Guide

Geopolitical Risk Assessment

A geopolitical risk assessment is a point-in-time scoring of a company’s exposure to state action, conflict, sanctions, and regulatory change, produced for a board paper, a market entry decision, or a due diligence file. Done properly, it names the exposure, scores it, and assigns an owner; done poorly, it is a country-level narrative with no decision attached.

Last updated: August 27, 2026

What an assessment is for

An assessment is the answer to a specific question asked at a specific moment: should we enter this market, take this counterparty, approve this supplier, or flag this to the board this quarter. It is not a general survey of the geopolitical environment. A useful assessment can be summarised in one sentence per finding: the risk, its severity, and what changes because of it. If it cannot be, the assessment is still a draft.

A working assessment framework

The framework below is the one Fortius Intel runs internally, described here in full because a framework a vendor will not show you is not one you can check.

1. Map the exposure

List the specific markets, suppliers, counterparties, and licences the assessment covers. This step fails most often by being too broad: “our exposure to Asia” is not a mappable exposure. A named supplier in a named country, with a named licence or contract behind it, is.

2. Score severity and confidence separately

For each item on the exposure map, score how much it would matter if the risk materialised, and separately, how confident the sourcing behind that risk is. A single blended score hides which of the two is driving the ranking, and lets a well-covered but minor risk crowd out a poorly covered but severe one. See geopolitical risk analysis for how this scoring is done at the pipeline level.

3. Chain the consequence

State what happens at 30 days, 90 days, and 180 days, and name the signal that would confirm each stage. A projection with no time horizon and no falsifiable signal cannot be checked later, which means it cannot be relied on now.

4. Assign an owner and a trigger

Every finding needs a named owner and a stated trigger: the condition under which that owner acts. Without this step, the highest-severity item in the assessment sits in a slide deck until it becomes a crisis. This is the step generic country-risk reports skip entirely, because a report sold to many buyers cannot assign an owner inside any one of them.

Common mistakes

  • Scoring the country instead of the specific exposure inside it.
  • Blending severity and confidence into one number.
  • Treating the assessment as a one-off, with no monitoring plan for the gap until the next one.
  • Leaving findings unowned, so nothing changes because of the highest-severity item.

Worked example: energy sector chokepoint exposure

An energy firm shipping through a single strait maps that route as an exposure, scores the severity of a closure as high and the confidence of an imminent closure as low-to-medium based on current security reporting, chains the consequence (a 30-day freight rerouting cost, a 90-day contract renegotiation, a 180-day sourcing decision), and assigns the shipping and trading desk as owner with a named trigger: act if a named security advisory escalates. See energy sector coverage for how this runs at scale across a full register.

From assessment to standing management

An assessment is a snapshot. Turning its findings into an owned, tracked function that revisits the register on a cadence is the job covered in geopolitical risk management, and the full method behind the scoring in either is covered on the methodology page.

Frequently asked questions

What is geopolitical risk assessment?

Geopolitical risk assessment is the point-in-time exercise of scoring a company's current exposure to state action, conflict, sanctions, and regulatory shifts, usually for a board paper, a market entry decision, or a due diligence file. It differs from ongoing risk management, which is the standing function that keeps the score current between assessments.

What is a geopolitical risk assessment framework?

A working framework has four parts: map the specific exposure (markets, suppliers, counterparties, licences), score each identified risk on severity and confidence as separate axes, chain the consequence across defined time horizons, and assign an owner with a stated trigger for action. A framework that stops at scoring, with no owner and no trigger, produces a document instead of a decision.

How often should a geopolitical risk assessment be repeated?

A full assessment tied to a board cycle is typically quarterly. Between assessments, the exposure map and the highest-severity items should be checked against live monitoring, since a sanctions designation or a chokepoint closure does not wait for the next board paper. See geopolitical risk monitoring for how the two connect.

Who should own a geopolitical risk assessment inside a company?

The chief risk officer or equivalent typically owns the assessment itself, but the exposure map underneath it is only accurate if procurement, legal, and regional leads contribute their own picture of counterparties and licences. An assessment built entirely from one function's view of the business will miss exposure that function does not see.

What is the difference between assessment and monitoring?

Assessment is the scored snapshot, taken at a point in time. Monitoring is the continuous watch that tells you when the snapshot is out of date. A company that only assesses, without monitoring in between, finds out its risk register was wrong on the day something happened, not before.