How to Build Geopolitical Capability: A Practical Guide for Business Leaders

Most companies that say they "take geopolitics seriously" cannot actually show what that means. Here's what a real capability requires — and where to start this quarter.

Most companies that say they take geopolitics seriously can describe a feeling — a function that exists, briefings that happen, a board that pays attention — but not a set of practices anyone could verify. That gap, not a shortage of intelligence, is why geopolitical risk keeps producing expensive surprises for companies that were, by every account, "paying attention".

Financial risk has GAAP and IFRS. Cybersecurity has NIST and ISO 27001. Sustainability reporting has the GRI. Each of those disciplines matured by settling on the same five foundations — a measurable unit, a way to classify what's being measured, named accountability, a maturity ladder, and an object that turns analysis into a recorded decision. Geopolitical risk management is now going through that same process, and understanding these five foundations is the fastest way to build real capability rather than another layer of reporting.

The problem isn't your intelligence — it's what happens to it

Picture a board briefing that goes well. A sharp analyst walks the board through a developing situation — a shift in trade policy, a contested shipping route, a sanctions regime tightening around a key input — the room asks good questions, and everyone leaves better informed. Six months later, the risk arrives close to as forecast. Someone asks what the company decided to do about it. Nobody can answer cleanly. There's a memory of a good discussion, maybe a slide deck, but no record of a decision, an owner, or a trigger that was supposed to prompt action.

This happens constantly, and it isn't a failure of analysis. Briefings are built to transfer understanding. They aren't built to converge a room on a choice, assign it to someone, and leave a trace. A company can have genuinely excellent geopolitical intelligence and still make worse decisions than a competitor with average intelligence and a better decision process, because intelligence quality and decision quality are different variables — and most geopolitical risk programs only invest in the first one.

Why this hits industrial companies hard

If you run a globally operating industrial business, this gap is highly expensive for you for a simple reason: your risk sits in physical things that are slow and costly to change. A single-source supplier of a critical input in a jurisdiction facing new export controls. A manufacturing footprint concentrated in a region where tariff policy is shifting quarter to quarter. A logistics route that runs through one strait or one canal. A compliance regime — dual-use export rules, sanctions lists, critical-minerals restrictions — that can turn a routine shipment into a legal problem overnight. Industrial companies are usually looking at requalifying a supplier, re-permitting a facility, or re-routing physical freight — processes that might take quarters, not weeks. That asymmetry is exactly why the five foundations below matter more, not less, for your sector: the lead time on your response is long, so the lead time on noticing the exposure has to be longer still.

A quick, honest test

Ask your own organization three questions and see how far you get.

  1. Show me your exposure. Not a slide describing regional tension in general terms — an actual list, where each item is a specific business exposure tied to a dollar or euro figure.
  2. Pick one item on that list and show me who owns it. Not "distributed across the C-suite" — a named individual with a last-review date.
  3. Go back to the last time something material shifted — a tariff, a sanctions package, an export control change — and show me the decision it produced. Who decided, what did they decide, and when?

Most executives who describe their geopolitical function as "reasonably mature" find this exercise deflating. That's normal, and it isn't really about effort or intelligence. It's the absence of a yardstick. Maturity is a feeling until it becomes a set of observable practices, and most companies have never seen those practices written down — so they grade themselves against a vibe instead of evidence.

The five foundations a real capability needs

1. A measurable unit

Every mature risk discipline has an atomic unit you can count. Financial risk has dollar exposure. Cyber risk has a severity score. Geopolitical risk needs its own unit, and the simplest version of it is this: a specific named risk, attached to a financial value. Not "we're exposed to trade tensions with China" — but "a $40 million annual cost increase if a specific supplier in a specific jurisdiction loses export clearance." An exposure without a number attached to it isn't managed; it's a feeling. Forcing every geopolitical concern through a value and a name does more to professionalize the function than any amount of additional analysis.

2. A way to classify what you find

Once exposures are written down with real numbers, they need a common structure so they can be compared, prioritized, and assigned. Two classifications matter most for an industrial company.

How the damage would actually arrive:

  • Market access — a country restricts who can sell or operate there.
  • Cost — tariffs, currency shifts, or compliance overhead raise the price of doing business.
  • Disruption — a route, port, or supplier physically stops functioning.
  • Obligation — a new legal or regulatory requirement forces action regardless of preference (sanctions compliance, export licensing, forced divestment).
  • Stakeholder — investors, customers, or governments change their expectations of you because of where or how you operate.

Most companies plan almost exclusively for disruption — the ship that doesn't sail, the port that closes — while underweighting the other four, which is usually where the real surprises come from.

Which part of the business owns it — sourcing and supply, logistics and routes, market access, regulatory and trade policy, or compliance and standards. An exposure's classification determines who should be accountable for it long before anyone writes a document about it.

3. Named accountability

Geopolitical risk cuts across procurement, legal, strategy, and operations simultaneously, which is exactly why it tends to belong to nobody. A workable model doesn't require a new C-suite title. It requires four roles to be filled for every material exposure: someone accountable to the board, someone who owns the specific domain (say, the Chief Procurement Officer for a sourcing exposure), someone doing the actual monitoring / analysis, and someone executing the response.

4. A maturity ladder

You can only manage what you can locate on a scale. A practical version of the ladder looks like this:

  • Ad hoc — geopolitics is handled reactively, in a crisis, with no shared vocabulary and no register.
  • Structured — a named function exists, exposures are written down with real figures, and someone owns each one.
  • Integrated — the function's outputs actually reach board reporting, capital allocation decisions, M&A due diligence, and the enterprise risk register — not just a standalone geopolitics deck that runs in parallel.
  • Continuous — exposures are monitored close to real time, decisions update as conditions shift, and the organization tracks whether its own past calls turned out to be right.

The trap most industrial companies fall into is treating maturity as a single number — "we're basically at the structured stage." In practice, capability is uneven across governance, exposure inventory, analytical rigor, decision process, integration, and assurance, and a company's real maturity is set by its weakest dimension, not the average. Sophisticated analysis sitting on top of no accountability isn't advanced with a gap — it's still ad hoc with good writing.

5. An object that turns analysis into a decision

The final foundation is the artifact actually produced when something material shifts — not another briefing, but a short, structured object that states what changed, the range of realistic options (not just the analyst's favorite one), who needs to decide, and the sequence of actions if conditions keep moving. If your geopolitical output can't survive that test, the intelligence was probably fine — the missing piece was the object that turns intelligence into an owned decision.

Where most industrial companies actually sit

Run the honest test above against your own organization, dimension by dimension, and be specific about the weakest one — not the strongest. Most globally operating industrials that believe they're "structured" are, on closer inspection, still ad hoc with a well-written slide deck: real analytical talent, a genuine sense that geopolitics matters, and no register, no named owners, and no reconstructable decision trail. That isn't a criticism — it's the current state of the field. Cybersecurity took most of two decades to standardize. Geopolitical risk management, as a formal enterprise discipline, is roughly where cybersecurity was before frameworks like ISO 27001 existed.

What to do this quarter

You don't need a new department to make real progress. Three steps get most industrial companies further than another round of briefings.

  1. Write down five real exposures. Not categories — specific, named risks with a dollar figure attached, sourced from the people who already half-know them. Procurement usually knows the single-source suppliers. Legal usually knows the compliance exposures. Logistics usually knows the chokepoints. The information exists; it's just never been written down in one comparable form.
  2. Assign one owner per exposure, with a review date. If ownership has to be described as "shared" or "cross-functional," it isn't real yet. A name and a date are what make an exposure manageable instead of merely known.
  3. Pick your last material geopolitical decision and try to reconstruct it. What changed, who decided, what was chosen, when would it be revisited. If you can't reconstruct it cleanly, that's the gap to close first — not the analysis, the decision trail.

The point of building this now

None of this requires waiting for a crisis, a new executive hire, or a bigger analyst team. It requires committing what your organization already half-knows — which suppliers are exposed, which regulations are shifting, which decisions never got properly recorded — into a shared, verifiable form. The companies that do this well over the next few years won't necessarily be the ones with the most geopolitical analysts. They'll be the ones that can show, on demand, exactly what they're exposed to, who owns it, and what they decided to do about it.

Get started

Let's get you onboard geopolitical intelligence

Book a demo to get started

Book demo
New How mature is your geopolitical function? Benchmark yourself in 5 minutes