All insights
Geopolitical RiskAugust 3, 202611 min read

Geopolitical Risk Governance: Ownership, Escalation and Board Reporting

Boards are being asked what the company's geopolitical exposure is. In most organisations exposure is real, spread across five functions and aggregated nowhere.

By Kamakshi Wason, Executive Director, TF Global Advisory Partners
Darkened boardroom with a world map projection on the far wall

Boards are being asked a question they cannot yet answer

Regulators, investors and audit committees increasingly expect a direct answer to a simple question: what is this company's geopolitical exposure, and who is managing it? In most organisations the honest answer is that exposure is real, distributed across five functions, and aggregated nowhere.

Geopolitical risk governance is the mechanism that fixes that — assigning ownership, defining escalation, and producing a board-level view that is consistent enough to show change over time.

Where geopolitical risk should sit

There is no single correct home, but there is a wrong one: leaving it unassigned across government affairs, legal, procurement, treasury and regional leadership, each holding a fragment.

Three workable models:

  • Enterprise risk-led. Geopolitical risk becomes a named category in the ERM framework with a dedicated owner. Best for organisations with a mature risk function; the failure mode is treating it as a register entry rather than a strategy input.
  • Strategy-led. Ownership sits with corporate strategy, tied directly to capital allocation and market planning. Best where geopolitics primarily drives investment decisions; the failure mode is weak operational escalation during incidents.
  • Dedicated function. A small geopolitical intelligence team reporting to the CRO, general counsel or strategy chief. Justified above roughly thirty markets or where exposure is concentrated in contested jurisdictions.

Whichever model, three things must be explicit: a single accountable executive, a cross-functional committee with authority to act, and a defined route from an indicator breach to a decision inside days rather than weeks.

The three-lines model applied

First line — the business. Regional and functional leaders own exposure in their markets: maintaining the dependency data, applying screening in supplier and customer onboarding, and executing contingency actions.

Second line — risk, compliance and the geopolitical function. Owns the framework, the indicator set, the assessment standard and the aggregated view. Challenges first-line optimism.

Third line — internal audit. Tests whether the framework is operating: is the exposure register current, are thresholds monitored, were escalations actioned, were board-approved mitigations implemented?

The third line is routinely missing in geopolitical programmes, which is why so many decay quietly after the first year.

What belongs in the board pack

One page, the same structure every quarter, four blocks.

1. Exposure summary. Top five jurisdictions by value at risk — revenue, assets and committed capital — with the quarter-on-quarter movement and the reason for it.

2. Direction of travel. Which markets deteriorated or improved, expressed as bands rather than false-precision scores, with a one-line mechanism for each move.

3. Open decisions. Decisions currently deferred or contingent on geopolitical developments, with the cost of delay and the date by which a decision must be made.

4. Mitigation status. What was approved, what has been implemented, and the residual exposure after implementation.

What does not belong: event narrative, regional commentary, or anything the board cannot act on. Supporting analysis goes into an annex for those who want it.

Metrics that survive scrutiny

Boards ask how performance in this area is measured. Five metrics answer credibly:

  • Value at risk by jurisdiction, trended over eight quarters.
  • Coverage — proportion of revenue and critical suppliers inside the maintained exposure register. Below full coverage, every other number is understated.
  • Gap count — nodes where time-to-recover exceeds time-to-survive, and total gap weeks.
  • Escalation performance — median time from threshold breach to decision, and the proportion of triggers actioned within the defined window.
  • Assessment calibration — retrospective scoring of past judgements against outcomes. This is the metric that distinguishes an intelligence capability from a reporting one.

Escalation: the part that breaks under pressure

Most organisations discover their escalation design during the incident it was meant to handle. Three design choices prevent that.

Pre-delegated authority. Named executives hold pre-approved authority to release buffer inventory, activate alternative suppliers, suspend shipments to a jurisdiction, or authorise evacuation, up to defined financial limits, without convening a committee.

Defined trigger thresholds. Written before the event, with owners. "Licence approval times exceed 45 days for two consecutive months" produces action; "situation deteriorates" produces a meeting.

A rehearsed crisis cell. Composition, convening time, decision rights and communication protocol, exercised at least annually against a realistic scenario. The rehearsal, not the document, is what creates the capability.

Disclosure and the external audience

Geopolitical exposure increasingly appears in risk factor disclosures, investor questions and lender covenants. Three principles keep disclosure defensible:

  1. Consistency with internal reporting. External statements should reconcile to what the board actually sees. Divergence is a governance finding waiting to happen.
  2. Specificity over boilerplate. Investors discount generic "geopolitical uncertainty" language. Named exposures with described mitigations read as control.
  3. Care with forward statements. Describe exposure and management approach; avoid implied predictions about political outcomes.

Common governance failures

  • The annual deep dive. One thorough review per year, with nothing between. Exposure changes on a monthly cadence.
  • The orphaned dashboard. Built by a consultant, unmaintained by month nine, still displayed.
  • Analysis without decision rights. A capable team that can describe risk and change nothing.
  • Committee latency. Escalation paths requiring three approvals across time zones for an action that had a 48-hour window.
  • No calibration. Judgements never scored, so quality never improves and the function's credibility rests on presentation.

A twelve-month build

Months 1–3. Assign the accountable executive, stand up the committee, build the first exposure register. Accept incomplete data; the gaps are findings.

Months 4–6. Define the indicator set and thresholds, agree pre-delegated authorities, publish the first board page.

Months 7–9. Scenario work on the top three exposures, financial translation, mitigation cost curve to the board for funding.

Months 10–12. Crisis rehearsal, first calibration review, internal audit of framework operation.

At the end of twelve months the test is not whether the organisation has a geopolitical risk framework. It is whether three specific decisions were made differently because of it.

How we support boards

We help enterprises stand up geopolitical risk governance — exposure registers, assessment standards, escalation design, board reporting formats and crisis rehearsal — supported by market-level analysis from our country intelligence coverage and delivered with our strategic consulting practice.

Request a governance scoping conversation.

Ready to move faster?

Book a free 20-minute diagnostic. We'll identify the highest-leverage opportunity on your plate and outline a path forward.

Book a Free Consultation