{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,26]],"date-time":"2026-06-26T13:12:15Z","timestamp":1782479535808,"version":"3.54.5"},"reference-count":28,"publisher":"Emerald","issue":"3","license":[{"start":{"date-parts":[[2012,7,13]],"date-time":"2012-07-13T00:00:00Z","timestamp":1342137600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.emerald.com\/insight\/site-policies"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2012,7,13]]},"abstract":"<jats:sec><jats:title content-type=\"abstract-heading\">Purpose<\/jats:title><jats:p>The purpose of this paper is to form a new framework for preventing money laundering by mapping COBIT (Control for Information and Related Technology) processes to COSO (Committee of Sponsoring Organisation) components.<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-heading\">Design\/methodology\/approach<\/jats:title><jats:p>First, a new framework for preventing money laundering in banks is formed by mapping COBIT to COSO. Further, the potential of the mapped framework to comply with the Bank Secrecy Act requirements is analysed.<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-heading\">Findings<\/jats:title><jats:p>The mapped framework effectively supports all the activities of financial sectors through defining efficient information technology\u2010based processes and control methods. Information systems play a key role for financial sectors in producing financial statements, managing customer databases, detecting frauds, etc.<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-heading\">Research limitations\/implications<\/jats:title><jats:p>Case studies of banks of different sizes, and in different countries are needed. It is necessary to improve the mapped framework by considering Basel III regulations.<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-heading\">Practical implications<\/jats:title><jats:p>COBIT\u2010mapped\u2010COSO framework is useful for banks to fight money laundering. While adopting the new framework, an organisation should apply the best practices that suit its operations rather than all the control objectives.<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-heading\">Social implications<\/jats:title><jats:p>The new framework can help banks fight money laundering.<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-heading\">Originality\/value<\/jats:title><jats:p>For preventing money laundering through banks, a number of policies and intelligence systems are in place. However, there is no efficient framework that could guide banks to follow these policies and use information technologies. This paper proposes a new framework to target these gaps.<\/jats:p><\/jats:sec>","DOI":"10.1108\/09685221211247280","type":"journal-article","created":{"date-parts":[[2014,1,24]],"date-time":"2014-01-24T09:09:59Z","timestamp":1390554599000},"page":"170-183","source":"Crossref","is-referenced-by-count":16,"title":["A framework for preventing money laundering in banks"],"prefix":"10.1108","volume":"20","author":[{"given":"Vandana","family":"Pramod","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jinghua","family":"Li","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ping","family":"Gao","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"140","reference":[{"key":"key2022012520480418100_b1","doi-asserted-by":"crossref","unstructured":"Abu\u2010Musa, A.A. (2006), \u201cPerceived security threats of computerized accounting information systems in the Egyptian banking industry\u201d, Journal of Information Systems, Vol. 20 No. 1, pp. 187\u2010203.","DOI":"10.2308\/jis.2006.20.1.187"},{"key":"key2022012520480418100_b2","doi-asserted-by":"crossref","unstructured":"Abu\u2010Musa, A.A. (2009), \u201cExploring the importance and implementation of COBIT processes in Saudi organizations\u201d, Information Management and Computer Security, Vol. 17 No. 2, pp. 73\u201095.","DOI":"10.1108\/09685220910963974"},{"key":"key2022012520480418100_b3","doi-asserted-by":"crossref","unstructured":"Angell, I.O. and Demetis, D.S. (2005), \u201cSystems thinking about anti\u2010money laundering: considering the Greek case\u201d, Journal of Money Laundering Control, Vol. 8 No. 3, pp. 271\u201084.","DOI":"10.1108\/13685200510620993"},{"key":"key2022012520480418100_b4","unstructured":"Barve, J. (2010), \u201cCOBIT for IT risk management in a bank \u2013 a case study\u201d, COBIT Focus, Vol. 3, July."},{"key":"key2022012520480418100_b5","unstructured":"Basel Committee on Banking Supervision (2004), Basel II: International Convergence of Capital Measurement and Capital Standards \u2013 A Revised Framework, June, available at: www.bis.org\/publ\/bcbs107.htm."},{"key":"key2022012520480418100_b6","unstructured":"Basel Committee on Banking Supervision (2010), Basel III: International Regulatory Framework for Banks, available at: www.bis.org\/bcbs\/basel3.htm."},{"key":"key2022012520480418100_b7","doi-asserted-by":"crossref","unstructured":"Brotby, K. (2009), Information Security Governance: A Practical Development and Implementation Approach, Wiley, New York, NY.","DOI":"10.1002\/9780470476017"},{"key":"key2022012520480418100_b8","doi-asserted-by":"crossref","unstructured":"Buchanan, B. (2004), \u201cMoney laundering \u2013 a global obstacle\u201d, Research in International Business and Finance, Vol. 18 No. 1, pp. 115\u201027.","DOI":"10.1016\/j.ribaf.2004.02.001"},{"key":"key2022012520480418100_b9","unstructured":"Chan, S. (2004), \u201cMapping COSO and COBIT for Sarbanes\u2010Oxley compliance\u201d, IT Audit, Vol. 7, October."},{"key":"key2022012520480418100_b10","doi-asserted-by":"crossref","unstructured":"Ciborra, C. (2006), \u201cImbrication of representations: risk and digital technologies\u201d, Journal of Management Studies, Vol. 43 No. 6, pp. 1339\u201056.","DOI":"10.1111\/j.1467-6486.2006.00647.x"},{"key":"key2022012520480418100_b11","unstructured":"Colbert, J. and Bowen, P. (1996), \u201cA comparison of internal controls: COBIT, SAC, COSO and SAS 55\/78\u201d, IS Audit & Control Journal, Vol. 4, pp. 26\u201035."},{"key":"key2022012520480418100_b12","unstructured":"COSO (1994), Internal Control \u2013 Integrated Framework, COSO, San Jose, CA."},{"key":"key2022012520480418100_b13","doi-asserted-by":"crossref","unstructured":"Doucet, M.S. and Doucet, T.A. (2003), \u201cControl and auditing\u201d, Encyclopaedia of Information Systems, Vol. 1, pp. 287\u2010305.","DOI":"10.1016\/B0-12-227240-4\/00019-8"},{"key":"key2022012520480418100_b14","doi-asserted-by":"crossref","unstructured":"Eloff, M.M. and Solms, V.S.H. (2000), \u201cInformation security management: a hierarchical framework for various approaches\u201d, Journal of Computers and Security, Vol. 19 No. 3, pp. 243\u201056.","DOI":"10.1016\/S0167-4048(00)88613-7"},{"key":"key2022012520480418100_b15","unstructured":"FFIEC (2010), Bank Secrecy Act\/Anti\u2010Money Laundering Examination Manual, Federal Financial Institutions Examination Council, Washington, DC."},{"key":"key2022012520480418100_b16","unstructured":"ITGI (2007), COBIT 4.1: Framework, Control Objectives, Management Guidance, Maturity Models, Information System and Audit Association, Chicago, IL, available at: www.isaca.org\/Knowledge\u2010Center\/cobit\/Documents\/COBIT4.pdf."},{"key":"key2022012520480418100_b17","doi-asserted-by":"crossref","unstructured":"Johnston, B.R. and Carrington, I. (2006), \u201cProtecting the financial system from abuse: challenges to banks in implementing AML\/CFT standards\u201d, Journal of Money Laundering Control, Vol. 9 No. 1, pp. 48\u201061.","DOI":"10.1108\/13685200610645210"},{"key":"key2022012520480418100_b18","doi-asserted-by":"crossref","unstructured":"Kuljis, J., Macedie, R.D. and Paul, R.J. (1998), \u201cInformation gathering problems in multinational banking\u201d, Journal of Strategic Information Systems, Vol. 7, pp. 233\u201045.","DOI":"10.1016\/S0963-8687(98)00031-6"},{"key":"key2022012520480418100_b19","unstructured":"Lohrke, C.A. and Hunton, J.E. (2002), \u201cNew opportunities for information systems auditors: linking SysTrust to COBIT\u201d, Information Systems Control Journal, Vol. 3, pp. 45\u20108."},{"key":"key2022012520480418100_b20","doi-asserted-by":"crossref","unstructured":"Luthy, D. and Karen, F. (2006), \u201cLaws and regulations affecting information management and frameworks for assessing compliance\u201d, Information Management and Computer Security, Vol. 14 No. 2, pp. 155\u201066.","DOI":"10.1108\/09685220610655898"},{"key":"key2022012520480418100_b21","unstructured":"Olasanmi, O. (2010), \u201cComputer crimes and counter measures in the Nigerian banking sector\u201d, Journal of Internet Banking & Commerce, Vol. 15 No. 1, pp. 1\u201010."},{"key":"key2022012520480418100_b22","unstructured":"Qualys (2009), Using Qualys Guard to Meet SOX Compliance and IT Controls, Report, Qualys Inc., Redwood City, CA."},{"key":"key2022012520480418100_b23","doi-asserted-by":"crossref","unstructured":"Solms, B.V. (2005), \u201cInformation security governance: COBI or ISO 17799 or both?\u201d, Journal of Computer and Security, Vol. 24, pp. 91\u2010104.","DOI":"10.1016\/j.cose.2005.02.002"},{"key":"key2022012520480418100_b24","unstructured":"Tarantino, A. (2006), Managers Guide to Compliance: Sarbanes\u2010Oxley, COSO, ERM, COBIT, IFRS, BASEL II, OMB A\u2010123, ASX 10, OECD Principles, Turnbull Guidance, Best Practices, and Case Studies, Wiley, New York, NY."},{"key":"key2022012520480418100_b25","unstructured":"Trcek, D. (2006), Managing Information Systems Security and Privacy, Springer, Heidelberg."},{"key":"key2022012520480418100_b27","doi-asserted-by":"crossref","unstructured":"Vaithilingam, S. and Nair, M. (2007), \u201cFactors affecting money laundering: lesson for developing countries\u201d, Journal of Money Laundering Control, Vol. 10 No. 3, pp. 352\u201066.","DOI":"10.1108\/13685200710763506"},{"key":"key2022012520480418100_b26","unstructured":"Van Jaarsveld, I. (2004), \u201cFollowing the money across cyber highways: a herculean task or international challenge? Some thoughts on money laundering on the internet\u201d, South African Mercantile Journal, Vol. 16 No. 4, pp. 685\u2010702."},{"key":"key2022012520480418100_b28","doi-asserted-by":"crossref","unstructured":"Zdanowicz, J. (2004), \u201cDetecting money laundering and terrorist financing via data mining: using import\u2010export information to improve financial transaction security\u201d, Communications of the ACM, Vol. 47 No. 5, pp. 53\u20105.","DOI":"10.1145\/986213.986239"}],"container-title":["Information Management &amp; Computer Security"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/www.emeraldinsight.com\/doi\/full-xml\/10.1108\/09685221211247280","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/www.emerald.com\/insight\/content\/doi\/10.1108\/09685221211247280\/full\/xml","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/www.emerald.com\/insight\/content\/doi\/10.1108\/09685221211247280\/full\/html","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,7,25]],"date-time":"2025-07-25T00:09:25Z","timestamp":1753402165000},"score":1,"resource":{"primary":{"URL":"http:\/\/www.emerald.com\/ics\/article\/20\/3\/170-183\/181169"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2012,7,13]]},"references-count":28,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2012,7,13]]}},"alternative-id":["10.1108\/09685221211247280"],"URL":"https:\/\/doi.org\/10.1108\/09685221211247280","relation":{},"ISSN":["0968-5227"],"issn-type":[{"value":"0968-5227","type":"print"}],"subject":[],"published":{"date-parts":[[2012,7,13]]}}}