Guide

Geopolitical Risk Analysis

Geopolitical risk analysis is the method that turns a raw development into a scored statement of business consequence: what it is, how severe, how confident the sourcing, and what it triggers next. It is the working half of geopolitical risk intelligence, the part that has to hold up when someone asks how a number was reached.

Last updated: August 23, 2026

The five-stage pipeline

Fortius Intel runs every scan through five stages, named plainly so there is nothing to interpret about what each one does:

  1. 01. Ingest. Sector, security, and regulatory sources are queried when you run the scan, not read from a cached digest.
  2. 02. Classify. Each development is matched to coded risks in your sector register by business consequence, never by keyword.
  3. 03. Score. Severity and confidence are set on separate axes, so weak sourcing cannot inflate an entry to the top.
  4. 04. Review. Entries that fail the evidence test are dropped, automatically, before the register is assembled.
  5. 05. Project. A 30/90/180-day consequence chain, each stage naming the signal that confirms it.

Each stage produces something the next stage can be checked against. A development that fails the Review stage's evidence test never reaches the register, and a reader can trace any final score back to the source it came from.

Why severity and confidence are scored apart

Most analysis that fails does so at the scoring step, by collapsing two different questions into one number. “How bad would this be” and “how sure are we this is true” are not the same question, and a single blended score lets a well-covered but minor story crowd out a poorly covered but severe one. Fortius Intel keeps the two axes separate through the pipeline. The output keeps four things apart: observed fact, Fortius assessment, forward projection, and the gaps where the evidence runs out.

What the Review stage actually checks

Review here is an automated evidence check. Analyst review is a separate, named service on the paid tiers. An automated check can catch missing corroboration and weak sourcing at scale; it cannot replace a human reading the register for judgement calls the evidence test does not cover, which is what the paid-tier analyst layer is for. A vendor that markets automated filtering as analyst review is worth pressing on the distinction before signing anything.

Where analysis becomes a decision

Analysis on its own is a scored register. It becomes useful once a risk officer decides what changes because of it, which is the job covered in geopolitical risk management. A single point-in-time run of this same analysis, done for a board paper or an entry decision, is what geopolitical risk assessment covers, including a worked assessment framework.

Sector-specific analysis

The five stages stay the same across sectors; the register they run against does not. A financial services scan classifies against correspondent banking and sanctions exposure; a manufacturing scan classifies against supplier concentration and tariff schedules. Fortius Intel publishes the sector registers behind each monthly outlook at sector outlooks, built from this same pipeline.

Reading someone else’s analysis critically

  • Ask what is scored and what is asserted. “High risk” with no source behind it is an assertion.
  • Ask whether severity and confidence are separable, or bundled into one number that hides which one is doing the work.
  • Ask what would falsify the projection. A forecast with no named signal cannot be wrong, which also means it cannot be checked.

Frequently asked questions

What is geopolitical risk analysis?

Geopolitical risk analysis is the process of taking a raw development, a sanction, a conflict, a regulatory change, and turning it into a scored, sourced statement about what it means for a specific business. The output is not a summary of the event; it is a judgement about severity, how confident that judgement is, and what happens next.

What is the difference between severity and confidence?

Severity is how much the development would matter if true: the operational or financial consequence. Confidence is how well-sourced and corroborated the development is. Scoring them on the same axis lets a widely reported but low-impact story outrank a poorly covered but high-impact one. Fortius Intel scores them separately for this reason.

Does automated analysis replace human analysts?

No. The automated pipeline handles ingestion, classification, scoring, and an evidence-based review that drops entries which fail sourcing checks. Analyst review is a separate, named service on paid tiers, where a human checks the register before it reaches a reader. Blurring the two, calling automated review "analyst reviewed," is the kind of claim that should make a buyer distrust the rest of a vendor's pitch.

How far ahead does geopolitical risk analysis project?

A useful analysis states a direct effect inside 30 days, a second-order effect inside 90 days, and the strategic decision environment at 180 days, with the signal that would confirm each stage. Projections with no time horizon and no falsifiable signal are opinion, not analysis.

What sources does the analysis draw on?

Sector and regulatory news sources, security and conflict reporting, and named sanctions and export control data, including the OFAC SDN list, the BIS Entity List, and DDTC licensing actions. Which sources matter is sector-specific; an energy scan weighs different inputs than a financial services scan.