Paper Type
Complete
Paper Number
PACIS2026-1564
Description
Adopting Gowin’s Vee knowledge map as the research strategy, this study developed and evaluated an auditing mechanism for IoT-oriented enterprise risk management (ERM) and internal control in response to the critical risk factors identified by Chang et al. (2020). First, to formulate a prototype, 422 internal control audit items from previous studies were categorized under the five components of the COSO 2013 framework. Second, the prototype was refined through Delphi expert surveys. Third, the adjusted mechanism was examined in three firms from Taiwan. Finally, the mechanism was applied to assess the firms’ internal control maturity. This study provides a research framework to address some limitations of qualitative studies and cast light on research of IT/IS risk management and internal control. The mechanism may serve as a benchmark for organizations seeking enhanced ERM and internal control.
Recommended Citation
Chang, She-I; Cheng, Su-han; Chang, Li-Min; and Liao, Jhan-Cyun, "Developing an IoT-oriented Auditing Mechanism for Enhancing Enterprise Risk Management (ERM) and Internal Control" (2026). PACIS 2026 Proceedings. 4.
https://aisel.aisnet.org/pacis2026/iot_smartcity/iot_smartcity/4
Developing an IoT-oriented Auditing Mechanism for Enhancing Enterprise Risk Management (ERM) and Internal Control
Adopting Gowin’s Vee knowledge map as the research strategy, this study developed and evaluated an auditing mechanism for IoT-oriented enterprise risk management (ERM) and internal control in response to the critical risk factors identified by Chang et al. (2020). First, to formulate a prototype, 422 internal control audit items from previous studies were categorized under the five components of the COSO 2013 framework. Second, the prototype was refined through Delphi expert surveys. Third, the adjusted mechanism was examined in three firms from Taiwan. Finally, the mechanism was applied to assess the firms’ internal control maturity. This study provides a research framework to address some limitations of qualitative studies and cast light on research of IT/IS risk management and internal control. The mechanism may serve as a benchmark for organizations seeking enhanced ERM and internal control.
Comments
10-IoT