How the FEMA National Risk Index Works

Every number on this site traces back to a single public dataset: the FEMA National Risk Index (NRI). This page explains where that data comes from, how the scores are calculated, and — just as importantly — what they can and cannot tell you.

What the National Risk Index is

The NRI is a nationwide, county-level dataset published by the Federal Emergency Management Agency. It rates every US county and county-equivalent (parishes in Louisiana, boroughs and census areas in Alaska, independent cities in Virginia) on its relative risk from 18 natural hazards, from hurricanes and wildfires to avalanches and volcanic activity.

FEMA built the index with input from state and local governments, universities, and private-sector risk modelers, and updates it roughly once a year. This site currently publishes version 1.20, released December 2025. The data is public domain under OpenFEMA’s terms; FEMA requests attribution but does not endorse or sponsor this site.

The three ingredients of a risk score

A county’s composite Risk Index score (0–100) is not just “how often disasters happen there.” It combines three separately measured components:

Expected Annual Loss (EAL) is the core of the index. For each hazard, FEMA estimates the average dollar loss the county should expect per year, averaged over the long run. EAL is built from three factors: exposure (the value of buildings, population, and agriculture in harm’s way), annualized frequency (how often the hazard historically strikes), and historic loss ratio (what share of exposed value a typical event destroys). A county with enormous property value and rare-but-severe events can carry a higher EAL than a county hit constantly by small ones.

Social Vulnerability measures how susceptible the population is to harm when a disaster does strike. The index’s social vulnerability layer is built on SoVI®, the Social Vulnerability Index developed at the University of South Carolina’s Hazards and Vulnerability Research Institute, which combines dozens of socioeconomic variables — poverty, age, disability, housing type, vehicle access, and more. (The CDC/ATSDR Social Vulnerability Index is the other widely used federal measure, and FEMA publishes it alongside the NRI.) Two counties with identical expected losses can experience very different human outcomes; this component captures that.

Community Resilience measures a community’s capacity to prepare for, absorb, and recover from disasters. It uses BRIC — the Baseline Resilience Indicators for Communities, also from the University of South Carolina’s HVRI — a set of dozens of indicators across social, economic, community-capital, institutional, housing/infrastructure, and environmental dimensions.

The composite formula, conceptually: Risk = Expected Annual Loss × Social Vulnerability ÷ Community Resilience. High vulnerability amplifies a county’s risk score; high resilience dampens it.

A worked example: how one number gets built

Abstract formulas are easy to nod along to and hard to actually use, so here is the calculation running end to end for a single hazard in a single county. The numbers below are illustrative and rounded, but the structure is exactly what FEMA does.

Suppose we want the tornado Expected Annual Loss for a mid-sized county.

Step 1 — Exposure. FEMA estimates the value that could be affected by a tornado in that county: the replacement value of buildings, the economic value assigned to the population, and the value of agriculture. Say the county has $18 billion in building stock, plus population and agricultural values that FEMA converts to dollar terms. Exposure is not “everything in the county” — for hazards with defined footprints (flood zones, lava zones, tsunami inundation) it is only the value inside the hazard area. Tornadoes can occur anywhere in a county, so tornado exposure is county-wide.

Step 2 — Annualized frequency. From NOAA’s Storm Prediction Center records, FEMA calculates how often a tornado historically affects the county in a year. Our county averages, say, 0.9 events per year.

Step 3 — Historic loss ratio. This is the share of exposed value a typical event actually destroys, derived from historical loss records for that hazard. Tornadoes destroy a very small fraction of a whole county’s building stock even in a bad year, so this number is tiny — on the order of 0.0002 for a hazard like this.

Step 4 — Multiply. Expected Annual Loss = Exposure × Annualized Frequency × Historic Loss Ratio.

$18,000,000,000 × 0.9 × 0.0002 ≈ $3.2 million per year

That is the county’s tornado EAL: not a prediction that $3.2 million of damage happens next year, but the long-run annual average. In most years the actual number is zero; occasionally it is a hundred times the average.

Step 5 — Repeat for all 18 hazards and sum. Each hazard gets its own EAL through the same three-factor calculation, using its own frequency records and loss ratios. Summing them gives the county’s composite EAL — the “Expected Annual Loss” figure shown at the top of every county page on this site.

Step 6 — Apply the community factors. The composite EAL is then adjusted: multiplied by the county’s Social Vulnerability score and divided by its Community Resilience score. A county with high vulnerability and low resilience ends up with a higher Risk Index score than a county with the same dollar losses but a better-resourced, less exposed population.

Step 7 — Score it against everyone else. The result is transformed into a 0–100 score representing where the county sits relative to all other US counties, and binned into one of five ratings. That final score is what drives the badge, the percentile, and the rankings across this site.

Two consequences fall out of this structure, and they explain most of the “surprising” results you will find here:

  • Big metros dominate the top of nearly every hazard ranking, because exposure is a multiplier. A tornado track through a dense city destroys vastly more value than the same track through wheat fields, so Cook County outranks rural Oklahoma for tornado EAL even though Oklahoma sees more tornadoes per square mile.
  • Frequency alone is not risk. A county hit constantly by minor events can carry a lower EAL than one hit rarely by catastrophic ones. Earthquake risk is the extreme case: a county can go a century without a damaging quake and still carry one of the largest EALs in the country.

Scores, percentiles, and ratings

The Risk Index is relative, not absolute. A score of 85 does not mean an 85% chance of anything — it means the county’s calculated risk is higher than roughly 85% of US counties. FEMA groups scores into five ratings: Very Low, Relatively Low (Low), Relatively Moderate (Medium), Relatively High (High), and Very High. On this site we show the score, the national percentile, and the rating together so the context is always visible.

Each of the 18 hazards also gets its own per-hazard score and rating, built the same way from that hazard’s EAL. A county can be Very High for one hazard and Very Low overall, or vice versa — the composite blends everything.

What this site adds on top

We publish the NRI data as-is — no re-weighting, no editorial adjustment of scores. What we add is context and navigability:

  • County pages show the composite score, all 18 hazard ratings, EAL, social vulnerability, and community resilience, plus each county’s federal disaster declaration history from FEMA’s separate Disaster Declarations Summaries dataset (1953–present).
  • State pages and rankings aggregate the same county data for comparison.
  • These guides are written and edited by a person (me — see the about page), not generated from the data.

Limitations you should know about

Risk is county-level, not address-specific. A county rated Very High for riverine flooding contains plenty of parcels that will never flood; a Low-rated county still has floodplains. For property decisions, pair this data with address-level tools — FEMA flood maps, state wildfire hazard maps, a local insurance agent.

EAL is a statistical average, not a forecast. A county with a $50M expected annual loss might see $0 in losses for a decade and then a $1B event. The average is meaningful for comparing places and pricing long-run risk, not for predicting any particular year.

The index looks backward and present-tense. Frequencies are estimated largely from historical records. Where climate change is shifting hazard behavior — wildfire seasons lengthening, rainfall intensifying — the historical record may understate future risk.

Boundaries and versions change. FEMA occasionally revises methodology between versions (v1.20, for example, renamed the riverine flooding hazard code from RFLD to IFLD). Scores are comparable within one version, not necessarily across versions.

How the NRI differs from the other risk numbers you’ve seen

People frequently assume the Risk Index is a version of a flood map or an insurance score. It is none of those, and conflating them leads to bad decisions.

Versus FEMA flood maps (FIRMs). Flood maps are regulatory products at parcel resolution: they draw the boundary of the 1%-annual-chance floodplain, which determines mandatory purchase requirements for federally backed mortgages and local building elevation rules. The NRI is a comparative product at county resolution covering 18 hazards. A flood map tells you whether your lot is in a mapped zone; the NRI tells you how your county’s overall flood exposure compares to other counties. Neither substitutes for the other, and the flood map’s known blind spot — it maps riverine and coastal floodplains but often not urban drainage or extreme-rainfall flooding — is not corrected by the NRI.

Versus NFIP Risk Rating 2.0 premiums. Since 2021 FEMA has priced flood insurance property by property, using distance to water, elevation, foundation type, and rebuild cost. That premium is the closest thing to an address-level flood risk assessment most homeowners can obtain, and it is generated by a different methodology than the NRI entirely. If you want to know what the federal government thinks of your parcel’s flood risk, get a quote.

Versus private catastrophe models. Insurers and reinsurers run proprietary models (AIR, RMS, and others) that simulate hundreds of thousands of synthetic events at building resolution. They are far more granular than the NRI, forward-looking in ways the NRI is not, and completely closed. The NRI’s advantage is that it is public, documented, and reproducible.

Versus commercial “risk score” products. Several consumer sites publish proprietary property-level hazard scores. Some are good; none are auditable, and their methodologies change without notice. The NRI’s numbers can be recomputed from published inputs by anyone who wants to check them.

Versus the CDC/ATSDR Social Vulnerability Index. The CDC SVI measures social vulnerability alone, with no hazard component. It answers “which communities would struggle most in an emergency,” not “which communities face the most hazard.” The NRI folds a social vulnerability measure into a hazard calculation; the two are complementary, not competing.

Versions, and why they aren’t comparable

FEMA revises the National Risk Index roughly annually, and revisions are not merely data refreshes — methodology, hazard definitions, and underlying source datasets change between releases.

The index was first released publicly in 2020 (Release 1), with a substantially revised Version 1.19 and subsequent annual updates following. This site currently publishes version 1.20, released December 2025.

Some changes are cosmetic but matter for anyone working with the raw files — v1.20, for example, renamed the riverine flooding hazard code from RFLD to IFLD (“inland flooding”) to better reflect what the hazard actually covers. Others are substantive: updated building-stock valuations, revised frequency records as new events enter the historical database, and refreshed social vulnerability and resilience inputs.

The practical rule: scores are comparable within a version, not across versions. A county whose score changed between releases may not have gotten riskier — the denominator may have moved, or its building stock may have been revalued, or a neighboring county’s data may have shifted the relative ranking. When we update this site to a new NRI version, we republish every page in full rather than mixing releases, and the version and release date appear in the footer of every page.

What this data is good for, and what it isn’t

Good for:

  • Comparing places. “Is this county’s hurricane exposure higher or lower than the one I’m moving from?” is exactly the question the index is built to answer.
  • Identifying which hazards deserve your attention where you live. Most people can name one hazard for their area and are wrong about the second and third.
  • Understanding a region’s long-run risk profile before a property, business, or relocation decision — as a first screen, not a final answer.
  • Public planning, grant applications, and hazard mitigation planning, which is what FEMA built it for.

Not good for:

  • Deciding whether your specific address will flood, burn, or slide. Use the address-level tools: FEMA flood maps and a flood quote, state wildfire severity maps, state landslide susceptibility mapping, a local insurance agent.
  • Predicting next year. EAL is a long-run average, and disasters are lumpy.
  • Estimating your personal financial exposure. That depends on your building, your policies, your deductibles, and your equity — none of which the index knows anything about.
  • Anything requiring sub-county resolution. Within a single county, parcel-level risk varies by orders of magnitude for wildfire, flood, and landslide.

Sources

Questions or corrections? Email hello@disasterriskindex.com, or see the contact page.

← All guides