Risk Analysis for Inter-organizational Controls.
Joris Hulstijn, Jaap Gordijn · 2010
governance and control, risk, value modeling Existing early requirements engineering methods for dealing with governance and control issues do not explicitly support comparison of alternative solutions and have no clear semantics for the notion of a control problem. In this paper we present a risk analysis method for inter-organizational business models, which is based on value modeling. A risk is the likelihood of a negative event multiplied by its impact. In value modeling, the impact of a control problem is given by the missing value. The likelihood can be estimated based on assumptions about trust and about the underlying coordination model. This allows us to model the expected value of a transaction. The approach is illustrated by a comparison of the risks of different electronic commerce scenarios for delivery and payment. 1