This report aims to support governments in developing, revising and implementing their risk management frameworks across the portfolio of companies they own.
The OECD Working Party on State Ownership and Privatisation Practices (WPSOPP) has developed good practice guidance to support the implementation of instruments under its purview, namely the OECD Guidelines on Corporate Governance of State‑Owned Enterprises (SOE Guidelines) and the Guidelines on Anti-Corruption and Integrity in State‑Owned Enterprises (ACI Guidelines). Notable examples include the Implementation Guide for the ACI Guidelines, as well as guides on aggregate reporting, privatisation, sustainability, and strengthening state ownership. By offering concrete examples, these guides have helped policymakers and practitioners alike in advancing reforms and implementing good practices.
This good practice guidance supports effective risk management at the portfolio level, complementing and supplementing risk management practices of individual enterprises. While the report does not assess the design of enterprise‑level systems themselves, it treats them as critical prerequisites for portfolio-level risk management systems. A portfolio‑level perspective allows state owners to understand their portfolio-level exposures and associated risks and opportunities which can support active and informed decisions on investment, divestment and restructuring, while strengthening accountability and public trust.
Addressed to ownership entities, the report identifies key building blocks and outlines practical steps for designing, implementing and operating portfolio‑level risk management frameworks. These approaches are adaptable to different institutional settings and ownership models, recognising that there is no single blueprint for effective state ownership.
The report has been developed drawing on international standards and frameworks including the SOE Guidelines and ACI Guidelines, Institute of Internal Auditors (IIA) standards and FATF Recommendations, as well as ISO 37301, ISO 37001, ISO 31000, ISO 14001, ISO 14004, BSI – BS 31100, and COSO ERM. It draws on information gathered through the OECD SOE Risk Management Survey, a perception-based survey covering 24 jurisdictions, interviews with ownership entities and risk management practitioners, as well as illustrative case studies from Canada, Greece, Israel, Peru, Singapore and the United Kingdom.
This report was developed by the Capital Markets and Financial Institutions Division of the OECD Directorate for Financial and Enterprise Affairs. It was prepared by Santiago Wortman Jofre, with inputs from Arijete Idrizi and Nina Chitaia, under the supervision of Sara Sultan, Head of the State‑Owned Enterprise Unit, and Serdar Çelik, Head of Division.
Delegates of the OECD Working Party on State Ownership and Privatisation Practices and corporate risk management experts consulted by the OECD provided information and insights on their practices.