All development co-operation is exposed to risks. Acknowledging and managing risks allows development co-operation actors to achieve their objectives. Effective risk management enables stakeholders to improve performance, encourages innovation and supports the achievement of objectives.
Abstract
What is the issue and why does it matter?
Copy link to What is the issue and why does it matter?The purpose of risk management is the creation and protection of value. It improves performance, encourages innovation and supports the achievement of objectives. All development co-operation is exposed to risks. Acknowledging and managing risks allows development co-operation actors to achieve their objectives. Otherwise, poor risk management can:
do harm, slowing progress towards the Sustainable Development Goals (SDGs)
lead to failure, wasting resources and damaging reputations
require additional human and financial resources or cause delays
endanger staff or partner safety
undermine support for development co-operation.
Figure 1. Theory of change
Copy link to Figure 1. Theory of change
What are the core principles and standards?
Copy link to What are the core principles and standards?Risks should be managed, not avoided (Busan 18.a)
Risk management should be an integral part of governance and decision-making (ISO 31000)
Figure 2. Basic standards
Copy link to Figure 2. Basic standardsFour key steps for risk management
Note: Section D.2 of the OECD DAC Peer Review Analytical Framework sets out the expectations of the Development Assistance Committee (DAC) on risk management. This relates to the OECD Council Recommendation on managing risks of corruption for development co-operation actors, and the DAC Recommendation on ending sexual exploitation, abuse, and harassment.
How does it work in practice?
Copy link to How does it work in practice?1. Leadership and policy. Policy frameworks clearly state the need to actively manage risks at all levels (corporate, portfolio, project) and of all types (political, operational, financial, security, reputational). Policy frameworks outline the approach to identifying and balancing different risks with the potential rewards.
The Austrian Development Agency has a Risk Management Policy that states the objective, scope and processes of its risk management. It makes explicit that its objectives are not to avoid risks, shift responsibility or focus only on risks.
The Australian Department of Foreign Affairs and Trade’s risk management policy articulates a strong risk-based management approach. The policy incentivise risk taking to increase effectiveness and achieve stronger outcomes.
2. Institutional management. Responsibility for managing risks is clearly assigned, including the capacity to escalate and de-escalate. Internal and external oversight bodies review risk management comprehensively. Measures are openly discussed and decisions are clear. Effective communication underlines the need to take risks and explains how risk management works in practice.
Ireland has clearly assigned risk responsibilities for each level of authority and created the position of Chief Risk Officer at management level. A multi-layered system of internal and external oversight assesses the quality of risk management, and is not limited to financial risk.
Sweden has evaluated risk management from the perspective of Sida’s partners.
Finland’s Ministry of Foreign Affairs 2021 risk management policy integrates risk procedures and assesses risks throughout the project cycle.
3. Staff and partner capabilities. Codes of conduct along with training, guidance and advice on risk management are provided to staff and, as needed, partners. There are rewards for good risk management and transparent reporting with no penalty for assuming residual risk (if deemed acceptable), should risk materialise. There is fair risk sharing between development partner and implementer, allowing for flexibility particularly in fragile contexts.
Australia has detailed guidance on its risk management process and specific categories of risk.
In Switzerland risk coaches support each administrative unit to map, assess and manage its own risks.
UNDP offers guidance for staff to identify, assess and monitor risks and provides risk appetite tools to support risk mapping and inform decisions.
Norad’s review of corruption risks and mitigation strategies of development co-operation to Ukraine, offers insights and evidence that can help decision-makers and partners manage conflict- and sector-specific risks.
Belgium’s Fragility Resilience Assessment Management Exercise (FRAME) tool harmonises risk analysis among stakeholders and helps them assess risks and opportunities in contexts facing high fragility, adapt interventions and prevent failure.
4. Processes. Risk management is integrated into general operational processes. Regularly updated risk registers document risks and responses. Mechanisms are in place for internal and external monitoring and reporting (including whistle-blowing). Contracts outline responsibilities for risk management and sanctions for severe violations. Partnering is used for both risk assessment and response.
Switzerland’s Monitoring System for Development-Related Changes assesses political, economic, social, environmental and security risks across projects. The Federal Department of Foreign Affairs’ audits ensure comprehensive oversight and adaptive risk management.
Finland has put in place internal systems for reporting, investigating and tracking suspected cases of misconduct. Its Ministry of Foreign Affairs collects data on the number of misconduct cases reported through an online reporting portal and has differentiated cases by type, for instance reports relating to fiduciary risks or case reports on Sexual Exploitation, Abuse and Harassment (SEAH).
French Development Agency (AFD) has a database of incidents logged as well as a reporting system and an investigation function.
Sweden manages corruption risks through Sida’s Contribution Management Processes and System Software TRAC, which guide risk assessment, impact evaluation and mitigation. In 2024, Sida evaluated its efforts to reduce corruption in partner countries.
Many DAC members conduct or use joint assessments, for example the World Bank’s Country Policy and Institutional Assessments (CPIA) and Public Expenditure and Financial Accountability (PEFA) assessments, and share analyses.
Measuring success
Copy link to Measuring successRisk management is effective if it strikes a balance that helps maximise the achievement of objectives. This means:
focusing attention on the most relevant risks
considering mitigation measures such as capacity-strengthening, insurance and risk sharing, responses at country level (rather than just project level) or jointly with partners (e.g. political dialogue, disaster preparedness, action on anti-corruption and public financial management)
putting the rewards and costs of risk management into perspective
taking a portfolio perspective to balance high and low risk interventions
ensuring that risks are understood and accepted by key stakeholders.
Further information
Copy link to Further informationRisk management - Guidelines, ISO 31000:2018.
OECD resources
Copy link to OECD resourcesOECD Council Recommendation on Managing the Risk of Corruption for Development Co-operation Actors (2016), [OECD/LEGAL/0431].
Report on the Implementation of the OECD Recommendation for Development Co-operation Actors on Managing the Risk of Corruption (2022), [C(2022)175], OECD Council.
OECD DAC Recommendation on Ending Sexual Exploitation, Abuse and Harassment in Development Co-operation and Humanitarian Assistance (2019), Development Assistance Committee.
Managing risks in the public procurement of goods, services and infrastructure (2023), OECD Public Governance Policy Papers, OECD Publishing, Paris.
Risk management and locally led development (2023), Development Co-operation Directorate.
Guidelines for Resilience Systems Analysis: How to Analyse Risk and Build a Roadmap to Resilience (2014), OECD Publishing, Paris.
Rapid Reactions to Corruption (2021), Anti-Corruption Task Team (ACTT), OECD Publishing, Paris.
Managing Risks in Fragile and Transitional Contexts (2012), Conflict and Fragility, OECD Publishing, Paris.
DAC Evaluation Resource Centre (DEReC), OECD [website].
More Framework principles are available on Development Co-operation TIPs • Tools Insights Practices.
Related content
-
29 July 20264 Pages