Showing posts with label Approva. Show all posts
Showing posts with label Approva. Show all posts

Friday, May 14, 2010

The High Cost of FCPA Compliance - CCM-T as Low-cost Antidote

We've been writing and tweeting about Foreign Corrupt Practices Act (FCPA) compliance for several months, after teaming with Houston-based Morgan-Garris for an innovative data-driven solution to help reduce the costs of FCPA monitoring and compliance. We'll actually be presenting next week at MISTI's SuperStrategies on using Continuous Auditing and Monitoring technology for several different applications, including FCPA.

This week's Forbes Article titled, "How Bribery Hurts Business and Enriches Insiders" shows the incredible high costs of FCPA investigations. Deloitte 1300+ project consultants billed more than 949,000 hours on their work for Siemens FCPA investigation. ABB has reserved $300 million, and Avon Products has reserved $95 million for their on-going investigations.

It is becoming increasingly common for FCPA costs to run tens, if not hundreds of millions of dollars. What takes so long? Why is it so expensive?

When Kim and I were at PwC, it was common for the data acquisition component of a Big 4 data analysis project to consume 60% or 70% or more of a project budget. Extracting flat files and fastidiously mapping them into desktop audit software tools was and still is a time-consuming process, especially for ad hoc analysis. At Visual Risk IQ, most of our data analysis projects are fixed-fee, and include time to acquire and map data into more modern audit software like Oversight, Approva, or SymSure for IDEA**. These more modern tools facilitate repeated extraction at dramatically lower costs of data acquisition, therefore allowing more time for research and review of results.

As such, each successive extract of a monthly or even daily file can be loaded into modern audit software, so that 100% of the time for the second file is spent on review of results, not loading data. Further, advances in workflow and logging can facilitate efficient review and oversight by finance or inside / outside counsel. Given the fees cited in Forbes, we know we have a much better way.

Joe Oringel
Visual Risk IQ
Charlotte NC, USA


** Author's Note - We read that ACL's AX/2 has similar automation for data extraction, through integration of Informatica for extract, transform, and load. We have not yet validated this functionality.

Friday, October 16, 2009

Forrester Research on Continuous Controls Monitoring is Spot On

Chatted with freelance writer and former CFO of one of our clients Chris McKittrick this week. Chris writes for Big Fat Finance Blog on a variety of topics, including CCM-T, which Forrester Research calls Internal Controls Monitoring. Chris pointed us to a CFO Magazine article earlier this year about CCM-T, which states the simple and profound:

“Internal controls monitoring. Technologies in this area so far have demonstrated a low level of success, or business value-add, and are on a trajectory for minimal success over their lifespan, according to Forrester. There is potential payback in error reductions, efficiency, and risk avoidance, but most installations have yet to prove what they will ultimately be worth. And while internal controls monitoring is important because of Sarbanes-Oxley and other compliance directives, "many of the solutions just raise red flags," Paul Hamerman, vice president of enterprise applications for Forrester, tells CFO.com. "Somebody has to go through these flags to figure out what they mean. If the application doesn't have the built-in intelligence to do that, it's value is diminished."

Going through the red flags is a real business challenge, and requires knowledge of technology, enterprise data, policies, business rules, and fraud. Unfortunately, many organizations who have invested in this technology do not put enough emphasis on the on-going care and feeding of the systems, and it's common for the number of red flags identified in a period to exceed the number of red flags that are fully researched and resolved. As a result, the business value add for the systems can fail to reach its potential.

Even for organizations that are managing the work queues well, it is rare to see organizations modify their rules and add more red flags for checking. Opportunities to help CCM-T users with post-implementation support, whether the tool of choice is Oversight, Approva, ACL Audit Exchange 2, or SymSure / IDEA, would seem to be a growth area.

* * * * * * * * * * *

Are you attending the Rutgers Continuous Auditing Symposium on November 6 and 7? We are. Look for us at the Conference or on a Panel at 4:00 on Day 1, and let's compare notes on the above. We're interested to share experiences with others...

Joe Oringel
Visual Risk IQ
Charlotte NC, USA

Wednesday, July 8, 2009

Observations from Recent, Local Frauds in Charlotte NC

Several folks commented on recent tweets of local fraud and embezzlement, first at UNC-Charlotte and again at Charlotte's Mecklenburg County, specifically within the Department of Social Services. The Fraud Triangle teaches us that as long as there is Pressure / Incentive (I really need the money), Rationalization (e.g. other people do it, I'll pay it back...etc.) and Opportunity (I won't get caught because...) fraud can and will occur and recur.

My own experience is these three elements of the fraud triangle are closely related, and that Opportunity needs to be re-evaluated, especially as Incentive increases. Today's economic times are proving this need most everywhere we look, yet we still see only a few companies who are actively changing and increasing how they monitor for potential fraud, despite the availability of very effective, modern tools for fraud detection. Like CCM-T tools from Oversight and Approva.

A specific example: During my Big 4 Accounting Firm days, I led a team that audited the procedures used to produce scratch-off lottery tickets. When we started, the largest prize awarded was $5,000 or $10,000. While internal controls were always very good (i.e. Opportunity = Low), there were still a number of people at the Ticket Printer and at the Big 4 Firm who had access to information that might help locate a batch of 250 tickets that would likely contain a $5,000 or $10,000 winner.

The likelihood that a person would risk their career to steal $5,000 or $10,000 (two to six months net pay) was pretty low. But when the Ticket Printer and State Lotteries began printing tickets with $100,000 and eventually $1,000,000 tickets. That represented at least a year or even 20 years or more in net pay. What a powerful Incentive!

This change in Incentive was a trigger that we saw to re-evaluate internal controls, because now the temptation needed a corresponding decrease in opportunity. In addition to our agreed-upon procedures to evaluate controls over ticket production, we began a continual security review which included review of other controls that would identify who may be accessing information that might allow a large ticket winner to be located. We publicized the continual security review within the company (and the Big 4 team!), so that the decreased Opportunity was understood by anyone who may have been tempted.

As staffs are cut and monitoring controls become less frequent, what is your organization doing to reduce the Opportunity for Fraud. For a couple of high-profile cases in Charlotte, it's clear that more needs to be done.

Joe Oringel
Visual Risk IQ
Charlotte NC, USA

Wednesday, February 25, 2009

Now Hiring - Continuous Auditing specialists

Many of you know who have heard my partner and I speak at various IIA and MISTI events have heard that we have Google alerts set up on Continuous Auditing and Continuous Monitoring. Most Continuous Monitoring alerts have been related to Medical Devices - glucose monitoring, pacemakers, but it has been rare that we actually get article posts related to Continuous Auditing or what is becoming known as Continuous Controls Monitoring.

But maybe this is changing....

For the past two weeks, I have gotten "hits" on Google Alerts for Continuous Auditing and Continuous Controls Monitoring that relate to data analysis, data mining, and continuous auditing, specifically Job Postings. Yes, despite the challenging economy, there are several Audit Groups that are hiring continuous auditing specialists. Technical skills needed include data analysis, such as working with ACL or IDEA, as well as to more modern tools such as Approva, Oversight Systems or Apex Analytix.

Not surprising, interpersonal skills, including good communication skills and technical writing are also required. You can't write a good continuous auditing test if you don't have good data. And auditors need help from someone to acquire and understand the data.

Kudos to the hiring executives who understand that increasing the depth and especially the frequency of data analysis can increase the value that internal audit brings. Two of the three job postings I've seen are in the Hospitality sector, and the third is in Healthcare. Common threads perhaps are large volumes of disparate data, and opportunities to increase top line revenue through improving data quality.

For more information on these jobs or to compare notes on data analysis and continuous auditing, please reach out via contact information below.

Regards,

Joe Oringel
Visual Risk IQ
Charlotte NC, USA
joe.oringel@visualriskiq.com