Geopolitical shocks must be treated as a live risk

APRA has written to banks, insurers and superannuation trustees setting out minimum expectations for readiness for geopolitical shocks.

This is not a narrow foreign affairs issue. It is a practical resilience issue.

The message is clear: awareness is not enough. Boards and executives need to be able to show how geopolitical risk is built into governance, risk appetite, operational resilience, financial planning, third-party management and crisis preparedness.


The 30-Second Take

Geopolitical risk can no longer sit as a broad scenario in a strategy paper.

APRA expects regulated entities to understand how shocks such as sanctions, trade restrictions, market closure, capital trapping, cyber escalation, foreign interference, disinformation and armed conflict could affect their business.

The real test is whether the organisation has worked through what happens when that risk becomes an operational event.


Why this matters

Geopolitical shocks rarely arrive in one neat category.

A single event can affect funding, liquidity, investments, offshore operations, critical suppliers, cyber exposure, sensitive data flows, customer confidence, conduct obligations and frontline service delivery at the same time.

That is why this issue cuts across far more than the risk team.

Legal, compliance, treasury, procurement, technology, cyber, privacy, operations, business continuity and frontline leaders all have a role to play.

Boards should be asking harder questions:

  • What would we do in the first 24 hours if sanctions, restricted market access or a regional conflict disrupted a critical service?
  • Which offshore dependencies, suppliers, data flows, investments or counterparties would be affected?
  • Have we tested decision-making, escalation and communication under pressure?
  • Do our crisis exercises create evidence, or just comfort?

The role of risk managers

This is where risk teams need to move from awareness to action.

The job is to turn broad concern into usable controls, clear ownership, realistic scenarios, escalation triggers and evidence-based reporting.

That means testing assumptions, challenging dependencies, validating control evidence and making sure crisis playbooks are practical enough to work under pressure.

What to do now

Boards and executives should review whether geopolitical risk is explicitly embedded in:

  • strategy and business planning
  • risk appetite
  • scenario analysis
  • capital and liquidity planning
  • investment stress testing
  • operational resilience
  • third-party and offshore dependency management
  • cyber and data risk
  • crisis exercises
  • board reporting and risk management declarations

Where gaps exist, the response should not be generic assurance language. It should be a prioritised uplift plan with clear owners, timelines and evidence.

Where gaps exist, the response should not be generic assurance language. It should be a prioritised uplift plan with clear owners, timelines and evidence.

This is exactly where maturity assessments can help, AI-enabled risk tools and consulting support are designed to help organisations quickly identify gaps, improve evidence quality and give boards clearer discussion points — without defaulting immediately to a large consulting program.

Geopolitical risk is no longer just something to monitor.

It is something boards need to be ready to govern.

More from the Reading Room

AI Agent Security: What the RubyGems and Hugging Face Incidents Reveal

Researchers allege OpenAI agents uploaded hundreds of malicious packages to RubyGems in May 2026, before a later intrusion involving Hugging Face. The incidents show why AI agent security requires stronger containment, monitoring and accountable governance.

When Fraud Syndicates Exploit Loan Processes: What Australia’s $600 Million Scam Reveals About Control Failures

NSW police allege a criminal syndicate defrauded banks of up to $600 million using false loan applications and insider help from accountants and money mules. This case uncovers how multi-party collusion exploits gaps in loan processes, demanding tighter fraud controls and cross-agency scrutiny.

APRA and ASIC put frontier AI, cyber and resilience on the board agenda

APRA and ASIC’s September 2026 superannuation roundtable summary shows why AI, cyber and supplier disruption should be tested as one compound event. Businesses need rehearsed authority to contain harm, operate through disruption and approve recovery.

APRA’s ING action is a blunt reminder: liquidity breaches are not just an internal issue

APRA’s 3 September 2026 action against ING Australia showed how a reported liquidity ratio near 160 per cent could conceal a materially lower position. Every business should govern critical metrics as controlled products with reproducible calculations, named ownership and escalation for uncertainty.