Geopolitical & Supply Chain OSINT Risk Assessment

An OSINT risk assessment shows which countries, suppliers and events could disrupt your business, and how exposed you already are. We map supply chains beyond the first tier, test them for forced-labor and sanctions exposure, watch for events that change the picture and brief your board on the scenarios that matter.

  • Country and supplier risk
  • Forced-labor and sanctions exposure
  • Event monitoring
  • Scenario briefings for boards
Short answer

An OSINT risk assessment uses public and commercially available information, such as registries, trade and customs data, sanctions lists, regulatory actions, media and local reporting, to judge the risk a country, supplier or event poses to your operations. OSINT-S delivers it as a one-off assessment of a market or supply chain, ongoing event monitoring, or a scenario briefing for your board.

Why Boards Are Asking for Geopolitical Risk Assessment

Trade conflict, sanctions and forced-labor rules now hit supply chains directly, and directors are expected to understand the exposure before it becomes a loss.

The World Economic Forum's Global Risks Report 2026, based on a survey of more than 1,300 leaders, ranks geoeconomic confrontation as the top risk over the next two years, covering challenges to trade, investment, supply chains and access to natural resources (WEF, January 2026). For most companies that risk does not arrive as a headline. It arrives as a detained shipment, a supplier that suddenly appears on a list, a tariff that changes the cost of a product line, or a strike or protest that closes a port.

The board's question is rarely "what will happen in the world?" It is "where are we exposed, how badly, and what would we do?" That is the question an assessment answers.

What Our OSINT Risk Assessment Covers

Six areas, from the country you operate in to the supplier three tiers down, each tied to a decision you have to make.

Country

Country and market risk

Political stability, regulatory and enforcement trends, sanctions regimes, security conditions and how they affect your sites, staff and contracts.

Suppliers

Supplier risk beyond tier one

Who your suppliers' suppliers are, who owns them, and where their goods and inputs come from.

Supplier due diligence →
Labor

Forced-labor exposure

Links to high-risk regions, entities named by regulators, and goods flagged by official lists.

Sanctions

Sanctions exposure

Listed owners, 50% ownership chains, intermediaries and trading patterns that need review.

KYC and AML →
Events

Event monitoring

Unrest, strikes, regulatory actions, disasters and security incidents near your sites and routes, verified before you are alerted.

Board

Scenario briefings

Short, sourced briefings on plausible scenarios, their triggers and the decisions each would force.

Forced-Labor Rules That Now Reach Your Supply Chain

US import rules already put the burden of proof on importers, and the EU ban applies from 14 December 2027; both require evidence about suppliers you may never have met.

RuleStatusWhat it means for buyers
US Uyghur Forced Labor Prevention Act (UFLPA)Rebuttable presumption in effect since 21 June 2022 (CBP)Goods made wholly or in part in the Xinjiang region, or by an entity on the UFLPA Entity List, are presumed barred from import unless the importer shows by clear and convincing evidence that no forced labor was used
EU Forced Labour Regulation (EU) 2024/3015In force since December 2024; applies from 14 December 2027 (EUR-Lex, European Commission)Products made with forced labor may not be sold in or exported from the EU; authorities investigate and can order withdrawal. The Commission published guidelines in June 2026, and member states must notify penalty rules by 14 December 2026 (Sidley)
US Department of Labor list2024 edition: 204 goods from 82 countries and areas (DOL)A starting point for which product and country combinations need closer review

The scale is large: the ILO estimates that 27.6 million people were in forced labor on any given day in 2021 (ILO, 2024). Supplier questionnaires and audit certificates rarely reach the tiers where the risk sits. Open sources can: corporate registries, shipping and customs records, company websites and filings, local media, NGO and academic research, and regulator lists. We use them to map who supplies whom and flag the links that need evidence.

Sanctions Exposure Beyond a List Match

Screening finds names; an assessment finds the owners, intermediaries and patterns behind them.

Under the OFAC 50 percent rule, entities owned 50% or more in aggregate by one or more blocked persons are themselves blocked, even if they never appear on a list (OFAC). The same logic applies to supply chains: a supplier with a clean name can still be controlled by a listed person, buy from a listed producer, or ship through an intermediary that exists to hide either.

We trace ownership through registries and filings, compare addresses, directors and contact details across related companies, and look for trading patterns that make no commercial sense. Where a counterparty needs a full background, the work continues as a company investigation. For regulated firms, the findings support your screening and due diligence files; see also OSINT for financial services.

How to Use OSINT for Risk Assessment

Start from the decision, map exposure, collect and verify, then rate the risk and agree what would change the rating.

  1. Define the decisionEntering a market, approving a supplier, renewing a contract or preparing a board discussion. The decision sets the scope.
  2. Map your exposureSites, routes, suppliers, customers, staff and assets in each country, as far down the supply chain as the decision requires.
  3. Collect from open sourcesRegistries, trade and customs data, sanctions and regulator lists, court records, local and international media, and specialist research.
  4. Verify and connectTest findings against independent sources and link them to your assets, so each risk is specific rather than generic.
  5. Rate the risk and set triggersLikelihood and impact for each issue, plus the signals that would raise or lower the rating.
  6. Report and monitorA sourced report reviewed by a senior analyst, then monitoring of the triggers if you want it.

Which Open Sources Feed an OSINT Supply Chain Risk Review

No single tool covers geopolitics; the value comes from combining several source types and checking them against each other.

Source typeWhat it showsLimits
Corporate registries and filingsOwners, directors, related companies, addressesCoverage and disclosure vary widely by jurisdiction
Trade, customs and shipping dataWho ships what to whom, through which portsIncomplete, often commercial, needs careful matching
Sanctions, export and regulator listsListed parties, enforcement actions, detention noticesShow names, not ownership or control
Media, NGO and academic researchLabor conditions, disputes, local politicsQuality varies; each claim needs verification
Commercial satellite imageryChanges at sites, construction, activity levelsShows what is visible, not who controls it
Event and social media monitoringProtests, strikes, incidents as they happenFast but noisy; early reports are often wrong

People often ask for the best OSINT tools for geopolitics in 2026. Tools matter less than method: a clear question, sources that can be checked against each other, and an analyst who says how confident the conclusion is.

Event Monitoring and Pre-Incident Warning

Monitoring watches the triggers agreed in the assessment, so you hear about the events that affect your sites, suppliers and routes, not every headline.

After the assessment, we can watch the countries, suppliers and locations that matter on our analyst-reviewed monitoring platform, which updates hourly. Alerts are checked before they reach you and say what happened, how reliable the report is, and which of your assets it touches. Pre-incident warning works best with specific triggers: a planned strike at a port you depend on, a court ruling against a key supplier, a new listing that names a supplier's owner.

For staff traveling to higher-risk locations, combine this with travel risk intelligence. Operators of essential services can read more on OSINT for critical infrastructure, and defense-sector supply chains are covered on our defense OSINT research page.

Scenario Briefings for Boards and Risk Committees

A short, sourced briefing that turns open-source findings into two to four scenarios, their warning signs and the decisions each one would require.

Boards do not need a forecast presented as fact. They need a small number of plausible scenarios, the evidence behind each, the early signals that would show which is unfolding, and what the company would do in each case. A typical briefing has a one-page summary, a scenario table, the exposure map behind it and the sources, followed by a session with directors if you want one.

Work is quoted at a fixed price after written scoping, and if we miss the agreed date the fee goes down. A focused assessment takes from 10 business days; a full supply chain review can take up to about a month, and urgent delivery adds 50%.

What a Desk-Based Assessment Cannot Do

It cannot replace on-site audits, legal advice or certainty about the future, and it never puts workers or sources at risk.

  • It is not a social audit. Open sources show links and red flags; confirming conditions in a factory needs on-site work by qualified auditors.
  • It is not legal advice. Whether evidence meets the UFLPA standard or EU requirements is for your counsel to decide.
  • It does not predict the future. Scenarios describe what is plausible and what to watch, not what will happen.
  • It does not endanger people. We do not contact workers or local sources in ways that could expose them, and we do not use pretexting, hacking or stolen data.

If the main question is about one counterparty rather than a market, start with due diligence or browse other OSINT services.

OSINT Geopolitical Risk: Specialized Services

Focused versions of geopolitical risk for specific subjects, deals and situations.

Geopolitical risk

Supply chain risk

Map the supplier network beyond tier one, expose hidden concentration and chokepoints, and monitor it for events that disrupt supply.

Read more →

Assess a Market or Supply Chain

Tell us the countries, suppliers or decision you are facing. We reply with a written scope, timeline and fixed quote.

OSINT Risk Assessment FAQ

We import electronics components through several Asian suppliers. Can an OSINT risk assessment show whether any of them link back to forced labor or entities on the UFLPA Entity List?

Yes. We map your suppliers and, as far as public and commercial data allows, their suppliers, then check owners, addresses and production sites against the UFLPA Entity List, regulator lists and research on high-risk regions. The result is a list of links that need evidence, with sources. It does not prove compliance on its own; your counsel decides whether the evidence meets the clear and convincing standard.

Our company sells into the EU and I need to prepare for the Forced Labour Regulation before December 2027. Where should a supply chain risk review start?

Start with the products and inputs most likely to carry risk: goods and countries flagged by official lists, regions under regulatory attention, and suppliers whose ownership or sourcing you cannot see. We map those chains first, flag the links that need evidence and help you prioritize supplier engagement. Doing this before the regulation applies on 14 December 2027 leaves time to change suppliers if needed.

My board wants a briefing on how trade conflict and sanctions could affect our two main manufacturing countries. Can you deliver something they will actually read?

Yes. A board briefing has a one-page summary, two to four scenarios with their warning signs and the decisions each would force, an exposure map and the sources. We keep the language plain and separate what is known from what is assessed. A session with directors can follow. Focused briefings take from 10 business days after written scoping.

We already screen suppliers against sanctions lists with a software tool. What would an OSINT supply chain risk assessment add on top of that for us?

Screening tells you whether a name is on a list. An assessment tells you who owns and controls the supplier, whether a listed person sits behind a chain of companies, whether the supplier buys from or ships through listed parties, and whether its trading pattern makes sense. Under the OFAC 50 percent rule, entities majority owned by blocked persons are blocked even when they are not named.

I'm responsible for a logistics network across several countries and want early warning of strikes, protests and port closures. How would your monitoring work for us?

We agree the locations, routes and triggers that matter, then watch them on our analyst-reviewed monitoring platform, which updates hourly. Analysts check alerts before they reach you, so each one says what happened, how reliable the report is and which of your assets is affected. Monitoring works best after a short assessment that sets the triggers and thresholds.

Can you visit our suppliers' factories or interview their workers as part of the risk assessment, or is the work entirely desk-based?

The assessment is desk-based and uses public and commercially available information. We do not run factory audits or interview workers, because that needs qualified on-site auditors and careful protection of the people involved. What we provide is the map of where risk is likely and which suppliers need on-site verification, so you can direct audits where they matter most.

How quickly can you deliver an OSINT risk assessment on a new market we're considering, and what affects the timeline and the cost?

A focused assessment of one market or a short supplier list takes from 10 business days; a full supply chain review can take up to about a month. Timing and cost depend on the number of countries and suppliers, how deep the tiers go and how transparent local registries are. You receive a fixed quote after written scoping, and urgent delivery adds 50%.