Integrated assessment for new IT solutions
How can technology risk assessments remain thorough while adapting to different types of requests? This study examines how assessment depth, specialist involvement and documentation can be tailored to each request, supporting a more proportionate and clearer process.
Gajic, Dejan, 2026
Art der Arbeit Bachelor Thesis
Auftraggebende Financial Institution
Betreuende Dozierende Misyura, Ilya
Views: 1
A financial institution uses an integrated assessment process for new technology-related requests. The challenge lies in maintaining broad risk coverage while varying the depth of assessment, the level of specialist involvement and the extent of documentation according to the request, while keeping the process manageable for requesters. The process must also coordinate several specialist perspectives, ensuring that the reasoning behind the chosen assessment path is clear and traceable.
The study adopted a qualitative single-case study design. Internal process documents were reviewed, and guided walkthroughs were conducted to understand the documented process and how selected parts operated in practice. Four completed requests with contrasting characteristics were then examined using a consistent framework covering request characteristics, assessment depth, specialist involvement and documentation. A targeted literature review was used to interpret the findings and develop recommendations.
The analysis showed that the current process already differentiates requests, but initial classifications alone did not fully explain the assessment depth ultimately applied. Practical differentiation occurred mainly after the initial information collection, through routing and specialist judgement, while the reasoning behind the final path was documented across several process elements. The thesis therefore proposes an adaptive questionnaire that would adjust the questions shown according to a limited set of request and risk characteristics and suggest an initial assessment route. The aim is to focus the requester's efforts on the information most relevant to the assessment, provide earlier guidance on likely documentation requirements, and make the basis for the assessment path more transparent. Human reviewers would retain authority over risk ratings, controls, evidence and approvals. A simplified user guide, developed separately, reorganises existing guidance around requester tasks, decisions and next steps.
Studiengang: Business Information Technology (Bachelor)
Keywords Integrated Assessment; Technology Risk Assessment; IT Governance; Risk Management; Adaptive Questionnaire; User Guidance; Qualitative Single-Case Study
Vertraulichkeit: vertraulich