scieee AI-readable full text Open interactive document viewer

Risk Identification, Assessment and Management in The Greek Public Hospitals: The Contribution of The Board of Directors and Internal Audit

Koutoupis, Andreas G.,Koufopoulou, Paraskevi N.,Antonoglou, Dimitrios I.,Vozikis, Athanasios P.

Abstract

EconStor is a publication server for scholarly economic literature, provided as a non-commercial public service by the ZBW.

Full text

Koutoupis, Andreas G.; Koufopoulou, Paraskevi N.; Antonoglou, Dimitrios I.; Vozikis, Athanasios P. Article Risk Identification, Assessment and Management in The Greek Public Hospitals: The Contribution of The Board of Directors and Internal Audit Journal of Accounting and Management Information Systems (JAMIS) Provided in Cooperation with: The Bucharest University of Economic Studies Suggested Citation: Koutoupis, Andreas G.; Koufopoulou, Paraskevi N.; Antonoglou, Dimitrios I.; Vozikis, Athanasios P. (2022) : Risk Identification, Assessment and Management in The Greek Public Hospitals: The Contribution of The Board of Directors and Internal Audit, Journal of Accounting and Management Information Systems (JAMIS), ISSN 2559-6004, Bucharest University of Economic Studies, Bucharest, Vol. 21, Iss. 1, pp. 92-112, https://doi.org/10.24818/jamis.2022.01005 This Version is available at: https://hdl.handle.net/10419/310824 Standard-Nutzungsbedingungen: Die Dokumente auf EconStor dürfen zu eigenen wissenschaftlichen Zwecken und zum Privatgebrauch gespeichert und kopiert werden. Sie dürfen die Dokumente nicht für öffentliche oder kommerzielle Zwecke vervielfältigen, öffentlich ausstellen, öffentlich zugänglich machen, vertreiben oder anderweitig nutzen. Sofern die Verfasser die Dokumente unter Open-Content-Lizenzen (insbesondere CC-Lizenzen) zur Verfügung gestellt haben sollten, gelten abweichend von diesen Nutzungsbedingungen die in der dort genannten Lizenz gewährten Nutzungsrechte. Terms of use: Documents in EconStor may be saved and copied for your personal and scholarly purposes. You are not to copy documents for public or commercial purposes, to exhibit the documents publicly, to make them publicly available on the internet, or to distribute or otherwise use the documents in public. If the documents have been made available under an Open Content Licence (especially Creative Commons Licences), you may exercise further usage rights as specified in the indicated licence. http://creativecommons.org/licenses/by/4.0/ Accounting and Management Information Systems Vol. 21, No. 1, pp. 92-112, 2022 DOI: http://dx.doi.org/10.24818/jamis.2022.01005 Risk identification, assessment and management in the Greek public hospitals: The contribution of the board of directors and internal audit Andreas G. Koutoupis1,a, Paraskevi N. Koufopouloub, Dimitrios I. Antonoglouc and Athanasios P. Vozikisd aDepartment of Accounting and Finance, University of Thessaly, Greece bKAT General Hospital of Attica, Department of Economics, University of Piraeus, Greece cDepartment of Economics, Aristotle University of Thessaloniki, Greece dDepartment of Economics,University of Piraeus, Greece Abstract Research Question: Our study examines the development of a reliable internal audit plan in the Greek public hospitals, focusing on how to identify, assess and evaluate the relevant risks by the Boards of Directors. Data: We use an exceptional database drawing information from a large sample of Greek hospitals based on a structured questionnaire for the period from September 1, 2015 to March 31, 2017. Tools: As our primary source of data we conduct interviews with CAEs of Greek hospitals’, while secondary data sources come from corporate governance codes, COSO framework for ERM, Greek corporate governance laws, regulations, best practices and published articles. Findings: Taking into account the financial crisis of the last ten years in Greece as well as the pathogenesis of the healthcare system, we note the poorly organized risk management in Greek hospitals. The results show that the financial crisis had a direct impact on the way risk management of public hospitals operates. Furthermore, we observe denial of the application and implementation in the form of formal guidelines to the members of the hospitals’ Board of Directors. Contribution: Research findings can have a catalytic effect on hospital management and those who implement public policies. 1 Corresponding author: Associate Professor of Accounting and Finance, University of Thessaly, Postal code: 415 00, Larissa, Greece, email addresses: [email protected]. Risk identification, assessment and management in the Greek public hospitals: The contribution of the board of directors and internal audit Vol. 21, No. 1 93 Keywords: Enterprise Risk Management, Internal Audit, Hospitals JEL codes: A34, B12, B13, B62 1. Introduction In the light of the stifling financial framework, firms and public institutions such as public hospitals must ensure their effectiveness and sustainability (Etges et al., 2019). However, the public sector is threatened by many risks leading to loss in functionality. Adopting the best risk management practices can lead to the reduction of problems through more efficient use of human, financial and technological resources. The concept of risk can vary from company to company, both in the likelihood of something good happening and in the threat of something unfavorable or negative happening. Successful companies do not avoid or transfer the necessary risks for the rating, but formulate their strategy based on these (COSO ERM, 2004). Effective Hospital Risk Management (HRM) requires excellent knowledge of the environment in which they operate (e.g., competition, regulations, etc.). Practically speaking about the HRM, according to modern theories, it is the responsibility of the Board of Directors (or the Management Board). The main responsibility of hospital management is to identify significant activities (actions), operations (processes) and processes (procedures) related to the risks that are identified and classified according to the impact and probability, of occurrence and take appropriate measures to address them, overthrow them and exploit them (e.g. informal economy, corruption, staffing etc). According to the COSO Enterprise Risk Management Methodology (ERM), risks must be identified after identifying and linking the objectives of each organization. To provide integrated risk management through an integrated approach, the risks that characterize the whole body (entity level), address, function or service (division), hospital unit level should be taken into account. Risk classification, includes four main categories: strategic risks, operational risks, risk of reliability of financial and other reports and risks of compliance with laws and other regulations and policies - procedures. In this study, we address the main threats to the hospital, as well as some of the most important methodologies. In addition, different hospital risk categories and risk classifications can be used to identify best practices with different hospital adaptations. The results of the current research can improve the current state of the health care system in Greece, while we used a representative sample of hospitals in order to identify, evaluate, measure and manage risks. Particularly, our findings show the increased need for an integrated approach to business risk management in Greek hospitals. It seems that ERM practices are not widely used in Greek hospitals and many hospitals must take into account the consequences of these risks, something we also find in many firms, Recognizing, understanding the degree of Accounting and Management Information Systems 94 Vol. 21, No. 1 impact, communicating information, and avoiding or mitigating risk at manageable tolerable levels are key steps that every entity must follow in managing risk (Luko, 2013) Our study is the first that examines the ERM system in Greek hospitals and provides early results, specifically, aiming to face this research gap in the literature. Practitioners and policymakers could benefit from the study, as the authors highlight the key issues concerning enterprise risk management in Greek hospitals. The rest of the paper unfolds as follows. Section 2 outlines a literature review, so we can have a clear picture generally on enterprise risk management. Section 3 discusses the identification, evaluation and risk management in Greek hospitals. Section 4 reports the data and the methodology. In Section 5, it reports the empirical findings. Finally, section 6 reports the conclusion and the future research. 2. Literature review Enterprise risk management (ERM) is recognized as an expectation of good management and corporate governance with the aim of improving organizational performance. Several studies analyzed the ERM system in different geographical areas. However, to the best of our knowledge, this paper is the first study that examines empirically the enterprise risk management in Greek Hospitals. Given the wide extent of the relative literature, we select to present only a few, despite our extensive research that we undertake in order to ensure the originality of the study, we discuss generally the literature of enterprise risk management over the period from 2015 to 2021. We distinguish four main topics regarding enterprise risk management so far, that is, the determinants of ERM implementation (Sax & Andersen, 2019; Lechner & Gatzert, 2018; Berry-Stolzle & Xu, 2018; Farrell & Gallagher, 2015; Brustbauer, 2016; Bohnert et al., 2019; Lundqvist et al., 2015; Khan et al., 2016; Pérez-Cornejo et al., 2019), effects of ERM adoption (Florio & Leoni, 2017; Lechner & Gatzert, 2018; Silva et al., 2019; Farrell & Gallagher, 2015; Karanja, 2017; Annamalah et al., 2018; Zou et al., 2019; Wang et al., 2018; Grace et al., 2015; Berry‐Stölzle & Xu, 2018), ERM maturity (Farrell & Gallagher, 2015; Oliva, 2016; Callahan & Soileau, 2017) and ERM strategies (Sax & Andersen, 2019; Cohen et al., 2017). In particular, several studies highlight four determinants that play a significant role in the ERM implementation which are financial leverage, firm size, business diversification and corporate governance characteristics. The ERM implementations require financial resources and it is easier for firms with lower levels of financial leverage (Berry-Stolzle & Xu, 2018; Sax & Andersen, 2019; Lechner & Gatzert, 2018). Consequently, firms with a holistic ERM implementation can avoid financial distress, improve profitability and achieve lower financial leverage (Lechner & Gatzert, 2018). In terms of firm size and business diversification, it has positive Risk identification, assessment and management in the Greek public hospitals: The contribution of the board of directors and internal audit Vol. 21, No. 1 95 impact on ERM implementation. Specifically, larger firms are more likely to adopt a holistic approach to the ERM system (Farrell & Gallagher, 2015; Lechner & Gatzert, 2018; Berry-Stolzle & Xu, 2018; Brustbauer, 2016; Bohnert et al., 2019). In addition, Lundqvist et al. (2015) examined that corporate governance characteristics are also determinants of ERM implementation. Specifically, corporate governance characteristics such as the independence of board, appears to influence ERM adoption (Khan et al., 2016). Nevertheless, Board of directors need to select independent members with excellent education and experience for audit committee positions to improve ERM system quality (Pérez-Cornejo et al., 2019). Regarding the effects of ERM, literature recognizes three effects of ERM adoption that is firm performance, cost of capital and corporate reputation. Specifically, firms with advanced levels of ERM implementation present higher performance (Florio & Leoni, 2017; Lechner & Gatzert, 2018; Silva et al., 2019; Farrell & Gallagher, 2015; Karanja, 2017; Annamalah et al., 2018; Zou et al., 2019). In addition, ERM quality system can add value and profitability to firms (Florio & Leoni, 2017; Lechner & Gatzert, 2018; Silva et al., 2019). However, weaker ERM systems are related with poor control mechanisms which seems to drive to less profitability and attract additional investor’s scrutiny (Florio & Leoni. 2017; Wang et al., 2018). Further, ERM adoption can create value reducing firm’s cost of capital (Berry‐Stölzle & Xu, 2018; Lechner & Gatzert, 2018). Moreover, Grace et al. (2015) observe that the increased value of ERM adoption can be achieved with the contribution of economic capital models and with dedicated risk managers subordinated to the board of directors or the chief executive officer. Furthermore, according to Perez-Cornejo et al. (2019) ERM affects positively corporate reputation. The authors confirm that audit committee independence plays a significant role in the enhancement of corporate reputation via ERM adoption. In particular, the independent directors have to have the appropriate education to supervise the ERM system and to guarantee the corporate reputation. When it comes to ERM maturity firms that have reached mature levels of ERM have higher firm value (Farrell & Gallagher, 2015). Moreover, companies in the intermediate level of maturity have an enterprise risk management with a high degree of planning, use of methods and techniques (Oliva, 2016). In particular, the maximization of ERM maturity can be achieved when the board of directors, senior management, and senior risk officers clarify the goals and the importance of risk management to all business units (Farrell & Gallagher, 2015). Ultimately, the role of the executive management and the board of directors is crucial in the ERM maturity because they have the control over the ERM process (Callahan & Soileau, 2017). Regarding ERM strategies, the combination of ERM implementation and strategic planning can generate positive effects like profitability and lower financial leverage Accounting and Management Information Systems 96 Vol. 21, No. 1 (Sax & Andersen, 2019). Auditors can involve to the ERM strategic, operational, and compliance process besides the financial reporting processes (Cohen et al., 2017). The main problem is that auditors cannot perceive the strategic risks on financial reporting quality. For this reason, the understanding of strategy risks on behalf of auditors could benefit towards more effective accounting estimates as well as better estimation of the viability of their clients (Cohen et al., 2017). Regarding the previous literature, empirical studies that examine the enterprise risk management in Greek hospitals are not yet to be conducted. This is due to the high level of complexity in Greek hospitals. However, there are common characteristics of ERM system with the previous literature. Specifically, the internal auditor plays a significant role in Greek Hospitals. The auditor should be in the position to understand the business model of the hospital following the Internal Audit Standards. Moreover, the internal auditor of the hospital has to develop the Audit plan to achieve the relevant ERM objectives that are divined in the following five areas: strategic, operational, information, reporting objectives and compliance, then the internal auditor identifies the risks associated with the functions and activities of the individual control areas. However, the risk factors that are common to all health organizations have not yet been verified (Etges, 2019). Taking into consideration the previous studies, the crucial point of the ERM is the identification of risk categories of the hospital and their activities, which are closely related to their objectives. There are several categories of risks that arise depending on the nature of the activity of hospital procedures, such as: strategic risks, which may have negative effects on the financial management of the hospital and credit risk related to the financial loss of hospitals likely to suffer from possible default by counterparties. Furthermore, operational risks - production risks, refer to the financial loss that might occur due to inadequate internal procedures, systems, human errors or external factors, including reputation risk. Focusing on the legal framework, there are also legal / compliance risks that include certain financial products providing insufficient protection and security in legal disputes. Another risk category is the risks of the IT system - the technological risks that reflect the risk of hospital information systems (HIS). According to Meidell and Kaarbøe (2017), the construction of risk technologies over time triggers a change in the ERM function's influence on decision-making; thus the technological risks of hospitals need new skills. Finally, in Greek Hospitals, a long-term and short-term audit plan is prepared, according to the identification and evaluation of the relevant risks. Identification, evaluation and risk management in Greek hospitals The most significant part of corporate governance practices in public hospitals is the risk assessment. It is a fundamental part relating to the prioritization of audit needs and development of the Audit Plan assisting the achievement of the relevant objectives. The process above is normally coordinated by the Internal Auditor of the Risk identification, assessment and management in the Greek public hospitals: The contribution of the board of directors and internal audit Vol. 21, No. 1 97 hospital (based on impartiality and objectivity principles) and begins by recognizing of the audit area, which includes all components, processes, activities and functions of the public hospital. The auditor should be in the position to understand the business model of the hospital. Following Internal Audit Standards, the hospital Chief Audit Executives (CAEs) must follow a strict and predetermined process. Initially, there is recognition of the audit universe, where the relevant components are collected (by Divisions, Sub - Divisions and Departments). CAEs should have access to data, files and data of any hospital staff units, as well as management information including the minutes and decisions of the Board of Directors and the other subcommittees of the BoD. A key element of the hospital risk identification, management and treatment process is the recognition of hospital objectives. The main categories of the hospitals’ objectives are divided into five main areas: strategic, operational, information, reporting objectives and compliance objectives. Once the goals are set, they are linked to the control room monitoring areas at all levels. The IAU then identifies the risks associated with the functions and activities of the individual control areas / units that make up the body control area and thus the achievement of the hospital objectives. Taking into consideration the previous, we must imply that a crucial point of the ERM is the identification of (key) risk categories of the hospital and their activities, which are closely related to their objectives. There are several categories of risks that arise depending on the nature of the activity of hospital divisions / departments / procedures, from external sources as well as from internal sources, such as: strategic risks, which may have negative effects on the financial management of the hospital. Credit risk related to financial loss of hospitals likely to suffer from possible default by counterparties. Furthermore, operational risks - production risks, refer to the financial loss that might occur due to inadequate internal procedures, systems, human errors or external factors, including reputation risk. Focusing on the legal framework, there are also legal/compliance risks that include certain financial products, provide insufficient protection and security in legal disputes. Finally, another risk category is the risks of the IT system - the technological risks that reflect the risk of hospital information systems (HIS). Following the recognition of the inherent risks and their correlation with the relevant controls and their respective objectives, an analysis and evaluation of the possible impact of each risk on the control area to which it is associated and the likelihood of its occurrence shall follow. In order to achieve uniformity in risk assessment and to provide a common rating methodology, each dimension is evaluated and rated based on five point Likert scale (e.g. from 1 to 5, where 1=Very Low, 2=Low, 3=Medium, 4=High, 5=Very High). Accounting and Management Information Systems 98 Vol. 21, No. 1 IAUs assess the risk score for each risk level of hospital department and/or function or activity level and are highly dependent on the number of risks identified by their level of development (secondary or other level). Given, the Identification Methodology and Risk Assessment, the risks are divided into categories and assessed in terms of potential impact, probability of occurrence and specific risk factors based on qualitative and quantitative criteria that may be related to specific hospital activities. Risk factors associated with a unit are rated individually. The final ranking of audit areas, is obtained by adding the total score of the risk assessment factors to the rating of the key risk categories, and based on the calculated average. The overall score is the estimation of the total risk unit score. Risk factors and the risk assessment categories can be weighted based on the importance and priorities of IAUs by the hospital’s Internal Auditor. These two parameters have the same weight in the formula and the results will be exported according to five grade scale of the previous subsection. The audit plan represents the agreement of Internal Audit at hospital level for the audit of certain areas and activities. Internal auditor is responsible for the establishment of a hospital monitoring program. Finally, a long-term and short-term audit plan is prepared, according to the identification and evaluation of the relevant risks. From the above we form our hypotheses: H1: Risk identification and assessment (RIA) positively affects risk management in Greek Hospitals. H2: Internal Audit (IA) positively affects risk management in Greek Hospitals. H3: Board of Directors’ Strategy-involvement (BDS) positively affects risk management in Greek Hospitals. 3. Hypotheses development 3.1 Research setting – sample The survey was conducted in a sample of fourteen hospitals from the total seven Greek Health Regions (two per Health Region), for the period September 1, 2015 until March 31, 2017. Our initial sample contained 20 public hospitals, but due to insufficient data at the time of data collection through the questionnaires, our final sample consisted of 14 hospitals. Additionally, in order for our sample to have hospitals from all over Greece, we select 2 from each health geographical region of the country, for the 7 regions in total, as shown in table 1 below. Risk identification, assessment and management in the Greek public hospitals: The contribution of the board of directors and internal audit Vol. 21, No. 1 99 Table 1 General Hospitals in Greece by Geographical Region Health Geographical Region of Hospital 1 Attica Evaggelismos Ippokratio 2 Piraeus and Aegean Attikon Thriassio 3 Macedonia Papageorgiou General Hospital of Katerini 4 Macedonia and Thrace General Hospital of Chalkidiki General Hospital of Kavala 5 Thessaly and Central Greece General Hospital of Larissa General Hospital of Volos 6 Peloponnese, Ionian Islands, Epirus and Western Greece General Hospital of Kalamata General Hospital of Korinthos 7 Crete General Hospital of Heraklion General Hospital of Chania 3.2 Sources of data – model Our research conducts qualitative and quantitative research to address the research topic, using primary and secondary data. As our primary source of data we conduct interviews with CAEs of Greek hospitals’, while secondary data sources come from corporate governance codes, COSO framework for ERM, Greek corporate governance laws, regulations, best practices and published articles. We used a structured questionnaire for the further analysis of the initial findings. The questionnaire is divided into two sections, in first there are fourteen questions on risk identification and assessment and in the second there are two sets of total twelve questions, six related to the Audit Universe and the other six related to the identification and assessment of risks. Usable response was received from 84 staff members from the public hospitals, which is 75% of our initial target. The evaluations of the answers are related to the Likert scale of five points, depending on how strongly the respondents agree or disagree with each question. The questionnaire was tested by a team of 2 academics and 2 professionals for validity and reliability checks. Then, following Hertzog (2008) as a first stage of pilot test, the questionnaire was answered by 31 responders. Accounting and Management Information Systems 106 Vol. 21, No. 1 Only 18% of the respondents argued that there is no such communication with the Board (the percentage is high even for Greece, as well as risk management need be made daily based on the strategies of each hospital so it makes sense to have in all cases a communication). Also, in 10% of our sample does not know if the risks faced by the hospital management were notified to the board. The breakdown of positive responses include a 25% where hospitals declare that risks are reported both in writing and orally, 9% only in writing, only 29% verbal practice poses particular risks regarding the necessary management monitoring, while the remaining 9% state that risks are reported but they did not know the communication method (verbal possibly). Oral communication as it emerged from our interviews focused on the president (or the CEO), the other does not refer to the entire Board or to its subcommittee or the CEO, General Manager, CFO etc. 4.3.6. Service Management and Risk Monitoring in Greek hospitals. Although there is no requirement for the establishment of the Service Management - Risk Monitoring only19% of hospitals state that such services exist in a different role as evidenced by our interviews with each of them (Table 10). Table 10: Service Management and Risk Monitoring establishment in Greek hospitals Answer % Yes 19% No 73% Other 8% Unfortunately, 73% of hospitals have not yet established risk detecting and Monitoring Service. That is really disappointed especially in view of the economic crisis, a reliable and functional way of safe operation of public hospitals, is strategic planning through preventive mechanisms e.g. the creation of specialized risk detection, management and settlement services. Nevertheless, the bureaucracy of the public sector in Greece will postpone the deployment of this management practice. Until then, each hospital will spend a lot of money to deal with the problems that will arise. 4.3.7 Hospital strategy information process, in terms of Detection and Risk Management to shareholders and other Stakeholders. Finally, we investigate whether the content includes information on hospital strategy and the identification and management of risks to shareholders and other stakeholders (Soltanizadeh et al., 2016) (Table 11). Risk identification, assessment and management in the Greek public hospitals: The contribution of the board of directors and internal audit Vol. 21, No. 1 107 Table 11: Hospital management information process, to shareholders and other stakeholders. Answer % Yes 53% No 47% As it turns out, just over half of hospitals, only 53%, inform their shareholders about the risks that characterize them, while the remaining 47% do not provide such information. Finally, it should be noted that there is a wide variety in the quality of information from hospital to hospital. Table 12 below presents the summary of the findings according the present study. Table 12: Summary of the findings Paragraph Findings § 4.3.1. Risk Management policies Written Meetings Oral Other 10% 51% 2% 37% § 4.3.2. Adopted Policies and Procedures Risk Management detection Yes No Other 39% 53% 8% There of: Internal resources 29% External consultants 10% § 4.3.3. Determining Risk level (via specific procedures) Yes No Other 31% 57% 12% § 4.3.4. Conducting Risk assesement Yes No Other 42% 47% 11% There of: Internal resources 32% External consultants 10% § 4.3.5. Management's communication with the BoD's Yes No Other 72% 18% 10% Accounting and Management Information Systems 108 Vol. 21, No. 1 Paragraph Findings There of: Written & Verbal 25% Verbal 9% Oral 29% Other 9% § 4.3.6. Service Management - Risk Monitoring Yes No Other 19% 73% 8% § 4.3.7. Management information process, to shareholders Yes No 53% 47% 5. Discussion and conclusion This paper investigates the influence of internal audit and BoD to risk management in Greek hospitals. To identify and evaluate this issue, we conducted interviews by selecting a sample of 14 hospitals throughout Greece, two hospitals from each geographical area in Greece. The findings show the increased need for an integrated approach to business risk management in Greek hospitals. It seems that ERM practices are not widely used in Greek hospitals and many hospitals must take into account the consequences of these risks, something we also find in many firms. Recognizing, understanding the degree of impact, communicating information, and avoiding or mitigating risk at manageable tolerable levels are key steps that every entity must follow in managing risk (Luko, 2013). 5.1 Findings - Suggestions for improvement Τhe lack of quality in the services provided in conjunction with the absence of modern management tools makes ineffective operation of Greek public hospitals, especially against all forms of risks. Corporate governance practices, in particular risk assessment from both management and internal audit, are an innovative tool that will enhance and improve the content of the internal audit process in public hospitals. Therefore close cooperation between hospital CEOs and a wider network of services or external consultants is required, ensuring the independence of internal auditors and their impartiality. The main role of the management of each hospital is to issue written and timely reports to the Board of Directors before the meetings, so that the latter has the right information for decision-making. However, the executives must be responsible for the proposals submitted, to implement the decisions of the Board of Directors, as Risk identification, assessment and management in the Greek public hospitals: The contribution of the board of directors and internal audit Vol. 21, No. 1 109 well as to report any activities that involve risk, beyond the acceptable limits. In addition, the hospital's control environment is enhanced by the proper functioning of the Internal Control System which is based on specific documented procedures (including those relating to Risk Management) and which will be periodically reviewed by an independent Internal Audit Service. In the context of the development adequate policy management and risk monitoring, it is proposed to establish an independent Risk Monitoring Department of the hospital. This service is supplementary to the work of the Management and should be reported either directly to the independent subcommittee of the Board or to the CEO, to ensure the maximum degree of independence. The development of risk registers should be encouraged by hospitals, to record and monitor relevant information. Hospital feedback procedures for risk data should be performed at regular intervals at least annually or earlier if circumstances require and should be linked to specific and documented risk measurement methods. In order to establish an appropriate framework for assessing and communicating results, there should be written policies and procedures for managing hospital risks, with clear limits on risk acceptance. Furthermore, it is necessary to establish appropriate mechanisms for effective communication within hospitals with a view to optimal risk management. An important role in supporting the adoption of risk management policies in hospitals could be operated and led by Audit Committees, which with an independent objective role, will be called upon to study and review risk management procedures through relevant research. Hospitals should be encouraged to create the appropriate framework for risk management. In addition, through appropriate training programs, their staff will be able to identify and manage risks. Finally, the conditions for proper communication between the involved executives and all hospital staff in general, with a clear description of the role of their work, evaluation and risk management must be created, according to their level and their responsibility. Business risk management strategy methodologies should be integrated rather than piecemeal. Specifically, it is proposed to adopt an integrated methodology for the business risk management strategy in compliance with the COSO Committee ERM Model (2004), which will include the development processes, reporting and monitoring the implementation of operational objectives, identification, risk assessment in relation to operational objectives, enterprise risk management strategy development processes, operational risk monitoring procedures, as well as procedures to improve their response strategies. Finally, after the completion of the proposals for the virtual assessment and evaluation of hospital risk, the determination of the desired hospital risk profile should be included, based on an inherent or occurring and/or residual risk or Accounting and Management Information Systems 110 Vol. 21, No. 1 combination of both parameters. Moreover, the determination of the maximum acceptable level of risk and tolerance of recognized or unrecognized risks in the hospital as well as the detection of any changes in systems and / or procedures is considered necessary. In conclusion, the importance of collecting and recording information on charges and risks and their inclusion in the relevant databases, examining the completeness of the above data, as well as the assessment and classification of risk in relation to tolerance levels should be emphasized, and should always be compared with the specified safety measures - checkpoints. In addition, the periodic reassessment of approved business risks as well as the review of any new ones is an important routine of the relevant process. Finally, it is more necessary than ever to adopt a new way of managing health institutions, in the light of new public management techniques, in order to ensure their sustainability and contribution to economic development even after the economic crisis. References Allegrini, M., & D’onza, G. (2003) “Internal auditing and risk assessment in large Italian companies: an empirical survey”, International Journal of Auditing, vol. 7(3): 191-208. Annamalah, S., Raman, M., Marthandan, G., & Logeswaran, A. K. (2018) “Implementation of enterprise risk management (ERM) framework in enhancing business performances in oil and gas sector”, Economies, vol. 6(1): 4. Berry‐Stölzle, T. R., & Xu, J. (2018) “Enterprise risk management and the cost of capital”, Journal of Risk and Insurance, vol. 85(1): 159-201. Bohnert, A., Gatzert, N., Hoyt, R. E., & Lechner, P. (2019) “The drivers and value of enterprise risk management: evidence from ERM ratings”, The European Journal of Finance, vol. 25(3): 234-255. Brustbauer, J. (2016) “Enterprise risk management in SMEs: Towards a structural model”, International Small Business Journal, vol. 34(1): 70-85. Callahan, C., & Soileau, J. (2017) “Does enterprise risk management enhance operating performance?”, Advances in accounting, vol. 37: 122-139. Campbell, S. (2005) “Determining overall risk”, Journal of risk research, vol. 8(7-8): 569-581. Cohen, J., Krishnamoorthy, G., & Wright, A. (2017) “Enterprise risk management and the financial reporting process: The experiences of audit committee members, CFO s, and external auditors”, Contemporary Accounting Research, vol. 34(2): 1178-1209. COSO Enterprise Risk Management — Integrated Framework, (2004) Retrieved 3 April 2021, from https://www.coso.org/Pages/erm-integratedframe work.aspx. Risk identification, assessment and management in the Greek public hospitals: The contribution of the board of directors and internal audit Vol. 21, No. 1 111 Dunbar, C. G., Li, Z. F., & Shi, Y. (2020) “Corporate social responsibility and CEO risk-taking incentives”, Journal of Corporate Finance, vol. 64: (101714). Etges, A. P. B. D. S., de Souza, J. S., Kliemann Neto, F. J., & Felix, E. A. (2019) “A proposed enterprise risk management model for health organizations”, Journal of Risk Research, vol. 22(4): 513-531. Farrell, M., & Gallagher, R. (2015) “The valuation implications of enterprise risk management maturity”, Journal of Risk and Insurance, vol. 82(3): 625-657. Florio, C., & Leoni, G. (2017) “Enterprise risk management and firm performance: The Italian case”, The British Accounting Review, vol. 49(1): 56-74. Grace, M. F., Leverty, J. T., Phillips, R. D., & Shimpi, P. (2015) “The value of investing in enterprise risk management”, Journal of Risk and Insurance, vol. 82(2): 289-316. Hertzog, M.A. (2008) “Considerations in determining sample size for pilot studies”, Research in Nursing and Health, vol. 31(2): 180-191. Karanja, E. (2017) “Does the hiring of chief risk officers align with the COSO/ISO enterprise risk management frameworks?”, International Journal of Accounting & Information Management. Khan, M. J., Hussain, D., & Mehmood, W. (2016) “Why do firms adopt enterprise risk management (ERM)? Empirical evidence from France”, Management Decision. Law 4025/2011, (November 2011) Reconstruction of the national system of social solidarity, Greece. Lechner, P., & Gatzert, N. (2018) “Determinants and value of enterprise risk management: empirical evidence from Germany”, The European Journal of Finance, vol. 24(10): 867-887. Luko, S. N. (2013) “Risk management principles and guidelines”, Quality Engineering, vol. 25(4): 451-454. Lundqvist, S. A. (2015) “Why firms implement risk governance–Stepping beyond traditional risk management to enterprise risk management”, Journal of Accounting and Public Policy, vol. 34(5): 441-466. Meidell, A., & Kaarbøe, K. (2017) “How the enterprise risk management function influences decision-making in the organization–A field study of a large, global oil and gas company”, The British Accounting Review, vol. 49(1): 39-55. Oliva, F. L. (2016) “A maturity model for enterprise risk management”, International Journal of Production Economics, vol. 173: 66-79. Pérez-Cornejo, C., de Quevedo-Puente, E., & Delgado-García, J. B. (2019) “How to manage corporate reputation? The effect of enterprise risk management systems and audit committees on corporate reputation”, European Management Journal, vol. 37(4): 505-515. Sax, J., & Andersen, T. J. (2019) “Making risk management strategic: Integrating enterprise risk management with strategic planning”, European Management Review, vol. 16(3): 719-740. Accounting and Management Information Systems 112 Vol. 21, No. 1 Silva, J. R., Silva, A. F. D., & Chan, B. L. (2019) “Enterprise risk management and firm value: evidence from Brazil”, Emerging Markets Finance and Trade, vol. 55(3): 687-703. Soltanizadeh, S., Rasid, S. Z. A., Golshan, N. M., & Ismail, W. K. W. (2016) “Business strategy, enterprise risk management and organizational performance”, Management Research Review. Wang, T. S., Lin, Y. M., Werner, E. M., & Chang, H. (2018) “The relationship between external financing activities and earnings management: Evidence from enterprise risk management”, International Review of Economics & Finance, vol. 58: 312-329. Zou, X., Isa, C. R., & Rahman, M. (2019) “Valuation of enterprise risk management in the manufacturing industry”, Total Quality Management & Business Excellence, vol. 30(11-12): 1389-1410.