This chapter presents a series of country case studies illustrating how portfolio‑level risk management frameworks are designed, implemented and applied in practice. Drawing on diverse institutional models, it examines approaches developed by Canada, Greece, Israel, Peru, Singapore and the United Kingdom. The case studies highlight how ownership entities consolidate risk information, define risk appetite, and link portfolio‑level assessments to strategic decisions on oversight, investment and restructuring. They also show how frameworks evolve over time, supported by governance arrangements, reporting systems and co‑ordination mechanisms. The chapter provides concrete examples of how the interconnectedness of risks is addressed and how portfolio‑level tools contribute to more informed and consistent state ownership practices.
Managing Risk Across State‑Owned Enterprises
4. Case studies
Copy link to 4. Case studiesAbstract
This chapter presents case studies of SOE portfolio-level risk management frameworks, highlighting how different organisations and ownership models approach portfolio risk management focussing, where relevant, on corruption, integrity and sustainability-related risks while capturing related opportunities. These cases also seek to show how those policies and processes that help establish effective and efficient portfolio risk management frameworks at the state level, or “key enablers”, act in practice to support effective risk management and identify opportunities across portfolios. The case studies are drawn from experiences in Canada (CDEV), Greece (Growthfund), Israel (Government Companies Authority), Peru (Fonafe), Singapore (Temasek), and the United Kingdom (UKGI).
4.1. Canada Development Investment Corporation (CDEV)
Copy link to 4.1. Canada Development Investment Corporation (CDEV)Canada Development Investment Corporation (CDEV) was incorporated in 1982 and is wholly owned by His Majesty in Right of Canada (Canada Development Investment Corporation, 2024[1]), operating as an agent Crown corporation listed in Schedule III, Part II of the Financial Administration Act and not subject to the Income Tax Act. CDEV reports to Parliament through the Minister of Finance, and has a mandate described by the Minister of Finance as reflecting ongoing commercial management of holdings and providing assistance to Government of Canada in policy directions suited to its capabilities (Canada Development Investment Corporation, 2024[1]).
In Canada, Crown corporations are government-owned corporations that operate under corporate governance arrangements and report to Parliament through a responsible minister (Treasury Board of Canada Secretariat, 2019[2]). Some Crown corporations are agents of the Crown, meaning they can bind the Crown and may benefit from Crown privileges and immunities as set out in the Financial Administration Act and related guidance (Treasury Board of Canada Secretariat, 2019[2]).
4.1.1. Ownership structure and portfolio overview
CDEV describes its mandate as providing financial advisory support to the Government of Canada and managing a group of companies and programmes held on behalf of the Government of Canada (Canada Development Investment Corporation, 2024[1]). CDEV’s governance structure is composed of a Board of Directors, comprising six members, including the President and Chief Executive Officer. The Board oversees CDEV’s affairs, including the management of its assets, liabilities and subsidiaries, and it approves financial statements and corporate reports that are made public through the company’s reporting mechanisms (Canada Development Investment Corporation, 2024[1]).
The Board is supported by three standing committees covering audit, governance and nominations, and human resources and compensation matters (Canada Development Investment Corporation, 2024[1]). The Board operates through a scheduled meeting cycle, including four regular meetings each year and additional meetings to approve quarterly financial statements. Risk oversight is embedded throughout the governance framework, with both the CDEV Board and subsidiary boards responsible for enterprise risk management. To support portfolio-level oversight, the CDEV Board receives summary risk reporting from each subsidiary, enabling it to monitor risks across the portfolio and maintain visibility over key risk exposures (Canada Development Investment Corporation, 2024[1]).
CDEV’s portfolio comprises eight wholly owned subsidiaries with different mandates and risk profiles, including regulated energy infrastructure, offshore resource royalties, emergency and strategic finance programmes, clean economy investment facilitation, Indigenous loan guarantees, innovation promotion and legacy environmental obligations (Canada Development Investment Corporation, 2024[1]).1 Based on CDEV’s reporting, the consolidated group includes the parent and wholly owned subsidiaries, while certain entities are treated as unconsolidated structured entities under International Financial Reporting Standards (Canada Development Investment Corporation, 2024[1]). CDEV appoints the boards of its subsidiaries, which report to the CDEV Board on a quarterly basis. (Canada Development Investment Corporation, 2024[1]).
In energy transport, Trans Mountain Corporation and Canada TMP Finance Ltd were incorporated in 2018. Trans Mountain Corporation is a non-agent Crown corporation, which owns and operates the Trans Mountain Pipeline and the Puget Pipeline, Canada's only oil and refined-products pipeline off the West coast. According to CDEV, the Trans Mountain Expansion Project commenced commercial operations on 1 May 2024 and increased pipeline capacity from about 300 000 barrels per day before May 2024 to about 890 000 barrels per day after May 2024 (Canada Development Investment Corporation, 2024[1]). In offshore oil, Canada Hibernia Holding Corporation holds minority, non-operated interests, in the Hibernia Development Project and the Hibernia Southern Extension Unit, with working interests of 8.5% and 5.67% respectively (Canada Development Investment Corporation, 2024[1]).
In emergency and strategic financing, Canada Enterprise Emergency Funding Corporation (CEEFC) was incorporated in May 2020, and is wholly owned by CDEV as a non-agent Crown corporation (Canada Enterprise Emergency Funding Corporation, 2025[3]). Until March 2025, CEEFC administered the Large Employer Emergency Financing Facility. After March 2025, CEEFC was mandated to establish and administer a Large Enterprise Tariff Loan facility (Canada Enterprise Emergency Funding Corporation, 2025[4]). In clean economy investment facilitation, Canada Growth Fund Inc. was incorporated in December 2022 and entered into an investment management agreement with the Public Sector Pension Investment Board and Canada Growth Fund Investment Management Inc (Canada Development Investment Corporation, 2024[1]).
According to the Canadian Government’s priorities related to Indigenous economic reconciliation, CDEV launched the federal Indigenous Loan Guarantee Program in December 2024 through the creation of Canada Indigenous Loan Guarantee Corporation (Canada Development Investment Corporation, 2024[1]).
CDEV reports holding CAD 75 billion in government assets, returning CAD 10.8 billion in dividends to Canada since 2010 (Canada Development Investment Corporation, 2026[5]). In 2024, it also reported consolidated revenues of CAD 2.15 billion, with Trans Mountain Corporation representing CAD 1.97 billion (91.5%) and Canada Hibernia Holding Corporation representing CAD 160 million (7.4%) within the consolidated perimeter (Canada Development Investment Corporation, 2024[1]).
4.1.2. Portfolio level risk management framework
According to CDEV’s 2024 annual report, the company’s Board, its committees, and the Boards of its subsidiaries are responsible for enterprise risk management, with management reporting annually and as required on risks and mitigating actions (Canada Development Investment Corporation, 2024[1]). For portfolio oversight, CDEV’s Board receives risk reports for each subsidiary, which are then compiled and analysed at a central level, to manage risks across the whole portfolio (Canada Development Investment Corporation, 2024[1]).
As co-responsible for CDEV’s risk management, Board committees support oversight of key risk domains. In this sense, the Audit Committee focusses on the integrity of financial statements, compliance with legal and regulatory requirements, external audit and internal controls, while the Nominating and Governance Committee focusses on governance policies and the Human Resources and Compensation Committee focusses on operational and employment-related risks (Canada Development Investment Corporation, 2024[1]).
The design of the boards of subsidiaries and appointment arrangements vary across the portfolio. While in some cases, subsidiary boards are composed exclusively of CDEV directors or management, others include a mix of CDEV directors, independent directors and executive representation (Canada Development Investment Corporation, 2024[1]).
CDEV maintains internal accounting and administrative controls designed to provide reasonable assurance on the reliability of financial records and the safeguarding of assets. Although CDEV is exempt from the requirement to carry out internal audits, as permitted by Order in Council, internal audits have been carried out nonetheless periodically upon request of the Board (Canada Development Investment Corporation, 2024[1]). CDEV’s audited consolidated financial statements are subject to joint audit by the Auditor General of Canada and a large auditing firm and includes a meeting with the Audit Committee to discuss auditing matters and financial reporting issues (Canada Development Investment Corporation, 2024[1]).
In its financial statement disclosures, CDEV framed risks arising from financial instruments into three categories: credit and contract risk, liquidity risk, and market risk (Canada Development Investment Corporation, 2024[1]). In its statement, CDEV also includes objectives, policies and processes for measuring and managing these risks (Canada Development Investment Corporation, 2024[1]).
CDEV defined credit and contract risk as the risk of financial loss to the Corporation if counterparties do not fulfil their contractual obligations arising primarily from the Corporation’s trade and other receivables. CDEV pointed out that a significant exposure to this risk is related to crude oil sales and oil shipment sales from contracts with customers (Canada Development Investment Corporation, 2024[1]). As an example of mitigating measures, CDEV reported that crude oil sales are conducted through creditworthy companies that act as principal purchasers and assume responsibility for subsequent sales to end customers (Canada Development Investment Corporation, 2024[1]). Another example included the use of tariff related requirements, such as guarantees or letters of credit, for customer financial assurance in regulated pipeline operations (Canada Development Investment Corporation, 2024[1]). Regarding its risks, CDEV, for example, also reports revenue concentration, including the fact that two customers represent about 30% of consolidated invoiced revenues (Canada Development Investment Corporation, 2024[1]).
Liquidity risk relates to the risk that the Corporation will encounter difficulty in meeting obligations associated with financial liabilities that are settled by delivering cash or another financial asset (Canada Development Investment Corporation, 2024[1]). As specific mitigating measures of liquidity risks, CDEV highlighted the forecasting of cash requirements, meaning that, to the extent possible, it tries to have sufficient cash or financial assets to meet its liabilities when due. Focusing on a cross-portfolio perspective, CDEV stresses its retention of liquidity through short-term investments, as well as the issuance of debt, which provides flexibility to meet obligations during a prolonged downturn in the energy sector (Canada Development Investment Corporation, 2024[1]).
Market risk relates to the risk that the fair value or future cash flows of a financial instrument will fluctuate due to changes in market prices, and includes foreign exchange, commodity price, and interest rate risk (Canada Development Investment Corporation, 2024[1]). Thus, according to CDEV, market risk includes currency risk, commodity price risk, interest rate risk, and price risk (Canada Development Investment Corporation, 2024[1]). To mitigate such risk, CDEV reported that it does not use derivative instruments, such as interest rate swaps or forward foreign currency contracts, and it discloses foreign exchange and commodity exposures and relevant sensitivities (Canada Development Investment Corporation, 2024[1]). Nevertheless, CDEV highlighted that it has not been significantly exposed to such risks in 2024 overall (Canada Development Investment Corporation, 2024[1]).
For programmes administered through CEEFC, risk management is described through financial risk management disclosures linked to programme design. As stated in the 2024 annual report of CEEFC, its financial performance is highly dependent on economic conditions, industry dynamics and specific borrower attributes (Canada Enterprise Emergency Funding Corporation, 2025[3]). CEEFC states that its credit risk is considered very high and that loans are monitored for indicators of impairment, with collectability assessments performed at each reporting period. CEEFC reported recognising a provision for losses on loans of CAD 485 million in 2024 following a loan portfolio assessment (Canada Enterprise Emergency Funding Corporation, 2025[3]). To manage risk, CEEFC reported using collateral for secured lending facilities, actively managing its equity and warrant holdings until disposal, and maintaining liquidity through preference shares subscribed by the Government of Canada under a funding agreement (Canada Enterprise Emergency Funding Corporation, 2025[3]). This funding arrangement also supports liquidity across the broader CDEV portfolio and therefore forms part of its portfolio-level risk management approach (Canada Development Investment Corporation, 2024[1]).
4.1.3. Examples of portfolio risk and opportunity management
The 2024 annual report of CDEV provided two concrete examples on how portfolio-level risk management can help mitigate risks and seize profitable opportunities. The first example concerns Trans Mountain as a strategic asset, which was expanded to triple its capacity by 2024, and finally refinanced through long-term funding. The second example focusses on the Canada Indigenous Loan Guarantee Corporation, as the latest company in CDEV’s portfolio, which doubled in size from CAD 5 billion to CAD 10 billion in 2024 (Canada Development Investment Corporation, 2024[1]).
Trans Mountain Corporation (TMC) refinancing illustrates how CDEV actively manages liquidity and financing risks across its portfolio as assets transition from construction to commercial operations. CDEV reported that the Trans Mountain Expansion Project commenced commercial operations on 1 May 2024, shifting the asset towards transportation revenues and operational cash flows (Canada Development Investment Corporation, 2024[1]). Following this transition, TMC refinanced portions of its debt, including modifications to borrowings under a credit agreement with Export Development Canada that reduced the fixed interest rate to 3.01% and extended the maturity date. Borrowings under a syndicated credit agreement were also replaced with a fixed-rate refinancing loan, generating expected savings of CAD 3.5 billion over six years (Canada Development Investment Corporation, 2024[1]). According to CDEV, these refinancing measures were made possible by the substantial reduction in project risk following the commencement of revenue‑generating operations (Canada Development Investment Corporation, 2024[1]).
The federal Indigenous Loan Guarantee Program illustrates CDEV’s role in developing new financing instruments that expand access to capital while maintaining prudent portfolio-level management of credit risk. The programme provides up to CAD 5 billion in federal loan guarantees and is designed to help eligible Indigenous Governments and their wholly owned and controlled entities access lower cost capital to acquire equity ownership in natural resource and energy projects in Canada (Government of Canada, 2025[6]). The policy intent is to reduce structural financing barriers and support economic reconciliation by enabling Indigenous participation in major projects on terms set by Indigenous communities (Government of Canada, 2025[6]). In risk terms, the programme transfers a defined portion of project financing risk from lenders to CDEV, which is able to take on such risk as a result of a detailed due diligence process, and a credit structuring system through negotiated terms between guarantor, lenders, and borrower. A portfolio level risk management framework also enables CDEV to take on these guarantor risks with adequate mitigating measures such as those in place for liquidity risks (Canada Development Investment Corporation, 2024[1]).
CDEV created Canada Indigenous Loan Guarantee Corporation in 2024 to administer the programme and issued the first loan guarantee in July 2025 (Canada Development Investment Corporation, 2025[7]). According to CDEV, the first guarantee covered CAD 400 million of a CAD 736 million investment by 38 First Nations in British Columbia for a 12.5% stake in Enbridge’s Westcoast pipeline system. CDEV also stated that the guaranteed bonds were rated AAA by Morningstar DBRS based on the guarantor’s status as an agent of the federal Crown (Canada Development Investment Corporation, 2025[7]).
4.2. Greece: Growthfund
Copy link to 4.2. Greece: GrowthfundGrowthfund is Greece’s sovereign investment holding company,2 established in 2016 and wholly owned by the Hellenic Republic, with the Minister of National Economy and Finance acting as the sole shareholder (Growthfund, 2025[8]). Its statutory mission is to modernise state‑owned enterprises and maximise the value of public assets and social impact by supporting national economic objectives through professional portfolio management and active stewardship.
4.2.1. Ownership structure and portfolio overview
Growthfund’s governance recognises the state as sole shareholder exercising ownership through a General Assembly and underscores heightened expectations for transparency, social effectiveness and accountability given its public-interest purpose (Growthfund, 2025[9]). As shown in Figure 4.1, Growthfund has a Corporate Governance Council which is entrusted with the oversight of the Board of Directors. The Corporate Governance Council consists of three members selected by the state, and two members, including the Chairperson, selected by the European Commission and the European Stability Mechanism, each with a five‑year term of office (Growthfund, 2025[10]). The Board of Directors implements the strategic directives of the Greek State and possesses decision making authority on all matters concerning the management of the company, except those explicitly entrusted to the Corporate Governance Council or the General Assembly as stipulated by the law. Its members are elected by the Corporate Governance Council and consist of five to nine individuals who serve a four‑year term. As of 2025, the Board has 75% independent non-executive members, and 25% executive members (Growthfund, 2025[11]).
The portfolio of Growthfund spans strategic sectors with direct social impact, including real estate, energy, transport and infrastructure, water and sewerage, postal services, food markets, technology and innovation and finance. As of 31 December 2023, Growthfund reported assets under management of EUR 11.7 billion, 23 subsidiaries and participations, plus concession rights and port-planning authority mandates. The portfolio includes holdings such as Hellenic Public Properties Company, Public Power Corporation, DEPA Commercial, Transport for Athens, major airports and ports, Hellenic Post, as well as stakes in the National Bank of Greece and Attica Bank; it also houses a Project Preparation Facility that develops and tenders strategic public projects exceeding EUR 8 billion (Growthfund, 2025[8]).
Figure 4.1. Organisational chart of Growthfund
Copy link to Figure 4.1. Organisational chart of Growthfund
Note: 1. “Audit” and “Group Risk”, report directly to the Risk Committee.
Source: Based on Growthfund, (2025[12]), Organizational Chart, https://growthfund.gr/en/about-us/organizational-chart/
4.2.2. Portfolio-level risk management framework
Growthfund assigns portfolio-level risk oversight to its Board, supported by the Board Risk Committee (BRC), Executive Management and a dedicated Group Risk Management Division under the three‑lines model (Growthfund, 2025[13]; The Institute of Internal Auditors, 2024[14]). The BRC, established as a distinct committee in 2021 (Growthfund, 2025[13]), supports the Board which approves the Risk Management Policy and the Risk Appetite Framework, monitors whether the Group’s risk profile remains within approved appetite and limits and assesses the effectiveness of risk management annually. The BRC oversees the Group Risk Management Division, reviews the Policy and the Risk Appetite Framework for submission to the Board, monitors key risk indicators and follows up on the implementation of mitigation actions (Growthfund, 2025[13]). The Audit Committee oversees financial reporting, the internal control system, compliance monitoring and internal audit, including supervision of the Internal Audit Unit and the external auditors. These committees are composed primarily of independent non-executive directors with relevant expertise (Growthfund, 2025[13]).
The Group Risk Management Division (see Figure 4.1) serves as the link between Executive Management, company units and BRC, and its goal is to design and implement risk policies, evaluate and validate methods for identifying, measuring and monitoring risks, and manage risk issues in line with the Board Committee’s directions (Growthfund, 2023[15]). The Division is led by a Group Chief Risk Officer and operates as a second line function working with Legal Services, the IT Security Officer, the Regulatory Compliance Director and the Data Protection Officer. It co‑ordinates with Internal Audit and the subsidiaries’ risk units through a formal co‑operation framework, with the Group Chief Risk Officer providing risk profile reports to inform the annual audit plan (Growthfund, 2023[15]). Second-line functions include Risk Management, Compliance, Legal Services, with Internal Audit providing independent assurance as the third line.
Growthfund’s Risk Management Framework covers strategic, operational, compliance, financial and information systems risks, reflecting the diverse risk exposures associated with managing a portfolio of state‑owned assets (Growthfund, 2024[16]). The framework provides a common basis for assessing and reporting risks across the portfolio, enabling management and the Board to identify emerging risk concentrations, monitor risks against established appetite and tolerance levels, and support portfolio-wide risk oversight (Growthfund, 2024[16]).
Executive Management is responsible for implementing and effectively operating the Risk Management processes and managing residual risks, based on the Risk Appetite Statements and limits that have been determined (Growthfund, 2024[16]). A common risk management framework is applied across the SOEs, as well as a formal collaboration mechanism enshrined in the “Collaboration Framework of the Risk Management Unit of Growthfund (RMU-GF)”, between Growthfund’s Group Risk Management Division and the risk units of subsidiaries to align methodologies. This collaboration framework reduces duplication of efforts and supports consistent aggregation and escalation to Growthfund.
According to Growthfund’s Risk Management Framework, the relevant risks are initially identified and recorded in the risk matrices of each SOE in relation to its purpose and operational framework, corporate governance structure, and specific activities (Growthfund, 2025[17]). These SOE‑level risks are then matched with the taxonomy of the central risk matrix of Growthfund, as the holding company, and registered in the corresponding category in collaboration with the business unit of each SOE. However, Growthfund emphasises that the practical implementation of mitigation actions is more important than the risk scores themselves (Growthfund, 2025[17]).
Methodologically, Growthfund applies a group-wide standardised process that covers identification, assessment, mitigation, monitoring and reporting, implementing the risk management process established in ISO 31000 (Section 3.3.2 on Risk assessment). Regular business risk assessments produce a consolidated Risk Registry that rates inherent (untreated risks) and residual risk (risk left after mitigating measures) by frequency and impact, assesses control sufficiency and determines residual risk that requires management (Growthfund, 2024[16]). Inherent risks are scored by combining the estimated likelihood of occurrence and the severity of impact on a five‑point scale and then plotted on a risk map that classifies exposures as low, medium, high or very high to guide prioritisation and treatment. Residual risk is then assessed by evaluating whether internal controls exist, are adequately designed, operate effectively and deliver the intended results; the same scale is used to re‑rate risks, with the heat map providing a consolidated view of the portfolio’s risk profile and helping to sequence mitigation actions. In practice, low and medium residual risks are subject to regular monitoring, while high and very high residual risks are prioritised for mitigation plans that are submitted to the Board for approval (Growthfund, 2024[16]; Growthfund, 2025[17]).
The process implements key international standards mentioned in previous chapters by using key risk indicators to track developments and requires systematic reporting to Executive Management and the Board Risk Committee, with the Committee updating the Board on substantial risks and the adequacy and effectiveness of the framework (Growthfund, 2024[16]).The policy assigns responsibilities to a Group Risk Management Division for the design, co‑ordination and monitoring of the framework, the maintenance of the Risk Registry, the development of key risk indicators and the preparation of risk reports to senior management and the Board (Growthfund, 2024[16]). Reporting is conducted on a regular and ad hoc basis with escalation protocols for significant or urgent matters, while addressing business continuity and crisis management arrangements (Growthfund, 2025[18]).
Figure 4.2. . Growthfund’s risk management framework
Copy link to Figure 4.2. . Growthfund’s risk management framework
Source: Based on Growthfund, (2025[18]), Risk Management, https://growthfund.gr/en/corporate-governance/risk-management/
Integrity and anti-corruption risks are categorised under compliance risks according to Growthfund’s risk taxonomy (Growthfund, 2024[16]), with expectations set out in the Anti-Corruption and Bribery Policy, and a Code of Ethics and Professional Conduct (Growthfund, 2018[19]; Growthfund, 2019[20]). Growthfund applies zero tolerance to all forms of corruption and bribery, prohibits facilitation payments and political contributions on behalf of the company, sets controls for gifts and hospitality, requires due diligence for third parties and commits to training and confidential reporting, with sanctions for violations (Growthfund, 2019[20]). The policy applies to Board members, employees and associates and provides guidance for subsidiaries to establish and implement similar measures (Growthfund, 2019[20]). Moreover, a Whistleblowing Policy encourages confidential reporting by employees and partners (Growthfund, 2022[21]). These policies set expectations for subsidiaries to adopt aligned measures and are complemented by third-party due diligence procedures (Growthfund, 2020[22]).
Sustainability is integrated into Growthfund’s risk management and oversight framework through a common ESG policy and reporting requirements that apply across portfolio companies (Growthfund, 2024[16]). By requiring investees to report against consistent sustainability standards and indicators, Growthfund supports comparable monitoring, risk assessment and engagement across its portfolio (Growthfund, 2022[23]).
4.2.3. Examples of portfolio risk and opportunity management
Growthfund’s portfolio includes transport and infrastructure exposures such as the SOE GAIAOSE S.A. and the Athens Urban Transport Organisation and its operating subsidiaries, which means global logistics disruptions can affect service continuity and financial performance across the group (Growthfund, 2025[24]). The grounding of the Ever Given vessel blocked the Suez Canal for six days from 23 to 29 March 2021, with at least 369 vessels queued and an estimated USD 9.6 billion of goods held up per day, highlighting concentration risk in critical trade corridors and the sensitivity of downstream networks to chokepoint failures (Lewis and Reuters, 2021[25]; Uras and Siddiqui, 2021[26]). This episode illustrates portfolio level exposures that cut across strategic, operational and financial risk categories in Growthfund’s taxonomy.
Events of this kind point to the value of digital tools, such as the use of risk management software (Growthfund, 2025[17]), for near real time supply chain visibility, scenario planning for route diversions, and contingency arrangements with alternative suppliers and carriers. For state portfolio entities operating or relying on logistics, this supports investment in data platforms and dashboards that feed portfolio risk indicators and heat maps, as well as automated and pre‑defined notifications for reporting to the relevant executives, thus enabling earlier escalation where disruptions threaten essential services (Growthfund, 2024[16]). The same analysis can inform opportunity capture in port and intermodal capacity where resilience investments can improve reliability and value over time.
Another example stems from Greece’s deadliest rail disaster near Tempi in 2023, which caused 57 deaths and had direct relevance for Growthfund’s transport exposures (Gatopoulos and Pitarakis, 2025[27]). The national investigation by the Hellenic Air and Rail Safety Investigation Authority found human error, outdated infrastructure and major systemic failures, including a lack of automated safety measures, underscoring the interaction of operational, compliance and information systems risk in the portfolio. These findings demonstrate how critical safety gaps can escalate residual risk to very high on a risk map and require board approved mitigation plans and transparent progress reporting.
Independent reporting and official communications note that modern train control systems could have averted the collision, specifically remote control, signalling renewal and the European Train Control System (ETCS) with automatic braking (European Public Prosecutor’s Office, 2023[28]). The government has since committed to install ETCS and real time train tracking on the main rail axis, reflecting a technology pathway to reduce residual risk and raise service reliability (Reuters, 2025[29]). For portfolio oversight, this shows how targeted investments in safety technology, training and asset renewal can shift exposures within Growthfund’s risk appetite, while creating opportunity for performance improvement and public value.
4.3. Israel: Government Companies Authority (GCA)
Copy link to 4.3. Israel: Government Companies Authority (GCA)The Government Companies Authority (GCA) is the State of Israel’s central ownership co‑ordination body for state‑owned enterprises. It was established in 1975 under the Government Companies Law and operates as an auxiliary unit of the Ministry of Regional Co‑operation. It sat within the Ministry of Finance until 2023, when it was transferred to the Ministry of Regional Co‑operation, as decided by Government decision 460 (Government Companies Authority, 2023[30]; 2024[31]). Its core purpose is to support the government and responsible ministers in exercising the state’s ownership rights, including the oversight of privatisations and the management of structural changes affecting government companies (Government Companies Authority, 2026[32]).
The following case study highlights the structure of a draft framework in the process of being implemented by the Government Companies Authority of Israel. Therefore, the structure differs from the one that has been applied to the other case studies and focusses on the intended structure and implementation methodology of the foreseen risk management framework at the portfolio level. This case study highlights the challenges for a government agency when developing and implementing such a framework and outlines the prospective strategic benefits for Israel’s state‑owned portfolio.
4.3.1. Ownership structure and portfolio overview
Ownership rights are exercised by responsible ministers, with the Government Companies Authority (GCA) serving as the state’s central ownership co‑ordination body. Acting as the government’s representative vis-à-vis state‑owned enterprises, the GCA advises ministers and companies on governance and corporate management matters, oversees company performance and reporting, and supports privatisations, restructurings, mergers and other ownership-related transactions. The Authority also contributes to the establishment, reorganisation and disposal of state shareholdings and supports the implementation of government ownership and privatisation decisions, through the Ministerial Committee on Privatisation. (OECD, 2011[33]).
The portfolio perimeter covers several legal categories. Public reporting distinguishes “government owned companies”, where the state holds more than half of voting rights or can appoint more than half of directors, and “mixed companies”, where the state holds half or less and is subject to a more limited set of provisions (OECD, 2011[33]; Government Companies Authority, 2023[30]; 2024[31]). In addition, the state‑owned sector includes government subsidiary companies, and, in some reporting, associated bodies such as certain associations and statutory corporations established under sector specific laws (Government Companies Authority, 2024[31]).
In 2024, the GCA reported the supervision of 68 government owned companies, 38 additional companies not controlled by the state, 18 government subsidiary companies, 4 non-profit organisations and 16 mixed companies. Combined assets, excluding supervised assets, were about EUR 78.6 billion, revenue was approximately EUR 29.1 billion, and net profit about EUR 2.2 billion, with around 50 000 employees (Government Companies Authority, 2024[31]). A set of 15 leading government companies accounts for 97% of the sector’s revenue and holds 96% of the total assets of all government companies (Government Companies Authority, 2024[31]).
Portfolio composition spans infrastructure heavy and strategically sectors. Official reporting highlights large exposures in public utilities and natural monopolies, transport and logistics infrastructure, defence and aerospace industries, and public service providers.3
4.3.2. Portfolio level risk management framework
In 2009 the GCA first issued policy guidelines outlining how the risk manager should operate within SOEs. Over the years, the guidelines have evolved in light of experience and changing conditions, as well as the GCA recognising the significant value of establishing a risk management function at the ownership level. GCA views portfolio-level risk oversight as a necessary complement to enterprise‑level risk management in SOEs operating in complex and interconnected environments.
To address these challenges, the Government Companies Authority has drafted in 2026 a comprehensive framework aimed at strengthening risk management practices across government companies. The framework seeks to establish a coherent, portfolio‑level approach that enhances comparability, enables aggregation of risk information and supports informed decision making, while remaining proportionate to differences in company size, mandate and risk profile.
The draft framework is designed to strengthen governance and performance management across government companies by establishing risk appetite consistent with business and budget objectives and clarifying accountability for risk oversight while improving the quality of information available to and from boards as well as the ownership entity. A core element of the framework is the aim to enhance systemic resilience and strategic oversight by enabling risks to be identified, assessed and monitored not only at the level of individual companies, but also across the government enterprise portfolio and by different sectors. The framework also aims to promote evidence‑based decision making by encouraging the use of standardised methodologies, quantitative indicators and analytical tools.
The draft framework is underpinned by a number of principles aligned with international good practice in enterprise risk management and state ownership. Responsibility for risk management rests ultimately with boards of directors, which are expected to develop the risk appetite and oversee the effectiveness of risk management systems. The framework integrates risk management into strategic planning, budgeting and operational decision making, rather than as a separate compliance exercise.
The draft framework also emphasises proportionality and the need for tailored risk management mechanisms, recognising that requirements should reflect differences in company size, complexity and exposure. Clear application of the three lines of defence model supports accountability by distinguishing between risk ownership, oversight and assurance functions. Finally, the use of common terminology, methodologies and reporting formats is intended to support comparability and aggregation.
4.3.3. Next steps: Phased implementation
Concerning the implementation of this draft framework, the GCA foresees a roll-out structured around four stages, reflecting increasing levels of maturity both in the relationship between SOEs and the state as an owner, and the state’s understanding of the risk exposure of its SOEs. This graduated approach allows for progressive capacity building while delivering early improvements in transparency, shareholder dialogue and governance.
Stage 1 focusses on mapping existing practices and identifying gaps. The objective is to establish a reliable baseline of risk management arrangements across government companies. This includes reviewing SOE‑level governance structures, policies and methodologies; assessing the articulation and use of risk appetite across SOEs; identifying key risk exposures; examining the use of basic risk quantification tools; and reviewing organisational arrangements for risk management, including the role and resourcing of the risk function. Particular attention is given to past failures and near‑failures, as well as to business continuity and operational resilience arrangements. In this stage, the GCA collects information through a dedicated survey deployed to gather data on key internal regulations and practices at the SOE level, as well as bilateral interviews aimed at building trust and information sharing between the GCA and the SOEs. This diagnostic phase enables the ownership entity to identify cross‑cutting vulnerabilities and common exposure patterns, as well as to examine the level of organisational maturity of each SOE in the portfolio.
Stage 2 centres on the establishment of minimum requirements and common frameworks. The objective is to move from data analysis and documentation to assistance in the implementation of key risk management mechanisms at individual SOEs, with the aim of improving transparency and stakeholder trust. Companies are required to adopt a formalised, board‑approved master document on risk management, while retaining flexibility in how it is applied. This master document will consist of a unified framework for reporting and managing risks, integrating financial, operational and strategic risks into strategic planning and budgets. Key elements of the framework include the definition of an accurate risk appetite, adoption of a recognised risk assessment methodology, and use of a common risk taxonomy (risk dictionary) covering strategic, financial, operational, cyber and regulatory risks. The role and independence of the board of directors and the chief risk officer are formally defined, with direct access to senior management and the board. Companies are also required to integrate cyber and information security risks into enterprise‑wide risk management and to treat environmental, social and governance (ESG) risks in a structured manner aligned with international standards. In parallel, mandatory business impact analysis, business continuity planning and regular testing are introduced to strengthen operational resilience. In addition, this stage is intended to provide critical information that will enhance SOEs’ preparedness for business continuity across a range of risk scenarios.
Stage 3 aims to develop more advanced and forward‑looking risk management capabilities, consolidating a uniform level of implementation between companies as well as a common language. Companies are expected to move beyond compliance‑oriented processes towards more analytical and strategic approaches that support proactive decision making. This includes the preparation of comprehensive risk reports, periodic structured risk surveys, identification and prioritisation of top risks, and use of heat maps to visualise overall exposure. Companies are expected to build an internal monitoring tool, providing an updated picture of risk exposures, and enabling proactive responses. Stress testing and scenario analysis are introduced to assess resilience under extreme but plausible conditions, while dashboards and key risk indicators support ongoing monitoring and early warning. Training programmes for board members and senior executives are used to reinforce risk culture and improve risk‑informed governance. A key landmark of this phase is the consolidation of reporting requirements to the GCA through quarterly reports featuring key risk indicators, heatmaps, and the top 5 risk priorities of the company. These reports will help establish continuity, transparency, and appropriate control over cross-portfolio risks.
Stage 4 completes the framework through portfolio‑level integration. The GCA aims at establishing a centralised risk management information system that consolidates company‑level data into an integrated portfolio view. The system will aim to support an up-to-date monitoring through dashboards and heat maps, enabling trend analysis and benchmarking across companies and sectors, and facilitate scenario analysis and stress testing of systemic risks. It also aims at strengthening co‑ordination with line ministries and relevant authorities, particularly in crisis situations. Continuous updating and refinement of analytical tools ensure that the system remains responsive to evolving risks and execution of government risk mitigation plans.
Throughout all stages, the framework places strong emphasis on regular, timely and proportionate reporting. Companies are expected to provide periodic updates on key risks, indicators and risk maps, and to escalate material risk events or significant breaches of approved risk appetite without delay. These mechanisms are intended to strengthen transparency, reinforce board accountability and enable timely intervention by both company leadership and the ownership entity when risks threaten the achievement of public objectives.
4.4. Peru: Fondo Nacional de Financiamiento de la Actividad Empresarial del Estado (FONAFE)
Copy link to 4.4. Peru: Fondo Nacional de Financiamiento de la Actividad Empresarial del Estado (FONAFE)FONAFE is a wholly state‑owned holding company operating under the Peruvian public-law framework, attached to the Ministry of Economy and Finance, with autonomy in exercising its functions, and responsible for directing and supervising the business activities of SOEs within its portfolio (Presidencia de la República del Peru, 2024[34]). As a public-law company, FONAFE was originally established by Law No. 27170 (1999) (Congreso de la República del Peru, 1999[35]). That founding framework has since been replaced by the Legislative Decree No. 1693 (2024) adopted in October 2024 (Presidencia de la República del Peru, 2024[34]).
The statutory mission of FONAFE is to ensure that the SOEs under its oversight create economic, social and environmental value (Presidencia de la República del Peru, 2024[34]). It seeks to help them achieve their goals related to the quality and accessibility of the goods and services they provide, while maintaining financial sustainability. In addition, FONAFE aims to foster synergy among its affiliated companies by promoting collaboration and the exchange of best practices to enhance overall management and performance (Presidencia de la República del Peru, 2024[34]).
4.4.1. Ownership structure and portfolio overview
FONAFE is a state‑holding company that sets ownership policy, appoints board members to SOEs, and clarifies how shareholding rights are exercised across the SOEs in its portfolio. Legislative Decree No. 1693 defines FONAFE’s perimeter as state‑owned companies whose capital is wholly, or majority owned (directly or indirectly) by the National Government, unless excluded by explicit legal rule. The Decree also explicitly excludes municipal enterprises, public university enterprises or production centres, and Petróleos del Perú – Petroperú S.A. from FONAFE’s scope (Presidencia de la República del Peru, 2024[34]).4
Figure 4.3. Corporate structure of FONAFE
Copy link to Figure 4.3. Corporate structure of FONAFE
Note: All corporate management areas perform dual functions towards FONAFE and the SOEs within its portfolio.
Source: Based on FONAFE, (2026[36]), Estructura de Fonafe, https://www.fonafe.gob.pe/pw_content/miscelanea/1/Doc/Estructura%20de%20Fonafe..jpeg.
FONAFE’s governance framework comprises a Council of Representatives, a Board of Directors and a Chief Executive Officer. The Council retains responsibility for key ownership policy decisions, while the Board directs and oversees FONAFE’s portfolio management activities, including strategic planning, shareholder oversight, governance standards and major financial decisions. Day-to-day management is delegated to the Chief Executive Officer, who is responsible for implementing board decisions (Presidencia de la República del Peru, 2024[34]).
FONAFE’s portfolio is composed of 34 SOEs and 1 health sector social security entity (ESSALUD), including 4 in finance, 5 in electricity generation, 11 in electricity distribution, 1 in sanitation, 4 in transport and communication, 4 in defence, 2 in hydrocarbon, 3 in services, and generated PEN 28 339 million (USD 8.32 billion) in 2024. Consistent with FONAFE’s public-service delivery mandate, the three largest sectors by revenue in 2024 were electricity distribution, state financial services, and hydrocarbons/energy.
4.4.2. Portfolio-level risk management framework
FONAFE uses a group-wide monitoring approach based on maturity and performance measurement across several governance systems, rather than only a financial risk lens. This approach seeks to standardise risk matrices and approaches to risk across all companies within the portfolio of FONAFE (OECD, 2025[37]). This standardisation enables FONAFE to adequately assess risk maturity and evaluate its implementation in its portfolio (OECD, 2025[37]). Beyond these minimum requirements of risk management processes and measures, individual SOEs within FONAFE’s portfolio may implement stricter measures if deemed relevant (OECD, 2025[37]).
FONAFE provides a harmonised framework for implementing risk management systems, through its corporate manual on how to implement a comprehensive risk management system (FONAFE, 2025[38]) and its corporate guideline on comprehensive risk management (FONAFE, 2025[39]). While the corporate guidelines set the mandatory principles, roles, and minimum requirements that companies under FONAFE must follow as part of the broader internal control framework, the corporate manual acts as an implementation guide and translates the guidelines into methodology, practical steps, plans, and assessment criteria for applying risk management in practice to portfolio companies. This framework helps FONAFE to enhance monitoring of portfolio-level risks (FONAFE, 2025[39]), for example by focussing on achieving expected objectives, within the limits of applicable legislation. It also enables FONAFE to manage changes to economic and competitive environment or internal management (FONAFE, 2025[39]).
In its 2024 annual report to the Ministry of Economy and Finance (MEF), FONAFE reported on monitoring good corporate governance, comprehensive risk management, internal control system, and integrity and anti-corruption system (FONAFE, 2025[40]). This report monitors risk related capability as part of an integrated report.
The 2024 annual report provides evidence of how this framework operates in practice, which is done by tracking and comparing progress over time (FONAFE, 2025[40]). FONAFE’s Comprehensive Risk Management (GIR) reports show a validated maturity result of 97.58% at the holding company level for fiscal year 2023 and 93.55% for 2024, which it evaluates as an advanced maturity level. At the company level of the portfolio, FONAFE reported a maturity level average of 71.46% for 2022, 71.17% for 2023, and 80.37% for 2024 (under validation) (FONAFE, 2025[40]).
FONAFE has adopted an integrated portfolio-level risk governance mechanism, with a central committee function that feeds on well-established information channels with shared oversight across several control systems. FONAFE’s risk management framework is applied to specific risk domains, for example on AML/FT, or specific strategic risks in key sectors (FONAFE, 2025[40]). Its managerial Risk and Compliance Committee, within the Corporate Governance, Risk and Compliance Management Unit (Figure 4.3), was strengthened by incorporating multiple criteria, including internal control, information security, and operational continuity, so that senior leadership remain informed of progress in risk management.
Recent corporate governance reforms at enterprise level help to reinforce portfolio risk oversight. Law No. 31912 introduced the obligation for state‑owned enterprises to have at least two independent directors on their boards (FONAFE, 2025[40]). While this is formally a corporate governance reform, in practice it is also part of FONAFE risk governance as it strengthens board capacity and oversight quality across the portfolio.
FONAFE’s risk management framework is also reinforced through its corporate transparency and disclosure mechanisms (FONAFE, 2018[41]). FONAFE’s corporate transparency policy applies to FONAFE and the entities in its portfolio and expressly states that it aims to mitigate reputational risks, especially those linked to corruption (FONAFE, 2018[41]). FONAFE’s transparency guidelines establish a structured publication and review cycle that operates as a portfolio‑level oversight mechanism (FONAFE, 2018[41]). They set standard requirements for the timely disclosure of key corporate information and enable FONAFE to monitor compliance across companies through regular reviews of their transparency portals (FONAFE, 2018[41]).
Finally, to foster implementation and continuous improvement, FONAFE allocates special bonuses to SOEs based on good performance on non-financial indicators, such as individual GIR maturity levels (OECD, 2025[37]). The MEF’s 2024 report records ongoing actions to continue training on integrated risk management, information security, and operational continuity, to assign more resources to GIR, and to revise the GIR maturity evaluation methodology considering companies’ significant progress and the need for new parameters.
4.4.3. Examples of portfolio risk and opportunity management
In its 2024 report to the Ministry of Economy and Finance, FONAFE reported that it used corporate purchasing as a portfolio level mechanism to manage both risk and value creation across its electricity distribution companies (FONAFE, 2025[40]). By centralising key acquisitions, FONAFE was able to capture economies of scale and strengthen procurement planning, thereby supporting better resource management. At the same time, FONAFE’s framework embeds risk‑mitigation measures, including standardised technical controls, oversight of production processes, and the maintenance of integrity safeguards such as ISO 37001:2016 certification (FONAFE, 2025[40]). Taken together, these practices demonstrate how FONAFE integrates opportunity‑seeking and risk management within a single, co‑ordinated portfolio mechanism (OECD, 2025[37]).
A second, more operational case concerns continuity risk linked to portfolio wide procurement dependence. In a 2025 report, FONAFE stated that an important corporate procurement procedure for leasing computer equipment was declared void during an advanced phase of the process despite participation from multiple enterprises (FONAFE, 2025[42]). In response and to ensure operational continuity, it initiated steps to move towards individual contracting for equipment leasing. This is an example of portfolio level risk response, where a centralised procurement failure is treated as a continuity risk and mitigated through co‑ordinated alternative arrangements to reduce disruption (FONAFE, 2025[42]).
4.5. Singapore: Temasek
Copy link to 4.5. Singapore: TemasekTemasek Holdings is a state‑owned investment company incorporated in 1974 and wholly owned by the Government of Singapore (Temasek, 2025[43]). It operates as a commercial investment holding company under the purview of the Ministry of Finance, with an independent board, the majority of whose members are non-executive and independent private sector business leaders, and a management team (Temasek, 2025[44]). Temasek is structured as a private limited company under the Singapore Companies Act and is subject to the same commercial and regulatory requirements as other companies incorporated in Singapore (Temasek, 2025[44]).
4.5.1. Ownership structure and portfolio overview
Temasek’s governance framework is designed to ensure separation between the government’s role as shareholder and Temasek’s operational and investment decision making (Temasek, 2025[45]). As an example, investments and operational decisions are made entirely by its board and management, without involvement from the government in individual transactions or strategic choices (Temasek, 2025[45]). The Ministry of Finance, as shareholder, receives an annual report and audited financial statements but does not direct Temasek’s investment activities. Temasek seeks to safeguard the independence of board and executive appointments through merit-based nomination processes and board-led succession planning. While remaining accountable to its sole shareholder, these arrangements are designed to reduce the risk of undue political interference in leadership decisions (Temasek, 2025[45]).
Temasek manages a globally diversified portfolio that spans multiple sectors including financial services, telecommunications, media, technology, transportation, industrials, energy, consumer products, life sciences, and agri-food. As of 31 March 2025, Temasek’s net portfolio value was SGD 434 billion (USD 339 billion), with investments distributed across Singapore, the rest of Asia, the Americas, Europe, the Middle East, and Africa (Temasek, 2025[46]). The portfolio is balanced between mature, dividends-generating investments and growth sectors, reflecting Temasek’s long-term investment strategy and its role in contributing to Singapore’s sustainable economic development (Temasek, 2025[47]).
While Temasek invests in companies where it holds varying degrees of ownership, it does not exercise direct management control over portfolio companies, although it acts as an active shareholder (Temasek, 2025[48]). It maintains significant stakes in several strategic Singapore‑based enterprises, many of which operate in key strategic sectors and are state‑owned.
Figure 4.4. . Temasek’s governance structure
Copy link to Figure 4.4. . Temasek’s governance structure
Source: Temasek, (2025[49]), Sustainability Governance – Oversight, Ownership, and Accountability, https://www.temasek.com.sg/en/sustainability/sustainability-governance#compensation-linked-to-sustainability-goals.
4.5.2. Portfolio-level risk management framework
Temasek assigns portfolio-level risk oversight to its Board and a set of Board committees, supported by senior management committees (Temasek, 2025[45]). The Board is assisted by a Risk and Sustainability Committee (RSC), which was founded in January 2022 and is composed of non-executive directors. The RSC reviews the portfolio risk appetite and profile, material environmental, social and governance issues, and the company’s risk and sustainability frameworks and policies, while co‑ordinating with the Audit Committee and the Leadership Development and Compensation Committee (Temasek, 2025[45]; 2024[50]; 2025[48]). The Audit Committee oversees internal controls and financial reporting and is supported by an Internal Audit function that reports functionally to the Audit Committee, which helps safeguard independence (Temasek, 2025[48]).
Risk appetite is articulated through an Organisational Risk Management Framework that includes Risk Return Appetite Statements (Table 4.1). These statements set tolerance levels for areas such as reputational risk, liquidity risk and the risk of sustained loss of overall portfolio value over prolonged periods (Temasek, 2025[51]). In addition, while Temasek is exempted under Singapore’s Companies Act from disclosing financial information publicly, it has been publishing its portfolio performance annually since 2004 (Temasek, 2025[48]). Such disclosure includes specific portfolio limits such as capping exposure to early-stage investments at up to 6% of portfolio value as part of its risk management approach (Temasek, 2025[48]).
Portfolio oversight links with frameworks of investee companies or entities through a defined engagement model. The day-to-day management and business decisions of portfolio companies are the responsibility of their respective boards and management (Temasek, 2025[48]; 2025[45]). Temasek does not direct those business decisions or operations and does not have access to non-public technical information or personal data held by portfolio companies. It engages as an active shareholder by voting, sharing expectations on governance and sustainability, promoting board effectiveness and convening best practice exchanges (Temasek, 2025[48]). This delineation reduces gaps and overlaps by preserving company-level responsibilities while allowing Temasek to consolidate and escalate issues that are essential to its portfolio.
In practice, the Organisational Risk Management Framework (Table 4.1) developed by Temasek identifies key risks and defines the organisation’s risk appetite. For each identified risk, Temasek establishes key risk indicators (KRIs) and subsidiary indicators, which are used to monitor those risks. These KRIs are informed by both legal and ESG policy frameworks and are integrated into operational processes. Temasek tracks adherence to these operational processes, evaluates historical performance, and assesses the risk environment through stress testing, including climate‑related scenarios.
Temasek defines the risk pillars in the Organisational Risk Management Framework (Table 4.1) as follows (Temasek, 2025[48]):
Investment risk is the risks inherent in underwriting and holding specific assets. It explicitly includes foreign exchange effects and environmental, social and governance considerations integrated into the investment process.
Liquidity and leverage risk is the risk that obligations cannot be met when due or that leverage constrains flexibility.
Portfolio value risk refers to sustained impacts on the intrinsic value of the portfolio through cycles. Temasek distinguishes sustained loss from short-term mark-to-market troughs, and acts by protecting or rebalancing positions rather than managing to short-term volatility.
Operational risk covers business continuity threats arising from safety, physical security, technology and other sources.
Cybersecurity risk refers to technology attacks and includes third-party and supply-chain cyber risk.
Legal, regulatory and tax risk comprises exposure to changing laws, enforcement and disclosure obligations across jurisdictions.
Macro and geopolitical risk stem from macroeconomic shifts and geopolitical tensions that affect openness of trade and investment and policy settings in key markets.
Table 4.1. Temasek’s portfolio risk management framework
Copy link to Table 4.1. Temasek’s portfolio risk management framework|
Organisational Risk Management Framework |
|
Risk Return Appetite Statements |
|
No tolerance for risks that could damage Temasek’s reputation and credibility |
|
Temasek rigorously identifies potential sources of reputational risk and how each type of reputation risk is to be managed |
|
Focus on performance over the long term |
|
|
|
Flexibility to take concentrated positions |
|
|
|
|
Maintain a resilient balance sheet |
|
Manage leverage and liquidity to ensure resilience and flexibility even in times of extreme stress |
|
Evaluate the potential for sustained loss of overall portfolio value over prolonged periods, and use different scenarios to test our resilience |
|
Risk Pillars |
|
Investment |
|
Includes Foreign Exchange Risk and Environmental, Social, and Governance Risk |
|
Liquidity & Leverage |
|
Portfolio Value |
|
Operational |
|
Cybersecurity |
|
Legal & Regulatory |
|
Tax |
|
Macro and Geopolitical |
Source: Based on Temasek, (2025[51]), Managing Risks, https://www.temasek.com.sg/en/about-us/managing-risks.
Temasek’s strategic approach to integrity and anti-corruption is built on a zero-tolerance stance reinforced by regular staff training and communications. Temasek refers to corruption in so far as it prohibits its employees from directly or indirectly offering, making, or accepting a bribe, or making a facilitation payment, for any reason (Temasek, 2025[52]). Integrity is defined as one of Temasek’s core values, expressed as “being honest to ourselves, our profession, our institution, and our stakeholders” (Temasek, 2022[53]). The Anti-Bribery and Anti-Corruption Statement confirms compliance with the Singapore Prevention of Corruption Act and applicable foreign laws, including the United States Foreign Corrupt Practices Act and the United Kingdom Bribery Act 2010; prohibits bribes and facilitation payments; establishes controls for gifts and entertainment; regulates charitable donations and sponsorships; prohibits political contributions on behalf of Temasek; extends expectations to third parties with the right to terminate engagements; and provides for investigation and whistleblowing channels for alleged misconduct (Temasek, 2025[52]).
Integrity expectations are embedded through the Temasek Code of Ethics and Conduct which sets day to day conduct requirements on anti-bribery and anti-corruption, gifts and entertainment, personal securities dealings, conflicts of interest, anti-harassment and whistleblowing. New joiners complete mandatory training on the Code and all staff undertake mandatory training on business conduct, including anti-bribery and anti-corruption, sanctions compliance and prevention of insider dealing. Reports made through the whistleblowing channel are handled with confidentiality and are protected by a non-retaliation policy. Breaches are escalated to an Ethics Committee and may carry employment and financial consequences (Temasek, 2025[54]).
Sustainability is framed as core to Temasek’s strategy, with a long-term ambition towards net zero, nature positive and inclusive growth. Portfolio-level analysis draws on data and analysis carried out as part of Temasek’s investment, risk or sustainability processes. It focusses on the environmental, social and governance factors that are financially material in each sector. Methodologically, Temasek applies an internal carbon price,5 a Climate Value Impact assessment6 using a third-party climate modelling tool and a proprietary Carbon Spread metric7 to trigger deeper analysis of transition plans, and to monitor asset level risks. Climate change is treated as a financially material concern that transcends industries, and engagement seeks to support investee companies in measuring and reporting emissions accurately and to establish relevant climate transition plans. Temasek has publicly stated portfolio targets to reduce net portfolio carbon emissions to half of 2010 levels by 2030 and to achieve net zero by 2050 (Temasek, 2024[55]; 2025[56]; 2025[57]).
From a risk perspective, ESG risks sit within the Investment Risk pillar of the Organisational Risk Management Framework, with an ESG framework integrated from pre‑investment due diligence through post-investment engagement. A dedicated ESG investment management function supports investment teams, analyses material issues, engages with portfolio companies and identifies emissions profiles (see Figure 4.5). Incentives are aligned with climate goals through a compensation framework and a long-term Wealth Added award linked to portfolio carbon reduction targets. Sector and market teams are assigned greenhouse gas budgets and use an in-house portfolio carbon analytics and reporting tool with dashboards (Temasek, 2025[48]; 2025[58]).
Figure 4.5. . Team structure of functional experts supporting Temasek’s sustainability strategy
Copy link to Figure 4.5. . Team structure of functional experts supporting Temasek’s sustainability strategy
Source: Based on Temasek (2025[49]), Sustainability Governance – Oversight, Ownership, and Accountability, https://www.temasek.com.sg/en/sustainability/sustainability-governance#compensation-linked-to-sustainability-goals.
4.5.3. Examples of portfolio risk and opportunity management
A first example of how Temasek’s portfolio risk management framework helps it mitigate risks and seize profitable opportunities concerns macro and geopolitical risks. Over the last decade, Temasek reported that it observed heightened geopolitical tensions alongside an evolving macroeconomic landscape, with renewed emphasis on national security, resilience, energy and commodity sufficiency, data ownership and “techno nationalism.” Considering its corporate priorities, Temasek noted it maintains dedicated teams in Beijing, Brussels, Singapore and Washington D.C. to monitor geopolitical risks, anticipate policy developments in key markets, and engage with authorities and thought leaders. Bespoke scenario analysis is used to evaluate the potential for sustained loss of portfolio value and to test resilience to short-term shocks. For instance, if a portfolio company relies on advanced semiconductor inputs, restrictions arising from national security considerations could constrain chip availability and therefore limit the business potential of that company, which would in turn inform Temasek’s decisions to reshape the portfolio through acquisitions or divestments. These practices illustrate how forward-looking geopolitical assessment and scenario testing guide portfolio stance and deployment pace (Temasek, 2025[54]).
A second example concerns the conversion of risk insights into opportunity. Within the investment risk pillar, Temasek identified that the energy transition, combined with intensified international competition, had driven a prolonged downturn in the offshore and marine industries since 2015 and had weakened the resilience of some portfolio companies active in that area. Through targeted engagement from Temasek, two companies with relevant engineering capabilities chose to merge and reposition their businesses towards growth areas, such as renewables. The merger delivered commercial success, with a total return of about 70% for shareholders, Temasek included, as of 2024 and contributed to a wider uplift in portfolio value of about USD 10 billion since Temasek began to integrate these risk factors into investment decisions and post-investment engagement. This example shows how a portfolio-level view of structural shifts, combined with a systematic approach to communication and key stakeholder engagement, can support value creation while managing transition risks (Temasek, 2025[54]).
These examples demonstrate some key benefits of implementing a systematic approach to portfolio risk and opportunity management frameworks. Corporate governance arrangements such as clear and structured communication and reporting channels ensure that specialist risk teams escalate material matters to senior leadership and the Board, while geopolitical monitoring and scenario analysis inform portfolio decisions. Engagement with portfolio companies connects entity level actions to portfolio-level objectives so that risks that are identified, assessed and monitored can also translate into strategic decisions and added value (Temasek, 2025[54]).
4.6. United Kingdom Government Investments (UKGI)
Copy link to 4.6. United Kingdom Government Investments (UKGI)UK Government Investments is the United Kingdom Government’s corporate finance and corporate governance specialist entity that acts as shareholder on behalf of the UK Government (UK Government Investments, 2025[59]). The entity holds a portfolio of government-owned and government-controlled bodies, while also supporting government corporate transactions and the structuring and management of contingent liabilities and financial transactions (UK Government Investments, 2025[59]).
UKGI operates as a company limited by shares, incorporated under the Companies Act 2006, and wholly owned by His Majesty’s Treasury, with governance and accountability set out through a framework document and the company’s board and committees (UK Government Investments; HM Treasury, 2024[60]). The governance framework sets out how HM Treasury and UKGI operate together, and although it does not provide legal powers, it provides interpretation of UKGI’s internal regulations and the applicable company law (UK Government Investments; HM Treasury, 2024[60]).
UKGI is classified as a central government organisation by the Office for National Statistics and HM Treasury and administratively classified by the Cabinet Office as a nondepartmental public body (UK Government Investments; HM Treasury, 2024[60]; UK Government Investments, 2025[59]). This hybrid form matters for portfolio risk management because it combines company style board governance with public sector accountability and “Managing Public Money” disciplines (UK Government Investments; HM Treasury, 2024[60]).
4.6.1. Ownership structure and portfolio overview
UKGI’s current operating model reflects its origin as it combines the functions of the former Shareholder Executive and UK Financial Investments into a single entity that works on corporate governance, corporate finance, government corporate transactions, and contingent liabilities financial instruments (UK Government Investments, 2025[59]; UK Government Investments; HM Treasury, 2024[60]; HM Treasury, 2024[61]).
UK Government Investments (UKGI) operates under a board-led governance model with support from specialised committees covering areas such as audit and risk, nominations, remuneration, transactions and contingent liabilities (UK Government Investments; HM Treasury, 2024[60]). The Board is responsible for setting strategic direction, overseeing organisational performance, ensuring effective risk management and stewardship of public resources, and maintaining accountability to HM Treasury as sole shareholder. Independent non-executive directors play a prominent role in providing challenge and oversight, including through the Audit and Risk Committee, which supports the Board in monitoring financial reporting, internal controls and key risks (UK Government Investments; HM Treasury, 2024[60]).
Governance arrangements seek to balance shareholder oversight with board autonomy. While HM Treasury appoints the Chair and independent non-executive directors and approves the appointment of the Chief Executive, the Board and its committees play a central role in succession planning, appointments and governance matters. The Chair serves as the principal channel of communication between the Board and HM Treasury, supporting accountability while preserving the Board’s responsibility for operational and strategic oversight (UK Government Investments; HM Treasury, 2024[60]).
UKGI performs the shareholder representative function for 25 organisations (See Note 8) on behalf of 9 government departments, with aggregate scale metrics for the portfolio including employment, gross income, and assets (UK Government Investments, 2025[59]). UKGI’s portfolio spans multiple sectors, including defence, energy, property and land, transport, manufacturing, communications, and finance (UK Government Investments, 2025[59]).8
Table 4.2. UKGI operating revenue composition and revenue weights, 2023‑2025
Copy link to Table 4.2. UKGI operating revenue composition and revenue weights, 2023‑2025|
2024-2025 |
2023-2024 |
|||
|---|---|---|---|---|
|
Revenue line in UKGI accounts |
Amount (GBP thousands) |
Share of total revenue |
Amount (GBP thousands) |
Share of total revenue |
|
Staff costs recovery |
534 |
7.2% |
229 |
3.4% |
|
Revenue from other government departments |
5 994 |
81.0% |
5 175 |
76.3% |
|
Recharges and recoveries |
870 |
11.8% |
1 380 |
20.3% |
|
Total revenue |
7 398 |
100% |
6 784 |
100% |
Note: Revenue from other government departments includes GBP 5 542k relating to fees charged for the provision of shareholder services. Staff costs recovery represents income from the secondment of UKGI staff to other government departments and public bodies. Recharges and recoveries are the reimbursement of professional advice related costs incurred by UKGI on behalf of UKGI’s partner bodies, and fees charged for UKGI staff acting as Non-Executive Directors.
Source: UKGI, (2025[59]), Annual Report and Accounts 2024 to 2025, https://www.gov.uk/government/publications/uk-government-investments-annual-report-and-accounts-2024-25/uk-government-investments-annual-report-and-accounts-2024-25.
UKGI’s own consolidated financial statements show that it is primarily a service and advisory entity financed through grant in aid from HM Treasury and fees and recoveries from partner departments and public bodies, rather than a holding company that consolidates portfolio entity income and balance sheets. In 2024 and 2025, UKGI reported operating expenditure of GBP 26.722 million, operating revenue of GBP 7.398 million, and net operating expenditure of GBP 19.324 million, with grant in aid of GBP 18.6 million. (UK Government Investments, 2025[59]).
4.6.2. Portfolio level risk management framework
UK Government Investments (UKGI) positions its risk management arrangements within HM Treasury’s Orange Book, requiring risks to be identified, reported, reviewed and mitigated in line with UKGI’s risk appetite (Government Finance Function and His Majesty’s Treasury, 2025[62]). This government wide standard harmonises the use of a shared risk language as well as baseline expectations across departments, projects and entities within the scope of UKGI. This harmonisation helps improve interoperability and comparability of risk signals across the portfolio (UK Government Investments, 2025[59]).
Within this framework, UKGI treats risk as inherent to its role as the entity exercising ownership on behalf of ministers and departments and differentiates risk appetite across different categories of work (UK Government Investments, 2025[59]). For portfolio ownership, UKGI’s risk appetite statement helps clarify which risks UKGI must accept to deliver policy objectives, particularly those associated with strategic delivery, and which risks it must actively constrain, notably exposures linked to controls, compliance and information security.
UKGI reports three risk appetite categories with different accepted ranges:
strategic delivery of its four objectives
people risk relating to deployment and well-being
operational risk relating to breaches of controls, including information technology, data, legal and compliance.
The risk appetite for these three categories is asymmetric, with higher tolerance for strategic delivery risk coupled with low tolerance for operational and data security risks (UK Government Investments, 2025[59]).
UKGI has a portfolio risk governance model that combines board and committee oversight, and executive control, which relies on structured information and reporting channels that flow from delivery teams to senior decision-making bodies. Risks are monitored through systematic review, including risk register reviews, portfolio reviews, and discussion at the Executive Committee and the Audit and Risk Committee. This approach functions as a portfolio-level risk management framework insofar as it aggregates entity-level and project-level risk signals into board oversight tools such as risk heatmaps, supporting escalation and prioritisation across assets and mandates (UK Government Investments, 2025[59]). UKGI’s board information architecture reinforces this aggregation structure. The board receives a dashboard on each current entity within the portfolio and a risk heatmap covering delivery and reputational risks for projects and portfolio entities, which standardises how risks are reported to central oversight (UK Government Investments, 2025[59]).
Assurance arrangements are explicitly structured through the three lines of defence model (The Institute of Internal Auditors, 2020[63]):
First line controls are embedded in project and entity work, including risk reporting every two months, codes of conduct and compliance requirements, and monitoring of internal operational and strategic risks such as staffing, finance, information technology and data management, as well as cross -government relationship risks, with regular reporting to HM Treasury (UK Government Investments, 2025[59]).
Second line activities include senior-led deep dives and project and portfolio reviews to identify issues and agree mitigation, with regular updates to the Executive Committee and board and scrutiny of the adequacy of mitigation measures; UKGI also refers to specialist governance arrangements that provide focussed assurance over areas such as contingent liabilities and asset realisation (UK Government Investments, 2025[59]).
Third line assurance is provided by the government Internal Audit Agency through internal audit work that offers independent insight into UKGI’s internal risk management processes (UK Government Investments, 2025[59]).
Committee roles further extend oversight across risk types in a way that aligns with a portfolio-level management of multiple risk classes concurrently. The Audit and Risk Committee supports the board on risk, internal control and governance; the Transactions Committee scrutinises major corporate transactions and shareholding related actions; and the Financial Instruments and Transactions Advisory Group Committee provides focussed governance of UKGI’s financial instruments and transactions advisory work, alongside Remuneration and Nominations Committee (UK Government Investments, 2025[59]).
Figure 4.6. Risk appetite statement of UKGI
Copy link to Figure 4.6. Risk appetite statement of UKGI
Source: Based on UKGI, (2025[59]), Annual Report and Accounts 2024 to 2025, https://www.gov.uk/government/publications/uk-government-investments-annual-report-and-accounts-2024-25/uk-government-investments-annual-report-and-accounts-2024-25.
UKGI’s portfolio model also incorporates delegated shareholder representation through its staff and shareholder non-executive directors, who sit on Boards of companies within UKGI’s portfolio and serve as channels of information to the central structure (UK Government Investments, 2025[59]). UKGI’s risk oversight is exercised primarily through corporate governance measures, including mandates, expectations, decisions, and information flows, rather than through consolidated balance sheet risk management of underlying portfolio entities (UK Government Investments, 2025[59]). Consistent with this, UKGI’s financial risk management focusses on operational exposures such as receivables from related parties, payables and cash management. UKGI reports total assets of GBP 2.407 million on 31 March 2025 and a general fund balance of negative GBP 3.094 million, financed through grant in aid and revenues (UK Government Investments, 2025[59]).
4.6.3. Examples of portfolio risk and opportunity management
The two cases of banks NatWest and Lloyds below show how portfolio-level risk events can be managed by a central ownership function with an adequate framework to inform key ownership decisions on assets. This can be achieved through a framework that sets risk appetite, allocates decision rights, defines escalation thresholds, and ensures consistent oversight across assets over time, particularly when the risks are shared across government and politically sensitive.
In the NatWest case, UKGI reported that HM Treasury’s shareholding fell from around 30% on 1 April 2024 to under 4% by 31 March 2025 through sales executed under the existing trading plan and two directed buybacks, with full disposal completed on 30 May 2025 after the financial year end (His Majesty’s Treasury, 2025[64]). UKGI characterised the disposal as the largest post-2008 financial crisis monetisation exercise globally, which underscores the portfolio relevance of designing sell down pathways that are credible under political scrutiny and robust under volatile market conditions (UK Government Investments, 2025[59]).
The documented risk profile for such disposals included market impact risk, price volatility and timing risk, reputational and political risk around perceived value for money, and compliance risk linked to market functioning. In response, HM Treasury explicitly emphasised market value sales and stated it halted a planned retail sale because it would have imposed additional costs on taxpayers and required discounted pricing, thereby favouring execution channels that better preserved value and market integrity (His Majesty’s Treasury, 2025[64]). NatWest’s published ownership statistics describe a pre‑arranged trading plan launched in 2021 that enabled measured sell down with an explicit cap of up to 15% of aggregate trading volume, complemented by directed and on market buybacks and accelerated bookbuild disposals, which directly reduce disruption by spreading sales over time (NatWest Group, 2025[65]; 2026[66]).
In the Lloyds case, government ownership originated from financial crisis-era support, which resulted in a 43% shareholding. Overtime, the disposal plan combined accelerated sales to key investors with trading plans that gradually sold shares into the market (His Majesty’s Treasury, 2017[67]). HM Treasury reports that the final sale was executed under a trading plan announced in October 2016 and that the government ceased to be a shareholder by 17 May 2017 (His Majesty’s Treasury, 2017[67]). The National Audit Office frames the programme as a sequence of transactions requiring disciplined preparation under uncertainty, and it highlighted governance discipline through UKFI’s role (National Audit Office, 2018[68]).9 The National Audit Office also highlighted the need for HM Treasury approval for disposals, alongside other execution safeguards such as the use of multiple valuation methodologies, fair value ranges and explicit parameters for brokers, including floor prices, as key risk management measures (National Audit Office, 2018[68]).
In both NatWest and Lloyds, the risk control was not a policy statement; it was the implementation design. These cases show that portfolio risk frameworks are not limited to risk registers and heatmaps. Effective sell down programmes depends on clear decision rights, explicit parameter setting that can be monitored and evaluated ex post, and clear decision-making channels that manage risk impact while protecting value for citizens, as ultimate shareholders. This logic aligns with UKGI’s own governance and reporting architecture, including board level dashboards, risk heatmaps, and committee scrutiny of transactions and financial instruments work, which turn risk appetite into controlled operation (UK Government Investments, 2025[59]).
References
[5] Canada Development Investment Corporation (2026), What We Do - CDEV, https://cdev.gc.ca/what-we-do/ (accessed on 27 February 2026).
[7] Canada Development Investment Corporation (2025), “Federal Indigenous Loan Guarantee Program Confirms Issuance of its First Loan Guarantee”, https://cdev.gc.ca/federal-indigenous-loan-guarantee-program-confirms-issuance-of-its-first-loan-guarantee/ (accessed on 27 February 2026).
[1] Canada Development Investment Corporation (2024), 2024 Annual Report: Delivering Value to Canada, CDEV, https://cdev.gc.ca/wp-content/uploads/2026/01/CDEV-2024-Annual-Report-EN-FINAL-2025.05.01.pdf (accessed on 27 February 2026).
[3] Canada Enterprise Emergency Funding Corporation (2025), Annual Report 2024, https://ceefc-cfuec.ca/wp-content/uploads/2025/06/CEEFC-Annual-Report-2024-FINAL-EN-2025.03.31.pdf (accessed on 27 February 2026).
[4] Canada Enterprise Emergency Funding Corporation (2025), “Large Enterprise Tariff Loan facility overview”, https://ceefc-cfuec.ca/letl-overview/ (accessed on 27 February 2026).
[35] Congreso de la República del Peru (1999), Ley N.° 27170, https://www.gob.pe/institucion/congreso-de-la-republica/normas-legales/3958539-27170 (accessed on 24 February 2026).
[28] European Public Prosecutor’s Office (2023), Greece: EPPO charges 23 suspects with crimes involving railway signalling systems, https://www.eppo.europa.eu/en/media/news/greece-eppo-charges-23-suspects-crimes-involving-railway-signalling-systems (accessed on 6 October 2025).
[36] FONAFE (2026), Estructura de Fonafe, https://www.fonafe.gob.pe/pw_content/miscelanea/1/Doc/Estructura%20de%20Fonafe..jpeg (accessed on 27 May 2026).
[39] FONAFE (2025), Corporate Guideline: “Comprehensive Risk Management Guideline”, https://www.fonafe.gob.pe/marconormativo/sistemadecontrolinterno#Documento-56 (accessed on 25 February 2026).
[38] FONAFE (2025), Corporate Manual: “Guide to Comprehensive Risk Management”, https://www.fonafe.gob.pe/marconormativo/sistemadecontrolinterno#Documento-57 (accessed on 25 February 2026).
[40] FONAFE (2025), Informe “Rendición de cuentas de titulares por periodo anual” FONAFE, https://www.mef.gob.pe/contenidos/acerc_mins/anexos/1_3_IRC_ANUAL_2024_FONAFE.pdf (accessed on 25 February 2026).
[42] FONAFE (2025), Informe transferencia de gestión de empresa del estado y otros organismos sujetos a control, FONAFE, Lima, https://www.mef.gob.pe/contenidos/acerc_mins/doc_gestion/ITG_gestion_JSalardi/8_1_ITG_FONAFE.pdf (accessed on 26 February 2026).
[41] FONAFE (2018), Corporate Guideline: “Guideline on transparency in the management of companies under the scope of FONAFE”, https://www.fonafe.gob.pe/marconormativo/buenaspracticas#Documento-20 (accessed on 25 February 2026).
[27] Gatopoulos, D. and L. Pitarakis (2025), Greek rail disaster report cites errors and major systemic failures | AP News, https://apnews.com/article/greece-rail-disaster-investigation-europe-tempe-36d3960f42528b1d12f998dcaa3e5924 (accessed on 6 October 2025).
[32] Government Companies Authority (2026), The Government Companies Authority - About, https://www.gov.il/en/departments/units/department_gca (accessed on 20 April 2026).
[31] Government Companies Authority (2024), Report on Government Companies for 2024, https://www.gov.il/BlobFolder/dynamiccollectorresultitem/gca-companies-report-2024/he/gca_reports_gca-companies-report-2024-accessible-version.pdf (accessed on 20 April 2026).
[30] Government Companies Authority (2023), Report on Government Companies for 2023, https://www.gov.il/BlobFolder/dynamiccollectorresultitem/gca_companies_report_2023/he/gca_reports_gca-companies-report-2023-accessible-version.pdf (accessed on 20 April 2026).
[62] Government Finance Function and His Majesty’s Treasury (2025), The Orange Book Management of Risk – Principles and Concepts, https://assets.publishing.service.gov.uk/media/6453acadc33b460012f5e6b8/HMT_Orange_Book_May_2023.pdf (accessed on 4 March 2026).
[6] Government of Canada (2025), Government of Canada Celebrates Launch of the $5-Billion Indigenous Loan Guarantee Program - Canada.ca, https://www.canada.ca/en/natural-resources-canada/news/2025/02/government-of-canada-celebrates-launch-of-the-5-billion-indigenous-loan-guarantee-program.html (accessed on 2 March 2026).
[11] Growthfund (2025), Board of Directors, https://growthfund.gr/en/corporate-governance/board-of-directors/ (accessed on 6 October 2025).
[13] Growthfund (2025), Committees, https://growthfund.gr/en/corporate-governance/committees/ (accessed on 3 October 2025).
[10] Growthfund (2025), Corporate Governance Council, https://growthfund.gr/en/corporate-governance/corporate-governance-council/ (accessed on 6 October 2025).
[8] Growthfund (2025), Growthfund at a Glance, https://growthfund.gr/en/about-us/growthfund-at-a-glance/ (accessed on 3 October 2025).
[17] Growthfund (2025), Growthfund at the 44th meeting of the Working Party on State Ownership and Privatisation Practices (WPSOPP).
[9] Growthfund (2025), Message By The Sole Investor, https://growthfund.gr/en/about-us/message-by-the-sole-shareholder/ (accessed on 3 October 2025).
[12] Growthfund (2025), Organizational Chart, https://growthfund.gr/en/about-us/organizational-chart/ (accessed on 6 October 2025).
[24] Growthfund (2025), Our Subsidiaries & Participations Portfolio, https://growthfund.gr/en/about-us/our-portfolio/ (accessed on 6 October 2025).
[18] Growthfund (2025), Risk Management, https://growthfund.gr/en/corporate-governance/risk-management/ (accessed on 3 October 2025).
[16] Growthfund (2024), Growthfund Risk Management Policy, https://growthfund.gr/wp-content/uploads/2024/06/anatheorimeni-politiki-diaxeirisis-kindynon_16.4.2024_en.pdf (accessed on 3 October 2025).
[15] Growthfund (2023), Risk Management Department Operations Regulation, https://growthfund.gr/wp-content/uploads/2024/06/kanonismos-leitourgias-ddk_250823_en.pdf (accessed on 6 October 2025).
[23] Growthfund (2022), Environmental Social & Governance (ESG) Policy, https://growthfund.gr/wp-content/uploads/2023/08/D13_ESG-Policy_en.pdf (accessed on 3 October 2025).
[21] Growthfund (2022), “Whistleblowing policy”, https://growthfund.gr/wp-content/uploads/2023/09/Whistleblowing-Policy.pdf (accessed on 3 October 2025).
[22] Growthfund (2020), Third-party due diligence policy, https://growthfund.gr/wp-content/uploads/2024/12/%CE%A0%CE%9F%CE%9B%CE%99%CE%A4%CE%99%CE%9A%CE%97-%CE%94%CE%95%CE%9F%CE%A5%CE%A3%CE%91%CE%A3-%CE%95%CE%A0%CE%99%CE%9C%CE%95%CE%9B%CE%95%CE%99%CE%91%CE%A3-%CE%A4%CE%A1%CE%99%CE%A4%CE%A9%CE%9D-%CE%9C%CE%95%CE%A1%CE%A9%CE%9D_EN.pdf (accessed on 3 October 2025).
[20] Growthfund (2019), Anti-corruption and bribery policy, https://growthfund.gr/wp-content/uploads/2023/09/Anti-Corruption-and-Bribery-Policy.pdf (accessed on 3 October 2025).
[19] Growthfund (2018), Code of ethics and professional conduct, https://growthfund.gr/wp-content/uploads/2023/09/Code-of-Ethics-and-Professional-Conduct.pdf (accessed on 3 October 2025).
[64] His Majesty’s Treasury (2025), “Government completes exit from NatWest”, https://www.gov.uk/government/news/government-completes-exit-from-natwest--2.
[67] His Majesty’s Treasury (2017), “Government shareholding in Lloyds Banking Group”, https://www.gov.uk/government/news/government-shareholding-in-lloyds-banking-group.
[61] HM Treasury (2024), UK Government Investments Public Body Review 2024, https://assets.publishing.service.gov.uk/media/65a67991640602000d3cb738/UK_Government_Investments_Public_Body_Review_2024.pdf.
[25] Lewis, A. and Reuters (2021), Diggers and dredgers struggle to free ship blocking Suez Canal, https://www.reuters.com/world/tugs-dredgers-continuing-efforts-free-ship-stranded-suez-canal-authority-2021-03-28/ (accessed on 6 October 2025).
[68] National Audit Office (2018), The return of Lloyds Banking Group to private ownership, https://www.nao.org.uk/wp-content/uploads/2018/06/The-return-of-Lloyds-Banking-Group-to-private-ownership.pdf.
[66] NatWest Group (2026), “Equity ownership statistics”, https://investors.natwestgroup.com/share-data/equity-ownership-statistics (accessed on 4 March 2026).
[65] NatWest Group (2025), “NatWest Group returns to full private ownership”, https://www.natwestgroup.com/news-and-insights/latest-stories/our-updates/2025/may/natwest-group-returns-to-full-private-ownership.html.
[37] OECD (2025), Interview held with FONAFE for the purpose of the OECD report “Managing Risk Across State-Owned Enterprises”.
[33] OECD (2011), Corporate Governance in Israel, OECD Publishing, Paris, https://doi.org/10.1787/9789264097698-en.
[34] Presidencia de la República del Peru (2024), Decreto Legislativo Nº 1693.
[29] Reuters (2025), Greece to install train control systems by September in reform after deadly 2023 crash | Reuters, https://www.reuters.com/world/europe/greece-install-train-control-systems-by-september-reform-after-deadly-2023-crash-2025-04-28/ (accessed on 6 October 2025).
[56] Temasek (2025), Business Resilience, https://www.temasek.com.sg/en/sustainability/sustainability-in-our-operations/business-resilience (accessed on 20 August 2025).
[45] Temasek (2025), Corporate Governance, https://www.temasek.com.sg/en/about-us/corporate-governance (accessed on 13 August 2025).
[57] Temasek (2025), Embedding ESG as Part of Our Investment Process, https://www.temasek.com.sg/en/sustainability/sustainability-in-our-investments/embedding-esg-as-part-of-our-investment-process (accessed on 19 August 2025).
[44] Temasek (2025), History of Temasek, https://www.temasek.com.sg/en/about-us/history-of-temasek (accessed on 13 August 2025).
[47] Temasek (2025), Investment Approach, https://www.temasek.com.sg/en/our-investments/investment-approach (accessed on 13 August 2025).
[51] Temasek (2025), Managing Risks, https://www.temasek.com.sg/en/about-us/managing-risks (accessed on 14 August 2025).
[46] Temasek (2025), Our Portfolio, https://www.temasek.com.sg/en/our-investments/our-portfolio (accessed on 13 August 2025).
[49] Temasek (2025), Sustainability Governance - Oversight, Ownership, and Accountability, https://www.temasek.com.sg/en/sustainability/sustainability-governance#compensation-linked-to-sustainability-goals (accessed on 19 August 2025).
[58] Temasek (2025), Sustainability Report 2025, https://www.temasek.com.sg/content/dam/temasek-corporate/sustainability/2025/Temasek-Sustainability-Report-2025.pdf (accessed on 20 August 2025).
[52] Temasek (2025), Temasek Anti-Bribery and Anti-Corruption (ABAC) Statement, https://www.temasek.com.sg/content/dam/temasek-corporate/about-us/managing-risk/Temasek%20Anti-Bribery%20and%20Anti-Corruption%20(ABAC)%20Statement.pdf (accessed on 20 August 2025).
[43] Temasek (2025), Temasek at a Glance, https://www.temasek.com.sg/en/about-us/temasek-at-a-glance (accessed on 13 August 2025).
[54] Temasek (2025), Temasek at the 44th meeting of the Working Party on State Ownership and Privatisation Practices (WPSOPP).
[48] Temasek (2025), Temasek Review 2025, https://www.temasekreview.com.sg/ (accessed on 13 August 2025).
[55] Temasek (2024), Sustainability Report 2024, https://www.temasek.com.sg/content/dam/temasek-corporate/sustainability/temasek-sustainability-report-2024.pdf (accessed on 20 August 2025).
[50] Temasek (2024), Temasek Review 2024, https://tr24.temasekreview.com.sg/ (accessed on 14 August 2025).
[53] Temasek (2022), Temasek Review 2022 Highlights, https://www.temasek.com.sg/content/dam/temasek-corporate/our-financials/investor-library/annual-review/en-tr-thumbnail-and-pdf/Temasek-Review-2022-Highlights1.pdf (accessed on 19 August 2025).
[14] The Institute of Internal Auditors (2024), “The IIA’s Three Lines Model: An update of the Three Lines of Defense”, The Institute of Internal Auditors, https://www.theiia.org/en/content/position-papers/2020/the-iias-three-lines-model-an-update-of-the-three-lines-of-defense/ (accessed on 26 May 2025).
[63] The Institute of Internal Auditors (2020), The IIA’s Three Lines Model: An Update of the Three Lines of Defense, https://www.theiia.org/globalassets/documents/resources/the-iias-three-lines-model-an-update-of-the-three-lines-of-defense-july-2020/three-lines-model-updated-english.pdf.
[2] Treasury Board of Canada Secretariat (2019), Agent status and Crown corporations, https://www.canada.ca/en/treasury-board-secretariat/services/guidance-crown-corporations/agent-status-crown-corporations.html (accessed on 27 February 2026).
[59] UK Government Investments (2025), Annual Report and Accounts 2024 to 2025, https://www.gov.uk/government/publications/uk-government-investments-annual-report-and-accounts-2024-25/uk-government-investments-annual-report-and-accounts-2024-25.
[60] UK Government Investments; HM Treasury (2024), UK Government Investments Framework Document, https://assets.publishing.service.gov.uk/media/66f3e2c1c71e42688b65eb95/UKGI_Framework_Document_2024_updated_on_21.08.24.pdf.
[26] Uras, U. and U. Siddiqui (2021), Stranded ship in Suez Canal refloated: Live news | Shipping News | Al Jazeera, https://www.aljazeera.com/news/2021/3/29/ever-given-turned-80-percent-in-right-direction-live-news (accessed on 6 October 2025).
Notes
Copy link to Notes← 1. CDEV’s main companies include:
● Canada Eldor Inc.: manages de remaining obligations of the corporation relating to disposal of low-level nuclear wastes and decommissioning of a former mine site;
● Canada Enterprise Emergency Funding Corporation: manages the government’s Large Employer Emergency Financing Facility;
● Canada Growth Fund Inc.: oversees the Canada Growth Fund;
● Canada Hibernia Holding Corporation: manages the government’s interest in Hibernia;
● Canada Indigenous Loan Guarantee Corporation: delivers and manages the federal indigenous Loan Guarantee Program;
● Canada Innovation Corporation: oversees the Canada Innovation Corporation;
● Canada TMP Finance Ltd.: aquires and provides financing to Trans Mountain Corporation, which owns and manages the entities that operate the Trans Mountain Pipeline System;
● 16342451 Canada Inc.: establishes and oversees the government’s CAD 2.14 billion loan for the Telesat Lightspeed project.
← 2. As Growthfund is under restructuring following the completion of the absorption of former Hellenic Financial Stability Fund (HFSF) and former Hellenic Republic Asset Development Fund (HRADF), the Group Risk Management Division is in progress of updating the current Risk Management Framework to be consistent with its post-absorption broadened responsibilities.
← 3. Some of the main companies include (Government Companies Authority, 2024[31]):
● Israel Electric Corporation Ltd
● Israel Natural Gas Lines Ltd
● Energy Infrastructures Ltd
● Mekorot Water Company Ltd
● Netivei Israel, the National Transportation Infrastructure Company Ltd
● Israel Railways Ltd
● NTA, Urban Mass Transit Lines Ltd
● Ayalon Routes Company Ltd
● Israel Ports Company, Development and Properties Ltd
● Ashdod Port Company Ltd
● Amidar, the National Housing Company in Israel Ltd
● Environmental Services Company Ltd
● Israel Aerospace Industries Ltd
● Rafael, Advanced Combat Systems Ltd
● The Society for Community Centers, Community Centers in Israel Ltd (HCCI).
← 4. Although Petroperú is legally excluded from FONAFE’s ownership perimeter, FONAFE can still receive time‑bound monitoring tasks (“encargos”) from the State related to specific SOEs outside its equity scope (e.g. 2024 monitoring around Petroperú’s restructuring actions) (Presidencia de la República del Peru, 2024[34]).
← 5. Temasek set an initial internal carbon price (ICP) of USD 42 per tCO2e in 2021 to embed the cost of carbon in its investment and operating decisions, and to further align its portfolio and business to its net zero target. This was subsequently increased to USD 50 per tCO2e in 2022 and to USD 65 per tCO2e in 2024, with a view for the carbon price to reach USD 100 per tCO2e by 2030. A review of the ICP is performed every two years that takes into account the carbon price projections by international bodies.
← 6. Temasek defines Climate Value Impact assessment as an estimate of the potential impact on the equity value of an individual asset under specified climate scenarios, using a third-party climate modelling tool. The assessment considers transition and physical factors such as company emissions, price elasticity, cost pass through and Scope 3 emissions, as well as exposure to acute and chronic climate hazards and the likely effects on assets, operations and critical supply chains, taking into account existing or planned mitigation efforts.
← 7. Temasek describes Proprietary Carbon Spread metric as a proprietary metric that reflects its internal carbon price modelled as a spread added to the investment’s risk adjusted cost of capital.
← 8. The companies in UKGI’s portfolio include:
● Sheffield Forgemasters (Defence)
● DE&S (Defence Equipment & Support)
● AWE Nuclear Security Technologies (Defence)
● OCTRIC (Defence)
● Nuclear Decommissioning Authority (Energy and Nuclear)
● UK National Nuclear Laboratory (Energy and Nuclear)
● Sizewell C (Energy and Nuclear)
● URENCO (Energy and Nuclear)
● National Energy System Operator (Energy and Nuclear)
● HM Land Registry (Property and Land)
● Government Property Agency (Property and Land)
● Ordnance Survey (Property and Land)
● National Highways (Transport Infrastructure)
● Network Rail (Transport Infrastructure)
● The Royal Mint (Commercial Enterprises)
● BBC Commercials (Commercial Enterprises)
● Channel 4 (Commercial Enterprises)
● Post Office (Commercial Enterprises)
● Eutelsat Group (Commercial Enterprises)
● National Wealth Fund (Financial and Investment Institutions)
● British Business Bank (Financial and Investment Institutions)
● Reclaim Fund Ltd (Financial and Investment Institutions)
● UK Export Finance (Financial and Investment Institutions)
● UK Asset Resolution (Financial and Investment Institutions)
● BIS Co (Financial and Investment Institutions)
← 9. UKFI became a UKGI subsidiary in 2016 and was fully merged in 2018.