Authors :
Võ Thị Thu Hồng; Vũ Kiều Sa
Volume/Issue :
Volume 11 - 2026, Issue 8 - August
Google Scholar :
https://tinyurl.com/mwrdayzn
Scribd :
https://tinyurl.com/327uav9n
DOI :
https://doi.org/10.38124/ijisrt/26aug789
Note : A published paper may take 4-5
working days from the publication date to appear in PlumX Metrics, Semantic Scholar, and
ResearchGate.
Abstract :
Purpose – This study investigated how a maritime logistics firm in Vietnam could develop organizational readiness
for the responsible use of artificial intelligence (AI) in compliance risk management. It addressed three connected questions:
which compliance risks should be prioritized, what organizational conditions constrain AI adoption, and which
implementation sequence is feasible for a resource-conscious firm. Design/methodology/approach – An applied qualitative
single-case design was used at TRA-SAS. Evidence comprised three semi-structured interview sessions involving eight
participants from leadership and key functional areas, internal process and business documents, public corporate reports
for 2021–2025, and a 5 × 5 risk-assessment matrix. Thematic analysis was combined with a purpose-specific AI-readiness
assessment covering data, technology, people, processes, finance, leadership, compliance culture, and security/legal
governance. Findings – Eight material compliance risks were identified. Customs compliance (CR04) received the highest
priority within the portfolio (likelihood 3, impact 5, score 15; High). The firm displayed an uneven M2–M3 digital-maturity
profile: software and selected processes were near M3, while data standardization and system integration remained closer
to M2. High-value AI opportunities were document checking, contract and obligation analysis, regulatory change
monitoring, early-warning analytics, and compliance reporting. However, these use cases depended on data governance,
standardized workflows, role clarity, human review, and model monitoring. Originality/value – The study connects
compliance-risk materiality with purpose-specific AI readiness in an under-researched maritime logistics setting. It proposes
a risk-first, readiness-gated, human-in-the-loop pathway that avoids treating AI adoption as a technology procurement
decision.
Keywords :
Artificial Intelligence; AI Readiness; Compliance Risk; RegTech; Maritime Logistics; Responsible AI; Vietnam.
References :
- Arner, D. W., Barberis, J., & Buckley, R. P. (2017). FinTech, RegTech, and the role of compliance in 2020. Northwestern Journal of International Law & Business, 37(3), 371–413.
- Braun, V., & Clarke, V. (2006). Using thematic analysis in psychology. Qualitative Research in Psychology, 3(2), 77–101. https://doi.org/10.1191/1478088706qp063oa
- Committee of Sponsoring Organizations of the Treadway Commission. (2017). Enterprise risk management: Integrating with strategy and performance.
- Davenport, T. H., & Ronanki, R. (2018). Artificial intelligence for the real world. Harvard Business Review, 96(1), 108–116.
- European Parliament & Council of the European Union. (2024). Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence. Official Journal of the European Union.
- International Organization for Standardization. (2018). ISO 31000:2018 risk management—Guidelines.
- International Organization for Standardization. (2021). ISO 37301:2021 compliance management systems—Requirements with guidance for use.
- International Organization for Standardization & International Electrotechnical Commission. (2023a). ISO/IEC 23894:2023 information technology—Artificial intelligence—Guidance on risk management.
- International Organization for Standardization & International Electrotechnical Commission. (2023b). ISO/IEC 42001:2023 information technology—Artificial intelligence—Management system.
- Institute of Internal Auditors. (2020). The IIA’s Three Lines Model: An update of the Three Lines of Defense.
- Jöhnk, J., Weißert, M., & Wyrtki, K. (2021). Ready or not, AI comes—An interview study of organizational AI readiness factors. Business & Information Systems Engineering, 63(1), 5–20. https://doi.org/10.1007/s12599-020-00676-7
- Kaplan, R. S., & Mikes, A. (2012). Managing risks: A new framework. Harvard Business Review, 90(6), 48–60.
- Micheler, E., & Whaley, A. (2020). Regulatory technology: Replacing law with computer code. European Business Organization Law Review, 21(2), 349–377. https://doi.org/10.1007/s40804-019-00151-1
- National Assembly of Vietnam. (2014). Law on Customs No. 54/2014/QH13.
- National Assembly of Vietnam. (2015). Vietnam Maritime Code No. 95/2015/QH13.
- National Assembly of Vietnam. (2025a). Law on Artificial Intelligence No. 134/2025/QH15.
- National Assembly of Vietnam. (2025b). Law on Personal Data Protection No. 91/2025/QH15.
- National Institute of Standards and Technology. (2023). Artificial intelligence risk management framework (AI RMF 1.0) (NIST AI 100-1). https://doi.org/10.6028/NIST.AI.100-1
- Organisation for Economic Co-operation and Development. (2019). Recommendation of the Council on artificial intelligence.
- Government of Vietnam. (2025). Decree No. 356/2025/ND-CP detailing the Law on Personal Data Protection.
- Government of Vietnam. (2026). Decree No. 142/2026/ND-CP detailing and implementing the Law on Artificial Intelligence.
- Tornatzky, L. G., & Fleischer, M. (1990). The processes of technological innovation. Lexington Books.
- TRA-SAS. (2022–2026). Financial statements and annual reports, 2021–2025.
- Yin, R. K. (2018). Case study research and applications: Design and methods (6th ed.). SAGE.
Purpose – This study investigated how a maritime logistics firm in Vietnam could develop organizational readiness
for the responsible use of artificial intelligence (AI) in compliance risk management. It addressed three connected questions:
which compliance risks should be prioritized, what organizational conditions constrain AI adoption, and which
implementation sequence is feasible for a resource-conscious firm. Design/methodology/approach – An applied qualitative
single-case design was used at TRA-SAS. Evidence comprised three semi-structured interview sessions involving eight
participants from leadership and key functional areas, internal process and business documents, public corporate reports
for 2021–2025, and a 5 × 5 risk-assessment matrix. Thematic analysis was combined with a purpose-specific AI-readiness
assessment covering data, technology, people, processes, finance, leadership, compliance culture, and security/legal
governance. Findings – Eight material compliance risks were identified. Customs compliance (CR04) received the highest
priority within the portfolio (likelihood 3, impact 5, score 15; High). The firm displayed an uneven M2–M3 digital-maturity
profile: software and selected processes were near M3, while data standardization and system integration remained closer
to M2. High-value AI opportunities were document checking, contract and obligation analysis, regulatory change
monitoring, early-warning analytics, and compliance reporting. However, these use cases depended on data governance,
standardized workflows, role clarity, human review, and model monitoring. Originality/value – The study connects
compliance-risk materiality with purpose-specific AI readiness in an under-researched maritime logistics setting. It proposes
a risk-first, readiness-gated, human-in-the-loop pathway that avoids treating AI adoption as a technology procurement
decision.
Keywords :
Artificial Intelligence; AI Readiness; Compliance Risk; RegTech; Maritime Logistics; Responsible AI; Vietnam.