Jim Littley from KPMG is talking about Continuous Monitoring (CM) / Governance Risk & Compliance (GRC) / Business Intelligence (BI) etc., and all of the alphabet soup of technology tools that can be used improve controls and risk monitoring. He observes that most large organizations have multiple initiatives related to acquiring and implementing tools and technologies for point solutions that assist in this area, but these are siloed and rarely linked together. He sees Internal Audit as a potential value-creator in this area.
Good points. We see Procurement teams with supply chain analytics, Finance with BI and macro-level analytics, and Internal audit with audit data analytics, ERM or Risk with survey tools for subjective risk assessment, sometimes all in the same firm. Ideally, macro-level analytics tools like BI should work together with the exception analytic tools in the CM world to provide a single, integrated review of risk.
Jim suggests we think of Continuous Monitoring as the first line of defense, and Continuous Auditing as the second or third line of defense. Using common data sources (i.e. a single source of truth) can lower the cost of acquiring data for each initiative, and improve overall quality.
Slides aren't posted (yet?), but I'll update this post with a link if they are made available.
Showing posts with label Continuous Auditing. Show all posts
Showing posts with label Continuous Auditing. Show all posts
Friday, November 4, 2011
Opening Rutgers WCARS session - Continuous External Auditing
The opening panel was led by Greg Shields of the Canadian Institute of Chartered Accountants (CICA) and included Deloitte's National Office Partner Tom Criste, Retired Deloitte Partner Trevor Stewart, and PhD Student Paul Byrnes. A little disappointing that more signing partners from more accounting firms were not on the panel. Perhaps that would help unlock the code on the very slow adoption of use of technology to execute external audits.
Much emphasis was on the degree of change that would be needed for the firms to seriously re-engineer their processes. My favorite quote from the session was from Tom Criste, who observes that the great increases in technology have affected how audits are documented, but not how audits are performed. The work programs for Inventory, A/R, Cash, etc., are relatively unchanged even from when he entered the profession decades ago. And because many procedures (e.g. Inventory Observation, Confirmations of A/R balances) are required by professional standards, it would be difficult to re-engineer the audit.
Mr. Criste envisions an audit where statisticians and economists could review data and help form the External Auditor's opinion. He suggests that a test audit could be performed in parallel with a traditional external audit, and that the firm could compare results and findings with each other and the client. But he says, who would want to invest that time and energy, even if the second audit was free?
If that's truly the barrier, I'd suggest to start with the users of financial statements. Would MF Global's investors and creditors like to have had any assurance provided on quarterly financial results? Probably so.
I'd advocate beginning with the end in mind, and determine the desired frequency of external audit assurance. More than annual is probably good. Daily is probably way too frequent. (What CEO wants to explain slow mid-month sales to Wall Street Analysts).
If quarterly assurance was desired, how should external audit procedures be changed? Comments welcome!
Much emphasis was on the degree of change that would be needed for the firms to seriously re-engineer their processes. My favorite quote from the session was from Tom Criste, who observes that the great increases in technology have affected how audits are documented, but not how audits are performed. The work programs for Inventory, A/R, Cash, etc., are relatively unchanged even from when he entered the profession decades ago. And because many procedures (e.g. Inventory Observation, Confirmations of A/R balances) are required by professional standards, it would be difficult to re-engineer the audit.
Mr. Criste envisions an audit where statisticians and economists could review data and help form the External Auditor's opinion. He suggests that a test audit could be performed in parallel with a traditional external audit, and that the firm could compare results and findings with each other and the client. But he says, who would want to invest that time and energy, even if the second audit was free?
If that's truly the barrier, I'd suggest to start with the users of financial statements. Would MF Global's investors and creditors like to have had any assurance provided on quarterly financial results? Probably so.
I'd advocate beginning with the end in mind, and determine the desired frequency of external audit assurance. More than annual is probably good. Daily is probably way too frequent. (What CEO wants to explain slow mid-month sales to Wall Street Analysts).
If quarterly assurance was desired, how should external audit procedures be changed? Comments welcome!
Labels:
Continuous Auditing,
External Auditing,
Rutgers
Thursday, November 3, 2011
Live from Rutgers WCARS - Friends and Family meeting
Most of you reading this blog post have an awareness and even a keen interest in data analysis and/or continuous auditing, whatever we agree that means. You may not know how long this topic has been being discussed and debated.
I'm writing this from the 23rd (!) World Continuous Auditing Symposium at Rutgers Business School in Newark NJ. It's been a semi-annual meeting, so the group began gathering in 1999. All of the Big 4 firms are here, as are the AICPA, software vendors like ACL, Caseware, Oversight, and even CA. For more information on the agenda, see: http://raw.rutgers.edu/23WCARS .
Beginning tomorrow morning, I'll be blogging about the most interesting speakers, topics, and academic papers on the main agenda, so come back often for updates.
Today is the "Friends and Family" meeting, where some of the longer-standing supporters of the Rutgers program are discussing emerging issues. One topic on the agenda is the notion of Audit Data Standards, which would be a common data model for certain business processes like General Ledger and perhaps subledger like Supply Chain or Revenue.
The presenters advocate a cloud-based data store that public companies would use to load daily or at least monthly transactions, and that external auditors (and perhaps internal auditors) would access that data periodically to perform audit analytics. Glad I'm here - there's a lot of pro's and con's to consider with this standardization.
I'm writing this from the 23rd (!) World Continuous Auditing Symposium at Rutgers Business School in Newark NJ. It's been a semi-annual meeting, so the group began gathering in 1999. All of the Big 4 firms are here, as are the AICPA, software vendors like ACL, Caseware, Oversight, and even CA. For more information on the agenda, see: http://raw.rutgers.edu/23WCARS .
Beginning tomorrow morning, I'll be blogging about the most interesting speakers, topics, and academic papers on the main agenda, so come back often for updates.
Today is the "Friends and Family" meeting, where some of the longer-standing supporters of the Rutgers program are discussing emerging issues. One topic on the agenda is the notion of Audit Data Standards, which would be a common data model for certain business processes like General Ledger and perhaps subledger like Supply Chain or Revenue.
The presenters advocate a cloud-based data store that public companies would use to load daily or at least monthly transactions, and that external auditors (and perhaps internal auditors) would access that data periodically to perform audit analytics. Glad I'm here - there's a lot of pro's and con's to consider with this standardization.
Thursday, August 11, 2011
Continuous Auditing and Monitoring Bootcamp Scheduled in Houston
Visual Risk IQ will be leading a one-day workshop in Houston on Tuesday 9/27, hosted by the Texas Society of CPA's. The workshop is designed to help you get started on the path to delivering measurable results with continuous monitoring and auditing. This class builds on a highly-reviewed program in Atlanta delivered earlier this year.
We will discuss overall methodology, detailed design for constructing a CA program, talk about current technology, and demonstrate how to turn “CA” into “CM” to benefit your entire organization.
Outcomes from the class will include a Company-specific roadmap, customized for your business and stakeholders, to target the risks you identify and benefits you want to achieve.
Attendees will receive up to 7.5 hours of NASBA-compliant CPE and accomplish the following learning objectives.
1. Business challenges today, and how early detection mitigates greater risks
2. Working definitions of CCM, CM and CA and supporting technologies
3. How to determine where your organization is on the CA/CM maturity model
4. Hurdles to CM/CA implementation and how to overcome them
5. How to dive deeper to determine specific needs in developing the roadmap for CM/CA implementations
6. Proven methods for engaging other stakeholders
For more information, see the following Registration page to download a more detailed program description.
We will discuss overall methodology, detailed design for constructing a CA program, talk about current technology, and demonstrate how to turn “CA” into “CM” to benefit your entire organization.
Outcomes from the class will include a Company-specific roadmap, customized for your business and stakeholders, to target the risks you identify and benefits you want to achieve.
Attendees will receive up to 7.5 hours of NASBA-compliant CPE and accomplish the following learning objectives.
1. Business challenges today, and how early detection mitigates greater risks
2. Working definitions of CCM, CM and CA and supporting technologies
3. How to determine where your organization is on the CA/CM maturity model
4. Hurdles to CM/CA implementation and how to overcome them
5. How to dive deeper to determine specific needs in developing the roadmap for CM/CA implementations
6. Proven methods for engaging other stakeholders
For more information, see the following Registration page to download a more detailed program description.
Wednesday, June 15, 2011
Continuous Auditing and Monitoring Bootcamp Scheduled in Atlanta
Visual Risk IQ will be leading a one-day workshop in Atlanta, hosted by the Georgia Society of CPA's. The workshop is designed to help you get started on the path to delivering measurable results with continuous monitoring and auditing.
We will discuss overall methodology, detailed design for constructing a CA program, talk about current technology, and demonstrate how to turn “CA” into “CM” to benefit your entire organization.
Outcomes from the class will include a Company-specific roadmap, customized for your business and stakeholders, to target the risks you identify and benefits you want to achieve.
Attendees will receive up to seven hours of NASBA-compliant CPE and accomplish the following learning objectives.
1. Business challenges today, and how early detection mitigates greater risks
2. Working definitions of CCM, CM and CA and supporting technologies
3. How to determine where your organization is on the CA/CM maturity model
4. Hurdles to CM/CA implementation and how to overcome them
5. How to dive deeper to determine specific needs in developing the roadmap for CM/CA implementations
6. Proven methods for engaging other stakeholders
For more information, see the following Registration page, or see our Events webpage to download a more detailed description.
We will discuss overall methodology, detailed design for constructing a CA program, talk about current technology, and demonstrate how to turn “CA” into “CM” to benefit your entire organization.
Outcomes from the class will include a Company-specific roadmap, customized for your business and stakeholders, to target the risks you identify and benefits you want to achieve.
Attendees will receive up to seven hours of NASBA-compliant CPE and accomplish the following learning objectives.
1. Business challenges today, and how early detection mitigates greater risks
2. Working definitions of CCM, CM and CA and supporting technologies
3. How to determine where your organization is on the CA/CM maturity model
4. Hurdles to CM/CA implementation and how to overcome them
5. How to dive deeper to determine specific needs in developing the roadmap for CM/CA implementations
6. Proven methods for engaging other stakeholders
For more information, see the following Registration page, or see our Events webpage to download a more detailed description.
Friday, November 5, 2010
Top 10 Things that Go Wrong in a Continuous Auditing Project
Very nice summary from Patrick Taylor from Oversight Systems of their experiences from CA and CCM implementation. Patrick did a very good job of sharing examples and screen shots of how their tool are being configured to monitor both routine and non-routine transactions.
10. Compliance is the Lead
9. Your eyes are bigger than your stomach (you try to monitor everything)
8. Look through this report please (tedious, there's no bottom to the report)
7. Let's learn a specialized analysis language (instead of SQL)
6. Let's clean up the last two years of exceptions (10000++ exceptions. Yikes!)
5. Continuous Audit instead of Continuous Improvement (i.e. Use Reason Codes)
4. Don't know how to spell Vasarhelee, Vaserheyli, Vasarhellee, Vasarhelyi... (LOL!)
3. Only know how to Audit AP (other apps are
2. Bringing a knife to a gun fight. (re-testing what is already controlled by ERP)
1. Not Using Oversight (LOL x 2)
10. Compliance is the Lead
9. Your eyes are bigger than your stomach (you try to monitor everything)
8. Look through this report please (tedious, there's no bottom to the report)
7. Let's learn a specialized analysis language (instead of SQL)
6. Let's clean up the last two years of exceptions (10000++ exceptions. Yikes!)
5. Continuous Audit instead of Continuous Improvement (i.e. Use Reason Codes)
4. Don't know how to spell Vasarhelee, Vaserheyli, Vasarhellee, Vasarhelyi... (LOL!)
3. Only know how to Audit AP (other apps are
2. Bringing a knife to a gun fight. (re-testing what is already controlled by ERP)
1. Not Using Oversight (LOL x 2)
Wednesday, June 23, 2010
Reflections on IIA International - Input for Continuous Auditing Global Technology Audit Guide (GTAG)
At IIA International conference this month, three of the more interesting presentations were by Dan Kneer, Steve Biskie (ACL Services) and Robert Mainardi. Each presenter spoke on some combination of Continuous Auditing and Continuous Monitoring, but if you attended all three session, you could easily come away a bit confused. While some or even many of the same words were used in the same sessions, each presenter's perspective on Continuous Auditing was quite different.
Steve Biskie is Best Practices Program Director for ACL Services, who writes market-leading data analysis software for internal auditors. ACL software like its peers from IDEA and SAS, among others, is an excellent tool for exception queries and structured data. At Visual Risk IQ, we use IDEA and ACL to analyze millions of records and isolate dozens of exceptions to be investigated by internal auditors. Results are often high-value, and can be made repeatable (i.e. Continual or Continuous Auditing) by automating data extraction and combining with workflow. Caseware Monitor (formerly known as SymSure for IDEA) and ACL's AX/2 are examples of emerging tools for continuous auditing.
Dr. Dan Kneer has retired from Academia and runs a firm called Dan Kneer Advisors. The Holy Grail of auditing according to Dr. Dan is regression analysis, and he advocates using the tool "already on every auditor laptop" (i.e. Microsoft Excel). Dr. Dan focuses on trending queries (e.g. the relationship between sales and costs of sales, or between sales and commissions) to identify outliers to be investigated in greater detail. Trending queries like regression analysis are highly useful, but we would advocate their use together with exception queries. And since IDEA and ACL each have regression analysis features, we would advocate using those tools instead of Excel due to improved audit trails and logging, as well as ability to work with datasets larger than 1 million rows. Dr. Dan's emphasis on analytical procedures have merit, and should be a component of a Continuous Auditing program.
Robert Mainardi's classes on continuous auditing receive high evaluations, in part because he keeps it simple. Strengths include visual reporting of risks and controls (color-coded heatmaps in MS-Office) and consistently reporting the results of audit procedures. A downside, per SAP's Norman Marks, is that "Mainardi designs continuous audit programs for clients that has limited use of technology. Missing the boat" We respectfully disagree with Mr. Marks. Instead of focusing on what's missing, let's focus on what's there. We see Mainardi's glass as at least half full, and would recommend that trending queries and exception queries be combined as part of the continuing auditing that Mainardi recommends.
Steve Biskie is Best Practices Program Director for ACL Services, who writes market-leading data analysis software for internal auditors. ACL software like its peers from IDEA and SAS, among others, is an excellent tool for exception queries and structured data. At Visual Risk IQ, we use IDEA and ACL to analyze millions of records and isolate dozens of exceptions to be investigated by internal auditors. Results are often high-value, and can be made repeatable (i.e. Continual or Continuous Auditing) by automating data extraction and combining with workflow. Caseware Monitor (formerly known as SymSure for IDEA) and ACL's AX/2 are examples of emerging tools for continuous auditing.
Dr. Dan Kneer has retired from Academia and runs a firm called Dan Kneer Advisors. The Holy Grail of auditing according to Dr. Dan is regression analysis, and he advocates using the tool "already on every auditor laptop" (i.e. Microsoft Excel). Dr. Dan focuses on trending queries (e.g. the relationship between sales and costs of sales, or between sales and commissions) to identify outliers to be investigated in greater detail. Trending queries like regression analysis are highly useful, but we would advocate their use together with exception queries. And since IDEA and ACL each have regression analysis features, we would advocate using those tools instead of Excel due to improved audit trails and logging, as well as ability to work with datasets larger than 1 million rows. Dr. Dan's emphasis on analytical procedures have merit, and should be a component of a Continuous Auditing program.
Robert Mainardi's classes on continuous auditing receive high evaluations, in part because he keeps it simple. Strengths include visual reporting of risks and controls (color-coded heatmaps in MS-Office) and consistently reporting the results of audit procedures. A downside, per SAP's Norman Marks, is that "Mainardi designs continuous audit programs for clients that has limited use of technology. Missing the boat" We respectfully disagree with Mr. Marks. Instead of focusing on what's missing, let's focus on what's there. We see Mainardi's glass as at least half full, and would recommend that trending queries and exception queries be combined as part of the continuing auditing that Mainardi recommends.
A continuous auditing program that includes one of the above techniques would add value for most any organization. A program that includes each of these techniques should be considered world-class.
Monday, March 22, 2010
Reflections on Mid-Atlantic District Conference - Continuous Auditing presentation
Continuous Auditing meets Continuous Improvement.
Along with colleagues Dr. George Aldhizer (Wake Forest University), Kathy Hardwick (Audit Relationship Manager of Arrowpoint Capital), and David Payseur (Chief Audit Executive of Arrowpoint Capital), I helped present our Continuous Auditing Maturity Model for the Charlotte, Raleigh, and Triad IIA Chapters last week at the District Conference in Charlotte. Thanks to each of the co-presenters, and especially to David who suggested that we update the material published in WG&L's Internal Auditing in Sept / Oct 2009.
Though we had presented together before, I was struck by how the material had evolved from our prior presentations. George Aldhizer updated his segment to provide an overview of Text Analytics. Text Analytics (i.e., tools that are used to analyze unstructured data such as email and other text-based documents) can identify, classify, and parse words and clusters of words in electronic documents. These tools are more commonly used in Forensic analysis, but depending on industry and business risk, he recommended that they be considered as part of an overall Data Analysis program. We agree with his assessment, and see application in journal entry analysis and other anti-fraud programs.
Kathy and David provided an update of the Continuous Auditing program at Arrowpoint. For those of you unfamiliar with Arrowpoint, they have had a data-driven Continuous Auditing (CA) program since 2003. Their CA program is fully integrated with Enterprise Risk Management and provides monthly reporting to executive management and the Board on assessment of risks and controls. Arrowpoint is among the most advanced of all CA programs that we have met with, regardless of industry. Most noteworthy for me last week was how the depth and breadth of their data analysis routines keeps improving. Some tests have migrated to the business from Internal Audit, while other tests are run more frequently or less frequently, based on past results and risk assessment.
Our update included an overview of Visual Risk IQ's QuickStart methodology, which we use to help separate the business-focused activities in a CA program from other more technical tasks. One of the common misconceptions about data analysis is that it is an "IT Audit" activity, because some of the tasks require some intermediate or even advanced technical skills for data acquisition. QuickStart separates data acquisition and script-writing tasks from analysis and reporting, so that business auditors are primarily responsible for reviewing query results and reporting on them. Feedback from Arrowpoint, from our clients, and also training sessions like the District Conference reinforce the importance of that approach.
Joe Oringel
Visual Risk IQ
Charlotte NC, USA
Along with colleagues Dr. George Aldhizer (Wake Forest University), Kathy Hardwick (Audit Relationship Manager of Arrowpoint Capital), and David Payseur (Chief Audit Executive of Arrowpoint Capital), I helped present our Continuous Auditing Maturity Model for the Charlotte, Raleigh, and Triad IIA Chapters last week at the District Conference in Charlotte. Thanks to each of the co-presenters, and especially to David who suggested that we update the material published in WG&L's Internal Auditing in Sept / Oct 2009.
Though we had presented together before, I was struck by how the material had evolved from our prior presentations. George Aldhizer updated his segment to provide an overview of Text Analytics. Text Analytics (i.e., tools that are used to analyze unstructured data such as email and other text-based documents) can identify, classify, and parse words and clusters of words in electronic documents. These tools are more commonly used in Forensic analysis, but depending on industry and business risk, he recommended that they be considered as part of an overall Data Analysis program. We agree with his assessment, and see application in journal entry analysis and other anti-fraud programs.
Kathy and David provided an update of the Continuous Auditing program at Arrowpoint. For those of you unfamiliar with Arrowpoint, they have had a data-driven Continuous Auditing (CA) program since 2003. Their CA program is fully integrated with Enterprise Risk Management and provides monthly reporting to executive management and the Board on assessment of risks and controls. Arrowpoint is among the most advanced of all CA programs that we have met with, regardless of industry. Most noteworthy for me last week was how the depth and breadth of their data analysis routines keeps improving. Some tests have migrated to the business from Internal Audit, while other tests are run more frequently or less frequently, based on past results and risk assessment.
Our update included an overview of Visual Risk IQ's QuickStart methodology, which we use to help separate the business-focused activities in a CA program from other more technical tasks. One of the common misconceptions about data analysis is that it is an "IT Audit" activity, because some of the tasks require some intermediate or even advanced technical skills for data acquisition. QuickStart separates data acquisition and script-writing tasks from analysis and reporting, so that business auditors are primarily responsible for reviewing query results and reporting on them. Feedback from Arrowpoint, from our clients, and also training sessions like the District Conference reinforce the importance of that approach.
Joe Oringel
Visual Risk IQ
Charlotte NC, USA
Tuesday, November 10, 2009
Reflections from the Rutgers World Continuous Auditing Symposium (WCAS)
I represented Visual Risk IQ as a panelist Friday 11/6 at the Rutgers WCAS event in New Jersey. Mike Cangemi, former president of FEI moderated our panel, which also included Eric Cohen from PwC / OCEG, and Dr. Virginia Cortijo from University of Huelva (Spain). Despite the presentation time on a Friday afternoon (4:00!), the panel generated nearly a dozen questions from the audience, and dialog continued into the dinner hour.
The event provided opportunity to reconnect with friends and colleagues from most of the CA / CCM software firms, from academia, and most importantly, with other early adopters of CA / CCM. Most attendees had already committed to some level of CA / CCM at their firms, each with varying levels of success. Some observations from the presentations:
The event provided opportunity to reconnect with friends and colleagues from most of the CA / CCM software firms, from academia, and most importantly, with other early adopters of CA / CCM. Most attendees had already committed to some level of CA / CCM at their firms, each with varying levels of success. Some observations from the presentations:
- External auditors opine on a balance sheet as of one day each year. Not much continuous about that. Internal Auditing should be leading the charge for Continuous Auditing.
- Most CCM applications focus on a single application - P-Card, Procure to Pay, or Journal Entry review, likely because of simpler data models and availability of commercial software. Exceptions are IBM (Order to Cash) and HP (IT General Controls)
- Organizations that are the best candidates for CCM are those that have a zero tolerance for Compliance exceptions and also a relentless desire for Continuous Improvement.
- Internal audit can be the CA / CCM learning lab for the rest of Company. See Terry Hickman's presentation (Proctor & Gamble) for more information.
- Most savings realized by audit teams through Continuous Auditing are re-directed toward emerging risks and increasing coverage.
- Continuous auditing and data analytics jobs are out there, but the quantity and quality of applicants has been below expectations, according to several hiring managers.
- New software entrants such as SymSure for IDEA and ACL's Audit Exchange 2 (AX2) are sparking new projects in CA, as their price point is a marked improvement relative to more comprehensive CCM tools that have previously been available.
Our presentation emphasized some of the challenges of defining Continuous Auditing. At some organizations, the term means Continuous Risk Assessment. At others, it means Control Assessment of configurable controls or Control Assessment of Transactions. If people that are doing CA / CCM use the same words for different activities, it's hard for others to follow this leadership. For more information on the conference, see: Rutgers WCAS.
Did you attend? What were your key take-aways. All comments are welcomed!
Joe Oringel
Visual Risk IQ
Charlotte NC, USA
Did you attend? What were your key take-aways. All comments are welcomed!
Joe Oringel
Visual Risk IQ
Charlotte NC, USA
Tuesday, October 13, 2009
Continuous Auditing Article accepted for publication in Internal Auditing
We received news that an article submitted jointly with Dr. George Aldhizer of Wake Forest University's has been accepted for publication by Thomson Reuters in their Internal Auditing publication for the September / October issue that will be mailed to subscribers shortly. Very timely, as Dr. Aldhizer, David Payseur (CAE of Arrowpoint Capital), and I are scheduled to present a Continuous Auditing CPE day in Winston-Salem NC on November 18, 2009.
The article describes Visual Risk IQ's Continuous Auditing Maturity model, and how the steps from moving from Basic data analysis toward Continuous Auditing requires more than just technology investments. Changes in audit methodology and especially reporting process are integral and equally important to such a journey.
The article profiles Arrowpoint Capital, a commercial property casualty run-off insurance carrier that is headquartered in Charlotte, NC, whose continuous auditing program is more than five years old and actually pre-dates the IIA's GTAG publication on Continuous Auditing. Arrowpoint has an established, data-driven ERM program that links the results of Continuous Auditing activities and query scripts to specific risk assessment and control assessment activities that is reported monthly to management and the board.
For more information, check back on how to order reprints and/or to come see us in Winston-Salem in November for the Triad CPE day.
Joe Oringel
Visual Risk IQ
Charlotte NC, USA
Labels:
Arrowpoint Captial,
Continuous Auditing,
ERM,
GTAG #3,
Internal Auditing
Sunday, September 20, 2009
Another CFO Article on Continuous Auditing - Correct about Vocabulary. Incorrect about no one doing it well.
We appreciate CFO Magazine writing about Continuous Auditing (CA) again. This month's piece is better than previous efforts, in that it focuses much more on the process changes needed for CA, and less on the actual technology that is used to accomplish CA, as we have blogged about previously. CFO Magazine interviewed several industry and academic leaders for this article - alas they didn't reach out to Visual Risk IQ, at least yet. So in today's blog, we'll summarize some of our observations and experiences about CA and contrast them to the CFO article. The centerpiece of our thoughts on CA is our proprietary maturity model, which we use to chart company-specific actions that help organizations advance on this journey. We'll also suggest one or two other organizations that CFO Magazine might talk to so that a clearer picture of CA can develop. In any case, we certainly echo the author's point, that a common, practical definition of CA is not yet accepted in the industry.
For this article, the author interviewed HCA, Microsoft, and AEP - and profiled how each organization uses CA. We feel especially qualified to comment on the article, because Kim Jones and I have been working almost exclusively on CA since our days at PwC in 2006, where he was a key team member on the Microsoft project cited in the article. We also count both HCA and AEP among our circle of friends from the speaking and writing that we each do in the Internal Audit community.
My counsel to the author would be to separate Continuous (which is really Continual) Risk Assessment from Continuous Controls Assessment. One of the reasons that there are such varying definitions of CA, are that are a diverse number of objectives that can be accomplished with CA and especially Continuous Controls Monitoring for Transactions (CCM-T). Organizations that set out to allocate their audit resources based on more up-to-date information than an annual risk assessment are likely to begin their CA efforts here. Companies profiled publicly in articles and cases that match this CA description include McDonald's and Wells Fargo, and usually have a very large number of audit entities (i.e. Stores or Branches), that make it difficult to visit each entity in a three- or five-year audit cycle. We have assisted several organizations to be more like McDonald's and Wells Fargo, by using data to perform more frequent, data-driven risk assessments to allocate their audit resources. Most often, the data used for this activity is aggregate financial or operational information like Financial Performance vs. Budget, Performance Ratios, or Employee Turnover. While it appears from the quotes from Jay Hoffman at AEP that his team is doing Continuous Risk Assessment, the controls being tested per the article seem to be more specific to Continuous Controls Assessment, which is using data-driven techniques to provide greater depth and frequency of audit coverage.
Continuous Controls Assessment are the techniques profiled in the article at HCA, AEP, and Microsoft. Instead of auditing overtime or journal entries only once every two or three years, many organizations use repeating data analysis scripts to assess the effectiveness of a control at multiple intervals during a year. These techniques can alert management to emerging issues with fraud risk or compliance, and also assist in following up on previous audit findings.
At Visual Risk IQ, we assert that "real continuous auditing" is to more fully integrate the Continuous Controls Assessment with Continuous Risk Assessment, so that audit project selection is based on the effectiveness of frequent, data-driven control assessment activities. Example: "What should be next on the audit plan - let's go to the regional office that hit their sales budget (to the penny!), but hasn't updated their allowance for doubtful accounts since the new accounting manager was hired six months ago."
I can think of two or three organizations that are doing real continuous auditing, according to this definition. Both Arrowpoint Capital in Charlotte and RLI Corporation in Peoria have presented at national and regional IIA / MISTI conferences about their CA programs, which originated with repeating the data analysis routines that were used for control assessment. While neither is a household name like Microsoft or HCA, each have been doing CA for more than five years, and are quite mature in their use of data for both control assessment and risk assessment.
In closing the article does a good job of distinguishing between CA and CM (continuous monitoring), which are activities performed by management. The evolution of CA to CM is a particular mark of growing CA maturity. Our work with CM, and especially CCM-T, has allowed us to help management use technology to test the right controls, at the right time, to achieve spectacularly effective results in business performance and internal controls. CA is often the first step on that journey.
Joe Oringel
Visual Risk IQ
Charlotte NC, USA
Wednesday, November 12, 2008
Continuous Auditing Maturity Model presented in Chicago
This past week, we presented an overview of Continuous Auditing and Monitoring to a group of internal audit and compliance executives in Chicago, IL. The session focused on the Continuous Auditing Maturity Model, and provided specific guidance on how to get started with data mining and data analysis, as well as more advanced advice on increasing frequency and progressing toward continuous auditing.
The session was attended by a diverse group of attendees from a variety of industries and functional backgrounds. Experience with data analysis ranged from "not started" to regular use of ACL and IDEA, and each attendee was able to take away practical advice to help them with their specific situation and risk profile.
Visual Risk IQ and Vonya Global, a Chicago-based consulting firm specializing in Internal Audit, co-sponsored the event, and Vonya hosted the event at their offices on N. Michigan Avenue. Feedback from attendees was very positive, and we expect to co-sponsor similar events together in the new year.
To obtain a copy of the slide deck used at the event, please email joe.oringel@visualriskiq.com or call 704-752-6403.
Regards,
Joe Oringel
Visual Risk IQ
Charlotte NC, USA
The session was attended by a diverse group of attendees from a variety of industries and functional backgrounds. Experience with data analysis ranged from "not started" to regular use of ACL and IDEA, and each attendee was able to take away practical advice to help them with their specific situation and risk profile.
Visual Risk IQ and Vonya Global, a Chicago-based consulting firm specializing in Internal Audit, co-sponsored the event, and Vonya hosted the event at their offices on N. Michigan Avenue. Feedback from attendees was very positive, and we expect to co-sponsor similar events together in the new year.
To obtain a copy of the slide deck used at the event, please email joe.oringel@visualriskiq.com or call 704-752-6403.
Regards,
Joe Oringel
Visual Risk IQ
Charlotte NC, USA
Monday, September 8, 2008
Expense Management becoming Mainstream?
We've been talking about using Continuous Auditing and Continuous Monitoring as ways to improve compliance and business performance for more than two years. The approach is characterized as "ask once, satisfy many," where business process owners can satisfy compliance objectives such as segregation of duties or spending authority limits, while also evaluating operational objectives like contract compliance and pricing.
CFO Magazine's September issue is highlighting some of the technologies that can accomplish these objectives.
The CFO article is very consistent with our experiences. Clients and business partners of Visual Risk IQ know that we can help review Accounts Payable, P-Card, and T&E data, looking for duplicate payments, financial fraud, and contract compliance. In the last several months, we've been expanding our service capabilities to deliver even more value for our clients.
My favorite quote in the article talks about the costs for such services. "For $50,000 to $100,000, a horde of consultants will sift through invoices, purchase orders, and contracts and produce a report, most likely on one facet of the business. Or, for $100,000 to $500,000, you can tap software that will do it for all aspects of the business all the time." People familiar with Visual Risk IQ know that our firm uses the continuous auditing software described in the article, to help organizations test-drive and prove its value for their organization, for less than the typical fees from the "horde of consultants."
The data files that we already use to provide a 100%, in-depth review of expenses for compliance and potential fraud factors can also be used to test for spending compliance. We have partnered with firms who are expert in selling and general & administrative cost reduction, and can analyze these same data files to identify the opportunities for improving expense management.
Joe Oringel
Visual Risk IQ
Charlotte NC, USA
CFO Magazine's September issue is highlighting some of the technologies that can accomplish these objectives.
The CFO article is very consistent with our experiences. Clients and business partners of Visual Risk IQ know that we can help review Accounts Payable, P-Card, and T&E data, looking for duplicate payments, financial fraud, and contract compliance. In the last several months, we've been expanding our service capabilities to deliver even more value for our clients.
My favorite quote in the article talks about the costs for such services. "For $50,000 to $100,000, a horde of consultants will sift through invoices, purchase orders, and contracts and produce a report, most likely on one facet of the business. Or, for $100,000 to $500,000, you can tap software that will do it for all aspects of the business all the time." People familiar with Visual Risk IQ know that our firm uses the continuous auditing software described in the article, to help organizations test-drive and prove its value for their organization, for less than the typical fees from the "horde of consultants."
The data files that we already use to provide a 100%, in-depth review of expenses for compliance and potential fraud factors can also be used to test for spending compliance. We have partnered with firms who are expert in selling and general & administrative cost reduction, and can analyze these same data files to identify the opportunities for improving expense management.
Joe Oringel
Visual Risk IQ
Charlotte NC, USA
Labels:
CFO Magazine,
Continuous Auditing,
Expense reduction
Saturday, April 5, 2008
New Entrant - Reliant Audit Solutions
As we did in 2007, my partner Kim Jones and I attended the IIA's General Audit Management (GAM) conference. The conference provided an excellent venue to renew relationships with clients and prospects, and as always, also provided interesting opportunities to meet with other service firms and software firms.
One new entrant in the Continuous Auditing software arena emerged at the GAM conference - a software firm called Reliant Audit Solutions, from Laguna Niguel, CA. Their CEO, Dipak Shah, has assembled a team with strong enterprise software experience, including software from the GRC space. We were especially impressed with their Marketing VP, who was with Logical Apps prior to their acquisition by Oracle. While we've not done a deep dive yet on their software, we were intrigued with what we saw, and will continue to investigate and report on what we learn.
Kim and I had met Dipak Shah at an IIA technology conference in 2007, when his firm was called DBExcel. At the time, he described his vision for an integrated, real-time auditing and monitoring system that would consider both configuration controls and transaction controls. In addition to controls monitoring, it would also serve as a document repository to assist audit or GRC executives with keeping the records that could demonstrate compliance. For more infomation, see www.reliantaudit.com
From first glance, he and his team at Reliant Audit are staying true to that vision. We look forward to staying connected with them as they grow.
Joe Oringel
Visual Risk IQ
Charlotte NC, USA
One new entrant in the Continuous Auditing software arena emerged at the GAM conference - a software firm called Reliant Audit Solutions, from Laguna Niguel, CA. Their CEO, Dipak Shah, has assembled a team with strong enterprise software experience, including software from the GRC space. We were especially impressed with their Marketing VP, who was with Logical Apps prior to their acquisition by Oracle. While we've not done a deep dive yet on their software, we were intrigued with what we saw, and will continue to investigate and report on what we learn.
Kim and I had met Dipak Shah at an IIA technology conference in 2007, when his firm was called DBExcel. At the time, he described his vision for an integrated, real-time auditing and monitoring system that would consider both configuration controls and transaction controls. In addition to controls monitoring, it would also serve as a document repository to assist audit or GRC executives with keeping the records that could demonstrate compliance. For more infomation, see www.reliantaudit.com
From first glance, he and his team at Reliant Audit are staying true to that vision. We look forward to staying connected with them as they grow.
Joe Oringel
Visual Risk IQ
Charlotte NC, USA
Sunday, March 16, 2008
Observations from the IIA District Conference in Greensboro NC - it's not about Software
Visual Risk IQ presented a session on Continuous Controls Monitoring (CCM) at the IIA's District Conference in Greensboro on March 14, and we had nearly 100 people join us for a dialog about how to get started with CCM and/or Continuous Auditing (CA). Several of the audience had seen us at either Triad or Charlotte CCM / CA training sessions, either alone or with ACL, Oversight, or Apex Analytix.
So to create some distinction from other CPE sessions we've made, we focused mostly on the maturity model and recommended first steps to move from current state toward a mature, highly frequent and in-depth process for risk and control assessment. We de-emphasized that the technology components and emphasized the importance of audit process, risk assessment approach, gaining buy-in from business process owners, training for IA staff. The non-technology components of embarking on a project.
Something very interesting happened. The Q&A was more lively. The audience was highly engaged, and a couple of audit directors came up to us after the presentation to thank us for NOT talking so much about software. It seems they hear (way too often) about the ways Brand X, Brand Y, or Brand Z software can make their audit function better. But their experience is that any prior technology investments are often short-lived because the technology often requires other changes to be made, and those changes are not well understood or sustained.
So we'll continue to talk about our experiences and approach to CA and CCM, including how more modern software can often help. But any discussion of software will be a late bind, and we'll start with emphasizing how audit functions can achieve marked increases in productivity, simply by better utilizing tools they already have.
Feel free to write or comment, and we'll share our presentation with you if you were unable to attend the Conference in Greensboro.
Joe Oringel
Visual Risk IQ
Charlotte NC, USA
www.visualriskiq.com
So to create some distinction from other CPE sessions we've made, we focused mostly on the maturity model and recommended first steps to move from current state toward a mature, highly frequent and in-depth process for risk and control assessment. We de-emphasized that the technology components and emphasized the importance of audit process, risk assessment approach, gaining buy-in from business process owners, training for IA staff. The non-technology components of embarking on a project.
Something very interesting happened. The Q&A was more lively. The audience was highly engaged, and a couple of audit directors came up to us after the presentation to thank us for NOT talking so much about software. It seems they hear (way too often) about the ways Brand X, Brand Y, or Brand Z software can make their audit function better. But their experience is that any prior technology investments are often short-lived because the technology often requires other changes to be made, and those changes are not well understood or sustained.
So we'll continue to talk about our experiences and approach to CA and CCM, including how more modern software can often help. But any discussion of software will be a late bind, and we'll start with emphasizing how audit functions can achieve marked increases in productivity, simply by better utilizing tools they already have.
Feel free to write or comment, and we'll share our presentation with you if you were unable to attend the Conference in Greensboro.
Joe Oringel
Visual Risk IQ
Charlotte NC, USA
www.visualriskiq.com
Wednesday, March 12, 2008
Defining Continuous-ness. One more reason why I love my mother-in-law
Donna, my mother-in-law, is a terrific lady. I remember meeting my then future in-laws less than a month after my wife and I began dating. They were fun, light-hearted, and affectionate toward their immediate family, extended family, and each other. Throughout literally dozens of moves across the country through a military career, they remain in touch with their many friends. Often via Donna's holiday letter. Which brings me to continuous auditing. Really.
This year, as she has during their forty-plus years of marriage, Donna recounted an update of their family's travels, joys, and important life events. Included in this years business was an update on my immediate family and a brief mention of my new business. "Joe has started a business focused on continual auditing..." Which brought about an interesting discussion about continuous-ness and continual.
Our dictionary makes a clear distinction between continuous and continual. "In precise usage, continual means 'frequent, repeating at intervals' and continuous means 'going on without pause or interruption" and provides instruction to "Avoid using continuous or continuously as a way of describing something that occurs at regular or seasonal intervals: in the sentence, "The White House's tree-lighting ceremony has been held continuously since 1923, the word continuously should be replaced with continually or annually."
So my mother-in-law is right. After all, we're trying to help our clients update the frequency of their risk and control assessments to be quarterly or monthly. And to assess some key controls as frequently as weekly or daily. But not to assess risk or controls without pause or interruption.
My partner Kim Jones and I have often talked about how continuous auditing should be about working smarter, not harder. Doing more with less. So stay tuned and see how we can begin to make this new label stick.
Joe Oringel
Visual Risk IQ
Charlotte NC, USA
This year, as she has during their forty-plus years of marriage, Donna recounted an update of their family's travels, joys, and important life events. Included in this years business was an update on my immediate family and a brief mention of my new business. "Joe has started a business focused on continual auditing..." Which brought about an interesting discussion about continuous-ness and continual.
Our dictionary makes a clear distinction between continuous and continual. "In precise usage, continual means 'frequent, repeating at intervals' and continuous means 'going on without pause or interruption" and provides instruction to "Avoid using continuous or continuously as a way of describing something that occurs at regular or seasonal intervals: in the sentence, "The White House's tree-lighting ceremony has been held continuously since 1923, the word continuously should be replaced with continually or annually."
So my mother-in-law is right. After all, we're trying to help our clients update the frequency of their risk and control assessments to be quarterly or monthly. And to assess some key controls as frequently as weekly or daily. But not to assess risk or controls without pause or interruption.
My partner Kim Jones and I have often talked about how continuous auditing should be about working smarter, not harder. Doing more with less. So stay tuned and see how we can begin to make this new label stick.
Joe Oringel
Visual Risk IQ
Charlotte NC, USA
Labels:
Continual Auditing,
Continuous Auditing,
GTAG #3
Tuesday, February 5, 2008
Back on Line - Continuous Auditing and Fraud Blog
Hi - welcome. You found us.
After a six-month hiatus due to some technical challenges related an Apple iLife '06 to iLife '08 upgrade, our Continuous Auditing blog returns. Now hosted by Google's Blogger, my Visual Risk IQ partner Kim Jones and I will endeavor to keep you posted on interesting (to us) stories in the news related to internal auditing and fraud. We intend to focus on stories which demonstrate the business value of more frequent and more in-depth internal control or risk assessment.
We welcome any comments or suggestions.
Joe Oringel
Visual Risk IQ
Charlotte, North Carolina, USA
www.visualriskiq.com
After a six-month hiatus due to some technical challenges related an Apple iLife '06 to iLife '08 upgrade, our Continuous Auditing blog returns. Now hosted by Google's Blogger, my Visual Risk IQ partner Kim Jones and I will endeavor to keep you posted on interesting (to us) stories in the news related to internal auditing and fraud. We intend to focus on stories which demonstrate the business value of more frequent and more in-depth internal control or risk assessment.
We welcome any comments or suggestions.
Joe Oringel
Visual Risk IQ
Charlotte, North Carolina, USA
www.visualriskiq.com
Subscribe to:
Posts (Atom)