Author
Listed:
- Ifeanyichukwu Jeffrey Okwesa
- Uchechi Mary-Linda Unamma
- Funmilayo Ashore-Onisemo
Abstract
Financial institutions and other regulated enterprises increasingly depend on complex technology estates whose failure can propagate into material financial, operational, and prudential consequences. Regulators have responded with granular reporting obligations that demand not only accurate data but demonstrable assurance that the controls governing that data are designed appropriately and operating effectively. Yet the disciplines of technology risk management, internal control, and regulatory reporting remain organizationally and methodologically fragmented, and control effectiveness is often asserted rather than evidenced. This conceptual paper proposes the Technology Risk and Control Effectiveness (TRACE) framework, an integrative structure that connects a technology control taxonomy to explicit effectiveness criteria, a maturity progression, an evidence-and-metrics layer, a closed assurance loop, and a mapping that ties each control to specific regulatory reporting obligations. TRACE draws on established authorities, including the COSO Internal Control–Integrated Framework, COBIT, the NIST Cybersecurity Framework and SP 800-53, ISO 31000 and ISO/IEC 27001, and the Basel Committee’s BCBS 239 principles for risk data aggregation, and organizes them into a coherent, auditable chain of reasoning from control objective to reported figure. We articulate five design components, present a conceptual architecture figure and a maturity-criteria table, and illustrate the framework by mapping a set of technology controls to a representative regulatory reporting obligation for risk data aggregation. We then discuss implementation challenges, including evidence automation, metric gaming, and the tension between standardization and context, and we acknowledge the limitations of a conceptual contribution not yet subjected to empirical validation. The framework offers practitioners a structured vocabulary for evidencing control effectiveness and researchers a testable model for future study.
Suggested Citation
Ifeanyichukwu Jeffrey Okwesa & Uchechi Mary-Linda Unamma & Funmilayo Ashore-Onisemo, 2023.
"A Control Effectiveness Framework for Technology Risk and Regulatory Reporting,"
International Journal of Scientific Research in Computer Science, Engineering and Information Technology, International Journal of Scientific Research in Computer Science, Engineering and Information Technology, vol. 9(6), pages 1069-1112, November.
Handle:
RePEc:jbh:ijsrcs:v9:y2023:i6:id:hcseit23906789
DOI: 10.32628/CSEIT23906789
Note: Article URL: https://ijsrcseit.com/CSEIT23906789
Download full text from publisher
Corrections
All material on this site has been provided by the respective publishers and authors. You can help correct errors and omissions. When requesting a correction, please mention this item's handle: RePEc:jbh:ijsrcs:v9:y2023:i6:id:hcseit23906789. See general information about how to correct material in RePEc.
If you have authored this item and are not yet registered with RePEc, we encourage you to do it here. This allows to link your profile to this item. It also allows you to accept potential citations to this item that we are uncertain about.
We have no bibliographic references for this item. You can help adding them by using this form .
If you know of missing items citing this one, you can help us creating those links by adding the relevant references in the same way as above, for each refering item. If you are a registered author of this item, you may also want to check the "citations" tab in your RePEc Author Service profile, as there may be some citations waiting for confirmation.
For technical questions regarding this item, or to correct its authors, title, abstract, bibliographic or download information, contact: Pankaj Sharma (USA) (email available below). General contact details of provider: https://ijsrcseit.com/home .
Please note that corrections may take a couple of weeks to filter through
the various RePEc services.