Accelerate Literature Icon
Want to do a literature review? Try our new Literature Review workflow

Uloga višeg menadžmenta u prirodnim hazardima - slučaj evropske bankarske industrije

  • Abstract
  • PDF
  • Literature Map
  • Similar Papers
Abstract
Translate article icon Translate Article Star icon

The issue of natural hazards is a major area of interest within the field of security and business management. Proper risk management has been found to be fundamental, thus has received considerable attention. However, very little attention has been paid to the role of senior management within an enterprise's risk management framework. This paper seeks to explore this special role in the risk management process, especially when dealing with the risks related to natural hazards. The appropriate role of senior management in managing the risks related to natural hazards is a key issue. The European banking industry's approach is presented, based on the publicly available sector-specific regulations and guidance. Some recommendations are provided to further enhance the key role of senior management in natural hazards. Our result is considered as a solution that can be adopted by enterprises, organisations and institutions in any sector.

Similar Papers
  • PDF Download Icon
  • Research Article
  • Cite Count Icon 1
  • 10.18775/jibrm.1849-8558.2015.81.3002
Enterprise Risk Management Practices in Kenya
  • Apr 1, 2023
  • Journal of International Business Research and Marketing
  • Stanley Chege + 2 more

Enterprise Risk Management (ERM) is a structured and coordinated approach for identifying, assessing, and managing risks faced by an organization. Implementing ERM standards and frameworks has several benefits, including improving focus and perspective on risk. ERM aids in developing leading indicators to detect potential risk events and provide early warning signals. ERM also incorporates key metrics and measurements of risk to improve reporting value and analysis and monitor possible changes in risk vulnerabilities or likelihood. An ERM facilitates an efficient risk management (RM) process, allowing businesses to manage risks efficiently across various departments through a robust risk management framework. This framework includes the related department’s team, working rules, and operational tools, covering all types of risks, including financial, strategic, operational, and accidental losses. The primary advantage of ERM is its ability to create a systematic and intentional process for identifying and addressing risks, treating risk management as a structured exercise where liabilities are addressed as part of a comprehensive framework rather than ad-hoc problem-solving. ISO 31000, NIST risk management framework, and COSO ERM framework are widely used frameworks for managing enterprise risks. Implementing a robust enterprise risk management standard has a positive relationship with business performance.

  • Research Article
  • Cite Count Icon 10
  • 10.1108/tlo-10-2019-0150
Why risk management frameworks fail to prevent wrongdoing
  • Jan 31, 2020
  • The Learning Organization
  • Chris Schmidt

PurposeThe purpose of this paper is to consolidate research in whistleblowing, wrongdoing prevention and enterprise risk management (ERM) frameworks with the goal of creating a more comprehensive and effective framework for the prevention of wrongdoings.Design/methodology/approachA gap analysis based on organizational learning theory (OLT) is performed between the research fields of whistleblowing, wrongdoing prevention and ERM to identify enhancements that are needed for effective wrongdoing prevention.FindingsERM is an incomplete framework for wrongdoing prevention which omits the components of prevention and learning. A culture of continuous learning is required to minimize the experience component of learning and maximizing sharing. Storytelling can be used to protect individuals and provide transparency. The stakeholder dimension must be expanded beyond the borders of the legal entity to include all stakeholders. Every stakeholder experiences the climate of wrongdoing prevention differently, and the evaluation of these different perspectives is essential in establishing a culture of prevention. Personal psychological safety is a critical element in empowering stakeholders to discuss and address wrongdoings. Standards established through professional associations enable innovations to diffuse more quickly throughout society than legislation. Standards and standard setting processes that are able to adapt to changes in societal expectations proactively help organizations to independently protect stakeholders. Global standards are needed to overcome incongruences between countries and cultures.Research limitations/implicationsThe effectiveness of a prevention framework is difficult to measure. Declining incidence of wrongdoing within an institution is an incomplete picture. Rare and severe types of wrongdoing, and their prevention throughout society should require a more concerted, centralized approach which could be modeled upon the health system’s national centers for disease prevention. By combining the dimensions of the learning organization questionnaire(Marsick and Watkins, 2003) and Whistleblowing and Wrongdoing statistics, organizations should be able to develop complex KPIs and be able monitor their development over time. Researchers should be able to use the same strategy to confirm the assertions made here will improve the safety and security of all stakeholders.Practical implicationsOrganizations which use ERM frameworks may be unable to effectively prevent wrongdoings and protect stakeholders from the consequences of such wrongdoings. The shortcomings identified here provide specific clear points that organizations can address to be more effective in preventing wrongdoings. Any one of these actions and the scope of their impact within the organization and their environment represent substantial challenges for all stakeholders. Like the ascent of a great mountain, the planning of the each step taken and thorough understanding of the challenges faced along the path to each waypoint are essential to reach the summit and the achieve the objective.Social implicationsThis paper advocates for changes that may take decades or generations to fully accept: inter-organizational sharing; stronger use of guidelines instead of legislation; and enhanced transparency on all organizational levels. The resources required to drive change on this scale are considerable with the private sector and public sectors having unique needs and requiring potentially different approaches.Originality/valueThe novelty lies in the identification of shortcomings in ERM frameworks to effectively prevent wrongdoing, through the integration of OLT, Whistleblowing and Wrongdoing Literature and the COSO Enterprise Risk Management Framework.

  • Research Article
  • 10.59841/inoved.v3i3.3183
Manajemen Risiko dalam Pendidikan: Tinjauan Literatur Sistematis Tentang Strategi, Praktik, dan Dampaknya Terhadap Ketahanan Organisasi
  • Aug 9, 2025
  • Journal Innovation In Education
  • Dedi Kustiawan + 6 more

This systematic literature review explores the transformation of risk management practices in educational institutions, tracing the shift from fragmented, siloed approaches toward integrated Enterprise Risk Management (ERM) frameworks in response to globalization, technological disruption, and increasing regulatory demands. Using the PRISMA 2020 methodology, we reviewed and synthesized findings from 10 high-quality empirical studies published between 2020 and 2024, focusing on theoretical advancements, adaptive mechanisms in volatile educational contexts, and strategies for context-specific ERM implementation. The analysis indicates that the scope of risks in education has expanded significantly beyond traditional physical safety concerns to encompass reputational, operational, and psychosocial dimensions. These emerging risks are often driven by factors such as digital inequities, organizational complexities, and evolving policy landscapes. Three critical components are identified for effective ERM in educational settings: (1) risk integration that unifies financial, operational, and reputational considerations into a cohesive portfolio; (2) adaptive feedback loops that combine prospective scenario modeling, real-time AI-enabled monitoring, and retrospective learning from past crises; and (3) contextual customization, ensuring ERM frameworks are tailored to the unique characteristics, resources, and cultural dynamics of individual institutions. The study demonstrates that merging probabilistic risk theories with regulatory compliance standards, such as ISO 31000 and COSO, strengthens institutional resilience. Moreover, it highlights the importance of shifting from blame-oriented to learning-oriented post-crisis evaluations to foster a culture of continuous improvement. The proposed ERM framework bridges financial economics, institutional theory, and practice-based approaches, offering actionable strategies including real-time digital equity monitoring, stakeholder engagement protocols, and gamified disaster preparedness initiatives.By addressing gaps in the literature, this review makes both a theoretical and practical contribution to educational risk management. It provides a roadmap for mitigating contemporary challenges, such as resource allocation disparities, resistance to cross-institutional collaborations, and the protection of vulnerable school environments, ultimately supporting more resilient and adaptive educational systems.

  • Research Article
  • Cite Count Icon 5
  • 10.1017/s1357321712000062
Enterprise risk management for health insurance from an actuarial perspective
  • Mar 13, 2012
  • British Actuarial Journal
  • G C Orros + 1 more

This paper focuses on Enterprise Risk Management (ERM) and strategic business management for health insurance companies in our world of ‘unknown unknowns’ and the emergence of unexpected risks over time. It illustrates how Chief Risk Officers (CROs) can focus on ‘risk and opportunity management’ through an ERM framework, and thereby balance risks against opportunities, whilst being resilient against ‘unknown unknowns’ and their emergence over time as ‘known unknowns’ and ‘known knowns’. The paper has been designed to meet the broad requirements of health insurers that would like to implement an ERM framework for the effective risk management of their health insurance lines of business. Risk management for health insurers in the context of Solvency II and broader European Commission regulatory requirements is also discussed. The authors discuss how insurers can develop and apply risk management to build resilience in the face of the storms and shocks that may lie ahead.

  • Research Article
  • Cite Count Icon 3
  • 10.6007/ijarbss/v14-i9/22353
The Implementation of Enterprise Risk Management (ERM) Frameworks in Small and Medium Enterprises (SMES): A Literature Review
  • Sep 4, 2024
  • International Journal of Academic Research in Business and Social Sciences
  • Siti Aminah Ahmad + 1 more

This literature review examines the implementation of Enterprise Risk Management (ERM) frameworks within Small and Medium Enterprises (SMEs), emphasizing the distinctive challenges and advantages for these organizations. SMEs often encounter obstacles such as limited financial resources, informal business processes, and a lack of specialized risk management expertise, which can impede effective risk management. Despite these challenges, the adoption of ERM frameworks can offer significant benefits, including improved risk identification and mitigation, enhanced decision-making capabilities, better resource allocation, and increased stakeholder confidence. The review identifies notable research gaps, including a scarcity of SME-focused studies, a lack of longitudinal research, and insufficient exploration of industry-specific ERM practices. The literature reveals contradictions, particularly concerning the complexity of ERM frameworks like COSO and ISO 31000, underscoring the necessity for simplified and tailored models for SMEs. However, there is a consensus on the critical role of leadership commitment, organizational culture, and the integration of ERM into strategic planning for successful implementation. Practical recommendations for SMEs include fostering a risk-aware culture, securing leadership commitment, and leveraging technology to enhance risk management processes. This review aims to contribute to a deeper understanding of ERM practices in SMEs and offers practical recommendations to enhance their resilience, competitiveness, and long-term success in a dynamic business environment.

  • Research Article
  • Cite Count Icon 1
  • 10.2139/ssrn.2792629
Toward Integrated Enterprise Risk Management, Model Risk Management & Cyber-Finance Risk Management: Bridging Networks, Systems and Controls Frameworks
  • Jun 11, 2016
  • SSRN Electronic Journal
  • Yogesh Malhotra

Toward Integrated Enterprise Risk Management, Model Risk Management & Cyber-Finance Risk Management: Bridging Networks, Systems and Controls Frameworks

  • Research Article
  • Cite Count Icon 17
  • 10.24191/mar.v15i2.593
ENTERPRISE RISK MANAGEMENT: EVIDENCE FROM SMALL-MEDIUM ENTERPRISES
  • Dec 23, 2016
  • Management & Accounting Review (MAR)
  • Yap Kiew Heong Angeline + 1 more

This paper aims to investigate the extent to which Malaysian small- and medium-sized enterprises (SMEs) practised enterprise risk management (ERM) framework and their effects on sales performance. The components of ERM examined includes: risk appetite, control environment, assessing the risk management framework and control activities. The paper is based on a questionnaire survey study among 214 SMEs that consist of 77.6% (166) from services related enterprises; and 22.4% (48) of manufacturing related enterprises. The data analysis indicates that 80% of the respondents are clear about the importance of risk management to achieve organisational long term sustainability; the senior management is committed to cultivate good culture and have policies to support ERM. More than 20% of the respondents failed to appoint an independent director to chair risk management committee and to obtain external stakeholders’ view when developing risk appetite. Regression analysis also indicates that control environment has a significant and positive impact on sales. Hence, it is important for SMEs to establish a structured system of internal control, to appoint oversight functions and independent assurance providers to manage risks. Risk management is vital in SMEs to reduce exposure to business loss. It is recommended that standards and professional bodies need to develop ERM principles applicable to SMEs. This principle should balance between preferences, requirements and resources within SMEs. This paper contributes to the empirical literatures on the extent ofERM practices and their effects on SMEs’ sales in emerging markets. Keywords: enterprise risk management, small and medium-sized enterprises, emerging markets, Malaysia

  • PDF Download Icon
  • Research Article
  • Cite Count Icon 6
  • 10.62304/ijmisds.v1i1.115
BASELINE SECURITY REQUIREMENTS FOR CLOUD COMPUTING WITHIN AN ENTERPRISE RISK MANAGEMENT FRAMEWORK
  • Apr 17, 2024
  • Global Mainstream Journal
  • Md Rasel Ul Alam, Asif Shohel & Mahmudul Alam

This paper examines integrating baseline security requirements within an Enterprise Risk Management (ERM) framework, specifically focusing on cloud computing environments. As organizations increasingly migrate their operations to the cloud, the necessity for a robust security posture that aligns with comprehensive risk management practices has never been more critical. Through a systematic review of existing literature and analysis of case studies, this study identifies key strategies for implementing security measures that address the unique risks posed by cloud computing. The findings highlight the importance of continuous risk assessment, compliance and governance standards adherence, and resilient incident response and business continuity plans. The research further explores the dynamic relationship between cloud service models (IaaS et al.) and ERM strategies, offering insights into best practices for mitigating risks while capitalizing on the cloud's scalability and flexibility. The paper concludes with recommendations for organizations seeking to enhance their security and risk management practices in cloud environments, emphasizing the need for an integrated approach that supports business objectives and drives technological innovation.

  • Research Article
  • Cite Count Icon 176
  • 10.1016/j.adiac.2017.01.001
Does Enterprise risk management enhance operating performance?
  • Mar 7, 2017
  • Advances in Accounting
  • Carolyn Callahan + 1 more

Does Enterprise risk management enhance operating performance?

  • Research Article
  • Cite Count Icon 58
  • 10.1108/maj-12-2017-1751
A framework for enterprise risk identification and management: the resource-based view
  • Jan 7, 2019
  • Managerial Auditing Journal
  • Birendra K Mishra + 3 more

PurposeThis study aims to examine the factors influencing enterprise risk management and propose a framework for identifying and explaining the components of enterprise risk management. To enable broader analytical thinking about risk factors, the framework utilizes the resource-based theory to link various classes of risks to an extended set of organizational resources.Design/methodology/approachThe paper opted for an exploratory study using a sample from an online survey. The survey subjects were recruited from the membership database of the American Institute of Certified Public Accountants, focusing primarily on CFOs. The survey consisted of six sections: demographics, a section on each of the four risk types included in ERM: strategic risk, operational risk, financial risk and hazard risk, and exit questions (where very general questions about ERM were asked). The survey yielded a data set of 227 valid responses.FindingsUsing the associated sample survey data, the paper provides empirical validation of the proposed framework that managers in any organizations could use to identify and manage risks.Research limitations/implicationsThe proposed model does have limitations that predominantly exist from the fact that human judgment in decision-making is not always data-driven, and hence, a proper risk exposure could be ignored based on pure arguments of cost and benefits from domain experts. Therefore, researchers and practitioners are encouraged to test the proposed framework further.Practical implicationsRisk exposure is not a snapshot event in an organization’s time horizon. Rather, risk identification is an ongoing process and the proposed framework allows organizations to handle increasing complex risks and/or identifying them based on how the organizational resources may be exposed over time. Managers could use a form of risk control analytics (monitoring dashboard of all identified risks under each interaction sets on a regular basis) to become more proactive in managing risk or exploiting opportunities across enterprise.Originality/valueThis paper fulfills an identified need to study how enterprise risks exposure can be proactively assessed and managed.

  • Research Article
  • Cite Count Icon 3
  • 10.30813/jab.v4i2.418
INTEGRASI BALANCED SCORECARD DENGAN COSO ENTERPRISE RISK MANAGEMENT FRAMEWORK
  • Jun 5, 2017
  • Kurniawati Kurniawati

Companies in the 21st century face a complex business environment, full of opportunities, but pitted with the risks, in which they should make effective business decisions, improve interpersonal relations, meet societal obligations with the right strategy and manage risks. To overcome those challanges, the company needs management tools that can help the company to achieve its objective. Balanced Scorecard (BSC) dan COSO Enterprise Risk Management (ERM) Framework are management tools that are well -recognized and accepted among academicians and more importantly business leaders. They link the high level corporate strategies as determined by top level management with the day-to-day activities of the employees within the organization. Surprisingly, most of companies view BSC and COSO ERM as separate, unrelated management initiatives. In this article, we studies the feasibility of integrating BSC with the COSO ERM Framework, the framework for state-of-the art risk management, similiar to the way the BSC can be integrated with a variety of business management frameworks and methods. The integration of these two management tools (BSC and COSO ERM Framework) is a natural step in the evolution of corporate management . Keywords : Balanced Scorecard, COSO Enterprise Risk Management Framework, Strategic Management System, Risk Management, Key Performance Indicators, Key Risk Indicators.

  • PDF Download Icon
  • Research Article
  • Cite Count Icon 4
  • 10.4102/apsdpr.v10i1.610
The regulatory framework for enterprise risk management in South African local government
  • Sep 23, 2022
  • Africa’s Public Service Delivery & Performance Review
  • Christopher E Whittle + 1 more

Background: Enterprise risk management (ERM) entails the processes and procedures applied to mitigate uncertainties that could impact the achievement of objectives. New public management introduced business practices such as ERM to the public sector, which was adopted by the South African government across all three spheres of government including municipalities. Local government is obliged to implement ERM because of legislative requirements, National Treasury prescripts and the adoption of the King IV Code of Corporate Governance.Aim: To discuss ERM within the public sector and provides the contextualisation of ERM. It sets out the ERM structure, roles and responsibilities required by legislation and good corporate governance. Recommendations to improve ERM are provided.Setting: Within the South African local government.Methods: This study adopted a qualitative research approach and applied a research method based on desktop analysis of literature and secondary data sources using unobtrusive research techniques.Results: Reference is only made to risk in relation to financial management in municipal legislation. National Treasury has guided ERM through the Public Sector Risk Management Framework. The King IV Code provides guidance to local government councils regarding risk governance.Conclusion: The current legislative framework does not provide adequate guidance for effective ERM. Focus is placed on controls and compliance, which undermines ERM’s potential contribution to value creation. ERM within local government has little predictive value and has limited contribution in ensuring objectives are achieved.

  • PDF Download Icon
  • Research Article
  • Cite Count Icon 9
  • 10.5539/ibr.v14n5p63
A Theoretical Framework for Enterprise Risk Management and Organizational Performance
  • Apr 21, 2021
  • International Business Research
  • Mohamed Santigie Kanu

The implementation of holistic risk management, enterprise risk management (ERM), is believed to contribute significantly to the successful performance of modern-day organizations that operate in an increasingly volatile and dynamic environment. In an environment of scarce resources and information uncertainty, ERM, risk culture, and strategic planning is required to face an unstable business environment to achieve organizational goals. Several conceptual and empirical studies have provided mixed evidence on the value relevance of ERM. Scholars have also demonstrated that the effects of ERM on performance are contingent upon certain contextual variables. Currently, the academic literature is silent on the joint relationship of ERM, risk culture, strategic planning, and organizational performance. The purpose of this study is to uncover this research gap by analytically reviewing pertinent conceptual and empirical literature to establish the possibility that the impact of ERM on organizational performance is transmitted through risk culture and strategic planning. This paper advances these evolving suggestions, which hinges on the conclusion that the direct effect of ERM on organizational performance is debatable and hence inconclusive due to the possible mediating influence of risk culture and strategic planning. A framework is conceptualized to examine the mediating effects of these two constructs on the relationship. The study proposes partial least squares structural equation modeling for statistical analysis using the unexplored multiple mediation analysis in the ERM academic literature. This paper’s postulations would guide empirical research in various contexts to address the knowledge gaps in the extant literature.

  • Research Article
  • Cite Count Icon 1
  • 10.3389/fpubh.2025.1608227
Integrating Occupational Health and Safety into Enterprise Risk Management: a structural evaluation
  • Aug 4, 2025
  • Frontiers in Public Health
  • Yalçın Kılıç + 1 more

IntroductionThis study aims to investigate the extent to which Occupational Health and Safety (OHS) risks can be incorporated into the broader framework of Enterprise Risk Management (ERM). Although both systems were developed with similar goals—identifying, assessing, and mitigating risks—they have often operated independently. The research explores whether aligning OHS practices with ERM strategies, particularly through internal audit mechanisms, can foster a more unified and efficient approach to organizational risk management.MethodA qualitative document analysis was conducted, examining current national legislation, international standards such as ISO 31000 (Risk Management) and ISO 45001 (Occupational Health and Safety), and selected academic studies. The evaluation focused on structural similarities, procedural intersections, and the functional roles of personnel involved in ERM, Internal Audit (IA), and OHS processes.ResultsThe analysis revealed a substantial convergence between ERM and OHS in terms of risk identification techniques, prevention-based methodologies, and monitoring processes. The responsibilities of internal auditors and occupational safety specialists display notable overlaps, particularly in areas such as compliance, documentation, hazard assessment, and performance reporting. These parallels support the feasibility of integrating OHS risk management into the ERM structure.ConclusionFor a more effective and holistic approach to enterprise-level risk governance, it is essential to include Occupational Health and Safety risks within the ERM framework. This integration would not only streamline risk management activities but also enhance audit efficiency and organizational resilience. Establishing a closer operational relationship between OHS units and internal audit systems would contribute to safer working environments and more strategic risk oversight.

  • PDF Download Icon
  • Research Article
  • Cite Count Icon 2
  • 10.35995/jbafp2030017
Danske Bank—A Smorgasbord of Risks
  • Jun 9, 2020
  • Journal of Business Accounting and Finance Perspectives
  • Patrick Mcconnell

In September 2018, Danske Bank, the largest bank in Denmark and one of the largest in the Nordic region, published a report which detailed that the bank’s board had fallen into lapses in Anti-Money Laundering/Counter Terrorism Financing (AML/CTF) policies at the bank, in particular, within its Estonian subsidiary. The report was devastating in its criticism of AML processes in the Estonian branch, stating that, over a period of several years, “all lines of defence failed” to manage money laundering risks. Soon after the publication of this report, the CEO of Danske resigned, causing the details of the underlying scandal to become public knowledge (although some the issues involved had been aired publicly on a number of occasions previously). It was also revealed that the bank had become the subject of criminal investigations by US authorities. While the events that are covered in the initial report related to failures to manage AML risks, the situation is more complex than merely deficient AML controls in a remote branch. There was a failure to manage a smorgasbord of different types of risks at both the local and group (i.e., headquarters) level, including: strategic risks; technology risks; and especially operational risks. As befits a sophisticated modern financial institution, Danske Bank operates a group-wide enterprise risk management (ERM) framework covering multiple types of risk (credit, market operational, etc.). The fact that the failure to manage the AML risks took several years to come to light casts doubts on the efficacy of their ERM framework and its implementation. Using Turner’s case study approach, this paper considers the Danske Bank case from the perspective of operational risk management with a view to identifying lessons that can be learned from the scandal that can be applied to future, large-scale operational risk events.

Save Icon
Up Arrow
Open/Close
Setting-up Chat
Loading Interface