The year 2025 should have been a quiet one for catastrophe modellers. For the first time in a decade, no hurricane made landfall on the US coast. And yet, according to Swiss Re Institute's sigma 1/2026 report, global insured losses from natural catastrophes still reached USD 107 billion — the sixth consecutive year above the USD 100 billion mark. A record 92% of those losses came from so-called secondary perils: the January wildfires in Los Angeles alone produced around USD 40 billion of insured losses, the largest wildfire loss event on sigma records, while severe convective storms added USD 51 billion (Swiss Re Institute, 2026).
Pause on that for a moment. The perils that traditional catastrophe models were built around — hurricanes and earthquakes — contributed a small fraction of the year's losses. The perils that dominated are precisely the ones the industry has historically modelled least well. If your view of risk is anchored in a vendor model calibrated primarily to peak perils, 2025 is a polite warning that the risk landscape and the modelling landscape have drifted apart.
The business problem: models under pressure from three directions
Catastrophe models have served the insurance industry well for three decades. They transformed underwriting after Hurricane Andrew, made probabilistic capital allocation possible, and underpin today's reinsurance and insurance-linked securities markets. But three pressures are now converging on the traditional model paradigm.
First, the risk itself is non-stationary. Swiss Re's analysis of the 1970–2025 loss record attributes more than 80% of the long-term growth in weather-related insured losses to exposure growth — more valuable property built in harm's way, at higher reconstruction costs — but also finds that for some perils and regions, hazard and vulnerability appear to be evolving faster than exposure alone would imply (Swiss Re Institute, 2026). A model calibrated to the historical record embeds yesterday's climate and yesterday's building stock.
Second, secondary perils have become primary loss drivers. Wildfire insured losses are estimated by Swiss Re to be growing at roughly 12% per year — the fastest-growing peril — yet wildfire, hail and flood models remain younger, more data-constrained and less validated than hurricane and earthquake models.
Third, validation expectations have hardened. Under Solvency II, insurers using catastrophe output within internal models must demonstrate understanding of the models they rely on. "The vendor calibrated it" is not an acceptable answer to a supervisor, a validator, or increasingly a board. EIOPA has explicitly promoted the use of open-source modelling and data as part of addressing climate-related protection gaps, including releasing its CLIMADA-based application to make open catastrophe modelling more accessible (EIOPA, 2023a; EIOPA, 2023b).
The business problem, then, is not that cat models are wrong. It is that opaque models are becoming difficult to govern, difficult to adjust for a changing climate, and difficult to defend.

What a catastrophe model actually is
Before discussing where the architecture is heading, it is worth stating plainly what sits inside any catastrophe model, vendor or open-source. Four modules connect in a chain:
- Hazard — a large catalogue of simulated events (storm tracks, fire footprints, flood extents), each with physical intensities at each location and an annual rate of occurrence.
- Exposure — the portfolio of insured assets: locations, values, construction and occupancy characteristics.
- Vulnerability — damage functions translating hazard intensity at a site into a damage ratio for a given building type.
- Financial — policy terms (deductibles, limits, reinsurance structures) that convert ground-up damage into insured loss.
The core output is the exceedance-probability curve. For each simulated year, the model produces an annual loss; ranking these losses gives the probability that annual losses exceed any threshold. Two summary quantities matter most. The expected annual loss is:
EAL = Σᵢ λᵢ · E[Lᵢ]
where the sum runs over all events i in the catalogue, λᵢ is the annual occurrence rate of event i (how many times per year, on average, that event happens), and E[Lᵢ] is the expected insured loss if it does occur. In plain terms: multiply how often each event happens by how much it costs, and add everything up. The return-period loss — for example the 1-in-200-year annual loss that drives Solvency II capital — is read directly off the exceedance curve as the loss level exceeded with probability 0.5% in any year.
Every catastrophe model in the market is a version of this chain. The differences — and the risk to the user — sit in the assumptions inside each module: how the event catalogue was built, which climate baseline it reflects, how damage functions were fitted, and how uncertainty is propagated. When those assumptions are invisible, the user carries model risk they cannot measure.
The transparency movement is no longer fringe
A structural shift is under way. The Oasis Loss Modelling Framework — a not-for-profit, fully open-source platform for building and running catastrophe models — now hosts an ecosystem of more than 18 model suppliers covering over 90 models, alongside open data standards for exposure, hazard and vulnerability designed to improve interoperability across the market (Oasis LMF, 2026). On the regulatory side, EIOPA's promotion of open-source tools, and the joint ECB–EIOPA work on European natural-catastrophe risk management, both point in the same direction: supervisors want risk assessment capabilities that can be examined, compared and stress-tested, not merely licensed (EIOPA & ECB, 2024).
This does not mean vendor models are obsolete — far from it. Vendor models embody decades of peril science and claims calibration that open frameworks cannot simply replicate. The realistic future is a blended architecture: vendor views where they are strongest, open and in-house components where transparency, adjustability or peril coverage demand it, and a disciplined process for reconciling the two.

A practical workflow: building an adjustable view of risk
Consider a mid-sized European property insurer whose vendor model underweights wildfire — a reasonable concern after 2025. A pragmatic modelling workflow, of the kind Quantica Risk is developing in its own frameworks, looks like this:
- Decompose the vendor output by peril and region, and identify where recent loss experience or scientific evidence diverges from modelled expectations.
- Construct an adjustment layer: a frequency–severity model of the under-represented peril (for example, a Poisson frequency assumption with a heavy-tailed severity distribution fitted to industry loss data), run on the insurer's own exposure through an open platform.
- Blend the vendor and in-house views with explicit, documented weights — and record the rationale as a formal model-change decision.
- Validate by backtesting the blended view against realised losses and benchmarking against industry aggregates such as the sigma loss record.
- Govern: every assumption in the adjustment layer is written down, owned, and reviewable — which is precisely what a black box cannot offer.
The mathematics in step 2 is deliberately classical; the innovation is architectural. Transparency is not a property of any single equation. It is a property of the workflow.
Implications for risk leaders
For chief risk officers and chief actuaries, three conclusions follow. First, treat your catastrophe model as a portfolio of assumptions to be governed, not a product to be consumed; ask which module — hazard, exposure, vulnerability or financial — dominates uncertainty in your book, because that is where validation effort belongs. Second, invest in the capability to adjust: the gap between modelled and emerging risk in secondary perils is now material enough that a pure licence-and-run operating model leaves earnings exposed and supervisors unsatisfied. Third, watch the open-source ecosystem seriously. Open platforms and data standards are becoming the lingua franca through which regulators, reinsurers and cedants will compare views of risk; institutions fluent in that language will negotiate, price and report from a position of strength.

Conclusion
The 2025 loss year — record wildfire losses, no US hurricane landfall, and still USD 107 billion of insured losses — is a snapshot of a risk landscape that has outgrown the assumption set of the classical vendor-model paradigm. The next generation of catastrophe modelling will not be defined by a single breakthrough technique. It will be defined by architecture: modular, inspectable, adjustable frameworks in which every assumption has an owner and every change leaves a trail. The firms that build that capability now will not merely satisfy their validators. They will understand their own risk better than their competitors understand theirs.
About the author. Jonas Osman is a risk-modelling and financial-risk professional and the founder of Quantica Risk, an AI-driven modelling company focused on insurance, banking, climate risk, actuarial analytics, and model validation.
Quantica Risk develops transparent, data-driven modelling frameworks for financial institutions and risk-sensitive businesses. To discuss catastrophe risk, climate analytics, or model validation, visit the Quantica Risk website. [website — to be inserted when verified]
Series links
- Next in this pillar: Frequency–Severity Modelling of Insured Catastrophe Losses (Article A2) — the classical machinery behind the adjustment layer described above.
- Related: From Hazard to Loss: A Financial Framework for Physical Climate Risk (Article B1) — how the same four-module chain generalises to climate risk beyond insurance.

References
- Swiss Re Institute (2026). sigma 1/2026 — Natural catastrophes in 2025: the persistent rise of wildfire and storm risk. https://www.swissre.com/institute/research/sigma-research/sigma-2026-01-natcat-2025-wildfire-storm-risk.html
- Swiss Re Institute (2026). Press release, 19 March 2026: Wildfires, storms, floods contribute to record 92% of global insured losses in 2025. https://www.swissre.com/press-release/Wildfires-storms-floods-contribute-to-record-92-of-global-insured-losses-in-2025-says-Swiss-Re-Institute/7b39b1a5-b878-4a55-a5ff-bf5aa561a675
- Swiss Re Institute (2025). sigma 1/2025 — Natural catastrophes: insured losses on trend to USD 145 billion in 2025. https://www.swissre.com/institute/research/sigma-research/sigma-2025-01-natural-catastrophes-trend.html
- EIOPA (2023a). Impact underwriting: Report on the implementation of climate-related adaptation measures in non-life underwriting practices. https://www.eiopa.europa.eu/publications/impact-underwriting-report-implementation-climate-related-adaptation-measures-non-life-underwriting_en
- EIOPA (2023b). Policy measures to reduce climate-related insurance protection gaps (including the CLIMADA-based open-source application). https://www.eiopa.europa.eu/publications/policy-measures-reduce-climate-related-insurance-protection-gaps_en
- EIOPA & ECB (2024). Towards a European system for natural catastrophe risk management. https://www.eiopa.europa.eu/document/download/d8c87070-f602-4bf7-b8d8-726ec0b5c173_en
- EIOPA (2025). Natural catastrophes and insurance: Managing risk and building resilience in the EU. https://www.eiopa.europa.eu/publications/natural-catastrophes-and-insurance-managing-risk-and-building-resilience-eu_en
- Oasis Loss Modelling Framework (2026). Platform and Open Data Standards overview. https://oasislmf.org/
