Very nice summary from Patrick Taylor from Oversight Systems of their experiences from CA and CCM implementation. Patrick did a very good job of sharing examples and screen shots of how their tool are being configured to monitor both routine and non-routine transactions.
10. Compliance is the Lead
9. Your eyes are bigger than your stomach (you try to monitor everything)
8. Look through this report please (tedious, there's no bottom to the report)
7. Let's learn a specialized analysis language (instead of SQL)
6. Let's clean up the last two years of exceptions (10000++ exceptions. Yikes!)
5. Continuous Audit instead of Continuous Improvement (i.e. Use Reason Codes)
4. Don't know how to spell Vasarhelee, Vaserheyli, Vasarhellee, Vasarhelyi... (LOL!)
3. Only know how to Audit AP (other apps are
2. Bringing a knife to a gun fight. (re-testing what is already controlled by ERP)
1. Not Using Oversight (LOL x 2)
Showing posts with label Oversight Systems. Show all posts
Showing posts with label Oversight Systems. Show all posts
Friday, November 5, 2010
Friday, May 14, 2010
The High Cost of FCPA Compliance - CCM-T as Low-cost Antidote
We've been writing and tweeting about Foreign Corrupt Practices Act (FCPA) compliance for several months, after teaming with Houston-based Morgan-Garris for an innovative data-driven solution to help reduce the costs of FCPA monitoring and compliance. We'll actually be presenting next week at MISTI's SuperStrategies on using Continuous Auditing and Monitoring technology for several different applications, including FCPA.
This week's Forbes Article titled, "How Bribery Hurts Business and Enriches Insiders" shows the incredible high costs of FCPA investigations. Deloitte 1300+ project consultants billed more than 949,000 hours on their work for Siemens FCPA investigation. ABB has reserved $300 million, and Avon Products has reserved $95 million for their on-going investigations.
It is becoming increasingly common for FCPA costs to run tens, if not hundreds of millions of dollars. What takes so long? Why is it so expensive?
When Kim and I were at PwC, it was common for the data acquisition component of a Big 4 data analysis project to consume 60% or 70% or more of a project budget. Extracting flat files and fastidiously mapping them into desktop audit software tools was and still is a time-consuming process, especially for ad hoc analysis. At Visual Risk IQ, most of our data analysis projects are fixed-fee, and include time to acquire and map data into more modern audit software like Oversight, Approva, or SymSure for IDEA**. These more modern tools facilitate repeated extraction at dramatically lower costs of data acquisition, therefore allowing more time for research and review of results.
As such, each successive extract of a monthly or even daily file can be loaded into modern audit software, so that 100% of the time for the second file is spent on review of results, not loading data. Further, advances in workflow and logging can facilitate efficient review and oversight by finance or inside / outside counsel. Given the fees cited in Forbes, we know we have a much better way.
Joe Oringel
Visual Risk IQ
Charlotte NC, USA
** Author's Note - We read that ACL's AX/2 has similar automation for data extraction, through integration of Informatica for extract, transform, and load. We have not yet validated this functionality.
Labels:
ACL,
Approva,
FCPA,
Oversight Systems,
SymSure for IDEA
Friday, October 16, 2009
Forrester Research on Continuous Controls Monitoring is Spot On
Chatted with freelance writer and former CFO of one of our clients Chris McKittrick this week. Chris writes for Big Fat Finance Blog on a variety of topics, including CCM-T, which Forrester Research calls Internal Controls Monitoring. Chris pointed us to a CFO Magazine article earlier this year about CCM-T, which states the simple and profound:
“Internal controls monitoring. Technologies in this area so far have demonstrated a low level of success, or business value-add, and are on a trajectory for minimal success over their lifespan, according to Forrester. There is potential payback in error reductions, efficiency, and risk avoidance, but most installations have yet to prove what they will ultimately be worth. And while internal controls monitoring is important because of Sarbanes-Oxley and other compliance directives, "many of the solutions just raise red flags," Paul Hamerman, vice president of enterprise applications for Forrester, tells CFO.com. "Somebody has to go through these flags to figure out what they mean. If the application doesn't have the built-in intelligence to do that, it's value is diminished."
Going through the red flags is a real business challenge, and requires knowledge of technology, enterprise data, policies, business rules, and fraud. Unfortunately, many organizations who have invested in this technology do not put enough emphasis on the on-going care and feeding of the systems, and it's common for the number of red flags identified in a period to exceed the number of red flags that are fully researched and resolved. As a result, the business value add for the systems can fail to reach its potential.
Even for organizations that are managing the work queues well, it is rare to see organizations modify their rules and add more red flags for checking. Opportunities to help CCM-T users with post-implementation support, whether the tool of choice is Oversight, Approva, ACL Audit Exchange 2, or SymSure / IDEA, would seem to be a growth area.
* * * * * * * * * * *
Are you attending the Rutgers Continuous Auditing Symposium on November 6 and 7? We are. Look for us at the Conference or on a Panel at 4:00 on Day 1, and let's compare notes on the above. We're interested to share experiences with others...
Joe Oringel
Visual Risk IQ
Charlotte NC, USA
“Internal controls monitoring. Technologies in this area so far have demonstrated a low level of success, or business value-add, and are on a trajectory for minimal success over their lifespan, according to Forrester. There is potential payback in error reductions, efficiency, and risk avoidance, but most installations have yet to prove what they will ultimately be worth. And while internal controls monitoring is important because of Sarbanes-Oxley and other compliance directives, "many of the solutions just raise red flags," Paul Hamerman, vice president of enterprise applications for Forrester, tells CFO.com. "Somebody has to go through these flags to figure out what they mean. If the application doesn't have the built-in intelligence to do that, it's value is diminished."
Going through the red flags is a real business challenge, and requires knowledge of technology, enterprise data, policies, business rules, and fraud. Unfortunately, many organizations who have invested in this technology do not put enough emphasis on the on-going care and feeding of the systems, and it's common for the number of red flags identified in a period to exceed the number of red flags that are fully researched and resolved. As a result, the business value add for the systems can fail to reach its potential.
Even for organizations that are managing the work queues well, it is rare to see organizations modify their rules and add more red flags for checking. Opportunities to help CCM-T users with post-implementation support, whether the tool of choice is Oversight, Approva, ACL Audit Exchange 2, or SymSure / IDEA, would seem to be a growth area.
* * * * * * * * * * *
Are you attending the Rutgers Continuous Auditing Symposium on November 6 and 7? We are. Look for us at the Conference or on a Panel at 4:00 on Day 1, and let's compare notes on the above. We're interested to share experiences with others...
Joe Oringel
Visual Risk IQ
Charlotte NC, USA
Labels:
ACL Audit Exchange,
Approva,
CCM-T,
Forrester,
IDEA,
Oversight Systems,
SymSure
Wednesday, July 8, 2009
Observations from Recent, Local Frauds in Charlotte NC
Several folks commented on recent tweets of local fraud and embezzlement, first at UNC-Charlotte and again at Charlotte's Mecklenburg County, specifically within the Department of Social Services. The Fraud Triangle teaches us that as long as there is Pressure / Incentive (I really need the money), Rationalization (e.g. other people do it, I'll pay it back...etc.) and Opportunity (I won't get caught because...) fraud can and will occur and recur.
My own experience is these three elements of the fraud triangle are closely related, and that Opportunity needs to be re-evaluated, especially as Incentive increases. Today's economic times are proving this need most everywhere we look, yet we still see only a few companies who are actively changing and increasing how they monitor for potential fraud, despite the availability of very effective, modern tools for fraud detection. Like CCM-T tools from Oversight and Approva.
A specific example: During my Big 4 Accounting Firm days, I led a team that audited the procedures used to produce scratch-off lottery tickets. When we started, the largest prize awarded was $5,000 or $10,000. While internal controls were always very good (i.e. Opportunity = Low), there were still a number of people at the Ticket Printer and at the Big 4 Firm who had access to information that might help locate a batch of 250 tickets that would likely contain a $5,000 or $10,000 winner.
The likelihood that a person would risk their career to steal $5,000 or $10,000 (two to six months net pay) was pretty low. But when the Ticket Printer and State Lotteries began printing tickets with $100,000 and eventually $1,000,000 tickets. That represented at least a year or even 20 years or more in net pay. What a powerful Incentive!
This change in Incentive was a trigger that we saw to re-evaluate internal controls, because now the temptation needed a corresponding decrease in opportunity. In addition to our agreed-upon procedures to evaluate controls over ticket production, we began a continual security review which included review of other controls that would identify who may be accessing information that might allow a large ticket winner to be located. We publicized the continual security review within the company (and the Big 4 team!), so that the decreased Opportunity was understood by anyone who may have been tempted.
As staffs are cut and monitoring controls become less frequent, what is your organization doing to reduce the Opportunity for Fraud. For a couple of high-profile cases in Charlotte, it's clear that more needs to be done.
Joe Oringel
Visual Risk IQ
Charlotte NC, USA
My own experience is these three elements of the fraud triangle are closely related, and that Opportunity needs to be re-evaluated, especially as Incentive increases. Today's economic times are proving this need most everywhere we look, yet we still see only a few companies who are actively changing and increasing how they monitor for potential fraud, despite the availability of very effective, modern tools for fraud detection. Like CCM-T tools from Oversight and Approva.
A specific example: During my Big 4 Accounting Firm days, I led a team that audited the procedures used to produce scratch-off lottery tickets. When we started, the largest prize awarded was $5,000 or $10,000. While internal controls were always very good (i.e. Opportunity = Low), there were still a number of people at the Ticket Printer and at the Big 4 Firm who had access to information that might help locate a batch of 250 tickets that would likely contain a $5,000 or $10,000 winner.
The likelihood that a person would risk their career to steal $5,000 or $10,000 (two to six months net pay) was pretty low. But when the Ticket Printer and State Lotteries began printing tickets with $100,000 and eventually $1,000,000 tickets. That represented at least a year or even 20 years or more in net pay. What a powerful Incentive!
This change in Incentive was a trigger that we saw to re-evaluate internal controls, because now the temptation needed a corresponding decrease in opportunity. In addition to our agreed-upon procedures to evaluate controls over ticket production, we began a continual security review which included review of other controls that would identify who may be accessing information that might allow a large ticket winner to be located. We publicized the continual security review within the company (and the Big 4 team!), so that the decreased Opportunity was understood by anyone who may have been tempted.
As staffs are cut and monitoring controls become less frequent, what is your organization doing to reduce the Opportunity for Fraud. For a couple of high-profile cases in Charlotte, it's clear that more needs to be done.
Joe Oringel
Visual Risk IQ
Charlotte NC, USA
Friday, April 24, 2009
NC State ERM Roundtable - GREAT Session from David Fox of KBR
Attended this morning's session in Raleigh for NC State's ERM Roundtable and had the pleasure to hear some thought-provoking ideas from both Dr. Mark Beasley (NC State) and David Fox of KBR in Houston. Thank you to Oversight Systems for their sponsorship of the event.
More on David's presentation later today, but for now here are a couple of resources that we know will be of interest to the ERM and Internal Audit community(s).
More on David's presentation later today, but for now here are a couple of resources that we know will be of interest to the ERM and Internal Audit community(s).
1) AICPA's Research on the Current State of Enterprise Risk Oversight, published April 2009.
Research by the American Institute of Certified Public Accountants (AICPA) and NC State ERM Initiative finds that while the volume and complexities of risks are increasing extensively, risk oversight is fairly immature, ad hoc, and the source of frustration for over 700 executives surveyed. Some great factoids from the survey...
Read more about Enterprise Risk Management at NC State's very thoughtful and thought-provoking Portal.
- Over 1/3 of organizations surveyed note they were caught off guard by an Operational Surprise either "Extensively" or a "A Great Deal" in the last five years. Another 1/3 of organizations faced a "Moderate" operational surprise.
- Almost half (47%) stated that they are "Not at All Satisfied" or "Minimally" satisfied with the nature and extent of reporting of key risk indicators to senior executives regarding the entity's top risk exposure.
- 44% of organizations surveyed have no enterprise-wide risk management process in place and no plans to implement one.
- An additional 18% without ERM processes in place indicate they are currently investigating the concept, but have made no decisions about implementing ERM.
Read more about Enterprise Risk Management at NC State's very thoughtful and thought-provoking Portal.
Labels:
AICPA,
ERM Roundtable,
NC State,
Oversight Systems
Sunday, April 19, 2009
SuperStrategies 2009 Reflections
Kim and I spoke at SuperStrategies 2009 in Las Vegas last week, where our topic was Finding Money and Detecting Fraud with Transaction Monitoring. The session was well-attended and provided some nice opportunities to meet some new friends and prospects, as well as connect with several alliance partners, including ACL, IDEA, and Oversight Systems.
Our conference presentation is available for download on LinkedIn and SlideShare.
Data analysis and continuous auditing clearly remained top of mind for most internal audit and ERM executives, especially as firms are all challenged to do more with less. A number of excellent presenters also shared their experience in the area, including RLI Insurance, HCA, and Continental Airlines. It was especially encouraging to hear the keynote panel's predictions for the future, and have each point toward data analysis and continuous auditing as a continued area of focus.
Conference takeaways related to data analysis included: ; comparing relative size factor on invoices and PO's (HCA); team award for the data analytic innovation of the month (Bristol-Myers Squibb); Geocoding and Q-grams (RLI); and reading your competitors' 10K for risk assessment input factors (Protiviti).
Joe Oringel
Visual Risk IQ
Charlotte NC, USA
Our conference presentation is available for download on LinkedIn and SlideShare.
Data analysis and continuous auditing clearly remained top of mind for most internal audit and ERM executives, especially as firms are all challenged to do more with less. A number of excellent presenters also shared their experience in the area, including RLI Insurance, HCA, and Continental Airlines. It was especially encouraging to hear the keynote panel's predictions for the future, and have each point toward data analysis and continuous auditing as a continued area of focus.
Conference takeaways related to data analysis included: ; comparing relative size factor on invoices and PO's (HCA); team award for the data analytic innovation of the month (Bristol-Myers Squibb); Geocoding and Q-grams (RLI); and reading your competitors' 10K for risk assessment input factors (Protiviti).
Joe Oringel
Visual Risk IQ
Charlotte NC, USA
Wednesday, April 23, 2008
More Continuous Auditing Software - Or is it?
As many who have met us know, Kim Jones and I keep various Google Alerts set for key phrases that relate to continuous auditing (CA) and continuous monitoring (CM). As is the case in most weeks, this week's alert had many more citations for CM than CA. But the CA alert did have a number of new and noteworthy items for us.
One of this week's most interesting CA alerts was from Atlanta-based software firm called Gideon Technologies and their SecureFusion suite. The suite should be of interest for configuration controls auditing and monitoring in the IT General Controls stack, but not for monitoring of financial transactions, as we focus on at Visual Risk IQ. Nevertheless, the alert reinforces how the analysts in the GRC space struggle when describing the capabilities and points of distinction among software firms known for CA, CM, and/or GRC. SecureFusion capabilities include IT asset detection, configuration management, and vulnerability assessment, and therefore have little if anything in common with CA and CM transaction monitoring tools like Oversight, Apex, or ACL.
Kim and I know Ken from our PwC days, and we recently saw him speak a March meeting in Atlanta, where they introduced Gideon's SecureFusion solution to a number of information security professionals. He was quick to agree that there are a number of technology solutions that share the similar names and even named features, but that they do not in fact compete in any meaningful way. Over time, hopefully the market(s) will also begin to distinguish this as well.
One of this week's most interesting CA alerts was from Atlanta-based software firm called Gideon Technologies and their SecureFusion suite. The suite should be of interest for configuration controls auditing and monitoring in the IT General Controls stack, but not for monitoring of financial transactions, as we focus on at Visual Risk IQ. Nevertheless, the alert reinforces how the analysts in the GRC space struggle when describing the capabilities and points of distinction among software firms known for CA, CM, and/or GRC. SecureFusion capabilities include IT asset detection, configuration management, and vulnerability assessment, and therefore have little if anything in common with CA and CM transaction monitoring tools like Oversight, Apex, or ACL.
Kim and I know Ken from our PwC days, and we recently saw him speak a March meeting in Atlanta, where they introduced Gideon's SecureFusion solution to a number of information security professionals. He was quick to agree that there are a number of technology solutions that share the similar names and even named features, but that they do not in fact compete in any meaningful way. Over time, hopefully the market(s) will also begin to distinguish this as well.
Sunday, March 16, 2008
Observations from the IIA District Conference in Greensboro NC - it's not about Software
Visual Risk IQ presented a session on Continuous Controls Monitoring (CCM) at the IIA's District Conference in Greensboro on March 14, and we had nearly 100 people join us for a dialog about how to get started with CCM and/or Continuous Auditing (CA). Several of the audience had seen us at either Triad or Charlotte CCM / CA training sessions, either alone or with ACL, Oversight, or Apex Analytix.
So to create some distinction from other CPE sessions we've made, we focused mostly on the maturity model and recommended first steps to move from current state toward a mature, highly frequent and in-depth process for risk and control assessment. We de-emphasized that the technology components and emphasized the importance of audit process, risk assessment approach, gaining buy-in from business process owners, training for IA staff. The non-technology components of embarking on a project.
Something very interesting happened. The Q&A was more lively. The audience was highly engaged, and a couple of audit directors came up to us after the presentation to thank us for NOT talking so much about software. It seems they hear (way too often) about the ways Brand X, Brand Y, or Brand Z software can make their audit function better. But their experience is that any prior technology investments are often short-lived because the technology often requires other changes to be made, and those changes are not well understood or sustained.
So we'll continue to talk about our experiences and approach to CA and CCM, including how more modern software can often help. But any discussion of software will be a late bind, and we'll start with emphasizing how audit functions can achieve marked increases in productivity, simply by better utilizing tools they already have.
Feel free to write or comment, and we'll share our presentation with you if you were unable to attend the Conference in Greensboro.
Joe Oringel
Visual Risk IQ
Charlotte NC, USA
www.visualriskiq.com
So to create some distinction from other CPE sessions we've made, we focused mostly on the maturity model and recommended first steps to move from current state toward a mature, highly frequent and in-depth process for risk and control assessment. We de-emphasized that the technology components and emphasized the importance of audit process, risk assessment approach, gaining buy-in from business process owners, training for IA staff. The non-technology components of embarking on a project.
Something very interesting happened. The Q&A was more lively. The audience was highly engaged, and a couple of audit directors came up to us after the presentation to thank us for NOT talking so much about software. It seems they hear (way too often) about the ways Brand X, Brand Y, or Brand Z software can make their audit function better. But their experience is that any prior technology investments are often short-lived because the technology often requires other changes to be made, and those changes are not well understood or sustained.
So we'll continue to talk about our experiences and approach to CA and CCM, including how more modern software can often help. But any discussion of software will be a late bind, and we'll start with emphasizing how audit functions can achieve marked increases in productivity, simply by better utilizing tools they already have.
Feel free to write or comment, and we'll share our presentation with you if you were unable to attend the Conference in Greensboro.
Joe Oringel
Visual Risk IQ
Charlotte NC, USA
www.visualriskiq.com
Subscribe to:
Posts (Atom)