Concept

Corporate geopolitical-risk management

Corporate geopolitical-risk management is private adaptation to changes in law, market access, political risk, sanctions exposure, supply chains and security conditions. Firms transmit statecraft when law, licence conditions, procurement rules or documented public direction require them to act. Diversification, exit, hedging and resilience remain corporate choices unless state direction or delegated authority is established. The concept therefore belongs in the context sequence.

Governance and exposure

Geopolitical risk can affect board oversight, strategy, compliance, capital allocation and operational resilience. A useful assessment maps dated exposure across jurisdictions, revenue, suppliers, logistics, data, finance, technology, ownership, licences and critical personnel. It then tests concentration, substitutability, contract terms, inventory, insurance, financing and recovery arrangements.

Fragmentation should refer to observable policy or network change, such as new trade restrictions, investment screening, sanctions, export controls or shifts in cross-border investment. It should not serve as a free-standing explanation for every corporate decision. The International Monetary Fund maps macroeconomic fragmentation channels and scenarios, while the European Economic Security Strategy names official risk categories. Neither establishes the cause of a particular firm's action.

Dario Caldara and Matteo Iacoviello's geopolitical-risk index is constructed from newspaper text about adverse geopolitical events and threats. It supports analysis of aggregate attention and association. It is not a calibrated probability of firm loss, a map of legal exposure or a measure of supplier concentration. Firm-level decisions require firm-level evidence.

Distinct corporate functions

Enterprise risk management governs uncertainty against strategy and performance. ISO 31000 and the Committee of Sponsoring Organizations' framework provide general risk principles and governance structures, but neither prescribes a national-security position. Scenario analysis, concentration limits, substitution plans, inventories, contractual protection and crisis governance remain management choices.

Compliance implements binding legal or regulatory duties. The United States Office of Foreign Assets Control's 2019 framework identifies five components of a risk-based sanctions compliance programme. For the relevant rule and transaction, a firm can act as a regulated intermediary. That role does not automatically extend to the firm's unrelated supply-chain or market strategy.

Responsible business conduct concerns due diligence over adverse impacts on people, the environment and society. The OECD Guidelines, OECD due-diligence guidance and United Nations Guiding Principles establish a separate normative and governance field. They should not be collapsed into sanctions compliance or national-security risk management. Political-risk transfer through insurance, guarantees, contracts and hedging is also distinct from operational continuity and legal compliance.

Corporate transmission of statecraft

A firm can be a regulated intermediary, delegated operator or private adapter in different episodes. The classification depends on jurisdiction, transaction, legal duty, public direction and discretion. A bank blocking a prohibited payment transmits a binding rule. A manufacturer leaving a market for commercial and reputation reasons makes a corporate choice, even if the exit amplifies state pressure. Adaptation can reinforce, blunt or redirect the sender's measure.

Claims about named firms require filings, enforcement decisions, contracts or reproducible datasets. A policy shock, management decision, market effect and strategic outcome are separate links. Broad figures for write-downs or exits are unreliable without a defined sample, period, currency and accounting treatment.

Joseph Baines, Julian Germann, Steve Rolf and Sean Starrs use network analysis to examine German corporate positioning in United States-China rivalry. Their 2026 article is peer reviewed, but its sample and method do not establish a universal corporate response. Luis Alberto Cochis's 2026 paper is an unreviewed SSRN working paper and provides an emerging practitioner-research contribution. It does not establish consensus or effectiveness.

See also

Economic security · Geoeconomic fragmentation · Sanctions compliance · Export controls · Supply-chain resilience · Public-private coordination (aligning incentives)

Sources

Recommended citation

Cite this entry

Tennant, James J., ed. 'Corporate geopolitical-risk management.' The Encyclopedia of Economic Statecraft, version 2.0, last reviewed 29 July 2026. https://jamesjtennant.com/entries/corporate-risk-management-under-geopolitical-fragmentation/.

Suggest an edit