GRC Accountability Gap in AI and Cloud Security: Limitations of Automated Compliance and Risk Control Mechanisms
Downloads
Background: Artificial Intelligence (AI) and cloud computing have emerged as important enablers of digital transformation by allowing organizations to increase efficiency, scalability, and cybersecurity. The reliance on automated Governance, Risk, and Compliance (GRC) has led to many accountability challenges, especially in terms of regulatory compliance, risk governance, and security decisions. Methods: A quantitative cross-sectional research design was used in this study using an online survey with 175 respondents comprising cybersecurity, AI, cloud security, and GRC professionals from the United States. Descriptive statistics, percentage analysis, correlation analysis, and regression analysis were performed in SPSS for examining the associations. Results: It was found out that the highest mean score of 4.02 is obtained for Human Oversight and Decision Making and the lowest mean score of 3.68 is obtained for Automated Compliance Effectiveness, thus stressing the role of human expertise. Governance Challenges turned out to be the most pressing issue 28.6% and Risk Control Shortcomings – the biggest contributor 18.3%. All the study variables were found to have a strong positive correlation with each other; the highest correlation was found between Risk Control Mechanisms and Organizational Security Performance r = 0.75. Further multiple regression analysis proved Risk Control Mechanisms to be the most effective predictor β = 0.28 and the suggested model to explain 68.4% of variance of organizational security performance. Conclusion: The study comes to conclusion that a combined approach involving governance, risk management and intelligent automation is required for efficient cloud security performance.
E. Hechler, M. Oberhofer, and T. Schaeck, "AI and Governance," in Apress eBooks, pp. 165–211, 2020. doi: 10.1007/978-1-4842-6206-1_8.
R. Farrell, "Securing the Cloud—Governance, risk, and compliance issues reign supreme," Information Security Journal: A Global Perspective, vol. 19, no. 6, pp. 310–319, 2010. doi: 10.1080/19393555.2010.514655.
S. Esayas and T. Mahler, "Modelling compliance risk: a structured approach," Artificial Intelligence and Law, vol. 23, no. 3, pp. 271–300, 2015. doi: 10.1007/s10506-015-9174-x.
S. Prithi, D. Sumathi, T. Poongodi, and P. Suresh, "Trust Management Framework for handling security issues in multi-cloud environment," in EAI/Springer Innovations in Communication and Computing, pp. 287–306, 2021. doi: 10.1007/978-3-030-74402-1_16.
M. P. Cangemi and P. Taylor, "Harnessing artificial intelligence to deliver Real-Time intelligence and business process improvements," EDPACS, vol. 57, no. 4, pp. 1–6, 2018. doi: 10.1080/07366981.2018.1444007.
T. Halabi and M. Bellaiche, "Towards quantification and evaluation of security of Cloud Service Providers," Journal of Information Security and Applications, vol. 33, pp. 55–65, 2017. doi: 10.1016/j.jisa.2017.01.007.
P. Ryan, M. Crane, and R. Brennan, "GDPR Compliance Tools: Best Practice from RegTech," Lecture Notes in Business Information Processing, pp. 905–929, 2021. doi: 10.1007/978-3-030-75418-1_41.
S. Sadik, M. Ahmed, L. F. Sikos, and A. K. M. N. Islam, "Toward a sustainable cybersecurity ecosystem," Computers, vol. 9, no. 3, p. 74, 2020. doi: 10.3390/computers9030074.
C. Sillaber, M. Brunner, and R. Breu, "Towards an architecture for collaborative Cross–Organizational security requirements management," Lecture Notes in Business Information Processing, pp. 199–210, 2013. doi: 10.1007/978-3-642-38366-3_17.
C. Tang and J. Liu, "Selecting a trusted cloud service provider for your SaaS program," Computers & Security, vol. 50, pp. 60–73, 2015. doi: 10.1016/j.cose.2015.02.001.
J. Agbaegbu, O. T. Arogundade, S. Misra, and R. Damaševičius, "Ontologies in Cloud Computing—Review and Future Directions," Future Internet, vol. 13, no. 12, p. 302, 2021. doi: 10.3390/fi13120302.
S. Thalmann, D. Bachlechner, L. Demetz, and M. Manhart, "Complexity is dead, long live complexity! How software can help service providers manage security and compliance," Computers & Security, vol. 45, pp. 172–185, 2014. doi: 10.1016/j.cose.2014.05.012.
B. E. Aslanertik and B. Yardımcı, "A Comprehensive Framework for Accounting 4.0: Implications of Industry 4.0 in Digital Era," in Contributions to Economics, pp. 549–563, 2019. doi: 10.1007/978-3-030-25275-5_27.
J. Bernal and C. Mazo, "Transparency of Artificial Intelligence in Healthcare: Insights from Professionals in Computing and Healthcare Worldwide," Applied Sciences, vol. 12, no. 20, p. 10228, 2022. doi: 10.3390/app122010228.
T. Wichary, J. M. Batalla, C. X. Mavromoustakis, J. Żurek, and G. Mastorakis, "Network slicing security controls and assurance for verticals," Electronics, vol. 11, no. 2, p. 222, 2022. doi: 10.3390/electronics11020222.
M. P. Cangemi, "Addressing the C-Level Question: How Effectively are Assurance Functions Contributing and Using Automated Analytics?" EDPACS, vol. 55, no. 5, pp. 1–12, 2017. doi: 10.1080/07366981.2017.1324702.
J. O. Imoniana, W. L. Silva, L. Reginato, V. Slomski, and V. G. Slomski, "Sustainable Technologies for the Transition of Auditing towards a Circular Economy," Sustainability, vol. 13, no. 1, p. 218, 2020. doi: 10.3390/su13010218.
D. Gozman, J. Liebenau, and J. Mangan, "The Innovation Mechanisms of Fintech Start-Ups: Insights from SWIFT’s Innotribe Competition," Journal of Management Information Systems, vol. 35, no. 1, pp. 145–179, 2018. doi: 10.1080/07421222.2018.1440768.
S. V. Bharathi, "Prioritizing and ranking the big data Information Security risk spectrum," Global Journal of Flexible Systems Management, vol. 18, no. 3, pp. 183–201, 2017. doi: 10.1007/s40171-017-0157-5.
K. S. R and S. K. Kattumannil, "ERRM Gap Analysis & Identification," in Apress eBooks, pp. 205–283, 2022. doi: 10.1007/978-1-4842-7440-8_3.
S. Saralaya, V. Saralaya, and R. D’Souza, "Compliance management in business processes," Lecture Notes on Data Engineering and Communications Technologies, pp. 53–91, 2018. doi: 10.1007/978-3-319-93940-7_3.
A. Adel, D. Sarwar, and A. Hosseinian-Far, "Transformation of cybersecurity posture in IT telecommunication: a case study of a telecom operator," in Advanced Sciences and Technologies for Security Applications, pp. 441–457, 2021. doi: 10.1007/978-3-030-68534-8_28.
F. Lahmar and H. Mezni, "Security-aware multi-cloud service composition by exploiting rough sets and fuzzy FCA," Soft Computing, vol. 25, no. 7, pp. 5173–5197, 2021. doi: 10.1007/s00500-020-05519-x.
Z. Chen, "Observations and expectations on recent developments of data lakes," Procedia Computer Science, vol. 214, pp. 405–411, 2022. doi: 10.1016/j.procs.2022.11.192.
R. Hibbert, "Calling time on compliance spreadsheet overload," Network Security, vol. 2013, no. 9, pp. 15–17, 2013. doi: 10.1016/s1353-4858(13)70104-1.
R. W. Griffin and S. La Porta, "Operational Smart Grid Security," in Elsevier eBooks, pp. 247–281, 2015. doi: 10.1016/b978-0-12-802122-4.00009-2.
T. A. Ibidapo, "From Industry 4.0 to Quality 4.0," in Management for Professionals, 2022. doi: 10.1007/978-3-031-04192-1.
J. Lloyd, "Additional workload architectural considerations," in Apress eBooks, pp. 279–314, 2022. doi: 10.1007/978-1-4842-8820-7_27.
V. Loia, F. Orciuoli, and A. Gaeta, Computational Techniques for Intelligence Analysis, Springer, 2023. doi: 10.1007/978-3-031-20851-5.
A. Revesz, C. Dunham, P. Jones, C. Bond, R. Fenner, S. Mody, R. Nijjhar, C. Marques, and G. Maidment, "A holistic design approach for 5th generation smart local energy systems: Project GreenSCIES," Energy, vol. 242, p. 122885, 2021. doi: 10.1016/j.energy.2021.122885.
Copyright (c) 2025 International Journal on Orange Technologies

This work is licensed under a Creative Commons Attribution 4.0 International License.




.png)