaboration shows up, and it is worth reporting at his weight rather than ours: his closing section names BASIN Natural Capital as the settlement layer, issuing certificates that finance a place directly and pricing them off a natural cap rate, in collaboration with BASIN's founder. The rail is wired to real keys and shows zero instruments issued today, because a place has to clear the honesty gate before an instrument appears against it. That restraint is his point, and he is right about it.
the market that already taught everyone to check
There is a reason this bar is higher for nature than for most new asset classes, and everyone in the room knows it.
The last environmental market ran on unaudited baselines. An independent review found that the large majority of one leading standard's rainforest credits delivered no real benefit, and nature-based prices fell from roughly fifteen dollars to about one. That is one sentence of history, not a verdict on anyone still doing careful work in that market — plenty are. But it set the buyer's reflex, and the reflex is correct: a claim that cannot be re-checked gets discounted to nothing.
The practical consequence is that rigor is now the product. An engine that pre-registers its test, checks itself against measured reality, and publishes where it fails is not competing on humility. It is competing on the only feature that survives diligence.
the objection worth taking head-on
"If a two-variable baseline beats the model, why fund anything at all?"
Because pricing and funding are two different acts, and only one of them needs the grade to be validated.
An unvalidated condition grade inside a price is a liability: it moves money on a link nobody has tested, and when it breaks it takes the credibility of everything around it. The same grade sitting beside the price is information: it tells an allocator where to look, what to watch, and how much to trust the looking.
And the underlying condition is worth funding on its own terms, whatever the model concludes about it. Headwater forest that holds its transpiration through a drought is worth holding whether or not anyone has yet proved the elasticity to a downstream cashflow. The failed test says we cannot price this yet. It does not say this does not matter. Those get conflated constantly, usually by people who want an excuse to wait.
The source, meanwhile, degrades on its own schedule. It does not wait for the validation gate.
seven questions before a model touches your price
- What is this a model of — condition, dependency, or loss? If the vendor's answer moves between the three during the meeting, that is the finding.
- What did you hold out, and when did you decide to hold it out? Pre-registration is the difference between a test and a story.
- What is the skill on held-out data, and what does a naive baseline get? A model that cannot beat elevation and land cover is a research project, not a rating.
- Which outputs are validated and which are scenario? Ask for the line between them in writing.
- What moves the headline, and what only moves the spread and the tail? If condition moves the headline, ask what validated that link.
- What is the boundary — which crop, which service, which season, which geography, which counterfactual? Numbers travel; boundaries usually do not.
- What would falsify this, and have you run it? No answer is an answer.
Any model that answers all seven cleanly is worth a second meeting, whatever its skill score. A model that cannot answer the second and third is not a model you can put in a price, no matter how good the map looks.
fund the condition; don't bake in the grade
Which leaves the question of what a capital provider actually does while the models mature.
The answer we work on is deliberately narrow. Once a pathway is named — this source, this mechanism, this flow, this beneficiary — the beneficiary can fund the source's present condition upfront, and hold that as an asset, rather than disclosing the exposure and waiting for the loss. That is ensurance: proactive funding of protection instead of reactive compensation. In practice it runs through two ordinary instruments — certificates, which fund one named natural asset directly, and coins, which fund protection across the protocol.
None of that requires a validated grade in a price. It requires a named source and a beneficiary willing to pay for its condition now. The grade, when it arrives, makes that decision sharper. It is not the precondition for making it.
Our own stage deserves the same treatment we are asking of everyone else. The instruments are live and the volumes are small. We collaborate with Jay Gutierrez; the engines described here are his and remain his; and we are not selling his model to you as a prudential rating, because it is not offered as one.
Grade beside the price. On the model, and on ourselves.
where to go next
- when nature is material enough to underwrite — the materiality threshold a living system has to clear before it can sit on a term sheet.
- the missing object is the graph — the pillar for this series: why nature-related financial risk is a pathway, not a site score.
- pricing nature risk treats the symptom, not the cause and insurability is the first domino — what happens to cover and capital when the repricing lands.
- If you are evaluating a nature risk model against a live book and want a second reader on the honesty architecture: talk to us.
- If you would rather see what funding a named source looks like today: specific ensurance.
