State ownership can entail risks both at the enterprise and portfolio levels. This report explores how governments can move beyond fragmented, enterprise-level approaches to build a consolidated understanding of risks across their state-owned enterprise (SOE) portfolios and inform strategic portfolio management. It examines relevant risks affecting SOE portfolios, including financial, operational, sustainability, and corruption and integrity-related risks, as well as their potential interlinkages. The report also considers how risk management can be integrated into ownership steering, oversight and performance monitoring moving beyond a narrow compliance exercise. Building on international standards and selected case studies, it outlines the key elements for the design and implementation of portfolio level risk management frameworks that can be adapted to different institutional settings and ownership models.
Managing Risk Across State‑Owned Enterprises
Abstract
Executive summary
As countries adapt to new economic, technological and global developments, state‑owned enterprises (SOEs) are taking an increasingly strategic role. Governments hold diversified portfolios of SOEs that operate in sectors ranging from energy, transport and finance to utilities, defence and infrastructure. These portfolios expose states to fiscal, operational, reputational and policy risks that can accumulate across enterprises and sectors. When unmanaged or insufficiently understood, such risks can affect public finances, service delivery, market confidence and public trust. When managed effectively, they also create opportunities to advance public policy objectives, support economic resilience and generate long-term value for citizens.
While governments have traditionally focussed on risk management at the enterprise‑level, many of the most significant risks associated with state ownership emerge only when viewed holistically. Drawing on a qualitative survey, interviews with ownership entities and practitioners, and a review of international standards and six case studies, this report examines how governments can better identify, assess and manage risks at the portfolio level. It develops the key building blocks to support ownership entities in the development of portfolio-wide risk management frameworks. Its key findings are outlined below.
Portfolio level risk management remains underdeveloped
Copy link to Portfolio level risk management remains underdevelopedRisk management practices are increasingly embedded within enterprise level risk management frameworks, but equivalent frameworks at the portfolio level remain comparatively rare. OECD data from the report to Council on the implementation of the ACI Guidelines show that while 81% of respondents reported having rules or expectations requiring SOEs to implement risk management systems, only 41% have a state level framework designed to monitor and manage risks across the portfolio (OECD, 2025[1]). When analysed in more detail, including informal or de facto frameworks, fewer than half of respondents reported having any form or elements of portfolio risk management frameworks. This limits governments’ ability to develop a consolidated understanding of how risks accumulate, interact and become concentrated at the portfolio level. This report seeks to unpack and analyse in more detail the gap between SOE risk management frameworks and risk management frameworks at the state portfolio level.
Reliance on enterprise‑level systems alone often results in fragmented oversight. Internal control, audit and compliance functions are essential components of good governance, but they tend to focus on risks within individual organisations, rather than on systemic, strategic or cross‑cutting risks affecting the broader portfolio. As a result, governments may struggle to identify exposures or interconnected risks and opportunities which only become visible at an aggregated level.
Several factors contribute to these gaps, including fragmented information flows between ministries, ownership entities and SOEs; inconsistent reporting practices; uneven alignment between SOE and state‑level systems; and capacity constraints within ownership entities. In some cases, SOE‑level systems are considered sufficient for oversight. However, even robust enterprise‑level systems cannot provide a consolidated view of how risks accumulate and interact across the portfolio level. This may result in governments overlooking both emerging exposures and opportunities to enhance performance, resilience and public value across their SOE portfolio.
Portfolio-level approaches help governments identify interconnected risks and opportunities
Copy link to Portfolio-level approaches help governments identify interconnected risks and opportunitiesGovernments most frequently focus on three broad categories of risk: sustainability-related risks, financial and performance risks, and corruption and integrity risks. Sustainability‑related risks were identified by 75% of respondents, reflecting the concentration of SOEs in carbon‑intensive industries and infrastructure sectors exposed to climate transition risks, environmental pressures and broader social impacts. Financial and performance risks were cited by 58% of respondents and include balance‑sheet vulnerabilities, long‑term liabilities, operational inefficiencies and the fiscal costs related to ensuring affordability of public services or financing to cover public policy objectives. Corruption and integrity risks were identified as one of the top three key risk priorities by 50% of respondents. Corruption and integrity risks are commonly associated with undermining transparency, accountability mechanisms, and legitimacy on which effective state ownership depends. These risks can lead to financial losses, operational inefficiencies, reputational damage and increased fiscal liabilities for the state. A portfolio‑level approach can help identify recurring governance weaknesses across enterprises and support more systematic risk mitigation and oversight.
These categories are often closely interconnected. Weak governance and integrity can amplify financial losses and undermine sustainability outcomes. Similarly, poorly managed sustainability transitions can generate fiscal pressures and reputational risks. The report’s case studies illustrate how portfolio‑level approaches help governments identify these interconnections, distinguish between policy‑driven and performance‑driven risks and opportunities, and prioritise mitigation efforts more effectively rather than relying on enterprise‑level assessments alone. The case studies also show that effective frameworks do not depend on a single institutional model. Across diverse ownership arrangements, successful approaches share common features, including clear governance and accountability structures, systematic aggregation of risk information, clear reporting mechanisms, and the integration of risk considerations into strategic and decision‑making processes. They further demonstrate that portfolio‑level risk management is most effective when treated as a continuous process that informs ownership policy, resource allocation and oversight decisions, rather than as a stand‑alone reporting or compliance exercise. Experiences from Canada, Greece, Israel, Peru, Singapore and the United Kingdom highlight different pathways to implementation, reflecting varying ownership models and institutional settings. Despite these differences, the case studies point to the importance of defining risk appetite, establishing consistent reporting frameworks, strengthening analytical capacity within ownership entities, and embedding risk assessments into broader portfolio and management practices.
Effective portfolio risk management supports better ownership decisions and strengthens resilience
Copy link to Effective portfolio risk management supports better ownership decisions and strengthens resiliencePortfolio risk management is most effective when it is integrated into the state’s broader ownership function rather than treated as a standalone compliance exercise. Mature frameworks enable governments to consolidate risk information across enterprises, align ownership decisions with risk appetite and policy objectives, and incorporate risk considerations into decisions regarding investment, restructuring, capital allocation and divestment. Although institutional arrangements vary considerably across jurisdictions, successful frameworks share several common characteristics. These include clear ownership objectives and articulation of risk appetite; defined governance arrangements and leadership responsibility; integration of risk considerations into ownership decisions; structured reporting, escalation and communication mechanisms; and continuous monitoring, review and adaptation.
These frameworks typically rely on shared terminology, standardised risk criteria and comparable reporting across SOEs, enabling information to be aggregated and analysed at portfolio level. They are further supported by reliable reporting systems, regular shareholder dialogue, relevant technical expertise within ownership entities and effective co‑ordination across relevant government bodies. Where these elements are present, ownership entities are better able to use risk information systematically to act as active and informed owners.
Portfolio‑level risk management is a strategic complement to enterprise‑level systems. By adopting portfolio‑level approaches grounded in international standards and adapted to national contexts, state owners can improve oversight of interconnected risks, enhance transparency and accountability, and support better ownership decisions that strengthen their portfolio’s resilience.
Related publications
-
1 April 2026151 Pages