Taxation, permits and justice delivered by armed groups create compliance exposure that a security policy alone cannot manage. This is number 15 in our standing watch list of security dilemmas, and it is written for the people who have to make a decision this week rather than for the commentary market. Our assessment is set out below against the six questions we apply to every INGO Advisory analysis.
1. What happened
The current phase of this dilemma is driven by Insurgents, militia and criminal networks exercising governance. The record we hold, drawn from ACLED event data, UN OCHA and ReliefWeb reporting, and official statements from the authorities concerned, shows sustained activity across Sahel / Horn of Africa / Great Lakes / Mozambique rather than a single decisive event. We do not restate casualty figures we cannot corroborate; where the record is thin we say so.
2. What is changing
The trend, at moderate to high confidence, is that the drivers behind this dilemma are becoming structural rather than episodic. Two years ago an operations manager could treat it as a background condition. It now belongs in the country risk register with named owners, review dates and defined triggers.
3. Why it matters
- Personnel: exposure shifts from frontline areas into routine movement, accommodation and airport transfers.
- Access: programme delivery slows through permits, escorts and route closures rather than outright refusal.
- Assets and supply chain: lead times lengthen, insurance terms tighten and single-source dependencies surface.
- Reputation and compliance: payments, partners and escorts create scrutiny long after the incident closes.
4. Where the exposure sits
Exposure concentrates in Multiple theatres and across Sahel / Horn of Africa / Great Lakes / Mozambique. We name the corridor, the port and the district in client-specific assessments; generic references to "the region" hide the decision. Organisations with staff, partners or supply chains in these areas should assume the assessment applies to them directly.
5. What organisations should watch
- Force posture changes: new deployments, withdrawals or a change in who holds a checkpoint.
- Administrative signals: registration reviews, visa processing times, import clearance delays.
- Market signals: fuel availability and price, currency movement, freight and insurance quotations.
- Information environment: network restrictions, coordinated messaging campaigns naming organisations or staff.
- Displacement: new arrivals in an area, or a route emptying, ahead of reported violence.
6. What organisations should do
- Re-baseline the country risk assessment against this dilemma and record the date it was done.
- Set movement rules to the threat level below, with the authorisation level written into policy.
- Test the crisis plan against the most likely scenario here, using the roster that would actually take the call.
- Confirm medical, communications and relocation arrangements before tempo builds, not during it.
- Screen counterparties, escorts and landlords; in several of these theatres due diligence is the security control.
Threat level and operational meaning
We assess this dilemma at SEVERE on the United Kingdom five-tier scale. An attack is highly likely. The rating is a decision trigger, not a description: it sets the authorisation level for movement, the reporting rhythm and the review frequency.
A rating that does not change what somebody does on Monday is commentary, not risk management.
Reporting basis
This analysis was written by Mowlid Ali for INGO Advisory. It draws on ACLED event data, UN OCHA and ReliefWeb humanitarian reporting, Insecurity Insight incident monitoring, official government and UN statements, and local media in Sahel / Horn of Africa / Great Lakes / Mozambique, triangulated against our own field engagement. The judgement is ours and is verified against multiple independent streams; the underlying reporting remains the property of the publishers named in the citations below.