Our study draws on self-organization theory to develop a framework for explaining financial executives' shadow information technology (IT) behavior (i.e., executive adoption of a technology without the IT department's knowledge). Understanding executive shadow IT usage is important, because it can significantly increase business risk related to loss of control and information security. Although directly involving shadow IT, our research also attempts to clarify mixed results in the broader usage policy literature. We investigate shadow IT usage via an experiment and separate interviews with financial executives from Germany and Italy, representing autonomous and autogenic environments, respectively. Results indicate higher shadow IT propensity in autonomous contexts and stronger adherence to stringent IT usage policies in autogenic contexts. Interview data further suggest that internal control strength and executive alignment with the IT department are key factors shaping shadow IT behavior. Unique findings add an international component to shadow IT and usage policy literatures.
SYNOPSIS: Firms invest heavily in information technology (IT) to gain a competitive advantage. Yet, the association between a firm's business strategy and its propensity for new IT adoption is underexplored in the existing literature. Our study bridges that gap by examining the interplay between business strategy (prospector versus defender) and blockchain adoption as the representative corporate IT investment, offering practical insights for managers. Our findings reveal that firms characterized by decentralization, a penchant for risk-taking, and a more flexible approach to technological efficiency (i.e., prospector firms) are inclined to adopt blockchain. Additional channel analyses refine this result as well identify conditions where a subgroup of defender firms adopt blockchain. Study insights underscore the significance of alignment between business strategy and IT characteristics, while recognizing that IT solutions like blockchain are not one-size-fits-all.
The accounting profession continues to face a talent shortage. In addition, the skills and demands of accountants continue to evolve as technology changes. At the same time, many autism spectrum disorder (ASD) persons remain unemployed or underemployed. Companies, including the Big 4, have begun hiring programs looking at a diverse set of individuals, including ASD persons. General anecdotes suggest ASD persons are thriving in terms of innovation, efficiency, and productivity. While neurotypical (NT) persons have been shown in multiple studies to rely on simple heuristics, which reduce judgment quality, we argue that there are neuropsychological differences in visual perception and attention that play a vital role in why ASD persons may be less susceptible to heuristics and biases; hence, increasing judgment quality. This paper presents an interdisciplinary research framework that adapts the human information processor model of cognition to bring together the judgment and decision-making, autism, and neuropsychological literatures to focus on areas where ASD persons may have judgment-related advantages over NT persons. We discuss the framework and present example research questions for two areas where ASD accountants are performing tasks: cybersecurity and software development. Our framework presents a guide for future empirical research where accounting academics can lead an interdisciplinary effort to support company inclusion programs of ASD persons and, more broadly, of neurodivergent persons.
SYNOPSIS Utilizing a common enterprise resource planning (ERP) vendor could improve supplier and customer performance by increasing supply chain information technology (IT) alignment, agility, and efficiency. However, supply chains could be hesitant to utilize a common ERP vendor for fear of intellectual capital loss, increased costs, and IT incapability with existing IT architecture. Relational view theory argues that information sharing and process integration advantages are achieved when supply chain partners share assets, knowledge, and capabilities through relation-specific investments, complementary resources, and knowledge sharing processes. We find evidence that common ERP vendor (CERPV) use is associated with greater supplier and customer efficiency, performance, and partnership strength. Our study directly examines the impact of CERPV use within a supply chain, adding to the limited accounting information systems’ evidence on the role of interorganizational ERP system investments on efficiency.
PurposeThe purpose of this study is to construct and test a new measure of auditor orientation using two audit quality-related tasks.Design/methodology/approachThe sample consists of 66 Dutch and US graduate auditing students. Participants complete two tasks: one involving a lease classification and another, supplemental experiment involving a contingent liability judgment. The purpose is to construct a new measure for rules-based/ principles-based orientation. Rigorous, psychometric testing confirms that parts of tolerance for ambiguity (TOA) and need for cognition (NFC), together, form a new construct the authors identify as auditor orientation. The authors next conduct a main and supplemental experiment with novice auditor participants from both the USA and the Netherlands.FindingsThe authors begin with rigorous, psychometric testing using participants from the USA and the Netherlands. The resulting 10-item scale combines parts of TOA and NFC to reflect auditor orientation. The common themes across scale items are high (low) adaptability to complexity and a substance-over-form (form-over-substance) preference for principles-oriented (PO) (rules-oriented [RO]) auditors. Conducting two experiments, results from two distinct tasks confirm our research question; novice auditors classified as RO (PO) are more (less) likely to recommend a more aggressive/client-favorable disclosure judgment.Originality/valueAuditor orientation (i.e. rules or principles) has a significant impact on the application of rules-based or principles-based standards. How the standards are applied, therefore, influences auditor decision-making and thus audit quality. However, there is a paucity of auditor orientation research to date, including a validated measure. The study contributes a new measure for future research in the related accounting standards and audit quality literatures, while also identifying a potentially important construct in auditor training.
ABSTRACT Using Twitter to disseminate information has two advantages: flexibility in presentation formats and the ability to redisclose a prior period’s information—referred to as “rehashing.” Our research examines the effect of these issues on market investors’ trading. Our experimental market results suggest that nonprofessional investors presented with whole-number quarterly earnings exhibit insensitivity to the large numbers (i.e., psychophysical numbing). Further, we find evidence suggesting that investors in the whole-number condition net the rehashed quarterly earnings information with current quarterly earnings information to counteract the psychophysical numbing effects, whereas those in the earnings per share (small-number) condition display a representativeness bias toward positive news when processing the rehashed information. Our results indicate that a firm can influence investor decisions when managers strategically disseminate larger whole numbers and rehash positive earnings information. Thus, our findings contribute novel information to the extant social media literature.
ABSTRACT Although the role that information technology (IT) executives’ expertise has in firm outcomes is well documented, little empirical work investigates the effect of the IT ability of non-IT executives on firm outcomes. We apply upper echelons theory and create a unique measure of chief executive officer (CEO) IT ability to empirically investigate its impact on bank loan pricing and nonpricing terms. Examining a sample of firms between 2002 and 2017, we find that CEO IT ability is associated with lower cost of debt, less collateral, fewer loan covenants, and fewer credit rating downgrades. Further, we show that our results are not due to high tech firms and are incremental to firm-level IT capability. Our results extend upper echelons theory and suggest that IT ability is an important CEO characteristic that can be influential in improving lending outcomes.
The 2008 financial crisis highlighted the significant, vertical pay disparity between chief executive officers (CEOs) and all other employees. Following equity theory, prior research finds negative associations between vertical pay disparity and job satisfaction and performance (i.e., more errors). We build on this research to investigate if vertical pay disparity between the CEO and employees/other executives is a previously unidentified determinant of data security breaches (DSBs). Results suggest that firms with large, vertical pay disparities are more likely to be breached, are associated with more DSBs, and are more likely to be associated with internal DSBs. We also find some evidence of remediation through narrowing the pay disparity between CEOs and employees/other executives after the DSB. Our findings contribute to the growing accounting information systems (AIS) cybersecurity literature, extend equity theory to a new context, and should be of interest to AIS governance researchers and stakeholders.
ChatGPT, a language-learning model chatbot, has garnered considerable attention for its ability to respond to users' questions. Using data from 14 countries and 186 institutions, we compare ChatGPT and student performance for 28,085 questions from accounting assessments and textbook test banks. As of January 2023, ChatGPT provides correct answers for 56.5 percent of questions and partially correct answers for an additional 9.4 percent of questions. When considering point values for questions, students significantly outperform ChatGPT with a 76.7 percent average on assessments compared to 47.5 percent for ChatGPT if no partial credit is awarded and 56.5 percent if partial credit is awarded. Still, ChatGPT performs better than the student average for 15.8 percent of assessments when we include partial credit. We provide evidence of how ChatGPT performs on different question types, accounting topics, class levels, open/closed assessments, and test bank questions. We also discuss implications for accounting education and research.
Nonfinancial information is becoming more readily available to investors, and thus, relative to annual financial reports, is having an increasing influence on investors' stock pricing decisions. Using Hogarth and Einhorn's (1992) belief-adjustment model, we examine how task familiarity (high, medium, and low) influences nonprofessional investor stock price decisions when these investors are presented with a stream of both positive and negative nonfinancial news. We find that task familiarity negatively correlates with reaction size for both positive and negative information, which creates arbitrage opportunities for those with more task familiarity. However, we find that assurance mitigates this effect, leveling the playing field for less task-familiar investors in most cases. These findings are important as the volume and variety of information types increase, and as more nonfinancial information enters the marketplace in discrete sound bites (e.g., social media, press releases, daily reports). Findings suggest that assurance is one way to lessen the biases exhibited by investors with less task familiarity. These results enhance our understanding of nonprofessional investor behavior through the lens of belief revision.
Although blockchain has drawn significant attention since its introduction in 2008, determinants of its adoption remain largely unknown.Relying on the Resource-Based View (hereafter, RBV) of the firm as a theoretical guide, we investigate whether a firm's business strategy affects its decision on blockchain adoption.We split firms into prospectors (risk takers) and defenders (interested in cost stability) consistent with the business strategy framework to determine if the former group is more likely to adopt blockchain.Using a sample of 208 firms from 2015 to 2019, we find that prospectors are more likely to adopt blockchain than defenders.Results suggest blockchain brings more net benefits to prospectors than to defenders.The results support RBV and business strategy theories and are robust to the consistency test, factor analysis, and placebo test.The findings imply that the alignment between business strategy and technology characteristics motivates firms to adopt specific technology.
Data security breaches have been consistentlyidentified in literature as significant, negative events. While most of the related research focuses on externally initiated breaches, far fewer studies provide clarity related to internally initiated breaches. The risk of internal breaches may be dramatically increased by shadow information technology (IT). Our study examines German and Italian financial executives' decisions to engage in shadow IT in combination with two potential mitigation techniques (severity of sanctions in violation of IT policy and outcome effect related to breach risk). While Italian executives act as predicted, German executives engage in a different decision-making process whereby a self-service business culture brought on by perceived increased IT capabilities supersedes the level of cybersecurity awareness and a strong IT usage policy.Results also suggest an outcome effect favoring increased likelihood of breaches may lessen the likelihood of shadow IT usage.Our study adds an international component to existing data security breach and shadow IT research, while also contributing to the IT usage policy, neutralization theory, dynamic capabilities, outcome effect, and selfservice literatures.1 Germany and Italy represent two symbolic archetypes of Northern and Southern European cultures, respectively (Del Junco and Brás-dos-Santos 2009).We examine financial executives,
Data security breaches (DSBs) are increasing investor and regulator pressure on firms to improve their IT governance (ITG) in an effort to mitigate the related risk. We argue that DSB risk cannot be mitigated by one executive alone, but, rather, is a shared leadership responsibility of the top management team (TMT) (i.e., Chief Executive Officer [CEO], Chief Financial Officer [CFO], and Chief Information Officer [CIO]). Our results suggest that IT-savvy CEOs see technologies related to mitigating DSBs as a top-three most important type of digital methodology for their firm. Similarly, the results related to CFOs with IT expertise single out the critical investment in controls designed to prevent DSBs. Our strong findings for CIOs on the TMT add to the related guidance from COBIT 5 for information security and consistently suggest that they are the key executive for securing IT systems. Finally, our granular explanation of each executive’s DSB-related responsibility could potentially provide firms the start of a governance-led roadmap for compliance to the Securities and Exchange Commission’s and Justice Department’s cyber regulations.
Purpose Risk management is an under-explored topic in information systems (IS) research that involves complex and interrelated activities. Consequently, the authors explore the importance of interrelated activities by examining how the maturity of one type of information technology risk management (ITRM) practice is influenced by the maturity of other types of ITRM practices. The purpose of this paper is to explore these relationships, the authors develop a model based on organizational strategy implementation theory and the COBIT framework. The model identifies four types of ITRM practices, namely, IT governance (ITG); communications; operations; and monitoring. Design/methodology/approach The authors use a survey methodology to collect data on senior information technology (IT) executives' perceptions on ITRM practices. The authors use an exploratory factor analysis (EFA) to identify four dimensions of ITR M practices and conduct a structural equation model to observe the associations. Findings The survey of senior IT executives' perceptions suggests that the maturity of ITRM practices related to ITG, communications and monitoring positively influence the maturity of operations-related ITRM practices. Further, the maturity of communications-related ITRM practices mediates the relationship between ITG and operations-related ITRM practices. The aggregate results demonstrate the inter-relatedness of ITRM practices and highlight the importance of taking a holistic view of ITRM. Research limitations/implications Given the content and complexity of the study, it is difficult to obtain senior executives’ responses in large firms. Therefore, this study did not use a separate sample to conduct the EFA to obtain the underlying four constructs. Also, the ITRM practices identified are perceptions. Even though the authors consider this to be a limitation, it also communicates the pressing areas that senior IT professionals are expected to focus given various external and internal pressures. This study focuses on large firms, hence, small to midsize firms are not well represented. Practical implications Given the demanding regulatory and financial reporting requirements and the complexity of IT, there is an increasing possibility that the accounting profession will require IT professionals to focus on operations-related ITRM practices, such as security, availability and confidentially of data and IS are closely related to internal controls. However, as this study demonstrates, the maturity of operations-related ITRM practices cannot be achieved by focusing solely on operations-related IT risks. Therefore, IT practitioners can use this study to raise awareness of the complex interrelationships among ITRM practices among managers to improve the overall ITRM practices in a firm. Social implications The study also shows the importance of establishing proper communication channels among various business functions with regard to ITRM. Extant IT research identifies the importance of the firm’s communication structure on various firm performance measures. For example, Krotov (2015) mentions the importance of communication in improving trust between the Chief Executive Officer and Chief Financial Officer. Firms with established communication channels have the necessary medium to educate and involve other departments with regard to the security of data. Thus, such firms are more likely to have mature risk management practices because of increased awareness of risks and preventive techniques. Originality/value The study contributes to ITG and risk management literature by identifying the role of monitoring-related ITRM practices on improving other areas of risk management. The study also extends the existing ITRM literature by providing an organizational strategy perspective to ITRM practices and showing how ITRM practices follow organizational strategy implementation. Further, the authors identify four underlying ITRM categories. Consequently, researchers could choose between two factors (Vincent et al., 2017) or four factors based on the level of detail required for the particular study.
ABSTRACTRecent research documents the improvement of Form 8-K disclosure timeliness in the post-Sarbanes-Oxley Act (SOX) era. However, it remains unclear why disclosure timeliness overall has improved, but disclosure timeliness for certain events has not improved. We examine firms' information technology (IT) management and IT governance in order to investigate their potential positive impacts on 8-K reporting timeliness. We find that, on average, IT-expert Chief Executive Officers (CEOs) and firms with board-level technology committees file Form 8-Ks in a timelier manner. Specifically, firms with IT-expert CEOs file a half-day sooner and firms with technology committees file a full-day sooner. Additional analyses show that firms with technology committees file 8-Ks in a timelier manner than firms without technology committees, even when the events are complicated or surprising. In aggregate, our evidence suggests that IT-expert CEOs and IT expertise on the board facilitates efficient IT utilization and is associated with timely disclosure.Data Availability: The data used are publicly available from the sources cited in the text.
Purpose The purpose of this paper is to examine the implementation and development of eXtensible Business Reporting Language (XBRL) at the Federal Deposit Insurance Corporation (FDIC). The investigation seeks to gauge the roles and experiences of the FDIC and its main stakeholders to determine their engagement in XBRL diffusion within their organizations. Design/methodology/approach This is an qualitative research approach that is driven by the use of an in-depth case study and supported by the use of semi-structured interviews. Findings The findings showcase the role played by the FDIC as the first US regulatory authority that implemented and developed Inline XBRL. In addition, the use of diffusion of innovation theory provides better understanding of each stakeholder’s issues, benefits and challenges based on their experience. Research limitations/implications The research does not examine the institutionalization of XBRL at the FDIC or its stakeholders. Therefore, future research could incorporate a different research design to capture the impact of the pressure resulting from the regulatory mandate. Practical implications The research offers practical insights into public information technology managers and policymakers at global government agencies which are either non-adopters of XBRL technology or current adopters and consider transitioning into Inline XBRL. Global stakeholders could learn from the US experience and develop better understanding of Inline XBRL applications and functionalities. Originality/value The originality of this research is driven by the FDIC’s experience as the first regulatory developer of Inline XBRL. As such, the case study is a best practice to future and current adopters who often navigate the nuisance of implementing new technologies and/or developing existing ones.
ABSTRACT Many firms cite cyber risk as a primary risk factor due to the increase in cybersecurity breach (CSB) incidents. Existing research focuses on the negative, short-term impacts from CSBs, but the longer-term impact is still unknown. Our study investigates firms' levels of innovation following a CSB as an important determinant of firm growth and profitability. Examining reported breaches from 2005–2014, we find a 10 percent decline in research and development spending in the year following a CSB. Further investigation indicates that firms for which R&D is not the primary business model drive the results. We also provide evidence of a decrease in patents two years after a breach, an increase in cash holdings in the year after the breach, and a decrease in investment efficiency four years following the breach. Our aggregate results suggest that CSBs are associated with future strategic decisions involving firm-level innovation and investment decisions. Data Availability: Data are available from the public sources cited in the text.
ABSTRACT Anecdotal research suggests that management is concerned about how Data Security Breaches (DSBs) impact a firm's financial performance. We investigate: whether managers in DSB firms manipulate earnings through real earnings management (REM) and/or accrual-based earnings management (AEM); how breach type, disclosure delay, and external monitoring impact earnings management activities; and how earnings management activities influence a DSB firm's performance. Using a propensity score matched sample, results suggest that DSB firms are more likely to manipulate earnings via REM, but not AEM. Additionally, we find that DSB firms engage in REM through cutting discretionary expenses, decreasing discretionary cash spending, and reducing the cost of goods sold through overproduction. We find some evidence that firms are more likely to increase REM when DSBs involve financial information or when firms delay the DSB disclosure or have low analyst coverage. We provide evidence that REM activities lead to lower subsequent performance in DSB firms. Data Availability: The data used are publicly available from the sources cited in the text.
The Securities and Exchange Commission's 2009 enhanced proxy disclosure requirements and the updated Committee of Sponsoring Organizations' (COSO) Internal Control Framework have caused organizations to increase their focus on risk management and consider the impact of information technology (IT) in enterprise risk management. Our study examines whether board involvement, board expertise, and top management's risk culture affect the maturity of IT risk management practices (maturity) in firms. We find that board involvement positively influences maturity while top managers' risk-taking behavior is associated with lower maturity. Even though board expertise influences maturity, board involvement is more important in explaining maturity. Maturity is higher in firms where risk oversight lies with a board-level, rather than a management, committee. However, the maturity of ITRM practices does not differ among firms whether risk oversight lies with the overall board, or any other board committee. The findings contribute to an under-researched area in IT governance.