To read this content please select one of the options below:

A framework for enterprise risk identification and management: the resource-based view

Birendra K. Mishra (School of Business, University of California Riverside, Riverside, California, USA)
Erik Rolland (College of Business Administration, California State Polytechnic University, Pomona, California, USA)
Asish Satpathy (Department of Information Systems, W. P. Carey School of Business, Arizona State University, Tempe, Arizona, USA)
Michael Moore (College of Business Administration, Loyola Marymount University, Los Angeles, California, USA)

Managerial Auditing Journal

ISSN: 0268-6902

Article publication date: 7 January 2019

Issue publication date: 6 March 2019

3483

Abstract

Purpose

This study aims to examine the factors influencing enterprise risk management and propose a framework for identifying and explaining the components of enterprise risk management. To enable broader analytical thinking about risk factors, the framework utilizes the resource-based theory to link various classes of risks to an extended set of organizational resources.

Design/methodology/approach

The paper opted for an exploratory study using a sample from an online survey. The survey subjects were recruited from the membership database of the American Institute of Certified Public Accountants, focusing primarily on CFOs. The survey consisted of six sections: demographics, a section on each of the four risk types included in ERM: strategic risk, operational risk, financial risk and hazard risk, and exit questions (where very general questions about ERM were asked). The survey yielded a data set of 227 valid responses.

Findings

Using the associated sample survey data, the paper provides empirical validation of the proposed framework that managers in any organizations could use to identify and manage risks.

Research limitations/implications

The proposed model does have limitations that predominantly exist from the fact that human judgment in decision-making is not always data-driven, and hence, a proper risk exposure could be ignored based on pure arguments of cost and benefits from domain experts. Therefore, researchers and practitioners are encouraged to test the proposed framework further.

Practical implications

Risk exposure is not a snapshot event in an organization’s time horizon. Rather, risk identification is an ongoing process and the proposed framework allows organizations to handle increasing complex risks and/or identifying them based on how the organizational resources may be exposed over time. Managers could use a form of risk control analytics (monitoring dashboard of all identified risks under each interaction sets on a regular basis) to become more proactive in managing risk or exploiting opportunities across enterprise.

Originality/value

This paper fulfills an identified need to study how enterprise risks exposure can be proactively assessed and managed.

Keywords

Citation

Mishra, B.K., Rolland, E., Satpathy, A. and Moore, M. (2019), "A framework for enterprise risk identification and management: the resource-based view", Managerial Auditing Journal, Vol. 34 No. 2, pp. 162-188. https://doi.org/10.1108/MAJ-12-2017-1751

Publisher

:

Emerald Publishing Limited

Copyright © 2018, Emerald Publishing Limited

Related articles