Skip to main content

Journal of Operational Risk

Risk.net

An expert-validated risk assessment framework for bank IT supply chain management

Merikh Ahadi, Eronimus Antonysamy and Kamran Morovati

  • This study develops and validates a comprehensive expert-based risk assessment framework for managing IT supply chain risks in the banking sector.
  • A structured taxonomy of 108 risk factors across multiple risk domains was identified through an extensive review of literature, regulatory guidance, and industry practices.
  • Statistical validation using expert responses confirmed the significance and practical relevance of all identified risk factors for bank IT supply chain risk management.
  • The proposed framework provides banking institutions with a practical tool for identifying, assessing, prioritizing, and mitigating IT supply chain risks, thereby supporting stronger cyber resilience and operational risk governance.

The growing dependence of banks on complex information technology (IT) vendor ecosystems has significantly increased exposure to third-party and IT supply chain risks. Grounded in principal–agent theory and transaction cost economics, this study develops and statistically validates a comprehensive risk assessment framework for bank IT supply chain management. A structured multidomain taxonomy of 108 risk factors is derived from the literature, regulatory guidance and domain risk practices, and is translated into a measurable questionnaire instrument. Expert data is collected from 200 banking and IT risk professionals across public and private sector institutions. Because the data is ordinal, nonparametric statistical methods are applied, including descriptive analysis, Shapiro–Wilk normality tests, one-sample Wilcoxon signed-rank tests, Friedman ranking tests and Kendall’s coefficient of concordance. The results show that all 108 identified risk factors are rated significantly above the neutral-importance benchmark (p < 0:001). Friedman ranking analysis indicates directional ranking differentiation across the full factor set (x2(107) = 132:12, p = 0:05), consistent with the narrow item-mean spread that characterizes a prefiltered expert-validated instrument. The framework’s nine risk domains are explicitly mapped to the Basel Committee’s operational risk event categories, supporting integration with banks’ regulatory capital measurement processes. These findings provide strong empirical support for the framework’s importance validity, discriminative validity and consensus validity. The study contributes a domain-specific, empirically validated and operationally usable IT supply chain risk model for banking institutions, advancing both principal–agent and transaction cost theoretical frameworks in the context of financial sector technology outsourcing governance.

Sorry, our subscription options are not loading right now

Please try again later. Get in touch with our customer services team if this issue persists.

New to Risk.net? View our subscription options

You need to sign in to use this feature. If you don’t have a Risk.net account, please register for a trial.

Sign in
You are currently on corporate access.

To use this feature you will need an individual account. If you have one already please sign in.

Sign in.

Alternatively you can request an individual account here