Quick Read
SPK DDMS2000:2026 Section 6.4.7 prohibits organisations from applying public country risk indices directly to their due diligence programmes without adapting them to their own business model, sectors, and risk appetite. A generic index reflects an assessment for an unspecified average organisation and cannot serve as a traceable likelihood and consequence assessment specific to your operations. Organisations must document how any public index input has been weighted, adjusted, or supplemented to reflect their actual footprint and risk tolerance.
Why This Whitepaper Exists
It is common practice for a jurisdiction risk factor in a due diligence programme to consist of a single lookup: take a publicly available country risk index, plug its rating straight into the tiering model, and move on. This is fast, defensible-looking, and almost never actually correct. A public index reflects a general assessment for an average or unspecified organisation. It does not reflect the specific sectors an organisation operates in, the nature of its actual presence in a given country, or that organisation's own risk appetite. SPK DDMS2000:2026 addresses this directly at Section 6.4.7, and this whitepaper sets out what adapting a public index actually involves.
A public index reflects a general assessment for an average or unspecified organisation; it does not, on its own, reflect the specific sectors the organisation operates in, the nature of its activities in a given country, or the organisation's own risk appetite and tolerance.
What the Standard Actually Says
Section 6.4.7 requires the organisation to document and justify the methodology it uses to assess country or jurisdiction risk, and prohibits adopting a publicly available country risk index or list as the jurisdiction risk factor without adapting it to the organisation's own business. Where a public index is used as an input, the organisation must document how it has been weighted, adjusted, or supplemented to reflect its own footprint and risk tolerance — not applied with its ratings unmodified.
This connects directly to the risk evaluation principles at Section 6.4.1, which require that a risk factor's contribution to tiering be traceable to a documented likelihood and consequence assessment, not asserted as a bare score. A raw country index rating is, by definition, not that assessment — it is somebody else's assessment, built for a different, unspecified organisation.
Annex A.2, the standard's own illustrative scoring model, reinforces this at the point it introduces the jurisdiction risk factor: the labels shown there are illustrative only, and organisations are directed not to adopt them, or any public index, directly as their own jurisdiction risk factor without the adaptation Section 6.4.7 requires.
Why the Unmodified Index Is a Trap, Not a Shortcut
A public country risk index typically measures something specific — perceived public-sector corruption, sanctions exposure, financial crime typologies, or a blend of factors chosen by the index's own methodology. None of these measures is the same question as the one a due diligence programme actually needs answered: what is the risk to this organisation, doing this activity, in this country, given this organisation's own risk appetite.
Two organisations operating in the same country can face materially different actual risk. One may have no local presence and purely arm's-length trade; the other may hold government contracts, employ local staff, and operate through a joint venture. A single index rating cannot distinguish between them, and applying it unmodified to both produces a jurisdiction risk factor that is simultaneously too conservative for one organisation and not conservative enough for the other.
What Adapting an Index Actually Involves
Section 6.4.7 does not require organisations to build a country risk methodology from nothing. It requires that a public index, where used, be treated as a starting input rather than a finished answer. The questions below illustrate the kind of adaptation the clause is asking for.
Adjustment dimension | Question to ask |
|---|---|
Sector relevance | Does the public index measure risk in sectors relevant to our activity in this country, or a general average across all sectors? |
Nature of presence | Do we have a physical presence, government contracts, or local employees here, or is our exposure limited to arm's-length trade? |
Transaction type | Does the index reflect the specific risk of the transaction type we engage in — procurement, licensing, permitting — or a broader measure not specific to our activity? |
Risk appetite fit | Does the index's rating threshold align with where our own risk appetite under Section 6.6 draws the line, or does it use a different scale entirely? |
Currency | When was the index last updated, and does it reflect the country's current position rather than a historical snapshot? |
Supplementation | What organisation-specific information do we hold — prior findings, local counsel input, sector-specific intelligence — that the index cannot reflect? |
The output of this exercise should be a documented methodology — not a single conversation — that a reviewer or certification assessor can trace from the public index's raw rating through to the organisation's own adjusted jurisdiction risk factor, with the reasoning for each adjustment recorded.
Where This Connects to the Rest of the Standard
Jurisdiction risk does not operate in isolation. It feeds directly into the risk appetite and tolerance determination at Section 6.6, which requires the organisation to formally decide how much residual risk it is willing to accept, and where it is not willing to accept any residual risk at all regardless of commercial pressure. An unmodified index rating that does not reflect the organisation's actual risk appetite will produce a tiering methodology systematically out of step with the organisation's own governance decisions — either escalating relationships the organisation's leadership would in fact accept, or clearing relationships it would not.
It also connects to the enhanced due diligence obligation at Section 6.3.5, which requires heightened due diligence for subjects and transactions connected to conflict-affected or high-risk areas, consistent with the OECD Due Diligence Guidance's specific recommendations for such areas. A jurisdiction risk factor built solely from an unmodified public index is unlikely, on its own, to correctly identify every conflict-affected or high-risk area relevant to the organisation's specific activity.
Common Gaps Worth Checking
The jurisdiction risk factor in the tiering model is a direct, unweighted lookup against a single public index, with no documented adaptation.
The same jurisdiction rating is applied uniformly across all modules and subject types, regardless of whether the organisation's actual presence or activity in that country varies by module.
The index used has not been reviewed for currency, and may reflect an outdated assessment of the country in question.
No one can explain, on request, why the organisation's jurisdiction rating for a given country sits where it does, beyond pointing to the index itself.
How Speeki Sentinel Certification Assesses This
Certification against SPK DDMS2000:2026 tests whether the organisation's jurisdiction risk methodology is genuinely its own — documented, justified, and traceable to the organisation's specific footprint and risk appetite — rather than a relabelled public index. An assessor will expect to see the adaptation reasoning, not only the final rating.
Speeki Sentinel is the certification product through which this assessment is delivered. Organisations may build and document their own jurisdiction risk methodology independently of Sentinel; certification is a separate, optional step available once an organisation believes its methodology is ready to be independently tested.
Speeki is an accredited certification body. For current information on the specific accreditations Speeki holds and their scope, please refer to speeki.com rather than relying on this whitepaper, as accreditation status and scope are maintained centrally and can change.
Closing Note
A public country risk index is a reasonable place to start a jurisdiction risk methodology. It is not a reasonable place to finish one. Section 6.4.7 asks organisations to do the work of making a general, third-party assessment specific to their own business — and to be able to show, on request, exactly how they did it.