Guide

Geopolitical Risk Management

Geopolitical risk management is the standing function that owns a company’s risk register between assessments: monitoring it, triaging what changes, and deciding what to act on. Most of what gets published under this name is a one-time framework built for a slide deck, not a job description for the person who has to run it every week.

Last updated: August 27, 2026

The gap between a framework and a job

Most published guidance on this topic reads as a framework for a report: a risk matrix, four quadrants, a scoring rubric applied once. That is useful for structuring a single assessment. It says nothing about what the person responsible for this function does on a Tuesday when a sanctions list updates, a supplier is flagged, or a board member asks why an item that was low severity last quarter is now urgent.

Management is the answer to that gap: a standing register, owned continuously, not reassembled from scratch each time someone asks for an update.

What the function actually does, week to week

  • Triage new developments against the existing register: does this change the severity or confidence of something already tracked, or is it a new item.
  • Check open triggers: has a condition set during the last assessment now been met, and does that force an owner to act.
  • Retire items whose underlying exposure has closed, a contract has ended, a licence has lapsed, so the register reflects current exposure rather than accumulating history.
  • Prepare the next formal review with a register that is already current, rather than rebuilt from a blank page.

What a working register contains

Each item needs five fields to be useful: the risk itself, a severity score, a confidence score, the specific exposure it applies to, and an owner with a stated trigger. Drop any one of the five and the register degrades into either a threat list nobody acts on, or a set of assertions nobody can check. The scoring itself, severity and confidence kept on separate axes, follows the same method covered in geopolitical risk analysis, and the full field-by-field structure is in the assessment framework.

Ownership, distributed

Centralising the register in one risk function, without distributing ownership of individual items to whoever can act on them, is the most common way this fails. A sanctions exposure needs a treasury or compliance owner who can act on it directly, not a risk analyst who has to escalate every item through a separate approval chain before anything moves. A manufacturer running this well typically splits ownership across procurement, compliance, and regional operations leads, coordinated by a central risk function rather than routed entirely through it. See manufacturing sector coverage for how that split works in practice.

Keeping the register current

A register updated only at the quarterly review is a snapshot, not a management function. It needs a continuous feed of triage-worthy developments between formal reviews, which is what geopolitical risk monitoring provides. The two are separate concerns, monitoring produces the developments, management decides what to do with them, and a vendor that conflates them into one undifferentiated product is usually weak at one of the two.

Frequently asked questions

What is geopolitical risk management?

Geopolitical risk management is the standing function that owns a company's geopolitical risk register and decides what changes because of it: which supplier gets diversified, which market entry gets delayed, which counterparty gets re-screened. It runs continuously, unlike a risk assessment, which is a point-in-time snapshot.

How does it differ from a one-off risk assessment?

An assessment scores exposure at a point in time, usually for a board paper or a decision. Management is what happens between assessments: monitoring the register, triaging new developments, and acting on triggers set during the last assessment. A company with only assessments and no standing management finds its register accurate on the day it was written and wrong by the time anyone reads it.

What does a geopolitical risk register actually contain?

A working register lists each identified risk with a severity score, a confidence score, the specific exposure it applies to (a supplier, a market, a counterparty), an owner, and a trigger condition for action. A register that lists risks without an owner or a trigger is a document, not a management tool.

Who should own geopolitical risk management inside a company?

Typically the chief risk officer or an equivalent enterprise risk function, but ownership of individual register items should sit with whoever can act on them: procurement for a supplier risk, treasury for a sanctions or currency risk, legal for a licensing risk. Centralising the register without distributing ownership of its items is the most common failure mode.

How does monitoring fit into risk management?

Monitoring is the input that keeps the register from going stale between formal review cycles. Without it, management becomes reactive: the register only updates when someone happens to notice a development, rather than when the development actually occurs. See geopolitical risk monitoring for how that layer works.