This study explores the intricate relationship between Enterprise Risk Management (ERM) and Internal Control Systems (ICS) in small and medium-sized enterprises (SMEs). Drawing from a preliminary literature review of approximately 200 academic articles identified via Scopus and Web of Science, we investigate the degree to which ERM and internal controls are integrated. The central thesis asserts that a strong and symbiotic relationship exists between the two: there can be no effective internal control without comprehensive risk analysis, and ERM frameworks are incomplete without robust control mechanisms. The findings highlight the evolving convergence of these two domains, particularly in the SME context, where resources are constrained, and informal processes often prevail. This preliminary study lays the groundwork for more empirical exploration and offers theoretical insight into the integrative design of governance mechanisms in SMEs.

Integrating Enterprise Risk Management and Internal Control System in SMEs: A Preliminary Study and Literature Review

paolo roffia
;
Thomas Henschel;
2025-01-01

Abstract

This study explores the intricate relationship between Enterprise Risk Management (ERM) and Internal Control Systems (ICS) in small and medium-sized enterprises (SMEs). Drawing from a preliminary literature review of approximately 200 academic articles identified via Scopus and Web of Science, we investigate the degree to which ERM and internal controls are integrated. The central thesis asserts that a strong and symbiotic relationship exists between the two: there can be no effective internal control without comprehensive risk analysis, and ERM frameworks are incomplete without robust control mechanisms. The findings highlight the evolving convergence of these two domains, particularly in the SME context, where resources are constrained, and informal processes often prevail. This preliminary study lays the groundwork for more empirical exploration and offers theoretical insight into the integrative design of governance mechanisms in SMEs.
2025
Enterprise Risk Management (ERM), Internal Control Systems (ICS), Small and Medium-Sized Enterprises (SMEs), COSO Framework, Risk-Control Integration
File in questo prodotto:
File Dimensione Formato  
ROFFIA_2177_2181_11ERRNProceedings.pdf

solo utenti autorizzati

Tipologia: Versione dell'editore
Licenza: Copyright dell'editore
Dimensione 202.16 kB
Formato Adobe PDF
202.16 kB Adobe PDF   Visualizza/Apri   Richiedi una copia

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11562/1177047
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus ND
  • ???jsp.display-item.citation.isi??? ND
social impact