As an international oil, gas, and chemicals company with operations extending from hydrocarbon exploration and production through to the trading and marketing of mineral oil products, chemical products, and natural gas, OMV is exposed to a variety of risks – including market and financial risks, operational risks, and strategic risks with the inherent ESG risks. The Group’s risk management processes focus on the identification, assessment, and evaluation of such risks and their impact on the Group’s financial stability and profitability. The objective of these activities is to actively manage risks based on the Group’s risk appetite and defined risk tolerance levels in order to achieve OMV’s long-term strategic goals.
Risk Management Governance
Effective risk governance is crucial for successfully navigating through uncertainties inherent to the nature of OMV’s operations. At the Supervisory Board level, the Audit Committee controls the implementation and effectiveness of the risk management processes at OMV. By utilizing the expertise within the Audit Committee and staying adaptable through ongoing education, the Supervisory Board maintains its commitment to robust risk governance. The Executive Board proactively oversees and enhances OMV’s risk management processes and ensures a strong risk culture across OMV. A cross-functional Risk Committee chaired by the CFO with senior management members ensures that the risk management process effectively captures and manages material risks across the Group. OMV has an effective Corporate Risk Management function within the CFO area that reports directly to the Executive Board and is independent from the business lines.
It is OMV’s view that the Group’s overall risk is significantly lower than the sum of the individual risks due to its integrated nature and the fact that various risks partially offset each other. The balancing effects of industry risks, however, can often lag or weaken over time. OMV’s risk management activities therefore focus on the net risk exposure of the Group’s existing and future portfolio. The interdependencies and correlations between different risks are also reflected in the Company’s consolidated risk profile. Risk management and insurance activities are centrally coordinated at the corporate level by the Treasury and Risk & Insurance Management departments. These departments ensure that well-defined and consistent risk management processes, tools, and techniques are applied across the entire organization. Risk ownership is assigned to the managers who are best suited to overseeing and managing the respective risk. The overall objective of the OMV risk policy is to safeguard the cash flows required by the Group and to maintain a strong investment-grade credit rating in line with the Group’s risk appetite.
Financial and non-financial risks are regularly identified, assessed, and reported through the Group’s Enterprise-Wide Risk Management (EWRM) process. Its main purpose is to deliver value through risk-based management and decision-making, which is ensured by applying a “three lines of defense” model (1. business management, 2. risk management and oversight functions, 3. internal audit). The assessment of financial, operational, and strategic risks helps the Group leverage business opportunities in a systematic manner. This systematic approach ensures that OMV’s value grows sustainably. Since 2003, the EWRM system has helped enhance risk awareness and improve risk management skills across the entire organization, including at subsidiaries in more than 20 countries. OMV is constantly enhancing the EWRM process based on internal and external requirements, for instance developing ESG (Environmental, Social, and Governance) reporting standards and frameworks. OMV’s EWRM process has been set up in accordance with the ISO 31000 standard and is facilitated by a Group-wide IT system supporting the established individual process steps: risk identification, risk analysis, risk evaluation, risk treatment, reporting, and risk review through continuous monitoring of changes to the risk profile. The overall risk resulting from the bottom-up risk management process is computed using Monte Carlo simulations and compared against planning data. This is further combined with a top-down approach from the senior management view to capture risks associated with the Group’s strategy. The process also includes companies that are not fully consolidated. The EWRM process uses common risk terminology and language across OMV to facilitate effective risk communication, whereby ESG risks play a key role in the OMV risk taxonomy.
Twice a year, the results of this process are consolidated and presented to the Executive Board and the Audit Committee of the Supervisory Board. In compliance with the Austrian Code of Corporate Governance, the effectiveness of the EWRM system is evaluated by an external auditor on an annual basis. The key financial and non-financial risks identified with respect to OMV’s mid-term planning are:
- Financial risks, including market price risks and foreign exchange risks
- Operational risks, including all risks and impacts related to physical assets, production risks, project risks, personnel risks, IT risks, HSSE, and regulatory/compliance risks
- Strategic risks, for example those arising from the energy transition, changes in technology, risks to reputation, or political uncertainties, including sanctions
For further details on risk management and the use of financial instruments, please refer to the Consolidated Financial Statements (Note 29).
Financial Risks
Market price and financial risks arise from volatility in the prices of commodities, including the market price risks from European Emission Allowances, foreign exchange (FX) rates, and interest rates. Also of importance are credit risks, which arise from the inability of a counterparty to meet a payment or delivery commitment. As an oil, gas, and chemicals company, OMV has a significant exposure to oil, natural gas, and chemicals prices. Substantial FX exposure includes the USD, RON, NOK, NZD, and SEK. The Group has an economic net USD long position, mainly resulting from oil production sales. The comparatively less significant exposure to RON, NOK, NZD, and SEK originates from expenses in local currencies in the respective countries.
Management of Commodity Price Risk, FX Risk, and European Emission Allowances
The analysis and management of financial risks arising from foreign currencies, interest rates, commodity prices, European Emission Allowances, counterparties, liquidity, and insurable risks are consolidated at the corporate level. Market price risk is monitored and analyzed centrally in respect of its potential cash flow impact using a specific risk analysis model that considers portfolio effects. The impact of financial risks (e.g., commodity prices, currencies) on OMV´s cash flow and liquidity is reviewed regularly by the Risk Committee, which is chaired by the CFO and comprises the senior management of the business segments and corporate functions.
In the context of commodity price risk and FX risk, the OMV Executive Board decides on hedging strategies to mitigate such risks whenever deemed necessary. OMV uses financial instruments for hedging purposes to protect the Group’s cash flow, for example from the potential negative impact of falling oil and natural gas prices in the Energy division. In the Fuels & Feedstock and Chemicals businesses, OMV is especially exposed to volatile refining and chemicals margins, natural gas prices, and CO2 emissions certificates, as well as inventory risks. Corresponding optimization and hedging activities are undertaken in order to mitigate these risks. They include margin hedges as well as stock hedges. An optimization, trading, and hedging risk control governance system defines clear mandates including risk thresholds for such activities.
Management of Interest Rate Risk
To balance the Group’s interest rate portfolio, loans can be converted from fixed to floating rates and vice versa according to predefined rules. OMV regularly analyzes the impact of interest rate changes on interest income and expenses from floating rate deposits and borrowings.
Management of Credit Risk
Significant counterparty credit risks are assessed, monitored, and controlled at the Group and segment level using predetermined credit limits for all counterparties, banks, and security providers. The procedures are governed by guidelines at Group level. In light of a challenging geopolitical and economic environment with volatile commodity prices, high interest rates, and distorted supply chains, special attention is paid to early warning signals like changes in payment behavior.
Operational Risks
The nature of OMV’s business operations exposes the Group to various health, safety, security, and environmental (HSSE) risks. Such risks include the potential impact of natural disasters, as well as process safety and personal security events. Other operational risks comprise risks related to the delivery of capital projects or legal/regulatory non-compliance. All operational risks are identified, analyzed, monitored, and mitigated in accordance with the Group’s defined risk management process. The control and mitigation of assessed risks take place at all organizational levels using clearly defined risk policies and responsibilities. The key Group risks are governed centrally to ensure the Group’s ability to meet planning objectives through corporate directives, including those relating to health, safety, security, environment, legal matters, compliance, human resources, and sustainability.
Project Risks
In implementing its Strategy 2030, OMV invests in both organic and inorganic growth projects following a mature project risk management process, identifying, analyzing, and monitoring project risks on a regular basis. OMV has vast experience in managing major capital projects and mitigating project risks.
OMV may experience operational, political, technological, or other risks beyond its control, both its own and belonging to its contractual partners, which may delay or hinder the progress of its projects. By way of an example, the execution of major onshore and offshore projects in Romania, Norway, and the UAE may be affected by changes to the respective regulatory or fiscal frameworks, by the unavailability of contractors, or the lack of qualified staff. Project costs may be negatively impacted by price inflation, labor shortages, or the disruption or reorganization of supply chains. Projects, particularly those related to recycling and sustainable fuels and feedstocks, may be affected by insufficient availability of required feedstock supply, by the inability to commercially scale up new technologies, or by the lack of regulatory clarity. In new business areas in particular, OMV may more often invest through partnerships and joint ventures, which may expose the Company to increased governance and credit risks and may negatively impact project execution. The effect of any of these risks may have a material adverse impact on OMV’s business, results of operations, and financial condition.
IT Risks
As OMV’s activities rely on information technology systems, the Group may experience disruption based on large-scale cyber events. Therefore, an Information Security Management System (ISMS) with related security controls is implemented across the Group IT services to protect information and IT assets that store and process information. IT-related risks are assessed, monitored regularly, and addressed with dedicated mitigations or managed by comprehensive information and security programs across the organization. Operational technology related risks are reflected in the assessment of process safety risks. Additionally, OMV recognizes the emergence of AI-related risks and is actively integrating measures within existing security governance frameworks and controls to address potential security exposures and vulnerabilities associated with artificial intelligence.
Strategic Risks
In order to identify strategic risks that might have potentially long-term effects on the Company’s objectives, OMV continuously monitors its internal and external environment.
Geopolitical and Regulatory Risks
OMV thoroughly monitors geopolitical developments, including the ongoing Russian war on Ukraine and any additional sanctions and countersanctions resulting from it, as well as developments in Israel, and Syria that have raised concerns about regional stability and their potential impact on OMV’s business activities. Nevertheless, it is important to note that, as it currently stands, OMV´s operations in the MENA region remain unaffected by these developments.
The Company regularly reviews the impact of such geopolitical developments on its business activities. Continued and/or intensified disruptions in Russian commodity flows to Europe, for example, could result in further increases in European energy prices. Sanctions on Russia and countersanctions issued by Russia could lead to further disruptions in global supply chains and shortages of products related to energy, raw materials, agriculture, and metals, and consequently lead to further increases in operational costs.
In December 2024, OMV terminated its gas supply contract to Austria with Gazprom Export with immediate effect following fundamental breaches of contract by Gazprom Export. This termination ended the contractual relationship and significantly reduced the Group’s risk exposure in relation to Russia. Prior to this and in anticipation of the disruption of all Russian natural gas supplies to Austria due to the discontinuation of the gas transit agreement between Ukraine and Russia, OMV had diversified both gas supply sources and routes to ensure energy supply to its customers. Having bought additional transportation capacities to Austria at the transfer points Oberkappel (pipeline from Germany) and Arnoldstein (pipeline from Italy) in July 2023 as well as securing additional supplies, OMV was well prepared for this situation. Due to warmer than average weather in Europe, increased renewable power generation, and elevated gas price levels, gas consumption households and industry was reduced in 2024. Storage levels were higher in Central Europe compared to previous years. OMV continues to closely monitor developments and regularly evaluates the potential impact on the Group’s cash flow and liquidity position.
High volatility in natural gas prices can potentially lead to peak liquidity demands to satisfy margin calls for exchange trading activities at short notice. OMV has unused committed and uncommitted credit facilities to meet such short-term requirements if needed. OMV responds to the situation with targeted measures to safeguard the Company’s economic stability as well as the secure supply of energy.
In addition to the above-mentioned geopolitical tensions, OMV’s operations are exposed to further geopolitical risks such as the expropriation and nationalization of property, restrictions on foreign ownership, civil strife and acts of war or terrorism, and political uncertainties, for example in Libya, Yemen, or Tunisia, as well as other countries where OMV operates and has financial investments. However, OMV has extensive experience in dealing with the political environment in emerging economies. Possible regulatory changes may also lead to disruptions or limitations in production or an increased tax burden. OMV continuously observes political and regulatory developments in all markets that affect OMV’s operations. Country-specific risks are assessed before entering new countries.
Macroeconomic Risks
Geoeconomic fragmentation, trade restrictions, and disruptions to global supply chains could lead to further cost increases for OMV. Coupled with high interest rates, this situation has the potential to also negatively impact economic growth, which in turn could affect demand for OMV’s products.
Climate Change-Related Risks
OMV consistently evaluates the Group’s exposure to risks related to climate change, in addition to the market price risk from European Emission Allowances. Such risks comprise the potential impact of acute or chronic events like more frequent extreme weather events, systemic changes to our business model due to a changing legal framework, or substitution of OMV’s products due to changing consumer behavior. OMV recognizes climate change as a key global challenge, and therefore integrates the related risks and opportunities into the development of the Company’s business strategy. Measures implemented to manage or mitigate such risks are set out in the relevant sections of this report, particularly in the Sustainability Statement and Strategy.
Business Transformation Risks
OMV’s transformation into a leading provider of sustainable fuels, chemicals, and materials, as well as sustainable energy solutions, is influenced by a variety of uncertainties. Such risks include the availability of skilled employees, technology and scale-up risks, availability of sustainable feedstock in sufficient quality and quantity, and governance risks related to joint ventures and partnerships.
Personnel Risks
Through systematic employee succession and development planning, OMV’s People & Culture department aims to develop and attract suitable managerial employees to meet future growth requirements and mitigate personnel risks.
Sustainability Impacts, Risks and Opportunities
Well embedded in the Enterprise-Wide Risk Management process, OMV places special emphasis on five sustainability focus areas: Climate Change, Natural Resources Management, People and their Human Rights, Health and Safety, and Ethical Business Practices. The established risk assurance model briefly described above has been adapted to ensure the effective management of the potential environmental, social, or governance impacts, risks, and opportunities.
For further details on environmental, social, or governance-related risks, please refer to the dedicated chapters in the Sustainability Statement.
OMV Group Security
In 2024, OMV Group Security monitored an increasingly unstable geopolitical environment. According to the Uppsala Conflict Data Program, more than 50 state-based conflicts are currently ongoing worldwide – the highest number since World War II. Global security is particularly affected by the ongoing conflicts in Ukraine and the Middle East. Consequently, OMV Group Security has continued to invest significant resources in ensuring resilience and security in areas previously considered low risk, while maintaining focus on assets in the Middle East and North Africa.
In addition to the challenges of operating securely in Yemen, Tunisia, and Libya, the persistent threat of terrorist attacks and hybrid warfare in Europe has not diminished. Political extremism, organized crime, and the increasing convergence of cyber risks with physical threats have necessitated the OMV Group Security department’s unwavering focus on a robust yet flexible security strategy. This strategy enables OMV to continue operating in dynamic environments with asymmetric threats.
OMV´s internal Security Management Standard lays out a comprehensive range of security regulations, plans, procedures, measures, and systems. The document utilizes the IOGP best practice guidelines, along with other industry best practice (ASIS and UK Security Institute), to enable OMV to more effectively detect, deter, protect against, prevent, record, and investigate threats.
Management and Due Diligence Processes
OMV has a unique, agile, and proven security management system that is regularly reviewed, amended, or enhanced as the situation requires. The philosophy of collecting security information and assessing it as a preventive security instrument remains a fundamental principle of OMV´s Security strategy. This approach allows us to anticipate or respond instantly to a broad spectrum of geopolitical events, regional conflicts, and isolated incidents. Effective interaction with government and local security agencies further enhances this approach by providing reliable corroboration of facts on the ground.
OMV’s security risk assessment platform continues to provide real-time oversight of OMV’s asset risk exposure levels and can be quickly adjusted in response to geopolitical or security events, as well as enabling the dissemination of security-critical information in real time.
To ensure the effectiveness and appropriateness of security practices within OMV’s business units, the OMV Group Security function conducts regular audits. These occur annually for those ventures deemed as high risk; for 2024 these were Tunisia, Libya, and Yemen. Two other major audits are conducted annually, with business units being chosen based on operational requirements. In 2024, the selected areas were OMV Abu Dhabi and OMV Libya, including field-based operations, as well as a detailed look at security operations in Tripoli and Benghazi.
Terms of Reference are agreed with the business unit prior to commencing the audit, a thorough review then takes place including site visits, interviews, document analysis, and observations. An audit report is then drafted, shared, agreed, and published. The report will include SMART actions, with the entire process being tracked via OMV’s HSSE reporting tool.
The OMV Group Security department continued to deliver operational support to OMV ventures globally, as well as surge capacity during security challenges. In high-risk countries, OMV also utilized dedicated Country Security Managers and Asset Protection Experts on site to enhance security via additional and, where appropriate, local expertise.
Security and Human Rights
We are committed to respecting human rights and international humanitarian law (IHL) while maintaining the security and safety of our staff and operations. We achieve this by acting in a manner consistent with all relevant laws and international standards or initiatives, including the Voluntary Principles on Security and Human Rights (VPs) and the International Code of Conduct for Private Security Service Providers (ICoC). This applies specifically but not exclusively to our interactions with public and private security forces. This ambition is a part of our business acumen, though it is not yet fully aligned with the European Sustainability Reporting Standards (ESRS). For more information about our human rights approach, please see the Sustainability Statement (S1 Human Rights).
OMV applied for membership of the Voluntary Principles on Security and Human Rights in 2023. Since then, we have been considered an applicant member and been actively engaged with the initiative, e.g., during the Annual Forum in Washington and during dedicated Q&A calls with the secretariat and active members from the Corporate, Government, and NGO pillars, all as part of the application process. OMV continues to abide by the initiative’s guidelines, with the VPs providing a foundational pillar for all our security operations globally.