Document Type


Publication Date


Publication Title

Journal of the Association for Information Systems





First Page


Last Page



The focus of this study is to identify the critical risk factors that can be used to assess the impact of B2B e-commerce on overall enterprise risk. We apply the Khazanchi and Sutton (2001) framework for B2B e-commerce assurance is applied as the organizing conceptual model for the study. The framework focuses on three primary risk components: (1) technical risks, (2) application-user risks, and (3) business risks. To identify a critical set of B2B risk factors, structured focus groups applying a nominal group technique were conducted with three internal constituency groups (corporate groups consisting of IS security, internal IT audit, and e-commerce development managers) and two external constituency groups (e-commerce consultants and external IT auditors). Tests of consistency between the groups confirm strong agreement on the identified critical B2B risk factors. Tests were also conducted on participant groups' perceived relative importance of the critical B2B risk factors. The only substantial inconsistencies were between the internal constituency groups and the e-commerce consultants' group for the business risk factors. This would appear to indicate that the priorities of internal groups might be different from the e-commerce consultants who appear more focused on management support of projects than necessarily on active involvement of trading partner staff with systems integration. Subsequent testing of the three- component B2B risk assurance model with a follow-up questionnaire suggests that the identified risk factors support the model, including theorized interrelationships among the three risk components.


© Association for Information Systems. Use for profit is not allowed. The original version of this article can be found at: