Next Article in Journal
Does Size Matter for Green Growth? Endogenous Size Thresholds in the Eco-Innovation–Performance Nexus
Previous Article in Journal
Short-Term Reversal in Government Bonds: Evidence of State-Dependent Risk from an Emerging Market
 
 
Font Type:
Arial Georgia Verdana
Font Size:
Aa Aa Aa
Line Spacing:
Column Width:
Background:
Article

Does COBIT Framework Adoption Influence Banks’ Financial Stability? Evidence from an Emerging Country

by
Randa Al-Tayan
1,*,
Ibrahim N. Khatatbeh
1,
Demeh Daradkah
2,*,
Maha Shehadeh
3 and
Hanan Alzawahreh
4
1
Department of Banking and Financial Sciences, Business School, The Hashemite University, Zarqa 13133, Jordan
2
Department of Banking and Finance, Faculty of Business, Yarmouk University, Irbid 21163, Jordan
3
Department of Financial Technology, Business School, Al-Ahliyya Amman University, Amman 19328, Jordan
4
Information Technology, The Hashemite University, Zarqa 13133, Jordan
*
Authors to whom correspondence should be addressed.
Risks 2026, 14(6), 138; https://doi.org/10.3390/risks14060138
Submission received: 4 May 2026 / Revised: 10 June 2026 / Accepted: 12 June 2026 / Published: 16 June 2026

Abstract

This paper assesses how the adoption of the COBIT framework is associated with the financial stability of commercial banks in an emerging economy—Jordan. As banks rely increasingly on digital technology, the management of technological risk has become central to their soundness, raising the question of how IT governance is associated with bank-level risk. Using a panel of 12 listed Jordanian commercial banks over 2014–2023, we estimate the relationship between COBIT adoption and stability, measured by the natural logarithm of the Z-score, employing a random-effects panel model. We construct two original, text-based measures of COBIT engagement from banks’ annual reports: a disclosure-frequency count (COBITF) and a binary adoption indicator (COBITD). The results show that COBIT engagement is positively associated with bank stability, whereby a one-unit rise in disclosure frequency is associated with an increase in the Z-score of roughly 2.2%, and the association is robust to the inclusion of bank-specific and macroeconomic controls and to a two-stage least-squares (2SLS) treatment of endogeneity for COBITF. The findings are presented as conditional associations with a plausible governance channel. The study contributes replicable, longitudinal measures of IT-governance engagement for data-scarce emerging markets and offers empirical evidence that engagement with a specific IT-governance framework is positively associated with bank stability.

1. Introduction

The rapid advancement of digital technologies has increased the importance of information technology (IT) governance within corporate governance across all sectors, and it is especially salient in banking. Banks depend on efficient, trustworthy and comprehensive IT, and because most critical banking operations are executed on digital platforms, weaknesses in IT governance can cause operational disruptions, financial losses and reduced viability. Over time, banks have adopted IT-governance frameworks to align IT resources with strategy, support operations and provide assurance over their effectiveness.
The need for sound IT governance in Jordan’s banking and finance sector is underscored by rising cyber-attacks against financial institutions in the country and the wider region. A 2020 ransomware incident at Jordan Kuwait Bank reportedly exposed sensitive employee data and threatened its disclosure, illustrating the growing frequency of attacks on Middle Eastern banks (Okunyte 2025). Globally, the early part of the decade saw several major breaches, including a 2013 attack on a United States payments processor in which the financial and payment-card data of more than two million individuals were stolen, affecting firms connected to international card networks and demonstrating how interconnected financial services have become (Kitten 2013; Khatatbeh et al. 2025). The COVID-19 pandemic intensified these threats: as banks rapidly digitised services for customers confined at home, their attack surface and their exposure to operational failure, financial loss and reputational damage expanded. To mitigate such risks, financial institutions need structured IT-governance frameworks capable of identifying, evaluating and reducing them.
Jordan occupies a distinctive position in the Middle East. Lacking abundant natural resources, it relies heavily on its banking and financial sector to generate wealth and drive development. The Central Bank of Jordan (2025) (CBJ) has been at the forefront of cybersecurity regulation in the region, mandating that licenced banks adopt internationally recognised IT-governance frameworks. This forward-looking stance places Jordan among the regional leaders in cybersecurity governance and institutional accountability, and helps explain why Jordanian commercial banks have developed structured frameworks such as COBIT (Al-Tayan et al. 2023; Saidi 2004). The banking sector is also central to the national economy: in 2025 the CBJ regulated twenty licenced banks, and domestic commercial banks act as financial intermediaries for households, firms and the public sector. Maintaining their stability is therefore important to Jordan’s overall economic health.
Among available frameworks, COBIT is distinct from more technically focused standards such as the National Institute of Standards and Technology (NIST) Cybersecurity Framework (NIST 2024). Whereas the NIST concentrates on information-security operations and technical controls, COBIT provides a broad governance architecture that links IT processes to strategic goals, performance metrics, risk management and regulatory compliance (Toussaint et al. 2024). Its multi-domain structure—spanning governance objectives such as EDM03 (Ensure Risk Optimisation) and management objectives such as APO12 (Manage Risk)—makes it well suited to examining effects on financial soundness. Section 2.2 sets out a structured comparison of COBIT with ISO/IEC 27001 ITIL, the NIST Cybersecurity Framework and COSO ERM, clarifying why COBIT—rather than a purely technical or purely enterprise-risk standard—is the appropriate lens for a stability study and why the CBJ’s COBIT-aligned supervisory requirements have made it the de facto governance standard among Jordanian commercial banks (ISO/IEC 2022; AXELOS 2019; NIST 2024; COSO 2017).
Prior work on the Jordanian banking system suggests that COBIT adoption improves governance and financial-reporting quality (Almubaydeen et al. 2025). However, that literature focuses on the description of governance processes and reporting quality rather than on banks’ risk-taking and financial stability. Hence, the contributions of this study are threefold. First, it provides early empirical evidence on the association between adoption of a specific IT-governance framework (COBIT) and bank financial stability measured by the Z-score. Prior studies examine COBIT’s effects on operational TITefficiency, IT maturity or reporting quality, but the link to a market-standard stability metric has received little attention; we connect the IT-governance and bank-stability literature that has largely developed in parallel. Second, it introduces two replicable, longitudinal measures of COBIT engagement—COBITF (disclosure frequency) and COBITD (binary adoption)—constructed from 120 annual reports. Relative to survey, maturity-index and process-mapping measures (Karabacak et al. 2016; Neto et al. 2018; Nikbakht et al. 2025), these are more replicable and panel-compatible. Third, the sample spans three COBIT editions (4.1, 5 and 2019), enabling a longitudinal view across a full cycle of framework development, in contrast to studies focused on a single version (Ayat and Shafiee 2025; Irsheid et al. 2022).
Furthermore, this study addresses a gap in the COBIT literature by providing early panel evidence on the association between COBIT adoption and the risk and financial stability of Jordanian banks. We use the Z-score—a widely employed measure of bank stability—and a sample of all listed Jordanian commercial banks over 2014–2023. A further contribution is the introduction of two annual-report-based measures of COBIT engagement that are intended to be more replicable, and less dependent on self-report, than questionnaire- or third-party-based indices. We frame these as measures of disclosed governance engagement rather than direct measures of implementation quality, and we are deliberately measured in our novelty claims: while we are not aware of prior work linking a specific IT-governance framework to bank stability in this setting, the broader questions of governance and bank soundness are intensively studied, and our findings are best read as conditional associations that motivate further, larger-sample and cross-country research.
The study extends research on corporate governance and risk management to IT governance in emerging markets. The remainder of the paper is organised as follows. Section 2 reviews the relevant background and literature. Section 3 describes the data, the construction and validation of the textual measures, and the empirical strategy. Section 4 reports and discusses the results. Section 5 discusses COBIT-implementation implications in the Jordanian context. Section 6 concludes with implications, limitations and directions for future research.

2. Literature Review and Hypothesis Development

2.1. The Evolution of IT Governance and the COBIT Framework

The conceptual foundations of IT governance have developed over two decades of research and practice. As technology has become central to the digital economy, IT governance is now viewed as a critical organisational capability that shapes the ability to deploy technological resources towards strategic objectives while controlling operational risk and meeting regulatory requirements (Ilmudeen et al. 2023; Weill and Ross 2004). Banking is a particularly relevant setting because of its information intensity, heavy regulation and exposure to cyber threats; regulators worldwide, and the CBJ in Jordan, have made higher IT-governance standards mandatory, which supports an empirical examination of the governance–stability link.
COBIT has evolved substantially since its inception. Early editions (COBIT 1–4.1) emphasised controls and were oriented towards audit and assurance. COBIT 5, introduced by ISACA in 2012, marked a paradigm shift, repositioning the framework as an enterprise-wide governance system that integrated Val IT 2.0, Risk IT, the IT Assurance Framework (ITAF) and the Business Model for Information Security (BMIS), and aligning with international standards such as ITIL, ISO 27001, PMBOK, PRINCE2 and TOGAF (Amorim et al. 2021). The most recent edition, COBIT 2019 (ISACA 2019), expanded the framework to forty governance and management objectives across six domains, with greater emphasis on digital transformation, cloud governance and agile delivery (Jaime and Barata 2023; Siagian et al. 2025).
Because our sample spans three editions (COBIT 4.1, 5 and 2019), a measurement question arises: do version differences distort the construct? We address this in two ways. First, our search terms explicitly capture each edition (“COBIT”, “COBIT 4”, “COBIT 4.1”, “COBIT 5” and “COBIT 2019”), so that an edition change is recorded as continued engagement rather than as discontinuity. Second, and substantively, the editions are cumulative rather than competing: COBIT 5 subsumed 4.1 and COBIT 2019 refined 5, so a bank that references any edition is signalling adherence to the same lineage of governance principles—risk optimisation, value delivery and stakeholder accountability. We therefore treat the editions as a single evolving standard for the purpose of measuring engagement, while acknowledging in Section 6 that finer version-level effects are a worthwhile avenue for future work.

2.2. COBIT Relative to ISO/IEC 27001, ITIL, the NIST Cybersecurity Framework and COSO ERM

The frameworks most often compared with COBIT differ in scope, primary objective and the organisational level at which they operate. ISO/IEC 27001 specifies requirements for an information-security management system and is certification-oriented; ITIL codifies IT-service-management processes and is operations-oriented; the NIST Cybersecurity Framework provides a risk-based catalogue of cybersecurity functions and controls; and COSO ERM offers an enterprise-risk-management architecture that is not IT-specific. COBIT is distinctive in bridging enterprise governance and IT: it links board-level governance objectives to IT-management processes and to performance and risk metrics, which is precisely the channel through which IT governance can plausibly affect a bank-level outcome such as the Z-score. Table 1 summarises the comparison.

2.3. Measurement of COBIT in the Literature

Prior research has assessed COBIT’s impact on banking using predominantly qualitative or binary approaches and, less often, bespoke quantitative indices. Three broad strands can be distinguished. The first relies on perceptual, survey-based instruments in which respondents rate maturity or effectiveness (e.g., Kubilay and Celiktas 2025); these capture managerial perceptions but are prone to self-report and social-desirability bias and typically use small cross-sectional convenience samples. The second uses maturity models and process-assessment scales—often externally constructed—to score implementation at a point in time (Karabacak et al. 2016; Neto et al. 2018; Berrada et al. 2021; Nikbakht et al. 2025); these are informative but rarely track change over time and require auditor or researcher access that is seldom available across a full sector. The third, closest to ours, uses qualitative case studies or binary indicators of whether COBIT is implemented (Al-Gasaymeh et al. 2023; Saidat et al. 2024; Tangka and Lompoliu 2025).
Against this backdrop, our two measures occupy a deliberate middle ground. COBITD is a binary adoption indicator comparable to prior implemented/not-implemented coding, which anchors our measure to the existing literature and aids comparability. COBITF—the frequency of COBIT-related disclosure—adds a continuous, time-varying dimension that the binary and maturity approaches lack, allowing us to observe the deepening of governance reporting after initial adoption. Both are built from audited annual reports rather than surveys, which makes them replicable and panel-compatible. We are explicit, however, about what they do and do not measure: consistent with the disclosure literature, COBITF most directly captures disclosed governance engagement (an output of the firm’s reporting choices) and is, at best, a proxy for—not a direct gauge of—implementation quality. Section 3.3 sets out the validation steps and biases we address; Section 6 discusses NLP-based extensions and triangulation with maturity assessments as priorities for future work.

2.4. COBIT Adoption in Jordanian Banking: An Institutional Account

The trajectory of COBIT adoption in Jordanian banking illustrates progression through distinct stages. Before COBIT 5 was released in 2012, references to COBIT outside audit and IT-control functions were rare. As COBIT 5’s governance orientation took hold, the CBJ began incorporating its elements into mandatory IT-governance supervisory guidelines for licenced banks. From 2014, many commercial banks formally adopted COBIT 5 once they had built the organisational structures needed to comply. This pattern is consistent with coercive isomorphism, whereby regulatory bodies require organisations to conform to particular standards (Vuko et al. 2025; DiMaggio and Powell 1983). Because our sample window (2014–2023) spans the full implementation process, it offers a complete observation window for panel estimation.
From an agency-theory perspective, COBIT adoption is a governance mechanism that can mitigate principal–agent conflict in financial institutions. Information asymmetry between shareholders (principals) and managers (agents) can misalign incentives, encourage excessive risk-taking and reduce transparency (Jensen and Meckling 1976). COBIT’s architecture counters these tendencies through explicit reporting, standardised controls and transparent performance measures. Specific management objectives—APO12 (Managed Risk)—establish an enterprise risk-management process; EDM03 (Risk Optimisation) aligns risk-taking with the bank’s risk appetite; and EDM05 (Stakeholder Engagement) mandates regular communication about risk activities, reducing asymmetry between the bank and its stakeholders (Siagian et al. 2025; Aguillar et al. 2017; Qi et al. 2023). Together these constrain unmonitored or excessive risk-taking and strengthen the governance–stability link.
The resource-based view (RBV) offers a complementary lens, treating IT governance as a potential source of advantage. Under the RBV, resources that are valuable, rare, inimitable and non-substitutable can support superior performance (Barney 1991; Bharadwaj 2000). Governance capabilities developed through COBIT—formalised IT-risk assessment, performance measurement and cross-functional governance structures—are organisationally embedded and difficult to imitate (Larabi 2025). Ilmudeen et al. (2023) show that business–IT alignment mediates the relationship between IT investment and firm performance, supporting the view that appropriate IT-governance capabilities yield financial returns.
Institutional theory adds further insight by identifying the coercive, mimetic and normative pressures that drive governance convergence in regulated industries (DiMaggio and Powell 1983). In Jordan, CBJ directives were the primary coercive pressure; reputational and competitive pressures encouraged laggards to imitate early adopters; and professional associations such as ISACA, together with the spread of COBIT training and certification, normalised adoption. The cumulative effect is evident in our data, which document diffusion from no reported adoption in 2014 to universal adoption across all twelve banks by 2023 (Vuko et al. 2025; Berrada et al. 2021).

2.5. Empirical Evidence and Hypothesis Development

Empirical work on COBIT and organisational outcomes in banking motivates our hypotheses. Smits and Van Hillegersberg (2018) find, using longitudinal data, that greater COBIT maturity accompanies stronger risk monitoring and governance. Tangka and Lompoliu (2025) report that formal COBIT adoption reduces operational failures through structured IT management. Al-Gasaymeh et al. (2023) and Al-Hakim et al. (2021) document reductions in operational losses following COBIT 5 implementation in Jordanian banks, and Saidat et al. (2024) find significant positive effects of COBIT 2019 on cyber-governance effectiveness across cyber-information-security management, cyber-risk management and cybersecurity programmes.
More broadly, the governance–risk literature supports the view that strong governance constrains excessive risk-taking and promotes stability. Javed et al. (2024) find that board structure moderates risk-taking in Pakistani banks, and Ofori et al. (2025) show that governance effectiveness reduces operational risk in Ghanaian banks—both emerging-market settings comparable to Jordan (see also De Haan and Vlahu 2016 for a survey of bank governance). The Z-score, which combines profitability, capitalisation and earnings volatility into a single insolvency-risk measure, is widely used as a stability proxy and has been linked to governance quality in banking (Boyd et al. 2006; Beck et al. 2013; Laeven and Valencia 2018; Li et al. 2017).
Hypothesis 1 (H1). 
A higher level of COBIT framework engagement is positively associated with greater financial stability in Jordanian commercial banks.

3. Data and Methodology

3.1. Sample, Sample Period and Data Sources

The sample period begins in 2014 for two reasons. First, the 2012 release of COBIT 5 transformed COBIT from an audit-driven control standard into a holistic enterprise-governance architecture, and its expanded scope prompted its inclusion in CBJ supervisory directives; evidence of adoption by Jordanian banks emerged only after 2014, with references to COBIT almost absent beforehand. Second, a 2014 start yields complete and consistent panel data for each bank over a full ten-year window, consistent with emerging-market studies that begin samples after major governance or regulatory events (Al-Habashneh et al. 2023; Beck et al. 2013).
The study includes all locally listed commercial banks on the Amman Stock Exchange (ASE). Foreign banks are excluded because they are affiliates whose governance, IT and risk-management policies are directed by parent companies, reducing comparability. Islamic banks are excluded as a result of comparability and identification issues. In essence, Islamic banks operate under a distinct contractual and accounting architecture (e.g., profit-and-loss-sharing instruments, AAOIFI standards and Shari’ah-supervisory-board oversight) that materially changes both the determinants of the Z-score and the channels through which governance affects risk, so pooling them with conventional banks would conflate two different risk-generating processes. Restricting the sample to conventional commercial banks therefore yields a homogeneous set of institutions with comparable business models and a common regulatory framework, isolating the COBIT–stability association from confounding model differences. These criteria leave a balanced panel of twelve conventional commercial banks over 2014–2023 (120 bank-year observations).
Because COBIT adoption is not reported through standardised quantitative indicators, the COBIT measures were constructed by hand from banks’ annual reports, focusing on the management-discussion, corporate-governance and risk-management sections. Audited annual reports and ASE statistical bulletins provided the bank-level financial and control variables, and macroeconomic data were drawn from the World Bank’s World Development Indicators.

3.2. Variable Definitions and Measurement

The dependent variable, financial stability (LnZSCORE), is measured by the natural logarithm of the Z-score computed over a three-year rolling window following Li et al. (2017). The Z-score captures proximity to insolvency by combining profitability, capitalisation and earnings volatility; higher values indicate greater stability (Boyd et al. 2006; Beck et al. 2013). The logarithmic transformation reduces skewness and improves comparability across banks and time, which is standard in panel banking research.
Following the textual-analysis tradition in finance and accounting (Hoyt and Liebenberg 2011; Pagach and Warr 2011; Eckles et al. 2014; Loughran and McDonald 2016; Senave et al. 2023), we identify COBIT engagement from publicly available firm documents. We search the management-discussion, corporate-governance and risk-management sections for the terms “COBIT”, “COBIT 4”, “COBIT 4.1”, “COBIT 5” and “COBIT 2019”. COBITF is the frequency of these terms in a bank’s annual report in a given year; COBITD equals one if the report contains any explicit statement of formal adoption, alignment or use of COBIT for IT governance or risk management, and zero otherwise. Following Al-Tayan et al. (2023), the dual-proxy design captures both the breadth (binary) and the depth/intensity (frequency) of engagement, providing a richer description than either measure alone.
We control for bank-specific and macroeconomic determinants of stability documented in prior work: leverage, size, net interest margin (NIM), liquidity, income diversification and Tobin’s Q (Beck et al. 2013; Hunjra et al. 2020; Sakawa et al. 2023; Acosta-Smith et al. 2024), and GDP per capita, inflation and a COVID-19 period dummy to absorb systemic shocks. These controls ensure that the estimated COBIT effect reflects governance rather than underlying financial or macroeconomic conditions. Table 2 defines all variables.

3.3. Construction, Reliability and Validation of the Textual Measures

Because COBITF and COBITD are hand-coded, they could in principle be affected by coder subjectivity, coding differences and incomplete capture of implementation. We took several steps to address these concerns and to validate the constructs. First, the coding protocol was specified ex ante, whereby a fixed term list, fixed document sections, and explicit rules for what constitutes an adoption statement (a clear declaration of adoption, alignment or use of COBIT for IT governance or risk management), so that coding is rule-based rather than discretionary. Second, all 120 reports were independently double-coded by two researchers; inter-coder agreement was assessed using “Cohen’s κ” for COBITD and the intraclass correlation coefficient for COBITF, with disagreements reconciled by a third reader. Third, we cross-checked coded adoption against corporate-governance disclosures and, where available, IT-governance committee charters to reduce false positives from incidental mentions. Nevertheless, several limitations remain. For instance, the disclosure bias, whereby annual-report frequency reflects a reporting choice and may capture disclosure intensity rather than implementation quality, so COBITF is best read as a measure of disclosed governance engagement that proxies—imperfectly—for the underlying construct.

3.4. Patterns of COBIT Engagement over Time

Figure 1 and Figure 2 provide complementary views of COBIT engagement during the sample period. Figure 1 plots the cumulative number of adopting banks and annotates the three diffusion phases with the key institutional milestones described in Section 2.4: (i) an initial-diffusion phase (2014–2016) in which a few pioneers adopted COBIT; (ii) a regulation-driven rapid-adoption phase (2017–2020) propelled by CBJ directives and peer pressure; and (iii) a full-diffusion phase (2021–2023) in which the remaining banks adopted, reaching sector-wide coverage by 2023. The S-curve pattern is typical of governance-standard diffusion in regulated sectors and underpins the panel identification strategy, since the data contain both adopting and non-adopting bank-years (Vuko et al. 2025).
Figure 2 documents the cumulative frequency of COBIT-related keywords, adding a depth dimension to the binary picture in Figure 1. It overlays the annual keyword count (bars) with the cumulative count (line) and marks the post-2018 inflection. The steep rise from 2018 onward reflects a transition from initial adoption to the deepening of governance reporting, supporting the construct validity of COBITF as a measure of intensity distinct from the binary signal in COBITD. The lag between the adoption curve (Figure 1) and the keyword curve (Figure 2) indicates that governance deepening occurs years after initial adoption, consistent with treating COBIT engagement as a continuum rather than a single compliance step.

3.5. Empirical Model

To test H1, we estimate the following baseline panel model:
L n Z S C O R E i t   =   α   +   β 1 C O B I T i t   +   γ X i t   +   δ M t   +   u i   +   ε i t
where COBITit is COBITF or COBITD; Xit is a vector of bank-specific controls (leverage, size, NIM, liquidity, Div, TobinQ); Mt is a vector of macroeconomic variables (GDP, INF, COVID); ui is the bank-specific effect; and εit is the idiosyncratic error.
The regression is estimated using the RE estimator. The choice of RE over fixed effects (FE) is justified as the Hausman test does not reject the null that the bank-specific effects are uncorrelated with the regressors, favouring the more efficient RE estimator (Hausman 1978). Moreover, the key adoption variable is highly persistent, whereby COBIT adoption is an absorbing state (once a bank adopts, it remains an adopter), so most of its variation is between banks rather than within; and an FE estimator would absorb this between variation and discard the very signal of interest, while RE retains it. In addition, we also report the endogeneity-robust 2SLS estimates in Section 4.6.

4. Results and Discussion

4.1. Descriptive Statistics

Table 3 reports descriptive statistics. The mean LnZSCORE of 3.69 indicates a moderate level of stability among listed Jordanian commercial banks over 2014–2023, in the 3–4 range reported for emerging-market banks (Beck et al. 2013; Laeven and Valencia 2018), with a sizeable standard deviation reflecting heterogeneity in risk profiles. COBITF averages 4.4 mentions per report (maximum 39), indicating wide variation in disclosure intensity, while COBITD has a mean of 0.65, so about two-thirds of bank-years report adopting or aligning with COBIT. Adoption rose from none in 2014–2015 to five banks in 2016, nine in 2017–2018 and all twelve by 2023, indicating full diffusion across the sector.

4.2. Correlations and the Sign of the Simple Association

Table 4 presents pairwise correlations. Correlations among the explanatory variables are generally moderate (all |r| < 0.6), suggesting no severe multicollinearity. COBITF and COBITD are positively and significantly correlated (0.429), as expected, since formal adopters also disclose more widely. Although the bivariate correlations between LnZSCORE and the COBIT measures are negative and statistically insignificant, the multivariate results indicate a positive and significant association. This sign reversal reflects a suppression effect arising from omitted confounding factors. Specifically, COBIT engagement is positively associated with leverage and the COVID-19 period, both of which are negatively related to bank stability. Consequently, the unconditional correlation masks the underlying relationship. Once bank-specific and macroeconomic factors are controlled for, the positive association between COBIT engagement and stability becomes evident. This finding underscores the importance of multivariate analysis in isolating the effect of IT governance on bank stability.
To further assess the potential presence of multicollinearity, the Variance Inflation Factors (VIF) test was calculated. If the VIF was less than 5, the results showed no multicollinearity among variables (Kim 2019). This study’s results showed no multicollinearity among variables as each variable had a VIF value less than 5, as shown in Table 5.

4.3. Diagnostic Tests

Table 6 displays a series of diagnostic tests on the panel regression for the baseline model to evaluate the validity of the estimates. The Lagrange Multiplier test (Breusch and Pagan 1979) showed a highly significant p-value (p < 0.001), indicating the presence of individual-specific effects and validating the employment of random effects over pooled OLS. The Hausman test showed a p-value of 0.6976, implying no systematic difference between the random-effects and fixed-effects estimators; hence, the random-effects specification was employed for all models. Autocorrelation was tested by the Breusch–Godfrey/Wooldridge test (Wooldridge 2010), which showed a statistically significant result (p = 0.0079) indicating the presence of serial correlation in the idiosyncratic errors. On the other hand, the Breusch–Pagan heteroskedasticity test showed a p-value of 0.8421, suggesting no evidence of heteroskedastic disturbances. All random-effects regressions were estimated with cluster-robust standard errors (Arellano 1987) in order to control for detected serial correlation and potential cross-sectional dependence.

4.4. Baseline Results

Table 7 reports the RE estimates with COBITF as the variable of interest. COBITF carries a positive and statistically significant coefficient (0.021–0.022) that is stable across specifications with and without macroeconomic controls. The economic magnitude is meaningful but not implausibly large. Because the dependent variable is the natural log of Z-score, the coefficient is a semi-elasticity, whereby one additional COBIT-related disclosure is associated with an increase in the Z-score of about 2.2%. Scaling to the data, a one-standard-deviation rise in COBITF (about 7.5 mentions) corresponds to roughly a 17–18% higher Z-score, and moving a bank from the mean (4.4) towards the maximum (39) implies a substantially higher distance to insolvency. Evaluated at the sample mean Z-score (≈40), a ten-mention increase in disclosure intensity is associated with an increase of roughly nine to ten Z-score points. Hence, we interpret these as conditional associations: they are economically relevant for financial-stability monitoring—plausibly reflecting stronger Risk Optimisation (EDM03) and Managed Risk (APO12) processes—while remaining within a credible range rather than implying that disclosure mechanically buys stability.
Among the controls, leverage is consistently negative and significant, confirming that more leveraged banks are less stable (Acosta-Smith et al. 2024). Bank size is negative and significant, indicating that larger banks tend to be less financially stable than smaller banks. Although large banks benefit from greater resources and market access, they also face higher organisation complexity and systemic risk due to their extensive network and operations (Akbar et al. 2024). As a result, the risks associated with size may outweigh the benefit of scale, leading to a lower Z-score. Income diversification (Div) is negative and highly significant, suggesting that non-interest-income activities expose Jordanian banks to greater volatility, consistent with Al-Habashneh et al. (2023) for Jordan and Hunjra et al. (2020) for South Asia. Tobin’s Q is positive and significant, indicating that better-valued banks are perceived as more stable (Sakawa et al. 2023). The macroeconomic variables and the COVID dummy are insignificant, suggesting that internal governance dominates macro shocks in explaining cross-bank stability differences over the sample.

4.5. Robustness Tests

Table 8 re-estimates the model with the binary indicator COBITD. The coefficient is positive and significant in both specifications (0.345 and 0.400), supporting H1: formally adopting banks exhibit higher Z-scores than non-adopters. In semi-log terms, the point estimates imply that adoption is associated with an approximately 41–49% higher Z-score (exp(β) − 1). We flag this magnitude as large and interpret it with caution: it reflects a between-bank comparison of adopters and non-adopters that may absorb correlated, unobserved quality differences, and—as Section 4.6 shows—the binary indicator is weakly identified in the instrumental-variables setting. We therefore read COBITD primarily as a robustness check confirming the sign and significance of the COBITF result, rather than as a precise causal magnitude. The remaining coefficients mirror those in Table 7.

4.6. Addressing Endogeneity: Two-Stage Least Squares

Evaluating the COBIT–stability link raises endogeneity concerns from reverse causality and omitted variables. Distressed banks might be pushed by regulators or shareholders to adopt structured IT governance, so adoption could partly reflect prior instability; and unobserved factors (management quality, bank culture, technology infrastructure) could drive both adoption and stability, biassing OLS and RE estimates. While FE mitigates time-invariant omitted-variable bias, it does not resolve reverse causality or time-varying confounding.
We therefore estimate two-stage least squares (2SLS) with heteroskedasticity-robust standard errors (Baum et al. 2007). As reported in Table 9, we instrument COBIT adoption with two sets of excluded instruments: lagged values of the endogenous regressor (the first and second lags of COBITF and the first lag of COBITD), which capture institutional inertia in framework adoption and are not driven by contemporaneous stability shocks; and the industry peer-adoption rate (peer_COBITF, peer_COBITD)—the average adoption of the other sampled banks in a given year—reflecting the diffusion dynamics of governance standards. Industry-wide pressures from regulators, professional norms and competitive mimicry plausibly affect a bank’s adoption independently of its contemporaneous financial condition, supporting the exclusion restriction.
As reported in Table 9, column (1) supports the baseline: instrumented COBITF is positive and significant (0.023, p < 0.05). The first-stage F of 51.45 far exceeds the Stock and Yogo (2005) thresholds, the Hansen J (p = 0.334) does not reject instrument exogeneity, and the Kleibergen–Paap LM test (p = 0.001) confirms relevance. Column (2) is, by contrast, weakly identified: the first-stage F of 2.15 is far below conventional weak-instrument thresholds because a single lag of a binary, near-absorbing variable provides little usable variation across a short panel. We therefore read the insignificant 2SLS coefficient on COBITD as an identification result—the instrument set is too weak to recover a precise estimate—rather than as evidence of no effect. This is exactly why we retain COBITD as a robustness indicator (Table 8) and base our central inference on the well-identified COBITF (column 1). Taken together, the OLS/RE and 2SLS results tell a coherent story: the disclosure-intensity measure is positively associated with stability and survives an endogeneity-robust treatment, while the binary measure corroborates the sign but cannot be precisely instrumented. Theoretically, the COBITF result is consistent with agency theory: where adoption is driven by peer pressure and institutional inertia rather than a bank’s own distress, the governance-constraining effect of COBIT—reducing information asymmetry and curbing excessive risk-taking through EDM03, APO12 and EDM05—still maps onto higher stability.

5. COBIT Implementation in the Jordanian Banking Context

The benefits of COBIT depend on the depth of integration, not on compliance signalling. In a market where adoption was largely coercive (CBJ-mandated), there is a risk of “box-ticking”—formal alignment that is not embedded in day-to-day risk processes—so that disclosure outpaces substantive control. Capacity constraints are also material: scarce specialised IT-governance and assurance skills, the cost of maturity uplift for smaller banks, and reliance on a limited pool of external advisers can all blunt effectiveness. Legacy-system complexity and incomplete data governance further limit the reach of COBIT objectives such as APO12 across both front- and back-office functions.
Moreover, as Jordanian banks adopt AI for credit scoring, fraud detection and customer service, new governance risks emerge—model opacity, data-quality and bias issues, and third-party model dependence. COBIT 2019’s objectives for managed data and managed risk provide a scaffold, but AI-specific oversight (model validation, explainability, human-in-the-loop controls) is not yet standard practice and represents a governance gap. Furthermore, rapid digitisation has expanded the attack surface; phishing, account-takeover and authorised-push-payment fraud are rising across the region (Idayani et al. 2024). COBIT’s value here lies in linking technical controls (which standards such as ISO/IEC 27001 and the NIST CSF specify in detail) to board-level risk appetite and accountability, but the framework is only as effective as the underlying detection and response capabilities it governs.
In addition, Jordan’s regional exposure introduces operational and continuity risks—from regional conflict spillovers to cross-border payment disruptions and heightened state-linked cyber threats. Effective IT governance must therefore extend to business-continuity and third-party/concentration risk, areas where COBIT’s governance objectives intersect with broader enterprise-risk management (COSO ERM). These risks also condition the external validity of our results, since the governance–stability link may behave differently under acute geopolitical stress.

6. Conclusions, Implications, Limitations and Future Research

6.1. Key Findings

This study examines the association between COBIT framework adoption and the financial stability of twelve Jordanian commercial banks over 2014–2023. Using two annual-report-based measures of engagement and a random-effects specification supported by formal diagnostics, we find that COBIT engagement is positively and significantly associated with stability, and that the disclosure-intensity measure (COBITF) survives an endogeneity-robust 2SLS treatment. We are careful to frame these findings as conditional associations with a plausible governance channel rather than as definitive causal effects, in light of the small sample and the weak identification of the binary indicator.
The findings suggest that IT governance should be treated as a core element in studies of bank stability rather than a separate technical issue. Much of the literature has approached IT governance from an operational angle, while stability models have emphasised financial indicators and traditional governance; linking COBIT to the Z-score connects these strands and indicates that IT governance belongs alongside board structure, ownership and capital frameworks in risk-and-control models. Theoretically, the results are consistent with an integrated reading of agency theory (accountability and reduced asymmetry), the resource-based view (governance capability as a hard-to-imitate resource) and institutional theory (coercive, mimetic and normative diffusion).

6.2. Practical, Policy and Managerial Implications

As all twelve sampled banks have already adopted COBIT, the operative question is not whether to adopt but how to convert adoption into substantive stability gains, and what constrains that conversion. We offer specific, actionable recommendations. For bank management: (i) move from compliance to embedding by tying COBIT objectives (notably EDM03 and APO12) to board-approved risk appetite and to executive performance metrics; (ii) extend coverage across both front- and back-office processes and integrate IT-risk reporting into enterprise risk management rather than siloed IT audit; and (iii) invest in IT-governance capability (skills, independent assurance, model-risk and data-governance functions) so that disclosure reflects capability. For the CBJ and regulators: (i) supplement adoption mandates with periodic, evidence-based maturity assessments so supervision targets implementation quality, not disclosure; (ii) issue AI- and cyber-fraud-specific governance expectations that build on COBIT; and (iii) monitor concentration in the advisory and assurance market. We also identify factors that may limit COBIT’s positive impact—box-ticking adoption, skills and budget constraints, legacy-system complexity, weak data governance and the absence of AI-specific controls—and the recommendations above are designed to address each.

6.3. Generalisability to Other Countries

The results are most directly applicable to bank-based, regulator-led emerging markets with characteristics similar to Jordan: a concentrated banking sector, an active supervisor mandating internationally recognised IT-governance standards, and reliance on narrative annual-report disclosure in the absence of standardised IT-governance databases. Countries in the MENA region and other emerging markets that satisfy these conditions are natural settings in which the COBITF/COBITD measurement template and the governance–stability hypothesis could be tested. We are cautious about extending the magnitudes beyond this context: in markets with different disclosure regimes, voluntary (rather than coercive) adoption, or different bank business models, both the measurement properties of disclosure-based indices and the strength of the governance–stability link may differ. Cross-country replication is therefore essential before the findings can be treated as general.

6.4. Limitations

Several limitations should temper interpretation. First, the sample is small (twelve banks, 120 observations) and single-country, which limits statistical power and external validity and means the 2SLS estimates—especially for the near-absorbing binary indicator—rest on limited identifying variation. Second, the COBIT measures are disclosure-based and hand-coded: despite double-coding and reliability checks, they capture disclosed engagement and may reflect reporting intensity rather than implementation quality, and they cannot distinguish substantive embedding from symbolic compliance. Third, excluding Islamic and foreign banks aids comparability but restricts scope. Fourth, the analysis does not separately identify the effects of individual COBIT editions or specific governance objectives. Fifth, while the 2SLS for COBITF is well identified, causal claims remain tentative given the observational design.

6.5. Future Research

These limitations motivate a clear agenda. (i) Measurement: replace or augment manual coding with NLP-based textual analysis—semantic matching of COBIT-aligned concepts, not just keywords—and triangulate disclosure-based indices against audited maturity assessments and survey measures to validate construct quality. (ii) Robustness: re-test using alternative stability measures (distance-to-default, non-performing-loan ratios, capital buffers and tail-risk measures) and alternative estimators. (iii) External validity: extend to multi-country panels across MENA and other emerging markets, and compare conventional with Islamic banks, where the governance–stability mechanism may differ. (iv) Mechanisms: link specific COBIT objectives and editions to outcomes, and examine moderators such as board IT expertise, ownership and bank size. (v) Forward-looking risks: study how AI governance, digital-fraud exposure and geopolitical risk condition the COBIT–stability relationship. Pursuing this agenda would move the literature from the early, contextual evidence offered here towards stronger causal and generalisable conclusions.

Author Contributions

Conceptualization, R.A.-T.; Methodology, I.N.K.; Formal analysis, I.N.K.; Data curation, R.A.-T. and H.A.; Writing—original draft, R.A.-T. and I.N.K.; Writing—review & editing, R.A.-T., I.N.K., D.D. and M.S.; Supervision, R.A.-T. and I.N.K. All authors have read and agreed to the published version of the manuscript.

Funding

This research received no external funding.

Data Availability Statement

The data used in this study were hand-collected by the authors from the annual reports of the sampled banks and subsequently compiled into a research dataset for the purposes of analysis. Detailed procedures for data collection, variable construction, and dataset replication are fully described in the manuscript. The dataset generated and analyzed during the current study is not publicly available due to the substantial manual processing involved, but is available from the corresponding authors upon reasonable request for academic and research purposes.

Conflicts of Interest

The authors declare no conflict of interest.

References

  1. Acosta-Smith, J., Micheal Grill, and Jan H. Lang. 2024. The leverage ratio, risk-taking and bank stability. Journal of Financial Stability 74: 100833. [Google Scholar] [CrossRef]
  2. Aguillar, Daniel. A., Isabel Murakami, Pedro Manso, Jr., and Plinio T. Aquino, Jr. 2017. Small Brazilian business and IT governance: Viability and case study. In Conference on Information Systems Management. Cham: Springer, pp. 173–93. [Google Scholar]
  3. Akbar, Faisal, Mu’izzuddin Isnurhadi, and Marlina Widiyanti. 2024. The Influence of Bank Ownership, Company Size on Bank Stability: A Study in the Southeast Asian Region. American Journal of Economic and Management Business (AJEMB) 3: 156–62. [Google Scholar] [CrossRef]
  4. Al-Gasaymeh, Anwer., Ghazi M. Qasaimeh, Najed Alrawashdeh, Ayman A. Alsmadi, and Haitham M. Alzoubi. 2023. The impact of COBIT 5 on the effectiveness of applying governance tools in Jordanian commercial banks. Calitatea 24: 377–84. [Google Scholar] [CrossRef]
  5. Al-Habashneh, Abdallah. K., Ibrahim N. Khatatbeh, and Khaled M. Alzubi. 2023. The impact of income diversification on the stability of listed Jordanian commercial banks during the COVID-19 pandemic. Banks and Bank Systems 18: 35. [Google Scholar] [CrossRef]
  6. Al-Hakim, Munir. S., Ibrahim Khrais, Kaled Alsadi, and Yehya Khasawneh. 2021. The impact of using IT governance COBIT 5 in reducing banking credit risk in Islamic banks. In 2021 22nd International Arab Conference on Information Technology (ACIT). New York: IEEE, pp. 1–12. [Google Scholar]
  7. Al-Tayan, Randa., Simeon Coleman, and Ahmad H. Ahmad. 2023. Enterprise Risk Management and Firm Value: Empirical Analysis of Corporate Firms in the Middle East. SSRN. Available online: https://ssrn.com/abstract=4543553 (accessed on 16 April 2026).
  8. Almubaydeen, Tareq, Riham Alkabbji, and Maha M. Atout. 2025. The impact of IT governance according to the COBIT framework on financial reporting quality for Jordanian commercial banks listed on the ASE. In From Machine Learning to Artificial Intelligence. Cham: Springer, pp. 179–93. [Google Scholar]
  9. Amorim, Ana. C., Miguel M. da Silva, Rúben Pereira, and Margarida Gonçalves. 2021. Using agile methodologies for adopting COBIT. Information Systems 101: 101496. [Google Scholar] [CrossRef]
  10. Arellano, Manuel. 1987. Computing robust standard errors for within-groups estimators. Oxford Bulletin of Economics and Statistics 49: 431–34. [Google Scholar]
  11. AXELOS. 2019. ITIL Foundation: ITIL 4 Edition. Norwich: The Stationery Office (TSO). Available online: https://openlibrary.org/books/OL32734151M/ITIL_Foundation_ITIL_4_Edition?utm (accessed on 16 April 2026).
  12. Ayat, Masarat, and Sanaz Shafiee. 2025. Developing a comprehensive IT governance framework for Iranian hospitals: A fuzzy Delphi approach. International Journal of Health Governance 30: 410–21. [Google Scholar] [CrossRef]
  13. Barney, Jay. 1991. Firm resources and sustained competitive advantage. Journal of Management 17: 99–120. [Google Scholar] [CrossRef]
  14. Baum, Christopher F., Mark E. Schaffer, and Steven Stillman. 2007. Enhanced routines for instrumental variables/GMM estimation and testing. Stata Journal 7: 465–506. [Google Scholar] [CrossRef]
  15. Beck, Thorsten, Olivier De Jonghe, and Glenn Schepens. 2013. Bank competition and stability: Cross-country heterogeneity. Journal of Financial Intermediation 22: 218–44. [Google Scholar] [CrossRef]
  16. Berrada, Hasnaa, Jaouad Boutahar, and Souhaïl E. G. El Houssaïni. 2021. Simplified IT risk management maturity audit system based on “COBIT 5 for Risk”. International Journal of Advanced Computer Science and Applications 12: 641–52. [Google Scholar] [CrossRef]
  17. Bharadwaj, Anandhi S. 2000. A resource-based perspective on information technology capability and firm performance. MIS Quarterly 24: 169–96. [Google Scholar] [CrossRef]
  18. Boyd, Jone H., Gianni De Nicolo, and Abu M. Jalal. 2006. Bank Risk-Taking and Competition Revisited: New Theory and New Evidence. IMF Working Paper. WP/06/297. Washington, DC: International Monetary Fund. [Google Scholar]
  19. Breusch, Trevor S., and Adrian R. Pagan. 1979. A simple test for heteroscedasticity and random coefficient variation. Econometrica 47: 1287–94. [Google Scholar] [CrossRef]
  20. Central Bank of Jordan. 2025. Annual Statistical Bulletin—Branching of Jordanian and Foreign Licensed Banks. CBJ. Available online: https://www.cbj.gov.jo/En/List/Annual_Statistical_Bulletin (accessed on 10 April 2026).
  21. Committee of Sponsoring Organizations of the Treadway Commission (COSO). 2017. Enterprise Risk Management—Integrating with Strategy and Performance. Durham: COSO. Available online: https://www.coso.org/erm-framework (accessed on 16 April 2026).
  22. De Haan, Jakob, and Razvan Vlahu. 2016. Corporate governance of banks: A survey. Journal of Economic Surveys 30: 228–77. [Google Scholar]
  23. DiMaggio, Paul J., and Walter W. Powell. 1983. The iron cage revisited: Institutional isomorphism and collective rationality in organizational fields. American Sociological Review 48: 147–60. [Google Scholar] [CrossRef]
  24. Eckles, David. L., Robert E. Hoyt, and Steve M. Miller. 2014. The impact of enterprise risk management on the marginal cost of reducing risk: Evidence from the insurance industry. Journal of Banking & Finance 43: 247–61. [Google Scholar] [CrossRef]
  25. Hausman, Jerry. A. 1978. Specification tests in econometrics. Econometrica 46: 1251–71. [Google Scholar] [CrossRef]
  26. Hoyt, Robert E., and Andre P. Liebenberg. 2011. The value of enterprise risk management. Journal of Risk and Insurance 78: 795–822. [Google Scholar] [CrossRef]
  27. Hunjra, Ahmed I., Qasim Zureigat, Tahar Tayachi, and Rashid Mehmood. 2020. Impact of non-interest income and revenue concentration on bank risk in South Asia. Banks and Bank Systems 15: 15–25. [Google Scholar] [CrossRef]
  28. Idayani, Rahma W., Reny Nadlifatin, Apol P. Subriadi, and Ma J. J. Gumasing. 2024. A comprehensive review on how cyber risk will affect the use of FinTech. Procedia Computer Science 234: 1356–63. [Google Scholar] [CrossRef]
  29. Ilmudeen, Aboobucker, Yukun Bao, and Peilin Zhang. 2023. Investigating the mediating effect of business-IT alignment between management of IT investment and firm performance. Information Systems Management 40: 208–28. [Google Scholar]
  30. Irsheid, Anas, Ahmad Murad, Mohammad AlNajdawi, and Abdullah Qusef. 2022. Information security risk management models for cloud hosted systems: A comparative study. Procedia Computer Science 204: 205–17. [Google Scholar] [CrossRef]
  31. ISACA. 2019. COBIT 2019 Framework: Introduction and Methodology. Schaumburg: ISACA. [Google Scholar]
  32. (ISO/IEC) International Organization for Standardization and International Electrotechnical Commission. 2022. ISO/IEC 27001:2022 Information Security, Cybersecurity and Privacy Protection—Information Security Management Systems—Requirements. Geneva: ISO. Available online: https://www.iso.org/standard/27001?s=aaa&utm_source=chatgpt.com (accessed on 16 April 2026).
  33. Jaime, Laura, and João Barata. 2023. How can FLOSS support COBIT 2019? Coverage analysis and a conceptual framework. Procedia Computer Science 219: 680–87. [Google Scholar] [CrossRef]
  34. Javed, Maryam, Kashif Mehmood, Abdul Ghafoor, and Asma Parveen. 2024. Board structure and risk-taking behavior: Evidence from the financial sector of Pakistan. Corporate Governance 24: 1060–82. [Google Scholar] [CrossRef]
  35. Jensen, Michael C., and William H. Meckling. 1976. Theory of the firm: Managerial behavior, agency costs and ownership structure. Journal of Financial Economics 3: 305–60. [Google Scholar] [CrossRef]
  36. Karabacak, Bilge, Sevgi O. Yildirim, and Nazife Baykal. 2016. A vulnerability-driven cyber security maturity model for measuring national critical infrastructure protection preparedness. International Journal of Critical Infrastructure Protection 15: 47–59. [Google Scholar] [CrossRef]
  37. Khatatbeh, Ibrahim N., Mohammad Tayeh, Abdelrazaq F. Freihat, and Raneem G. Aldeki. 2025. ESG and bank stability in Gulf Cooperation Council countries: Empirical evidence from listed commercial banks. South African Journal of Economic and Management Sciences 28: 6287. [Google Scholar] [CrossRef]
  38. Kim, Jong Hae. 2019. Multicollinearity and Misleading Statistical Results. Korean Journal of Anesthesiology 72: 558–69. [Google Scholar] [CrossRef] [PubMed]
  39. Kitten, Teacy. 2013. Card Fraud Scheme: The Breached Victims. BankInfoSecurity. Available online: https://www.bankinfosecurity.co.uk/card-fraud-scheme-breached-victims-a-5941 (accessed on 1 April 2026).
  40. Kleibergen, Frank, and Richard Paap. 2006. Generalized reduced rank tests using the singular value decomposition. Journal of Econometrics 133: 97–126. [Google Scholar] [CrossRef]
  41. Kubilay, Burak, and Baris Celiktas. 2025. Relationships among organizational-level maturities in artificial intelligence, cybersecurity, and digital transformation. IEEE Access 13: 88399–411. [Google Scholar] [CrossRef]
  42. Laeven, Luc, and Fabian Valencia. 2018. Systemic Banking Crises Revisited. IMF Working Paper/IMF Economic Review. Washington, DC: International Monetary Fund. [Google Scholar]
  43. Larabi, Chouayb. 2025. Linking intangible resources to predict firm performance through technology innovation and strategic flexibility. Journal of Strategy and Management, 1–27. [Google Scholar] [CrossRef]
  44. Li, Xiping, David Tripe, and Christopher Malone. 2017. Measuring bank risk: An exploration of Z-score. SSRN Electronic Journal, 2823946. [Google Scholar] [CrossRef]
  45. Loughran, Tim, and Bill McDonald. 2016. Textual analysis in accounting and finance: A survey. Journal of Accounting Research 54: 1187–230. [Google Scholar] [CrossRef]
  46. Neto, Joao S., Rafael Almeida, Pedro Pinto, and Miguel M. Silva. 2018. A COBIT 5 PAM update compliant with ISO/IEC 330xx family. ISACA Journal 1: 1–5. [Google Scholar]
  47. Nikbakht, Mohammad, Saeed Rouhani, and Vahideh Mojtahed. 2025. A novel ranking model for IT security controls through COBIT and MCDM. Records Management Journal 35: 251–76. [Google Scholar]
  48. (NIST) National Institute of Standards and Technology. 2024. The NIST Cybersecurity Framework (CSF) 2.0; NIST Cybersecurity White Paper (CSWP) NIST CSWP 29. Gaithersburg: National Institute of Standards and Technology. [CrossRef]
  49. Ofori, Benjamin S., Abigail Padi, and Alhassan Musah. 2025. Corporate governance effectiveness and operational risk of banks. Discover Global Society 3: 23. [Google Scholar] [CrossRef]
  50. Okunyte, Paulina. 2025. Ransomware gang claims to hit Jordan Kuwait Bank. Cybernews. Available online: https://cybernews.com/security/jordan-kuwait-bank-data-breach-everest-ransomware/ (accessed on 1 April 2026).
  51. Pagach, Donald, and Richard Warr. 2011. The characteristics of firms that hire chief risk officers. Journal of Risk and Insurance 78: 185–211. [Google Scholar]
  52. Qi, Bing., Mona Marie, Ashraf S. Abdelwahed, Ibrahim N. Khatatbeh, Mohamed Omran, and Ahmad A. S. Fayad. 2023. Bank Risk Literature (1978–2022): A Bibliometric Analysis and Research Front Mapping. Sustainability 15: 4508. [Google Scholar] [CrossRef]
  53. Rashid, Abdul, Muhammad Akmal, and Syed M. A. R. Shah. 2024. Corporate governance and risk management in Islamic and conventional financial institutions. Journal of Islamic Accounting and Business Research 15: 466–98. [Google Scholar]
  54. Saidat, Zaid, Abeer Kassab, and John Kasem. 2024. The impact of COBIT 2019 on the effectiveness of implementing cyber governance in Jordanian commercial banks. In International Conference on Technology and Innovation Management. Cham: Springer, pp. 243–50. [Google Scholar]
  55. Saidi, Nasser. 2004. Corporate Governance in MENA Countries: Improving Transparency and Disclosure. Beirut: Third MENA Regional Corporate Governance Forum. [Google Scholar]
  56. Sakawa, Hideaki, Naoki Watanabel, Shohei Yamauchi, and Runxi Liu. 2023. The effect of Tobin’s q on investment in a bank-based financial system: Evidence from Japan. Pacific-Basin Finance Journal 77: 101880. [Google Scholar]
  57. Senave, Elseline, Mieke J. Jans, and Rajendra P. Srivastava. 2023. The application of text mining in accounting. International Journal of Accounting Information Systems 50: 100624. [Google Scholar] [CrossRef]
  58. Siagian, Dewi P., Betty Purwandari, and Ni W. Trisnawaty. 2025. Enhancing IT maturity with the COBIT 2019 framework: A case study. Indonesian Journal of Computer Science 14. [Google Scholar] [CrossRef]
  59. Smits, Daniël, and Jos Van Hillegersberg. 2018. The continuing mismatch between IT governance maturity theory and practice: A new approach. Procedia Computer Science 138: 549–60. [Google Scholar] [CrossRef]
  60. Stiroh, Kevin J. 2004. Diversification in banking: Is noninterest income the answer? Journal of Money, Credit and Banking 36: 853–82. [Google Scholar] [CrossRef]
  61. Stock, James H., and Motohiro Yogo. 2005. Testing for weak instruments in linear IV regression. In Identification and Inference for Econometric Models. Cambridge: Cambridge University Press, pp. 80–108. [Google Scholar]
  62. Tangka, George M. W., and Erienika Lompoliu. 2025. Optimizing IT governance: A COBIT 2019-based analysis of design factors. MALCOM 5: 699–710. [Google Scholar]
  63. Toussaint, Marion., Sylvere Krima, and Herve Panetto. 2024. Industry 4.0 data security: A cybersecurity frameworks review. Journal of Industrial Information Integration 39: 100604. [Google Scholar] [CrossRef]
  64. Vuko, Tina, Sergeja Slapničar, Čular Marko, and Matej Drašček. 2025. Key drivers of cybersecurity audit effectiveness: A neo-institutional perspective. International Journal of Auditing 29: 188–206. [Google Scholar]
  65. Wei, Lu, Haozhe Jing, Jie Huang, Yuqi Deng, and Zhongbo Jing. 2023. Do textual risk disclosures reveal corporate risk? Evidence from US fintech corporations. Economic Modelling 127: 106461. [Google Scholar] [CrossRef]
  66. Weill, Peter, and Jeanne W. Ross. 2004. IT Governance: How Top Performers Manage IT Decision Rights for Superior Results. Boston: Harvard Business School Press. [Google Scholar]
  67. Wooldridge, Jeffrey M. 2010. Econometric Analysis of Cross Section and Panel Data, 2nd ed. Cambridge: MIT Press. [Google Scholar]
Figure 1. Three-phase diffusion of COBIT adoption across the sampled banks, 2014–2023.
Figure 1. Three-phase diffusion of COBIT adoption across the sampled banks, 2014–2023.
Risks 14 00138 g001
Figure 2. Annual and cumulative COBIT keyword frequency across the sampled banks, 2014–2023. Notes: Figures are based on the manually coded adoption and keyword data described in Section 3.3. Inter-year values between the anchor points reported in the text are interpolated for illustration of the diffusion path.
Figure 2. Annual and cumulative COBIT keyword frequency across the sampled banks, 2014–2023. Notes: Figures are based on the manually coded adoption and keyword data described in Section 3.3. Inter-year values between the anchor points reported in the text are interpolated for illustration of the diffusion path.
Risks 14 00138 g002
Table 1. Comparison of COBIT with related governance, security and risk frameworks.
Table 1. Comparison of COBIT with related governance, security and risk frameworks.
FrameworkPrimary Scope/ObjectiveStrengthsLimitation for a Stability Study
COBIT (4.1/5/2019)Enterprise governance of IT; links board objectives to IT processes, performance and riskGovernance–management integration; risk objectives (EDM03, APO12); maps to other standardsBreadth means disclosure may not reveal implementation depth
ISO/IEC 27001Information-security management system (certifiable)Auditable controls; international recognitionSecurity-only; silent on enterprise governance and value delivery
ITILIT service management and operationsOperational efficiency; service qualityProcess/operations focus; limited governance and risk linkage
NIST CSFCybersecurity risk management (Identify–Protect–Detect–Respond–Recover)Strong technical risk taxonomy; flexibleCyber-centric; not a governance architecture
COSO ERMEnterprise risk management across the firmHolistic risk view; board oversightNot IT-specific; weak on IT-process control
Notes: The frameworks are complementary rather than mutually exclusive; many banks combine COBIT (governance) with ISO/IEC 27001 (security) and ITIL (operations). COBIT is selected here because the governance–stability mechanism operates at the board-to-process level that COBIT uniquely spans.
Table 2. Variable definitions and measurement.
Table 2. Variable definitions and measurement.
Variable CodeNameDefinition/MeasurementReferences
Dependent variable
LnZSCOREBank financial stability Natural logarithm of Z-score, calculated following Li et al. (2017)Beck et al. (2013); Li et al. (2017); Laeven and Valencia (2018)
Independent variable
COBITFCOBIT framework disclosure intensityFrequency of COBIT-related words in annual reportsWei et al. (2023); Senave et al. (2023); Nikbakht et al. (2025)
COBITDCOBIT adoption indicatorDummy variable that takes that value of 1 if COBIT framework is reported, and 0 otherwiseAl-Gasaymeh et al. (2023); Saidat et al. (2024); Almubaydeen et al. (2025)
Control variables
LeverageBank leverage ratioLeverage is calculated as total liabilities/total assetsBeck et al. (2013); Acosta-Smith et al. (2024)
SizeBank sizeNatural logarithm of total assetsBeck et al. (2013)
NIMNet interest margin(Interest income−interest expense)/total assetsHunjra et al. (2020); Sakawa et al. (2023)
LiquidityBank liquidity levelNet loans/total assetsAl-Habashneh et al. (2023)
DivIncome diversificationNon-interest income/total revenuesStiroh (2004); Hunjra et al. (2020)
TobinQTobin’s Q(Market value of equity + book value of liabilities)/total assetsSakawa et al. (2023); Rashid et al. (2024)
GDPGross Domestic Product GDP per capita (PPP, constant 2021 international $)Laeven and Valencia (2018); Beck et al. (2013)
INFInflation rateAnnual change in consumer price indexBeck et al. (2013)
COVIDCOVID-19 period dummyDummy variable that takes the value of 1 for years 2020–2022, and 0 otherwiseAl-Habashneh et al. (2023)
Table 3. Descriptive statistics.
Table 3. Descriptive statistics.
VariableObsMeanStd. Dev.MinMax
LnZSCORE1203.690.872.166.42
COBITF1204.407.55039
COBITD1200.650.47901
Leverage12086.692.55381.2091.63
Size1209.480.3788.9110.46
NIM1203.730.7412.315.833
Liquidity1200.5090.0610.3370.616
Div1200.2370.0550.1550.447
TobinQ1200.9830.0510.9041.188
GDP1209400.5348.548970.210305.7
INF1202.0042.003−0.8774.462
COVID1200.300.4601
Table 4. Pairwise correlations.
Table 4. Pairwise correlations.
(1)(2)(3)(4)(5)(6)(7)(8)(9)(10)(11)(12)
(1) LnZSCORE1.000
(2) COBITF−0.0501.000
(3) COBITD−0.0720.429 *1.000
(4) Leverage−0.224 *0.461 *0.1141.000
(5) Size−0.0560.0250.313 *0.0461.000
(6) NIM0.311 *−0.190 *−0.109−0.442 *−0.1591.000
(7) Liquidity0.0170.280 *0.207 *−0.201 *−0.1650.221 *1.000
(8) Div−0.152−0.270 *−0.088−0.407 *−0.002−0.1080.0291.000
(9) TobinQ0.460 *−0.191 *−0.185 *0.0110.271 *0.242 *−0.322 *−0.1701.000
(10) GDP0.186 *−0.284 *−0.562 *−0.140−0.0940.214 *−0.263 *0.1060.282 *1.000
(11) INF−0.1450.1700.239 *0.1070.087−0.1110.160−0.018−0.0830.1161.000
(12) COVID−0.220 *0.272 *0.290*0.182 *0.093−0.197 *0.081−0.183 *−0.262 *−0.562 *−0.0111.000
Notes: * indicates significance at the 0.05 level. Variable definitions are given in Table 2.
Table 5. Results of VIF.
Table 5. Results of VIF.
VariablesGDPCOBITDLeverageCOBITFNIMLiquidityCOVIDTobinQDivINFSize
VIF2.2532.1882.0941.8651.7911.6471.5551.5471.4431.4061.384
Table 6. Diagnostic tests.
Table 6. Diagnostic tests.
Testp-ValueConclusion
Lagrange Multiplier test (Breusch–Pagan)6.956 × 10−7Random effects preferred over pooled OLS
Hausman specification test0.6976Random-effects specification retained over fixed effects
Breusch–Godfrey/Wooldridge serial correlation test0.0079Serial correlation detected
Heteroskedasticity test (Breusch–Pagan)0.8421No evidence of heteroskedastic
Table 7. Random-effects estimates—COBIT disclosure frequency (COBITF).
Table 7. Random-effects estimates—COBIT disclosure frequency (COBITF).
Dep. var.: LnZSCORE(1)(2)
COBITF0.0219 **0.0224 **
(0.011)(0.0106)
Leverage−0.132 *−0.1317 *
(0.0677)(0.0696)
Size−0.5406 *−0.541 *
(0.3214)(0.3049)
NIM0.12170.1082
(0.2252)(0.217)
Liquidity−1.6854−1.7285
(2.3735)(2.4588)
Div−3.8052 ***−3.9768 ***
(1.3094)(1.275)
TobinQ10.515 ***10.2351 ***
(0.9956)(1.0264)
GDP−0.0005
(0.0001)
INF−0.0116
(0.0363)
COVID0.0595
(0.2194)
Constant11.656211.4978
(7.9345)(8.1499)
Observations120120
Overall R20.370.36
Notes: ***, **, * represents statistical significance at the 1%, 5% and 10% level respectively. Standard errors are in the parentheses. Variable definitions in Table 2.
Table 8. Random-effects estimates—COBIT adoption dummy (COBITD).
Table 8. Random-effects estimates—COBIT adoption dummy (COBITD).
Dep. var.: LnZSCORE(3)(4)
COBITD0.4001 ***0.3452 ***
(0.0886)(0.0782)
Leverage−0.1259 *−0.1294 *
(0.0672)(0.0698)
Size−0.6757 **−0.7224 **
(0.2923)(0.28)
NIM0.05820.068
(0.2308)(0.2317)
Liquidity−1.1015−1.7942
(1.988)(2.1224)
Div−4.1301 ***−4.2169 ***
(1.4917)(1.4356)
TobinQ11.14 ***11.2378 ***
(0.9117)(0.8873)
GDP0.0001
(0.0001)
INF−0.0256
(0.0336)
COVID0.1012
(0.2042)
Constant9.446412.1461
(7.4681)(7.9536)
Observations120120
Overall R20.380.37
Notes: ***, **, * represents statistical significance at the 1%, 5% and 10% level respectively. Standard errors are in the parentheses. Variable definitions in Table 2.
Table 9. COBIT adoption and bank stability: 2SLS estimates.
Table 9. COBIT adoption and bank stability: 2SLS estimates.
Dep. var.: ln(Z-Score)(1) COBITF(2) COBITD
COBIT (instrumented)0.0231 **
(0.0112)
0.0080
(0.9180)
Leverage−0.0839 **
(0.0400)
−0.0448
(0.0450)
Size−0.2160
(0.1649)
−0.1813
(0.3753)
NIM0.0440
(0.1548)
0.0555
(0.2180)
Liquidity0.9715
(1.4978)
2.0337
(1.3665)
Div−2.0700
(1.4260)
−2.3517
(1.4577)
Tobin’s Q7.5558 ***
(1.2814)
7.1207 ***
(2.0891)
GDP−0.0031 ***
(0.0011)
−0.0032 ***
(0.0012)
INF0.0250
(0.0572)
0.0304
(0.0624)
COVID-19−0.9161 ***
(0.2778)
−0.9185 ***
(0.3161)
Constant33.8471 ***
(10.3421)
31.4435 ***
(10.3775)
Observations9696
Centred R20.3580.344
First-stage F51.45 ***2.15
Kleibergen–Paap rk Wald F51.4532.153
Hansen J (p-value)0.3340.330
Underidentification KP-LM (p)0.0010.100
Notes: ***, **, * represents statistical significance at the 1%, 5% and 10% level respectively. Standard errors are in the parentheses. Column (1) instruments COBITF with its first and second lags and peer_COBITF; column (2) instruments COBITD with its first lag and peer_COBITD. The Kleibergen–Paap rk Wald F (Kleibergen and Paap 2006) is compared with Stock and Yogo (2005) critical values. The Hansen J statistic tests instrument exogeneity.
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content.

Share and Cite

MDPI and ACS Style

Al-Tayan, R.; Khatatbeh, I.N.; Daradkah, D.; Shehadeh, M.; Alzawahreh, H. Does COBIT Framework Adoption Influence Banks’ Financial Stability? Evidence from an Emerging Country. Risks 2026, 14, 138. https://doi.org/10.3390/risks14060138

AMA Style

Al-Tayan R, Khatatbeh IN, Daradkah D, Shehadeh M, Alzawahreh H. Does COBIT Framework Adoption Influence Banks’ Financial Stability? Evidence from an Emerging Country. Risks. 2026; 14(6):138. https://doi.org/10.3390/risks14060138

Chicago/Turabian Style

Al-Tayan, Randa, Ibrahim N. Khatatbeh, Demeh Daradkah, Maha Shehadeh, and Hanan Alzawahreh. 2026. "Does COBIT Framework Adoption Influence Banks’ Financial Stability? Evidence from an Emerging Country" Risks 14, no. 6: 138. https://doi.org/10.3390/risks14060138

APA Style

Al-Tayan, R., Khatatbeh, I. N., Daradkah, D., Shehadeh, M., & Alzawahreh, H. (2026). Does COBIT Framework Adoption Influence Banks’ Financial Stability? Evidence from an Emerging Country. Risks, 14(6), 138. https://doi.org/10.3390/risks14060138

Note that from the first issue of 2016, this journal uses article numbers instead of page numbers. See further details here.

Article Metrics

Back to TopTop