Skip to main content

Journal of Operational Risk

Risk.net

Managing the risks of generative AI: a framework for enterprise risk management

Ahmad Haidar and Christine Balagué

  • We propose a framework to guide GenAI risk mitigation for enterprise risk management.
  • GenAI risk patterns across business functions through constructs and typologies are identified.
  • we map the results onto the four classical operational risk categories defined by the Basel II Accord.
  • Risks of GenAI are shown to not only be technical and strategic but also operational.

As organizations increasingly integrate generative artificial intelligence (GenAI) into core business functions, a new landscape of managerial and operational risk is emerging that remains insufficiently explored in academic research. By developing a conceptual framework for mitigating these risks, based on a semi-systematic literature review of 76 peer-reviewed articles from Web of Science, this study aims to identify how GenAI is reshaping enterprise risk management. We apply keyword co-occurrence analysis, a quantitative clustering technique conducted using VOSVIEWER, to identify five key constructs that underpin risk emergence in managerial contexts: the enterprise readiness gap; novice risk work; shadow GenAI governance; unethical GenAI; and innovation drift. These constructs are systematically mapped to 10 typologies of GenAI-related risks (eg, data-related, legal, human-GenAI interaction) and further refined into 36 distinct observed risks (eg, loss of control, hallucinations, customer well-being concerns), highlighting how these risks materialize in practice. The framework outlines a system of relationships that explains how these risks manifest across six core management functions: strategy; human resources; operations; finance; marketing; and legal compliance. The review highlights that GenAI risks are both strategic and operational, presenting five propositions that map GenAI risk patterns to guide enterprise risk managers in scenario-based risk modeling.

Sorry, our subscription options are not loading right now

Please try again later. Get in touch with our customer services team if this issue persists.

New to Risk.net? View our subscription options

You need to sign in to use this feature. If you don’t have a Risk.net account, please register for a trial.

Sign in
You are currently on corporate access.

To use this feature you will need an individual account. If you have one already please sign in.

Sign in.

Alternatively you can request an individual account here