A COSO-Based Enterprise Risk Management Maturity in the Service Industry: Perspectives from Turkish Hotels and Hospitals


Creative Commons License

Soner M., Karadağ M.

SUSTAINABILITY, cilt.18, sa.1929, ss.1-21, 2026 (SCI-Expanded, SSCI, Scopus)

  • Yayın Türü: Makale / Tam Makale
  • Cilt numarası: 18 Sayı: 1929
  • Basım Tarihi: 2026
  • Doi Numarası: 10.3390/su18041929
  • Dergi Adı: SUSTAINABILITY
  • Derginin Tarandığı İndeksler: Scopus, Science Citation Index Expanded (SCI-EXPANDED), Social Sciences Citation Index (SSCI), Geobase, INSPEC
  • Sayfa Sayıları: ss.1-21
  • Açık Arşiv Koleksiyonu: AVESİS Açık Erişim Koleksiyonu
  • Lokman Hekim Üniversitesi Adresli: Evet

Özet

This study proposes and pilots a COSO-2017-based enterprise risk management (ERM) maturity index informed by the use of strategic management tools (SMTs) to benchmark strategic risk management capability in service organizations. Using secondary SMT usage data extracted from seven Turkish graduate theses (eight organizations in hotels and hospitals), we computed overall and component-level maturity scores on a standardized 0–1 scale. The average ERM maturity was 0.52 (medium), with stronger Governance and Culture (0.56) than Performance (0.48) and Information, Communication and Reporting (0.51), indicating persistent gaps in risk-to-metrics translation and reporting infrastructures. Hotels exhibited higher maturity than hospitals (0.575 vs. 0.49), and private hospitals outperformed public hospitals (0.57 vs. 0.41). The  index illustrates a replicable benchmarking approach to identify capability gaps and prioritize ERM improvements—particularly strengthening KRIs, performance feedback loops, and data-enabled reporting that are central to resilience- and sustainability-oriented decision-making.