IT/IS Risk Management Framework for the National Bank of Ethiopia

dc.contributor.advisorTemtim Asefa
dc.contributor.authorMohammed Kemal
dc.date.accessioned2026-04-13T06:44:47Z
dc.date.available2026-04-13T06:44:47Z
dc.date.issued2025-07-01
dc.description.abstractWith the increasing prevalence of cyber threats and rapid digital transformation, robust IS risk management has become essential for financial institutions particularly central banks that play a critical role in ensuring national economic stability. Despite the growing complexity and volume of IS-related risks, the National Bank of Ethiopia has not yet implemented a formal IS risk management framework aligned with its strategic objectives. The absence of a structured approach limits the bank ability to proactively identify, assess, and respond to evolving IS risks, thereby exposing critical systems to potential disruptions.This study aims to assess the current IS risk management practices at NBE, identify organizational and procedural gaps, and propose a practical IS Risk Management Framework tailored to the institution‘s context. The research adopts a qualitative methodology grounded in the ISACA Risk IT Framework, focusing on the domains of Risk Governance, Risk Evaluation, and Risk Response. Data were collected through semi-structured interviews with 20 participants from ISMD, Internal audit and risk management, and business units, as well as document reviews. This study employed qualitative data analysis software (QDAS) to systematically code and interpret interview transcripts.The findings reveal that NBE current approach to IT/IS risk management is fragmented, reactive, and poorly integrated with enterprise-level strategies. Key issues include the absence of a dedicated IS risk policy, lack of a governance committee; silos risk data, and reliance on basic risk categorization methods. Interview responses also highlighted gaps in risk communication, cross functional coordination, and post-incident learning processes. Based on these insights and supported by best practices (e.g., the risk IT framework, ISO 31000, COBIT 5 for Risk, and Option Based IT risk management framework), a tailored Information system Risk Management Framework is proposed. The framework includes strategic alignment mechanisms, formal governance roles, continuous risk monitoring processes, and a capacity-building agenda.research makes a theoretical contribution by contextualizing and extending the ISACA Risk IT the central banking sector in developing countries, addressing a gap in IS risk management literature within this underexplored domain. It provides a structured model for enhancing Information system risk oversight in NBE and similar institutions. Future studies are recommended to test the framework effectiveness across broader institutional settings and to explore quantitative validation approaches
dc.identifier.urihttps://etd.aau.edu.et/handle/123456789/8064
dc.language.isoen
dc.publisherAddis Ababa University
dc.subjectIT Risk
dc.subjectInformation system risk
dc.subjectthe risk IT
dc.subjectERM
dc.subjectIT governance
dc.titleIT/IS Risk Management Framework for the National Bank of Ethiopia
dc.typeThesis

Files

Original bundle
Now showing 1 - 1 of 1
No Thumbnail Available
Name:
Mohammed Kemal 2025.pdf
Size:
1.56 MB
Format:
Adobe Portable Document Format
License bundle
Now showing 1 - 1 of 1
No Thumbnail Available
Name:
license.txt
Size:
1.71 KB
Format:
Item-specific license agreed to upon submission
Description: