Guide
Geopolitical Risk Intelligence
Geopolitical risk intelligence is the practice of turning state action, conflict, sanctions, and shifts in the balance of power into named, scored consequences for a specific business. It is not a country score or a headline feed: it says which risk, how severe, how confident the sourcing is, and what happens across the next 30, 90, and 180 days.
Last updated: August 23, 2026
What the discipline actually does
Most enterprise risk functions already track geopolitics in some form: a subscription digest, a country index, a Google Alert with a hundred keywords in it. None of that is intelligence. Intelligence means someone, or something, has done the work of connecting a development to a specific consequence for a specific reader. A tariff announcement is an event. “This tariff schedule adds 90 days to your Vietnam sourcing timeline and forces a supplier decision by the end of Q3” is intelligence.
The gap between the two is the actual product. A risk officer does not need more news. They need fewer, better-scored items, each one tied to a decision they are already responsible for making.
How it differs from country reports and news feeds
A country risk rating scores a country. It says Nigeria is riskier than Norway, which is true and not useful on its own, because a firm with three suppliers in Nigeria needs to know which three risks matter to those specific suppliers, not a national average. See country risk analysis for where that approach breaks down in practice.
A news feed reports events without judging their consequence. It will tell a reader that a strait has been mined, a regulator has opened an investigation, or a minister has resigned, at the same volume and the same urgency as everything else in the feed. Geopolitical risk intelligence has to do the opposite: drop the items that do not matter to this reader, and rank what is left by how much it actually changes the business.
What good sourcing looks like
Specificity is the tell. “Recent regulatory activity” is not sourcing; it is a hedge. A named list, a named order, a named date is sourcing. Fortius Intel's scans match developments against the OFAC Specially Designated Nationals list, the BIS Entity List, CISA advisories, and DDTC licensing actions, alongside sector and security reporting, precisely because a vague source produces a vague score.
How the analysis is actually produced
Fortius Intel runs a five-stage pipeline on every scan: ingest, classify, score, review, project. Each development is matched to a coded risk in the reader's sector register by business consequence, not by keyword match. Severity and confidence are scored on separate axes, so a poorly sourced item cannot inflate itself to the top of the register by volume alone. The full mechanics are on the methodology page, and the scoring logic specifically is covered in geopolitical risk analysis.
Where this fits: assessment, management, monitoring
The discipline splits into three practical jobs inside a company, and most vendors only do one of them well. Geopolitical risk assessmentis the point-in-time exercise: score today's exposure, usually for a board paper or an entry decision. Geopolitical risk management is the standing function that owns the register and decides what changes because of it. Geopolitical risk monitoring is the continuous layer that keeps both from going stale between board cycles.
Who runs this inside a company, by sector
The buyer and the framing shift by sector, even when the underlying method does not. An energy firm reads geopolitical risk intelligence through chokepoints, sanctions on counterparties, and licensing; a financial services firm reads it through correspondent banking exposure and sanctions screening; a manufacturer reads it through tariff schedules and single-source suppliers; a technology firm reads it through export controls and semiconductor dependency. Fortius Intel publishes sector-native monthly outlooks for each at sector outlooks, built from the same scoring pipeline described above.
What to check before buying it
- Does the output name a specific risk, or does it describe a general situation? “Tensions remain elevated” is not a finding.
- Are severity and confidence scored separately? If a single number covers both, a well-covered rumour can outrank a poorly covered fact.
- Does it say what happens next, with a time horizon, or does it stop at describing what already happened?
Fortius Intel's own register is one worked example; it is not the only way to run this well, and a reader evaluating any provider against this checklist should hold Fortius to the same standard.
Frequently asked questions
What is geopolitical risk intelligence?
Geopolitical risk intelligence is the discipline of turning state action, conflict, sanctions, and shifts in the balance of power into named, scored consequences for a specific business. It is the analysis layer, not the raw feed: a country risk index or a news alert tells you something happened; geopolitical risk intelligence tells you what it does to your operations, your suppliers, or your licence to trade.
How is it different from political risk insurance?
Political risk insurance transfers the financial consequence of an event, such as expropriation or currency inconvertibility, to an underwriter. Geopolitical risk intelligence identifies and scores the event before it happens, so a risk team can act on it directly rather than only recover from it after the fact. The two are complementary; a good intelligence function shortens the list of things an insurer ever has to pay out on.
Who inside a company actually uses geopolitical risk intelligence?
Chief risk officers use it to build board-ready risk registers. Supply chain and procurement teams use it to flag single points of failure before a chokepoint closes or a supplier is sanctioned. Compliance teams use it to catch export control and sanctions exposure before a shipment or a hire creates a violation. The framing differs by function; the underlying scored risk is the same.
What data feeds geopolitical risk intelligence?
A working system draws on sector-specific news and regulatory sources, security and conflict data, and named sanctions and export control lists, including the OFAC Specially Designated Nationals list, the BIS Entity List, and DDTC licensing actions. The data matters less than what happens to it afterward: whether it gets matched to a real business exposure and scored, or just displayed as a feed.
How often does geopolitical risk intelligence need to be updated?
Sanctions lists, export control designations, and conflict conditions change daily; a risk register built once a quarter is stale before the next board meeting. The right cadence depends on exposure: a firm with active shipments through a contested strait needs daily monitoring, while a firm with static, low-exposure operations can run monthly. Static reports covering both cases equally are a sign the vendor has not thought about this.