This chapter examines the risks and opportunities associated with state ownership and explains why they matter from a portfolio perspective. While individual SOEs are expected to manage their own risks, some of the most significant exposures only become visible when viewed across the portfolio as a whole. Drawing on survey evidence, the chapter identifies the risk categories most frequently prioritised by state owners and examines how a portfolio-level approach can help governments spot vulnerabilities, identify interdependencies, assess cumulative impacts and make more informed ownership decisions.
Managing Risk Across State‑Owned Enterprises
1. What are the risks and why does it matter?
Copy link to 1. What are the risks and why does it matter?Abstract
Governments’ portfolios of state‑owned enterprises (SOE) are exposed to a wide range of fiscal, operational, reputational and policy-related risks. At the same time, they can create opportunities to advance strategic objectives, support economic resilience and generate public value. While many of these risks and opportunities originate within the individual SOEs or are driven by external developments, their cumulative effects for the state as owner often only become fully visible when viewed holistically. A portfolio-level perspective therefore helps governments identify interdependencies and assess aggregate exposures and opportunities that may not be apparent at the level of individual SOEs.
The implications of these risks and opportunities extend beyond individual enterprises. When risks materialise, they can affect public finances, market confidence, sovereign credit ratings, and the quality or continuity of essential services. They may also have broader economic and social consequences, including spillovers across sectors, disruptions across supply chains, or result in erosion of public trust. Understanding these wider impacts is therefore an important component of informed state ownership.
A portfolio-level perspective is valuable not only because it helps governments identify risks and opportunities but also because it provides a basis for action. By consolidating information across SOEs and sectors, ownership entities can establish consistent criteria for assessing exposures, define risk appetite, strengthen reporting arrangements, and develop escalation pathways when risks exceed agreed thresholds. This supports better prioritisation, more timely corrective action, and more informed decisions on investment, divestment, capital allocation or future portfolio composition. It also helps move from a reactive to a proactive approach by identifying emerging trends, anticipating vulnerabilities, and recognising opportunities across the portfolio as a whole.
This report focusses on frameworks operating at the portfolio level of state ownership, rather than on SOEs’ individual risk management systems. Effective portfolio risk management, nevertheless, depends on reliable information generated through robust enterprise‑level risk management systems, which remain the primary mechanism for identifying and managing risks within SOEs (OECD, 2018[1]).1 For the purpose of this report, portfolio risk management framework refers to the arrangements used by the state as owner to identify, assess, monitor, and report risks and opportunities arising across its SOE portfolio. These arrangements may be formalised or de facto and are distinct from, but complementary to SOE level risk management frameworks. They are typically developed and implemented by those exercising ownership on behalf of the state, including line ministries, centralised ownership or co‑ordination entities, or state‑owned holding companies.
Effective portfolio-level risk management is only as effective as the governance arrangements and institutional capacity that support it. Those exercising ownership on behalf of the state require both the ability to collect and analyse information across the portfolio and a governance framework that clearly separates ownership from policymaking and regulatory roles. The OECD Guidelines on Corporate Governance of State‑Owned Enterprises (SOE Guidelines) and the OECD Guidelines on Anti-Corruption and Integrity in State‑Owned Enterprises (ACI Guidelines) emphasise these elements as essential foundations for transparent, accountable and effective state ownership.
Against this backdrop, this report examines how state owners are approaching portfolio-level risk management in practice and identifies the main building blocks for more effective frameworks. The remainder of this report is structured as follows: this chapter examines the principal categories of risks and opportunities facing state owners and explains why they matter. Chapter 2 presents the findings from the OECD SOE Risk Management Survey, a perception-based survey on current portfolio-level risk management practices.2 Chapter 3 identifies key building blocks for effective portfolio-level frameworks, drawing on international standards and country practices. Chapter 4 presents case studies illustrating different approaches to portfolio risk management.
1.1. What are the risks?
Copy link to 1.1. What are the risks?State owners may face a wide array of potential risks and opportunities arising from individual SOEs, external developments and broader portfolio dynamics. Survey evidence nevertheless suggests that certain categories consistently emerge as priorities for ownership entities. According to the OECD SOE Risk Management Survey, the three risk categories prioritised by state owners are: sustainability-related risks (75% of respondents); financial and performance risks (58%); and corruption and integrity risks (50%) (Figure 1.1 and Table 1.1).
These risks are particularly relevant given the concentration of SOEs in strategic sectors, the significant economic footprint of SOEs, and the potential implications SOEs can have for public finances, service delivery and public trust (OECD, 2020[2]; 2024[3]; 2018[1]; Baum et al., 2019[4]). Each category is explored in further detail below.
Figure 1.1. . Top three risk priorities for state owners
Copy link to Figure 1.1. . Top three risk priorities for state ownersWhich are or would be (in the absence of relevant risk assessments) your organisation’s top three risk priorities?
Note: Percentage of respondents, out of 24, that placed each risk category among their top 3 priority risks.
Source: OECD SOE Risk Management Survey.
1.1.1. Sustainability-related risks
Sustainability-related risks are the most frequently prioritised risk category among surveyed respondents. For state owners, these risks are particularly significant as SOEs often operate in sectors that are critical to economic resilience, the energy transition and the delivery of essential services. As a result, environmental, social and governance (ESG) related developments can have implications not only for specific ESG factors that can affect individual SOEs, but they can also have implications for broader public policy objectives, including SOEs’ long-term resilience and value creation.
The OECD’s SOE Risk Management Survey shows that for many governments, this increasingly includes exposure to climate‑transition risks, resource over-exploitation or dependency, energy-price volatility, and workforce or community impacts (e.g. labour disputes, occupational safety, human rights). Taking into consideration these elements, some ownership entities define sustainability as the capacity to generate long-term economic, social, environmental, and institutional value through responsible and transparent management of resources, ensuring that the needs of the present are met without compromising the ability of future generations to meet their own (intergenerational responsibility).
SOEs are particularly exposed because they are often concentrated in carbon-heavy (e.g. energy, transport, infrastructure) and strategic sectors such as finance and public utilities, amongst others (OECD, 2025[5]). This makes them both central to achieving sustainability goals and commitments and vulnerable to related disruptions (OECD, 2025[5]).
1.1.2. Financial and performance risks
Financial and performance risks – which relates to the financial soundness, efficiency and reliability of SOEs’ operations, systems and internal controls – represents the second most frequently prioritised category among surveyed ownership entities. Given the scale of many SOE portfolios and their importance to public finances, weaknesses in financial performance, operational efficiency or governance can create significant fiscal exposures for the state. Effective management of these risks is therefore central to protecting public value and ensuring the long-term viability of SOEs.
Additionally, as many SOEs manage large balance sheets, complex infrastructure projects and long-term liabilities, weaknesses in financial planning, cost control or governance oversight can translate into fiscal exposure for the state. In some cases, fiscal risks also arise from policy choices, such as under-compensated public service obligations, below-cost pricing or the use of SOEs as tools to achieve public policy goals (e.g. as employers of last resort). When operational losses accumulate, mandates are not transparently funded or liabilities are underestimated, governments often intervene through capital injections, guarantees or debt assumption. Based on a sample of 80 countries, this support has been estimated to average above 5% of gross domestic product (GDP) in the 2010-2018 period, with severe cases, like in Jordan, reaching up to 15% of GDP in the period 2012-2015 (IMF, 2025[6]; Baum et al., 2020[7]). Strengthening financial and operational risk management helps state owners distinguish between performance‑related and policy-related exposures, enabling timely corrective action and better fiscal planning.
1.1.3. Corruption and integrity risks
Corruption and integrity risks were identified by half of survey respondents as a top risk priority. These risks are particularly important because they can undermine transparency, accountability and legitimacy on which effective state ownership depends. Where governance arrangements are weak, corruption and integrity failures may result in financial losses, operational inefficiencies, reputational damage and erosion of public trust.
Corruption and integrity risks arise when weak internal controls, political interference or opaque decision making undermine transparency and accountability in SOEs. These risks may include bribery, fraud, nepotism, and conflicts of interest. Recent OECD survey data identifies several elements that could encompass the definition of corruption. The most common elements referred to corruption as the abuse of entrusted power, authority, or position for private gain or undue advantage, whether for oneself or for another person or entity. Definitions from the survey refer both to active and passive forms, including the offering, giving, solicitation, or acceptance of any undue benefit, advantage, or promise thereof, to influence the performance, omission, or facilitation of an act contrary to one’s official duties or responsibilities.
Such vulnerabilities often emerge in environments with weak regulatory oversight or opaque governance structures, making them particularly challenging to address. They can be aggravated by complex procurement processes, discretionary subsidies or non-transparent board or management appointments. Effective risk mitigation requires robust reporting and communication systems between SOEs and the state as owner, internal controls, transparency measures, and accountability mechanisms.
Table 1.1. . Main types of risk categories
Copy link to Table 1.1. . Main types of risk categories|
Category |
Definition |
Risk examples |
Opportunity examples |
Percentage of respondents listing it in their top 3 risks |
|---|---|---|---|---|
|
Sustainability |
Risks encompassing economic, environmental, social, and governance factors that can affect SOE long-term resilience and value creation. |
Exposure to climate‑transition risks, resource over-exploitation or dependency, energy-price volatility, and workforce or community impacts (e.g. labour disputes, occupational safety, human rights). |
Addressing sustainability-related risks can mitigate the vulnerability of SOEs which are often concentrated in carbon-heavy (e.g. energy, transport, infrastructure) and strategic sectors such as finance and public utilities, amongst others. A risk management framework focussing on sustainability can therefore help reduce their own vulnerabilities. |
75% |
|
Financial and performance |
Risks concerning the financial soundness, efficiency and reliability of SOEs’ operations, systems and internal controls. |
Large balance sheets, complex infrastructure projects with long-term liabilities, weaknesses in financial planning and miscalculation, cost control, and fiscal exposure. |
A sound risk management framework mitigating financial and performance risks may allow ownership entities to make informed capital allocation decisions, re‑optimise portfolios and ensure that resources are channelled towards productive and efficient activities that enhance competitiveness and support long-term value creation. |
58% |
|
Corruption and integrity |
Risks arising when weak internal controls, political interference or opaque decision making undermine transparency and accountability in SOEs. |
Bribery, fraud, nepotism, and conflicts of interest. |
Anti-corruption and integrity controls may improve access to markets and partners; they can create stronger stakeholder trust; reduce legal/enforcement exposure and costs. All this can increase the value of SOEs. |
50% |
|
Governance and operational |
Operational risk: risk of loss from inadequate or failed internal processes, people and systems, or from external events (legal risk included; strategic and reputational excluded). Governance: guidance emphasises boards’ responsibilities for internal controls, risk oversight, transparency, and accountability (incl. in SOEs). |
Process failures causing service outages; weak board oversight over major projects; health & safety incidents; procurement control gaps. |
Board-level risk governance raising performance/resilience; process redesign/automation improving quality and cost; stronger internal control environment enabling faster scale‑up. |
21% |
|
Compliance and regulatory |
Risk of legal/regulatory sanctions, financial loss, or reputational damage from non-compliance. |
Non-compliance with Anti-Money Laundering/Know Your Customer; data-protection breaches; export-controls violations. |
Systematic compliance elevating market entry readiness; smoother regulatory approvals; reduced cost of remediation/penalties. |
21% |
|
Reputational |
Risk arising from negative stakeholder perception (customers, counterparties, creditors, investors, etc.) that can lead to adverse effects. |
Publicised ethics breaches; product quality failures; controversies around executive conduct leading to loss of trust. |
Proactive transparency and issues management strengthening brand equity; superior sustainability performance differentiating with lenders and buyers. |
17% |
|
Geopolitical |
Political instability (local or international)/armed conflict as material disruptors to people and operations. |
Sanctions/export-control shifts; expropriation or conflict-zone shutdowns; travel restrictions and civil unrest disrupting operations. |
Geographic diversification and near-shoring; resilient supply-chain and Business Continuity Management capabilities that reduce downtime; enhanced duty-of-care programmes improving workforce readiness. |
8% |
|
Cybersecurity |
Risk to the safeguarding of the confidentiality, integrity, and availability of information within cyberspace, encompassing the protection of information systems, networks, and data against unauthorised access, attacks, or damage. |
Ransomware halting operations; third-party data breach; Operational Technology/Industrial Control Systems compromise impacting safety. |
Adequate controls may enable trusted data-sharing; faster incident response and recovery; competitive advantage with customers demanding robust security. |
4% |
Source: OECD SOE Risk Management Survey; ISO/IEC 27032:2012; NIST Cybersecurity Framework 2.0; ISO 31000; BIS OPE10; IFRS; ISO 37301.
While sustainability, financial and performance, and corruption and integrity risks are often identified and managed at the level of individual SOEs, their implications frequently extend beyond individual enterprises. For state owners, the challenge is to not only understand these risks in isolation, but also to assess how they accumulate, interact and affect the portfolio of companies. This broader perspective is essential for understanding why portfolio-level risk management matters. Ultimately, sound portfolio-level risk management systems allow ownership entities to make informed capital allocation decisions, optimise portfolios and ensure that resources are channelled towards productive and efficient activities that enhance competitiveness and support long-term value creation.
1.2. Why do they matter?
Copy link to 1.2. Why do they matter?The risks described above do not occur in isolation. While many originate at the level of individual SOEs or from external developments, their implications often extend more broadly. For state ownership the challenge is therefore to understand individual risks as well as how they may accumulate across sectors, ownership structures (especially if ownership is decentralised) or public policy mandates, creating vulnerabilities that may not be visible when viewed in isolation. A portfolio-level approach therefore enables ownership entities to identify concentrations of risk, understand their interdependencies and evaluate their potential implications as an owner.
Some challenges may relate to:
Fragmented information and oversight. Even where SOEs have their own risk management systems, information is siloed within SOEs, or limited to a narrower fiscal oversight review related to budgetary and contingent liability risks rather than operations, strategic or reputational dimensions. Depending on the level of centralisation or co‑ordination, information may also be fragmented across ownership entities and line ministries, limiting the ability to assess cross-cutting priorities from a whole‑of-portfolio perspective. Company-level systems are necessary, but they are not sufficient to identify systemic, correlated or cross-cutting risks that may only become visible when SOE exposures are analysed in aggregate.
Policy-related and governance‑related risks may not be fully visible from an enterprise‑level perspective. While fiscal risks tend to be well addressed, policy choices can create hidden liabilities. Quality of SOE governance arrangements can further amplify these exposures, such as weak board oversight, ineffective internal controls, or misaligned accountability structures. Elements of these may be well monitored such as through SOE scorecards and performance monitoring, but such information may not feed into a holistic consideration of risks.
New and emerging risks. New areas of risk that could cut across the SOE portfolio may not be visible if managed in isolation. Portfolio-level approaches allow ownership entities to spot systemic vulnerabilities (e.g. energy dependency, exposure to carbon pricing, risk of stranded assets, investment needs, etc.) and identify priority areas.
A portfolio-level approach complements these existing mechanisms bringing together dispersed information from across SOEs, sectors and ownership entities into a single view of the state’s risk and opportunity landscape. This helps ownership entities identify cross-cutting exposures, priority risks and align portfolio decisions with broader ownership policy, budget objectives and risk appetite thresholds, enabling better-informed decision-making processes.
It can also help to identify correlations between SOEs, distinguish policy from performance‑related exposures, and assess how risks may be concentrated in one sector or can spillover into others. By linking information from individual SOEs with broader ownership decisions, portfolio-level risk management supports governments in acting as active and informed owners, consistent with the ACI Guidelines and the SOE Guidelines. These are summarised in Table 1.2.
Table 1.2. Relevant provisions in the SOE and ACI Guidelines
Copy link to Table 1.2. Relevant provisions in the SOE and ACI Guidelines|
Recommendation |
Provision |
|---|---|
|
ACI Guidelines, recommendation III.5.v |
“Us[e], as appropriate, benchmarking tools to assess the overall risk exposure of the state through its ownership of SOEs”. |
|
SOE Guidelines, Guideline II.F.4 |
Among the prime responsibilities of the state ownership entity: “Setting up reporting systems that allow the ownership entity to regularly monitor and assess SOE performance and oversee and monitor their compliance with applicable corporate governance standards, including by making use of digital technologies”. “Such reporting systems should also be designed to ensure that appropriate government bodies can monitor and evaluate any fiscal risks, particularly where state support is large and depending on SOEs’ level of systemic importance which may affect public finances or financial stability”. |
|
Annotations to Guideline VII.A.3 of the SOE Guidelines |
“Regular performance reviews can support ownership entities with developing a clear understanding of the sustainability issues related to their portfolios and individual companies, as well as setting or adjusting new performance targets on an informed basis. In addition, the state should also consider evaluating the performance of its portfolio as a whole and consider how it can contribute to long-term value creation. To support its analysis, the state may measure its portfolio-level exposure to sustainability-related risks and/or benchmark sustainability performance of SOEs across the portfolio or among peer companies, amongst other aspects. This should help the state evaluate and prioritise sustainability risks and opportunities and devise expectations on an informed basis”. |
Source: OECD, (2019[8]), Guidelines on Anti-corruption and Integrity in State‑Owned Enterprises, www.oecd.org/corporate/Anti-Corruption-Integrity-Guidelines-for-SOEs.htm; OECD (2024[9]), Recommendation of the Council on Guidelines on Corporate Governance of State‑Owned Enterprises, OECD/LEGAL/0414, https://legalinstruments.oecd.org/en/instruments/OECD-LEGAL-0414.
Effective portfolio-level risk management depends not only on information, but also on institutional capacity. Ownership entities require access to timely and reliable financial and non-financial information, clear governance expectations of SOEs and mechanisms for translating risk information into ownership decisions. Without these foundations, risk signals may be identified but not acted upon.
Survey evidence suggests that portfolio-level risk management remains underdeveloped. While many countries require SOEs to manage risks at the enterprise level, portfolio-level approaches remain considerably less developed. While 81% of respondent countries have regulations or expectations requiring SOEs to implement risk management systems, only 41% are assessing their overall risk exposures at the portfolio-level (Figure 1.2) (OECD, 2025[10]). Moreover, fewer than half of respondents reported having formalised or de facto frameworks in place (Figure 1.3). This suggests that while many countries have established elements of risk management, fewer have integrated them into a coherent portfolio-level framework. Without such frameworks, governments may receive information on individual enterprises while lacking the ability to assess how risks and opportunities accumulate across sectors, risk categories and public policy mandates. This can limit their ability to act as an informed and active owner.
While the rationale for portfolio-level risk management is increasingly recognised, the extent to which such approaches have been implemented varies across jurisdictions. The following chapter examines survey evidence on how ownership entities are currently approaching portfolio-level risk management in practice.
Figure 1.2. Risk management systems in state ownership entities and SOEs
Copy link to Figure 1.2. Risk management systems in state ownership entities and SOEsSource: OECD, (2025[10]), Report on the implementation of the OECD recommendation on guidelines on anti-corruption and integrity in state‑owned enterprises, https://one.oecd.org/document/C(2025)18/en.
Figure 1.3. Portfolio risk management frameworks in place at state‑level
Copy link to Figure 1.3. Portfolio risk management frameworks in place at state‑levelDoes your entity currently have a portfolio risk management framework at the level of the state?
Source: OECD SOE Risk Management Survey.
References
[4] Baum, A. et al. (2019), “Governance and State-Owned Enterprises: How Costly is Corruption?”, Working Paper No. 2019/253, International Monetary Fund, Washington DC, https://doi.org/10.5089/9781513519296.001.
[7] Baum, A. et al. (2020), “Managing Fiscal Risks from State-Owned Enterprises”, IMF Working Papers, Vol. 20/213, https://doi.org/10.5089/9781513557502.001.
[6] IMF (2025), STATE-OWNED ENTERPRISE (SOE) HEALTH CHECK TOOL (HCT), https://www.imf.org/en/Topics/fiscal-policies/Fiscal-Risks/Fiscal-Risks-Toolkit/Fiscal-Risks-Toolkit-SOE-HCT (accessed on 30 September 2025).
[10] OECD (2025), Report on the implementation of the OECD recommendation on guidelines on anti-corruption and integrity in state-owned enterprises, https://one.oecd.org/document/C(2025)18/en (accessed on 9 March 2026).
[5] OECD (2025), State-Owned Enterprises and Sustainability: Leading by Example, OECD Publishing, Paris, https://doi.org/10.1787/c99c7ef0-en.
[3] OECD (2024), Ownership and Governance of State-Owned Enterprises, OECD Publishing, Paris, https://doi.org/10.1787/395c9956-en.
[9] OECD (2024), Recommendation of the Council on Guidelines on Corporate Governance of State-Owned Enterprises [OECD-LEGAL-0414], https://legalinstruments.oecd.org/en/instruments/OECD-LEGAL-0414.
[2] OECD (2020), OECD Business and Finance Outlook 2020: Sustainable and Resilient Finance, OECD Publishing, Paris, https://doi.org/10.1787/eb61fd29-en.
[8] OECD (2019), Guidelines on Anti-corruption and Integrity in State-Owned Enterprises, OECD Publishing, Paris, https://doi.org/10.1787/315dab91-en.
[1] OECD (2018), State-Owned Enterprises and Corruption: What Are the Risks and What Can Be Done?, OECD Publishing, Paris, https://doi.org/10.1787/9789264303058-en.
Notes
Copy link to Notes← 1. This is supported by OECD data which shows that SOEs report as key challenges to their companies’ integrity their relationship with the government, including ineffective control and accountability (including ineffective internal control or risk management).
← 2. The perception-based survey aimed at identifying current portfolio risk management frameworks and practices at the state ownership level. The survey gathered views on whether state‑level portfolio risk management frameworks are well-adapted to support effective oversight of the SOEs. The survey was answered by 24 jurisdictions: Australia, Azerbaijan, Colombia, Costa Rica, Croatia, Czechia, Estonia, Finland, Germany, Iceland, India, Italy, Latvia, Lithuania, Morocco, New Zealand, Norway, Peru, Philippines, the Slovak Republic, Spain, Sweden, Switzerland and the United Kingdom.