Showing posts with label Continuous Controls Monitoring. Show all posts
Showing posts with label Continuous Controls Monitoring. Show all posts

Saturday, November 5, 2011

Another Saturday Morning in Newark NJ

Very energizing sessions this morning, as we heard from a Who's Who of large, multinational firms who have implemented CA and CM solutions. Siemens Financial Services led things off with their "Road to Continuous Assurance," as Jason Gross leads a mature CM function that was born in Internal Audit and has migrated to the CFO's office. His deck is downloadable at: http://raw.rutgers.edu/23WCARS

Brad Ames from HP followed with another strong presentation on using CA / CCM for assessing both IT controls and Financial Controls. @43Chase and @debreceny observed that strong IT controls help enable strong financial controls. I was focused on their use of dashboards at HP, and have asked for examples. Stay tuned.

Dave Levin of Proctor & Gamble followed with a strong session on the use of data-driven risk assessments. They compare results of Control Self Assessment and actual audit results, using outliers and differences between management's assessment (i.e. CSA) internal audit's evaluation as input into Internal Audit's risk assessment. Dave's session is available for download at this link.

Thursday, August 11, 2011

Continuous Auditing and Monitoring Bootcamp Scheduled in Houston

Visual Risk IQ will be leading a one-day workshop in Houston on Tuesday 9/27, hosted by the Texas Society of CPA's. The workshop is designed to help you get started on the path to delivering measurable results with continuous monitoring and auditing. This class builds on a highly-reviewed program in Atlanta delivered earlier this year.

We will discuss overall methodology, detailed design for constructing a CA program, talk about current technology, and demonstrate how to turn “CA” into “CM” to benefit your entire organization.

Outcomes from the class will include a Company-specific roadmap, customized for your business and stakeholders, to target the risks you identify and benefits you want to achieve.

Attendees will receive up to 7.5 hours of NASBA-compliant CPE and accomplish the following learning objectives.

1. Business challenges today, and how early detection mitigates greater risks
2. Working definitions of CCM, CM and CA and supporting technologies
3. How to determine where your organization is on the CA/CM maturity model
4. Hurdles to CM/CA implementation and how to overcome them
5. How to dive deeper to determine specific needs in developing the roadmap for CM/CA implementations
6. Proven methods for engaging other stakeholders

For more information, see the following Registration page to download a more detailed program description.


Wednesday, June 15, 2011

Continuous Auditing and Monitoring Bootcamp Scheduled in Atlanta

Visual Risk IQ will be leading a one-day workshop in Atlanta, hosted by the Georgia Society of CPA's. The workshop is designed to help you get started on the path to delivering measurable results with continuous monitoring and auditing.

We will discuss overall methodology, detailed design for constructing a CA program, talk about current technology, and demonstrate how to turn “CA” into “CM” to benefit your entire organization.

Outcomes from the class will include a Company-specific roadmap, customized for your business and stakeholders, to target the risks you identify and benefits you want to achieve.

Attendees will receive up to seven hours of NASBA-compliant CPE and accomplish the following learning objectives.

1. Business challenges today, and how early detection mitigates greater risks
2. Working definitions of CCM, CM and CA and supporting technologies
3. How to determine where your organization is on the CA/CM maturity model
4. Hurdles to CM/CA implementation and how to overcome them
5. How to dive deeper to determine specific needs in developing the roadmap for CM/CA implementations
6. Proven methods for engaging other stakeholders

For more information, see the following Registration page, or see our Events webpage to download a more detailed description.

Tuesday, November 10, 2009

Reflections from the Rutgers World Continuous Auditing Symposium (WCAS)

I represented Visual Risk IQ as a panelist Friday 11/6 at the Rutgers WCAS event in New Jersey. Mike Cangemi, former president of FEI moderated our panel, which also included Eric Cohen from PwC / OCEG, and Dr. Virginia Cortijo from University of Huelva (Spain). Despite the presentation time on a Friday afternoon (4:00!), the panel generated nearly a dozen questions from the audience, and dialog continued into the dinner hour.

The event provided opportunity to reconnect with friends and colleagues from most of the CA / CCM software firms, from academia, and most importantly, with other early adopters of CA / CCM. Most attendees had already committed to some level of CA / CCM at their firms, each with varying levels of success. Some observations from the presentations:
  • External auditors opine on a balance sheet as of one day each year. Not much continuous about that. Internal Auditing should be leading the charge for Continuous Auditing.
  • Most CCM applications focus on a single application - P-Card, Procure to Pay, or Journal Entry review, likely because of simpler data models and availability of commercial software. Exceptions are IBM (Order to Cash) and HP (IT General Controls)
  • Organizations that are the best candidates for CCM are those that have a zero tolerance for Compliance exceptions and also a relentless desire for Continuous Improvement.
  • Internal audit can be the CA / CCM learning lab for the rest of Company. See Terry Hickman's presentation (Proctor & Gamble) for more information.
  • Most savings realized by audit teams through Continuous Auditing are re-directed toward emerging risks and increasing coverage.
  • Continuous auditing and data analytics jobs are out there, but the quantity and quality of applicants has been below expectations, according to several hiring managers.
  • New software entrants such as SymSure for IDEA and ACL's Audit Exchange 2 (AX2) are sparking new projects in CA, as their price point is a marked improvement relative to more comprehensive CCM tools that have previously been available.
Our presentation emphasized some of the challenges of defining Continuous Auditing. At some organizations, the term means Continuous Risk Assessment. At others, it means Control Assessment of configurable controls or Control Assessment of Transactions. If people that are doing CA / CCM use the same words for different activities, it's hard for others to follow this leadership. For more information on the conference, see: Rutgers WCAS.

Did you attend? What were your key take-aways. All comments are welcomed!

Joe Oringel
Visual Risk IQ
Charlotte NC, USA

Sunday, September 20, 2009

Another CFO Article on Continuous Auditing - Correct about Vocabulary. Incorrect about no one doing it well.

We appreciate CFO Magazine writing about Continuous Auditing (CA) again. This month's piece is better than previous efforts, in that it focuses much more on the process changes needed for CA, and less on the actual technology that is used to accomplish CA, as we have blogged about previously. CFO Magazine interviewed several industry and academic leaders for this article - alas they didn't reach out to Visual Risk IQ, at least yet. So in today's blog, we'll summarize some of our observations and experiences about CA and contrast them to the CFO article. The centerpiece of our thoughts on CA is our proprietary maturity model, which we use to chart company-specific actions that help organizations advance on this journey. We'll also suggest one or two other organizations that CFO Magazine might talk to so that a clearer picture of CA can develop. In any case, we certainly echo the author's point, that a common, practical definition of CA is not yet accepted in the industry.

For this article, the author interviewed HCA, Microsoft, and AEP - and profiled how each organization uses CA. We feel especially qualified to comment on the article, because Kim Jones and I have been working almost exclusively on CA since our days at PwC in 2006, where he was a key team member on the Microsoft project cited in the article. We also count both HCA and AEP among our circle of friends from the speaking and writing that we each do in the Internal Audit community.

My counsel to the author would be to separate Continuous (which is really Continual) Risk Assessment from Continuous Controls Assessment. One of the reasons that there are such varying definitions of CA, are that are a diverse number of objectives that can be accomplished with CA and especially Continuous Controls Monitoring for Transactions (CCM-T). Organizations that set out to allocate their audit resources based on more up-to-date information than an annual risk assessment are likely to begin their CA efforts here. Companies profiled publicly in articles and cases that match this CA description include McDonald's and Wells Fargo, and usually have a very large number of audit entities (i.e. Stores or Branches), that make it difficult to visit each entity in a three- or five-year audit cycle. We have assisted several organizations to be more like McDonald's and Wells Fargo, by using data to perform more frequent, data-driven risk assessments to allocate their audit resources. Most often, the data used for this activity is aggregate financial or operational information like Financial Performance vs. Budget, Performance Ratios, or Employee Turnover. While it appears from the quotes from Jay Hoffman at AEP that his team is doing Continuous Risk Assessment, the controls being tested per the article seem to be more specific to Continuous Controls Assessment, which is using data-driven techniques to provide greater depth and frequency of audit coverage.

Continuous Controls Assessment are the techniques profiled in the article at HCA, AEP, and Microsoft. Instead of auditing overtime or journal entries only once every two or three years, many organizations use repeating data analysis scripts to assess the effectiveness of a control at multiple intervals during a year. These techniques can alert management to emerging issues with fraud risk or compliance, and also assist in following up on previous audit findings.

At Visual Risk IQ, we assert that "real continuous auditing" is to more fully integrate the Continuous Controls Assessment with Continuous Risk Assessment, so that audit project selection is based on the effectiveness of frequent, data-driven control assessment activities. Example: "What should be next on the audit plan - let's go to the regional office that hit their sales budget (to the penny!), but hasn't updated their allowance for doubtful accounts since the new accounting manager was hired six months ago."

I can think of two or three organizations that are doing real continuous auditing, according to this definition. Both Arrowpoint Capital in Charlotte and RLI Corporation in Peoria have presented at national and regional IIA / MISTI conferences about their CA programs, which originated with repeating the data analysis routines that were used for control assessment. While neither is a household name like Microsoft or HCA, each have been doing CA for more than five years, and are quite mature in their use of data for both control assessment and risk assessment.

In closing the article does a good job of distinguishing between CA and CM (continuous monitoring), which are activities performed by management. The evolution of CA to CM is a particular mark of growing CA maturity. Our work with CM, and especially CCM-T, has allowed us to help management use technology to test the right controls, at the right time, to achieve spectacularly effective results in business performance and internal controls. CA is often the first step on that journey.

Joe Oringel
Visual Risk IQ
Charlotte NC, USA

Sunday, March 1, 2009

New acronyms in the Continuous Controls Monitoring space - CCM-T

Those of you who have met Kim Jones and me, either from our PwC days or since we've founded Visual Risk IQ, know that we believe that the IT Research community has not done a great job of defining categories within Governance, Risk and Compliance software. Even the Continuous Controls Monitoring category had everything from Segregation of Duties tools like Virsa (now SAP-GRC) to IT General Control Tools (like TripWire) to more general purpose CCM tools like those from ACL, Apex, Approva, and Oversight.

But now in 2009, the Research community is getting better. Maybe much better. Gartner has published a new report on the segment of the GRC category that we specialize in, and they have named the category "Continuous Controls Monitoring for Transactions, or CCM-T" We believe this segmentation does a MUCH better job of identifying the vendors who are in this cateogory.

The report separates CCM-T from other CCM technologies, like Segregation of Duties tools, Application Controls, and Master Data tools. For a copy of the report, register on ACL's web site and download the Gartner CCM-T Report

Take a look and tell us what you think, either by commenting below, sending an email or seeing us in person. Look for Visual Risk IQ at IIA's GAM conference or at MISTI's SuperStrategies, where we will be a sponsor and speaker on Thursday morning April 16.

Joe Oringel
Visual Risk IQ
Charlotte NC, USA

Wednesday, November 12, 2008

Continuous Auditing Maturity Model presented in Chicago

This past week, we presented an overview of Continuous Auditing and Monitoring to a group of internal audit and compliance executives in Chicago, IL. The session focused on the Continuous Auditing Maturity Model, and provided specific guidance on how to get started with data mining and data analysis, as well as more advanced advice on increasing frequency and progressing toward continuous auditing.

The session was attended by a diverse group of attendees from a variety of industries and functional backgrounds. Experience with data analysis ranged from "not started" to regular use of ACL and IDEA, and each attendee was able to take away practical advice to help them with their specific situation and risk profile.

Visual Risk IQ and Vonya Global, a Chicago-based consulting firm specializing in Internal Audit, co-sponsored the event, and Vonya hosted the event at their offices on N. Michigan Avenue. Feedback from attendees was very positive, and we expect to co-sponsor similar events together in the new year.

To obtain a copy of the slide deck used at the event, please email joe.oringel@visualriskiq.com or call 704-752-6403.

Regards,

Joe Oringel
Visual Risk IQ
Charlotte NC, USA

Friday, October 17, 2008

Visual Risk IQ, Vonya Global to present Continuous Auditing workshop in Chicago on November 7, 2008

One of our speaking efforts has been picked up on PRWeb. Come join us in Chicago for two hours of CPE and some lively discussion on Continuous Auditing and Monitoring

---------------------------------------------------------------------------

Vonya Global, a leader in internal audit and independent risk assurance consulting, and Visual Risk IQ, a thought leader in continuous auditing, have come together to create a training workshop on the Continuous Auditing Lifecycle.

Chicago, IL, October 17, 2008 -- Vonya Global, a leader in internal audit and independent risk assurance consulting, and Visual Risk IQ, a thought leader in continuous auditing, have come together to create a training workshop on the Continuous Auditing Lifecycle. This workshop will be held in Chicago on November 6, 2008 and is open to the public but registration is required.

Continuous auditing and continuous monitoring are hot topics in the internal audit and compliance communities. While solutions offered by technology firms in this space can be quite capable, they are often impractical unless audit processes and management are also ready to adapt. Continuous auditing is known to help achieve compliance, audit and business performance objectives, so understanding some of the steps along the journey is often essential to getting such results in a cost-effective and direct approach.

This workshop will discuss several companies' journeys toward Continuous Auditing and Monitoring, and will present a Maturity Model that charts their course. The session will provide practical strategies that can be immediately applied to business regardless of where companies are on the maturity curve.

About Vonya Global - Vonya Global is a new idea in internal audit consulting and independent risk assurance services. With expertise in Finance, IT and Operations, Vonya Global helps its clients identify and assess risk, evaluate and improve internal controls, and implement continuous monitoring systems. Vonya Global is on a mission to prove there is a better way to serve clients by focusing on the basics; providing consistent quality, responsive service, and knowledge leadership. Having locations throughout the world, Vonya Global serves as a value added alternative to the large accounting firms. There is a better way, Vonya Global will show you.

Vonya Global LLC headquarters is located at 150 N. Michigan Avenue, Suite 2935, Chicago, IL 60601. For more information please email info @ vonyaglobal.com or visit www.vonyaglobal.com.

ABOUT VISUAL RISK IQ - Visual Risk IQ specializes in helping companies plan and implement continuous auditing and monitoring solutions that help them achieve their specific business objectives through increased frequency and depth of risk and control analysis. The company works with a variety of Fortune 1000 and large non-profit enterprises across a broad range of industry sector.

Saturday, June 14, 2008

How to Earn $25 Million Per Year, at Least for a While....

The answer isn't to be an NBA All-Star or an Oscar winning actress. But the good news is a college degree isn't required. Apparently limited Federal oversight over Medicare and Medicaid spending in South Florida has allowed at least one fraudster to "earn" $105 Million over four years before finally getting caught in a recent sting operation.

Clues that led to the prosecution include Department of Health and Human Services include the following:
  • The South Florida region billed Medicare more than $2 billion each year for injectable HIV medications. That figure is 22 times as high as the amount of similar claims in the rest of the country, and is far out of line with demographic data in a population of 2 million people in Miami-Dade County, HHS statistics show.
  • HHS investigators discovered that nearly half of 1,581 medical equipment companies they visited in the Miami area did not comply with basic Medicare requirements to be open during scheduled hours and to have a telephone number.
For more information on the specific case and some of the troubling patterns suggested, read the MSNBC story.

Those of you familiar with Visual Risk IQ's services know that we combine visual outlier analysis with continuous transaction monitoring, primarily for accounts payable, procurement card, and travel and entertainment. But since summer of 2007, we have also been developing a practice in Health Benefits auditing, in partnership with Atlanta-based Thomas Ray and Associates. Stories like this validate our decision to expand our work into this payment stream, as overpayments through errors and fraud seem much greater than with accounts payable.

More to follow this summer as we continue to continue our work in this highly visible expense area.

Joe Oringel
Visual Risk IQ
Charlotte NC 28277

Sunday, March 16, 2008

Observations from the IIA District Conference in Greensboro NC - it's not about Software

Visual Risk IQ presented a session on Continuous Controls Monitoring (CCM) at the IIA's District Conference in Greensboro on March 14, and we had nearly 100 people join us for a dialog about how to get started with CCM and/or Continuous Auditing (CA). Several of the audience had seen us at either Triad or Charlotte CCM / CA training sessions, either alone or with ACL, Oversight, or Apex Analytix.

So to create some distinction from other CPE sessions we've made, we focused mostly on the maturity model and recommended first steps to move from current state toward a mature, highly frequent and in-depth process for risk and control assessment. We de-emphasized that the technology components and emphasized the importance of audit process, risk assessment approach, gaining buy-in from business process owners, training for IA staff. The non-technology components of embarking on a project.

Something very interesting happened. The Q&A was more lively. The audience was highly engaged, and a couple of audit directors came up to us after the presentation to thank us for NOT talking so much about software. It seems they hear (way too often) about the ways Brand X, Brand Y, or Brand Z software can make their audit function better. But their experience is that any prior technology investments are often short-lived because the technology often requires other changes to be made, and those changes are not well understood or sustained.

So we'll continue to talk about our experiences and approach to CA and CCM, including how more modern software can often help. But any discussion of software will be a late bind, and we'll start with emphasizing how audit functions can achieve marked increases in productivity, simply by better utilizing tools they already have.

Feel free to write or comment, and we'll share our presentation with you if you were unable to attend the Conference in Greensboro.

Joe Oringel
Visual Risk IQ
Charlotte NC, USA

www.visualriskiq.com