This chapter provides practical guidance for developing portfolio‑level risk management frameworks for state ownership entities. Drawing on international standards and country practices, it identifies the key building blocks of an effective framework, the main stages of the risk management process, and practical considerations for implementation. The chapter highlights the importance of integrating risk into ownership decision making, co‑ordinating information across the portfolio and adopting a holistic approach that recognises the interconnections between risks and opportunities to support informed portfolio decisions.
Managing Risk Across State‑Owned Enterprises
3. Building blocks of portfolio risk management
Copy link to 3. Building blocks of portfolio risk managementAbstract
State owners should distinguish clearly between portfolio-level risk management frameworks at the level of the state and risk management within individual state‑owned enterprises (SOEs). While the two levels pursue different objectives, they are interdependent. Risks and opportunities arising within individual SOEs shape the state’s aggregate risk profile including portfolio-wide financial performance, compliance, integrity and sustainability outcomes. Effective portfolio oversight, therefore, depends on clear expectations, shared terminology, consistent reporting and regular co‑ordination between the ownership entity and SOEs.
Building on the findings of the previous chapter, this chapter provides practical guidance for designing and implementing portfolio level risk management frameworks. Drawing on international standards and country practices, it translates established risk management principles into approaches that can be adapted to different ownership models and institutional contexts. The aim is to help state ownership embed risk considerations into ownership decisions, strengthen portfolio oversight and identify opportunities alongside potential risks.
Section 3.1 reviews the main international standards that inform risk management. Section 3.2 distils the six building blocks of an effective portfolio-level risk management framework covering: clear objectives and value focus; governance and leadership; risk appetite and criteria; integration into ownership processes; stakeholder engagement; and continuous monitoring and improvement. Section 3.3 explains how these elements are applied through the risk management process, while Section 3.4 considers the interconnections between risks and opportunities and the importance of a holistic portfolio perspective.
3.1. Risk management frameworks: international standards
Copy link to 3.1. Risk management frameworks: international standardsPortfolio-level risk management can draw on a range of international standards outlined in Table 3.1. While some of these standards were not developed specifically for state ownership entities, they provide shared common principles and practices that can be adapted to portfolio-level oversight. Taken together, these standards support the development of portfolio-level risk management frameworks by establishing a shared terminology, consistent reporting, clear governance arrangements and structured approaches to identifying, assessing and managing risks across the state’s portfolio.
While these standards share common principles, each contributes differently to portfolio-level risk management. ISO 31000 provides the overarching principles and processes for risk management; ISO 37301 focusses on the design of compliance management systems; ISO 37001 addresses anti-bribery risks; ISO 14004 provides guidance on environmental management; and the IIA standards emphasise independent assurance over governance, risk management and internal controls. National standards, such as BS 31100, adapt these principles to domestic contexts. These and other frameworks, including OECD, Committee of Sponsoring Organizations Enterprise Risk Management (COSO ERM) and the Financial Action Task Force (FATF) standards, provide complementary guidance that state ownership entities can draw on when designing portfolio-level risk management frameworks (see also Annex A).
Not every provision contained in these standards is directly applicable at the portfolio-level. This chapter therefore focusses on those principles that can reasonably be adapted from enterprise‑level risk management to the responsibilities of state ownership entities. Table 3.1 provides a comprehensive overview of the main international standards and guidance considered in this report, including frameworks addressing specific aspects of governance, enterprise risk management, integrity and internal control. Figure 3.1 complements this overview by showing which standards respondents to the OECD SOE Risk Management Survey most frequently cited in informing risk management practices at the state ownership level. These include the OECD SOE Guidelines (92%), the OECD ACI Guidelines (75%), ISO 31000 (38%), COSO ERM (33%) and ISO 37301 (25%).
Despite their different objectives and areas of emphasis, these standards converge around a common set of principles. The following section distils those shared principles into six practical building blocks for portfolio-level risk management frameworks.
Figure 3.1. . Key international standards informing portfolio-level risk management
Copy link to Figure 3.1. . Key international standards informing portfolio-level risk managementWhat are the key international standards you use to guide your risk management practices?
Note: Percentage out of 24 respondents.
Source: OECD SOE Risk Management Survey.
Table 3.1. Key international standards used to guide risk management practices
Copy link to Table 3.1. Key international standards used to guide risk management practices|
Standard |
Description and purpose |
Main user |
|---|---|---|
|
OECD Guidelines on Corporate Governance of State‑Owned Enterprises (SOE Guidelines) |
Concrete guidance to help policymakers evaluate and improve the legal, regulatory and institutional framework for the ownership and governance of state‑owned enterprises (SOEs). They identify the key building blocks to ensure professionalised ownership and governance and offer practical guidance for implementation at the national level. The Guidelines ensure state‑owned enterprises contribute to sustainability, economic security and resilience, by maintaining a global level playing field and high standards of integrity and business conduct. |
Governments, entities responsible for the ownership functions, policymakers, SOEs pursuing economic activities, SOEs solely carrying out non-economic activities (which are only expected to apply relevant provisions) |
|
OECD Guidelines on Anti-Corruption and Integrity in State‑Owned Enterprises (ACI Guidelines) |
First international instrument to offer states, in their role as enterprise owners, support in fighting corruption and promoting integrity in the enterprises they own. They can help states to ensure that owners exemplify integrity in their conduct, that ownership arrangements are conducive to integrity, that state‑owned enterprises adhere to good practices at the SOE level and that accountability mechanisms are integral to SOE sectors. The Guidelines complement the goals of the OECD Guidelines on Corporate Governance of State‑Owned Enterprises. |
Governments, entities responsible for the ownership functions, policymakers, SOEs pursuing economic activities, SOEs solely carrying out non-economic activities (which are only expected to apply relevant provisions) |
|
Financial Action Task Force Recommendations (FATF) |
Set out a comprehensive and consistent framework of measures which countries should implement in order to combat money laundering and terrorist financing, as well as the financing of proliferation of weapons of mass destruction. Countries have diverse legal, administrative and operational frameworks and different financial systems, and so cannot all take identical measures to counter these threats. The FATF Recommendations, therefore, set an international standard, which countries should implement through measures adapted to their particular circumstances. |
Governments, financial Institutions, designated non-financial businesses and professions, virtual assets providers, businesses and civil society, self-regulatory bodies, non-profit organisations, international organisations |
|
Committee of Sponsoring Organisations (COSO): Enterprise Risk Management (ERM) |
It aims to help organisations identify, assess and manage compliance risks by aligning them with the principles of the COSO ERM framework and the elements of an effective compliance and ethics (C&E) programme. The standard covers governance, culture, strategy, performance, review, and communication aspects of compliance risk management, offering practical steps and principles to enhance organisational compliance efforts. |
Boards and all levels of management across public and private organisations of any size |
|
The Institute of Internal Auditors (IIA) Standards |
Set mandatory requirements for the professional practice of internal auditing and for evaluating the effectiveness of internal audit activities. They provide a global framework for purpose, ethics, governance, performance, and conformance of internal audit, and are applicable at organisational and individual levels. |
Chief audit executives, internal auditors, boards and their audit committees, executive management relying on internal audit assurance |
|
ISO 37301 – Compliance management systems |
Specifies requirements and provides guidance for establishing, developing, implementing, evaluating, maintaining, and improving an effective compliance management system. It is designed to help organisations meet their compliance obligations and foster a culture of integrity. |
Boards and top management, compliance officers and legal functions, risk and internal audit teams, and business unit leaders across organisations of any type or size |
|
ISO 37001 – Anti-bribery management systems |
Sets out requirements and guidance to help organisations establish, implement, maintain, review, and improve an anti-bribery management system that prevents, detects, and responds to bribery in connection with the organisation’s activities. It applies to public, private, and not-for-profit sectors and covers direct and indirect bribery. |
Boards and senior management, compliance and ethics officers, procurement and finance leaders, human resources, internal audit, and controlled affiliates and business partners |
|
ISO 31000 – Risk management |
Sets out principles, a framework and a process for managing risk across any organisation regardless of size, activity or sector. Its purpose is to help organisations increase the likelihood of achieving objectives, improve the identification of opportunities and threats, and allocate resources for risk treatment more effectively, while integrating risk-based decision making into governance, planning, management and reporting. It is intended for use across governing bodies and management as well as specialist risk and assurance functions, since the standard is designed to be applied enterprise‑wide and embedded in organisational governance and culture. |
Boards and executives, enterprise risk leaders and second-line functions, project and operations managers, and internal audit and assurance providers |
|
ISO 14001 – Environmental management system |
Is the internationally recognised standard for environmental management systems (EMS). It provides a framework for organisations to design and implement an EMS, and continually improve their environmental performance. By adhering to this standard, organisations can ensure they are taking proactive measures to minimise their environmental footprint, comply with relevant legal requirements, and achieve their environmental objectives. The framework encompasses various aspects, from resource usage and waste management to monitoring environmental performance and involving stakeholders in environmental commitments. |
Boards and top management, environmental and sustainability leaders, operations and facilities management, supply chain and procurement, and internal audit |
|
ISO 14004 – Environmental management system |
Provides general guidance on the establishment, implementation, maintenance, and improvement of an environmental management system, complementing ISO 14001 with practical advice. It is intended for organisations seeking a systematic approach to environmental responsibilities that supports the environmental pillar of sustainability. Is applicable to any organisation, regardless of size, type and nature, and applies to the environmental aspects of its activities, products and services that the organisation determines it can either control or influence, considering a life cycle perspective. The guidance can be used in whole or in part to systematically improve environmental management. It serves to provide additional explanation of the concepts and requirements. |
Environmental and sustainability teams, operations managers, quality and integrated-management-system leaders, and internal auditors |
|
BSI – BS 31100 – United Kingdom’s local implementation of ISO 31000:2018 |
Gives recommendations for implementing the principles and guidelines in BS ISO 31000:2018 (United Kingdom’s local implementation of ISO 31000:2018), which offers practical guidance to develop proportionate and effective risk management frameworks and processes throughout an organisation. |
Boards and executives, enterprise risk managers, compliance and control functions, programme and project managers, and internal audit |
3.2. Building blocks of portfolio level risk management
Copy link to 3.2. Building blocks of portfolio level risk managementAs noted, for the purpose of this report, a portfolio-level risk management framework refers to a systematic and co‑ordinated approach to identifying, assessing, and managing risks and opportunities across the state’s portfolio. Drawing on international standards and country practices, the six building blocks that underpin effective portfolio-level risk management frameworks include:
1. set clear objectives and value focus
2. establish governance and leadership
3. define risk appetite and criteria
4. integrate into ownership processes
5. strengthen stakeholder engagement
6. monitor, review and improve continuously.
These building blocks are mutually reinforcing. Together they support more consistent decision making, clearer accountability, stronger co‑ordination across the portfolio, and more effective oversight of risks and opportunities. While presented separately for clarity, they should be implemented as an integrated framework rather than standalone measures. The remainder of this section will explain each of these steps. A distillation of good practices by building block is also provided below.
Building blocks of portfolio-level risk management
Copy link to Building blocks of portfolio-level risk managementSet clear objectives and value focus
Regularly review ownership policies to ensure objectives, values and responses to emerging risks remain aligned.
Define portfolio priorities (e.g. financial sustainability, energy security, climate transition, service delivery) to guide risk appetite.
Require SOEs to identify key risks and opportunities in strategic plans and explain how they support long-term value creation and ownership objectives.
Discuss material risks and opportunities with SOE boards at least annually and integrate findings into performance reviews and shareholder dialogue.
Establish governance and leadership
Designate a central risk co‑ordination function within the ownership entity to consolidate and report portfolio risks.
Define clear escalation channels to senior leadership.
Establish periodic interagency risk committees involving ownership, finance, sector ministries, and oversight bodies to address systemic and cross-SOE risks.
Define risk appetite and criteria
Develop a portfolio-level risk appetite aligned with ownership priorities and fiscal constraints.
Expect SOEs to set risk tolerance levels consistent with the state’s risk appetite and review them through shareholder dialogue.
Integrate into ownership processes
Embed risk considerations into performance reviews, board discussions, major investment decisions, and restructuring proposals.
Require significant transactions to include a concise assessment of risks, opportunities, and mitigation measures.
Establish escalation protocols for risks exceeding predefined thresholds.
Use standardised reporting templates to improve consistency, comparability, and portfolio-wide risk monitoring, focussing on key risks and emerging trends.
Strengthen stakeholder engagement
Draw on specialist expertise (e.g. cyber, climate, integrity) where needed.
Promote timely information-sharing and early-warning mechanisms.
Maintain regular shareholder engagement and disclosure of material risks and performance information.
Encourage peer learning and exchanges among SOEs on emerging risks and good practices.
Monitor, review and improve continuously
Develop portfolio risk dashboards to track key indicators and identify cross-cutting issues.
Conduct annual portfolio risk reviews to assess evolving risks and opportunities.
Implement lessons-learned processes following incidents, crises, or near misses and update guidance accordingly.
Maintain clear documentation of risk assessments, decisions, controls, and incidents to support oversight, accountability, and continuous improvement.
3.2.1. Set clear objectives and value focus
Risk management should support the achievement of the state’s ownership objectives, rather than focussing solely on risk avoidance. Effective risk management allows governments to pursue strategic objectives in a sustainable manner while identifying opportunities alongside potential risks. ISO 31000 emphasises that the purpose of risk management is to create and protect value and to support decision making in pursuit of objectives (ISO, 2018[1]). Similarly, the SOE Guidelines expect state owners and boards to integrate risk management as a tool for strategic planning linked to the enterprise’s performance and long-term value creation, rather than treating it as a standalone compliance exercise (OECD, 2024[2]). Accordingly, portfolio-level risk management should be embedded into strategic planning and ownership decisions, ensuring SOEs and their owners are guided by the same objectives and values.
For SOEs to align risk management with the state’s goals, the government owner should ideally articulate clear ownership rationales and objectives. This can be achieved through an ownership policy or equivalent that sets out government expectations regarding value creation, risk tolerance, and sustainability priorities. Clear ownership objectives promote consistent interpretation across ministries and SOEs, helping ensure that enterprise level risk appetite reflects the state’s broader public policy objectives.
Ownership entities can operationalise these principles by:
Periodically reviewing the ownership policy to ensure ownership objectives, values and responses to emerging risks remain aligned.
Defining portfolio-level priorities (e.g. financial sustainability, energy, economic or national security, climate transition or adaptation, service delivery) to guide risk appetite and decisions.
Requiring SOEs to explain in their strategic or business plans how key risks and opportunities affect long-term value creation and ownership objectives. These discussions should link back to the state’s ownership rationale and expectations.
Ensuring shareholder representatives discuss material risks and opportunities with SOE boards at least annually. The discussion should also assess whether such risks and opportunities could affect the achievement of public policy objectives (e.g. energy transition commitments, digital security priorities).
Creating a feedback loop between SOE financial and non-financial performance and board-shareholder discussions so that evolving risks inform future ownership decisions.
By establishing clear objectives and a shared value focus, ownership entities create the foundation for consistent governance, risk appetite and decision making across their portfolio.
3.2.2. Establish governance and leadership
Effective portfolio-level risk management depends on clear governance arrangements, well-defined responsibilities and visible leadership. International standards emphasise that accountability for risk management should be clearly assigned, supported by appropriate oversight and embedded in organisational decision making.
At the SOE level, boards are ultimately accountable for risk oversight, setting the organisational risk appetite and ensuring effective risk governance and internal control systems are in place. The SOE Guidelines state that SOE boards should have the authority and objectivity to exercise “risk management oversight and monitoring of management” (OECD, 2024[2]). Boards set the tone by approving risk policies and defining the organisation’s risk tolerance levels in line with its objectives (OECD, 2024[2]). Management, on the other hand, is responsible for designing and implementing the risk management framework and processes, as the first line managers responsible for day-to-day risk management. The IIA’s Three Lines Model reinforces the importance of separating governance, management and independent assurance functions, while ensuring that responsibilities for risk oversight remain clearly defined (The Institute of Internal Auditors, 2024[3]). An effective framework will often include oversight committees or dedicated risk functions to co‑ordinate risk management activities.
At the portfolio level, the governance arrangements will depend on the ownership model. In ownership entities that are corporatised holdings, responsibility for governance and leadership will mirror those of a company. Ultimate responsibility and oversight would be vested with the board, ensuring a clear separation of roles and responsibilities with management and internal audit and controls. In ownership entities organised as government departments or co‑ordination units, specific governance arrangements may be required to ensure responsibility for risk oversight (see case study of Israel in Chapter 4). Whether exercising ownership through centralised or dispersed arrangements, roles, responsibilities and accountability mechanisms on risk management should be clearly defined. Moreover, those exercising ownership on behalf of the state should consistently communicate a strong commitment and tone from the top.
Depending on the ownership model, governance arrangements may include:
Assigning a co‑ordination risk unit within the ownership entity (e.g. a risk or performance team) responsible for consolidating risk information across SOEs and regularly reporting to an ownership steering body.
Escalation channels within the ownership entity to leadership (responsible minister or head of agency) should be clearly defined.
Establishing interagency risk committees to support co‑ordination across ownership, line ministries, ministry of finance, and audit institutions; they meet periodically (quarterly or biannually) to align views on systemic risks, cross-SOE exposure and mitigation strategies.
Ultimately, leadership commitment is essential. ISO 31000 notes that the effectiveness of risk management depends on its integration into governance and on leadership support from the highest levels (ISO, 2018[1]). Without active endorsement by senior leadership, risk management frameworks may exist on paper but lack influence on decision making. Risk oversight responsibilities should thus be clearly identified in the governance arrangements of the ownership entity and the SOEs themselves to ensure accountability flows in both directions – from the state’s strategic guidance and from SOEs upwards through transparent reporting and feedback.
3.2.3. Define risk appetite and criteria
Risk appetite and risk criteria translate the state’s ownership objectives into practical decision making. Together, they define the level and types of risks the state is prepared to accept in pursuit of those objectives and provide a consistent basis for assessing, prioritising and responding to risks across the portfolio.
International standards emphasise that both should reflect the organisation’s objectives, context and available resources (ISO, 2018[1]). Risk appetite expresses the level and type of risk that the state is willing to accept in pursuing its ownership objectives. Risk criteria establish how risks will be evaluated, including the measures of likelihood and impact, thresholds for escalation and treatment, and a consistent basis for determining whether risks are acceptable. These criteria ensure that when risks are evaluated, there is a consistent basis for judging their significance and deciding on responses.
For state ownership entities, risk appetite should reflect the state’s ownership objectives and fiscal capacity, while allowing individual SOEs to establish risk tolerances appropriate to their mandate and operating contexts. The SOE Guidelines therefore encourage ownership entities to define clear expectations, including defining risk tolerance levels (OECD, 2024[2]). Clear risk criteria and appetite statements are core to framing how risks are managed and reported up the chain.
Practical approaches might include:
Developing a portfolio-level risk appetite framework aligned with ownership objectives and fiscal constraints.
Expecting SOEs to establish enterprise‑level risk tolerances that are consistent with the state’s overall risk appetite (especially if the state is the sole shareholder). The attainment of those risk tolerance levels can be discussed as part of shareholder dialogue.
3.2.4. Integrate into ownership processes
International standards emphasise that risk management should be embedded in organisational processes (e.g. integral to all organisational activities, including strategic planning, project management, and day-to-day operations) rather than treated as a standalone activity (ISO, 2018[1]). For state ownership entities, this means systematically incorporating risk considerations into ownership decisions, including major investment decisions or restructuring proposals. The framework element of ISO 31000 explicitly aims to “assist the organisation in integrating risk management into significant activities and functions,” including its governance and decision making structures (ISO, 2018[1]). Practical day-to-day integration may include considering risk-reward trade‑offs, including project-level risk registers, and integrating risk analyses into policy proposals.
In practice, integrating risk into ownership processes means ensuring that material risks and opportunities are considered consistently whenever material ownership decisions are taken. Practical measures can include:
Embedding risk considerations into performance reviews and shareholder dialogue, so that material financial, operational, integrity and sustainability-related risks are discussed alongside performance results. Where appropriate, risk management indicators can also inform board and/or executive management evaluation.
Requiring that major investments, restructuring proposals and other significant transactions that are submitted to shareholder approval include a summary of material risks, opportunities and mitigation measures.
Establishing escalation protocols so that significant or emerging risks exceeding a predefined thresholds are reported promptly to the appropriate decision maker (e.g. responsible minister or centralised state ownership entity).
Assigning clear focal points for portfolio risk co‑ordination within the ownership entity, with defined responsibilities for consolidating information and following up with SOEs. Where such functions are organised by sector, consistent reporting channels to the central co‑ordination unit would be advisable.
Co‑ordinating across ownership entities, line ministries and relevant public bodies to ensure that different categories of risk (financial, operational, strategic, compliance, etc.) are managed coherently and consolidate a portfolio-wide view.
Using standardised reporting templates to ensure consistent and comparable SOE risk information. These templates should capture key risks, likelihood and impact assessments, mitigation measures and links to relevant objectives (e.g. strategic or sustainability related). This supports effective consolidation of risk data, monitoring of portfolio-wide trends and identification of systemic vulnerabilities or opportunities. The focus should be on the quality over quantity of information. Aggregate SOE reports can also help consolidate sustainability-related data and identify common trends, gaps or exposures across the portfolio.
Ultimately, integrating risk into ownership processes ensures that portfolio-level risk management supports strategic decision making at key decision making points rather than operating as a separate compliance exercise. Effective implementation, however, also depends on timely information-sharing and engagement with the right stakeholders.
3.2.5. Strengthen stakeholder engagement
Effective portfolio-level risk management depends on engaging the relevant stakeholders and establishing clear channels for communication and information sharing. Information should flow both vertically (between the SOE and the state‑ownership entity) and horizontally across relevant ministries, agencies and public institutions to ensure that material risks are identified and assessed in a timely manner. Consistent with ISO 31000, stakeholder engagement should include both internal and external actors whose perspectives can improve risk identification, assessment and response (ISO, 2018[1]). Where appropriate, ownership entities may engage with SOE employees, regulators, auditors or other relevant stakeholders to better understand emerging risks and their potential implications on the portfolio.
Ownership entities can strengthen stakeholder engagement through measures such as:
Drawing on specialised expertise, whether internal or external, to inform ownership decisions on complex risks (e.g. cyber security, climate or integrity).
Establishing communication and information-sharing mechanisms that support timely escalation of material risks and early warning across the portfolio (FATF, 2025[4]; 2017[5]). Standardised reporting arrangements can facilitate consistent information flows and serve as early warnings systems.
Maintaining regular shareholder dialogue supported by regular disclosure of material risk factors and performance information to strengthen oversight and provide a continuous feedback loop between SOEs and the ownership entity (OECD, 2024[2]; 2019[6]).
Facilitating peer learning among SOEs through sectoral knowledge‑sharing platforms to disseminate lessons on emerging risks and effective mitigation practices.
Ultimately, effective stakeholder engagement ensures that portfolio risk management benefits from diverse expertise, timely information and continuous dialogue, strengthening oversight and decision making.
3.2.6. Monitor, review and improve continuously
Risk management is a continuous process that should evolve as the organisation’s objectives, operating environment and risk profile changes. International standards emphasise regular monitoring, review and continuous improvement to ensure that risk management remains effective and supports informed decision making over time. Consistent with ISO 31000, each cycle of risk identification, assessment, treatment and monitoring should inform future improvements (ISO, 2018[1]). For ownership entities, continuous improvement could involve:
Developing portfolio-level risk dashboards that consolidate key risk indicators across SOEs (as derived from pre‑existing risk reporting templates), enabling the ownership entity to identify trends, cross-cutting risks and emerging issues.
Conducting regular (annual) portfolio-level risk reviews to proactively assess changes in portfolio risk profile and determine whether governance arrangements, risk responses and priorities remain appropriate. Stakeholder consultation can inform this review process.
Establishing “lessons learned” processes to review incidents, crises or near-misses, translating experiences into updated guidance or risk criteria to drive continuous improvement. Fostering a culture of learning helps both government and SOEs continuously strengthen their risk management approaches.
Continuous improvement also depends on clear documentation and effective internal controls, which provide the foundation for consistent implementation, accountability and organisational learning. OECD guidance emphasises that risk management should be supported by coherent and comprehensive internal controls, ethics and compliance arrangements (OECD, 2024[2]) Similarly, frameworks such as COSO, which align with IIA Guidance, highlight the close relationship between risk management, internal control and ongoing monitoring. Practical implementation would include:
Maintaining clear documentation, including risk registers, risk reports, incident logs, and documented procedures to support consistency, transparency and oversight.
Keeping records of risk assessments and decisions to strengthen accountability and facilitate future review.
Comprehensive documentation facilitates oversight, audit and organisation learning while providing decision makers and other relevant stakeholders with a clear record of how risks were assessed and managed. Together, monitoring, review and documentation help ensure that portfolio risk management remains effective and responsive to change. (ISO, 2018[1]).
3.3. Putting frameworks into practice: Distilling risk management processes
Copy link to 3.3. Putting frameworks into practice: Distilling risk management processesHaving outlined the key building blocks of an effective portfolio risk management framework, this section describes how those elements are applied in practice through risk management processes. Figure 3.3 summarises the key stages of the portfolio risk management process, drawing on ISO 31000:2018 and adapting it to the context of state ownership. Although presented sequentially, it is iterative in practice with activities revisited as conditions evolve. The process is scalable (applicable to a whole enterprise or a small project) and can be applied to individual decisions, specific projects or the portfolio as a whole.
Figure 3.2. Risk Management Process based on ISO 31000:2018
Copy link to Figure 3.2. Risk Management Process based on ISO 31000:2018
Source: ISO (2018[1]), ISO 31000:2018 – Risk management – Guidelines, https://www.iso.org/standard/65694.html
Figure 3.3. The risk management process cycle based on ISO 31000:2018
Copy link to Figure 3.3. The risk management process cycle based on ISO 31000:2018Source: ISO, (2018[1]), ISO 31000:2018 – Risk management – Guidelines, https://www.iso.org/standard/65694.html
3.3.1. Establishing the scope, context and criteria
Before aiming to identify risks, ownership entities should first establish the scope, context and criteria for the assessment. This ensures that risk identification is aligned with the objectives of the exercise and that risks are assessed consistently across the portfolio. This step, based on the ISO framework, entails (ISO, 2018[1]):
Scope: Defining what is being assessed (e.g. portfolio-wide, a sector, a major transaction).
Context: Considering the external and internal environment, including government priorities, market conditions, legal or regulatory developments, and stakeholder expectations.
Risk Criteria: Defining how risks will be assessed, including risk appetite, likelihood, impact and thresholds for escalation or treatment. Risk criteria should not be generic; they should be tailored to the specific objectives and context of the ownership entity.
Risk criteria should reflect the ownership entities’ objectives, risk appetite and institutional context, and should be periodically reviewed to remain aligned with changing circumstances. The state ownership policy, national anti-corruption strategy or other strategic document can inform this step (OECD, 2016[7]).
In developing appropriate risk criteria, ownership entities should consider the following factors:
types and sources of uncertainty that may influence outcomes, whether tangible or intangible
methodologies by which consequences, both beneficial and adverse, and their likelihoods are identified, quantified, and evaluated
temporal dimensions that may impact the manifestation or evolution of risks
need for consistency in measurement approaches
thresholds and parameters by which levels of risk are to be categorised
manner in which concurrent or sequential risks are to be assessed in aggregate
state’s institutional capacity to respond to or absorb risk.
Figure 3.4. Risk criteria factors to consider
Copy link to Figure 3.4. Risk criteria factors to consider3.3.2. Risk assessment
Risk assessment is the overall iterative process of identifying risks that are material, analysing, and evaluating risks to further treat them (ISO, 2018[1]). This step is central to understanding what risks exist and how significant they are. It also helps assess the materiality of certain risks and opportunities since it is essentially a structured process to help determine which risks and opportunities matter most for decision making and disclosure. In practice, organisations, including state ownership entities, would define scope and criteria, identify a long list of relevant risks and opportunities, gather inputs from internal analysis and stakeholders, evaluate significance using defined criteria, and validate outcomes through governance before reporting. According to ISO 31000, risk assessments should be conducted “systematically, iteratively and collaboratively, drawing on the knowledge and views of stakeholders” (ISO, 2018[1]) to ensure they are comprehensive and up to date. Table 3.2 summarises this process.
Table 3.2. Risk assessment
Copy link to Table 3.2. Risk assessmentRisk assessment is the overall iterative process of identifying risks that are material, analysing, and evaluating risks to further treat them.
|
Risk identification |
At the portfolio level, risk identification aims to develop a comprehensive review of all material risks and opportunities affecting the state’s SOE portfolio. This involves asking: “What could happen? How, when, and why could it happen?” It includes identifying sources of risk, events (including rare but impactful events), situations or hazards, and opportunities that could impact objectives. Relevant information may come from experience, historical data, brainstorming, expert judgment, and checklists or frameworks, for example political, economic, social, technological, legal, and environmental (PESTLE) analysis for external factors, or a business process model for operational risks. ISO 31000 emphasises using appropriate and up-to-date information in identifying risks. Some factors to consider are tangible and intangible sources of risk, causes and events, threats and opportunities, vulnerabilities, existing capabilities (controls), changes in context, and indicators of emerging risks. At this stage, the aim is to compile a comprehensive inventory of risks without yet prioritising them – often documented in a risk register. |
|
Risk analysis |
Once risks are identified, each risk is analysed to understand its nature and characteristics, including the potential consequences and how likely those consequences are to occur. ISO 31000 defines the purpose of risk analysis as “to comprehend the nature of risk and its characteristics, including, where appropriate, the level of risk.”. This typically involves assessing the likelihood of the risk event and the impact (consequence) if it occurs, given the existing controls in place. Risk analysis can be qualitative, quantitative or combined approaches depending on data availability and the decision needs. Factors considered in analysis include the effectiveness of current controls, complexity or interdependence with other risks, and uncertainty factors. The output of risk analysis is typically an estimation of the level of risk, often expressed as a risk rating or mapped on a risk matrix. For example, an identified risk of “data breach” might be analysed as medium likelihood but high impact, yielding a “high” risk rating, whereas “minor legal compliance violation” might be low likelihood and low impact, yielding a “low” risk rating. ISO 31000 notes that risk analysis provides the basis for risk evaluation and decisions on treatment priorities. Importantly, analysis should document assumptions, uncertainty ranges, and the rationale, as these will be important for transparency and later review. |
|
Risk evaluation |
In this sub-step, the results of the risk analysis are compared against the previously defined risk criteria to determine which risks need further action and what that action should be. Essentially, risk evaluation asks: “Which risks are acceptable, and which require treatment?” and “What are the priorities?” According to ISO 31000, the purpose of risk evaluation is “to support decisions” about which risks need treatment and the priority of such treatment. If a risk’s level is above the acceptable threshold (for instance, exceeding the risk appetite), it will likely require treatment. The outcome of evaluation might be a decision to:
For example, a risk evaluated as “extreme” might lead to a decision to invest in significant new controls or to halt a project, whereas a “moderate” risk might simply be monitored. The evaluation step ensures that management and the board make informed choices about risk responses, focussing resources on the most significant risks. |
|
Risk treatment |
After evaluation, the next step is to treat the risks that have been deemed unacceptable or that present worthwhile opportunities. Risk treatment means selecting and implementing one or more risk control or response options. ISO 31000 defines the purpose of risk treatment as “to select and implement options for addressing risk.” Treatments modify the risk by changing its likelihood, its impact, or both. Common risk treatment strategies include:
Selecting the best combination of options involves balancing the cost and effort of implementation against the benefits in risk reduction. Once options are chosen, an action plan (risk treatment plan) is developed, assigning owners and deadlines to each action. Implementation then proceeds, and the effectiveness of treatments is monitored. After implementation, the remaining residual risk should be assessed again, or addressed through another round of risk treatment until an acceptable level of risk is achieved. |
Source: Adapted from ISO (2018[1]).
3.3.3. Communication and consultation
Whereas the earlier section focussed on stakeholder engagement as a building block, communication and consultation with relevant stakeholders aims to support the risk management process by building ownership. Effective communication promotes awareness of risks, and consultation enables gathering diverse perspectives and information. (ISO, 2018[1]). This might involve workshops to identify risks with experts, discussions with management to define risk criteria, and reporting to the board about significant risks.
3.3.4. Monitoring and review
Risk management does not end with implementing risk treatments. Continuous monitoring and review are critical to ensure that risks and controls remain relevant and effective over time. ISO 31000 states that the purpose of monitoring and review is “to assure and improve the quality and effectiveness of process design, implementation and outcomes.” (ISO, 2018[1]). Monitoring can include performance indicators (e.g. tracking frequency of incidents or control failures), audits and evaluations of controls, and periodic risk reviews by management committees. ISO 31000 highlights that monitoring and review should be embedded in all stages of the process and in normal management routines. For instance, a project team might review its risk register at each project milestone, or an enterprise risk committee might review top risks quarterly. Regular reviews might lead to revisions in risk analysis or the introduction of new treatments, essentially feeding back into the cycle (hence the iterative nature of risk management). In addition, review includes learning from experience – after incidents or near-misses, organisations should investigate causes and update their risk assessments and controls accordingly. In the public sector or SOE context, monitoring also ensures accountability: for example, the government owner might periodically evaluate whether the SOE’s risk management practices align with expectations and best practices. Ultimately, this step ensures the risk management process remains dynamic and responsive, and it drives continuous improvement. This means closing the loop and starting back again with establishing a new scope, context and criteria that incorporates feedback from the previous assessment and thus creates a continuous cycle of risk management and compliance (ISO, 2018[1]).
3.3.5. Recording and reporting
Throughout the process, and especially as a final step, the framework calls for proper recording and reporting of risk information. All risks identified, analysis results, decisions, and actions taken should be documented in a systematic way. Good record-keeping facilitates transparency and institutional knowledge – new managers can understand past decisions, and auditors or regulators can review the risk management process. Reporting is about communicating relevant risk information to the right people. ISO 31000 notes that recording and reporting aim to “communicate risk management activities and outcomes across the organization; provide information for decision-making; improve risk management activities; and assist interaction with stakeholders responsible for risk management.” (ISO, 2018[1]). Different levels of reporting will exist, such as operational reports for line managers, summary reports for executives and boards, and even public disclosures in some cases (for example, annual reports of companies often include a section on principal risks and how they are managed, in line with governance codes). For SOEs, there may be additional reporting lines to the government or supervising ministry focussing on key risk exposures (e.g. contingent liabilities, financial risks, safety risks). The OECD SOE Guidelines specifically call for SOEs to disclose “any material foreseeable risk factors and measures taken to manage such risks” in their annual disclosures (OECD, 2024[2]). Effective recording and reporting strengthen accountability, support informed decision making and enhance transparency.
3.4. Interconnectedness of risks and opportunities
Copy link to 3.4. Interconnectedness of risks and opportunitiesAn effective portfolio-level risk management framework requires ownership entities to develop a comprehensive and integrated perspective on risks, recognising that they often do not occur in isolation. Risks that may appear unrelated in concept or distant in time can interact in ways that amplify their overall impact or create new opportunities in other unforeseen areas. For example, environmental risks such as climate change can influence supply chain stability, financial performance, and social cohesion, which in turn may affect the strategic objectives of state‑owned enterprises. OECD survey data shows that 79% of state owners think that corruption, integrity and sustainability risks should be addressed together as part of the same holistic framework (Figure 3.6). Respondents provided as an explanation the interconnected nature of these risks as well as efficient allocation of resources through a comprehensive overview of risks. Adopting this integrated and holistic view enables governments to anticipate cascading effects that could be missed if risks were managed in isolation.
Figure 3.5. Managing risks holistically
Copy link to Figure 3.5. Managing risks holisticallyIn your opinion, how can anti-corruption, integrity and sustainability risks be addressed for better outcomes?
Source: OECD SOE Risk Management Survey.
Equally important is the recognition that the interrelationship between risks can generate opportunities. For instance, technological innovation adopted to mitigate operational or compliance risks may also create competitive advantages for state‑owned enterprises and improve efficiency and service delivery (see for example Temasek case study in Chapter 4). Similarly, initiatives aimed at enhancing environmental performance or responsible business conduct, can open access to new markets, attract sustainable investment and talent, and strengthen the reputation of the state as an owner (ISO, 2016[8]; OECD, 2023[9]). Understanding these linkages should enable state ownership entities to make strategic choices that maximise value creation while managing risk exposure across the portfolio.
A holistic view on interconnected risks and opportunities also facilitates better prioritisation of resources and interventions. By mapping the relationships among different categories of risk, states can identify areas where intervention may reduce risk exposure while generating cross-cutting benefits. A comprehensive portfolio-level risk management framework also enables state ownership entities to harmonise practices across enterprises, establish shared terminology and reporting, and improve transparency and accountability, while leading by example on managing risks and opportunities. Portfolios that are managed with a systemic understanding of these linkages may be better positioned to respond to emerging challenges, adapt to shifting contexts, and seize opportunities for sustainable growth.
References
[4] FATF (2025), International Standards on Combating Money Laundering and the Financing of Terrorism & Proliferation, FATF, http://www.fatf-gafi.org/en/publications/Fatfrecommendations/Fatf-recommendations.html (accessed on 16 May 2025).
[5] FATF (2017), Consolidated FATF Standards on Information Sharing, FATF, Paris, http://www.fatf-gafi.org/publications/fatfrecommendations/documents/consolidated-fatf-standard-information-sharing.html (accessed on 8 October 2025).
[1] ISO (2018), ISO 31000:2018 - Risk management - Guidelines, https://www.iso.org/standard/65694.html.
[8] ISO (2016), “ISO 14004:2016 Environmental management systems — General guidelines on implementation”, https://www.iso.org/standard/60856.html (accessed on 10 July 2025).
[2] OECD (2024), Recommendation of the Council on Guidelines on Corporate Governance of State-Owned Enterprises, OECD/LEGAL/0414, https://legalinstruments.oecd.org/en/instruments/OECD-LEGAL-0414.
[9] OECD (2023), OECD Guidelines for Multinational Enterprises on Responsible Business Conduct, OECD Publishing, Paris, https://doi.org/10.1787/81f92357-en.
[6] OECD (2019), Guidelines on Anti-corruption and Integrity in State-Owned Enterprises, OECD Publishing, Paris, https://doi.org/10.1787/315dab91-en.
[7] OECD (2016), Risk Management by State-Owned Enterprises and their Ownership, Corporate Governance, OECD Publishing, Paris, https://doi.org/10.1787/9789264262249-en.
[3] The Institute of Internal Auditors (2024), “The IIA’s Three Lines Model: An update of the Three Lines of Defense”, The Institute of Internal Auditors, https://www.theiia.org/en/content/position-papers/2020/the-iias-three-lines-model-an-update-of-the-three-lines-of-defense/ (accessed on 26 May 2025).