Institutionalizing Risk Management in the Public Sector: The Case of Greece

Abstract

This study explores the institutionalization of risk management practices within the Greek public sector, drawing on a national survey of 378 civil servants. Amid post-crisis governance reforms, Greece presents a compelling context to examine how risk-related processes are adopted and perceived across ministries and state organizations. While public sector risk management has garnered growing international interest, empirical studies remain scarce, especially in southern European administrations. We find limited maturity in formal risk procedures but an emerging awareness among middle- and upper-level officials. The findings contribute to the literature on public governance by highlighting the challenges of embedding risk management practices in hierarchical and legalistic administrative traditions.

Share and Cite:

Papadopoulos, T. (2025) Institutionalizing Risk Management in the Public Sector: The Case of Greece. Theoretical Economics Letters, 15, 1050-1070. doi: 10.4236/tel.2025.154058.

1. Introduction

Risk management has become an increasingly salient component of modern public governance, particularly following financial crises, health emergencies, and geopolitical uncertainty. Public organizations are being called upon to anticipate, mitigate, and manage complex risks while maintaining service delivery and fiscal prudence. However, public sector adoption of risk-oriented frameworks remains uneven, especially in states characterized by bureaucratic inertia or rigid legal-administrative traditions.

Over the past two decades, a significant number of OECD member countries have institutionalized comprehensive risk management frameworks within their public financial management systems. Notably, countries such as Australia, New Zealand, the United Kingdom, and Netherlands have enacted legislation mandating the disclosure and strategic management of fiscal risks by their Ministries of Finance. These frameworks often include the establishment of Independent Fiscal Institutions (IFIs) tasked with overseeing fiscal policy and ensuring transparency. The proliferation of such practices underscores a global trend towards enhancing fiscal resilience and accountability in the public sector.

Greece presents a compelling case within this context due to its recent efforts to modernize its public financial management amid economic challenges. The establishment of the Independent Authority for Public Revenue (IAPR) and the implementation of laws such as Law 4795/2021 and Law 5013/2023 signify steps towards aligning with OECD best practices. However, the unique administrative culture and historical fiscal issues in Greece pose distinct challenges to the effective institutionalization of risk management. Law 4795/2021 introduced a structured framework for internal control systems in public sector entities, making risk assessment and management a mandatory component of administrative processes. Law 5013/2023 further advanced this agenda by embedding risk management into the broader public financial management system, explicitly linking it to strategic planning, transparency obligations, and compliance monitoring.

This study’s findings offer valuable insights for practitioners and stakeholders by highlighting the practical implications of adopting risk management frameworks in a complex governance environment. Furthermore, Greece’s experience serves as a pertinent example for other OECD countries navigating similar reforms, emphasizing the importance of contextual factors in the successful implementation of risk management practices.

This paper investigates risk management diffusion in the Greek public sector, offering empirical evidence from a broad-based national survey. This study makes three key contributions. First, it extends the literature on public risk governance by providing rare empirical evidence from a Southern European, post-crisis state—a context underrepresented in international comparative research. Second, it captures the perceptions of civil servants across levels of authority, educational backgrounds, and institutional types, enabling a nuanced understanding of organizational readiness and resistance. Third, it delivers actionable insights for policymakers, international organizations (e.g., OECD, IMF), and reform leaders seeking to foster administrative capacity for risk management in complex bureaucracies. The innovation of this study lies in its ability to document a live institutional transformation—where risk governance is not yet fully embedded, but actively evolving—offering a forward-looking view of reform processes in practice. Greece, in this sense, becomes both a critical case and a mirror for other OECD states navigating the tension between policy ambition and administrative reality.

2. Literature Review

Risk management in the public domain has received growing scholarly attention, reflecting its relevance to strategic control and organizational resilience (Power, 2007; Bhimani, 2009). Governments increasingly embed risk discourse in legislative, financial, and administrative functions (Black, 2005; Boin & Lodge, 2016), with higher education providing an early example of how risk-based regulation was institutionalized within public organizations (Huber, 2009). Nevertheless, scholarship highlights a persistent gap between formal frameworks and substantive practices (Kolisovas & Andrius, 2011; Palermo, 2014). Empirical work often focuses on Anglo-Saxon or Nordic systems, while Mediterranean contexts remain underexplored (Ahmeti & Vladi, 2017; Bracci et al., 2022). Evidence from Central and Eastern Europe also highlights case-based challenges in embedding risk management practices within public entities (Kapuscinska & Matejun, 2014). In Greece, recent reforms (e.g., Law 4795/2021; Law 5013/2023) have attempted to centralize and formalize risk responsibilities, but implementation challenges persist. Our study situates itself in this empirical lacuna.

To contextualize these developments analytically, this study draws from internationally recognized risk management frameworks, ISO 31000 and COSO Enterprise Risk Management (ERM), which provide structured, principles-based approaches to managing uncertainty and enhancing decision-making (ISO, 2018). ISO 31000 emphasizes integration, accountability, and continual improvement across all levels of an organization, aligning risk practices with governance (Andersen, 2016), strategy, and performance (Lark, 2015). COSO ERM (COSO, 2017), in turn, promotes a holistic, integrated approach to risk that aligns with internal control systems and emphasizes value creation, strategic objectives, and organizational culture. Academic reviews, however, caution that despite its promise, ERM research reveals both conceptual fragmentation and unresolved tensions (Bromiley et al., 2015). These frameworks offer conceptual tools for distinguishing between formal, compliance-driven risk routines and embedded, governance-oriented practices. Recent contributions also underline the need to integrate risk management into broader management control systems, offering practical lessons for public sector managers (Rana, Wickramasinghe, & Bracci, 2019). Similar integrative approaches have been noted in private-sector contexts such as supply chain management, where ERM has been reviewed as a means of managing interdependent risks (Olson & Dash Wu, 2010). As such, they serve as useful lenses for interpreting the maturity, fragmentation, and institutionalization patterns identified in our empirical findings.

Despite the growing international focus on public sector risk management, the academic literature remains disproportionately centered on Anglo-Saxon and Northern European administrative contexts, where governance structures tend to be more performance-oriented and technocratically driven. Even within Nordic countries, adoption at the local government level has been uneven and shaped by contextual administrative traditions (Oulasvirta & Anttiroiko, 2017). Empirical studies examining how risk management is interpreted, implemented, or resisted within Southern European or post-crisis settings are rare. Evidence from continental Europe shows that even in well-resourced administrations, risk analysis methods face significant implementation barriers (Rocher, 2011). In particular, Greece remains critically under-researched. Existing studies largely focus on fiscal oversight or broader administrative reform, while overlooking the institutional, cultural, and organizational dynamics that influence risk management uptake within the state apparatus. There is a notable absence of empirical work capturing how public officials, across ministries, agencies, and revenue authorities, perceive and engage with risk-oriented practices.

This study addresses that gap by providing one of the first comprehensive, data-driven examinations of risk management institutionalization within the Greek public sector. By anchoring its analysis in ISO 31000 and COSO ERM (COSO, 2017), it contributes original insights into national policy debates and enables cross-jurisdictional comparisons relevant to the broader field of comparative public administration and risk governance.

3. Theoretical Framework and Research Setting

This study draws conceptually from institutional theory and the literature on risk society (Beck, 1992). Public organizations do not adopt innovations solely due to efficiency pressures, but also in response to institutional isomorphism, legitimacy concerns, and policy diffusion (DiMaggio & Powell, 1983; Power, 2007). Contingency-based perspectives further highlight that the design and operation of risk management systems are highly dependent on organizational and contextual factors (Woods, 2009). Risk logics in late modernity further emphasize reputational concerns as a driving force behind organizational adoption of governance frameworks (Power et al., 2009). Beck’s (1992) notion of the “risk society” is particularly relevant to post-crisis Greece, where the accumulation of fiscal, social, and institutional vulnerabilities has heightened the salience of anticipatory governance. In this context, risk management becomes not merely a technical or compliance exercise, but a strategic response to the pervasive uncertainties and systemic risks characteristic of a society emerging from prolonged economic and administrative upheaval.

Greece offers a critical and revealing case in the study of public sector risk governance, particularly in the aftermath of a prolonged period of fiscal austerity, externally imposed reform, and administrative restructuring. As a member of both the European Union and the OECD (2005, 2014), Greece has been subject to multilayered compliance demands, including stringent oversight by international creditors and the adoption of standardized governance frameworks. These external pressures, combined with internal demands for modernization, have catalyzed a unique reform trajectory, one that attempts to reconcile inherited legalistic, hierarchical public administration structures with contemporary expectations for strategic planning, transparency, and accountability. Yet, as prior scholarship reminds us, risk management frameworks are themselves fraught with uncertainty and ambiguity in their application (Vinnari & Skærbæk, 2014). The Hellenic Independent Authority for Public Revenue (AADE), established to insulate tax collection from political interference, has played a pivotal role in operationalizing these reforms. Alongside AADE, several ministries, particularly the Ministry of Finance, have begun to adopt risk management language and tools as part of broader efforts to build fiscal resilience and administrative coherence. Yet, the tension between institutional innovation and deeply rooted administrative norms presents ongoing challenges, making Greece a vital case for understanding the contingent nature of public sector transformation under constraint.

4. Methodology and Empirical Findings

We administered a structured questionnaire to 378 civil servants across various ministries, agencies, and public entities in Greece. The sample was stratified by gender, seniority, level of education, and institutional type. The survey assessed perceived maturity in risk procedures, existence of formal frameworks, organizational effectiveness, and training exposure. The analysis is primarily descriptive but offers granular insights into intra-organizational variation and interpretive patterns. Despite its limitations, this approach is appropriate for exploratory inquiries in under-researched administrative contexts.

The survey instrument consisted of a structured questionnaire with predominantly closed-ended questions designed to capture respondents’ perceptions and experiences. Most attitudinal and evaluative items employed 5-point Likert-type scales (ranging from “not at all” to “to a great extent” or from “insufficient” to “very high”), allowing for the quantification of subjective assessments across key domains such as strategic, operational, financial, environmental, and reputational risk management. Demographic and organizational profile questions were also included to enable cross-tabulation and comparative analysis.

To capture domestic experience, a field survey was conducted (questionnaire design, completion, processing, and evaluation of findings). Initially, the sample characteristics are illustrated through Simple Distribution Analysis. Subsequently, gender and the extent to which the organization uses Risk Management procedures will be examined in conjunction with other variables.

The survey sample (n = 378) reflects the demographic and structural composition of Greece’s public sector. Women (63%) outnumber men, reflecting national employment trends where men prefer freelance professions offering higher but riskier returns. The demographic and organizational characteristics of the survey respondents are presented in Tables 1-11.

Most respondents are aged 41 - 50, with one-third having over 20 years of service, consistent with hiring freezes during the memorandum period. While 44% have spent under five years in their current organization, mobility across entities appears more common than often assumed. Educational attainment is high: nearly seven in ten hold postgraduate degrees, including 7% with doctorates, and 7.4% are graduates of the National School of Public Administration (ESDDA). Organizationally, over half work in ministries, with most employed in entities exceeding 500 staff, and nearly one-third occupy supervisory or directorial roles. These characteristics position respondents to provide informed assessments of their organizations’ risk practices.

Table 1. The gender of the respondents.

Sex

Man

142

37.6

Wife

236

62.4

Total

378

100.0

Table 2. The ages of the respondents.

Frequency

%

Cumulative distribution

Ages

<35

22

5.8

5.8

36 - 40

48

12.7

18.5

41 - 45

88

23.3

41.8

46 - 50

96

25.4

67.2

51 - 55

68

18.0

85.2

56 - 60

32

8.5

93.7

>61

24

6.3

100.0

Total

378

100.0

Table 3. Period of employment in the institution.

Years

Frequency

%

Cumulative distribution

Employment interval

<5 years

52

13.8

13.8

6 - 10 years

42

11.1

24.9

11 - 15 years

56

14.8

39.7

16 - 20 years

92

24.3

64.0

>20 years

136

36.0

100.0

Total

378

100.0

Table 4. Employment time in the service you are in.

Frequency

%

Cumulative distribution

Time in current service

<5 years

166

43.9

43.9

6 - 10 years

82

21.7

65.6

11 - 15 years

50

13.2

78.8

16 - 20 years

36

9.5

88.4

>20 years

44

11.6

100.0

Total

378

100.0

Table 5. Previous management experience.

Years

Frequency

%

Cumulative distribution

Management experience

<2

248

65.6

65.6

3 - 4

54

14.3

79.9

5 - 6

18

4.8

84.7

>7

58

15.3

100.0

Total

378

100.0

Table 6. Level of study.

Frequency

%

Cumulative distribution

Level of education

Higher education

90

23.8

23.8

Postgraduate studies

260

68.8

92.6

Doctoral degree

28

7.4

100.0

Total

378

100.0

Table 7. Studies at the ECHR.

Answers

Frequency

%

Cumulative distribution

Graduate of the USSR

No

350

92.6

92.6

Yes

28

7.4

100.0

Total

378

100.0

Table 8. Attending seminars or lectures on management.

Answers

Frequency

%

Cumulative distribution

Attending seminars

No

216

57.1

57.1

Yes

162

42.9

100.0

Total

378

100.0

Table 9. In which category of employment institution is he employed?

Bodies

Frequency

%

Cumulative distribution

Category of employment institution

N.P.D.D/N.P.I.D

50

13.2

13.2

Ministry

198

52.4

65.6

Public organization

106

28.0

93.7

Public enterprise

18

4.8

98.4

Region/local government

6

1.6

100.0

Total

378

100.0

Table 10. Position of responsibility.

Frequency

%

Cumulative distribution

Place

Employee

248

65.6

65.6

Supervisor/deputy

82

21.7

87.3

Director

48

12.7

100.0

Total

378

100.0

Table 11. Number of employees in the institution.

Frequency

%

Cumulative distribution

Number of employees

0 - 500

190

50.3

50.3

501 - 1000

22

5.8

56.1

1001 - 1500

12

3.2

59.3

1501 - 2000

14

3.7

63.0

More than 2000

140

37.0

100.0

Total

378

100.0

Findings highlight a gradual but uneven institutionalization of risk management practices across the Greek public sector. Fewer than half of the respondents report the existence of a formal risk management program, although awareness and procedural uptake are growing. Approximately 25% of participants rate risk procedures as highly embedded, while 38% consider them moderately developed. Notably, financial risk management emerges as the most advanced area, largely attributed to compliance-driven pressures, such as regulatory and audit requirements. In contrast, strategic and environmental risk management remains underdeveloped, indicating a gap in the governance-oriented approach, which emphasizes anticipatory, integrated, and leadership-led risk thinking.

This distinction between compliance-based risk management (focused on adhering to rules and controls) and governance-based risk management (focused on strategic foresight and institutional resilience) is essential for interpreting the findings. Empirical evidence from Northern Europe further illustrates how vernacular practices interact with formal systems, shaping the effectiveness of risk governance in public organizations (Carlsson-Wall et al., 2019).

Tables 12-23 present respondents’ evaluations of how risk factors are considered, the extent to which organizational objectives are achieved, and the perceived effectiveness of programming, overall performance, and specific domains of risk management, including strategic, financial, environmental, operational, and reputational dimensions. While over 70% of respondents noted some improvement, these advances appear incremental and largely procedural. As such, the broader institutionalization of risk management, as a core element of governance and decision-making, remains incomplete.

Table 12. Risk factors are taken into account by the competent department.

Frequency

%

Cumulative distribution

Evaluation

At all

48

12.7

12.7

Little

72

19.0

31.7

Moderate

122

32.3

64.0

Very

98

25.9

89.9

Too

38

10.1

100.0

Total

378

100.0

Table 13. Degree of achievement of objectives.

Degree of achievement

Frequency

%

Cumulative distribution

Evaluation

At all

4

1.1

1.1

Little

18

4.8

5.8

Moderate

114

30.2

36.0

Very

182

48.1

84.1

Too

60

15.9

100.0

Total

378

100.0

Table 14. Evaluation of the organization at the programming level.

Degree

Frequency

%

Cumulative distribution

Evaluation

Insufficient

6

1.6

1.6

Limited efficacy

24

6.3

7.9

Mediocre

154

40.7

48.7

Very good

158

41.8

90.5

Very good

36

9.5

100.0

Total

378

100.0

Table 15. Evaluation of an organization at the level of effectiveness.

Degree

Frequency

%

Cumulative distribution

Evaluation

Insufficient

4

1.1

1.1

Low efficiency

15

4.0

5.0

Mediocre

154

40.7

45.8

Very high

173

45.8

91.5

Too high

32

8.5

100.0

Total

378

100.0

Table 16. Does the agency have an official risk management program.

Frequency

%

Cumulative distribution

Answers

No

200

52.9

52.9

Yes

178

47.1

100.0

Total

378

100.0

Table 17. Degree to which the operator uses risk management procedures.

Degree

Frequency

%

Cumulative distribution

Evaluation

Zero

42

11.1

11.1

Low

78

20.6

31.7

Mediocre

144

38.1

69.8

Very large

94

24.9

94.7

Too big

20

5.3

100.0

Total

378

100.0

Table 18. Degree of development or improvement of management processes.

Degree

Frequency

%

Cumulative distribution

Evaluation

Zero

28

7.4

7.4

Low

58

15.3

22.8

Mediocre

160

42.3

65.1

Very large

116

30.7

95.8

Too big

16

4.2

100.0

Total

378

100.0

Table 19. Management assessment at the strategic risk level.

Degree

Frequency

%

Cumulative distribution

Evaluation

Nonexistent

34

9.0

9.0

Minimally successful

34

9.0

18.0

Moderate

206

54.5

72.5

Very successful

96

25.4

97.9

Very successful

8

2.1

100.0

Total

378

100.0

Table 20. Management assessment at the level of financial risk.

Degree

Frequency

%

Cumulative distribution

Evaluation

Nonexistent

28

7.4

7.4

Minimally successful

28

7.4

14.8

Moderate

188

49.7

64.6

Very successful

120

31.7

96.3

Very successful

14

3.7

100.0

Total

378

100.0

Table 21. Management assessment at the level of environmental risk.

Degree

Frequency

%

Cumulative distribution

Evaluation

Nonexistent

30

7.9

7.9

Minimally successful

86

22.8

30.7

Moderate

168

44.4

75.1

Very successful

80

21.2

96.3

Very successful

14

3.7

100.0

Total

378

100.0

Table 22. Management assessment at the operational risk level.

Degree

Frequency

%

Cumulative distribution

Evaluation

Nonexistent

28

7.4

7.4

Minimally successful

42

11.1

18.5

Moderate

186

49.2

67.7

Very successful

104

27.5

95.2

Very successful

18

4.8

100.0

Total

378

100.0

Table 23. Management assessment at the level of reputational risk.

Degree

Frequency

%

Cumulative distribution

Evaluation

Nonexistent

24

6.3

6.3

Minimally successful

44

11.6

18.0

Moderate

166

43.9

61.9

Very successful

128

33.9

95.8

Very successful

16

4.2

100.0

Total

378

100.0

Cross-tab analyses provide deeper insights into how risk management is perceived across different demographics and organizational contexts. Tables 24-39 report cross-tabulation analyses, illustrating how perceptions and use of risk management procedures vary across demographic characteristics, professional experience, education, training, organizational type, managerial responsibility, and institutional size.

Table 24. To what extent does your employer use risk management procedures? * What is your age? * What is your gender?

What is your gender?

What is your age?

Total

<35

36 - 40

41 - 45

46 - 50

51 - 55

56 - 60

>61

Man

To what extent does your employer use risk management procedures?

Zero

2

2

2

0

6

2

2

16

Low

4

2

2

10

6

2

0

26

Mediocre

0

8

18

14

2

4

6

52

Very large

4

6

4

10

6

4

6

40

Too big

0

0

2

4

0

0

2

8

Total

10

18

28

38

20

12

16

142

Wife

To what extent does your employer use risk management procedures?

Zero

0

2

12

2

6

4

0

26

Low

0

8

6

18

16

4

0

52

Mediocre

6

10

30

16

20

6

4

92

Very large

4

10

8

22

4

2

4

54

Too big

2

0

4

0

2

4

0

12

Total

12

30

60

58

48

20

8

236

Table 25. To what extent does your employer use risk management procedures? * What is the length of time you have been employed in a Public Institution? * What is your gender?

What is your gender?

What is the length of time you have been employed in a Public Body?

Total

<5 years

6 - 10 years

11 - 15 years

16 - 20 years

>20 years

Man

To what extent does your employer use risk management procedures?

Zero

6

0

0

4

6

16

Low

4

2

2

8

10

26

Mediocre

4

14

10

10

14

52

Very large

4

2

8

10

16

40

Too big

0

0

0

0

8

8

Total

18

18

20

32

54

142

Wife

To what extent does your employer use risk management procedures?

Zero

0

2

4

8

12

26

Low

6

2

8

20

16

52

Mediocre

12

14

14

20

32

92

Very large

12

4

8

12

18

54

Too big

4

2

2

0

4

12

Total

34

24

36

60

82

236

Table 26. To what extent does your employer use risk management procedures? * What is the length of time you are employed in the service/organization/business you are currently in? * What is your gender?

What is your gender?

What is the length of time you are employed in the service/organization/business you are currently in?

Total

<5 years

6 - 10 years

11 - 15 years

16 - 20 years

>20 years

Man

To what extent does your employer use risk management procedures?

Zero

10

0

2

2

2

16

Low

14

8

0

0

4

26

Mediocre

22

10

8

6

6

52

Very large

16

10

4

4

6

40

Too big

0

2

4

0

2

8

Total

62

30

18

12

20

142

Wife

To what extent does your employer use risk management procedures?

Zero

2

10

8

6

0

26

Low

24

16

4

6

2

52

Mediocre

44

20

10

4

14

92

Very large

26

4

10

8

6

54

Too big

8

2

0

0

2

12

Total

104

52

32

24

24

236

Table 27. To what extent does your employer use risk management procedures? * Have you had previous experience in a public or private body on issues related to risk management? If so, how many years? * What is your gender?

What is your gender?

Have you had previous experience in a public or private body on issues related to risk management? If so, how many years?

Total

<2

3 - 4

5 - 6

>7

Man

To what extent does your employer use risk management procedures?

Zero

10

2

0

4

16

Low

14

4

2

6

26

Mediocre

28

6

2

16

52

Very large

22

12

0

6

40

Too big

4

4

0

0

8

Total

78

28

4

32

142

Wife

To what extent does your employer use risk management procedures?

Zero

22

2

0

2

26

Low

42

2

4

4

52

Mediocre

58

12

6

16

92

Very large

42

6

4

2

54

Too big

6

4

0

2

12

Total

170

26

14

26

236

Table 28. To what extent does your employer use risk management procedures? * What is your level of study? * What is your gender?

What is your gender?

What is your level of study?

Total

Higher education

Postgraduate studies

Doctoral degree

Man

To what extent does your employer use risk management procedures?

Zero

4

10

2

16

Low

8

14

4

26

Mediocre

10

40

2

52

Very large

12

22

6

40

Too big

2

6

0

8

Total

36

92

14

142

Wife

To what extent does your employer use risk management procedures?

Zero

10

14

2

26

Low

12

36

4

52

Mediocre

24

62

6

92

Very large

8

46

0

54

Too big

0

10

2

12

Total

54

168

14

236

Table 29. To what extent does your employer use risk management procedures? * You are a graduate of the E.S.D.D.DA * What is your gender?

What is your gender?

You are a graduate of the E.S.D.DA

Total

No

Yes

Man

To what extent does your employer use risk management procedures?

Zero

14

2

16

Low

24

2

26

Mediocre

50

2

52

Very large

40

0

40

Too big

6

2

8

Total

134

8

142

Wife

To what extent does your employer use risk management procedures?

Zero

18

8

26

Low

48

4

52

Mediocre

88

4

92

Very large

50

4

54

Too big

12

0

12

Total

216

20

236

Table 30. To what extent does your employer use risk management procedures? * Have you attended seminars (or lectures) on risk management? * What is your gender?

What is your gender?

Have you attended seminars (or lectures) on risk management?

Total

No

Yes

Man

To what extent does your employer use risk management procedures?

Zero

12

4

16

Low

16

10

26

Mediocre

28

24

52

Very large

14

26

40

Too big

4

4

8

Total

74

68

142

Wife

To what extent does your employer use risk management procedures?

Zero

24

2

26

Low

34

18

52

Mediocre

56

36

92

Very large

24

30

54

Too big

4

8

12

Total

142

94

236

Table 31. To what extent does your employer use risk management procedures? * In which category of public sector do you employ? * What is your gender?

What is your gender?

In which category of public sector do you employ?

Total

N.P.D.D/N.P.I.D

Ministry

Public organization

Public enterprise

Region/local government

Man

To what extent does your employer use risk management procedures?

Zero

2

12

0

0

2

16

Low

2

8

14

2

0

26

Mediocre

6

32

10

4

0

52

Very large

10

20

8

2

0

40

Too big

0

4

2

2

0

8

Total

20

76

34

10

2

142

Wife

To what extent does your employer use risk management procedures?

Zero

0

20

6

0

0

26

Low

10

28

14

0

0

52

Mediocre

12

42

30

4

4

92

Very large

2

28

20

4

0

54

Too big

6

4

2

0

0

12

Total

30

122

72

8

4

236

Table 32. To what extent does your employer use risk management procedures? * Do you have a position of responsibility? * What is your gender?

What is your gender?

Do you have a position of responsibility?

Total

Employee

Supervisor/deputy

Director

Man

To what extent does your employer use risk management procedures?

Zero

8

8

0

16

Low

14

8

4

26

Mediocre

34

10

8

52

Very large

28

4

8

40

Too big

4

2

2

8

Total

88

32

22

142

Wife

To what extent does your employer use risk management procedures?

Zero

12

10

4

26

Low

40

8

4

52

Mediocre

72

14

6

92

Very large

32

12

10

54

Too big

4

6

2

12

Total

160

50

26

236

Table 33. To what extent does your employer use risk management procedures? * How many people work in your Employment Organization? * What is your gender?

What is your gender?

How many people work in your employment organisation?

Total

0 - 500

501 - 1000

1001 - 1500

1501 - 2000

More than 2000

Man

To what extent does your employer use risk management procedures?

Zero

6

0

4

4

2

16

Low

10

2

0

0

14

26

Mediocre

16

2

4

2

28

52

Very large

28

0

0

0

12

40

Too big

4

0

0

0

4

8

Total

64

4

8

6

60

142

Wife

To what extent does your employer use risk management procedures?

Zero

12

10

0

2

2

26

Low

36

2

2

2

10

52

Mediocre

50

2

0

2

38

92

Very large

24

4

2

2

22

54

Too big

4

0

0

0

8

12

Total

126

18

4

8

80

236

Table 34. To what extent do you think risk management processes are currently being developed or improved in your employment organisation? * What is the length of time you have been employed in a public institution? * What is your gender?

What is your gender?

What is the length of time you have been employed in a public body?

Total

<5 years

6 - 10 years

11 - 15 years

16 - 20 years

>20 years

Man

To what extent do you think risk management processes are currently being developed or improved in your employment organisation?

Zero

4

0

0

4

4

12

Low

4

2

2

4

8

20

Mediocre

4

10

8

8

22

52

Very large

6

6

10

16

16

54

Too big

0

0

0

0

4

4

Total

18

18

20

32

54

142

Wife

To what extent do you think risk management processes are currently being developed or improved in your employment organisation?

Zero

0

0

2

8

6

16

Low

4

0

8

14

12

38

Mediocre

12

18

16

26

36

108

Very large

16

4

8

12

22

62

Too big

2

2

2

0

6

12

Total

34

24

36

60

82

236

Table 35. To what extent do you think risk management processes are currently being developed or improved in your employment organisation? * What is the length of time you are employed in the service/organization/business you are currently in? * What is your gender?

What is your gender?

What is the length of time you are employed in the service/organization/business you are currently in?

Total

<5 years

6 - 10 years

11 - 15 years

16 - 20 years

>20 years

Man

To what extent do you think risk management processes are currently

being developed or improved in your employment organisation?

Zero

8

0

2

0

2

12

Low

4

6

4

4

2

20

Mediocre

30

10

0

4

8

52

Very large

20

14

10

4

6

54

Too big

0

0

2

0

2

4

Total

62

30

18

12

20

142

Wife

To what extent do you think risk management processes are currently being developed or improved in your employment organisation?

Zero

4

6

4

2

0

16

Low

18

8

6

6

0

38

Mediocre

40

34

12

8

14

108

Very large

34

2

10

8

8

62

Too big

8

2

0

0

2

12

Total

104

52

32

24

24

236

Table 36. To what extent do you think risk management processes are currently being developed or improved in your employment organisation? * Have you had previous experience in a public or private body on issues related to risk management? If so, how many years? * What is your gender?

What is your gender?

Have you had previous experience in a public or private body on issues related to risk management? If so, how many years?

Total

<2

3 - 4

5 - 6

>7

Man

To what extent do you think risk management processes are currently being developed or improved in your employment organisation?

Zero

10

0

0

2

12

Low

10

4

0

6

20

Mediocre

26

8

4

14

52

Very large

30

14

0

10

54

Too big

2

2

0

0

4

Total

78

28

4

32

142

Wife

To what extent do you think risk management processes are currently being developed or improved in your employment organisation?

Zero

14

0

0

2

16

Low

28

2

4

4

38

Mediocre

74

12

8

14

108

Very large

48

8

2

4

62

Too big

6

4

0

2

12

Total

170

26

14

26

236

Table 37. To what extent do you think risk management processes are currently being developed or improved in your employment organisation? * In which category of public sector do you employ? * What is your gender?

What is your gender?

In which category of public sector do you employ?

Total

N.P.D.D/ N.P.I.D

Ministry

Public organization

Public enterprise

Region/local government

Man

To what extent do you think risk management processes are currently being developed or improved in your employment organisation?

Zero

2

8

0

0

2

12

Low

2

10

8

0

0

20

Mediocre

8

26

14

4

0

52

Very large

8

30

12

4

0

54

Too big

0

2

0

2

0

4

Total

20

76

34

10

2

142

Wife

To what extent do you think risk management processes are currently being developed or improved in your employment organisation?

Zero

0

16

0

0

0

16

Low

4

24

8

0

2

38

Mediocre

16

50

36

4

2

108

Very large

6

26

26

4

0

62

Too big

4

6

2

0

0

12

Total

30

122

72

8

4

236

Table 38. To what extent do you think risk management processes are currently being developed or improved in your employment organisation? * Do you have a position of responsibility? * What is your gender?

What is your gender?

Do you have a position of responsibility?

Total

Employee

Supervisor/deputy

Director

Man

To what extent do you think risk management processes are currently being developed or improved in your employment organisation?

Zero

4

8

0

12

Low

14

2

4

20

Mediocre

32

14

6

52

Very large

36

8

10

54

Too big

2

0

2

4

Total

88

32

22

142

Wife

To what extent do you think risk management processes are currently being developed or improved in your employment organisation?

Zero

10

6

0

16

Low

24

8

6

38

Mediocre

86

16

6

108

Very large

36

14

12

62

Too big

4

6

2

12

Total

160

50

26

236

Gendered and experiential patterns emerge: men with over 20 years of service and women in mid-level management report higher satisfaction with procedural improvements. For example, cross-tabulation results indicate that among respondents with more than 20 years of public sector experience, 40% of men rated the use of risk management procedures as “very large” compared to only 22% of women in the same tenure group. Conversely, women in supervisory roles reported higher scores for perceived procedural improvement than their male counterparts, suggesting that professional role and career stage intersect with gender in shaping attitudes toward risk governance.

Table 39. To what extent do you think risk management processes are currently being developed or improved in your employment organisation? * How many people work in your Employment Organization? * What is your gender?

What is your gender?

How many people work in your employment organisation?

Total

0-500

501 - 1000

1001 - 1500

1.501 - 2000

More than 2000

Man

To what extent do you think risk management processes are currently being developed or improved in your employment organisation?

Zero

6

0

2

2

2

12

Low

6

2

4

4

4

20

Mediocre

20

2

2

0

28

52

Very large

30

0

0

0

24

54

Too big

2

0

0

0

2

4

Total

64

4

8

6

60

142

Wife

To what extent do you think risk management processes are currently being developed or improved in your employment organisation?

Zero

10

4

0

2

0

16

Low

18

6

2

4

8

38

Mediocre

68

4

0

0

36

108

Very large

28

4

2

2

26

62

Too big

2

0

0

0

10

12

Total

126

18

4

8

80

236

Education and training also influence perceptions, with postgraduate degree holders and National School of Public Administration graduates more likely to recognize advancements in risk-related practices. Seminar attendance correlates with more positive evaluations of institutional procedures, while organizational size and role level affect how respondents rate risk management use and progress. These relational findings underscore that the adoption of risk management is shaped not only by organizational structures but also by the professional and educational profiles of public servants. Prior research similarly highlights how perceptions of uncertainty and reliance on external consultants can significantly influence organizational risk management outcomes (Subramaniam et al., 2011).

5. Empirical Inference and Concluding Remarks

The empirical data presented in this study reveal both the challenges and emerging potential in institutionalizing risk management within the Greek public sector. While formal adoption remains fragmented and uneven across institutions, there is a discernible trend toward growing awareness and moderate integration of risk-related practices among civil servants. Respondents’ evaluations, particularly across strategic, operational, and financial domains, suggest that although formal frameworks are still at an early stage, procedural development is gaining traction.

Crucially, progress appears more advanced in areas subject to stronger regulatory oversight, such as financial risk management. This highlights a pattern of compliance-driven implementation, where external mandates, rather than internal governance priorities, serve as the primary catalyst. In contrast, domains requiring anticipatory planning and strategic coordination (e.g., strategic and operational risks) remain comparatively underdeveloped. This indicates a gap in the governance-oriented dimension of risk management, which involves embedding risk awareness into institutional culture, leadership behaviour, and long-term planning processes.

Factors such as years of service, educational background, and organizational size influence perceptions of maturity and effectiveness, underscoring the importance of targeted training and leadership engagement. Overall, the findings suggest that risk governance in Greece is not yet embedded as a cultural or strategic norm, but is instead evolving under external and procedural pressures. Bridging this gap will require sustained institutional support, capacity building, and a shift from rule-based compliance to holistic, leadership-led risk governance aligned with public administration reform.

6. Conclusion and Policy Implications

This study offers a systematic, data-driven analysis of how risk management is emerging within Greece’s public sector, with a focus on the perceptions, experiences, and institutional positioning of civil servants across ministries and agencies. We undertook this research to address a critical gap in the literature regarding the early-stage institutionalization of risk frameworks in Southern European contexts, where governance reform is often externally motivated but domestically implemented. Greece is especially significant in this regard: it has been both a laboratory and a stress test for public sector transformation under extreme fiscal and administrative pressure.

The findings hold practical implications for a wide range of stakeholders. For policymakers and public managers, the study provides diagnostic insight into the level of readiness, cultural resistance, and training needs that influence the success of risk governance initiatives. For international bodies such as the OECD (2005, 2014), IMF (2023) and EU institutions, the Greek case offers a real-time assessment of reform traction in a member state undergoing recovery and modernization. Most importantly, the study informs stakeholders within the Greek administration, particularly those in leadership roles, about where targeted interventions, capacity-building efforts, and communication strategies could enhance the legitimacy and functionality of risk-based management systems. In this way, the study not only contributes to academic knowledge, but also serves as a practical resource for guiding implementation and institutional design.

Acknowledgements

The author gratefully acknowledges the financial support provided by the University of West Attica, which made this research possible.

Conflicts of Interest

The author declares no conflicts of interest regarding the publication of this paper.

References

[1] Ahmeti, R., & Vladi, D. B. (2017). Risk Management in Public Sector: A Literature Review. European Journal of Multidisciplinary Studies, 5, 323-329. [Google Scholar] [CrossRef]
[2] Andersen, T. J. (2016). The Routledge Companion to Strategic Risk Management. Routledge.
[3] Beck, U. (1992). Risk Society: Towards a New Modernity. Sage.
[4] Bhimani, A. (2009). Risk Management, Corporate Governance and Management Accounting: Emerging Interdependencies. Management Accounting Research, 20, 2-5. [Google Scholar] [CrossRef]
[5] Black, J. (2005). The Emergence of Risk-Based Regulation and the New Public Risk Management in the United Kingdom. Public Law, 3, 512-548.
[6] Boin, A., & Lodge, M. (2016). Designing Resilient Institutions for Transboundary Crisis Management: A Time for Public Administration. Public Administration, 94, 289-298. [Google Scholar] [CrossRef]
[7] Bracci, E., Mouhcine, T., Rana, T., & Wickramasinghe, D. (2022). Risk Management and Management Accounting Control Systems in Public Sector Organizations: A Systematic Literature Review. Public Money & Management, 42, 395-402. [Google Scholar] [CrossRef]
[8] Bromiley, P., McShane, M., Nair, A., & Rustambekov, E. (2015). Enterprise Risk Management: Review, Critique, and Research Directions. Long Range Planning, 48, 265-276. [Google Scholar] [CrossRef]
[9] Carlsson-Wall, M., Kraus, K., Meidell, A., & Tran, P. (2019). Managing Risk in the Public Sector—The Interaction between Vernacular and Formal Risk Management Systems. Financial Accountability & Management, 35, 3-19. [Google Scholar] [CrossRef]
[10] Committee of Sponsoring Organizations of the Treadway Commission (COSO) (2017). Enterprise Risk Management: Integrating with Strategy and Performance. American Institute of Certified Public Accountants (AICPA).
[11] DiMaggio, P. J., & Powell, W. W. (1983). The Iron Cage Revisited: Institutional Isomorphism and Collective Rationality in Organizational Fields. American Sociological Review, 48, 147-160. [Google Scholar] [CrossRef]
[12] Huber, C. (2009). Risks and Risk-Based Regulation in Higher Education Institutions. Tertiary Education and Management, 15, 83-95. [Google Scholar] [CrossRef]
[13] IMF (International Monetary Fund) (2023). Fiscal Monitor: Climate Crossroads: Fiscal Policies in a Warming World.
[14] International Organization for Standardization (ISO) (2018). ISO 31000:2018 Risk ManagementGuidelines. ISO.
[15] Kapuscinska, K., & Matejun, M. (2014). Risk Management in Public Sector Organizations: A Case Study. International Journal of Business and Management Studies, 3, 129-143.
[16] Kolisovas, D., & Andrius, S. (2011). Risk Management in Lithuania’s Public Sector: Starting Point, Current Situation and Future Perspectives. Intellectual Economics, 5, 547-559.
[17] Lark, J. (2015). ISO 31000: Risk Management—A Practical Guide for SMEs. ISO.
[18] OECD (2005). Advances in Risk Management of Government Debt. OECD Publishing.
[19] OECD (2014). Risk Management and Corporate Governance. OECD Publishing.
[20] Olson, D. L., & Dash Wu, D. (2010). A Review of Enterprise Risk Management in Supply Chain. Kybernetes, 39, 694-706. [Google Scholar] [CrossRef]
[21] Oulasvirta, L., & Anttiroiko, A. (2017). Adoption of Comprehensive Risk Management in Local Government. Local Government Studies, 43, 451-474. [Google Scholar] [CrossRef]
[22] Palermo, T. (2014). Accountability and Expertise in Public Sector Risk Management: A Case Study. Financial Accountability & Management, 30, 322-341. [Google Scholar] [CrossRef]
[23] Power, M. (2007). Organized Uncertainty: Designing a World of Risk Management. Oxford University Press.
[24] Power, M., Scheytt, T., Soin, K., & Sahlin, K. (2009). Reputational Risk as a Logic of Organizing in Late Modernity. Organization Studies, 30, 301-324. [Google Scholar] [CrossRef]
[25] Rana, T., Wickramasinghe, D., & Bracci, E. (2019). New Development: Integrating Risk Management in Management Control Systems—Lessons for Public Sector Managers. Public Money & Management, 39, 148-151. [Google Scholar] [CrossRef]
[26] Rocher, S. (2011). ‘Re-Opening the Black Box’: The Story of Implementing a Risk Analysis Method in a French Local Government. Financial Accountability & Management, 27, 63-82. [Google Scholar] [CrossRef]
[27] Subramaniam, N., Collier, P., Phang, M., & Burke, G. (2011). The Effects of Perceived Business Uncertainty, External Consultants and Risk Management on Organisational Outcomes. Journal of Accounting & Organizational Change, 7, 132-157. [Google Scholar] [CrossRef]
[28] Vinnari, E., & Skærbæk, P. (2014). The Uncertainties of Risk Management. Accounting, Auditing & Accountability Journal, 27, 489-526. [Google Scholar] [CrossRef]
[29] Woods, M. (2009). A Contingency Theory Perspective on the Risk Management Control System within Birmingham City Council. Management Accounting Research, 20, 69-81. [Google Scholar] [CrossRef]

Copyright © 2026 by authors and Scientific Research Publishing Inc.

Creative Commons License

This work and the related PDF file are licensed under a Creative Commons Attribution 4.0 International License.