Thursday, February 11, 2010
Green Energy / Sustainability and CCM-T?
As we have much of last year, again today we're thinking about Green Energy and Sustainability. The sociological and public good components of Green Energy and Sustainability are clear, but the growing number of new business start-ups in this space is a sign that the financial rewards of doing good are may also be rewarding. Evidence includes the Wharton School's Sustainability Program and the high ROI payback that can be obtained from Energy Audit activities in both commercial and even residential space. In the last month, we've met with BreezePlay (a Charlotte-based Green Energy start-up focusing in the residential space) and Energy Reduction Solutions (a Florida-based Engineering start-up focusing in the commerical space). Each have sparked our interest.
At Visual Risk IQ, we talk about how CCM-T reduces the marginal cost of "one more question," and helps audit and financial professionals answer important questions about internal controls, fraud, and expense management. Who are the smart people asking questions about Green Energy and Sustainability?
We'd like to meet more of them, so please drop us a line!
Joe Oringel
Visual Risk IQ
Charlotte NC, USA
Tuesday, November 24, 2009
Conflict of Interest / External Databases, in the news again!
Though grantee institutions often require researchers to disclose conflicts of interest in research publications, the same institutions rarely reduce or eliminate the financial conflicts. Ninety percent of grantee institutions rely solely on researcher discretion to determine which interests are required to be reported. Because equity interests (i.e. stock ownership) is rarely required to be reported, the specific financial interests of NIH-funded researchers are often unknown.
The OIG audit report recommends that National Institute of Health request grantee institutions to provide detailes to NIH regarding the nature of ALL reported financial conflicts of interest, and how the conflicts are managed, reduced, or eliminated. This change, if implemented, would be a major step-up in Oversight on how the University Research community is monitored.
Stay tuned - the compliance and record keeping impact of such changes could be quite widespread. Fortunately for some universities who have implemented Continuous Controls Monitoring (CCM-T) solutions that compare data from internal to external databases, these changes may be easier to implement. For more information, see: www.VisualRiskIQ.com/HigherEd
For related posts, see: October 2009 and July 2009 blog entries.
Friday, October 16, 2009
Forrester Research on Continuous Controls Monitoring is Spot On
“Internal controls monitoring. Technologies in this area so far have demonstrated a low level of success, or business value-add, and are on a trajectory for minimal success over their lifespan, according to Forrester. There is potential payback in error reductions, efficiency, and risk avoidance, but most installations have yet to prove what they will ultimately be worth. And while internal controls monitoring is important because of Sarbanes-Oxley and other compliance directives, "many of the solutions just raise red flags," Paul Hamerman, vice president of enterprise applications for Forrester, tells CFO.com. "Somebody has to go through these flags to figure out what they mean. If the application doesn't have the built-in intelligence to do that, it's value is diminished."
Going through the red flags is a real business challenge, and requires knowledge of technology, enterprise data, policies, business rules, and fraud. Unfortunately, many organizations who have invested in this technology do not put enough emphasis on the on-going care and feeding of the systems, and it's common for the number of red flags identified in a period to exceed the number of red flags that are fully researched and resolved. As a result, the business value add for the systems can fail to reach its potential.
Even for organizations that are managing the work queues well, it is rare to see organizations modify their rules and add more red flags for checking. Opportunities to help CCM-T users with post-implementation support, whether the tool of choice is Oversight, Approva, ACL Audit Exchange 2, or SymSure / IDEA, would seem to be a growth area.
* * * * * * * * * * *
Are you attending the Rutgers Continuous Auditing Symposium on November 6 and 7? We are. Look for us at the Conference or on a Panel at 4:00 on Day 1, and let's compare notes on the above. We're interested to share experiences with others...
Joe Oringel
Visual Risk IQ
Charlotte NC, USA
Sunday, August 9, 2009
Anything worth doing is worth doing well - and Often!
He asked me what other business processes make good applications for CCM, and I shared that it's a variety of application areas - everything from review of Manual Journal Entries to Accounts Payable Disbursements to Grants and Contracts in Higher Education. Across multiple industries and also across multiple systems.
So whether it's updating an audit plan quarterly instead of annually, or analyzing manual journal entries for fraud or error monthly instead of quarterly. If it's worth doing, ask how you might do it more frequently. With modern CCM tools, you'll find that many important financial control activities can be done well, and Often!.
Tuesday, August 4, 2009
When the Going Gets Tough, the Tough Go Shopping (around)
Also interesting, though not in the Chronicle's article. is the potential synergy between improving Purchasing and CCM-T. In the last few years, we've had deep-dive meetings with a number of firms who specialize in SG&A cost reduction and vendor negotiation. It has become clear that among their most distinctive strengths are data analysis and vendor negotiation. Their projects are net cash flow positive, funded by realized, hard-dollar savings, paid on a contingent fee.
Once new contracts are re-negotiated, the firms review actual spending and compute realized savings, to compute their fees. Which represents the opportunity for CCM-T. Just as Visual Risk IQ has implemented CCM-T to review invoices and invoice lines for suspicious, fraudulent, or duplicate payments, we also can configure CCM-T to review invoice lines for rogue or unauthorized spending from non-preferred vendors.
So if you're a CCM-T user looking for improved business value from your implementation, or a finance, audit, or procurement executive looking to improve your bottom line through an evaluation of your Purchasing group, let us know. We know some great places to shop!
Joe Oringel
Visual Risk IQ
Charlotte NC, USA
Wednesday, July 22, 2009
Conflict of Interest - the Power of External Databases
Representative Charles Grassley is regularly in the news for advocating a national law (i.e. Physician Payments Sunshine Act) that would require disclosure of speaking fees. Currently, state laws and specific academic institution each set their own policies and monitoring requirements.
The Chronicle opined that "Universities also need to pay more attention to whether they review research activities by their own staff that may damage their institutional reputations even though the work involves outside facilities, Ms. Chimonas said. The case of Dr. Wang may prove a strong incentive for UCLA to do so. Even within the same statewide system, she said, there are campuses such as the University of California at Davis that have taken a much more aggressive definition of how they monitor outside research by university faculty members.
Institutions such as UCLA could be realizing the danger of ignoring outside research work, Ms. Chimonas said. "This may be a wake-up call for a lot of institutions who have been thinking, 'Well, this has nothing to do with us,'" she said."
Taking information from external databases like Excluded Parties List System (the list of Federally debarred vendors), or the OFAC Watch List is a high-value audit test, especially as frequency is increased from annual to quarterly or more frequently. UCLA's situation with Dr. Wang, especially because of reputation risk, calls for better monitoring of external databases.What external databases are your organizations monitoring? How often? What are the more interesting findings? Please comment - all input is welcomed!
Joe Oringel
Visual Risk IQ
Charlotte NC, USA
Monday, July 20, 2009
The Value of Frequency - how the Defense Department paid millions in wages to invalid accounts
These payments represent fraud and misuse of tax dollars, but because the audit approach was a point in time audit, looking backward over a very long time period (six years!), it is highly likely that the money will never be recovered.
Had the DOD used leading edge technology like Continuous Controls Monitoring for Transactions (CCM-T), which can compare all SSN's from master files, from payment files, to the suspicious SSN lists like those at Social Security Death Index database, they could have known of the errors PRIOR to payment. The more frequently the data is compared, the more valuable the analysis becomes.
And implementation is a tiny fraction of the $15 million spent for erroneous payments. Factor in the time value of money (errors go back to 2002!) and the reputation risk associated with such errors, and CCM-T looks better and better.
Joe Oringel
Visual Risk IQ
Charlotte NC, USA
Tuesday, July 14, 2009
University Business - 101 Ways to Raise Revenue or Decrease Costs
One that grabbed my attention this week is an archived (pre-recesssion!) article titled 101 Smart Revenue Generators and Money Saving Ideas. After all, who wouldn't like a little more on the top line, and on the bottom line. Regardless of whether you're for-profit or non-profit.
What strikes me as noteworthy about the article is that most (and the first few!) Revenue Generating ideas are actually all related to expense control and expense reduction. Some are traditional vendor negotiation strategies, like Visual Risk IQ does together with its partner Third Law Sourcing, while others are P-Card. Many can benefit from CCM-T, and many are worth a fresh read / re-read, given the current state of the economy.
Feel free to add Comments on your strategies for trimming costs or raising revenue in today's challenging times. Success stories are always welcome!
Joe Oringel
Visual Risk IQ, LLC
Charlotte NC, USA
Wednesday, July 8, 2009
Observations from Recent, Local Frauds in Charlotte NC
My own experience is these three elements of the fraud triangle are closely related, and that Opportunity needs to be re-evaluated, especially as Incentive increases. Today's economic times are proving this need most everywhere we look, yet we still see only a few companies who are actively changing and increasing how they monitor for potential fraud, despite the availability of very effective, modern tools for fraud detection. Like CCM-T tools from Oversight and Approva.
A specific example: During my Big 4 Accounting Firm days, I led a team that audited the procedures used to produce scratch-off lottery tickets. When we started, the largest prize awarded was $5,000 or $10,000. While internal controls were always very good (i.e. Opportunity = Low), there were still a number of people at the Ticket Printer and at the Big 4 Firm who had access to information that might help locate a batch of 250 tickets that would likely contain a $5,000 or $10,000 winner.
The likelihood that a person would risk their career to steal $5,000 or $10,000 (two to six months net pay) was pretty low. But when the Ticket Printer and State Lotteries began printing tickets with $100,000 and eventually $1,000,000 tickets. That represented at least a year or even 20 years or more in net pay. What a powerful Incentive!
This change in Incentive was a trigger that we saw to re-evaluate internal controls, because now the temptation needed a corresponding decrease in opportunity. In addition to our agreed-upon procedures to evaluate controls over ticket production, we began a continual security review which included review of other controls that would identify who may be accessing information that might allow a large ticket winner to be located. We publicized the continual security review within the company (and the Big 4 team!), so that the decreased Opportunity was understood by anyone who may have been tempted.
As staffs are cut and monitoring controls become less frequent, what is your organization doing to reduce the Opportunity for Fraud. For a couple of high-profile cases in Charlotte, it's clear that more needs to be done.
Joe Oringel
Visual Risk IQ
Charlotte NC, USA
Friday, June 12, 2009
Stimulus Fraud Could hit $50 Billion. How could CCM-T help?
Thursday, June 11, 2009
The Red Flags Rule: What Utility Companies Need to Know About Complying with New Requirements for Fighting Identity Theft (source: www.FTC.gov)
Visual Risk IQ is currently working on a continuous controls monitoring for transactions (CCM-T) project for a Utility Company, specifically focused on FACTA and the Red Flags requirement. Through a series of customized risk and performance checks, we will be assisting the Utility to monitor its new and existing customer for Red Flags related to fraud and identity theft. While the CCM-T component is only one part of a comprehensive set of policies, procedures, and new work processes, it is an integral component that will enable to Utility to achieve compliance and reduce potential fraud often associated with theft of service and bad debt.
For more information on FACTA requirements, specific to Utilities, see the article below, from the FTC's web site on the Red Flag Rules and FACTA.
The article below was originally published by Tiffany George and Pavneet Singh, from FTC.gov
As many as nine million Americans have their identities stolen each year. The crime takes many forms. Thieves may buy a car, get a credit card, or establish gas, water, or electric service using someone else’s identity. The cost to business can be staggering as well, with charges racked up by identity thieves unpaid and uncollectible. In addition, crooks may use proof of utility service to get driver’s licenses illegally or to apply for government benefits using a bogus address.
Utility companies may be the first to spot the “red flags” of identity theft, including suspicious activity suggesting that thieves may be using stolen information to establish service. That’s why you need to know about a new law – called the Red Flags Rule – that requires many businesses, including most companies that provide utility services to consumers, to spot the red flags that can be the telltale signs of identity theft. Under the Red Flags Rule, which the Federal Trade Commission (FTC) will begin enforcing on August 1, 2009, companies covered by the law must develop a written Identity Theft Prevention Program. Is your utility required to comply with the Red Flags Rule? If so, have you developed your program to detect, prevent, and minimize the damage that could result from identity theft?
WHO MUST COMPLY
Companies that provide utility services are covered by the Rule if they are “creditors” with “covered accounts.” A creditor is a business or organization that regularly defers payments for goods or services. The Rule defines a “covered account” as a consumer account that allows multiple payments or transactions – for example, a standard household utility account – or any other account with a reasonably foreseeable risk of identity theft. Even government agencies and publicly-owned utilities may be “creditors” covered by the Rule.
Because the Rule is geared to the types of accounts that are targeted by identity thieves, the determination of whether the law applies to your business or organization isn’t based on your status. Rather, it’s based on whether your organization’s activities fall within the relevant definitions. It boils down to this: If your utility regularly bills customers after services are provided, you are a creditor under the new law and will have to develop a written program to identify and address the red flags that could indicate identity theft in your covered accounts.
SPOTTING RED FLAGS
The Red Flags Rule gives utilities the flexibility to implement an identity theft prevention program that best suits the operations of their business, as long as it conforms to the Rule’s requirements. You may already have a fraud prevention or security program in place that you can use as a starting point.
If you’re covered by the Rule, your program must:
- Identify the kinds of red flags that are relevant to your business;
- Explain your process for detecting them;
- Describe how you’ll respond to red flags to prevent and mitigate identity theft; and
- Spell out how you’ll keep your program current.
What red flags signal identity theft? There’s no standard checklist. Supplement A to the Red Flags Rule – available at ftc.gov/redflagsrule – sets out some examples, but here are a few warning signs that may be relevant to utilities:
- Suspicious documents. Has a new customer given you identification documents that look altered or forged? Is the physical description on the identification inconsistent with what the customer looks like? Is other information on the identification inconsistent with what the customer has told you? Under the Red Flags Rule, you may need to ask for additional information.
- Suspicious personally identifying information. Personal information that doesn’t match what you’ve learned from other sources also may be a red flag of identity theft. For example, if you pull a credit report based on the prospective customer’s Social Security number and the report comes back under someone else’s name, fraud could be afoot. A billing address that appears to be fictitious also could signal a problem.
- Suspicious activities. Did a new customer fail to make the first payment or make an initial payment but no others? Did payments abruptly stop on an otherwise up-to-date account? Did a customer’s use pattern suddenly change? For example, are you detecting unusual activity on what’s always been a “snowbird” account? Is mail returned repeatedly as undeliverable even though transactions still are being conducted on the account? Are utilities still being used after a known move-out? Trust your gut when something seems questionable. These questionable activities may be red flags of identity theft.
- Notices from victims of identity theft, law enforcement authorities, or others suggesting possible identity theft. Have you received word about identity theft from another source? Cooperation is key. Heed warnings from others that identity theft may be ongoing.
SETTING UP YOUR IDENTITY THEFT PREVENTION PROGRAM
Once you’ve identified the red flags that are relevant to your utility, your program should include the procedures you’ve put in place to detect them in your day-to-day operations. Your program also should describe how you plan to prevent and mitigate identity theft. How will you respond when you spot the red flags of identity theft? Will you close questionable accounts or monitor them more closely? Will you contact the customer directly? When automated systems detect red flags, will you manually review the file? If you’re notified that an identity thief has run up bills using another person’s information, how will you ensure that the debt is not charged to the victim? Your response will vary depending on the circumstances and the need to accommodate other legal obligations – for example, laws regarding the provision and termination of utility service. Finally, your program must consider how you’ll keep it current to address new risks and trends.
No matter how good your program looks on paper, the true test is how it works. According to the Red Flags Rule, your program must be approved by your Board of Directors, or if you don’t have a Board, by a senior employee. The Board may oversee the administration of the program, including approving any important changes, or designate a senior employee to take on these duties. Your program should include information about training your staff and provide a way for you to monitor the work of your service providers – for example, those who manage your debt collection operations. The key is to make sure that all members of your staff are familiar with the Rule and your new compliance procedures.
WHAT’S AT STAKE
Although there are no criminal penalties for failing to comply with the Rule, violators may be subject to financial penalties. But even more important, compliance with the Red Flags Rule assures your customers that you’re doing your part to fight identity theft.
Looking for more information about the Red Flags Rule? The FTC has published Fighting Fraud with the Red Flags Rule: A How-To Guide for Business, a plain-language handbook on developing an Identity Theft Prevention Program. For a free copy of the Guide and for more information about compliance, visit ftc.gov/redflagsrule. In addition, the FTC has released a fill-in-the-blank form for businesses and organizations at low risk for identity theft. The online form offers step-by-step instructions for creating your own written Identity Theft Prevention Program. You can fill it out online and print it. The do-it-yourself form is available at ftc.gov/redflagsrule.
Questions about the Rule? Email RedFlags@ftc.gov.
Tiffany George and Pavneet Singh are attorneys with the Federal Trade Commission’s Division of Privacy and Identity Protection.
Monday, May 18, 2009
Visual Risk IQ to present at Blue Cross / Blue Shield Internal Audit and Fraud Conference
Sunday, April 12, 2009
Are you a creditor? How FACTA compliance may affect your organization
FACTA defines the terms “credit” and “creditor” the same as section 702 of the Equal Credit Opportunity Act:
• The term "credit" means the right granted by a creditor to a debtor to defer payment of debt or to incur debts and defer its payment or to purchase property or services and defer payment therefore.
• The term "creditor" means any person who regularly extends, renews, or continues credit; any person who regularly arranges for the extension, renewal, or continuation of credit; or any assignee of an original creditor who participates in the decision to extend, renew, or continue credit.
This definition of creditor casts a large and wide net. In fact, the American Medical Association (AMA) recently wrote the FTC essentially pleading exemption under the FACTA covered accounts. However, in response, the FTC stated that it “believe[s] that the plain language and purpose of the Rule dictate that health care professionals are covered by the Rule when they regularly defer payment for goods or services. We also believe that implementation of the Rule will help reduce the incidence of medical identity theft; and that the burden on health care professionals need not be substantial.”
We seem to be getting further from the typical line of thinking with the term creditor and identity theft, but now that electrons carry out our human fiduciary responsibilities, the door is now wide open to applying the term “creditor” to most any firm.
Firms should consider implementation of a solid continuous controls monitoring for transactions (CCM-T) framework that can help them comply with the FACTA Red Flag Rules. More information on FACTA and CCM-T's application for FACTA compliance in the coming weeks.
Joe Oringel
Visual Risk IQ
Charlotte NC, USA