The Policy Shift Enterprise Risk Management Wasn’t Built For

How U.S. economic security policy is creating a new category of geopolitical risk for enterprise risk management, and what risk leaders need to understand before the next policy shift arrives.

Decorative image

Governmental actions have always shaped enterprise risk management (ERM). Regulations, sanctions, and merger and acquisition oversight have long influenced the business environment. Underlying enterprise risk management was a working assumption: that commercial strategy and government policy occupied largely separate spheres.

When the United States announced sweeping tariff increases in April 2025, companies discovered within hours that procurement strategies, supplier contracts, and pricing models built for a different trade environment were suddenly exposed not because market conditions changed, but because policy did.

The assumption of separate spheres is no longer defensible. Economic policy has become an instrument of geopolitical competition, creating a category of geopolitical risk that most enterprise risk programs were never designed to see.

It is not a new practice for the United States to use economic tools to pursue strategic objectives once associated primarily with diplomacy, defense, or foreign policy. What is new is the scale and integration. The combined and coordinated use of tariffs, investment screening, outbound investment restrictions, industrial policy, and supply chain resilience initiatives, each addressing distinct policy priorities, now represents a durable integration of economic policy into the national security framework that shows no sign of reversing.

For multinational corporations, this is far more than another source of regulatory change. It is a structural shift in how compliance, geopolitical, and operational risk intersect. Government priorities now influence sourcing decisions, technology strategies, investment planning, manufacturing footprints, and third-party relationships in ways that were once driven primarily by commercial considerations. Enterprise risk management was built to help organizations understand uncertainty within markets. Now it must also explain what happens when governments begin reshaping those markets.

Rule-based compliance and existing risk programs absolutely remain essential, but they cannot fully explain operational exposure when political priorities are shaped by geopolitical competition. Risk teams are now being asked to understand how those priorities could reshape strategic decisions long before they appear as operational disruption.

That raises an uncomfortable question. If government policy is shaping commercial strategy, how many geopolitical dependencies already exist inside the business without anyone fully seeing them?

In This Article
  1. Why Is the Definition of Resilience Changing?
  2. Why Do Most Organizations Discover Geopolitical Risk Exposure Too Late?
  3. Why Is Traditional Enterprise Risk Management No Longer Sufficient?
  4. How Do the Best-Prepared Risk Programs Connect Policy to Operational Exposure?
  5. Is Enterprise Risk Evolving Fast Enough?
  6. Frequently Asked Questions

Why Is the Definition of Resilience Changing?

Resilience used to mean recovery and how quickly an organization could restore operations after disruption. Economic security and geopolitical risk haven’t replaced that definition. They’ve expanded it. For risk leaders today, resilience means knowing where strategic dependencies exist before a disruption exposes them, not discovering them only after one does. The difference between those two positions defines who owns the conversation with the board and who is still catching up.

For much of the past three decades, resilience was largely defined by recovery. Businesses optimized for efficiency, expanded global supply chains, concentrated production where costs were lowest, and adopted interconnected technology ecosystems because those decisions delivered competitive advantage. Risk management focused on withstanding disruption. The goal was to preserve an operating model that few executives had reason to question.

Economic security policy is changing that calculation. Today, resilience means understanding where strategic dependency exists before disruption occurs. U.S. policy now encourages organizations to reduce reliance across sectors viewed as strategically important to national security and long-term economic competitiveness, including:

  • Semiconductors and advanced manufacturing
  • Critical minerals and energy security
  • Cloud infrastructure and emerging technologies
  • Pharmaceuticals and healthcare resilience

These are not simply industries receiving greater political attention. They represent areas in which commercial dependency and national strategy now overlap. In semiconductors, decisions about where to manufacture advanced chips, which suppliers to use, and which customers to serve are now shaped as much by U.S. national security priorities as by cost and commercial logic, a shift that no conventional resilience framework was intended to capture. Decisions about sourcing, manufacturing, investment, technology adoption, and market expansion now require risk programs to evaluate geopolitical exposure alongside traditional commercial considerations and, in some cases, ahead of them.

Enterprise risk management no longer asks only whether the business can recover after disruption. The function is now expected to identify where strategic assumptions themselves may become vulnerable as government priorities evolve. Valuable insights often come before a policy announcement, when dependencies remain manageable rather than exposed.

Most programs were not created to deliver that insight. That gap is widening.

Why Do Most Organizations Discover Geopolitical Risk Exposure Too Late?

Most enterprises encounter geopolitical risk through economic security policy not as a strategic question but as an operational one. Few executives begin their day thinking about tariffs or outbound investment restrictions. They think about delayed product launches, disrupted supply chains, acquisitions that became more complicated overnight, or technology decisions that no longer make commercial sense because the policy environment shifted.

The operational consequence arrives before the risk has been mapped, and by the time it’s visible, the strategic flexibility to respond has often narrowed. The geopolitical risk was always there. Most programs just weren’t looking for it in the right places.

This is how economic security enters the enterprise:

  • Export controls can reshape technology roadmaps by restricting access to critical components, advanced software, or emerging capabilities.
  • Investment screening and outbound investment restrictions can influence acquisitions, partnerships, and long-term growth strategies.
  • Sanctions can alter supplier relationships, customer portfolios, financial institution relationships, and third-party arrangements with little warning, requiring operational adjustments rather than simply legal interpretation.
  • Industrial policy and strategic incentives can influence manufacturing decisions, sourcing strategies, and capital investment that were once driven almost exclusively by commercial considerations.

The practical consequences are not theoretical. In 2024 alone, the U.S. Department of Commerce added more than 340 parties to its Entity List, restricting which technologies, components, and capabilities organizations could source, sell, or transfer. Each addition created compliance obligations that procurement, legal, and operations teams had to absorb, often with limited lead time.

What makes these developments significant is not any individual policy instrument. It is the cumulative effect across the enterprise. A policy decision may begin in Washington, but its consequences quickly extend into procurement, compliance, information security, operations, finance, strategy, and enterprise risk. Every function sees a different part of the problem. Very few see the whole picture.

And by the time the full picture comes into focus, the window for a strategic response has usually closed. This is the governance gap that boards and executive teams are increasingly being asked to account for, often after the fact.

Understand where economic security and geopolitical risk intersect with your enterprise risk

Learn More

Why Is Traditional Enterprise Risk Management No Longer Sufficient?

Traditional enterprise risk management was built for a world in which governments set the rules and businesses optimized within them. Geopolitical risk operating through economic policy behaves differently. It doesn’t arrive as a market event. It arrives as a shift in the conditions under which markets operate. Risk programs designed for the old model are measuring exposure in the wrong frame.

Geopolitical risk in enterprise risk management refers to the exposure that arises when deliberate government action, through tariffs, export controls, investment screening, sanctions, or industrial policy, reshapes the conditions under which an enterprise operates. Unlike traditional market risk, it originates from political decision-making rather than market dynamics, and it can alter strategic assumptions across sourcing, technology, investment, and third-party relationships with limited warning.

The problem runs deeper than regulatory compliance. Modern enterprise risk management matured during a period when globalization, commercial efficiency, and relatively predictable markets generally reinforced one another. Governments established the rules under which markets operated, while businesses optimized within those rules. Risk professionals focused on understanding how market volatility, operational failures, regulatory requirements, and competitive pressures could affect organizational objectives. That model assumed a stable boundary between government and market. That boundary has moved.

Today, governments are doing more than regulating markets. Through industrial policy, investment screening, export controls, strategic incentives, and intervention across critical sectors, they are now influencing how markets themselves develop. Commercial assumptions that appeared stable only a few years ago can change because national priorities change.

Investment screening alone illustrates the scale: the Committee on Foreign Investment in the United States reviewed 325 covered transactions in 2024 and opened formal inquiries into 76 transactions that were never voluntarily filed, a sign of how deeply geopolitical scrutiny has embedded itself into mergers and acquisitions and investment decisions that once proceeded on purely commercial terms.

The distinction matters. Traditional risk assessments ask what events could affect your business. Geopolitical risk asks how changing government priorities might redefine the conditions under which your business operates.

Those questions are related, but they are not the same. One anticipates disruption within an existing operating model. The other examines whether the operating model itself depends upon assumptions that governments are actively reshaping.

Risk programs that treat geopolitical developments as background context rather than a direct input to enterprise risk are measuring the wrong things. Strategic dependencies develop gradually across suppliers, technologies, cloud providers, logistics networks, manufacturing capacity, investment strategies, and critical business capabilities. This happens until a policy decision suddenly reveals how interconnected they had become.

The question most boards have not yet asked their risk teams is not “what are our regulatory obligations?” It’s “where are our strategic dependencies, and which of them are being reshaped by government priorities right now?”

How Do the Best-Prepared Risk Programs Connect Policy to Operational Exposure?

The best-prepared risk programs treat geopolitical risk and economic security as enterprise-wide governance issues, not specialist compliance functions. They map policy developments to operational dependencies, flagging where government priorities could affect suppliers, technologies, and strategic relationships before those effects create disruption. Cross-functional governance makes that analysis actionable, board visibility is what turns it into decisions.

Risk programs built for this environment follow a three-part geopolitical risk governance model. First, policy mapping: identifying in real time which government actions across tariffs, export controls, sanctions, and investment restrictions intersect with operational dependencies, rather than waiting for disruption to reveal them. Second, enterprise-wide exposure analysis: broadening dependency mapping beyond supplier concentration to include technologies, cloud providers, logistics networks, manufacturing capacity, and strategic relationships that could become operational constraints when government priorities shift. Third, governance integration: connecting those findings to executive accountability and board visibility, not running geopolitical risk as a checkbox exercise, but as a governance priority with named ownership.

That cross-functional view requires governance architecture, not just process. Legal, government affairs, procurement, compliance, information security, strategy, finance, and enterprise risk each understand different aspects of economic security and geopolitical risk. The organizations making this work are running it as a cross-functional governance priority with executive accountability and board visibility attached.

According to the World Economic Forum’s 2026 Global Risks Report, geoeconomic confrontation (trade restrictions, sanctions, and industrial policy) ranks among the most severe near-term risks facing organizations globally. The implication for risk programs is direct: geopolitical risk is no longer a background consideration. It is a primary governance input. That finding is reinforced at the executive level: in PwC’s 2026 Global CEO Survey, nine out of ten executives cited geopolitical uncertainty as a moderate or serious risk to their organization, placing it alongside cybersecurity and macroeconomic volatility as a defining governance concern. AI-assisted intelligence and integrated GRC platforms are what allow risk programs to act on it.

Is Enterprise Risk Evolving Fast Enough?

Economic security is redefining the relationship between U.S. policy and enterprise risk management. The assumption that commercial strategy and government policy occupy separate spheres is not a workable foundation for risk programs or for the boards that oversee them. When public decisions shape markets, technology, investment, manufacturing, and supply chains, competitive advantage belongs to organizations that understand where geopolitical risk and strategic dependencies exist before policy changes expose them.

The strongest risk programs will not be those that successfully predict every tariff, sanction, or investment restriction, because that is not attainable. They will be the programs that understand how government priorities intersect with operational dependencies, technology ecosystems, third-party relationships, and enterprise strategy well enough to adapt when those priorities change.

This challenge does not stop at the U.S. border. Many of the same forces reshaping enterprise risk in America are influencing regulatory and geopolitical developments across other jurisdictions as governments place greater emphasis on industrial capacity, technological leadership, strategic autonomy, and supply chain resilience. The specific policies may differ, but the underlying direction is consistent.

Enterprise risk management has always been concerned with uncertainty. Geopolitical risk introduces a distinct kind of uncertainty, one created not by market volatility but by governments actively using commercial policy as an instrument of strategic competition.

The question we should be asking is not whether economic security belongs within enterprise risk management. It does. The harder question is whether enterprise risk management programs are evolving quickly enough to govern an economy that has itself become an arena of geopolitical competition. According to PwC’s 2025 Annual Corporate Directors Survey, boards increasingly lack the expertise in geopolitical risk that their agendas now demand, a skills gap that is forcing the governance question from background awareness to board priority. Boards are beginning to ask that question directly. The risk leaders who have built the visibility to answer it will be in a different position than those who are still working out where to start.

 

Other blogs in this series:
The Geopolitical Risk That’s Already Inside Your Organisation
European Regulation Doesn’t Stop at Europe’s Borders

See how the most prepared risk programs are building geopolitical risk visibility

Learn More

 

At Mitratech, we help enterprise risk and compliance teams build the visibility this environment demands. Our capabilities span enterprise risk management, third-party risk management, and AI-assisted intelligence through ARIES™, connecting geopolitical developments, policy changes, regulatory obligations, and operational dependencies in a single platform. The goal is not to predict what governments will do next. It is to ensure your risk program understands where those decisions will land when they do.

Frequently Asked Questions

What is geopolitical risk in enterprise risk management?
Geopolitical risk in enterprise risk management refers to the exposure that arises when government policy, including tariffs, export controls, investment screening, sanctions, and industrial policy, reshapes the commercial and operational conditions in which an enterprise operates. Unlike traditional market risk, geopolitical risk originates from deliberate government action rather than market dynamics, and it can alter strategic assumptions across sourcing, technology, investment, and third-party relationships with limited warning.
How does U.S. economic security policy create geopolitical risk for multinationals?
U.S. economic security policy creates geopolitical risk for multinational corporations through several interconnected mechanisms: export controls that restrict access to critical technologies, investment screening through CFIUS that complicates acquisitions and partnerships, sanctions that alter supplier and customer relationships, and industrial policy incentives that shift manufacturing and sourcing economics. Cumulatively, commercial decisions once driven purely by market logic now require geopolitical input before they are made.
What is the difference between geopolitical risk and economic security risk?
Geopolitical risk refers broadly to the impact of political events (conflicts, elections, diplomatic disputes) on business operations. Economic security risk is a more specific category: it describes the deliberate use of economic instruments (trade policy, investment controls, export restrictions, industrial incentives) to advance national security objectives. The two increasingly overlap, but economic security risk is where most of the operational exposure for enterprise risk programs now concentrates.
How do export controls create enterprise risk management challenges?
Export controls create enterprise risk management challenges by restricting which technologies, components, and capabilities organizations can source, sell, or transfer across borders. Technology roadmaps, supplier selection, and product strategies may require geopolitical and compliance screening before finalizing commercial decisions. Controls on advanced semiconductors, software, and AI-related technologies have made export compliance a direct input to enterprise risk, not solely a legal function. Cross-jurisdictional complexity adds another dimension: in some markets, routine compliance with U.S., UK, or EU controls can itself trigger legal exposure under local counter-extraterritoriality regulations, a category of risk that moves faster than most enterprise risk management (ERM) review cycles.
How should enterprise risk programs adapt to geopolitical risk from economic security policy?
Enterprise risk programs should treat geopolitical risk from economic security policy as an enterprise-wide governance issue, not a specialist compliance function. This means mapping operational dependencies (suppliers, technologies, cloud providers, logistics networks) against policy and geopolitical exposure; building continuous monitoring rather than periodic review; and connecting legal, government affairs, procurement, compliance, and finance through a common operational risk framework with board-level visibility and accountability attached.