From Geopolitical Concern to Governable Risk

Geopolitical risk is already firmly on board agendas. The question is what it actually means for the organisation itself.

The Bank of England’s 2026 H1 Systemic Risk Survey shows geopolitical risk at its highest level recorded in the survey. It was cited by 95% of respondents as one of the risks that would have the greatest impact on the UK financial system if it materialised. It was also cited by 81% as one of the risks most challenging to manage and by 84% as among the most likely to materialise.

Those figures establish the concern. They do not, by themselves, tell an individual organisation what to do about it.

A risk register entry labelled “geopolitical instability” may be accurate, but it is still too broad to help management decide what to do next. Organisations cannot control relations between states or know when sanctions regimes will change. What they can do is work out where those developments would hit the business, which dependencies or assumptions they would put under pressure, and what decisions might then be needed.

The closer an organisation can get to those specific exposures, the more actionable the risk becomes for management.

A broad risk label can hide very different exposures

Consider a deterioration in relations between two countries in which an organisation has commercial interests.

For compliance, the immediate concern may be sanctions and financial-crime risk. Procurement may be more concerned about suppliers operating in or sourcing from affected jurisdictions. Cyber teams may see a change in threat activity. Treasury may be monitoring market, currency or liquidity effects. Business leaders may be considering customers, counterparties, employees and planned investment.

None of those perspectives is wrong. The difficulty arises when they continue to remain disconnected.

One external development can affect several existing risks at the same time, and those effects may interact. A supplier problem can quickly become an operational one. Market stress may be putting pressure on a counterparty at the same time, while the recovery plan itself could rely on a jurisdiction or provider caught up in the disruption.

The ECB describes geopolitical risk as a cross-cutting risk driver because it can affect traditional risk categories including credit, market, liquidity, business model, governance and operational risk. A single category at the top of a risk taxonomy can therefore reveal very little about how the risk could reach the organisation.

Tracing how geopolitical risk reaches the organisation

That requires a clearer line of sight between an external development and the parts of the organisation that could be affected.

The route may run through a jurisdiction, supplier, customer or counterparty. It may involve a system or data flow, an important service, a financial position or an assumption underpinning strategy. The problem is, in complex organisations, several of these may be involved at once.

The objective is not to map every conceivable geopolitical consequence. It is to understand the routes through which a change in the external environment could become material.

That process can also expose assumptions which ordinary risk reporting leaves implicit.

Those assumptions can be buried across the organisation. A resilience plan might depend on moving activity to another country, procurement on finding an alternative supplier quickly, and liquidity planning on continued market access. Strategic plans may also rely on regulatory permission, demand or operating conditions remaining broadly stable in a particular jurisdiction.

Those assumptions can become important well before the underlying risk has crystallised.

There is a similar emphasis in the PRA’s 2026 supervisory priorities. Against a backdrop of elevated geopolitical tensions and fragmentation in trade and financial markets, it points to the need for continued attention to risk management, governance and controls, operational and financial resilience, and data risk. Its 2026/27 Business Plan also identifies geopolitical trends among the emerging risks it continues to monitor.

External geopolitical intelligence clearly has value. But for individual firms, it also needs to find its way into existing risk, resilience and decision-making processes.

Distributed ownership still needs an overall view

Once the implications become more specific, ownership is likely to be spread across the organisation.

Sanctions may sit with compliance, while supplier continuity may sit with procurement or an operational team. Treasury will own relevant financial risks, while cyber teams manage threat activity and the business leaders remain accountable for commercial decisions within their areas.

Trying to place all of this under one operational “geopolitical risk owner” is unlikely to improve accountability. The specialist risks still need to be managed where the relevant expertise sits.

But someone also needs to be able to see the combined picture.

A risk committee might receive one update on sanctions, another on financial markets and a separate paper on cyber threats. Each area can be well managed in its own right, while the relationships between them receive much less attention.

This is where enterprise risk management can add value: not by taking ownership away from specialist functions, but by helping management identify when apparently separate risks share the same external driver, dependency or assumption.

That may mean common escalation criteria, clearer links between relevant risks and controls, or simply knowing who is expected to bring the overall picture together when circumstances change.

Monitor exposure, not only the external environment

Most large organisations already have access to considerable geopolitical intelligence. Elections, conflicts, sanctions, trade restrictions and diplomatic developments can all be followed in detail.

But more information does not necessarily mean a better understanding of risk.

The significance of an external development depends on where the organisation is exposed. A change in sanctions designations matters because of the customers, counterparties or transactions involved. Deteriorating conditions in a jurisdiction become more serious when important suppliers are concentrated there, while increased cyber activity needs to be viewed against the organisation’s own vulnerabilities and critical services. Market movements only become meaningful when set against actual exposures, funding requirements and customer behaviour.

The most useful information is the information that tells management something about its own position.

That can also help organisations respond before an external development becomes a crisis. An indicator might show that exposure has moved beyond appetite, that an important assumption is becoming less reliable or that several individually manageable risks are beginning to compound.

There will always be judgement involved. Geopolitical signals can be uncertain or ambiguous. The aim is not to create an illusion that the next event can be predicted, but to understand when the organisation’s exposure may be changing.

Scenario analysis can test the assumptions

That uncertainty is one reason scenario analysis is particularly relevant to geopolitical risk.

The purpose is not to predict which crisis will happen next. It is to ask what the organisation would do if important conditions changed.

What happens if a jurisdiction becomes inaccessible at short notice, or sanctions change faster than customer and transaction controls can be updated? An important supplier might fail just as market conditions are deteriorating. Management may have contingency actions in place, but those plans also need to consider whether the same options would still be available if other organisations were trying to respond in the same way.

These questions turn a broad concern into consequences and decisions that can be examined.

The ECB’s 2026 geopolitical risk reverse stress test provides a useful example. It asked 110 directly supervised euro-area banks to develop institution-specific geopolitical scenarios severe enough to have a material impact on their capital positions. Banks were generally able to produce meaningful scenarios, but the exercise also identified weaknesses including the granularity and sensitivity of some risk assessments, the connection between scenario narratives and solvency and liquidity impacts, and the realism of some proposed mitigating actions.

In September, ECB Supervisory Board Chair Claudia Buch drew out some of the wider governance lessons: reliable information, effective board involvement in scenario analysis and realistic assumptions about what management could actually do under stress.

Those issues reach beyond the mechanics of bank stress testing.

A good scenario can reveal dependencies that normal reporting keeps apart. It can challenge whether contingency plans would really work, whether the organisation has sufficiently detailed information and whether different risks might deteriorate together.

What does the board need to see?

Boards need to understand material developments in the external environment. But a geopolitical briefing alone may still leave directors unclear about what those developments mean for the organisation.

Risk reporting needs to bring the external and internal pictures together.

The board needs to understand where the organisation is exposed, how material that exposure could become, which assumptions are under pressure and whether the position is changing. It also needs clarity over who owns the resulting risks and, if circumstances moved quickly, what decisions management or the board might need to make.

Uncertainty also needs to be visible.

If management does not have reliable information about a supplier dependency, if exposure further down a supply chain remains unclear or if an important contingency has never been tested, that is relevant information for the board too.

Much of the underlying data may already exist across supplier management, sanctions screening, resilience, finance, cyber, risk and strategy. The problem arises when each part is reported separately and nobody has a clear enough view of what they add up to.

A board can know a great deal about geopolitical events and still know too little about how exposed its own organisation is.

Making uncertainty governable

No governance framework can make geopolitical events predictable. Their timing, severity and consequences will continue to be uncertain.

But organisations can do more to understand how that uncertainty could affect them.

That means tracing external developments into specific exposures, recognising where risks and dependencies connect, challenging the assumptions behind existing plans, using scenarios to explore what could change and monitoring the organisation’s own position rather than the external environment alone.

Geopolitical risk may begin outside the organisation. Its governance challenge lies in understanding where, and how, it reaches inside.

Stay up to date with the latest news and views from the world of governance, risk, audit and compliance >>>

Facebook
Twitter
LinkedIn