Integrating Accounting Governance, Cybersecurity Governance and Digital Trust for Digital Banking Risk Reduction in Jordanian Banks: A Conceptual Framework for Digital Banking Risk Governance
Abstract
Beginning with this paper's overall objective is to develop a comprehensive theoretical framework that illustrates how Jordanian banks reduce digital banking risk (DBR) through two distinct but complementary paths: digital trust (DT) and operational resilience (OR). As such, this paper will expand upon the traditional focus on channel-specific risks associated with e-banking by providing an alternative ecosystem-based perspective on digital banking risk governance. This paper uses a structured conceptual synthesis methodology. In doing so, it synthesizes four separate literature streams including those related to cybersecurity governance; digital trust-risk logic in digital financial services; API security and third-party risk management; and operational resilience. To facilitate this process, studies were selected based on relevance for developing theory, clarity regarding constructs, applicability to banking or financial service institutions, and the potential to inform development of specific propositions. Additionally, two institutional sources located in Jordan were relied upon to provide additional contextualization of the proposed conceptual model in terms of the Jordanian banking environment. The paper presents a multi-layered conceptual model illustrating the role that cybersecurity governance plays in supporting both DT and OR, and ultimately reducing DBR. Specifically, four governance capability domains (API security, customer digital awareness, third-party risk management, and incident response capability) are identified as critical domains of practice that link high-level cybersecurity governance practices to tangible reductions in digital banking risk. The paper provides value by integrating previously separate concepts (cybersecurity governance, DT, TPRM, API security, CDA, IRC, and OR) into a cohesive conceptual architecture designed to facilitate understanding of factors that contribute to reductions in DBR. Further, the paper shifts the emphasis from viewing DBR as being primarily attributable to narrow technological or consumer behavioral issues (e.g., Internet banking channels) to viewing DBR as an issue of broader ecosystem governance. From an accounting information systems and internal control lens, the framework also positions digital banking risk as a problem of transaction authorization, auditability, control monitoring, exception reporting, and assurance over digitally processed banking activities.