Journal of Operational Risk
ISSN:
1755-2710 (online)
Editor-in-chief: Marcelo Cruz
Managing the risks of generative AI: a framework for enterprise risk management
Need to know
- We propose a framework to guide GenAI risk mitigation for enterprise risk management.
- GenAI risk patterns across business functions through constructs and typologies are identified.
- we map the results onto the four classical operational risk categories defined by the Basel II Accord.
- Risks of GenAI are shown to not only be technical and strategic but also operational.
Abstract
As organizations increasingly integrate generative artificial intelligence (GenAI) into core business functions, a new landscape of managerial and operational risk is emerging that remains insufficiently explored in academic research. By developing a conceptual framework for mitigating these risks, based on a semi-systematic literature review of 76 peer-reviewed articles from Web of Science, this study aims to identify how GenAI is reshaping enterprise risk management. We apply keyword co-occurrence analysis, a quantitative clustering technique conducted using VOSVIEWER, to identify five key constructs that underpin risk emergence in managerial contexts: the enterprise readiness gap; novice risk work; shadow GenAI governance; unethical GenAI; and innovation drift. These constructs are systematically mapped to 10 typologies of GenAI-related risks (eg, data-related, legal, human-GenAI interaction) and further refined into 36 distinct observed risks (eg, loss of control, hallucinations, customer well-being concerns), highlighting how these risks materialize in practice. The framework outlines a system of relationships that explains how these risks manifest across six core management functions: strategy; human resources; operations; finance; marketing; and legal compliance. The review highlights that GenAI risks are both strategic and operational, presenting five propositions that map GenAI risk patterns to guide enterprise risk managers in scenario-based risk modeling.
Copyright Infopro Digital Limited. All rights reserved.
As outlined in our terms and conditions, https://www.infopro-digital.com/terms-and-conditions/subscriptions/ (point 2.4), printing is limited to a single copy.
If you would like to purchase additional rights please email info@risk.net
Copyright Infopro Digital Limited. All rights reserved.
You may share this content using our article tools. As outlined in our terms and conditions, https://www.infopro-digital.com/terms-and-conditions/subscriptions/ (clause 2.4), an Authorised User may only make one copy of the materials for their own personal use. You must also comply with the restrictions in clause 2.5.
If you would like to purchase additional rights please email info@risk.net