1 / 133100%
REPUTATION RISK AND POTENTIAL PROFITABILITY: BEST PRACTICES TO PREDICT
AND MITIGATE RISK THROUGH AMALGAMATED FACTORS
Overview
The purpose of this qualitative phenomenological structured interview research study was
to provide the best practices of predicting and mitigating reputational risk to achieve projected
profitability. The study was the means used to gain information about the participants’ motivation,
thoughts, and attitudes (Lune & Berg, 2016) regarding managing reputational risk and
amalgamating the risk information to achieve project profitability. In 2016, 77% of chief financial
officers reported increased risk aversion from executives from the prior year
(Shinkman, 2017), indicating that leaders are becoming much more opposed to risk-taking. While
the 21st century commenced with a succession of diverse crises, employers continued to face the
negative impact of reputational risk. Heil (2018) referred to reputation risk as the “risk of all
risks” (p. 1). Snider and Davies (2017), Calagna (2017), and Deloitte (2014) suggested that
employers had not implemented the appropriate strategies to effectively manage reputational
risks. Arniati, Puspita, Amin, and Pirzada (2019) indicated that the leadership’s information on
company status typically did not match the company’s actual situation. Corporate reputation is a
vital component of shaping stakeholders’ perceptions and responses during crisis development
that ultimately affects a company’s financial performance (Wei, Ouyang, & Chen, 2017).
Leaders often consider risk an administrative function instead of a strategic priority as long
as an organization’s luck continues or until a substantial missed opportunity occurs (Pritchard,
2014). According to the Gartner Strategy Agenda Poll (Gartner; 2019), 70% of respondents
2
expressed low confidence in their abilities to translate strategy into action. Additionally, 60% of
corporate strategists indicated that lagging strategy execution was their main challenge in 2019
(Gartner, 2019). Gartner acknowledged that strategic planning and implementation are challenges
that often require changes to the business model. Equifax, Exxon,
Wells Fargo, Papa John’s Pizza, and Carolina Panthers all lacked reputational risk management
strategies. The 2017 NotPetya ransomware attack resulted in the loss of $870 million in damages
for Merck, as much as $300 million for Maersk, and an estimated $400 million for FedEx (Sanna,
2019). The fourth annual study from the Ponemon Institute (2019) provided responses from over
3,655 global information technology and information technology security professionals who
indicated that the rates of cybersecurity breaches had increased to 11% since 2018 and 67% since
2014.
Breaches are expensive problems that result in adverse perceptions of an organization.
There is little information about the connection between managing enterprise-level risk and the
financial reporting process. There have been increased instances in the insurance industry of
losses due to cybersecurity incidents and doubled insurance activity in 2015 and 2016 (Sapona,
2017). Understanding the potential connection is critical because financial reporting shows a
correlation between a company’s economic standing (e.g., valuations and estimations) and its
related risk exposure through the risk management program (Cohen, Krishnamoorthy, & Wright,
2017). If an adverse event has an impact on a business, the reputational damage could last for
years. In 1987, Chrysler was indicted for altering odometers, as executives used vehicles with
disabled odometers for personal use, reconnected the odometers after driving for thousands of
miles, and then sold the vehicles as new (Racine, Wilson, & Wynes, 2020).
Corporate missteps could result in reputational damage with adverse business outcomes,
including attrition in corporations’ industry standings. Although scholars use the terms brand and
3
reputation interchangeably, the words and their connotations are different; however,
commonalities between the two result in the same goal of protecting organizational sustainability
and profitability. Bill Coletti (2017), author of The New Mindset of Reputation Management,
asserted that employers own their brands and that members of the public own the company’s
reputation. The alignment between brand and reputation indicate the need to manage reputation
risk. Reputation risk is a top 10 global business risk (Allianz Risk Barometer, 2018); however, it
remains a little-known concept (Sapona, 2017). According to Deloitte (2018), reputational risk is
considered to be “meta risk” ahead of key strategic and operational concerns, and positioned
beside risks related to new competition, failed technology, challenges with talent and changes to
regulatory requirements. While concerns related to reputation vary, the outcome of a negative
reputation risk event can be damaging.
In 2016, cyberthieves stole the data of more than 57 million Uber riders and drivers,
resulting in a $100,000 payoff by Uber (Newcomer, 2017). The Equifax data breach of personal
information (DiPietro, 2017) had an effect on 143 million consumers (Johnson, 2017). Hackers
stole consumer data, including drivers’ license numbers, birthdates, Social Security numbers, and
addresses, and many consumers felt exposed and annoyed with how Equifax professionals had
handled their information (Rapoport & Andriotis, 2017).
ExxonMobil is another example of reputational risk. State attorney generals conducted
investigations into ExxonMobil for climate deception, with New York City and several
California municipalities filing climate lawsuits against the company (Mitchell, 2018). In
November 2016, a shareholder class-action lawsuit was filed against ExxonMobil on behalf of
purchasers of ExxonMobil stock. The class-action lawsuit suggested that ExxonMobil provided
misleading statements, leading to company stock trading at artificially inflated prices (Foerster,
Peel, Osofsky, & McDonnell, 2017). Claimants alleged that they sustained losses when the value
4
of ExxonMobil stock fell significantly due to regulatory investigations into the company’s
disclosure and accounting practices. Additional allegations were that ExxonMobil had an incorrect
price on carbon to value confident of its future oil and gas prospects to maintain the value of its
reserves were materially inflated (Foerster et al., 2017; Sanzillo et al., 2018). The reputational risk
stemmed from allegations of materially false and deceptive ExxonMobil public assets statements,
as the statements did not provide internal reports about the nature and extent of climate change.
Accordingly, material shares of Exxon’s reserves were stranded and consequently documented as
risks (Sanzillo, Hipple, & Williams-Derry, 2018). ExxonMobil had been one of the most respected
oil companies in the world; however, it lost its global position as a result of these practices
(Katsenelson, 2018).
Inappropriate actions cause reputational risk. Wells Fargo is another example of
reputational risk. Wells Fargo leaders avoided most of the concerns of the 2008 financial crisis yet
experienced a crisis in late 2016 and mid-2018 (Whitman, 2018). Although Wells Fargo’s account
selling scandal in 2016 resulted in mass public attention (Finkle, 2018) and the termination of
product sales by retail-banking employees (Back, 2016), another scandal erupted. According to
Finkle (2018), Wells Fargo documented the incorrect foreclosures of hundreds of homes. Egan
(2018) recounted that Wells Fargo’s corporate scandals had a negative effect on its reputation,
evidenced through an operational loss of 77% and a profit decline of 12%. In another example,
Chipotle Mexican Grill stock prices fell due in 2015 to the suspension of a major pork supplier
due to allegations of substandard procedures related to animal welfare. By the end of
2015, the stock price had fallen from $757 to $479 (Gilliard, Hoffman, & Baalbaki, 2017).
Papa John’s founder and chairman John Schnatter made racist comments in a call between
company executives and the marketing agency Laundry Service (Fickenscher, 2018a,
5
July 11). Due to the statements, Papa John’s stock fell $48.33 a share, or 4.8 (Fickenscher, 2018a).
Papa John’s reputation underwent additional damage due to Schnatter’s record of sexual
harassment, to include his admission in a Delaware Chancery Court (Fickenscher, 2018b, October
1). Public outcry against Papa John’s was evident not only by reduced stocks, but through the
University of Louisville’s decision to remove Papa John’s name from its football stadium (Kirsch,
2018; Watkins, 2018) and rename its business school. Major League Baseball also stopped
showing Papa John’s promotions (Fickenscher, 2018c, July 13; Paul & Rosenberg, 2018).
According to Stevenson (2018), leaders of other sports teams, including the Texas
Rangers, either severed ties or changed business deals with Papa John’s due to allegations of
Schnatter’s use of racial slurs.
Jerry Richardson, owner of the Carolina Panthers, underwent investigation for workplace
misconduct, first by Quinn Emanuel Urquhart and Sullivan LLP, followed by Erskine Bowles,
past White House Chief of Staff and Carolina Panthers’ minority owner, managed (Wertheim &
Bernstein, 2017). Later, NFL professionals took over the investigation (Wertheim & Bernstein,
2017). The allegations against the Carolina Panthers included sexual and racial misconduct
(Newton, 2018). The lack of or inadequate risk reputation policy could result in a diminished
reputational standing and fines (Egan, 2018; Spanberg, 2018). According to Spanberg (2018),
Richardson received a $2.75 million fine from the NFL after he substantiated the allegations.
Additional disruption to the Carolina Panthers occurred due to Richardson’s decision to sell the
team to the hedge fund billionaire David Tepper for $2.28 billion (Spanberg, 2018). The Carolina
Panthers was an example of the need for reputational risk management strategies, strategies that
are proactive rather than reactionary processes. The considerations for organizational focus are
what is the needed agreement on how to define reputational risk (Stern, 2017), how should the
reputational risk be viewed and demonstrated concerning reduced operations and financial losses
6
(Eckert, 2017), and meeting corporate objectives (Stern, 2017). Sanna (2019) reported that
corporate board leaders had begun questioning vulnerabilities due to cyberattacks, data breaches,
and ransomware attacks that have resulted in substantial losses.
Directors, chief executive officers, and organizational managers might believe they
possess a strong understanding of corporate risks; however, research suggests this might not be
the case (Stern, 2017). A substantial concern is that leaders may hold too high of opinions of their
abilities to determine significant but indistinct issues (Stern, 2017). Individuals frequently base
decisions on uncertain data, predisposed views, or unreasoned thinking (Greis, Avci, Schmidt, &
Machulla, 2017; Shankar, 2019). Thus, leaders could be susceptible to faulty decision-making,
such as that caused by groupthink (Hill, 2018), biases, and hasty or uninformed decisions.
Organizational reputation could determine a company’s success or failure (Agnihotri,
Yang, & Briggs, 2019). Despite quasi-egotistical organizational behaviors, there are few warnings
regarding the need to manage activity detrimental to reputation and risk management (Gaudenzi,
Confente, & Christopher, 2015). A negative reputation could lead to organizational failure. López-
Quesada (2017) indicated that a company could undergo a damaging cycle having devastating
effects on the entire business. Gartner (2019) pointed out that successful businesses require
strategic leaders; otherwise, a short-term focus and routine activities might damage strategic
planning.
In 1760, Benjamin Franklin suggested the need for good deeds in establishing a
respectable reputation, asserting that the loss of status could occur with one mishap (Lilienfeld,
2015; University of Pennsylvania, 2018). Reputational damage can occur if the organization does
not provide for stakeholders’ expectations (Fitzsimmons & Atkins, 2017). A good reputation
typically indicates stakeholder and public acceptance and approval (Duhan, 2016; Popoli, 2017),
whereas a poor reputation generally indicates a lack of public and stakeholder approval. A bad
7
reputation is a warning sign to consider feedback from stakeholders (Duhan, 2016). Gold (2016)
stated that because employers invest in ensuring positive reputations, they should consider the
costs associated with a negative reputation.
Both positive and negative information in the news and social media could affect
reputation (O’Sullivan, 2015). Accordingly, a strong web presence is a means of elevating brand
awareness; however, interactivity and real-time communication could make brands susceptible to
misuse or attack (Langley, 2016). A detrimental reputational event causes organizational leaders to
reexamine operations and how external stakeholders perceive those operations (Anderson,
2016). Social media provides the opportunity to alter a company’s reputation through a viral post
or a hashtag. Effective social media requires a pliable strategy and thoughtful contemplation of the
public’s reaction to organizational actions (Duhan, 2016). Steffee (2018) encouraged leaders to
pay close attention to the impact of social media, as it provides the public’s opinion and has a
financial implication. The impact of public opinion can be negatively impactful whether it is real
or alleged (Leonard, 2018).
The goal of business is to achieve external stakeholders’ positive perceptions to improve
financial performance (Gatzert, 2015). The topic of reputation risk does not have a long-standing
history; as such, it is an evolving subject (Bonime-Blanc, 2017). Organizations need formal,
standard operations and procedures to understand how to predict and mitigate reputation risk.
Risk entails probable consequences and how the decision-maker draws conclusions (Adriaenssen
& Johannessen, 2016). Organizational reputation consists of customers’ perception of how well
company officials listen to its customers (internal and external), as well as the impact of
customers’ interests on the company. Reputation risk assessments in which professionals review
and ascertain customer complaints help to bridge the gap in how the organization presents itself
and how others view the organization (Agnihotri et al., 2019). Customers base their perceptions
8
on the organization’s products and services (Agnihotri et al., 2019). However, a good or bad
reputation could develop without direct contact with customers (Duygun, Mentes, & Kubas,
2014). When misfortunes occur, leaders of large organizations quickly realize the mistake of
overlooking reputation as a significant factor to organizational success.
Defining and measuring corporate reputation (Eckert, 2017) is a central component of
managing corporate reputation; therefore, organizational leaders must consider risk individually
and collectively to understand the big picture (Gunsalus, 2014). In addition to building a positive
corporate reputation, firm leaders should use scenario analysis or risk maps to assess the potential
for damage (Gatzert & Schmit, 2015). Despite possible threats, few companies have programs for
managing reputation risk (Calagna, 2017) and do not focus on issues that can create reputation
risk (Deloitte, 2014). Organizational leaders must respond to reputational risk proactively and in
a balanced manner to defend the organization without imposing unnecessary burden or excessive
analysis (Ingber, 2016). Generally, risks can have economic, professional, environmental, safety,
and societal impacts (Fickenscher, 2018a, 2018c; International Organization for Standardization,
2018; Kirsch, 2018; Watkins, 2018; Wattles, Geier, Egan, & Wiener-Bronner, 2018).
A decade of Global Risk reports provided a list of universally challenging risks, including
water and food crises, terrorist attacks, cybercrime, financial crises, and extreme weather events
(World Economic Forum, 2015). Organizational leaders must address stakeholders at varying
echelons to responsibly manage expenses and realize maximum profit (Stern, 2017). Corporate
markets and regulators indicate the need for senior leaders to consistently achieve goals despite
challenges (López-Quesada, 2017; Sanna, 2019). Executives must ensure success by obtaining
market data on competitors, trends, and external factors with an influence on the corporate
landscape (López-Quesada, 2017). Effectively managing risk in ambiguous situations is a way to
facilitate organizational performance (Wattles et al., 2018). Senior executives and board members
9
set the “tone at the top” and establish organizational culture (Committee of Sponsoring
Organizations of the Treadway Commission [COSO], 2018). A reliable, consistent approach is a
means of reassuring stakeholders that organizational leaders have internal sound controls to
maintain compliance and a financial edge (Eustache & Zeghal, 2016). Figure 1.1 presents the
components of the 2017 COSO ERM framework. The COSO Helix commences with a focus on
mission, vision, and core values, next focusing on strategy development and business objectives.
The areas shown in the helix provide the foundation for the next area of implementation and
performance. Each of the helix areas has organizational value, but collectively, these areas
contribute to heightened business value.
Figure 1. COSO Helix. Adapted from the “Enterprise Risk Management Framework – Integrated
Framework,” 2017. Copyright Committee of Sponsoring Organizations of the Treadway
Commission. 2017.
Companies that provide superior goods and services receive stakeholder compensation
through strong reputations beneficial for competitive advantages (Dowling, 2016). Stakeholders
must be confident that organizations are operating as intended. According to Waller and Younger
(2018), one individual, organizational leader, or publicist cannot manage or own a reputation;
rather, reputation is a result of trust conferred upon companies by the stakeholders. Eustache and
Zeghal (2016) asserted that the issues concerning senior leaders align with the leadership
capabilities needed to solve reputation related concerns. If senior leaders do not possess those
10
specific skills, they must influence their leaders to address challenges successfully. Board
members have begun requesting crucial information about risks with a potentially negative impact
on organizational objectives, including emerging strategic risks (Eustache & Zeghal, 2016). In a
2015 McKinsey study, a mere 16% of board directors admitted to understanding changes in the
industry and how technology could result in fluctuations in their business and sector. Business has
become an extraordinarily intricate sector, and advancements occur too quickly for board
members and chief executive officers to make sound decisions without leveraging intelligent
business systems (Libert, Beck, & Boncheck, 2017), such as artificial intelligence, governance,
and processes. Despite senior leaders’ awareness of the significance of their companies’
reputations (Eckert, 2017), some leaders administer risk management in an ad
hoc, informal, and implicit manner.
While exploring risk management strategies, DuHadway, Carnovale, and Hazen (2019)
found that risk identification is a way to identify deliberate and unintentional disruptions. Aven
(2016) asserted that managers must know about the gains and shortcomings of risk management
strategies and appropriate use. An inherent part of management is predicting, measuring, and
planning risk mitigation (Aven, 2016); however, an inconsistent risk management process
provides leaders with only a partial view of the top risk exposures. The strength of an
organization’s governance correlates with internal control quality (Amoozegar, Pukthuanthong,
& Walker, 2017); leaders must be aware of organizational risks to ensure effective management.
Collaboration is a synergistic process in which all stakeholders work collectively to achieve
communal targets (Wright, 2017).
Reputation risk remains at the core of all risk categories and, thus, must be a focus area for
businesses and business relationships (Hagel, 2013). Kelley and Thams (2019) asserted that the
ability to meet stakeholders’ expectations of what they perceive as important equaled reputation.
11
Modern organizational environments contain a myriad of reputational risks, such as misleading or
falsified information related to financial reporting (Mitchell, 2018), data breaches
(DiPietro, 2017), racist comments (Fickenscher, 2018a; Stevenson, 2018), and sexual harassment
(Fickenscher, 2018b; Wertheim & Bernstein, 2017). The frequency of reputational risk shows the
need for financial firm leaders to develop means of reputation risk management (DiPietro, 2017;
Fickenscher, 2018a, 2018b; Hagel, 2013; Mitchell, 2018; Stevenson, 2018; Wertheim &
Bernstein, 2017).
A good reputation often leads to a strong market position and increased shareholder value
(Fragouli & Ekruka, 2016), requiring an effective reputation risk management approach.
Reputational risk management involves the assembly of processes for protecting and promoting a
company’s reputation (Ernst & Young, 2013; Swanson, 2013). Reputation risk management is a
way to shape a compelling corporate image (Ernst & Young, 2013; Fragouli & Ekruka, 2016;
Hagel, 2013). Thus, organizational leaders must understand that a lack of risk reduction is an
indirect means of diminishing the realization of organizational goals (Hagel, 2013). Rapid
technological advancements that could indicate the company’s direction could cause
longstanding companies to lag (Libert et al., 2017). Corporate leaders should focus on protecting
their organizational reputations (López-Quesada, 2017).
Risk caused by the negative perceptions of clients, stakeholders, depositors, venture
capitalists, debtholders, market analysts, and regulators could have a critical effect on an
organization’s ability to sustain or launch a business (Ingber, 2016). Safeguarding reputation is not
the same as preserving an ethical culture (Ingber, 2016). PricewaterhouseCoopers (2017) added
that reputation risk is the possibility of revenue loss or considerable costs in an organization due to
a damaged public image. A company’s reputation comprises 58% company perception and 42%
products and services perception (Fragouli & Ekruka, 2016; Reputation Institute, 2017). Corporate
12
leaders should protect their reputations as fundamental assets to reduce risk to market and public
standing (Lavermicocca & Buchan, 2015).
As regulatory guidance, public scrutiny, and stakeholder expectations increase, so does the
value of the corporate brand (Lavermicocca & Buchan, 2015). Most organizational leaders
develop strategies to manage tangible assets, which comprise physical, financial, intellectual, and
reputational capital (Fombrun et al., 2015; Khan & Digout, 2018). Reputation usually receives
less attention because it is a decidedly difficult asset to identify and manage (Insurance Journal,
2013; Visvanathan, 2017). Seventy-seven percent of company leaders find it challenging to
quantify the financial impact of reputational risk to their businesses as opposed to traditional,
more concrete risks (Insurance Journal, 2013). Research has shown that there are painful
consequences of a damaged reputation (Agnihotri et al., 2019; Fragouli & Ekruka, 2016; Hagel,
2013; Ingber, 2016). According to Building Security (2017), company leaders must identify and
proactively address all risks, not only the most catastrophic ones.
Consistent, measurable risk reduction does not occur by chance; it must be a managed
process (Gaudenzi et al., 2015; Visvanathan, 2017). Company leaders must strive to predict risk,
relinquish reactive stances (Gaudenzi et al., 2015), and understand risk by avoiding behaviors
such as anchoring biases in which they rely too heavily on the first piece of information (Oliver,
2019). Dynamic analysis could provide indicators of threats and mitigation strategies before the
threat even occurs (Butchko, 2015). Eckert (2017) indicated that organizational leaders tend to
focus on managing reputational threats that have already materialized. Unmanaged risk is an
uncontrolled danger often due to overreliance on chance and hope for good fortune (Federal
Deposit Insurance Corporation, 2014).
Many organizational leaders fail to use risk-reduction methods (Eckert, 2017), instead
relying on unanalyzed initiatives and intuition (Gaudenzi et al., 2015). Organizational leaders who
13
lack sound risk analysis must depend on intuition and data availability when making timesensitive
decisions despite the effects of ambiguous risks on decision-making (Butchko, 2015; Sadegh &
Jalili, 2016). Companies need to assimilate business-wide risk management functions to increase
communication and collaboration and meet corporate objectives (Kimbrough, 2015; Stern, 2017).
Financial decisions have consequences that not only affect the decision maker, but impact others
as well (Vieider, Villegas, Martinsson, & Mejía, 2016).
Gaudenzi et al. (2015) indicated that reputation remains a concern for status and revenue.
Without mitigation strategies commensurate with the risks faced, organizational leaders are
susceptible to damaging consequences due to reputational injury (Federal Deposit Insurance
Corporation, 2014). Understanding internal risks to reputation and branding could provide
organizations with key areas for remaining competitive and improving market share and
profitability (Flax, Bick, & Abratt, 2016; Gunsalus, 2014). There is a significant, positive
relationship between the level of reputation (over time) and firm performance with measures of
reputation and financial performance (Gaudenzi et al., 2015; McGuire, Schneeweis & Branch,
1990; Raithel & Schwaiger, 2015). Raithel and Schwaiger (2015) observed that nonfinancial
reputation components might contribute more to financial performance than monetary
components.
Background and Rationale of the Study
An abundance of regulations exists for conducting daily business (Daferighe & Adedeji,
2010), reducing stakeholders’ financial risks (Ingber, 2016), and maximizing shareholders’ value
(Daferighe & Adedeji, 2010). Compliance, ethics, and social responsibility are the three
cornerstones of business mandates (Ji, Li, North, & Liu, 2017). When compliance, ethics, and
social responsibility co-occur, they result in higher profitability, improved competitiveness, and
easier access to funds (Ji et al., 2017). Ingber (2016) affirmed that balancing risk was the only way
14
to effectively manage a company in the multifaceted world. Organizational leaders must
understand the risk of managing risk (Ingber, 2016) while practicing the three fundamental
cornerstones (Ji et al., 2017). Understanding risk potential in a corporation is inherently valuable
(Fitzsimmons & Atkins, 2017; Kaiser, 2015). Reputation leaders and practitioners must learn
about global expansions to increase interest in risk-based decision-making. The Center for Safety
and Health Sustainability, International Network of Safety and Health Practitioner Organizations,
and International Organization of Standardization focus on advancing these initiatives (Ennis,
2015). The International Organization of Standardization provided the ISO 45001 Standard to set
the direction for global safety and health management systems, both of which contain risk
assessment practices and processes (Ennis, 2015). Ultimately, reputation is a summation of
stakeholders’ opinions of the organization, rather than the opinions of the consumers, employees,
or upper managers (Ingber, 2016).
Around the world, damaged corporate reputations have resulted in declined profits
(Cârstea, 2016; Dhaliwal, Goodman, Hoffman, & Schwab, 2016; Woodyard, 2015). Reputational
risk is not new, as the Space Shuttle Columbia accident investigation report found that NASA’s
organizational culture was a significant cause of the 1981 disaster (DeLoach, 2015a). A 2015
Volkswagen scandal resulted in a 20% devaluation of shares and a 25% drop in sales (Cârstea,
2016). Volkswagen was accused of engine rigging practices that began in 2008 and continued
until the discovery in 2015 (Nunes & Park, 2016). Volkswagen had to recall 500,000 diesel engine
cars in the United States with devices designed to circumvent emission tests
(International Council on Clean Transportation, 2017; Woodyard, 2015).
As corporations are profit-driven, organizational leaders must protect their reputations
(Dhaliwal et al., 2016). A corporate brand has tangible organizational value, and effective risk
15
mitigation is a way to reduce the likelihood and severity of damage (Flax et al., 2016). Many
organizations have faced backlash resulting in reputational impact, including Uber, United
Continental Holdings, Equifax, Perrigo Co., Wells Fargo, and Equifax (Dhaliwal et al., 2016;
Wilson, 2017). The dichotomy of managing internal and external expectations to meet established
goals can cause internal conflict (Dhaliwal et al., 2016). Nunes and Park (2016), Gaudenzi et al.
(2015), and Kaiser (2015) emphasized that modern business leaders should consider the effects of
reputation risk planning on the organization. The premise of reputational risk management is to
provide companies with strategies to reduce reputation risk (Flax et al., 2016). The
implementation of risk management should contain preferred organizational cultural qualities,
such as cross-functional collaboration, open communication across alignments, trust in colleagues’
competency, and the inclination to deal with enterprise-wide threats (Kimbrough,
2015).
Successful organizational leaders treat reputation risk as a strategic issue (Deloitte, 2014).
Reputational risk management should be a primary business concern. Previous reputation studies
have indicated inadequate development of concrete reputational risk management methods
(Gaudenzi et al., 2015). An unreported risk could have an incalculable, adverse impact on an
organization; a damaged reputation could have a fiscally immeasurable impact (Tanimura, &
Wehrly, 2015).
In all industries, corporate leaders must perform due diligence to protect the stakeholders’
interests (Deloitte, 2014). An example of a failure to perform due diligence occurred in 2012,
when Federal Trade Commission professionals filed suit against Wyndham Worldwide
Corporation and three of its subsidiaries for having three data breaches within 2 years (Fair,
16
2015). The case was an example of the Federal Trade Commission’s efforts to ensure business
privacy and data security rules and procedures (Fair, 2015). The reality is that many company
leaders have failed to establish programs for targeting corporate threats (Nunes & Park, 2016;
Tanimura & Wehrly, 2015). Risks could create rapid reputational destruction, derailed financial
goals, or damaging headlines that cause mass stakeholder distress and negative corporate climates
(Hawn & Ioannou, 2016). Sanna (2019) supported the SEC observation that publicly traded
companies present any substantial cybersecurity risks in monetary terms.
As every company is subject to risk, it is necessary to understand how to mitigate risk,
either before or immediately after it occurs. The profit-driven nature of the corporate structure,
regulatory guidance, and stakeholders require that organizational leaders invest in structured
frameworks to reduce internal and external commercial risks (Hawn & Ioannou, 2016). Even with
the best intentions, executives often expect year-to-year success without understanding the
dynamics between organizational culture and reputation risk (Liu & Tan, 2017). Executives
frequently fail to consider how organizational culture and reputation risk affects profit and loss
(Denis, 2016), failing to account for the rapid pace of change within the business environment.
Social media has been a predominant influencer in the marketplace, as well as an equalizer
for companies who can expertly leverage its utility (Solis, 2011). Business-to-business social
media risk branding requires additional research; however, with both types of reputation risk-
based branding, companies have to reinvent themselves, increasing impact through digital crowds
(Cawsey & Rowley, 2016). Digital media is a source of reputation risk-based branding (Cawsey &
Rowley, 2016). The alignment of business images, products, and technology enables message
delivery and assistance for individuals seeking products and services (Benn, Abratt, & Kleyn,
2016). Together, these paradigms enable users to communicate with one another and create digital
content about companies, products, and services (Kizgin et al., 2020; Nabi, 2019). Consequently,
17
business leaders have begun to strategically improve their service quality through process
improvements, such as reputation risk-based branding (Rufaidah, 2016), as a means to sustain
business in times of heightened competition (Martin & Zacrias, 2017). Improving business
processes and performance are meaningful organizational goals that can produce effective change
(Burton, 2014; Kull & Wacker, 2010).
Some companies have undergone isolated events with such severe effects on their
reputations that there were nearly incalculable costs to regain competitive market standing (Benn
et al., 2016). Organization leaders should seek to understand the relationship between reputation
and potential profit (Benn et al., 2016). Conversely, when an unfortunate event results in a media
response, organizational leaders tend to respond by expending countless financial resources to
mitigate reputational damage and stabilize stakeholder opinions, which could result in a loss of
future profits (Burke & Martin, 2016; Kölbel, Busch, & Jancso, 2017). The absence of bad press
correlates with a high level of success (Lee & Vachon, 2016). Organizational leaders may ignore
the influence of risks on profit margins, a necessary consideration in strategic and operational
planning (King, 2016; Kölbel et al., 2017). Further, decision-makers may fail to identify internal
barriers, such as corporate climate and culture, which could be significant factors in success or
failure (King, 2016). Exploring the multidimensionality of an organization’s reputation could
provide greater transparency than economic and noneconomic factors.
A favorable corporate reputation could be a significant differentiator among competitors
(Carmassi & Herring, 2016; Sheahan & Williamson, 2016; Verhezen, 2016). In an era of
increasing regulation, advanced technology, and superior innovation, company executives find
themselves navigating a multitude of complexities to maintain a competitive standing (Carmassi
& Herring, 2016). Walter (2016) found that company size directly correlated with reputation,
18
suggesting that larger firms had higher status. Practitioners and scholars acknowledge the
necessity to advance organizational risk management (Ingley & van der Walt, 2008; Kleffner,
Lee, & McGannon, 2003; Kraus & Lehner, 2012; Mensah, 2016; Nocco & Stulz, 2006; Paape &
Speklé, 2012; Stroh, 2005). There must be formal risk management, specifically for risks that could
impact an organization’s reputation, as unmanaged dangers could result in reduced
earnings or even bankruptcy (Lam, 2014).
Statement of the Problem
Companies are particularly vulnerable to factors with adverse reputational impact, with
70% to 80% of market value derived from assessing intangible assets such as brand, intellectual
capital, and goodwill (Su, 2014). Executives who do not understand the influence of reputation
risk cannot effectively manage the impact on profit earnings (Bonime-Blanc & Ponzi, 2016).
Organizational leaders expend financial resources to reduce risk but fail to proactively protect the
fundamental asset of reputation, which could affect goal realization (Moon, 2016). Due to the
exploitation of vulnerabilities, Fortune 500 companies, including Google, Marriott International,
Equifax, Home Depot, and Coca-Cola, have experienced losses. According to Jensen and
Rosenthal (2015), low-cost loss scenarios across sectors are $150 million; high-cost scenarios
could be than $287 million (National Association of Federally Insured Credit Unions, 2016).
Research has indicated that corporate crisis response is a component of restoring brand equity
(Dutta & Pullig, 2011; Sisson & Bowen, 2017). Executives recognize that corporate gaffes present
substantial reputation risk, which could have a significant impact on earnings and stakeholders’
opinions. Leaders must predict and mitigate risks to reputation to achieve projected profitability
and avoid other implications, such as:
• legal actions, monetary fines, and operational disruptions;
• loss of customers, clients, and employees;
• increased remediation and assurance expenses;
19
• reduced stock prices;
• high insurance premiums;
• declined sales of products and services; and
• loss of competitive status in the industry (Alviniussen & Jankensgard, 2015).
Purpose of the Study
The purpose of this qualitative phenomenological structured interview research study was
to identify the best practices of predicting and mitigating reputational risk to achieve projected
profitability. Corporate reputation and reputation risk are issues of growing relevance due to their
direct correlation with firm value (Gatzert, 2015). Organizational leaders must understand the how
and why of brand management, analysis, and planning to know how others perceive their brands
in the marketplace (Flint, Signori, & Golicic, 2016). Social media has caused a paradigm shift in
reputation risk-based brand management and brand management control and the resulting
discussions (Cawsey & Rowley, 2016). Business preparation does not have a standardized method
of managing reputation risk at the organization level. There is a need to investigate the best
practices to improve businesses’ overall positioning, risk awareness and prioritization, and
capabilities in a digital world (Rufaidah, 2016). Also necessary is research on effective and
ineffective reputation risk-based practices for online or digital communities (crowd-culture) (Holt,
2016). An additional benefit of such research is reducing reputational risk to improve the
attainment of potential profit (Nakano & Aoki, 2016).
Research Questions
The study had three guiding research questions:
RQ1. What risk categories should organizational risk management programs include to
predict reputational risk and achieve financial objectives?
RQ2. What are the leading practices of mitigating reputational risk?
RQ3. What reputational risk management techniques should organizational leaders use for
business process improvement initiatives?
20
Nature of the Study
The study had a qualitative phenomenological structured interview design, which entails
deriving information from input, partnership, and inquiry to answer collective concerns (Lune &
Berg, 2016), in this case, on the best practices for predicting and mitigating reputation risk and
achieving projected profit. This study was the means used to develop best practices for reputation
risk-based procedures for organizations across the United States. The research focused on
nonstatistical approaches of inquiry and an analysis of social phenomena with an inductive
process (Krueger & Casey, 2014). The action research approach drove data collection,
incorporating a methodical review process and investigation to comprehend the problem and
build a theoretical basis for the reputation risk phenomena (Stringer, 2013).
Structured interviews are an appropriate approach for determining phenomena (Chiarini,
2017; Stewart & Shamdasani, 2014). In this study, structured interviews allowed the researcher to
understand the barriers and enablers of risk-based management. Later chapters include a literature
review, interview data collection method, and best reputation risk practices. The selection of
interview participants entailed criteria based largely on role and experience. The participants
served as risk management professionals in the areas of risk-based strategy and management,
corporate branding, higher education management, entrepreneurship, technology, and
cybersecurity.
Definition of Terms
Amalgamation. The action or process of uniting or merging two or more things
(Merriam-Webster.com).
Assumptions. Statements taken for granted or contemplated as real that have not
undergone scientific testing (Geczy, 2015).
21
Branding. Proactive practices and procedures created to engender cultural relevance and
get the most return on the brand; a multiplier causing desire, variation, and motivation for
purchasers to pay more for products than they would otherwise (Holt, 2016).
Brand management. The planning and analysis of the understanding of a brand in the
marketplace and the approaches for establishing a positive brand (Flint et al., 2016).
Chief risk officer. The executive responsible for the competent, efficient, and effective
governance of substantial risks and related opportunities of an organization and its segments.
(Amoozegar et al., 2017).
Crisis management. An interdisciplinary subject field characterized by theoretical problems,
realistic activity, people management, and the practice of crisis-event solving (Ristvej,
Holla, & Titko, 2018).
Crowd-culture. Digital crowds that consist of especially productive and prolific
innovators of culture (Holt, 2016). Members of the crowd-culture have changed branding
practices.
Delimitations. Limits or boundaries established by the researcher (Theofanidis &
Fountouki, 2018).
Environmental and social governance (ESG). A set of norms for an organization’s
operations that socially conscious investors employ to examine potential investments (Johnson,
2016).
E-reputation [online reputation]. The reflection of the image that Internet users have of a
company or an individual, derived from information available online and regarding what others
state about a company or an individual (Frochot & Molinaro, 2008).
Limitations: The influences that the researcher cannot control (Joyner, Rouse, &
Glatthorn, 2013).
22
Potential earnings. An organization’s conjectural in-flows of capital; also known as
earnings management and potential earnings (Zhang & Gimeno, 2016);
Potential profitability. The potential profit margins of an organization as estimated by
financial data professionals. The potential profits indicate the additional capital earned after
designated costs (Zhang & Gimeno, 2016). Also referred to as potential profit.
Profitability. The degree to which a corporation produces financial gain (Nakano &
Aoki, 2016).
Profit goals. The expected potential profit of upper-level corporate management
stakeholders and other demographics with dependencies on said expectations (Bennett, Bettis,
Gopalan, & Milbourn, 2017).
Reputation. Perception of an individual, that it is externally derived and not necessarily
inherent to the individual (Raskin, 2013).
Reputation (reputational) risk. The possibility of adverse publicity of an organization’s
business practices. Whether correct or false, reputation risk could result in a decreased customer
base, expensive legal processes, or diminished revenue (Federal Reserve System, 2020).
Reputation (reputational) management. The control asserted over the individual, group,
or the corporate perceptions held by internal and external stakeholders (Dhaliwal et al., 2016).
Risk. In the context of corporate and other institutions, the definition of risk is the same as
in most other contexts. It focuses on the potential of a negative consequence, hazard, loss, or
exposure to mischance (Amoozegar et al., 2017).
Risk management. The ongoing process of identifying, analyzing, evaluating, and
treating loss exposures and overseeing risk control and financial resources to mitigate the adverse
effects of loss (Amoozegar et al., 2017).
23
Significance of the Study
Organizational leaders could use the study’s results to develop the best practices of
predicting and mitigating risk. The results will be significant to corporate leaders seeking to model
successful behaviors (Nakano & Aoki, 2016) of managing and mitigating risk for increased
opportunities to attain the projected profitability. Enterprise risk managers could also use this
study’s results to strengthen risk management frameworks or provide thought leadership when
establishing new risk management programs (Katsenelson, 2018). Professionals seeking to use
reputation-risk leveraging traditional techniques (Gunsalus, 2014) could also benefit from this
study. Additionally, the findings may provide useful information to vendors, associations, and
institutions for promotion and training of robust risk management techniques (Nakano & Aoki,
2016).
This study will contribute to the improvement of organizations and the fields of business
and reputational risk management by providing information on potential threats and risks relative
to the uncertainty faced (Calagna, 2017). According to Elkington and Upward (2016), senior
leaders have begun to understand the degree to which managing reputation risk supports the
recognition of factors detrimental to financial objectives, thus enabling them to apply appropriate
preemptive strategies. Risk management is a continually developing and evolving discipline
(Elkington & Upward, 2016; Hopkin, 2017); this study could provide information that supports
financial goal attainment.
The study’s results could indicate how to achieve the intended organizational results
through careful and consistent consideration of the influence of organizational culture and
reputation risk on organizational results (Flint et al., 2016). Like all categorically defined risk, the
risk to reputation could also be an opportunity and not just a threat (Honey, 2017). Individuals
working in research and development, decision sciences, project management, information
24
technology, economics, engineering, social and biological sciences, political science, and
consulting practices routinely apply risk management methods to achieve desired outcomes
(Hopkin, 2017). Professionals and scholars use risk reduction across disciplines and industries;
however, there are gaps in the strategies for mitigating or avoiding risk through risk management
processes (Hopkin, 2017).
Assumptions, Limitations, and Delimitations
Assumptions
Assumptions are elements out of the researcher’s control but accepted as truth (Rose,
). Several assumptions were made in this qualitative phenomenological structured
interview research study. First, all participants had experience with managing risk. Second, all
participants were assumed to understand how to manage risk as it relates to executing a formal
organizational risk management framework. Third, participants understood whether reputation
risk was a distinct category of risk or an aggregation of other risk types as it relates to the
participants’ experience with managing risk. Fourth, participants were aware of the extent to
which reputational risk was integrated into the organizational risk management framework during
the participants’ current or previous role[s] as a risk manager. Lastly, significance of organizations
impacted by an ineffectual focus on managing reputational risk.
Limitations
The results of this study were limited to the phemonenological experiences of the
participants. Variations in professional skills and abilities, roles and responsibilities, size of the
organization, industries supported, and organizational culture, policies and procedures may have
influenced the applicability of the results of this study to other organiztions. The data relied on
collective responses to the interview questions. Additionally, this study did not address judicial
2019
25
reputational risk-based management; therefore, the findings are not generalizable to the Legal
field.
Delimitations
Delimitations confine the scope of the study within the researcher’s control (Simon.
2011). Apart from the traditional delimitations such as selection of research questions,
instrumentation, and design of methodology, there were two noted delimitations in this study.
Firstly, the findings were specific to the concerns, specialties, and subspecialties discovered from
the relevant research. Secondly, this researcher conducted this study as a full-time risk
management professional. As such, the researcher made methodological choices and decisions
based on time constraints. For example, the researcher expected to have designed, developed, and
conduct the study successfully within 3 months.
Scope of the Study
This researcher limited the scope of the study to the best practices for predicting and
mitigating risk for small to medium organizations and the subsequent consequences of risk
materialization. The researcher leveraged information through structured interviews with the
intention of scalability for small to large organizations. The results provided a foundation for the
topics included in organizational risk management programs.
Worldview and Theoretical Foundation
A systematic view of reputational risk-based management in the corporate sector presents
an opportunity for augmenting risk management programs. Reputation risk can be a formidable
topic (Johnson, 2017), but executives have begun to recognize the importance of reputational risk
(Cawsey & Rowley, 2016; Moise, 2018). Risk theories provide the conjectural relation and
framework that align concepts to increase understanding and address risk. On a constructivist
scale, high-risk actions that appear to have limited and isolated results could increase in severity
26
and cause regional and global damage (Van Der Vegt, Essens, Wahlström, & George, 2015). The
pragmatist worldview, guided by practical considerations (Pryba, 2015), is that the value of
reputation has steadily become a significant corporate issue in an increasingly interconnected
world (Van Der Vegt et al., 2015). Reputation-building is a process; it is the outcome of an
organization’s actions and manifestations in which leaders consider future actions and viewpoints
(Szwajca, 2018). Reputation risk is a complicated process because of global interconnectivity
(Van Der Vegt et al., 2015). The interwoven relationship between people, organizations, and
nations results in opportunities for risk on a larger scale (Van Der Vegt et al., 2015).
Globally, leaders seek an understanding of the relationship between reputation risk and
impediments to meet financial goals and establish effective mitigation strategies (Hopkin, 2017).
Companies including ExxonMobil (Mitchell, 2018), Equifax (DiPietro, 2017), Papa John’s
(Fickenscher, 2018a), and the Carolina Panthers (Wertheim & Bernstein, 2017) have experienced
significant reputation damage. Organizational reputation correlates to organizational value and the
ability to produce future benefits. Risk management requires an understanding of the intricate
nature of reputation and its challenges (Szwajca, 2018), thus necessitating academic inquiry to
close the knowledge gap on reputation risk management.
Organization of the Remainder of the Study
This study consists of five chapters. Chapter 2 is the literature review, Chapter 3 presents
the methodology used, Chapter 4 shows the results of data analysis, and Chapter 5 contributes a
discussion of the findings and the implications and recommendations for future research.
27
CHAPTER 2: LITERATURE REVIEW
This study’s purpose was to address the phenomenon of reputational risk and potential
profitability, two little-researched components of constantly evolving business practices
(Dijkmans, Kerkhof, & Beukeboom, 2015; Meadows & Meadows, 2016; Sanzillo et al., 2018;
Spence, Sellnow-Richmond, Sellnow, & Lachlan, 2016). The definition of reputational risk
management is risk to an establishment’s reputation that could result in the destruction of
shareholder value (Global Association of Risk Professionals, 2013). A reputational risk
management plan requires a paradigm shift to prevent breaches and other negative events. The
Equifax breach (DiPietro, 2017) affected 143 million consumers (Johnson, 2017). According to
the Allianz Risk Barometer (2019), cyber incidents were a primary business concern among 50%
of respondents. Since 2014, cybercriminal activity costs have increased from $445 billion to
approximately $600 billion annually (Allianz, 2019; Swiss Re, 2108).
ExxonMobil underwent multipart investigations for climate deception from state attorney
generals and lawsuits from New York City and several California municipalities (Mitchell,
2018). Wells Fargo’s leaders got caught in an account-selling scandal (Moise, 2018; Whitman,
2018). According to Finkle (2018), Wells Fargo recorded the incorrect foreclosure of hundreds of
homes over 5 years. Papa John’s founder and chairman John Schnatter made racist comments
during a call between corporate executives and Laundry Service marketing professionals that
caused Papa John’s stock to fall 4.9% (Fickenscher, 2018a). The scandal and community outcry
also resulted in the removal of Papa John’s name from the University of Louisville’s football
stadium (Watkins, 2018) and the renaming of its business school (Fickenscher, 2018c; Paul &
Rosenberg, 2018). Further, Major League Baseball indeterminately stopped showing a Papa
John’s promotion (Fickenscher, 2018c; Paul & Rosenberg, 2018).
Missteps require considerations of the definition of reputational risk (Stern, 2017), how
leaders should assess reputational risk to reduce operational and financial losses (Eckert, 2017)
28
and meet corporate objectives (Stern, 2017), and directors, chief executive officers, and
organizational managers’ belief of their own knowledge about reputational risks (Stern, 2017).
Rates of reputational risk and financial profitability concerns are rising. There is a need for
proactive prevention rather than reaction when a corporate crisis occurs, which is a mounting
challenge that could cause stakeholder worry (Deloitte, 2014; Gunsalus, 2014). Organizational
leaders must establish reputational risk management and stakeholder- and business-centered risk
systems. Also beneficial is using social media, information technology, and communication to
improve access and quality, decrease risks, and manage high volumes of data and customer
(internal and external) relationships (Campbell, 2017; Gunsalus, 2014; King, 2016; Stern, 2017).
Consumer opinion affects reputational branding in terms of the organization’s appearance,
written and spoken words, tone, quality of products and services, and customer service. An
example of appearance is Jared Fogle, the former Subway restaurant spokesperson, who pled
guilty to federal charges of committing sex acts with children and obtaining and supplying child
pornography (Phillip & Larimer, 2015). An example of written and spoken words is Papa John’s
founder and chairman John Schnatter’s racist remarks (Fickenscher, 2018a; Paul & Rosenberg,
2018). Tone was a component of a Unilever’s Dove soap advertisement in which a Black woman
removed her shirt to reveal a White woman (Buckley, 2017). An example of the quality of
products and services was Wells Fargo’s report of incorrect foreclosures on hundreds of homes
(Finkle, 2018). According to Consumer Affairs (2018), Bank of America’s closure of customers’
accounts for not using their credit cards frequent enough reflected poor customer service.
According to University of Maryland’s Clifford Rossi (2016), organizational leaders must
discover the indicators of reputational risk. Reducing reputational risk often entails improving
business processes (Gaudenzi et al., 2015; Kaiser, 2015; Walter, 2016).
29
This chapter will present the historical context of the problem and the literature relevant to
the study’s problem. The reviewed literature provided the theoretical frameworks for this
qualitative phenomenological structured interview research study. The literature review will
address the practical concerns and the issues shown in the literature. Finally, this chapter indicates
the information needed to fill the gap in the literature.
The researcher explored other qualitative studies to answer the research questions. This
literature review addresses reputation risk and potential profitability through two qualitative
components with a focus on phenomenology, the study of how human beings experience
phenomena (Smith, Flowers, & Larkin, 2009). The literature review contains information on
general risk, reputation risk, the historical perspective, previous studies on reputation risk and the
theoretical frameworks, practical concerns, and problem.
Historical Context of the Problem
Providing a phenomenon’s historical context is a means of establishing familiarity with
developments and recognizing the likely directions for future research (University of South
Carolina Libraries, 2018). Knight (1921) introduced the concept of risk as “tendencies” (p. 5).
Despite Knight’s idea and theory, there is no single definition of risk in the literature (Bakke,
Mahmudi, Fernando, & Salas, 2016; Mateescu, Olaru, Sârbu, & Surugiu, 2016; Sadgrove, 2016).
Knight suggested that there was a difference between risk and doubt, with risk being something
distinctly out of character. There are extensive and decisive variances in the bearings of the
phenomenon conditional to what is present and operating. Knight asserted that uncertainty exists
when there is a lack of predictability, even with a probability model. Accordingly, the ambiguity
experienced by organizational leaders indicates that reducing reputation risk is a significant
concern (Foss & Klein, 2016). The modern definition of risk includes the categorization of risk
types (Foss & Klein, 2016). Elshandidy and Neri (2015) examined the influence of corporate
30
governance on risk disclosure practices in the United Kingdom and Italy. The authors found that
voluntarily revealing the potential levels of risk within a corporate structure enabled limiting the
negative impacts if the risks occurred (Elshandidy & Neri, 2015). Despite this finding, Elshandidy
and Neri used more than one definition of risk in their study.
The problem of reputational risk originated from political bribery (Bukh, 2016).
According to President Ronald Reagan, politics is the second oldest profession, and bribing
public officials has been an ongoing issue for governments and businesses alike (Bukh, 2016;
Krock, 1971. Anticorruption laws in support of positive reputational risks and to stop corruption
appeared in many countries in the 1970s and 1980s. In 1977, Congress passed The Foreign
Corrupt Practices Act (FCPA); a United States federal law that forbids U.S. citizens and entities
from bribing foreign government officials to benefit their business interests. There were minimal
enforcement actions in the first few decades of the Foreign Corrupt Practices Act’s existence.
However, after the financial crisis, a surge in both political and regulatory expectations resulted
in increased enforcement from regulatory agencies (Salbu, 1999). After several corruption
scandals, including the Watergate investigation and the subsequent resignation of President
Richard Nixon (Hermanson, 2004; Salbu, 1999). Although Watergate was an instance of political
corruption, investigators found over 400 American organizations with cases of bribery with
foreign governments (Salbu, 1999).
As a conduit to encouraging and supporting research in the economy of risk and insurance,
The Geneva Papers were established in 1976. The Geneva Papers indicated that reputation risk
was one of the greatest concerns for insurance companies (Gatzert & Schmit,
2016; Sapona, 2017; Schanz, 2006; Zboron, 2006). Once an insured’s reputation valuation falls
below an established measure, the insurer will initiate financial loss procedures (Sapona, 2017).
During The Geneva Papers presentations, Eccles and Vollbracht (2006) focused on the relevance
31
of strategic management communication based on empirical observations of long-term media
reputation. Sarbanes-Oxley Act of 2002 (SOX 404) was additional legislation enacted to mitigate
the risk of financial loss due to the ineffectiveness of a publicly traded companies’ internal
controls. SOX 404 mandates the auditing and reporting of the publicly-traded companies’
financial controls. The results of the SOX 404 audits can lead to reputational risk if the results are
found to be unsatisfactory.
Reputational risk management is connected with insurers’ inclusive risk assessments and
risk control strategies (Zboron, 2006). A respectable reputation is an important, intangible asset
with an unspecified relationship between portraying a good reputation and strong business
performance or low costs or additional risks (Huda, 2019). Slight doubt in insureds’ assurances as
a result of financial constraints and business practices could have an impact on businesses’
profiles (Zboron, 2006). According to Forstmoser and Herger (2006), no organizational leader
can afford to forgo beneficial practices for the impulses of public opinion. Leaders should
endeavor to shape reputational opportunities and risks in the organization’s best interests
(Forstmoser & Herger, 2006), while exercising good ethics and corporate social responsibility.
In 2009, scholars noted that reputational risk correlated with operational risks but was not
considered a serious matter (Benyon, 2010). According to Coleman and Casselman (2016),
strategy mapping is a useful tool for identifying risks. Operational risk is the danger of loss that
could result from insufficient or unsuccessful internal processes, people, and systems or external
events (Benyon, 2010). Reputational risk is separate from operational risk because a reputation
event precedes most operational risk events. Professionals should track and index reputational
risks as impacts rather than types (Benyon, 2010). Organizations have found effective alternatives
to managing identified risks (Coleman & Casselman, 2016). Many regulations apply to daily
organizational activities and how to amplify shareholders’ value (Daferighe & Adedeji, 2010).
32
In 2014, increased transparency or hyper-transparency (Johnson, 2016) was a popular
way to manage behavioral-based risk to predict future performance by reviewing past
occurrences (Khan & Digout, 2018). The highest levels of company leadership must monitor
employee behavior for developments in trends, disposition and acuities that merit attention
(DeLoach, 2015b). Corporate misconduct and unlawfulness are business behaviors that digress
from social norms and could harm a reputation (Sampath, Gardberg, & Rahman, 2018). Such
behaviors are not addressed in formal risk management programs despite evidence that shows
reputation risk management’s contribution to the bottom line (Bătae, 2018). Questionable, illegal,
and criminal behaviors have had a significant impact on the financial industry. An increasing
body of work shows a connection between ethical behaviors and the culture of solutions and
performance that management must own (Bătae, 2018).
No two organizations are the same and each organization must be evaluated for requisite
adjustments to its risk culture in response to strategic and external changes (DeLoach, 2015b).
Investors and analysts must understand the organization’s ability to handle reputational risks while
maintaining profitability, which requires emphasizing nonmonetary factors of the environment,
human capital, social capital, business model and innovation, governance, and leadership
(Johnson, 2016). Standardized reporting includes the creation of frameworks for protecting
against financial and operational hazards, including reputational risk (Bonime-Blanc & Ponzi,
2016). Organizational leaders need to understand the significance of reputation risk and to develop
agility by predicting, categorizing, and preparing for potential risks (Deloitte, 2017;
Pretty, 2018).
According to a 2017 Deloitte Debrief webinar poll, less than 15% of business
professionals reported having prepared for a risk event with clear crisis-management strategies
33
and processes (Deloitte, 2017). The history of reputation risk suggests that reputational and ethical
business practices could influence organizational performance and value (Tannous &
Yoon, 2018). Reputational risk seeps into ethical and unethical perceived cultural risk practices
(Tannous & Yoon, 2018). The chance of reputational risk decreases if stakeholders positively
influence social sustainability policies and procedures (Mani & Gunasekaran, 2018). In addition
to the other impacts of reputational risks, Mani and Gunasekaran (2018) posited that risk
assessment plans must include ethical guidelines to alleviate reputational risk and maximize value
for stakeholders.
Previous Studies’ Additions to the Body of Knowledge
Four studies contributed significantly to the body of knowledge on reputational risk. Ways
of reducing the informational gap include contributing to the data on little-researched topics;
researching a topic with no sound data, contesting accounts, or insufficient substantiation to
determine which are valid; and developing new theories (University of Florida, 2018). Research is
a means to discover different data about diverse locations with diverse cultures (University of
South Carolina Libraries, 2018).
Kaiser (2015) defined reputational risk as the risk of unforeseen loss due to internal or
external stakeholder response to an organizational change. Reputation management influences the
public’s perception of the organization. Reputational risk management consists of the systematic
recognition and evaluation of potential threats to reach or maintain a particular perception, to
include the subtraction of risk management measures (Kaiser, 2015). The study’s results showed
the need for organizations to have reputational risk management frameworks and a designated
reputational risk department. Some organizational leaders have either systematically assimilated
reputational risk into their overall risk management approach or have developed risk management
frameworks (Kaiser, 2015). According to Kaiser, organizational leaders should have tools and
34
instruments for managing operational risk. Chapelle (2019) identified four activities necessary in
risk management models: risk identification, risk assessment, risk mitigation, and risk monitoring.
Risk management frameworks could also include risk management and risk response activities. As
not all risk responses require mitigation, organizational leaders could use other response
strategies, such as risk avoidance, risk transfer, and risk acceptance (Project Management Institute
[PMI], 2017; Yeomans, 2016). Appropriate risk management processes should include the entire
organization.
Pretty (2018) discovered that reputation-damaging crises, such as cyberattacks, product
recalls, and executive misconduct, have had an impact on share prices and that social media has
doubled the severity of the impacts. Pretty studied the effects of natural disasters in the early
1990s and their organizational impact, finding captivating risk replaced by reputation in 2000.
The late 20th century saw remarkable telecommunications and information-sharing
advancements worldwide, enabling individuals to engage with others and gain influence at an
unprecedented rate (Harwood, 2017). Social media has enabled information-sharing in abundance
(Eckert, 2017). Online reviews have become significant information sources for consumers
(Robertson, 2016). When making deciding to make purchases, 76% of consumers hold equal
value in online reviews and personal recommendations (Test, 2020). Managing reputational risk
is critical due to the evolving dimensions of the business landscape.
Pretty reviewed reputational risk and its undercurrents in the age of cybersecurity,
including such topics as the rise of technology, social media, cyberattacks and shareholder value,
and consequences for reputation risk management. During reputation-damaging crises,
preparedness and management’s behaviors could contribute to 20% of the company’s perceived
value or a loss of up to 30% (Pretty, 2018; Tuttle, 2018b, October 1). The research showed that
neither the size nor the strength of an organization’s reputation was an effective shield against
35
value loss (Pretty, 2018; Tuttle, 2018b). The three actions that could result in positive recovery
were instant and global crisis communications, opinions of trustworthiness and transparency, and
invoking active and positive social responsibility (Pretty, 2018).
Organizational leaders face a learning curve in operational risk. Kaiser (2015) identified
an 8- to 10-year period for operational risk to become a relatively mature discipline; due to the
existing data and toolsets; however, the relative maturity of reputational risk should take less time
(Kaiser, 2015). Balancing risk is the only effective way to manage a company in a multifaceted
world (Baldi, Baglieri, & Corea, 2015). Balancing risk could occur through the lens of theoretical
frameworks to diminish the internal and external organizational perils (Hawn &
Ioannou, 2016).
Theoretical Frameworks
With an impact on all facets of a study, a theoretical framework has six components: the
main topic of the study, the existing knowledge about the topic, the focus of the topic focuses, the
unknown about the topic, the importance of knowing the unknown, and the study’s specific
purpose (Merriam & Tisdell, 2015). This section will present this study’s theoretical framework
according to the aforementioned six areas. The use of a theoretical framework requires the
examination of noteworthy points (Fox, Gardner, & Osborne, 2015). The researcher based the
choice of theoretical framework on reputational risks, change management, and business process
improvements. The framework consists of the concepts, beliefs, views, principles, and theories
used to reinforce the research. The theoretical and conceptual framework provided substantial
points of study and the relationships among them (Fox et al., 2015).
Practical Concerns Addressed Through the Review of the Literature
Corporate social responsibility (CSR) literature has shown that companies’ existing CSR
reputation can protect against the effects of reputation-damaging events (Noack, Miller, &
36
Smith, 2019). The practical concerns addressed in the literature review are CSR (Harjoto &
Laksmana, 2018), ethical and unethical perceived cultural practices (Tannous & Yoon, 2018),
reputational risks (Fragouli & Ekruka, 2016), social media (Cawsey & Rowley, 2016), and
reputation risk management (Bakke, Mahmudi, Fernando, & Salas, 2016). CSR is an increasingly
important topic (Aqueveque, Rodrigo, & Duran, 2018) because it provides an avenue to (a)
comprehend and frame the relationship between business and society and (b) shows the rise and
points of resolution of specific social issues from the economic activities of corporations
(Schwartz, 2017).
Ethical and unethical cultural practices are significant as behavior can influence
reputation. In addition, ethical business practices and the ability to manage reputational risk could
have an impact on performance and value (Tannous & Yoon, 2018). Reputational risk is another
concern because organizations must have good reputations to reinforce market position and
amplify shareholder value. Consequently, good reputational risk management provides rewards
for the organization (Aqueveque et al., 2018; Fragouli & Ekruka, 2016). A key challenge for
organizations is realizing that inadequate risk reduction could obstruct the achievement of
organizational goals (Hagel, 2013). A good corporate reputation correlates with effective
reputation risk management (Fragouli & Ekruka, 2016).
Reputation risk management, the last noted concern, is the assembly of processes designed
to protect and promote a company’s reputation (Gaudenzi et al., 2015). Reputation risk
management entails formulating an effective and operative corporate image, examining changing
regulatory requirements and compliance issues (Gaudenzi et al., 2015). Reputational risk
management consists of more than misleading information (Mitchell, 2018), data breaches
(DiPietro, 2017), racist comments (Fickenscher, 2018a; Stevenson, 2018), and sexual harassment
(Fickenscher, 2018b; Wertheim & Bernstein, 2017).
37
In the 21st century, organizational leaders have begun to focus on reputational risk more
than in the past (Hagel, 2013). Inadequate reputational risk management suggests that leaders of
financial firms must pay attention to the importance of such preparation (DiPietro, 2017;
Fickenscher, 2018a, 2018b; Hagel, 2013; Mitchell, 2018; Stevenson, 2018; Wertheim & Berstein,
2017). According to Ernst & Young (2013) and DiPietro (2017), reputation risk management
consists of the processes designed to protect and promote a company’s reputation.
Reputation risk management is a component of shaping an effective corporate image (Fragouli &
Ekruka, 2016; Hagel, 2013). Cole (2009) posited that protecting an institution’s reputation is the
most significant risk management challenge that financial institution directors face.
Social media is a concern for corporate social responsibility (Eberhardt & Schwaiger,
2016), ethical and unethical perceived cultural practices, reputational risks, and reputation risk
management. Social media is a source of reputation risk (Aula, 2010; Copulsky, 2011;
GainesRoss, 2010; Szwajca, 2018; Steffee, 2018; Vollenbroek, De Vries, Constantinides, &
Krommers, 2014) involving business-to-customer and business-to-business social media
reputation risk branding (Cawsey & Rowley, 2016). Social media presents the sources of
reputation risk-based branding, including business images, products, and internal and external
stakeholders’ reviews (Cawsey & Rowley, 2016). Benn et al. (2016) identified an immediate and
increased risk to organizations because social media has an instant reach. Appropriate messaging
is a requirement, and such messaging should present thoughtful organizational and public
perceptions at all times
(Benn et al., 2016).
The Problem Addressed by the Literature Review
The overall problem addressed by the literature review is reputational risk and the manner
of investigating concerns such as corporate social responsibility (Harjoto & Laksmana, 2018),
38
ethical and unethical perceived cultural practices (Tannous & Yoon, 2018), reputational risks
(Fragouli & Ekruka, 2016), social media (Cawsey & Rowley, 2016), and reputation risk
management (Bakke et al., 2016). Organizational leaders can mitigate reputation risk with
management strategies, which should be a key business priority (Gaudenzi et al., 2015). Despite
research indicating that reputation risk can change over time, there are no definitive approaches
to managing reputational risk (Gaudenzi et al., 2015). Reputation risk management remains a
significant issue, in great part due to the pervasiveness of social media and increased surveillance
from banking and insurance regulators who consider the impact of reputation on organizational
value (Gatzert, Schmit, & Kolb, 2016).
Questions that Guide the Research
The study’s three central research questions were:
RQ1. What risk categories should organizational risk management programs include to
predict reputational risk and achieve financial objectives?
RQ2. What are the leading practices of mitigating reputational risk?
RQ3. What reputational risk management techniques should organizational leaders use for
business process improvement initiatives?
Method for Reviewing the Literature
The literature review consists of relevant research on the influence and management of
reputational risk. The keywords searched included reputation risk, reputational risk, reputation
risk management, intangible assets, brand management, potential profit, social media, corporate
social responsibility, and profit targets AND corporate financial objectives. The secondary search
terms were risk satisfaction, adoption of reputational risk, risk framework shortages, risk
governance shortages, risk management care education, qualitative risk assessment, utilization,
global impact, and best practices, plus the subject of the inquiry. The academic databases used
39
through the Capitol Technology University library were Business Source Premier, ProQuest
Dissertations & Theses Global, and Capitol Technology University OPAC. ABI/INFORM
Collection, ProQuest, OmniFile, JStor, Google Scholar, and Scientific Research Publishing
provided the peer-reviewed literature relevant to this study. Additionally, the researcher reviewed
Reputation Institute, the world’s leading research and advisory firm for reputation, for insight
into the benchmark and measurement data; the RepTrak model; and data on reputational
occurrences. The researcher conducted a manual search of the reference list of reviewed articles,
performing Internet searches for historical information confirmed by academic literature. The
literature search and selection process consisted of three steps: previewing the material, selecting
the appropriate literature, and organizing the information to explore or solve an issue (Greener &
Greenfield, 2016). This research study entailed a literature review consisting of seminal and
contemporary sources that varied in breadth, age and type.
Method for Analyzing the Literature
The selection of studies to review was according to keywords and phrases that included the
topics of best practices of reputational risk with technology, best practices of reputational risk with
social media, risk management, reputational management, innovation, crowd-culture, business-to-
customer social media reputation risk branding, business-to-business social media risk branding,
corporate social responsibility, and business process improvement. The resulting documents
underwent review and analysis for methodology quality and themes. The researcher organized the
literature into themes on the best practices of reputation risk management in U.S. organizations
influenced by technology and social media.
The documents underwent assessment for consistency. The researcher reviewed both
supporting and non-supporting data and analyzed the strengths and weaknesses of the literature. It
was necessary to identify any gaps or missing information from the body of research to synthesize
40
a research focus and technique. Literature analyses commenced to determine a research design
and guidance for sample size, data collection methods, and tools. Finally, the researcher studied
the documents for the best practices, relevant reputation risk theories, methodologies, and
frameworks.
Relevant Reputation Risk Theories, Methodologies, and Frameworks
The relevant risk reputation theories are risk colonization, enterprise risk
management, and corporate social responsibility. The appropriate research approach was the
qualitative risk assessment methodology. The relevant frameworks are reputational risks,
change management, and business process improvements.
A general definition of a theory is an assumption, or a scheme of ideas proposed to clarify
something, expressly when the something is founded on general principles independent of that
requiring explanation (Boer et al., 2015). The following sections present the study’s three
theories: theory of risk colonization, enterprise risk management, and corporate social
responsibility.
Theory of Risk Colonization
The theory of risk colonization has three components: the necessity of responding to new
and discovered risks, the growth of regulatory frameworks, and the utilization of the risk
instrument as a framework for innovative decision-making (Rothstein, Huber, & Gaskell, 2006).
The theorists distinguished between societal and institutional risks. Societal risk consists of
threats to members of society and their environment (Van Weyenberge, Deckers, Caspeele, &
Merci, 2016). Institutional risk comprises threats to regulatory organizations and the acceptability
of rules and regulations (Rothstein et al., 2006). Rothstein et al. (2006) argued that the pressures
of improving the coherence, transparency, and accountability of societal risk regulations could
produce institutional risks by presenting the regulations’ limitations.
41
The theory of risk colonization was important for this study because it indicates regulation
as a valuable instrument for managing institutional threats (Rothstein et al., 2006). Management
institutional threats lead to vigorous tension concerning the management of societal and
institutional risks, with the consequences being circling feedback loops (Rothstein et al., 2006).
The process of regulating societal risks indicates institutional risks that regulators can manage to
mitigate societal risks in diverse ways (Global Competitiveness and Risks Team,
2016).
Critique of the Theory of Risk Colonization
Straightforward, risk-based governance requires strategies consistent with the impact and
likelihood of the societal risks to set standards or for compliance (Mateescu et al., 2016; Sadgrove,
2016). Notwithstanding their methodological validity, numerical and calculative validations could
be a means of amplifying the genuineness and rightfulness of decision-making (Mwangi, 2014).
Risk assessment could be a means of validating organizational operations for bureaucratic due
diligence, enacting defenses as a direct encounter with increased responsibility and answerability
pressures (Mwangi, 2014). Regulatory agencies typically support if the regulators use their
established guidelines to assess risk. However, reviewers commonly dismiss criticism of their
assessments (Baldwin, 2016). There is a void in companies with regard to risk assessments
(Goetz, Laeven, & Levine, 2016); therefore, risk assessment guidelines may not be a suitable
approach for decision-making in uncertain circumstances (Baldwin, 2016).
Enterprise Risk Management Theory
ERM in business environments consists of the risk management techniques and processes
used to attain organizational objectives (Lackovic, 2017). ERM is a top-down, enterprise-wide
view of risks (Baxter, Bedard, Hoitash, & Yezegel, 2013). ERM differs from traditional risk
management because the latter cannot indicate key limitations (e.g., sales and customer service;
42
production and distribution; finance and treasury; human resources; IT risks; legal and
compliance; and strategic management) before the risk occurs (Beasley, 2016). The value of ERM
has undergone frequent analysis as organizational leaders strive to rationalize the time and effort
ERM requires (2018). Schiller and Prpich (2014) reasoned that ERM clarified primary risks
typically understood by organizational leaders as theory must be used to secure opportunities. Due
to volatile and tumultuous environments with numerous external and internal risks, organizational
leaders have begun to see the value of ERM (Lackovic, 2017).
The theory of ERM is relevant to this study because it focuses on all organizational risks at
once rather than addressing risks one at a time (Lackovic, 2017). The salient trait of ERM is the
consideration of risks from diverse sources that require holistic treatment (Lackovic, 2017).
There is a need for a holistic view of risk management (Gaudenzi et al., 2015; Hagel, 2013;
Visvanathan, 2017). The purpose of ERM is to increase organizational value with an
organizational strategy (DiPietro, 2017; Reputation Institute, 2017).
Critique of enterprise risk management theory. In addressing organizational risk,
reliance on traditional concepts such as risk appetite and risk tolerance could be too simplistic an
approach and may not align with the options that leaders implement (Goldstein & McElligot,
2014). Rather, value is amplified when leaders balance ERM concepts with established strategy,
objectives and effectual resource allocation to achieve the organizational goals (COSO, 2004).
In 2004, COSO issued the enterprise risk management (ERM) framework, titled
“Enterprise Risk Management — Integrated Framework.” The ERM Integrated Framework
purposed to standardize ERM rules, define crucial ERM components, examine significant ERM
principles and concepts, recommend a common ERM language, and provide ERM direction and
guidance (COSO, 2004; COSO, 2018; Veltsos, 2017). In 2017, COSO issued an updated ERM
framework; “Enterprise Risk Management – Integrating with Strategy and Performance.” The
43
updated 2017 ERM framework focused on the relationship between risk and value and the
association among risk, strategy, and performance (COSO, 2018; Veltsos, 2017). According to
Bromiley and Rau (2016), although researchers have provided valuable tools and resources, a
review of all potential risks is neither practical nor economical. Therefore, the prioritization of
risks must occur (Hopkin, 2017). Another concern is the unpredictability of the future. Leaders
can only evaluate some risks by selecting and applying effective risk management instruments at a
given time (Bromiley, McShane, Nair, & Rustambekov, 2014). Leaders and strategists must
remain competitive and make changes to guide their economic, environmental, and corporate
social responsibility impacts (Epstein, 2018).
Corporate Social Responsibility Theory
Business leaders in the United States have begun using corporate social responsibility
theory to sustain good relationships with internal and external stakeholders and understand the
influence of corporate engagement on organizational image and staff outcomes (Slack, Corlett, &
Morris, 2015). Mainenti (2016) identified corporate social responsibility as a prevailing and
central theory for organizations due to globalization and universal cognizance. Individuals
generally interpret corporate social responsibility as a good organizational strategy for managing
reputational risks. However, not all company leaders have successfully implemented corporate
social responsibility (Mainenti, 2016). Leaders who do not recognize the influence of reputation
risk cannot effectively manage its impact on profit earnings (Bonime-Blanc & Ponzi, 2016).
Corporate social responsibility predicts organizational identification, which then shows the
importance of organizational commitment to reputational risk management (Del Rosario, 2016).
The staff’s dedication to corporate social responsibility is the foundation of corporate citizenship.
Organizations must have corporate social responsibility plans, and employees must practice
corporate citizenship (Arruda & Fennell, 2015).
44
Corporate social responsibility affects job satisfaction, connecting the staff and the
organization. Organizational success cannot occur without the internal staff (Del Rosario, 2016).
Zhou, Luo, and Tang (2018) researched the effect of corporate social responsibility on employee
engagement and job satisfaction. The authors suggested that perceived corporate social
responsibility has a direct and indirect influence on job satisfaction and is a means of fortifying
the relationship between organizations and their employees. Thus, organizational identification is
a way to mediate the relationship between perceived corporate social responsibility and job
satisfaction (Zhou et al., 2018). Additionally, overall justice is a mediator for the relationship
between organizational identification and corporate social responsibility (Zhou et al., 2018).
Company leaders must recognize, scrutinize, and remediate noncompliant actions with
organizational codes of conduct and ethical ideologies (Bătae, 2018).
Critiques of corporate social responsibility theory. Corporate social responsibility is a
relevant theory for this study because the employees’ abilities to practice good corporate
citizenship leads to organizational success (Mainenti, 2016). A significant challenge for the theory
is that many organizations do not provide employees with corporate social responsibility training.
Employee commitment to organizations and community programs could be a problem when
pursuing organizational associations and coalition (Callaway, 2013). Research has shown that
organizational leaders do not manage their corporate values due to a lack of support and the
exclusion of human resources officials who present the benefits of workplace practices for
corporate social responsibility, organizational efficiency, and success (Mainenti, 2016). GibbClark
(2013) posited that incorporating corporate social responsibility requires replacing managers who
have not successfully implemented corporate social responsibility.
Realizing change could be a challenge, as people do not generally welcome change
(Burton, 2016). According to Mainenti (2016) and Cameron and Green (2019), successful change
45
management cannot occur if employees do not understand the change (i.e., what is expected,
when is it expected, and how it is expected). Another critique of corporate social responsibility is
that leaders might not ensure the change includes the organization globally (Umble & Umble,
2014). These are critiques relevant to the study because organizational leaders acknowledge that
change must happen (Kotter, 2012), leaders have neglected the role of human resource
management (Zhang, 2020), and human resources management is the foundation of employee
relations and performance management (Wells, 2013). Human resources managers must guide
employee change (Rylatt, 2013).
Qualitative Risk Assessment Methodology
The purpose of qualitative research is to understand a topic or concern from the
participant’s perspective (Creswell & Creswell, 2018). Qualitative risk assessment is an essential
component of any successful strategy (Obicci, 2017). It is most effective between quantitative and
qualitative models (Goulden, 2020; Vargas, 2013) and, in some cases, the most practical (PMI,
2017). In qualitative risk management, analysts use descriptive and categorical treatments of data
instead of quantitative estimates (Allen, Carpenter, Hutchins, & Jones, 2015). The qualitative
descriptive and categorical treatments are analytical, evidence-based characterizations of risk that
have two functions: risk identification and risk characterization and analysis (Asadi,
2015).
Over the past 2 decades, risk management professionals and internal auditors have
become skilled at calculating the likelihood and impact of risks (Ramamoorti, Baskin, Epstein, &
Wanserski, 2017). Qualitative risk assessment begins with a risk narrative that includes the four
risk assessment modes: categorizing hazard, consequences, likelihood, and final risk (Allen et al.,
2015; Asadi, 2015). Qualitative risk assessment is a means of grading or scoring a risk to
determine the need for additional control (Alvarenga & Tanev, 2017). This researcher conducted
46
qualitative risk assessment and analyzed the data by employing a relative, or descriptive, scale to
measure probability through risk probability and impact assessment, the qualitative Risk
Assessment Matrix (RAM), risk categorization, urgency assessment, and professional opinion.
Risk Probability and Impact Assessment. Risk probability and impact assessment
commonly occurs through meeting and questioning stakeholders, examining ongoing work, and
documenting the results of the full examination (Goulden, 2020; PMI, 2017). Using this method,
the researcher could review the likelihood of risk occurring and the significance of that risk on
separate project objectives, such as budget, schedule, and performance (Asadi, 2015). Risk
probability and impact assessment assists with evaluating the possibility of risk realization and
magnitude of loss should the risk occur. As negative influences are threats and positive influences
yield opportunities (Vargas, 2013), a risk probability and impact assessment can be leveraged as a
leading indicator in applying the appropriate risk response strategy.
Qualitative Risk Assessment Matrix (RAM). The RAM probability and impact matrix
is a means of explaining the rating scales for the possibility and impact of a specific risk
(Goulden, 2020). The purpose of the RAM is to ascertain which risks require developed
responses (Vargas, 2013). A risk matrix is a framework of cells that shows the defined impact
(severity) and probability categories of loss events (Rooney, 2019). Probability and impact are
typically rated on a scale of very low, low, moderate, high, and very high (Vargas, 2013);
however, ratings can vary based on the structure of an organization’s risk management
framework. According to Rooney (2019), the risk scale has three levels of high, medium, and low
to present the risk of loss events. Rooney posited that the probability and impact categories
provide a distinct way to determine a suitable risk cell within the RAM for each loss event but are
limited enough to support variable solutions.
Risk categorization. Risk categorization is a means of grouping risks by their shared
causes to arrange and prioritize concerns (Asadi, 2015). Risk categorization is a type of qualitative
47
risk assessment for discerning the areas of risk with the highest exposure to work backward from
that point (Goulden, 2020). Categorizing risks enables qualitative risk assessment professionals to
view risks in small, manageable groupings (PMI, 2017).
Urgency assessment. Urgency assessment necessitates consideration of the imminent
threat of the risk (Asadi, 2015). The key is connecting the risk urgency with the data from the risk
ranking ascertained from the probability matrix (PMI, 2017). Merging these pieces of information
enables risk assessment professionals to determine a final risk sensitivity rating to prioritize the
risks (PMI, 2017).
Professional opinion. Professional opinion is the last qualitative risk assessment
approach. Leaders should seek risk assessment professionals’ opinions due to their knowledge,
skills, and ability to interpret risk information (Asadi, 2015). Interviews and risk facilitation
workshops are ways to gather data from professionals (Aburub & Mayo, 2017) about managing
qualitative risk assessment (Allen et al., 2015).
When organizational leaders determine risk tolerances, they should decide whether to use
qualitative, semiqualitative, or quantitative criteria (CCPS, 2019). Qualitative risk assessment
entails creating regulatory risk management measures rules, policies, standards, criteria, and goals
to protect the product or service by scrutinizing research needs and information or modeling
necessities (Dearfield, Hoelzer, & Kause, 2014). Analysts use the qualitative risk assessment
methodology to discern the outcomes of baseline risk and risk reduction strategies
(Aburub & Mayo, 2017; Asadi, 2015; Dearfield et al., 2014).
Critiques of Qualitative Risk Assessment Methodology
Critiques of qualitative risk assessment offer opportunities for enhancement to existing
methodologies. Enhancements focus on areas such as providing information that is key to
decision-making; guiding researchers in the selection of best practices, ensuring expediency and
48
accuracy of information and processes, and resolving concerns through the most appropriate
approaches (Bagnoli, 2015; Kleist, 2013). The qualitative risk assessment method does not include
the use of statistical values to assess organizational risk. Individuals who conduct qualitative risk
assessment use relative values as data entries for the values of potential loss; however, if there is a
need for statistical values, there could be gaps in the data (Denning et al.,
2014). There are other disadvantages of qualitative risk assessment.
Qualitative risk assessment includes the subjective evaluation of risk and its results (Asadi,
2015). Inaccurate qualitative risk assessments could occur due to the analyst’s subjective
perspective (Alvarenga & Tanev, 2017). Also, it could be a challenge to monitor the performances
of risk management to measure subjectivity (Asadi, 2015). Additionally, analysts generally do not
implement cost-benefit analyses, only subjective approaches that could present challenges for
implementing controls (Harris, 2014). Further, there could be inadequate differentiation of major
risks (Williams & Woodward, 2015). Finally, quality results require astute, perceptive, and
judicious risk management stakeholders (Asadi, 2015; Bagnoli, 2015; Denning et al., 2014;
Harris, 2014; Kleist, 2013; Williams & Woodward, 2015).
There has been diminished use of matrix-based approaches to quantitative risk due to
quantitative methods such as the applied information economics and the factor analysis of
information risk (FAIR; Catán, 2019). The FAIR is the international standard for cyber risk
quantification and a measure of the efficacy of cybersecurity controls for a basis for acceptable
cybersecurity investments (ET Bureau, 2019). FAIR is a means for evaluating cyber risk and
quantifying other enterprise risks (Sanna, 2019). The FAIR framework provides a risk taxonomy
with 12 components for codifying and calculating risk losses (see Figure 2). Each element has
four categorical areas for probability and loss calculations. FAIR provides a way to measure each
component for quantitative analysis conclusions (Wangen, Hallstensen, & Snekkenes, 2018). The
49
FAIR model is based on the mathematical probability theory of Bayesian networks (Dobrynin,
Radivilova, Maltseva, & Ageyev, 2018). Bayes’ theorem enables revisions to predictions as new
information presents (Fenton & Neil, 2018). Bayes’ theorem, experimental data (i.e., observed
values), and prior knowledge of an issue provide a combined approach for data analysis in which
the practitioner’s knowledge is part of the framework (Urteaga, 2016).
The FAIR model consists of numerical estimations and differs from qualitative methods
that characteristically compete at the probability and impact estimation stage. The methodology
contains two restrictions of cyber risk inquiry: the absence of a dependable lexicon to discuss risk
and a lack of an archetype for approximating losses from an economic perspective (RiskLens,
2020). The best way to determine the suitability of a quantitative method such as
FAIR for an organization’s needs is to deploy the method and assess its efficacy (Catán, 2019).
Figure 2. FAIR model. Adapted from “The RiskLens FAIR Enterprise Model,” 2020. Copyright
2020 RiskLens.
Reputational Risk Management Framework
Researchers frame theories to illuminate, predict, and understand singularities and expand
a prevailing awareness within the parameters of shifting conventions. The theoretical framework
is a means of familiarizing and defining theories about the studied problem. The frameworks
relevant for this study were reputational risks, change management, and business process
50
improvements. Reputational damage is the most significant organizational risk; therefore,
reputation risk management is necessary to protect both reputation and brand (Walter, 2016).
Further, leaders of reputable organizations such as Ernst & Young, Yes Bank, O P Khaitan & Co,
Premier Shield Group, IIFL and KPMG agreed that ERM is a systematic way to reduce
organizational risk to achieve business objectives. Reputational risk management is a significant
competitive driver in business and education and an important component of social status and
online communities (Walter, 2016). Khan and Digout (2018) indicated that the insufficient
measurability of reputation resulted in a lack of visibility in estimating market value. Thus,
reputational risk management is an essential framework for organizations (Walter, 2016) due to
its usefulness to enhancing organizational sustainability by raising visibility of impactful risks.
Three components warrant consideration to determine the degree of reputational risk. The
first is whether a company’s reputation is better than how it actually operates. The second is the
extent to which external opinion and expectations change. The third component is the quality of
organization within the company (Eccles, Newquist, & Schatz, 2007). The Reputation Institute
(2017) indicated that companies with excellent or strong reputations received significant societal
support. Reputational risk frequently correlates with operational risk (Walter, 2016). Operational
risks could have adverse effects on the company’s reputation that result in the loss of the business
relationships needed to achieve financial targets (Goetz et al., 2016). Due to the inherent nature
of risks, company leaders must take measures to predict and manage risks (Goetz et al., 2016). In
a business context, an organization’s reputation supports the ongoing value of a business; it is
important to manage risks that have the ability to adversely impact a company.
There are many risk types that can impact a company’s reputation such as strategic, operational,
financial, technical, competitive, supply chain, and other categories of risks. Table 1 presents the
51
risk types and definitions that focus on financials as defined by the Securities and Exchange
Commission.
Table 1
Risk Types as Defined by the Securities and Exchange Commission
Risk type
Definition
Finance
The level of haziness and/or possible financial loss basic to an investment
decision.
Business
Common stockholders compensated after organizations’ bondholders and
preferred stockholders; the risk is that of not obtaining any capital.
Volatility
The instability of stock prices. Even when organizations are not in peril of
declining, stock price could fluctuate.
Inflation
The loss of returns for individuals participating in cash equivalents because
of inflation.
Interest
If unloaded prior to maturity, bonds may be worth more or less than the
actual face value grounded on the interest rate.
Liquidity
Indecision as to whether investors will find a market for their securities,
possibly, at will, hindering buying or selling.
Critiques of reputational risk frameworks. Critiques of reputation risk frameworks vary
in concept (Tehrani, 2020). Due to the lack of commonalities across reputation risk frameworks,
accordingly, many organizational leaders do not know how to effectively manage reputational risk
(Farha, Sekeris, & Hermansson, 2017; Tehrani, 2020). Most reputation research has focused on
establishing reputation as external stakeholders’ judgments of the organization, including how
leaders develop their reputations and the positive and negative outcomes of the organization’s
reputation (Gatzert et al., 2016). Changes in the business environment has engendered modern
critiques of reputation risk frameworks. Due to the influence of social media, there is a need for
reputation risk management (Eberhardt & Schwaiger, 2016). Increased monitoring of risk by
banking and insurance regulators have also changed the business landscape. Another reputational
risk critique is that organizational leaders will focus on a single risk type; consideration of
52
different risk types (e.g., earnings announcements, media mentions, and operational risk loss
databases) to avoid narrow data (Farha et al., 2017). For example, legal risk and its implications
are an inherent consideration of reputation risk. If lawsuits ensue, especially if they last for an
extended time, proceedings could result in losses not fully known until years later (Walker, 2012).
For highly publicized events, the impact of legal risk includes immediate damage to an
organization’s reputation. Lawsuits can take years to settle and could result in devalued products
or services when settlements occur (Farha et al., 2017; Walker, 2012). There is a need for
reputational risk plans to mitigate the risk (Mani & Gunasekaran,
2018). Organizational leaders cannot manage reputational risk appropriately without change.
Change Management Framework
A change is a transition from one distinct state to another—for example, all enhancements
to a service, product, or system (Cameron & Green, 2019). Organizational change is important
(Kotter, 2012) and necessary for establishing reputational risk management. Organizational
leaders must envisage, design, and consistently apply reputational management programs in
organizational support structures through education, training, and the implementation of
information technology to advance workflow means, competencies, and proficiencies (Deloitte,
2013). Organizational leaders need to imagine how to achieve effective change, which, in the
case of this qualitative phenomenological structured interview study, means thoughtful
reputational risk identification. Leaders must emphasize the importance of change to employees;
when there are convincing and reasonable data provided, a method for change emerges
(Krzakiewicz & Cyfert, 2015).
Change management is an essential component of this study because it includes the
processes, techniques, and tools needed to manage the human capital aspect of achieving an
intended business outcome (Cameron & Green, 2019). Further, organizational leaders who do not
53
regularly implement change initiatives will experience difficulties or barriers in sustaining long-
term success (Abudi, 2017). Necessary changes could be instilling best practices to develop
formal standards that become part of the daily work environment. Both user involvement and
management support indicate successful implementation of a reputational risk management
initiative (Cameron & Green, 2019; Lackovic, 2017; Hayes, 2018).
Lewin’s force field analysis model suggests that all systems have driving and preventive
forces (Hamilton, 2016; McShane, Newman, Olekains, & Martin, 2018). Employees who block
objectives obstruct the realization of transformational plans (Kotter, 2012; Lewis, 2017;
Morrison, 2014; Popa, 2017), often resulting in ingenuity and a critical means of identifying and
mitigating risk (Gallo, 2017; Kotter, 2012). According to Ferrazzi (2014), lasting organizational
change cannot occur if the employees do not embrace the change by altering their behaviors.
Behavioral psychologists have noted that individuals do not always make cogent decisions and
that risk attitudes and behaviors often deviate from ideal behavioral patterns. Adriaenssen and
Johannessen (2016) theorized that most people oppose losing something that they have obtained,
and that people make biased situational analyses. Involving stakeholders as early in the process as
possible can mitigate the risk of resistance to implementing change management procedures.
Carter (2019) proposed five strategies for results: collaboration, optimism, values, respect, and
performance. Raising awareness of the reasons for and significance of the initiative could cause
employees to have positive impressions, relinquish prior business methods, and embrace the new
processes and procedures (Cameron & Green, 2019).
Critiques of change management framework. Change management research suggests
that change occurs continuously (Coleman & Thomas, 2017), in a convoluted manner (Senior &
Swailes, 2016) and with increasing velocity (Kotter, 2012). From 513 B.C., when Heraclitus of
Greece declared that “there is nothing permanent except change,” to the 21st century that indicates
54
“business as usual” (Bawany, 2016), change has been a part of life. Societal evolution takes
advancements and change. The urbanization of contemporary society occurred with four industrial
revolutions: mechanization and steam power, assembly line and mass production, automation and
electronics (Burton, 2019; Daemmrich, 2017), and cyber systems and networks. Technological
interference has had an impact since the first industrial revolution, leading to increased
employment and productivity (Burton, 2019). Strategic thinking, communication, and decision-
making are crucial components of organizational efficacy and productivity when operating under
time constraints (Burrell, 2019). Continuous evolution led to the fifth industrial revolution:
computational power (Burton, 2019; Ericsson, 2019).
Implementing change can produce resistance, confrontation, and challenge from internal
and external stakeholders (Starnes, 2016). The concept of change could cause disturbances, as
change processes and modifications might cause impediments and slow reform (Caruth & Caruth,
2013; Starnes, 2016). Change management initiatives could cause systems modifications that
could result in apprehension, influencing other business initiatives (Caruth & Caruth, 2013;
Senge, 2014). Understanding the critiques for change management is an essential concept in this
study because internal and external stakeholders must recognize change management processes
and procedures and future resistance to change (Husain, 2013; Starnes, 2016).
Another critique of the change management framework is the lack of understanding
factors, such as the loss of well-known, recognized, and consistent processes and procedures.
Resistance to change may arise based on conditions, individual choice and values, conceivable
forfeiture of authority, trepidation regarding change, struggle, stress, preference, and habits
(Pourrajab, Basri, Daud, & Asimiran, 2015). Change requires leadership and the development of a
new approach (Kotter, 2012). According to Burton (2016) and Kotter (2012), unsuccessful change
management initiatives generally correlate with misjudging the complexities of change,
55
comprehending the significance of establishing a governance body, and needing an established
governing body whose exclusive purpose is establishing requisite resolutions supporting the
business. Senior leaders should know about the power of vision (Kotter, 2012), organizational
models (e.g., change management), and the antecedents to change that result in the success or
failure of organizational operations and long-term financial objectives (Dewhurst & Willmott,
2014). Also, leaders could undervalue change management. Some managers do not have
established strategies, do not focus on improvement, do not employ employees as subject matter
experts, and have not prepared to train employees in new processes and procedures (Popa, 2017).
Maintaining communications with employees and stakeholders throughout transformative
initiatives is a means of facilitating reputation management (Heywood & Heidari-Robinson,
2016). Changes to reputational risk processes, procedures, and policies to reduce resistance to
change could result in improved business processes (Bakotic & Krnic, 2017).
Business Process Improvements Framework
According to Garza-Reyes, Rocha-Lona, and Kumar (2017), quality has rapidly become
one of the most significant influencers of consumers’ decision-making. Creating and promoting
value in a progressively service- and knowledge-based economy is a necessity requiring
awareness of the intangible benefits involved (Wirtz & Lovelock, 2016). Improving business
processes by making fundamental changes and maintaining performance levels is another
important organizational goal that could result in several benefits (Schulien, 2017; Walter, 2016).
The outcome of changed norms and beliefs of people reinforced by encounters could lead to
wanted change (Petrovic, 2016).
Over the years, there have been changes to business process improvement (BPI)
frameworks, with varied similarities and differences in the approaches (Silvia Inês & Charbel
56
José, 2015). Before examining the differences and similarities, a dialogue of the understanding of
BPI must occur. (See Appendix A for a graphical depiction of BPI.) Pyzdek (2003) defined BPI as
a methodical technique of enhancing fundamental organizational processes to achieve desired
outcomes. Later, Silvia Inês and Charbel José (2015) identified BPI as a performance
measurement system for improving sustainability and business processes. Processes are linked
activities to transform requirements into outputs (e.g., products and services) for people (e.g.,
internal and external customers) or for a group of stakeholders; completing processes should result
in the accomplishment of organizational goals (Tallon, Queiroz, Coltman, & Sharma, 2016).
Before creating improvement concepts, leaders must gather key information relevant to the
process under study (Vanwersch et al., 2016).
In this study, this researcher used the BPI approach to discern the best practices of
reputation risk management. Business process improvement is an important component in this
study, as prior research has shown the pressing challenges of not implementing reputational risk
strategies (Calagna, 2017; Deloitte, 2014). Frank Bunker Gilbreth, Sr., a groundbreaking supporter
of scientific management (1924–1968; Gibson, Deem, Einstein, & Humphreys, 2016), identified
BPI as scientific management. Gilbreth ascertained how to streamline work for employees and
improve output through clerical and manufacturing employees’ habits across industries (Gibson et
al., 2016). Gilbreth and his wife Lillian earned a reputation for their time and motion studies to
eliminate waste and identify the most effective manner of conducting work (Gibson, Clayton,
Deem, Einstein, & Henry, 2015; Gibson, Deem, et al., 2016). This study did not focus on
manufacturing; however, inputs, outputs, and processes were concepts applicable to the best
practices of reputation risk management.
The quality process leader Allan H. Mogensen, known as the father of work simplification
(1901–1989), developed the BPI framework of work simplification in 1926 (Hammer, 2016).
57
Mogensen proved the assumption that individuals of lesser status could not analyze and provide
more than habitual physical work false (de Haaff, 2016). Work simplification consists of the
principles of motion created by the Gilbreths (Hammer, 2016). Mogensen created a structured
strategy of connection in which all individuals interested in the process of improving work
processes could partake (de Haaff, 2016). Mogensen shaped a portion of the new BPI concepts
and procedures.
Ben S. Graham (1900–1960) continued the work of Gilbreth and Mogensen by advocating
that exhaustive documentation could indicate the need for process modifications (Ben Graham
Corporation, 2018a). Graham presented a model for the simplification of paperwork for
considerable organizational savings (Ben Graham Corporation, 2018a). Graham enhanced the
practices and procedures of benefit and cost analysis, design and analysis of forms (paper and
electronic), process analysis, process charting, project management, and implementation
techniques (Ben Graham Corporation, 2018b).
Walter A. Shewhart published a book with the basic principles of quality control (Nolan,
Perla, & Provost, 2016). Shewhart’s work was an inspiration to William Edwards Deming, who
developed the Shewhart Learning and Improvement Cycle of Plan, Do, Check, Act (PDCA; see
Figure 3, Appendix B). PDCA is a statistical analysis process with management viewpoints
(Nolan et al., 2016). Deming extended PDCA’s application to include all learning and
enhancement efforts. Shewhart later introduced the philosophy of total quality management
(TQM) in the business world (Coury et al., 2017; Kiran, 2016).
58
Figure 1. Plan, Do, Check, Act model.
The TQM philosophy has four components: (a) management answerability for continuous
improvement, (b) emphasis on work processes to achieve improvements, (c) utilization of
statistics for measuring process operations, and (d) employee contribution and enablement (Faihan
Mosaad, 2014). Deming hypothesized that training and enabling staff members to manage their
own would result in additional proofing errors and poor work quality in addition to augmenting
the use of process (Mahmood, Zubair, & Salam, 2015). In 1950, Deming took his
TQM philosophy to Japan, where it received support from the Japanese Quality Function
Deployment Institute (2018).
In 1928, Joseph M. Juran, another forerunner of business process improvement, authored
a document on the practice of sampling in examining and controlling manufacturing quality
(Abdel, 2014; Rost & Jubenville, 2015). Juran also emphasized the significance of establishing
orderly manufacturing trails for product design, prototype testing, appropriate equipment
operations, and accurate process feedback. Later, Juran composed the Pareto principle, named for
Vilfredo Pareto, the Italian economist (Ivančić, 2014). In 1906, Pareto detected that 20% of the
members of the population owned 80% of Italy’s land, thus the alternate name of the principle as
the 80/20 rule (Ivančić, 2014). In BPI, the 80/20 rule is the notion that 80% of the quality issues
59
in an organization are caused by 20% of the problems. Scholars use the 80/20 rule to create best
practice models. Later, TQM became a highly advocated process that preceded BPI.
Kaoru Ishikawa, an advocate of TQM in Japan, created the Ishikawa (fishbone) causeand-
effect diagramming tool (Sutterfield & Daramola, 2016). The fishbone is a pragmatic means of
establishing the causes of effects and how to cluster those effects together (Sutterfield &
Daramola, 2016). Scholars generally use the Ishikawa diagram in product design and quality
defect deterrence to recognize the possible causes for end result (Watson, 2015). Researchers who
use this framework understand each cause for imperfection as a basis of variation, of which there
are six categories: man, methods, machines, materials, measurements, and environment. Scholars
use Ishikawa’s cause-and-effect diagram to identify the root causes of problems and develop
solutions (Luca, 2015). There were additional phrases and tools created in the quality management
space, a forerunner of BPI.
Philip Bayard Crosby coined the phrases “do it right the first time” and “zero defects”
(Smith, 2014). Crosby expressed quality as conformity to the requirements that an organization
has established for its products based on the needs of internal and external customers (Smith,
2014). The purpose of Crosby’s two phrases is not to discourage errors but to inspire
organizational leaders to realize that people do not always cause organizational errors. A
significant component of Crosby’s method was that leaders should not force individuals to bear
the responsibility of poor quality. Instead, leaders should foster a top-down approach and share in
the accountability for quality measures (Smith, 2014).
The last approach is Lean production methodology, a means of maximizing customer value
while minimizing waste (Armstrong & Diehl, 2015). Presented in Japan by Taiichi Ohno,
Lean production methodology is an approach relevant to all businesses and processes
60
(Wickramasinghe & Wickramasinghe, 2017). Lean production is a manner of thinking and acting
to identify and eliminate organizational waste instead of using a cost-reduction program
(Armstrong & Diehl, 2015). The five values of lean production are: specify value, identify the
value stream, smooth process flow, production based on pull, and perfection through elimination
of waste (Armstrong & Diehl, 2015). Even though quality management and BPI are means of
reducing errors and improving quality, these processes and tools have received critique.
Critiques of business process improvements framework. BPI often produces mixed
results in drawn-out or constant implementation periods, inadequate organizational interest or
acknowledgment, and hidden expectations (Schramke, 2018). No single cause of unsuccessful BPI
efforts exists. According to Sallos, Yoruk, & García-Pérez (2017) and Schramke, (2018),
organizational leaders remain unsuccessful in judiciously managing and implementing changes
desired for the organization. Multifaceted organizations do not have environments with the
frameworks and supports needed to enhance, modify, and advance fundamental business processes
and maximize profit (Sallos et al., 2017). Leaders must choose the BPI project suitable for their
people to provide a basis for BPI accomplishment. On the other hand, BPI is an incremental,
evolutionary redesign of business processes (Sallos et al., 2017).
Synthesis and Summary
A synthesis emerges from a paradigm shift to challenge ideas about problems and solutions
and how to establish new knowledge and understanding. The study’s theoretical foundation was a
synthesis of three reputational risk management concepts: reputational risks, change management,
and BPI. Building and maintaining a favorable reputation enables a competitive advantage (Wang,
Yu, & Chiang, 2016). Reputation has an impact on a company’s position in the marketplace and
on stock prices (Ma & Zhan, 2016; Steffee, 2018). Reputation is a valuable asset; however, the
literature has shown that it is a challenge to protect (Eckert, 2017).
61
This critical review of the history of reputational risk began in biblical times (Walter,
2016) to the introduction of risk and the theory, defining risk by determining potential
consequences and measuring the probabilities against those results. Next, the review focused on
Knight (1921) and Goldratt’s theory of constraints, which showed that (a) leaders must address
the entire company as a system and (b) ideal systems may break down as change occurs (Moreira,
Rosario, Castaño, Sousa, & Meneses, 2014). Therefore, leaders must make improvements to
sustain organizational effectiveness (Moreira et al., 2014). Despite Knight’s idea and theory, there
are various definitions of risk, even in recent literature (e.g., Bakke et al., 2016; Mateescu et al.,
2016; Sadgrove, 2016). Knight’s (1921) risk definition and theory of uncertainty and a lack of
predictability present the evolution of risk into the categorization of risk types (Foss & Klein,
2016). Because Knight’s initial studies of risk had varied results, very few researchers utilize a
standard definition of risk (Elshandidy & Neri, 2015).
AON (Pretty, 2018) conducted a survey to determine the number of definitions for
reputational risk. The multiple definitions are no surprise due to the number of global news stories
focused on budding or actual reputational concerns (Ching, 2015). The literature review provided
information on reputational risk and the opportunity to evaluate conventions and views about said
risk. A paradigm shift in thinking remains at the center of reputational risk theory.
Reputational risk management and change management are the focal points of reputational risk.
Although the risk management theory lacked a specific definition, several theories, a
methodology, and frameworks underwent investigation for inclusion in this research. The relevant
theories were the theory of risk colonization, enterprise risk management, and corporate social
responsibility; the relevant methodology was the qualitative risk assessment methodology; and the
relevant frameworks were reputational risks, change management, and business process
62
improvements. Reputational risk requires multidimensional conceptualization aimed at the
application of the theory instead of reliance on a single point.
The organizational assumptions and beliefs about reputational risk received discussion in
the literature review. Practitioners and scholars could use this study’s data to develop the best
practices of reputation risk management with the concepts of reputational risk, change
management, and BPI. A concise history of reputational risk underwent examination to establish a
context for the study.
Summary of the Problem in Light of the Recent Research
Goldratt embraced the notion of organizations as systems to support an understanding of
risk management (Beer, 2015). The pervasive belief exists that organizations with better
reputations have better performance than their competitors; however, ambiguity remains about
how to develop such a reputation (López-Quesada, 2017; Swanson, 2013). Leaders must manage
reputational risks to attain financial objectives and obtain the right data to make effective
riskbased decisions (Gaudenzi et al. 2015). Sound decision-making requires vetted qualitative
information and accurately quantified data. The results of this qualitative phenomenological
structured interview study provided a status of the problem in light of the research.
63
(Intentionally Left Blank)
64
CHAPTER 3: METHODOLOGY
Overview
The first challenge when preparing to conduct a qualitative phenomenological structured
interview study is gathering the data relevant to the topic (Stringer, 2013). This chapter will
present the trends and significant data on reputational risk issues to identify areas in which
reputational risk could help. The data have shown that there is no best practice for developing
standard operating procedures for reputational risk (Calagna, 2017; Epstein, 2018). Thus, there is
a need for this qualitative phenomenological structured interview research study to fill the gap in
knowledge (Caro, 2017; Eckert, 2017; Stern, 2017).
Overview of Structured Interviews Qualitative Research Methodology
Chapter 3 presents the design and implementation of a phenomenological study on the
best practices of reputational risk management. Qualitative structured research is an approach for
questioning and analyzing the preliminary theory and philosophical conventions of the study
(Morgan, 2019). Researchers conduct structured interviews when they have only one opportunity
to interview the participants (Dilshad & Latif, 2013). Because structured interviews enable
participants to engage with topics that could provide solutions (as opposed to opinions), they are
an academically acceptable method of data collection (Morgan, 2019). According to Hampson,
Hicks, and Watt (2016), structured interviews enable an extensive collection of responses through
interviews. Structured interviews are an appropriate data-gathering technique for developing
thoughts and ideas, leveling qualitative research, and creating, expanding, and evaluating
programs (Hardy et al., 2016). This researcher conducted structured interviews with the
participants.
Researchers conduct structured interviews when there is a need for discussions with open-
ended questions instead of a closed-ended, question-and-answer format. The method enables
65
advanced preparation of questions (Creswell & Creswell, 2018). The interviewer confidently
prepares and delivers the structured interview (Creswell & Creswell, 2018; Roach, 2014). Roller
(2018) posited that structured interviews enable the understanding of mindsets and behaviors
related to a specific topic. Interviews with a limited number of unstructured and openended
questions inspire the participants to share their insights and beliefs (Creswell & Creswell, 2018).
According to Dube, Roberts-Lombard, and Van Tonder (2015), the purpose of qualitative research
is to collect wide-ranging data of the why and how of decision-making. There are detailed
strategies of inquiry, designs, or procedures in qualitative research (Creswell & Poth, 2018). The
qualitative structured interview method was the most effective way to collect data from
participants with related backgrounds and experiences (Carey & Asbury, 2016; Burton,
2014). Structured interviews provide tractability and elasticity to participants and researchers
(Martins & Martins, 2014). Additionally, qualitative research is a cost-effective method that
produces benefits from free-flowing conversations with participants with open-ended questions
(Creswell & Creswell, 2018). Furthermore, industrial psychologists and human resource
practitioners conduct structured interview research to increase organizational efficacy (Martins &
Martins, 2014).
According to Martins and Martins (2014), the disadvantages of qualitative structured
interviews are (a) the inability to apply statistical processes to the qualitative data, which obstructs
the ability to comprehend the larger population, and (b) the void of data reliability due to the
minimal number of participants. Researchers such as Martins and Martins and Williams, Grizzell,
and Burrell (2011) endeavored to increase the level of participation by utilizing a nonprobability
sampling method in which they selected participants based on the participants’ knowledge related
to the study. Moreover, Burton (2014), Martins and Martins, and Williams et al. used a meticulous
data collection methodology with reliable techniques and tools.
66
Overview of the Research Design
A structured interview approach used due to its aptness to obtain responses to the research
questions (Lune & Berg, 2016). This qualitative phenomenological structured interview study
produced data for analyzing common trends, themes, and findings. The researcher constructed a
narrative of the phenomenon by reviewing literature related to the subject of study. Qualitative
techniques enabled the researcher to understand participant experiences, as documented in
Chapter 4. According to Burton (2014) and Roach (2014), researchers should interview 10 to 16
participants. The researcher selected 16 participants to achieve the best results (Creswell &
Creswell, 2018; Morgan, 1996; Roach, 2014). The structured interviews provided ideas,
analytical processes, and stimulating dialogue (Krueger & Casey, 2014) that the researcher sorted
by trends and themes to discover the best practices to identify and mitigate reputational risk. The
process consisted of data collection, interview transcription, and coding for categories, trends,
and themes (Saldaña, 2016).
Procedures
The researcher followed all human subjects’ and Columbia Technical University protocols
and procedures to conduct the research study. Structured interviews occurred after receiving the
appropriate signed approvals and consent forms.
Population and Sample
Purposive sampling, the process of purposefully selecting experienced participants to
achieve the best results, was the method used to recruit the participants (Roach, 2014; Hanif,
Ahmad, & Shahbaz, 2018). Participants had a minimum of two years of experience in reputational
risk, reputational risk management, or an accredited higher education program. The comparatively
small number of participants or situations in qualitative research supports the uniqueness of each
analysis (Marshall, Cardon, Poddar, & Fontenot, 2013). The researcher transmitted the survey
67
instrument to each participant individually for confidentiality and segmentation. According to Oge
and Burrell (2012) and Onghena (2013), segmentation helps to uncover the best data to reduce
groupthink responses.
Selection of Participants
The 16 participants were experts involved directly in risk management strategies, policies,
higher education management, technology, and cybersecurity. Qualified individuals received
invitations to participate via e-mail (see Appendix C). Each participant reviewed and signed a
voluntary informed consent form (see Appendix D). The required informed consent form
presented each participant’s legal right to participate. After signing the informed consent form
and agreeing to participate (see Appendix E), each participant completed the demographics
survey (see Appendix F). The participants could withdraw at any time.
Ethical Considerations
The researcher completed an Institutional Review Board (IRB) and Academic Review
Board (ARB) application before conducting the study. The researcher followed all the IRB and
ARB criteria and described the data storage, safeguarding methods, and destruction methods and
how the results of the study will be published. Per IRB approval, the researcher described the
subject recruiting, informed consent processes, and the voluntary nature of the study. The
researcher also identified the potential risks for harm inherent in the study to ensure
confidentiality. The researcher protected the participants by removing names and job titles.
Further, the participants did not receive compensation or other gains for participation; rather,
participation was voluntary, and the participants could withdraw at any time.
Data Collection
Qualitative phenomenological structured interviews were the means to collect data. The
interview is a specific form of discussion that produces information (Kvale & Brinkmann, 2018;
68
Olson, 2016; Packer, 2017). A questionnaire was used in this qualitative phenomenological
structured interview study to collect data from the interview participants. The researcher
contacted and interviewed participants to ensure anonymity and segmentation. The responses
remained anonymous, and the researcher did not share the results with the other participants. A
questionnaire is an acceptable instrument (Oge & Burrell, 2012; Roach, 2014). The questionnaire
contained questions related to the studied topic, and the researcher administered the questionnaire
to each participant. The researcher collected and reviewed the data from 16 participants to ensure
consistency, accuracy, and validity. The responses were coded. The researcher recorded the data
in an electronic document saved as a .pdf file on a passwordprotected, personal computer used
only by the researcher. The researcher uploaded a backup file on a thumb drive, subsequently
stored in a locked, fire-retardant file cabinet in the researcher’s home office. All the participants’
names and titles will remain confidential, and the researcher will not publish any identifying
information in field notes, field examinations, artifact collections, or on the Internet.
Data Analysis
This researcher utilized qualitative, phenomenological structured interview to collect data
for subsequent analysis leading understanding who, when, why, and how, and the results of the
data (Charmaz, 2014). The research design enabled the orderly detection of trends, themes, topics,
and categories by studying the participants’ perceptions, questions, problems, and beliefs
(McMillian & Schumacher, 2014). This researcher simplified the information by asking the
following questions during data analysis: (a) What do the data indicate? (b) What was the looked-
for state, and how did the themes, topics, and trends connect? (c) What was the participants’
rationale for assimilating reputational risk management into their organizations?
and (d) What were the data found through the participants’ responses?
69
The initial coding of the data had seven subcategories—grammatical, elemental, affective,
literary and language, exploratory, procedural, and theming (Saldaña, 2016), all of which the
researcher employed in data analysis. The information was independently coded and segmented
(Looney, 2018; Saldaña, 2016) using NVivo processes. According to Saldaña (2016),
NVivo coding and process coding are the basis of grounded theory methods for small projects.
Through NVivo coding, this researcher used the participants’ speech as codes instead of
researcher-generated words and phrases. Coding was an appropriate method for practical research
(Bazeley & Jackson, 2019; Stringer, 2013). The researcher used gerunds (words ending with -ing)
to indicate actions in the information. The process coding occurred concurrently with the initial,
focused, and axial coding, and an analysis of the results was a part of the process (Saldaña,
2016). This researcher used focused, axial, and theoretical coding for the second cycle of coding
to develop a grounded theory. The second-cycle methods necessitated analytic skills, such as
abstracting, classifying, integrating, prioritizing, synthesizing, and theory-building (cf.
Saldaña, 2016). Theoretical coding commenced akin to a method that covered all other codes and
categories (cf. Saldaña, 2016).
Reliability and Validity
The purpose of a research study is to generate reliable (consistent) and valid (accurate)
outcomes. According to Creswell (2012), a coherent and systematic research process predicts the
reliability and validity of a qualitative study. Validity is a gauge of accuracy that the researcher
ascertained by providing the questionnaire to the first three participants to determine if there was a
need for adjustments. There were no modifications required before providing the remaining
questionnaires. The researcher established reliability by designing an easy-to-understand
questionnaire sufficient for collecting reliable information (Cover, 2009). The researcher
streamlined the questionnaire by limiting the number of questions that enabled the respondents to
70
expound on their experiences with the topic. All participants received the same questionnaire to
maintain the same conditions. Instructions were provided as a part of the instrumentation. The
process of constructing and distributing the questionnaire to the participants commenced in the
manner presented in this chapter.
Anonymity and Research Data Protection
A researcher must safeguard the structured interview audio recordings and documents
(Kite & Whitley, 2018). Qualitative data has an illustrative nature; as such, qualitative
researchers convey data with accounts, graphics, and videos (Lari, Rose, Ernst, Kelly, & DeLuca,
2019). The researcher examined the data for accuracy, importance, application, and consistency.
The data underwent scrutiny for tendencies, topics, themes, and categories, followed by coding.
Participants’ positions were as shown in Table 2.
Table 2
Participant Positions
Human subject
Participant Position
Risk Management Subject Matter Expert – Practitioner #1
Respondent 1
Risk Management Subject Matter Expert – Practitioner #2
Respondent 2
Risk Management Subject Matter Expert – Practitioner #3
Respondent 3
Note: 16 interview participants in this search study occurred using this construct.
Synthesis and Summary of Data
Data collected for this qualitative phenomenological structured interview research study
underwent synthesis and documentation. Chapter 4 presents the results to answer the study’s
research questions.
71
CHAPTER 4: RESEARCH FINDINGS
Overview
This qualitative phenomenological structured interview research study focused on the best
practices for managing reputational risk. The study had three guiding research questions:
RQ1. What risk categories should organizational risk management programs include to
predict reputational risk and achieve financial objectives?
RQ2. What are the leading practices of mitigating reputational risk?
RQ3. What reputational risk management techniques should organizational leaders use for
business process improvement initiatives?
This chapter presents the results of data analysis arranged by emergent themes based on
the responses of the interview participants.
Clarifying the Meaning of Qualitative Results
Qualitative research is a method of inquiry used in the social sciences to determine how
people perceive and experience phenomena (Burton, 2014; Liamputtong, 2011; Maxwell, 2012;
Saldaña, 2016). Qualitative research is nonstatistical inquiry to explore social phenomena through
inductive activities (Garner, 2011) that produce themes and categories during the data analysis
process (Liamputtong, 2011; Merton & Kendall, 1946; Probst, 2016). Using a relatively small
number of respondents in a qualitative study is a means of preserving the distinctiveness of all the
analyses (Marshall et al., 2013; Saldaña, 2016).
This qualitative phenomenological structured interview research study consisted of
thematic, inductive content analysis for in-depth insights into the lived experiences of risk
management professionals. The qualitative data provided narrative information about the
participants’ lived experiences (Burton, 2014; Probst, 2016). This researcher used the firsthand
interactions from the participants to identify the study’s outcomes (Soltanifar & Ansari, 2016).
72
The themes that emerged from these interviews indicated the best practices for organizational
reputation risk management. The qualitative data consisted of descriptions of the participants’
lived experiences.
Summary of Findings and Conclusions
Responses to Structured Interview Question 1
What topics or categories of risk should risk management programs include to predict reputational
risk and achieve financial objectives?”
The qualitative content analysis of the participants’ responses produced nine themes (see
Table 4). The researcher expounded upon the themes through explanations derived from a
sampling of responses. Data analysis and presentation entailed displaying identified themes
aligned with other qualitative content analysis studies (Burton, 2014; Ramakrishna, 2018).
73
Table 3
Themes Identified From Responses to Structured Interview Question 1
Theme #
Theme
1.1
How to understand the perceived relationship between reputation and financial
outcomes
1.2
How to find data on reputation as a risk
1.3
How to apply reputational distancing as a strategy to protect, rebrand, or rebuild
1.4
How to ascertain the impact of stakeholder levels of satisfaction to drive revenue
generation
1.5
How to communicate with employees when potentially challenged by reputational
risk
1.6
How to communicate with customers and potential customers when challenged by
reputational risk
1.7
Where to find compliance measures to avoid fines and other financial penalties
1.8
How to manage the impact of social media on reputation and financials
1.9
How to develop and maintain long-term reputation strategies for revenue
generation
Theme 1.1: How to understand the perceived relationship between reputation and
financial outcomes. All the participants described a connection between reputation and financial
outcomes.
• A respondent stated, “Prior experience and observations have allowed me to
experience a positive correlation between [reputation and financial outcomes], as
managing the categories above affect reputational risk in such a way that reputational
risks are limited.”
• Another respondent stated, “If an organization’s reputation is at risk [or] tarnished,
there is a direct connection to its financial posture [that has an] impact [on] financial
goals short-term or long-term. Financially losing potential market position,
recovering from the incident [or] event at hand, and future investments to regain
customer confidence and loyalty.”
74
• One respondent said, “A company’s reputation is directly tied to the revenue it
generates. Few businesses [with] unhappy customers and boards of directors are
meeting their financial targets.”
• An entrepreneur who manages business risk said, “As a business owner, my
experience is firsthand regarding the importance of reputational risks and how it
enables a business to reach their financial goals.”
• One participant discussed reputation and financial objectives in the academic
environment and said, “Operational realities [and] networking and exposure, as a
business strategy, tends to aid in attracting students [and] parents who are (a)
financially strong, (b) academic scholars, and (c) legacy admissions. These areas were
significant in both managing the reputation of the institution and attaining a strong
financial infrastructure.”
• Another participant said, “My role directly impacted the readiness of the organization
to receive funding for a strategic initiative that would have increased business
resiliency while protecting consumer data. In some cases, [we must] bring innovation
to specific markets in order to gain market share by converting new clients.
Marketing does a great job bringing customers to the organization. An incident would
have to impact the end consumer directly financially before true consideration of the
reputation is changed.” The participants’ responses indicated a relationship between
reputation and profitability, and job roles and functional roles could have an influence
on an organization’s perceived reputation.
Theme 1.2: How to find data on reputation as a risk. The participants had varying
degrees of focus on reputation risk and the associated data points.
75
• One participant said, “Consider the data source and having online ‘listeners’ on
websites and mediums to capture any data points that mention the company along with
incidents.”
• Another respondent said, “Implementation of improved measures (oversight)
monitoring operational controls to ensure an enhanced alignment managing
governance, data management, risk, operations, and data analysis. In addition to
focusing on managing human and physical assets, one should focus on managing
intangible assets, grasping the risk, and defin[ing] strategies. Removal of an
organization’s internal silos [and] developing a unified collaboration between
departments and stakeholders to abate undetected risks.”
• Another responded stated, “Data. 100%. If you can use surveys to gather data from
your consumer base and integral stakeholders, that could help, as long as you don’t
give them survey fatigue. Watching social media management software for trends on
click-through rates, buying behavior, etc.”
• Another respondent said, “All risks are important, but don’t they all work together to
build or destroy a reputation? There should be a continued focus there to understand
what makes up reputation using a risk lens.”
• A participant asked, “What number of risk functions do you see partnering with brand
managers to understand the components of reputation that might lead to identifying a
risk? This should be done proactively; we could potentially avoid something negative
from happening. We can determine a lot from risk registers talking with the business,
and things that bubble up during risk reporting. [There] are ways that we can find risk
data to work proactively.”
76
• Another respondent said, “Previous organizations moderately managed reputational
risk to stay on track with meeting financial goals. Reputational risk management was a
top priority, but my role was definitively necessary to continue winning contracts and
bids.”
• One respondent who had worked for federal government agencies had not observed
substantial efforts to manage reputation risk. The respondent said, “Due to the nature
of my professional experience in support of U.S. federal government agencies, there
was a lack of significant efforts noted on management reputation risk to meet financial
goals.”
As federal government agencies typically receive funding, one could infer a different need
to manage reputation risk than that of a corporate, for-profit entity from a financial attainment
perspective. However, Holzinger and Parker (2018) noted that professionals from government
agencies must effectively carry out their missions while new technology and functioning with
limited resources. In governmental agencies, reputation and external stakeholder satisfaction is
an essential component of receiving funding. However, organizations tend to have varied
approaches to managing reputation. Collectively, these responses suggest that the organizational
factors indicate the degree of reputation risk management. All the participants contributed to this
theme. One respondent said, “My observations and experiences regarding organizations
managing reputation risk to help reach their financial goals has been extensive”; however, no
participants indicated experiencing organizations with a consistent focus on reputation risk data
or reputational components as a distinct and categorical means of achieving projected
profitability.
Theme 1.3: How to apply reputational distancing as a strategy to protect, rebrand, or
rebuild. Bamfo, Dogbe, and Osei-Wusu (2018) posited that in an era of swift changes in business
77
environments, corporate rebranding continues to be a highly strategic means of managing a brand.
Managing a brand is a requirement due to varying competition. The intent is to produce a more
satisfactory consumer attitude toward the rebranded product. All the participants provided input
into this theme. Several respondents noted reputation distancing (i.e., moving away from another
company or transforming a company) as a means of achieving, regaining, or maintaining a healthy
reputation. The term conceptually mirrors the act of social distancing to prevent the spread of the
novel coronavirus (COVID-19) in 2020 (Greenstone & Nigam, 2020; Lewnard & Lo, 2020).
Organizational leaders conduct reputational distancing to prevent the absorption of a negative
reputation.
• One respondent said, “In order to distance ourselves from certain products and
embrace a new brand reputation as an application services model, we sold off part of
the business and completely rebranded the company with a new name, new service
offerings, and [a] new logo. We had to go so far as changing our ticker symbol with
NASDAQ. The investment was not effective, as shortly after we completed our
rebrand, the Internet bubble burst, and the company failed.”
• Another respondent said, “One company ultimately made a decision that the negative
brand recognition outweighed the positive brand recognition, so they essentially
rebranded. Similar things have been done across some budget airlines as well, i.e., big
mistakes, so renaming, etc.”
78
Another participant said, “A company that was right in the middle of an acquisition of
another company literally pulled out of the deal when news came out that the
leadership of the company that was being acquired did some seriously shady things
on their road to success. Once they were found out, the acquiring company all but ran
to get away from that company. As a person who helped manage their risk, this
should [not] have happened any other way. They were right for cutting their losses.”
• Another participant stated, “Based on observation, some companies sought to change
the face of their company[ies] by rebranding and rebuilding; sometimes just by
changing the logo, and sometimes with a complete makeover, such as [a] new
company name, leaders, logo, and colors and even new products to appear to be a
new company. Some companies go from using a name that they have had for decades
to a shorter initial or acronym-style name as an attempt to rebrand and increase its
attractiveness.”
The responses indicated that some organizational leaders will engage in reputation
distancing to a varying extent to achieve, regain, or maintain a reputation. Malliaris (2016)
posited that a company that has spun off an uncertain subsidiary and achieved a less-risky
objective is a less risky business because of severed ties with the past. However, a leader who
engages in a reputationally risky tactic and fails will carry an adverse reputation into future
endeavors (Malliaris, 2016).
Theme 1.4: How to ascertain the impact of stakeholder levels of satisfaction to drive
revenue generation. All the participants contributed to this theme. Multiple participants
indicated the impact of stakeholder satisfaction on the ability to generate profit.
79
A sampling of participant responses was:
“Ensure you have a diverse leadership staff and diverse employees because they can
make sure that your messages include all communities in ways that understand those
communities.”
• “Our employees have an important role in helping with the success of the business
and its reputation. Inclusion was instrumental in formally incorporating reputational
risk into our organization. Having our employees buy in and take ownership and
pride in their tasks has enabled us to raise the bar and maintain a higher level of
customer satisfaction.”
• “Stakeholders obviously make or break the business. Without customers, there is no
business. Even in a federal government agency, customers would be the public or
Congress, and if those groups fail to see the value of the organization, then the
organization will disappear over time.” This was a response consistent with Lerman
(2019), who suggested the resistance of negative perceptions to change because
people tend to view the world in a manner that endorses negative stereotypes of the
government, even when provided with new information.
• Another respondent stated, “Using a franchise [as an] example, the company had to
establish, across the board, a common direction [and] goal in order for the general
public [and] customers to come to expect to receive a high level of cleanliness,
service, and quality.”
• “Customer levels of satisfaction equate to job success and company success. The
revenue stream is the win-win-win arena.”
80
• “One organization went so far as to routinely refer to the customer as ‘king’ so you
could say that, for us, customers reigned supreme every day.”
“The customer satisfaction rating was, in turn, directly proportionate to the
organization’s revenue.”
• “Any time you expand beyond your market, you risk losing profit. It is always less
expensive with less risk to advertise to your current customer base.”
• “You want to not only keep your customers but to keep them happy and make them
loyal. Word of mouth and social media, which is the new digital word of mouth, are
the best ways to grow a positive cash flow.”
• Two respondents described the effect of a tarnished reputation on a company’s
standing. One participant described the potential consequences of a lack of
stakeholder satisfaction: “Financially losing potential market position, recovering
from the incident [or] event at hand, and future investments to regain customer
confidence and loyalty.
For governmental agencies, relationship management is an essential component of
governance practices (Eshuis & Klijn, 2012). Branding in the government has begun to attract
researchers, as organizational leaders have started using branding elements to develop
welldefined brands (Leijerholt, Chapleo, & O’Sullivan, 2019).
Theme 1.5: How to communicate with employees when potentially challenged by
reputational risk.
81
• One participant said, “When a company is the subject of an adverse event that is
reputationally damaging, they must respond with several critical actions. One action
is to ensure that [the] employees know what to do as well as what [to communicate]
and what not to communicate externally, especially to the press. The appropriate
82
actions need to be determined in advance; the time of crisis is not the time to
piecemeal communications. It was almost as disastrous to watch as the actual event.”
• Another participant stated, “When a reputational risk situation challenges an
organization, it is critical to have a document on hand and in the hands of employees
to instruct them accordingly. In either case, ongoing communications is essential.”
An organization should have preplanned responses to an event and not random, reactive
responses, as employees do not always make the right decisions. Two respondents described
unethical behaviors that potentially caused reputational risk for the organizations: “Experiences
and observations have allowed me to observe companies forgoing ethical policies, disregard
standard equal employment opportunity (EEO) practices, and assist with revising pertinent
content to support the company’s desired narrative.”
• Another respondent with extensive experience said, “[As] an independent contractor
in the late-’80s to mid-2000s, my focus was to help minimize any internal unethical
behavior that would affect the reputation of a very large, big-brand software
company [that] could have tainted their image and affect[ed] their revenues. During
my time there, upper management [took] advantage of their limitless use of the
corporate credit cards (e.g., booking first-class flights instead of economy, restaurant
receipts over $500 for two or more than four [times] in a week, and buying personal
items, such as a sports car or other expensive items). This was an unbelievable
situation because a few individuals were not reprimanded [and] because one’s
hierarchy in the company gave her [or] him the confidence to misuse funds. . . . A
83
task force helped to resolve this matter within the company’s walls to prevent any
public scrutiny, which could have affected their reputation.”
Theme 1.6: How to communicate with customers and potential customers when
challenged by reputational risk. Six participants described established governance through a
communications function and customer relationship management programs. The responses for
this theme included:
• One respondent said, “Policies and incident response plans need to be established
before a negative event occurs. By doing so, all employees will know what to do
when challenged by reputational events. The corporate communications area will
address [the] area.”
• Another respondent said, “In the military, we called the office that established these
policies and procedures the Protocol Office. We could not speak with the press or
anyone else other than our direct leadership if a negative occurrence took place. This
approach was best, [and] it typically saved the units quite a bit of grief for having to
retract statements or making the situation worse.”
• Another respondent said, “CRM programs are viewed as a table-stake function, but
they can be the cornerstone of keeping business.”
• Another respondent stated, “Governance in an organization is critical when it comes
to policy and procedures. It establishes the corporate stance on any topic and how to
behave accordingly. Without this as a respected function, the way employees engage
customers could vary. With [governance], there is an established standard to follow
for consistency and repeatability of [the] business process.”
84
• Another respondent said, “It is also too late to think about how to handle customers
after something goes wrong. How to communicate with the customers and potential
customers when potentially challenged by reputational risks has to be addressed in
advance. It is acceptable to address a situation as it is developing to adjust to the
situation, but if such processes are not predefined, then the situation is very much left
to chance.”
• Another respondent stated, “Communicating with customers when confronted [with]
negative reputational condition should be done in writing after the facts have been
established and approved by the organization’s legal office. However, only
designated leaders should speak to others outside of the organization about the risk
condition. How the risk condition is handled will affect the organization’s
reputation.”
• Another respondent stated, “However it’s done, it needs to be done in writing with a
positive spin, no matter how bad it is. Take the good from the situation and speak on
that, or at least indicate the positive steps that the company is taking. This will help
reduce the company’s exposure to secondary risks.”
Theme 1.7: Where to find compliance measures to avoid fines and other financial
penalties.
• One participant said, “Operations were more willing to produce documents or select
the documents to pass an audit or review [than] ensuring that best practices are
consistently followed. Near the end of my tenure, senior leadership in operations
85
eliminated the entire risk department responsible for patient and associate safety,
which led to a rise of fines [and] patient- and associate-related claims that could
[have] result[ed] in millions of dollars in losses.” This participant’s response
suggested that organizational leaders perform activities to remain compliant, but
once compliant, they may believe that they have eliminated the risk.
86
Another respondent said, “A vital component of an organization’s internal control is
the success[ful] management of the organization’s operation[s], values, ethics,
compliance, and reporting objectives. This would entail a strong organizational
structure and [the] assignment of authority and responsibility; the processes for
attracting, developing, and retaining competent people; [and] performance measures
and accountability.”
• Another participant stated, “Organizations deployed solutions to comply with recent
privacy regulations such as the General Data Protection Regulation (GDPR) and the
California Consumer Privacy Act (CCPA) to manage reputational risks. These
regulations come with hefty fines and broad announcements to the public when a
violation occurs.”
Two participants indicated a willingness to proactively comply with regulatory
requirements to avoid financial repercussions
• “As a former divisional director of safety, observations resulted in operations being
more willing to produce documents or select the documents to pass an audit or review
[than] ensuring that best practices are consistently followed.”
• “Companies make the decision to report breaches where, perhaps legally, they could
have or could not have (in grey-area examples), but an abundance of brand reputation
they normally report.
• “[What] would a company prefer if laws and ethics weren’t in the equation? It would
mostly depend on what the risk analysts said would be the most profitable.” Hill
(2019) posited that business conduct is still a challenging issue.
87
Theme 1.8: How to manage the impact of social media on reputation and financials.
The participants spoke of the impact of social media on reputation and its eventual influence on
financial standings.
• A respondent stated, “Prior to the Internet of things, reputational risk was easier to
manage due to slow spread. However, the Internet now extends exposure overtly or
covertly as a public form of communication.”
• Another respondent stated, “Social media can elevate a company or help its downfall.
Being fully integrative in your marketing campaign is a good strategy. A bit of e-mail
marketing, some Facebook, Instagram, geocaching, print, app development, etc.”
• A respondent stated, “Technology is the way we communicate, and it’s no different in
business. One negative Tweet or post can start a firestorm of posts that can make
stocks dive overnight. The same is true of the impact of positive posts. One young
social media influencer mentioned the use of an application, and within days, the
company’s stock fell.”
• Another participant stated, “Social media can enable success, or it can bring a
company down. Companies do not have the option of participating in social media
activity—they are out there, whether they decide to be or not. People will post about
a company through reviews [or] make recommendations or whatever the case may
be.
Once the company’s name appears in a post, it does not take long for people to latch
on[to] the post. Unlike celebrities, being in the press isn’t always good news. The
88
news has to be good for companies to show well; otherwise, their bottom line will be
impacted. This means that companies have to proactively lead others in how they
want to be perceived as an industry leader.”
Three other participants also indicated how social media and technology enabled
near-instant communication about companies and had an impact on a company’s
reputation. Rufaidah (2016) stated that business leaders do not manage risk in
consistent ways and do not typically provide a common way to manage reputation
risk. Further, making prioritization a standard is a necessity to advance business
knowledge and capabilities to face a digital environment.
Theme 1.9: How to develop and maintain long-term reputation strategies for
revenue generation.
• The participants noted the following: “The commonly defined risk categories should
not be viewed as independent areas of potential risk, but interdependent areas of risk.
Risk associated with one’s strategy can impact reputation, as can reputational risk’s
impact, [requiring] for one’s strategy to be adjusted, and so forth.” “Reputational risk
can be controlled by managing other risk categories. For example, the operational
risk as it relates to privacy regulations, and the technology risk to mitigate data
breaches, which also comes with hefty fines and broad announcements to the public
when a violation occurs.”
• Other strategies cited by the participants included, “Keeping abreast of current events
as it relates to one’s competitors and the impact of a negative event on them.”;
89
“Reputational risk can be controlled by managing other risk categories, including
strategic, operational, technological, and financial categories.”; “It is best to build
healthy and positive relationships with key members in the community you serve.
Ensure you have a diverse leadership staff and diverse employees because they can
make sure that your messages include all communities in ways that understand those
communities.”
• Another participant stated, “Senior leadership in operations eliminated the entire risk
department responsible for patient and associate safety, which led to a rise of fines
[and] patient- and associate-related claims that could [have] result[ed] in millions of
dollars in losses.” This participant alluded to termination of a formal risk
management function, an action that could have had a significant financial impact.
• Another respondent said, “Any time you expand beyond your market, you risk losing
profit. I have helped clients advertise to new target markets. This is also a risk. It is
always less expensive [and] less risk[y] to advertise to your current customer base.”
• Another participant stated, “A major beverage company targeted teenagers as a way
to maintain a strong reputation with new generations of future consumers. This was a
tricky endeavor because marketing to minors must be done carefully, but without it,
there may not be future consumers of the product. Part of risk mitigation is to acquire
new products that appeal to the next generation, whether it’s health-focused,
energyfocused, or follows some other trend. This strategy has paid off in billions for
more than 100 years for this company.”
90
• Another participant said, “The desired goal of operations was to free up the
consciousness exhibited by risk to increase profit margins by cutting salaries and
employee benefits.” The participants indicated that organizational leaders act
intentionally with long-term strategies when seeking to generate revenue.
Another respondent stated, “Not all consumers consume messages in the same place.
Think of it like investing in stocks. You want to diversify. You don’t want to put all
your money into one [thing]. If that one fails, you lose it all.”
Consistent with Szwajca (2018) and Fitzsimmons and Atkins (2017), there was the
shared perception that a company’s reputation is a valuable asset because it could provide
enduring competitive gains and market value. However, not all organizations focused on
managing reputational risks, despite financial implications.
• One respondent stated, “Businesses that do not have strong reputations are less likely
to hit their financial targets. There has to be a focus on reputation drivers and
financial drivers.” This statement was consistent with Tuttle (2018a), who theorized
that organizational leaders could witness doubled financial losses due to reputational
risk. They must align to hit targets and have sustainable success.
Another respondent said, “Some companies are very well-known in the technology sector
[for] pay[ing] attention to their reputation only when something happens and they are
forced to. Otherwise, it’s ‘get to the market’ as fast as possible at all costs.” Eccles et
al. (2007) indicated that leaders deemed reputational risk as a significant issue only
when making major decisions that could result in a higher amount of risk. DeLoach
91
(2015a) posited management’s disregarding dysfunctional conduct and “blind spots”
produced by the organization’s culture is a certain indication that the organization
will experience problems.
Responses to Structured Interviews Questions 2
The researcher addressed the second research question by asking, “What are the leading
organizational practices for mitigating reputational risk?” The qualitative content analysis of the
participants’ responses produced 12 themes of mitigating reputational risk (see Table 4).
Table 4
Themes Identified From Responses to Structured Interview Question 2
Theme #
Theme
2.1
How to engage C-suite and business leaders to support managing risk
2.2
When to engage C-suite and business leaders to support managing risk
2.3
How to employ technology to assist an organization with proactively managing risk
to its reputation
2.4
How to develop a plan to continuously review and update a strategic, reputation
risk management plan
2.5
How to determine the organizational risk tolerance level and risk thresholds for
managing reputational risk
2.6
How to establish a priority emphasis on the identification of risk from the lens of
stakeholders to manage reputational risk
2.7
How to assess risk for crisis scenario planning and operational resilience to
reputational risk events
2.8
How to lead strong board oversight on matters of strategy, policy, execution, and
transparent reporting for vital effective corporate governance for managing
reputational risk
2.9
How to establish a common understanding for risk and mitigating risk for
managing reputational risk
92
2.10
How to drive business value by extracting the relevant data points to understand the
threat that is unfolding
2.11
How communications influence the narrative of reputation perception
2.12
How to integrate risk into strategy setting and business planning for managing
reputational risk
Theme 2.1: How to engage C-suite and business leaders to support managing risk.
Examples of participant responses were:
“Reputational risk management starts at the top. By conducting strategic meetings,
senior executives and the board of directors should identify major threats to an
organization’s reputation and work with essential staff to ensure the risks are reduced
to a suitable level. To effectively manage from a strategic perspective, the executive
committee should establish a strong compliance administration, ensure
implementation of effective internal controls and continuous oversight across the
organization. Key areas of oversight should include administer[ing] a comprehensive
risk assessment, review[ing] and updat[ing] compliance program for changes based
on regulatory developments, implement[ing] compliance training, maintain[ing]
documentation of compliance-related communications, and employ[ing] processes
for reporting misconduct and suspected violations.”
• “Organizations will react to how the leader reacts to an event. It is vital to
demonstrate courage and stay positive when negative events occur. Effective
leadership, in this sense, does not make the main focus blame and shame if mistakes
are made. People should be held accountable for actions that are [against] company
culture, missions, and values; however, it [is] not productive to only focus on being
bloodthirsty for a vindictive penalty. This is about being a transformational and a
93
servant leader. Transformational leaders encourage and inspire staff to go about
change differently to enable the successful future of the organization. This is
performed by example-setting at top levels through a strong sense of corporate
culture, employee empowerment, and independence in the workplace. Leaders
influence and motivate people without over-managing. Employees are empowered to
make decisions in their assigned roles.”
• “Discuss adverse results from previous case studies from organizations that failed to
incorporate reputational risk management into their business practices. The bottom
line with each of the scandals was poor communication, a lack of transparency, poor
leadership, an inability to accept full responsibility immediately, and ineffective crisis
management. Executive sponsorship is needed to enable and support incorporating
reputational risk management into business processes.”
Theme 2.2: When to engage C-suite and business leaders to support managing risk.
• A participant stated, “Involve leadership with scenario building, tabletop exercises,
and crisis drills to properly prepare for risk scenarios. Prepare a crisis management
plan that dovetails into other risk categories. Depending on the product, industry, and
leadership team, there is either a complete focus on reputation risk or [a] lack thereof.
Clients, customers, and boards of directors are the ones [who] evaluate on an ongoing
basis. The products and services must appease these groups, or one could expect
[more] organizational transformation and downsizing.”
94
• A participant stated, “In times of significant negative events, leaders should form
cross-matrix teams in order to have the right mix of people to get to the root cause of
a situation.”
• One respondent noted, “C-suite members typically concern themselves with risk
management when circumstances arise that they must respond to. Otherwise, it is
BAU (business as usual). Where possible, senior leaders should delay other activities
that could be viewed as less essential, such as business travel and outings. It is critical
for leaders to be present when big challenges arise. It is important to not engage in
activities that would be perceived as leaders not taking the issues seriously.”
95
Theme 2.3: How to employ technology to assist an organization with proactively
managing risk to its reputation. Examples of participant responses were:
• “The most noteworthy enabler is utilizing information technology in risk
management. It is also critical to educate the key players, clarifying the efficacy of
technology as a tool to identify risk, data governance, and compliance. Technology
would enable management to have a birds’ eye view [to] evaluat[e] and analyz[e]
risks arising from internal operations and/or regulatory violations. This would prove
to be a valuable asset [for] mitigating financial losses, adverse media, [and a] loss of
trust and influence the success of the organization’s mission, organizational
transparency, and business processes.”
• “One must leverage technology to drive initiatives through technology-based
systems, which facilitate results [and] statistics. As a result, one can deliver the value
organizations need[ed] to navigate critical exposures and achieve strategic
objectives.”
• “The case of investing in technology and artificial intelligence must be made within
the risk management discipline. We can no longer function effectively without it.
With global employee teams and suppliers positioned around the world, spreadsheets
just don’t cut it. Too often, risk managers are not empowered through technology, yet
risk managers are expected to manage [at a] higher standard than other departments
and to prove our business value. That is hard to do with inept tools. It begs the
question if organizations are serious about managing the risk that could so easily
cause devastating harm to the bottom line.”
96
• “Organizations need to invest in automation. Excel spreadsheets have a place in
accountability, but million- and sometimes billion-dollar corporations are expecting
top-notch risk reduction without committing to effectively enable[ing] that
capability.” This participant inferred that managing risks requires modern technology.
The participant stated, “Defining the strategic approach with the support of financial
means can be operationalized through technology.”
For companies with e-commerce, Ramamoorti et al. (2017) discovered that online
commerce has contributed to faster business transactions. Participants responded in line with this
finding.
• “Employ technology to identify, monitor, and manage risk and secure the appropriate
resources to protect the organization’s brand and reputation. Distinguish areas
necessitating concern for a response plan to improve preparedness and rapid
response.”
• “The financial payment industry has taken great strides in terms of technology and
innovation, as the digital payment transformation began years ago. Physical cards
[have gotten] an upgrade with EMV chips, and stores accept digital currency as a
means of payment. This is a correlation and response to card and payment fraud.
Although threat actors have also changed the methods in which they continue to
commit fraud, the negative events have spurred the need for reputation risk
management.”
97
• “Financial, operational, and technological risks were largely focused on in my
position. With these risks being managed, the reputation of the company was able to
remain stellar and experience tremendous growth.”
Theme 2.4: How to develop a plan to continuously review and update a strategic,
reputation risk management plan. Several of the participants advocated for the use of strategy.
Examples of participant responses were:
• “If the focus was on reputation, not just brand image, staff could actually identify
things that point to areas that we have to pay attention to, not just areas that have been
the status quo. There would be the ability to pay attention to areas that deserve
attention, not just the areas that always get our attention because it defaults to
business as usual.”
• “If companies focus on risk details, they would have a better idea what is coming.
But most simply stop at high-level risk because prioritization is necessary, and a
cursory review is considered efficient prioritizing, which is normally not the case.”
This participant expressed the desire to conduct analytics based on risk details.
“There must be honest and open thoughts when you have a situation that can harm
the company’s reputation and the public’s trust of your organization. The key is to
have a sound managerial strategy.”
• Another participant said, “Consistently reevaluate approaches and their ability to
reduce reputational risk management and implement and utilize a strong checks-
andbalances system to ensure the practices are maintained with strategy, innovation,
ethics, and integrity.”
98
Theme 2.5: How to determine the organizational risk tolerance level and risk
thresholds for managing reputational risk.
• One respondent said, “What is acceptable in terms of risk should come from the
senior leadership of an organization. Helping senior leaders through an exercise of
understanding and establishing a risk appetite, risk thresholds, and the company’s
attitude toward risk and why—[I’ve] never seen this done with reputation risk. To
know where to begin, perhaps looks at other risks collectively. Not certain if the
result would be the same.”
• Another participant suggested establishing risk tolerance and risk threshold based on
past adverse events: “Ultimately, every breach that occurs (if the company survives),
you can almost guarantee will eventually improve that company’s risk profile in the
future if they learn from it and apply the learnings [before] a future situation.”
The responses suggested that organizational leaders may establish risk thresholds and
tolerances based on occurrences at other companies as well as at their companies.
Theme 2.6: How to establish a priority emphasis on the identification of risk from
the lens of stakeholders to manage reputational risk.
• One participant stated, “Like anything else, where a service provides, put yourself in
the position of the receiver. Managing risk is no different. Think about the board,
Csuite members, and [the] internal [and] external business partners. What would they
want, when would they want it, and what would they do with it? You then have to do
the work of understanding what are the blockers to accomplishing any of those
requirements on time, on budget, and in line with expectations. It is a lot to imagine
99
and work through, but that is the business of risk management. You don’t leave
results to chance.”
• Another participant stated, “Reputational risk has a great impact [on] an organization
[that] is attempting to gain traction in an industry versus a company [that] has an
established foundation.”
100
Another respondent said, “As they are all interconnected, the primary goal in setting a
superior reputation is and should be to earn through excellence in governance,
controls, and risk management and not manufactured through overzealous public
relations [and] marketing strategies.”
The participants also discussed roles:
• “Develop a strong cultural alignment by displaying and articulating the desired tone
at the top and conduct periodic assessments with middle management and lower-level
staff.”
• One respondent stated, “There are several ways to perform risk identification.
Regular rhythms with stakeholders brainstorming about potential risks is an effective
way to generate lists of potential risks. Employee risk management training is also an
effective way to broaden the sphere of awareness that would assist in the early
identification of potential risks that should be captured in a risk management log for
monitoring. Risk management training should also emphasize and encourage risk
identification from all personnel. Once risks are identified, documented, [and]
assessed and mitigation strategies developed, the mitigation initiatives can be worked
through the regular business rhythms. With the successful mitigations of the risks,
their impacts can be minimized, and reputational risks contained.”
Theme 2.7: How to assess risk for crisis scenario planning and operational resilience
to reputational risk events. Eleven respondents mentioned crisis management or business
continuity.
101
Examples of participant responses were:
“Have plans ready to activate: risk management plan, incident or crisis management
plan, business continuity plan, and disaster recovery plan. Because when something
adverse happens, it’s too late to start from scratch, figuring out what to do. We even
have to think about the unthinkable, like 9/11 and the COVID-19 pandemic that the
world is currently facing.”
• “If you have a business continuity strategy without a disaster recovery strategy, then
you have an incomplete risk profile.”
• “If there’s a corporate crisis plan in place but there’s no information risk strategy, you
may be able to respond to media and investors during a data breach, but you won’t
have the right cyber insurance to cover data losses and systems recovery. There are
layers to risk, but they cannot operate without each other.”
• “Every organization will face a significant crisis once or twice a year and other minor
obstacles.” Kamiya, Kang, Kim, and Milidonis and Stulz (2020) found that in
successful cyberattacks that resulted in the loss of personal financial information,
there was substantial shareholder capital loss larger than the out-of-pocket costs of
the attack.
• A participant stated, “This is the reason that having a pre-established management
strategy and a risk management plan in place is crucial. Strategic planning has
become a major business driver to success[ful] businesses more than ever before.
Whereas a decade ago, some organizations could scrape by without one, increasingly
102
competitive environments leave little space for organizations without strateg[ies] to
thrive or even survive.”
A participant said, “Based on my experience, companies should invest in business
resiliency and contingency to ensure that if an incident occurs, [they] will see little to
no disruption in business. [They must] ensure [that] their teams know what playbooks
they need to leverage [and] that [they] are driving the right technologies and
standardization across different departments.”
• A participant stated, “Developing a crisis response or crisis strategic plan sets the
direction and establishes priorities for your organization. It defines your
organization’s view of success and prioritizes the activities that will make this view
your reality. Meet with stakeholders and understand business requirements. They will
let you know what needs to be in your program for appropriate user adoption. This is
a good starting point to manage reputation risk.”
• Another respondent said, “Create a solutions response team. When a crisis hits your
organization, it is important to get your most effective team members assigned to a
small team to manage the situation. It is a mistake to underestimate the potential
severity of a risk to an organization’s reputation. They should have clear authority
from management. Management should also communicate who is on the team and
clarify their purpose and role in assessing the problem. This includes experts in public
relations and social media, experts in business operations, experts in risk
management, experts in information technology, experts in organizational
103
development, experts in project management, experts in data analysis, experts in
information technology, and experts in systems thinking.”
• Another respondent said, “Historical events [that cause] negative circumstances can
be very helpful in assessing what went wrong initially and [to learn] the steps
104
implemented to minimize or resolve the problem. Enterprise environmental factors
(EEFs) or organizational process assets (OPAs) contribute to risks happening if there
is no responsibility or accountability involved.”
Theme 2.8: How to lead strong board oversight on matters of strategy, policy,
execution, and transparent reporting for vital, effective corporate governance for
managing reputational risk.
• One respondent noted the following three actions: “(1) Knowing what the risks are.
This is something that companies just struggle [with]. (2) Knowing how to interpret
what the risk means in a dollar amount. Saying something is a risk is challenging
unless it can be given a dollar amount for a risk event. (3) Ensuring that the
decisionmakers that are acting on risks understand [Points] 1 and 2. For example, if
you report something, ensure you truly know (and [have] planned for) what that will
do for the company.”
• Another respondent said, “Conduct tabletop and simulation exercises and ensure
business continuity and disaster recovery plans are tested.”
• Another respondent stated, “More awareness by executives and employees after
viewing [or] experiencing a negative reputational event reduces barriers.”
• Another respondent stated, “From the previous question . . . lessons learned . . .
lawsuits can be avoided . . . loss of loyal customers . . . etc. . . .Companies have come
to understand how important it is to stay ahead of bad news and to be more
transparent, honest, and open in ways that allow other organizations to learn from the
poor responses and failures of other companies.”
105
Theme 2.9: How to establish a common understanding for risk and mitigating risk
for managing reputational risk.
Several participants described establishing a common understanding of risk and mitigation
to manage reputational risk. Examples of participant responses were:
• “Training is important for anyone working in the risk space or involved with risks. A
number of people quite simply do not understand the concepts of risk ratings and
analysis or how risk equations work. When a company has an understanding among
its staff members of what a risk actually is—and not just the definition but truly how it
will affect a company’s earnings—that is an enablement to the business as a whole.
Reputational risk management would then be learned as part of more centralized risk
management in general.”
• “Relearning from others’ misfortune or mistakes. [I] see other organizations in the
news that are impacted financially or reputationally due to cyber breaches, product
recalls, unethical behavior, etc. Proactively use the occurrence as an opportunity to
prepare your company.”
• “Some enablers would include looking across industries and studying trends of
organizations that have been impacted by reputation risk, the financial and market
impact, how they managed their response, and the length of time [it took] to recover.”
Theme 2.10: How to drive business value by extracting the relevant data points to
understand the threat that is unfolding.
• One respondent stated, “In my experience, companies usually do not fully focus on
reputation risks separately from other types of risk. They usually manage part and
106
pieces of risk to drive down exposure to reputational risk; this is how they, in effect,
manage risk to their reputation.”
• Another respondent said, “Make sure that there is alignment on how risks are
managed at all levels and how it all impacts the company’s standing based on its
reputation. Highlight risk and reputation in the company’s core competencies and
strategies and make reputation its own category of risk and then let the other risk
categories feed into that to help close gaps around it.”
• Another respondent said, “We need a way to figure out the unknown-unknown risks.”
• A respondent stated, “Historical information can include lessons learned, which can
help to gain new ideas to create new processes or systems that would reduce risks.”
• A respondent said, “Realistically, it would be naive to believe that companies that
have big bounty programs do not receive reports that contain customer data. These
companies, however, do have their reputation to consider. Whether they report is a
different matter.”
• One participant said, “Much like cyber breaches, negative events are distractors to a
company’s goals and initiatives. Negative events cost money and take time to resolve
and recover from. From these incidents and events, most companies learn that it is
faster (time-wise) and cheaper (financially) to proactively prepare and respond to
aspects of reputational risk versus post incident or event. Unfortunately, negative
reputational events are occurring on an increasingly frequent basis. The realization of
these impacts occurring to other companies can be a significant motivator to ensure
these same ramifications do not occur within your own company.”
107
• Another respondent said, “A project charter or a work breakdown schedule [to] clarify
the expectations and the strategic plan [for] meet[ing] or exceed[ing] those
expectations would help to improve the quality of reputational risk management.”
Theme 2.11: How communications influence the narrative of reputation perception.
• One respondent said, “In PR, any press is good press. An organization in the news, for
example, is at least top of mind for consumers, even if it’s a negative association. Take
that negative, give a heartfelt apology—a sweeping, positive altruistic action— and
give away something as a good gesture. Admit being wrong. Some people would say
the opposite, [to] blame others, anyone but you, but ethics are a prime concern.
Consumers have choices; they are incredibly discerning. Why would they go with an
organization that they feel is shady? Exposing a negative can happen but the positive
is that it offers a feeling of openness and sincere apology. Also admitting mistakes
early on is important. Try not to push situations under the rug. People will appreciate
your candidness.”
• Another respondent stated, “Be consistent in communicating the risks that are of top
concern and the risk categories associated with them.”
• Another respondent said, “Communication is the most important practice, [as] most
organizations lack efficiency in this area. Communication promotes transparency that
breeds trust, and trust is the foundation for great teamwork. Active listening also is
part of having effective communication. Both are essential, [as] a proactive effect can
reduce risk management issues or problems. It important to identify historical
108
solutions that worked, [as] this would help to prepare for unforeseen risk or
opportunities.”
• Another respondent stated, “Communicate, communicate, and communicate through
approaches [such as] social media, press releases, websites, podcasts, e-mails, print
advertising, radio advertising, [and] cable TV advertising. It is important that this
advertising focus[es] on media approaches that include clients, potential clients,
minority populations, and even linguistically and culturally competent messages for
people where English is not their first language. Whether it is your employees,
customers, [or] suppliers, over-communicate . . . actions, results, and the status of the
situation often. Communication is important in influencing the narrative of how much
your organization cares, your organization’s sense of urgency, if your leaders are
competent, and that your organization is taking this situation seriously. It is critical to
create feedback loops that include stakeholders from all levels from inside and outside
the organization. This can include structured interviews, town-hall-style meetings, and
monthly surveys that allow individuals to respond anonymously [about] issues [of] the
crisis. These activities can become forums where the organization can crowdsource
new ideas, approaches, and solutions. This also allows the organization to find out
how they are doing and ways that they can be better at what they do.”
Theme 2.12: How to integrate risk into strategy setting and business planning for
managing reputational risk.
• One respondent said, “Formally incorporating reputational risk management into a
business allows time to implement a policy and strategic methods to help avoid
negative events and potential risks.”
109
• Another respondent said, “Reputational risk can be control[led] by having a strategic
plan [and] discussing the pros and cons of what is working or not [working]. A great
plan is only created by effective communication and conversations, [with] all the
stakeholders involved to help minimize any risk that would affect a company’s
reputation.”
• Another respondent said, “Embed reputation into the risk management framework as a
formal component. Train employees on how to manage risk. The training does not
have to be deep, but they should know how the company thinks about risk, its risk
appetite, and [the] key risks of the company. Ensure that there is agreement ahead of
time on how risks are managed from a hierarchical structure and how it all impacts the
company’s standing based on its reputation. Highlight risk and reputation in the
company’s core competencies and strategies. Make reputation its own category of risk
and then let the other risk categories feed into that to help close [the] gaps around
it.”
• Another respondent stated, “Negative reputational events have improved the quality of
reputational risk management. Specifically, by implementing more proactive strategies
and combing through the preventive measures as it relates to possible reputational
risk.”
In addressing the second research question to understand the best practices for mitigating
reputational risk, most of the themes showed higher-level strategic focus as a leading practice.
The participants described strategy, planning communications, C-suite engagement and support,
use of relevant data, and establishing a common understanding of risk perspectives, including risk
thresholds.
110
• One respondent said, “Any practices that protect your client, stakeholder, or
inventory’s best interests and promote your brand positively will help you to manage
reputational risk.”
A consistent, debated topic in corporate reputation literature is that reputational risk, or
risk of reputation loss, results from all company risks (Pérez-Cornejo, de Quevedo-Puente, &
Delgado-García, 2019). Therefore, leaders should understand the details of managing all other
risks. The amalgamation of risk outcomes may provide the information necessary to develop a
comprehensive view of an organization’s reputational risk exposure and the remaining challenges.
Responses to Structured Interview Question 3
The researcher addressed the third research question by asking the participants, “How
should organizational leaders include reputational risk management techniques in business
process improvement initiatives?” The qualitative content analysis of the participants’ responses
produced seven themes for alleviating reputational risk (see Table 5).
Table 5
Themes Identified From Responses to Structured Interview Question 3
Theme #
Theme
3.1
How to determine the top 10 business process improvement tools for use to manage
reputational risk
3.2
How to protect the business using remote security insights and solutions to manage
reputational risk
3.3
How to recruit and retain a full-time Chief Risk Officer and team to focus on
reducing risk and increase opportunities for success
3.4
How and when to apply a SWOT analysis to determine the strengths, weaknesses,
opportunities, and threats of the organization to manage reputational risk
3.5
How and when to establish a risk proximity chart for determining risk velocity
3.6
How to develop and apply decision trees diagrams for charting risk management
actions to include any options that could result in extremely diverse solutions and
costs
111
3.7
How to ascertain trends that affect insurance protection coverage to manage
reputational risk
Theme 3.1: How to determine the top 10 business process improvement tools for use
to manage reputational risk.
• A participant said, “Some quality assurance tools are staple items. My go-to is
www.asq.org. Membership to ASQ is a must to get deep insights, but some of the
material can be accessed by going to the ASQ website and searching The Seven Basic
Quality Tools for Process Improvement (ASQ.org, 2020). It helps ‘sell’ the program
when risk information is backed up with the outputs from reputable tools.” This
participant referred to the seven basic tools for process improvement: cause-andeffect
diagram, check sheet, control chart, histogram, Pareto chart, scatter diagram, and
stratification.
• Another participant said, “A key technique used to help manage risk is the SWOT
method. This is a magic quad that makes the current situation more visible. When
listed out, these factors make the risk more real, especially for an intangible asset such
as reputation risk that can have such [a] major impact on an organization.”
• Another respondent said, “Managing risk is sometimes a ‘sell’ to management, even
though they know what managing risk can mean. Listen for what they are saying
without explicitly stating it. If there is not a way to readily develop that information,
automation is an option [as well as] business process improvement tools [and]
solutions and whatever else will meet the needs of what is being requested.”
Theme 3.2: How to protect the business using remote security insights and solutions
to manage reputational risk.
112
• A participant said, “It is my belief that businesses perform better when they can
forecast and react swiftly—the precise reason to support threat intelligence
automation. Some platforms [offer] near real-time data that is external to a business. It
is a trade-off because when you open up your business to vendors, more oversight has
to be put in place and managed. The reward, though, is usually far greater [than] the
risk—usually. But this can be addressed by performing due diligence before deciding
upon a specific vendor.”
• Another respondent stated, “Third-party solutions can provide insight above a
business’s capability. We utilize third-party solutions to collect data external to the
organization to provide security intel that provides the immediate ability to reduce
reputation risk and other types of risks.”
Theme 3.3: How to recruit and retain a full-time chief risk officer (CRO) and team to
reduce risk and increase opportunities for success. Today’s global business environment
requires that risk management aligns with business strategies and protection against financial
losses (Amoozegar et al., 2017). The CRO strives to reduce risk and increase opportunities for
success to achieve the organization’s long-term strategic targets (Karanja & Rosso, 2017;
Wasser, 2019).
• One respondent stated, “Making an organization’s leadership aware of the potential
impacts that [could] result from negative reputation damage can be powerful evidence
of what could occur in their company if risks were not professionally managed.”
• Another respondent stated, “Hiring [and] identifying a [CRO] would enable more
organizations to formally incorporate reputational risk management into business
process improvement initiatives.”
113
• Another respondent said, “A trained staff on incorporating and managing reputational
risks will help with ensuring the success of business process initiatives.”
• Another participant said, “Properly trained people with risk certifications such as
CRISC [Certified in Risk and Information Systems Control]. Outsourced agency
support with out-of-the-box processes, procedures, crisis plans, and other resources
that can be held on retainer and help manage some of the scenario-building with
leadership. Proven communications tools that make it easy for interdepartmental
communications to occur, such as SharePoint, MS Teams, and Yammer. Insurance
partners who can help train, educate, and prepare organizations that value risk
strategy.”
• Another participant stated, “The best way to effectively manage a reputation is to hire
professionals [who] understand risk as a full-time focus. Something as significant as
reputation that drives revenue is too important to be left to chance or as a part-time
responsibility.”
Theme 3.4: How and when to apply a SWOT analysis to determine the strengths,
weaknesses, opportunities, and threats of the organization to manage reputational risk.
Examples of participant responses were:
• “By understanding the mission along with key objectives of the organization and its
stakeholders, leaders should conduct a thorough SWOT and gap analysis across key
functional areas that can either mitigate or increase the possibility of risk.”
• “If an organization undergoes a SWOT analysis and keeps up with a strategic
scoreboard or dashboard for their organization, [it can mitigate] most major liabilities
and risks.”
114
• “In risk management, you need to think critically about a given situation and the
potential for [risk to come to fruition]. A good risk manager will ask why and then ask
why again when the question is answered. The ‘5 Why Analysis’ a technique that will
help break the situation down [to] get to underlying causes.”
• “Find out what sets the organization apart. What are the positives? Build on those.
Perform a SWOT analysis constantly, [and] mitigate risk by managing threats and
taking advantage of opportunities.”
• “Analysis through the SWOT method can be used alongside risk management
processes to better understand strengths, weaknesses, opportunities, and threats. These
are more of a complementary process not recommended for use in the place of a
sanctioned risk framework.”
• “The adverse press will force most companies to rethink strategies around protecting
their reputation. When they take a hit for a negative event, that will reactively drive
the change that should have been proactively implemented.”
Theme 3.5: How and when to establish a risk proximity chart for determining risk
velocity. Three participants discussed risk velocity.
• One respondent said, “Risk velocity refers to how fast a risk will affect an
organization, and scoring that risk is a part of an enterprise risk management
program.”
• Another respondent stated, “Most companies consider risk from a perspective of
likelihood [multiplied by] impact, but how quickly the risk is coming toward the
organization must also be considered. Risk velocity can be baked into a risk matrix or
used as standalone model.”
115
• Another respondent stated, “The velocity enlightens us on how close looming risks are
to realization. It facilitates prioritization.”
Theme 3.6: How to develop and apply decision tree diagrams for charting risk
management actions to include any options that could result in extremely diverse solutions
and costs. Three participants discussed decision trees.
• “Quantifying reputation is difficult until a trigger causes a surge in profit or a quick
loss of sizable revenue. Decision trees are useful in deciding whether to act or invest
or not.”
• “As the senior risk leader in the company, my team relies on the most effective
solutions, tools, and techniques to enable strategy by reducing risk. Numbers help tell
the story and decision trees, as well as trend charts, are almost an imperative to my
recommendations.”
• “Actions have direct or indirect impacts on the overall reputation, whether it is
immediate or long-term. Modeling possible outcomes and costs of resources [is] an
internal control technique that can be applied before making decisions to help with
cost analysis.”
Theme 3.7: How to ascertain trends that affect insurance protection coverage to
manage reputational risk. Two respondents inferred that insurance protection was a means of
managing reputational risk.
• “Cyber insurance is an area where the enterprise risk function and IT risk function can
strategically partner. The IT risk manager will have a better sense for the IT/IS posture
of the company. This information [will] help an organization when they perform due
diligence to acquire the appropriate amount of cyber insurance coverage.”
116
• “In risk transference, insurance forms need to be completed for cyber coverage and
financial loss protection. In a former role, responsibilities included collecting the
information security data used to populate the documents. This was a first for the
company and the risk department, obviously, and a huge win. We gained a new partner
with those managing risk for the enterprise, and we added value and gained more
visibility. Insurance coverage won’t protect the reputation when there is a negative
event, but it can help the company cover areas that would be pain points for customers
and other stakeholders.”
The researcher determined the themes above from the participants’ responses about the
best practices for reputational risk management. As indicated in the research, organizational
leaders can gain benefits by combining the areas of risk management and business process
management. Combining risk management and business process enables leaders to reduce risks
when designing business processes and to mitigate risk when needed (Aragon, Miklos, &
Schulkey, 2019). Consistent with Aragon et al. (2019), the participants affirmed that integrating
reputational risk methods into process improvement initiatives would be an effective means of
reducing reputational risk and attaining goals.
Chapter Summary
The qualitative content analysis of the structured interview data produced 28 themes of
reputation risk and potential profitability that the researcher organized into three high-level
categories: (a) risks coverage to achieve financial objectives, (b) leading practices to mitigate
reputation risk, and (c) business process improvement techniques. An evaluation of the interview
data showed that the participants specified phenomenological responses to questions using
personal terms (e.g., “my experience,” “my observations,” “my former role”). There were no
117
conflicting responses from the participants. The respondents validated the need to manage and
mitigate reputational risk to achieve financial goals.
The emergent themes broadly showed that organizational leaders do not integrate
reputation as a distinct category within their risk management frameworks. Further, reputational
risk does not receive consideration, leading to inept management of reputational risk.
Subsequently, an adverse event could have an impact on revenue generation. In addition, the
themes suggested a lack of essential technological resources, such as automated platforms. The
participants described using antiqued, inefficient risk management tools, despite the requirement
to provide value as a corporate function. The findings also showed support for the appointment of
CROs and CRO staff to ensure a focus on risk, including reputational risk. Considering the
financial crisis of 2007–2009, ongoing corporate failures, and current corporate‐governance
requests for the installation of CROs and risk‐management committees, there is a need to know
what role risk officers fulfill in organizations (Mikes, 2014).
The findings also showed that integrating reputational risk management into strategic
plans enabled a consistent focus on key areas. The results provided resounding support for
integrating reputation risk management into strategic planning and organizational plans.
According to Gatzert and Schmit (2016), there should be a focus on the identification and
significance of key stakeholders, the impact of dynamic events on organizational reputation, and
the impact of technological advances. The participants had not experienced the integration of
reputation risk management with organizational strategy. The findings also indicated the need to
ensure that employees and leaders know about their expected behaviors during significant,
unexpected events. Leaders should have strategy documents, such as a crisis management plan,
118
for risk response. The findings showed that in the event of an organizational crisis, employees
tended to display unethical behaviors.
Organizational leaders seek to maintain positive images and reputations. However, the
findings indicated that these leaders often focused on their reputations reactively after an adverse
event and learned about reputational risk from other businesses. The findings also showed that
leaders implemented reputational distancing if they needed to disassociate from another
organization. The participants reported occurrences when organizational leaders sought to protect,
rebrand, or rebuild their images. Poor reputational risk management suggests the need to pay
attention to the significance of managing reputational risk (DiPietro, 2017; Fickenscher, 2018a,
July 11, 2018b, October 1; Hagel, 2013; Mitchell, 2018; Stevenson, 2018; Wertheim & Bernstein,
2017).
Communication was a necessity, and leaders must provide support risk managers with
resources for adequate communication. Communication with stakeholders included directors,
C-suite executives, vendors, clients, and customers. The findings further showed that stakeholder
satisfaction influenced the organization’s reputational and financial success. How stakeholders
discussed the organization on social media also had an impact on reputation. According to this
study, risk managers believed they could control reputational risk by managing other categories of
risk in the company. Risk managers also thought there should be a specific focus on risk for
comprehensive oversight of reputational risk. The findings showed that leaders did not consistently
aggregate data to provide insights into reputation, which caused them to face a loss of revenue.
The purpose of this qualitative phenomenological structured interview research study was
to identify the best practices of predicting and mitigating reputational risk to achieve projected
profitability. As shown in this chapter, there were best practices successfully developed.
119
Administered by experienced practitioners, the best practices could provide organizational leaders
with insights into successfully mitigating reputational risk to achieve profit goals by
amalgamating risk data. The best practices could also provide a model for organizations that
receive funding based on their perceived value to external stakeholders.
Chapter 4 presented the answers to the research questions. The chapter addressed each
question independently and provided thematic summaries of the findings of the three research
questions. Chapter 5 will provide the study’s contribution to the body of knowledge, additional
observations from the study, and recommendations for further research.
CHAPTER 5: CONCLUSIONS AND RECOMMENDATIONS
Conclusion
This chapter presents the key findings of this qualitative phenomenological structured
interview study. The goal of this study was to discover the best practices for predicting and
mitigating reputational risk. This chapter provides the study’s contribution to the body of
knowledge on risk management, the study’s implications, recommendations for future research,
and conclusions. The chapter includes a model that organizational leaders could use to
amalgamate data and predict and mitigate risk. There is insufficient management of reputational
risk as a distinct category. Some leaders do not integrate reputational risk into their risk
management programs. Organizational reputation has an impact on the ability to achieve
projected profitability; therefore, organizations must have effective techniques to predict and
mitigate reputational risk challenges.
120
Examination of Results
The structured interviews showed the need for research on effective ways to predict and
mitigate reputational risk. Leaders should focus on reputation as a distinct category of risk while
aggregating information within other risk categories to identify more impactful events. This study
was a means to discover the best practices of identifying and predicting risk detrimental to
economic standing and profit attainment. The research questions were:
RQ1. What risk categories should organizational risk management programs include to
predict reputational risk and achieve financial objectives?
RQ2. What are the leading practices of mitigating reputational risk?
RQ3. What reputational risk management techniques should organizational leaders use for
business process improvement initiatives?
Structured interviews were the means used to explore the research questions. The results
produced three high-level categories of themes: (a) risks coverage to achieve financial objectives,
(b) leading practices to mitigate reputation risk, and (c) business process improvement
techniques. The researcher kept the identities of participants anonymous to ensure voluntary
participation and to safeguard the participants from bias or coercion. A researcher does not choose
participants based on any aspiration to authenticate a viewpoint or interest that could have
resulted in skewed objectivity (Krueger & Casey, 2008; Liamputtong, 2011). Member checks
occurred to alleviate bias, and the researcher correctly handled and analyzed the data. Two
independent doctorate-credentialed professionals assessed the data and the results of the analysis
to ensure the accuracy of the study’s findings.
121
Contribution to the Body of Knowledge
This study contributed to the body of knowledge by providing the risk management
discipline with a different lens through which to understand, aggregate, and view risk
management information. The three categories of themes were (a) risks coverage to achieve
financial objectives, (b) leading practices to mitigate reputation risk, and (c) business process
improvement techniques. The direct beneficiaries of this qualitative phenomenological structured
interview research study were risk practitioners, trainers, third-party vendors, and others
responsible for identifying and predicting significant risks. A search of major online scholarly
databases provided organizational frameworks and techniques for managing reputational risk and
showed the financial implications of not managing reputational risk. Leech (2018) asserted that
there is a global lack of integration of strategic risk management with performance.
The results of this study showed that leaders must communicate and implement effective
reputational risk practices to avoid the pitfalls of operating with narrow views of their risk
landscapes. Hutchinson (2000) argued that, by nature, senior organizational leaders are
risksensitive but not risk-taking. Organizational leaders use costly resources to reduce risk but
often do not proactively guard reputation, an asset with an effect on the organization’s ability to
realize goals (Moon, 2016). Bonime-Blanc and Ponzi (2016) found that executives who do not
recognize the pervasive influence of reputation risk are unable to effectively manage the impact
of reputation. A key finding of this study was that organizational leaders who do not establish risk
management programs could not address risks to their goals and objectives. Another key finding
was that amalgamating risk data points could indicate unidentified reputational risks.
Integrating the best practices of identifying and predicting reputation risk into risk
management programs could provide clarity in the decision-making process. Best practices can
122
enable the prioritization of impending threats and early identification of the resources needed to
reduce risk exposure. Chapter 2 showed that events had adverse effects on well-established and
well-branded organizations that caused substantial financial impact. The results of this study
provided three best practices of predicting and mitigating risk through amalgamated indicators.
First, the results of this study showed the risks that leaders should include in their risk
management programs to achieve financial objectives. The literature review in Chapter 2
indicated that insufficient reputational risk management could result in potentially disastrous
situations, such as bad publicity, the loss of customers and hard-earned status, and fines. The
literature review indicated that there was a lack of technique for aggregating risk information to
envisage the highly valuable, but intangible asset of reputation. This study’s findings provided the
best practices for moving from managing risk in a disjointed fashion to harnessing the entirety of
the data to avoid disaster. Data typically undergo aggregation and grouping according to
commonalties (Jones, 2019). This research suggested that the amalgamation of data did not
require an initial affinization of data points, but, rather, an ability to analyze the aggregated data
to visualize previously undetected or overlooked risk events. Technology provides ways to
accurately and rapidly aggregate data (James, 2016) and is more effective than performing the
task manually.
The second contribution of these findings related to leading practices of mitigating
reputational risk. The researcher expanded the body of knowledge through the 12 themes that
emerged from participants’ responses. The themes consisted of board oversight, C-suite and
business leader support, technology, strategic scenario and business planning, organizational risk
tolerance, shared understanding, and communication. The participants identified the best practice
areas as risk elements that many leaders and risk practitioners have not integrated into their risk
123
management programs. Leaders can implement regularity by using the best practices developed
based on these findings.
The third contribution of this research related to business process improvement
techniques. The seven themes identified through data analysis provided information about
organizations, including reputational risk management techniques in BPI initiatives. The data
showed that leaders and practitioners should develop best practices to offer guidance to
professionals with risk management responsibilities. The best practices lend guidance for
applying business process tools and risk management leadership value. BPI tools provide a
standard for reviewing, comparing and contrasting, cost-out, and other benefits. Quality systems
management tools enable the reinforcement of risk management programs through proven
techniques for planning, assertion, control, monitoring, and continuous improvement. Integrating
the best practices into a risk management program is a way for organizational leaders to gain a
clearer picture of risks as they occur. Leaders must meet the expectation of customers,
regulators, shareholders, and other stakeholders; thus, they must have the ability to make
informed, risk-based decisions.
Leaders in all business sectors and industries could benefit from this research by using the
findings to develop the best practices for predicting and mitigating risk. The study’s results
showed an alignment to the components of the 2017 COSO ERM framework presented in the
COSO Helix in Figure 1. This study also provided information to close the gaps in the knowledge
of BPI and amalgamating risk for improved risk-based decision-making. This research addressed
a gap in managing the reputational risk resultant from amalgams based on other categorical risk
information.
124
Theoretical and Conceptual Framework Discussion
Understanding the intricate nature of reputation and its challenges is a means of enhancing
the knowledge of managing risk (Szwajca, 2018). There is a need to distinguish between the
theoretical frameworks associated with this topic and the conceptual framework resultant from
this research study. Leaders must understand the connections between reputation risk theory and
conceptual frameworks to improve understanding of utility and application (Johnson, 2017). As a
result of the analysis of the responses obtained through this research study, this Researcher was
able to connect reputation risk theory and concept to develop and recommend a practical
framework model; L. Jones 10-Factor RepRisk Framework (2020). The L. Jones 10-Factor
RepRisk Framework (2020) is a schematizing instrument, contributing a central focus, perceptual
diagram, and design to strengthen practical debates (van der Waldt, 2020). The L. Jones 10-
Factor RepRisk Framework (2020) depicts focus key areas to predict and mitigate reputation risk
and provides potential consequences of an inept focus on reputation risk. Accordingly, the L.
Jones 10-Factor RepRisk Framework (2020) provides a conceptual means to translate theoretical
constructs into practical execution based on categorical factors and the areas of focus
consequential to the improper management of reputation risk. This research study addressed the
gaps in risk management programs for managing reputational risk.
Recommendations
This study was a means to explore the phenomenology of reputational risk and potential
profitability, two components of business that have not received adequate attention in
contemporary business (Dijkmans, Kerkhof, & Beukeboom, 2015; Meadows & Meadows, 2016;
Sanzillo et al., 2018; Spence et al., 2016). Reputation risk management is a means of critically
considering an organization’s vision and strategy (Campbell, 2017; Graybeal, Cooper, & Franklin,
125
2019). The process also entails investigating the contexts and implications of ineffective risk
management for reputation and profitability, the role of leadership, strategic integration into
business plans and risk management frameworks, multichannel communications, ethics and
compliance, technology, social media, resiliency, protection, and BPI. The researcher
recommended that more organizational leaders adopt the L. Jones Reputation Risk Management
Framework, a model developed from this qualitative phenomenological structured interview
research study.
An exploration of the literature enabled the identification and organization of the theories
pertinent to this study (Aarseth, Ahola, Aaltonen, Okland, & Andersen, 2017; Rowley & Slack,
2004). The L. Jones 10-Factor RepRisk Framework (see Table 6), developed through content
exploration of the literature, provided a model with contexts for reputational risk identification
and mitigation.
Table 6
L. Jones 10-Factor RepRisk Framework (2020)
Categorical factors
Factor 1: Reputation
and Profitability –
Alignment
Factor 2: Leadership
Factor 3: Strategy and
Integration
126
Factor 4:
Communications
Factor 5: Ethics and
Compliance
Factor 6: Technology
Factor 7: Social Media
Factor 8: Resiliency
Continued
Categorical factors
Factor 9: Protection
Factor 10: Process
Improvement
127
Recommendations for That Not Fully Proved
The purpose of this research was to identify the best practices for predicting and
mitigating risk through the amalgamated indicators related to reputation risk and potential
profitability (as shown in Chapter 2). The study contributed to the body of knowledge; however,
the researcher acknowledged the limitations of the analysis and the ability to prove some
recommendations. First, the researcher limited the scope to risk management programs. For this
study, risk management programs could have been situated in any sector or industry, as
reputational risk could have an impact on any business. Although the study included responses
from federal, state, and local risk professionals, the study primarily focused on businesses with
projected profit as a strategic goal. Due to these limitations, the researcher could not prove the
effectiveness of the model for not-for-profit organizations or nonprofit organizations maintained
by donations. The limitations did not provide the researcher with the opportunity to substantiate
the model’s benefits to organizations receiving an annual budget instead of income from
stakeholders, such as consumers and clients. The researcher recommended exploring the areas not
fully explored in this study.
Recommendations for Future Research
Before this study, there was minimal literature on the best practices for mitigating
reputational risk management to achieve potential profitability. The amalgamation of knowledge
provided for compatible frameworks and methods to link knowledge and practice in a functional
manner. There were four recommendations based on the study’s findings. First, there is a need for
additional research to understand compliance and the number of assessments required to manage
cyber-risk internally, as well as for third-party vendor networks. The data show that measuring
and managing reputational risk has been a difficult task because there are limited tools for
128
forecasting visibility. Emerging threats pose risks to organizations’ reputations, business partners,
and third-party vendors. Understanding reputational risk in coupled business communities,
including social media, is a process whereby key stakeholders work with and combine
unconnected data (Houghton, Keenan, Edmonds, & Blix, 2020).
Second, reputational risk and potential profitability studies on key stakeholders at
organizations of diverse sizes with different input and output systems would enable a study of the
frequency of risk assessment when there are multiple reputations at stake. Further research could
provide long-term risk management mitigation strategies. Third, there should be future research to
understand the required security for organizational vendors and the cycle of required change.
Study topics could include the level of security systems used by partnering vendors; areas of
security monitoring; frequency of captured activity within the systems; and level, method, and
output of risk data. Studies specific to organizational risk management should present data on the
partnering of businesses with outsources services through third-parties, thirdparties’ reputation
identities, and the extent to which third-parties share data across business platforms with other
third-parties. Reputation risk researchers could help leaders succeed in today’s cyber world and
add to the body of knowledge of reputation risk management, potential profitability, and practices
for predicting and mitigating risk.
Lastly, future researchers could investigate whether the best practices shown in this study
could provide benefits for businesses sustained by charitable contributions. Researchers can
investigate whether organizations with an annual budget instead of income from stakeholders
could benefit from this study. Balogun (2020) indicated that agency leaders who use approaches
that suit their mission and needs achieve budget success. Researchers could ask the question, “To
what extent does the funding entity need to be satisfied with an organization’s reputation to
129
continue to receive repetitive subsidy?” It could be a concern if organization leaders develop
budgets expecting to receive the same funding the following year or beyond. Regarding not-
forprofit and nonprofits, Fiennes (2016) indicated that some altruistic donors are a net drain:
Their costs to organizations outweigh the assistance they provide. Leaders must understand the
implications of an adverse reputational risk event to recognize the financial impact of such an
event and whether the stakeholders will continue to provide funding.
Other recommendations for future studies are to develop a process for reputation risk
management professionals to provide consistent feedback on how to improve a process, how to
better support risk management staff members who monitor reputation, and how to improve
knowledge transfer across teams. Scholars could conduct qualitative studies that include data
reviews (e.g., system evaluations, system output data reviews, risk management teams of all
levels, and transparent and anonymous feedback) and interviews. The recommendation is to
conduct annual reputation risk management research. Every annual research report should show
changes from the previous year’s data. Organizational leaders operating with multiple vendor
stakeholders who consider such relationships would be useful subjects of study because there
should be results about the enhancement and development of organizational risk management.
The data show a need to understand cybersecurity to maintain operations (Burton, 2019).
There were two recurring themes important for facilitating the success of risk
identification and prediction: the integration of risk management into all levels of strategic
planning and the support of risk management programs from senior leadership. The recurring
themes emerged during the phenomenological structured interviews. Also recommended would
be developing a process to help leaders think critically about how they influence reputation risk
and how they can lessen the ambiguity of tacit assets, leverage risk professionals, improve the
130
risk management experience, and leverage artificial intelligence to clarify unknown-unknown
risks. Future studies should use a qualitative approach and include literature reviews, data
reviews, and interviews. There is a need for more research to understand how to predict and
mitigate the most ambiguous risks.
Summary
As a senior practitioner in the areas of quality systems, governance, risk, and compliance
management in corporate America and other sectors, this researcher has been involved in risk
management strategy initiatives. The risk management strategy initiatives included the analysis,
design, development, implementation, and evaluation of risk management strategies and leading
risk management communities of practice. The results of this study and this researcher’s work
experience aligned in the suggestion that reputation risk management is an important component
for organizations’ status, particularly in today’s digital world. Burton (2019) and Skaife and
Werner (2020) suggested, and this examiner concurred, that there has been insufficient or lacking
risk practitioner skills and professional development in this technological and cyberdriven world,
something that requires change.
This action research resulted in several lessons and best practices that the researcher will
apply in future studies. There are rising rates of risks and negative reputational impacts, coupled
with a loss of revenue. Cyberattacks and data breaches persist. Inflammatory remarks by public
figures and insensitive marketing blunders have resulted in the expenditure of countless corporate
resources in response to a crisis. A lack of disclosure, mishandling of funds, an absence of due
diligence, coverups for faulty products, and notable events remain problems in the corporate
sector. Yet, a review of the literature showed that there is little information for organizational
leaders to embrace effective aggregate risk data models for a comprehensive view of intangible
131
threats. Organizations with multiple critical vendor support systems or leaders considering such
partnerships are recommended subjects of study because there should be research on growth,
achievement of objectives, and enhancement of organizational risk management. The data have
shown that the world continues to evolve and understanding cybersecurity in relation to critical
vendor support is a way to maintain operational continuity (Burton, 2019).
Having served in several risk management roles as a strategic business partner and as a
risk management officer, this researcher has been involved in the development of numerous risk
management strategy initiatives. These initiatives have included the analysis, design,
development, implementation, and evaluation of risk management strategies, leading risk
management communities of practice, and the inception and implementation of eight risk
management programs with national and global execution. The results of this qualitative
phenomenological structured interview research study and this researcher’s work experience
aligned in the suggestion that reputational risk management was an important component in the
advancement of organizations in today’s technological and cyber world. Burton (2019) and Parra
(2010) suggested, and this examiner concurred, that reputational risk management practitioner
skills and professional development are insufficient and lacking in this technological and
cyberdriven world.
The results of this qualitative phenomenological structured interview research study
showed that reputational risk management practitioners value knowledge capital, continuous
learning about technological advancements, the need to guide and support leaders at all levels,
and other best practices. In the reputational risk management environment, there have been
differences in understanding competitive performance, operational risk and regulations,
technology, and financial management. In consequence, there is a need for more studies to
132
stimulate conversations; attain valuable, suitable, and beneficial practices; and learn of the
enduring impacts of progressive technology and cybersecurity on reputational risk management.
Determining best practices is a means of helping organizational leaders gain insight into these gap
areas.
(Intentionally Left Blank)
133
Students also viewed