Skip to main content

Journal of Operational Risk

Marcelo Cruz

Editor-in-chief

Welcome to the third issue of Volume 21 of The Journal of Operational Risk. Risk appetite is a fundamental component of operational risk management because it defines the amount and type of risk an organization is willing to accept in pursuit of its strategic objectives. By establishing clear risk appetite thresholds, management can make informed decisions, allocate resources effectively and ensure operational activities remain within acceptable risk boundaries. A well-defined risk appetite also promotes consistent risk-taking behavior across the organization, strengthens governance and enables timely identification and escalation of risks that exceed established limits, thereby supporting organizational resilience and long-term success. For banks, the importance of risk appetite is reinforced by regulatory expectations, including the principles issued by the Basel Committee on Banking Supervision and supervisory guidance from banking regulators, which require institutions to establish, monitor and regularly review a comprehensive risk appetite framework. Such frameworks help ensure that risk-taking activities remain aligned with the bank’s capital, liquidity and strategic objectives while supporting effective risk governance and regulatory compliance.

#Earlier in June, Risk.net published a report – part of a series of benchmarking reports on bank practices – on how banks are handling their operational risk appetite. The report makes for very interesting reading and I strongly recommend taking a look if you are a practitioner. What surprised me is that 40% of banks breached their appetite for information security risk, while 55% breached formal thresholds for at least one of the top five risks surveyed. According to the report, this is the joint highest proportion since Risk.net began surveying this data. We do not have space here to go through all the survey findings, but another highlight is that 37% of banks had breached their risk appetite threshold for cyber-led IT disruption.

Clearly the disruption that the fast-paced implementation of artificial intelligence (AI) into banking operations is bringing to the financial industry is increasing operational risks. Banks need to beat the competition by moving quickly in incorporating AI into their operational framework; however, such speedy implementation increases information security and cyber risks, among others. In this issue alone there are two papers on this subject, and more articles on this hot topic will be published in subsequent issues.

RESEARCH PAPERS

In the first paper in this issue, “Managing the risks of generative AI: a framework for enterprise risk management”, Ahmad Haidar and Christine Balague highlight that as organizations increasingly integrate GenAI into their core business functions, a new landscape of managerial and operational risks is emerging that is underexplored in academic research. By developing a conceptual framework for mitigating these risks, based on a semi-systematic literature review of 76 peer-reviewed articles from Web of Science, Haidar and Balague’s study aims to identify how GenAI is reshaping enterprise risk management. The authors apply keyword co-occurrence analysis – a quantitative clustering technique conducted using VOSVIEWER – to identify five key constructs that underpin risk emergence in managerial contexts: the enterprise readiness gap; novice risk work; shadow GenAI governance; unethical GenAI; and innovation drift. These constructs are systematically mapped to 10 typologies of GenAI-related risks (eg, data-related, legal, human–GenAI interaction) and further refined into 36 distinct observed risks (eg, loss of control, hallucinations, customer well-being concerns), highlighting how these risks materialize in practice. The paper’s literature review highlights that GenAI risks are both strategic and operational, and Haidar and Balague present five propositions that aim to provide managers with guidance for policy, strategy and adoption choices through an operational risk map.

The issue’s second paper, “The role of business and IT alignment in cyber security risk management” by Samir Jarjoui, Julia Fulmore, Mona Lisa Pinkney and Renita Murimi, a team from the University of Dallas, identifies the significant challenges cyber risk management faces and shows that cyber attacks are actually increasing despite substantial investment. Traditional risk management approaches often fail due to their siloed nature, which does not align cyber security holistically with business and information technology functions. Using systems theory, this study examines six dimensions of the role of business and IT alignment (BITA) in influencing cyber risk management, and it offers a blueprint for future research and practical implementation that integrates BITA into cyber risk management, suggesting that strategic planning, governance and shared knowledge are crucial.

In “Operational risk measurement: integrating the amplification effects of reputational risk”, our third paper, Yinghui Wang, Xuting Mao, Jianping Li, Xiaoqian Zhu and Yizhe Dong explore the complex interplay between operational risk and reputational risk, suggesting that operational risk events lead not only to direct economic losses but also to negative stakeholder evaluations, which escalate into reputational risk. Because the estimation of reputational risk is challenging, research often underestimates operational risk capital by overlooking the amplification effect of reputational risk. The authors propose an approach to measuring operational risk losses that integrates the relationship between reputational and operational risks. Based on observations from the Chinese Operational Loss Database, their paper quantifies the reputational losses triggered by operational risk events within the Chinese banking sector, demonstrating their amplification effects on direct losses. For example, based on the traditional loss distribution approach, the operational risk capital for the whole Chinese banking industry from 1986 to 2023 is estimated to be ¥322.278 billion, while this figure jumps to ¥1687.706 billion when the amplification effects of reputational risk are incorporated. The findings of this study provide a new perspective for the more rational allocation of operational risk capital.

The issue’s fourth paper, “The impact of environmental, social and governance scores on corporate risk: evidence from Chinese listed companies” by Jing Huang, Zhuoran Zhang, Shih-Tse Lo and Yihong Huang, highlights a gap in the literature on how environmental, social and governance (ESG) performance relates to corporate risk; in particular, there is a lack of large-scale, up-to-date and context-specific empirical analysis on the ESG–risk nexus in non-Western economies, particularly China’s. Using a comprehensive panel of companies listed on China’s A-share market, this study examines whether changes in ESG performance are associated with firms’ market-based risk exposure. The results show that ESG score upgrades are significantly associated with higher total risk and higher systemic risk, whereas ESG downgrades are associated with reduced risk exposure. The ESG–risk association is more pronounced in environmentally sensitive industries. In dimension-level analyses, environmental and social improvements are positively associated with risk, while governance exhibits a modest negative association. Mediation analyses further indicate that stock price volatility partially transmits the relationship between ESG changes and risk outcomes.

You need to sign in to use this feature. If you don’t have a Risk.net account, please register for a trial.

Sign in
You are currently on corporate access.

To use this feature you will need an individual account. If you have one already please sign in.

Sign in.

Alternatively you can request an individual account here