Jul 2026· Journal of Management Research and Review· Vol 02· 0 citations
Abstract
Technology assurance practices have become central to efforts aimed at strengthening operational resilience across U.S. regulated sectors, including finance, healthcare, and critical infrastructure. This integrative review examines how audits, compliance mechanisms, governance frameworks, and emerging-technology controls are discussed in the recent peer-reviewed literature. Drawing on a synthesis of recent peer-reviewed studies, the analysis reveals recurring attention to traditional compliance-oriented approaches alongside growing interest in adaptive practices and data-protection balances. Studies consistently identify resource constraints, static checklists, and dynamic threats as barriers that limit the translation of assurance activities into sustained resilience. In financial and healthcare contexts, audits and regulatory implementation show promise for risk mitigation but frequently lack integration with broader operational strategies. Similar patterns appear in utility-sector discussions of cyber-physical threats and in examinations of AI governance, where qualitative reviews emphasize ethical and compliance balances without extensive empirical outcome data. Disclosure quality and framework application are linked to market or organizational responses, yet long-term quantitative evaluation remains underdeveloped. Overall, the literature suggests alignment around the identification of barriers and the need for adaptive cultures, while remaining fragmented on consistent linkages to resilience outcomes and silent on cross-sector empirical validation. These insights point to practical implications for regulated organizations seeking to move beyond compliance checklists toward more responsive assurance systems. The review contributes a grounded perspective on current evidence and highlights targeted areas for future inquiry.
This review synthesizes peer-reviewed literature on governance structures, auditing methods, and resulting outcomes across key sectors including financial services, capital markets, healthcare, and critical infrastructure to reveal consistent emphasis on integrated governance approaches alongside persistent implementation tensions.
William Asare Yirenkyi, Apaflo Godson Teye, Matilda Konotey et al.· Magna Scientia Advanced Rese...· 0 citations
Information technology controls are intended to safeguard operations in safety-critical environments across the United States, yet they frequently fall short of expectations. This review synthesizes evidence on why controls designed for compliance and risk management often fail in practice. Audit practices and compliance frameworks can improve effectiveness and resilience when integrated with mature risk management, yet they encounter subjectivity, inconsistency, and burdensome documentation once deployed. Framework and model design, including maturity approaches and hybrid analytical tools, promises mitigation of control challenges but reveals gaps in interpretability, ethical governance, and real-world deployment. Governance adaptation in development and operations and information technology-operational technology settings balances effectiveness gains with tensions around speed, role transitions, and fragmentation. Technical detection tools and maturity models enhance detection and resilience yet introduce new deployment complexities in healthcare and safety-critical systems. Policy directives and guidance documents outline methodologies and best practices but rarely provide empirical validation of outcomes. The synthesis shows that control failure arises primarily from the persistent gap between design intent and operational reality. Organizations that treat controls as dynamic systems rather than static requirements are better positioned to close this gap. The findings highlight the need for approaches that prioritize integration, adaptability, and continuous empirical validation to strengthen control performance in high-stakes settings.
Keywords: Information Technology Controls, Safety-Critical Environments, Cybersecurity Audits, Regulatory Compliance, Design-Operation Gap.
Matilda Konotey· International Journal of Man...· 0 citations
Telecommunications networks now underpin the delivery of financial, healthcare, government, and
emergency services, which makes service continuity in this sector a matter of public as well as commercial
consequence. Operators face disruption from two directions that they typically govern separately: physical and
technical failure addressed through engineering maintenance, and adversarial activity addressed through information
security. This article examines whether that separation is defensible and what an integrated alternative would involve.
Using a structured narrative literature review of thirty peer reviewed sources, six core standards and guidance
documents, and selected primary United States legal and regulatory materials, it synthesises four literatures that have
developed largely in parallel, covering critical infrastructure resilience, maintenance optimisation, incident response,
and cybersecurity governance. The review finds that resilience measurement weights heavily toward outcome
indicators, that maintenance optimisation remains largely cyber agnostic, that incident response research centres on
enterprise security operations rather than multi vendor field restoration, and that governance research is normative
rather than operational. Drawing on management system logic, the governance function of the NIST Cybersecurity
Framework 2.0, cyber resiliency engineering objectives, and organisational learning theory, the article proposes a
thirteen stage integrated governance framework organised into phases of direction, prevention, response, and learning,
together with nine performance indicators combining leading and outcome measures. Its central proposition is that
preventive maintenance and security monitoring should share a governance cycle because both depend on asset
inventory and behavioural baselining. The framework is proposed rather than empirically validated
Josephat Deogratius Katundabwile, David Mbui Kamau· International Journal of Eng...· 0 citations
This study asks which Performance Audit (PA) practices Supreme Audit Institutions (SAIs) prioritize to address cybersecurity risks and how these contribute to public sector cyber-resilience.
Drawing on semi-structured interviews with sector participants across several jurisdictions, complemented by documentary analysis and international training materials, our exploratory qualitative design analyses the reconfiguration of PA practices to respond to public sector cyber-resilience imperatives.
We show that public sector cyber-resilience goals re-temporalize and re-scale PA. Rather than focusing primarily on retrospective compliance, high-functioning SAIs increasingly orient PA towards anticipatory, system-level and future-facing forms of governance. Empirically, this shift is expressed through new audit objects, new audit practices and new audit products. Combined, these changes reposition PA as a catalytic and infrastructural governance device for building public sector cyber-resilience.
PA contributes most strongly to cyber-resilience planning and anticipatory preparedness and increasingly to absorptive capacity, while recovery and adaptation remain uneven and often constrained by mandates, capabilities and institutional boundaries. Thus, PA has potential for, and limitations in, governing cybersecurity risk. The imperative of cyber-resilience underscores emerging tensions between independence, collaboration, transparency and security in cyber-related audits.
What is new here is not “audit adapts to cybersecurity risk”, but that public sector cyber-resilience forces a reconfiguration of what counts as auditable, when audit intervenes (ex-ante or ex-post) and what the audit product is (including guidance, simulations, readiness reviews and cross-system coordination). Thus, PA moves beyond retrospective evaluation towards anticipatory and system-oriented governance.
Carolyn Cordery, Tarek Rana· Accounting, Auditing & A...· 0 citations
Major disruptive events are inevitable, yet organisations continue to experience vulnerabilities despite the widespread adoption of risk management practices. This paper examines whether the expansion of risk management frameworks has led to improved resilience or has introduced unintended complexity that limits effectiveness. In response to significant incidents, standards, regulations, and assessment processes have been developed to strengthen preparedness. These frameworks are often implemented independently, however, resulting in overlapping requirements, fragmented processes, and increased administrative burden. The accumulation of multiple programmes may therefore create inefficiencies in identifying, managing, and reporting emerging risks, while contributing to a false sense of preparedness. The paper analyses how siloed frameworks and function-specific response plans can reduce organisational effectiveness, particularly in complex incidents involving multiple risk domains. It considers how current approaches may fail to provide a coherent, enterprise-wide view of risk and response readiness. The paper argues for a more integrated approach to enterprise risk management, emphasising cross-functional coordination, consolidation of assessment activities, and improved alignment of stakeholders. A more holistic framework enables organisations to prioritise critical risks, improve decision making, and strengthen resilience in an environment of increasing uncertainty and complexity. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
Diane Doering· Journal of Business Continui...· 0 citations
This study systematically reviews recent evidence on transparency, ESG governance, and emerging risk disclosure in financial institutions, with particular attention to how governance mechanisms shape disclosure quality and institutional resilience. Guided by the PRISMA 2020 framework, the review synthesises peer-reviewed literature published from 2013 to 2025 and complements the evidence with recent regulatory and standard-setting developments. The findings show that board effectiveness, audit committee oversight, enterprise risk management, and internal controls are associated with more credible and decision-useful disclosures. The review also finds that disclosure expectations have expanded from traditional financial risks to ESG, climate-related risks, cybersecurity, operational resilience, and artificial intelligence. Recent developments in global sustainability standards reinforce the need for comparable, material, and decision-useful information. However, evidence remains concentrated in developed markets, while empirical work on African financial institutions is comparatively limited. The review therefore identifies contextual, theoretical, and methodological gaps, particularly in Ghana and other emerging economies. It proposes an integrated governance–disclosure–resilience framework and a future research agenda focused on regulatory reform, digital governance, climate-risk management, ESG assurance, and mixed-method research. The study contributes by connecting previously fragmented strands of governance and disclosure research across increasingly complex financial and technological environments.
M. Antwi· African Journal of Economic...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.