Basic Concepts of Risk Management in Organizational Management

Author


Abdurrahman Arrasidi(1Mail), Akbar Lubis(2), Al Amin Lubis(3), Amelia Marcella(4), Muhammad Ryan Huda Manurung(5),
(1) Manajemen, Universitas Muslim Nusantara Al Washliyah, Indonesia,
(2) Manajemen, Universitas Muslim Nusantara Al Washliyah, Indonesia,
(3) Manajemen, Universitas Muslim Nusantara Al Washliyah, Indonesia,
(4) Manajemen, Universitas Muslim Nusantara Al Washliyah, Indonesia,
(5) Manajemen, Universitas Muslim Nusantara Al Washliyah, Indonesia,

Mail Corresponding Author
Article Analytic
  [File Size: 247KB]  Language: en
Available online: 2026-09-21  |  Published : 2026-09-21
Copyright (c) 2026 Abdurrahman Arrasidi, Akbar Lubis, Al Amin Lubis, Amelia Marcella, Muhammad Ryan Huda Manurung
Article can trace at:

Article Metrics

Abstract Views: 0 times PDF Downloaded: 0 times

Abstract


Digital transformation has expanded banks’ capabilities to provide fast, integrated, and data-driven services, but at the same time, it has increased their exposure to technology, cyber, operational, third-party, data, and sustainability risks. This article aims to identify the major risk groups in digital banking and establish risk priorities as a basis for strengthening risk mitigation. The study employs a descriptive-qualitative approach based on document analysis by reviewing regulations issued by the Financial Services Authority (Otoritas Jasa Keuangan/OJK), the framework of the Basel Committee on Banking Supervision (BCBS), and recent scholarly literature on banking digitalization, FinTech, cybersecurity, and operational risk. Risk identification was conducted by mapping risk sources, the likelihood of occurrence, impacts on operations and customers, and control requirements. The analysis identifies five major risk groups: cybersecurity and information security risk, data and privacy risk, technology and operational disruption risk, third-party risk/technology dependency, and climate/ESG risk. In the conceptual priority matrix, cybersecurity and information security risks, as well as technology disruption risks, receive the highest level of attention because they have the potential to disrupt critical services, cause financial losses, and undermine customer trust. This article develops an identification framework that links risk identification, assessment, prioritization, mitigation, monitoring, and operational resilience. The framework can serve as a basis for further empirical research and the development of risk management indicators for banks undergoing digital transformation.

Keywords


risk identification; digital banking; cyber risk; operational risk; resilience

References


Bank for International Settlements. (2021). Principles for operational resilience. Basel Committee on Banking Supervision.

Bank Indonesia. (2024). Peraturan Bank Indonesia Nomor 2 Tahun 2024 tentang Keamanan Sistem Informasi dan Ketahanan Siber bagi Penyelenggara Sistem Pembayaran, Pelaku Pasar Uang dan Pasar Valuta Asing, serta Pihak Lain yang Diatur dan Diawasi Bank Indonesia.

Javaheri, D., Fahmideh, M., Chizari, H., Lalbakhsh, P., & Hur, J. (2024). Cybersecurity threats in FinTech: A systematic review. Expert Systems with Applications, 241, 122697.

Otoritas Jasa Keuangan. (2022). Peraturan Otoritas Jasa Keuangan Nomor 11/POJK.03/2022 tentang Penyelenggaraan Teknologi Informasi oleh Bank Umum.

Otoritas Jasa Keuangan. (2024). Panduan Climate Risk Management & Scenario Analysis (CRMS) Perbankan 2024.

Otoritas Jasa Keuangan. (2026). Climate Risk and Banking Resilience Assessment (CBRA) 2026.

Papathomas, A., & Konteos, G. (2024). Financial institutions digital transformation: The stages of the journey and business metrics to follow. Journal of Financial Services Marketing, 29, 590–606.

Uddin, M. H., Mollah, S., Islam, N., & Ali, M. H. (2023). Does digital transformation matter for operational risk exposure? Technological Forecasting and Social Change, 197, 122919.

Zhang, Y. et al. (2024). Research on the impact of digital transformation on the systemic risk of banks. Procedia Computer Science, 242, 364–371.


Refbacks

  • There are currently no refbacks.

Creative Commons License
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.