Country and market risk
Political stability, regulatory and enforcement trends, sanctions regimes, security conditions and how they affect your sites, staff and contracts.
An OSINT risk assessment shows which countries, suppliers and events could disrupt your business, and how exposed you already are. We map supply chains beyond the first tier, test them for forced-labor and sanctions exposure, watch for events that change the picture and brief your board on the scenarios that matter.
An OSINT risk assessment uses public and commercially available information, such as registries, trade and customs data, sanctions lists, regulatory actions, media and local reporting, to judge the risk a country, supplier or event poses to your operations. OSINT-S delivers it as a one-off assessment of a market or supply chain, ongoing event monitoring, or a scenario briefing for your board.
Trade conflict, sanctions and forced-labor rules now hit supply chains directly, and directors are expected to understand the exposure before it becomes a loss.
The World Economic Forum's Global Risks Report 2026, based on a survey of more than 1,300 leaders, ranks geoeconomic confrontation as the top risk over the next two years, covering challenges to trade, investment, supply chains and access to natural resources (WEF, January 2026). For most companies that risk does not arrive as a headline. It arrives as a detained shipment, a supplier that suddenly appears on a list, a tariff that changes the cost of a product line, or a strike or protest that closes a port.
The board's question is rarely "what will happen in the world?" It is "where are we exposed, how badly, and what would we do?" That is the question an assessment answers.
Six areas, from the country you operate in to the supplier three tiers down, each tied to a decision you have to make.
Political stability, regulatory and enforcement trends, sanctions regimes, security conditions and how they affect your sites, staff and contracts.
Who your suppliers' suppliers are, who owns them, and where their goods and inputs come from.
Supplier due diligence →Links to high-risk regions, entities named by regulators, and goods flagged by official lists.
Listed owners, 50% ownership chains, intermediaries and trading patterns that need review.
KYC and AML →Unrest, strikes, regulatory actions, disasters and security incidents near your sites and routes, verified before you are alerted.
Short, sourced briefings on plausible scenarios, their triggers and the decisions each would force.
US import rules already put the burden of proof on importers, and the EU ban applies from 14 December 2027; both require evidence about suppliers you may never have met.
| Rule | Status | What it means for buyers |
|---|---|---|
| US Uyghur Forced Labor Prevention Act (UFLPA) | Rebuttable presumption in effect since 21 June 2022 (CBP) | Goods made wholly or in part in the Xinjiang region, or by an entity on the UFLPA Entity List, are presumed barred from import unless the importer shows by clear and convincing evidence that no forced labor was used |
| EU Forced Labour Regulation (EU) 2024/3015 | In force since December 2024; applies from 14 December 2027 (EUR-Lex, European Commission) | Products made with forced labor may not be sold in or exported from the EU; authorities investigate and can order withdrawal. The Commission published guidelines in June 2026, and member states must notify penalty rules by 14 December 2026 (Sidley) |
| US Department of Labor list | 2024 edition: 204 goods from 82 countries and areas (DOL) | A starting point for which product and country combinations need closer review |
The scale is large: the ILO estimates that 27.6 million people were in forced labor on any given day in 2021 (ILO, 2024). Supplier questionnaires and audit certificates rarely reach the tiers where the risk sits. Open sources can: corporate registries, shipping and customs records, company websites and filings, local media, NGO and academic research, and regulator lists. We use them to map who supplies whom and flag the links that need evidence.
Screening finds names; an assessment finds the owners, intermediaries and patterns behind them.
Under the OFAC 50 percent rule, entities owned 50% or more in aggregate by one or more blocked persons are themselves blocked, even if they never appear on a list (OFAC). The same logic applies to supply chains: a supplier with a clean name can still be controlled by a listed person, buy from a listed producer, or ship through an intermediary that exists to hide either.
We trace ownership through registries and filings, compare addresses, directors and contact details across related companies, and look for trading patterns that make no commercial sense. Where a counterparty needs a full background, the work continues as a company investigation. For regulated firms, the findings support your screening and due diligence files; see also OSINT for financial services.
Start from the decision, map exposure, collect and verify, then rate the risk and agree what would change the rating.
No single tool covers geopolitics; the value comes from combining several source types and checking them against each other.
| Source type | What it shows | Limits |
|---|---|---|
| Corporate registries and filings | Owners, directors, related companies, addresses | Coverage and disclosure vary widely by jurisdiction |
| Trade, customs and shipping data | Who ships what to whom, through which ports | Incomplete, often commercial, needs careful matching |
| Sanctions, export and regulator lists | Listed parties, enforcement actions, detention notices | Show names, not ownership or control |
| Media, NGO and academic research | Labor conditions, disputes, local politics | Quality varies; each claim needs verification |
| Commercial satellite imagery | Changes at sites, construction, activity levels | Shows what is visible, not who controls it |
| Event and social media monitoring | Protests, strikes, incidents as they happen | Fast but noisy; early reports are often wrong |
People often ask for the best OSINT tools for geopolitics in 2026. Tools matter less than method: a clear question, sources that can be checked against each other, and an analyst who says how confident the conclusion is.
Monitoring watches the triggers agreed in the assessment, so you hear about the events that affect your sites, suppliers and routes, not every headline.
After the assessment, we can watch the countries, suppliers and locations that matter on our analyst-reviewed monitoring platform, which updates hourly. Alerts are checked before they reach you and say what happened, how reliable the report is, and which of your assets it touches. Pre-incident warning works best with specific triggers: a planned strike at a port you depend on, a court ruling against a key supplier, a new listing that names a supplier's owner.
For staff traveling to higher-risk locations, combine this with travel risk intelligence. Operators of essential services can read more on OSINT for critical infrastructure, and defense-sector supply chains are covered on our defense OSINT research page.
A short, sourced briefing that turns open-source findings into two to four scenarios, their warning signs and the decisions each one would require.
Boards do not need a forecast presented as fact. They need a small number of plausible scenarios, the evidence behind each, the early signals that would show which is unfolding, and what the company would do in each case. A typical briefing has a one-page summary, a scenario table, the exposure map behind it and the sources, followed by a session with directors if you want one.
Work is quoted at a fixed price after written scoping, and if we miss the agreed date the fee goes down. A focused assessment takes from 10 business days; a full supply chain review can take up to about a month, and urgent delivery adds 50%.
It cannot replace on-site audits, legal advice or certainty about the future, and it never puts workers or sources at risk.
If the main question is about one counterparty rather than a market, start with due diligence or browse other OSINT services.
Focused versions of geopolitical risk for specific subjects, deals and situations.
Map the supplier network beyond tier one, expose hidden concentration and chokepoints, and monitor it for events that disrupt supply.
Read more →Tell us the countries, suppliers or decision you are facing. We reply with a written scope, timeline and fixed quote.
Yes. We map your suppliers and, as far as public and commercial data allows, their suppliers, then check owners, addresses and production sites against the UFLPA Entity List, regulator lists and research on high-risk regions. The result is a list of links that need evidence, with sources. It does not prove compliance on its own; your counsel decides whether the evidence meets the clear and convincing standard.
Start with the products and inputs most likely to carry risk: goods and countries flagged by official lists, regions under regulatory attention, and suppliers whose ownership or sourcing you cannot see. We map those chains first, flag the links that need evidence and help you prioritize supplier engagement. Doing this before the regulation applies on 14 December 2027 leaves time to change suppliers if needed.
Yes. A board briefing has a one-page summary, two to four scenarios with their warning signs and the decisions each would force, an exposure map and the sources. We keep the language plain and separate what is known from what is assessed. A session with directors can follow. Focused briefings take from 10 business days after written scoping.
Screening tells you whether a name is on a list. An assessment tells you who owns and controls the supplier, whether a listed person sits behind a chain of companies, whether the supplier buys from or ships through listed parties, and whether its trading pattern makes sense. Under the OFAC 50 percent rule, entities majority owned by blocked persons are blocked even when they are not named.
We agree the locations, routes and triggers that matter, then watch them on our analyst-reviewed monitoring platform, which updates hourly. Analysts check alerts before they reach you, so each one says what happened, how reliable the report is and which of your assets is affected. Monitoring works best after a short assessment that sets the triggers and thresholds.
The assessment is desk-based and uses public and commercially available information. We do not run factory audits or interview workers, because that needs qualified on-site auditors and careful protection of the people involved. What we provide is the map of where risk is likely and which suppliers need on-site verification, so you can direct audits where they matter most.
A focused assessment of one market or a short supplier list takes from 10 business days; a full supply chain review can take up to about a month. Timing and cost depend on the number of countries and suppliers, how deep the tiers go and how transparent local registries are. You receive a fixed quote after written scoping, and urgent delivery adds 50%.
Sources checked 7 October 2026. Figures about third-party firms and tools are as published by them or by the cited source on that date.