This annex summarises the main international standards and best practices that cover aspects of risk management relevant to this study.
Managing Risk Across State‑Owned Enterprises
Annex A. Risk management standards
Copy link to Annex A. Risk management standardsOECD Guidelines for Multinational Enterprises
Copy link to OECD Guidelines for Multinational EnterprisesThe 2023 OECD Guidelines for Multinational Enterprises (MNE Guidelines) provide recommendations aimed at promoting sustainable and ethical conduct in key areas, including anti-corruption and environmental management (OECD, 2023[1]). Central to the MNE Guidelines is the concept of risk-based due diligence, structured as a six-step process: embedding responsible business conduct into organisational operations; identifying and assessing actual or potential adverse impacts; ceasing, preventing, or mitigating those impacts; tracking performance; transparently communicating the measures taken; and enabling appropriate remediation. The MNE Guidelines strongly advocate for due diligence to be embedded across all organisational levels and the wider value chain, with active stakeholder engagement and transparent disclosure of practices and outcomes (OECD, 2023[1]).
In the context of state-level portfolio risk management frameworks, the MNE Guidelines offer a standardised terminology and a practical methodological approach for evaluating and managing responsible business conduct across SOEs. By adopting this six-step due-diligence process at the portfolio level, governments can ensure consistency in assessing and monitoring ethical, environmental, and governance risks, while also benchmarking SOE performance and fostering continual improvement.
Financial Action Task Force (FATF) international standards on combating money laundering and the financing of terrorism and proliferation
Copy link to Financial Action Task Force (FATF) international standards on combating money laundering and the financing of terrorism and proliferationThe Financial Action Task Force (FATF) issues the international standards on combating money laundering and the financing of terrorism & proliferation, and a cornerstone of its guidance is the “risk-based approach.” FATF Recommendation 1 requires countries and institutions to identify and assess their relevant risks and then apply mitigation measures commensurate with the level of risk (FATF, 2025[2]). In FATF’s words, “Countries should identify, assess, and understand the money laundering and terrorist financing risks… and should take action… aimed at ensuring the risks are mitigated effectively. Based on that assessment, countries should apply a risk-based approach (RBA) to ensure that measures… are proportionate to the risks identified.” (FATF, 2025[2]). At the state’s portfolio level, this risk-based approach allows resources to be focused on higher-risk areas while simplifying measures for lower risks, thereby promoting efficient and effective risk management in the domain of financial crime compliance. FATF standards underscore that risk management is not one-size-fits-all; instead, controls and oversight should be scaled according to risk, and reviewed as risks evolve (FATF, 2025[2]). Such flexibility creates great opportunity, as states with enhanced anti-money laundering and finance of terrorism frameworks are able to project trust and thus have better access to the international market. Moreover, FATF recommendations are key standards for those state portfolios with SOEs operating in regulated sectors such as finance.
ISO 31000 (Risk management – guidelines)
Copy link to ISO 31000 (Risk management – guidelines)The International Organization for Standardization’s ISO 31000:2018 is a globally recognised standard for risk management. ISO 31000 provides a set of principles, a framework, and a process for managing risk that can be applied by any organisation, regardless of size, sector, or type of risk (ISO, 2018[3]).1 The standard defines risk as the “effect of uncertainty on objectives,” noting that this effect can be positive or negative (thus risk management addresses both opportunities and threats) (ISO, 2018[3]). The fundamental purpose of risk management, as stated in ISO 31000, is “the creation and protection of value,” improving organisational performance, encouraging innovation, and supporting the achievement of objectives (ISO, 2018[3]).
ISO 31000 lays out eight principles of effective risk management, which guide the characteristics of sound risk practices (ISO, 2018[3]): (a) Integrated – risk management is an integral part of all organizational activities; (b) Structured and comprehensive – a structured approach contributes to consistent and comparable results; (c) Customised – the framework is tailored to the organisation’s context and objectives; (d) Inclusive – appropriate involvement of stakeholders improves awareness and informs decision-making; (e) Dynamic – risk management is responsive to changes, with risks emerging, changing or disappearing as internal and external contexts evolve; (f) Best available information – decisions are based on the best available information, while acknowledging limitations and uncertainties; (g) Human and cultural factors – human behaviour and culture significantly influence all aspects of risk management (ISO, 2018[3]); and (h) Continual improvement – risk management is continually improved through learning and experience (ISO, 2018[3]). These principles underpin a risk management framework and process that together ensure risk management is effective and aligned with the organisation’s or government’s governance and strategy (ISO, 2018[3]).
ISO 37301 specifies requirements and offers guidance for establishing, implementing, maintaining and continually improving a compliance management system (CMS) across any organisation, irrespective of size or sector (ISO, 2021[4]). It adopts the high-level structure common to ISO management system standards, ensuring its integration with other systems such as quality (ISO 9001) or environmental management (ISO 14004). Central to ISO 37301 is the concept of risk-based due diligence, which states that organisations must identify relevant compliance obligations, from laws and regulations to voluntary codes, and assess the risks of non-compliance, including those related to corruption, integrity breaches and sustainability (2024 Amendment 1).
Leadership commitment is also at the core of ISO 37301, which requires the governing body and top management (or state ownership entity) to take ownership of the CMS, define a compliance policy, and allocate adequate resources. Roles and responsibilities, including the compliance function, management and all staff, are clearly delineated, with senior management expected to exemplify ethical conduct and foster a compliance culture. Performance evaluation through monitoring, internal audit and management review ensures that the CMS remains dynamic, responsive to evolving risks, and continuously improves.
ISO 37001 (Anti-bribery management systems)
Copy link to ISO 37001 (Anti-bribery management systems)ISO 37001 prescribes requirements and guidance for an anti-bribery management system (ABMS), enabling organisations to prevent, detect and respond to bribery in any form. Applicable to both private and public entities, this ISO addresses bribery by the organisation, its personnel and its business associates, as well as bribery of the organisation itself. The standard enshrines the “three lines” of anti-bribery, including operational management (first line), specialised compliance functions (second line), and independent assurance (third line), thus mirroring the IIA’s Three Lines Model.
As in all ISOs, leadership and governance are pivotal. Boards and top executives must establish an anti-bribery policy, exhibit “tone from the top”, and ensure that an anti-bribery function has the autonomy and resources to oversee risk assessments, due diligence, financial and non-financial controls, and incident investigations. Risk assessments extend to third parties and emerging technologies (e.g. AI), reflecting the standard’s emphasis on adaptability to new threats.
When applied at state level portfolio scale, the ABMS framework ensures consistent and systematic anti-bribery policies, risk assessments and oversight mechanisms across all government entities and SOEs, thereby reinforcing integrity, reducing reputational exposures, and seeking to enhance public trust in state ownership.
ISO 14001 and 14004 (Environmental management systems guidelines)
Copy link to <strong><strong>ISO 14001 and 14004 (Environmental </strong><strong>m</strong><strong>anagement</strong> <strong>s</strong><strong>ystems </strong><strong>g</strong><strong>uidelines)</strong></strong>ISO 14001 sets the requirements for an environmental management system that an organisation can use to enhance environmental performance, while ISO 14004 provides guidance on establishing, implementing, maintaining and improving an EMS. For example, ISO 14004 offers interpretative guidance illustrating how to integrate EMS elements into core processes, apply a life-cycle perspective, and coordinate with other management systems such as quality and occupational health and safety (ISO, 2016[5]).
Key EMS stages mirror the ISO high-level structure, thus focusing on:
context and leadership (defining environmental policy, roles and responsibilities)
planning (identifying environmental aspects and compliance obligations)
support and operation (resources, competence, documented information, operational controls)
performance evaluation (monitoring, measurement, audit)
improvement (corrective actions, continual improvement).
These standards emphasise a cycle of “Plan-Do-Check-Act” and a risk-based way of thinking and identifying environmental risks and opportunities to guide decision-making and allocation of resources. For state portfolio risk management, ISO 14004’s EMS guidance can be scaled to oversee environmental risks and opportunities across multiple SOEs, thus guiding the investments of the state to meet their sustainability objectives. A portfolio EMS framework ensures that individual entities’ environmental objectives and controls are harmonised with national sustainability goals, enabling a cohesive approach to environmental governance, transparent reporting on collective performance, and strategic resource deployment to address portfolio-level environmental risks.
Institute of Internal Auditors (IIA)
Copy link to <strong><strong>Institute of Internal </strong><strong>Auditors</strong><strong> (IIA)</strong></strong>The IIA is a global professional body that, while focused on internal audit, plays a key role in shaping risk management best practices, and can provide valuable insights to core concepts and procedures to support risk management frameworks both at the SOE and the state level. The IIA’s International Professional Practices Framework includes standards and guidance on risk management and control. Notably, Standard 2120 states: “The internal audit activity must evaluate the effectiveness and contribute to the improvement of risk management processes.” (The Institute of Internal Auditors, 2017[6]). This means internal auditors in an organisation, whether private or public, are expected to assess how well risk management is working and help strengthen it, thus reflecting the view that effective risk management is a critical component of governance. State ownership entities may transfer key insights from the IIA standards, including how internal auditors from the executive government, or Supreme Audit Institutions (SAIs), can provide valuable data to inform the portfolio risk management framework of the state.
The IIA also introduced the three lines model (2024) as an update to the “three lines of defence” concept, defining clear roles in risk management and oversight. The model emphasises the importance of effective governance through appropriate assignment of responsibilities, alignment of activities through cooperation, collaboration and communication (The Institute of Internal Auditors, 2024[7]). This model can be implemented both at the SOE and the state level, covering any type of organisation whether private or public. In the Three Lines Model, the first line owns and manages risks, the second line provides specialised expertise on risk management and compliance functions through guidance and monitoring of risk matters, while the third line provides independent assurance over the entire risk management framework, through internal audit (The Institute of Internal Auditors, 2024[7]). The IIA emphasises that organisations need effective structures and processes to enable the achievement of objectives while supporting strong governance and risk management (The Institute of Internal Auditors, 2024[7]). In practice, this means establishing sound risk governance, clear accountability for managing specific risks, and independent assurance to ensure the framework is functioning as intended. Together, the IIA standards and model reinforce that a holistic, well-governed approach to risk management is an international best practice.
Many countries align with ISO 31000 through their national standards bodies. The British Standards Institution (BSI), for example, has published BS 31100:2021 (Risk management – Code of practice and guidance for the implementation of BS ISO 31000:2018), which provides additional guidance for implementing ISO 31000 in practice (BSI, 2021[8]). This code of practice helps organisations interpret ISO 31000’s principles and integrate them into their management systems. The existence of BS 31100 underscores that ISO 31000’s approach is considered best practice and is adapted into national guidance to support consistency in risk management across organisations. Other national and sector-specific standards (such as those by Standards Australia/New Zealand, which pioneered AS/NZS 4360, a predecessor to ISO 31000) similarly reinforce the core concepts of ISO 31000. In all cases, the emphasis is on a systematic, proactive and tailored approach to managing risk.
References
[8] BSI (2011), Risk management - Code of practice and guidance for the implementation of BS ISO 31000.
[2] FATF (2025), International Standards on Combating Money Laundering and the Financing of Terrorism & Proliferation, FATF, http://www.fatf-gafi.org/en/publications/Fatfrecommendations/Fatf-recommendations.html (accessed on 16 May 2025).
[4] ISO (2021), ISO 37301:2021 Compliance Management Systems - Requirements with guidance for use.
[3] ISO (2018), ISO 31000:2018 - Risk management - Guidelines, https://www.iso.org/standard/65694.html.
[5] ISO (2016), “ISO 14004:2016 Environmental management systems — General guidelines on implementation”, https://www.iso.org/standard/60856.html (accessed on 10 July 2025).
[1] OECD (2023), OECD Guidelines for Multinational Enterprises on Responsible Business Conduct, OECD Publishing, Paris, https://doi.org/10.1787/81f92357-en.
[7] The Institute of Internal Auditors (2024), “The IIA’s Three Lines Model: An update of the Three Lines of Defense”, The Institute of Internal Auditors, https://www.theiia.org/en/content/position-papers/2020/the-iias-three-lines-model-an-update-of-the-three-lines-of-defense/ (accessed on 26 May 2025).
[6] The Institute of Internal Auditors (2017), International Standards for the Professional Practice of Internal Auditing, https://www.theiia.org/en/standards/what-are-the-standards/mandatory-guidance/standards/introduction/ (accessed on 26 May 2025).
Note
Copy link to Note← 1. ISO International Standards go through a systematic review at least every five years. In that review, ISO member bodies vote on whether to confirm, revise/amend, or withdraw the standard. That does not mean every standard changes every five years; committees can confirm a standard for another cycle or decide to revise earlier than five years if needed. Thus, a standard adopted in 2015 can still be up to date as it may have gone through multiple revision and confirmation cycles.