Sunday, March 1, 2009

New acronyms in the Continuous Controls Monitoring space - CCM-T

Those of you who have met Kim Jones and me, either from our PwC days or since we've founded Visual Risk IQ, know that we believe that the IT Research community has not done a great job of defining categories within Governance, Risk and Compliance software. Even the Continuous Controls Monitoring category had everything from Segregation of Duties tools like Virsa (now SAP-GRC) to IT General Control Tools (like TripWire) to more general purpose CCM tools like those from ACL, Apex, Approva, and Oversight.

But now in 2009, the Research community is getting better. Maybe much better. Gartner has published a new report on the segment of the GRC category that we specialize in, and they have named the category "Continuous Controls Monitoring for Transactions, or CCM-T" We believe this segmentation does a MUCH better job of identifying the vendors who are in this cateogory.

The report separates CCM-T from other CCM technologies, like Segregation of Duties tools, Application Controls, and Master Data tools. For a copy of the report, register on ACL's web site and download the Gartner CCM-T Report

Take a look and tell us what you think, either by commenting below, sending an email or seeing us in person. Look for Visual Risk IQ at IIA's GAM conference or at MISTI's SuperStrategies, where we will be a sponsor and speaker on Thursday morning April 16.

Joe Oringel
Visual Risk IQ
Charlotte NC, USA

Wednesday, February 25, 2009

Now Hiring - Continuous Auditing specialists

Many of you know who have heard my partner and I speak at various IIA and MISTI events have heard that we have Google alerts set up on Continuous Auditing and Continuous Monitoring. Most Continuous Monitoring alerts have been related to Medical Devices - glucose monitoring, pacemakers, but it has been rare that we actually get article posts related to Continuous Auditing or what is becoming known as Continuous Controls Monitoring.

But maybe this is changing....

For the past two weeks, I have gotten "hits" on Google Alerts for Continuous Auditing and Continuous Controls Monitoring that relate to data analysis, data mining, and continuous auditing, specifically Job Postings. Yes, despite the challenging economy, there are several Audit Groups that are hiring continuous auditing specialists. Technical skills needed include data analysis, such as working with ACL or IDEA, as well as to more modern tools such as Approva, Oversight Systems or Apex Analytix.

Not surprising, interpersonal skills, including good communication skills and technical writing are also required. You can't write a good continuous auditing test if you don't have good data. And auditors need help from someone to acquire and understand the data.

Kudos to the hiring executives who understand that increasing the depth and especially the frequency of data analysis can increase the value that internal audit brings. Two of the three job postings I've seen are in the Hospitality sector, and the third is in Healthcare. Common threads perhaps are large volumes of disparate data, and opportunities to increase top line revenue through improving data quality.

For more information on these jobs or to compare notes on data analysis and continuous auditing, please reach out via contact information below.

Regards,

Joe Oringel
Visual Risk IQ
Charlotte NC, USA
joe.oringel@visualriskiq.com

Wednesday, February 11, 2009

What is the cost of non-compliance? How's $579 million sound?

Source: Reuters: Halliburton and KBR agree to Settlement in historic Foreign Corrupt Practices Act (FCPA) case

In the largest FCPA settlement against a US-based company, KBR and its former parent Halliburton agreed to pay $579 million in fines to settle charges that they violated Foreign Corrupt Practices Act (FCPA) as part of a plan to secure large, long-term construction contracts in Nigeria.

According to the DOJ, KBR was part of a four-company joint venture that received the contracts. As part of its plea, KBR admitted to conspiring with those partners to promise and pay bribes. They also admitted to paying tens of millions of dollars in consulting fees to two agents for use in bribing government officials.

As part of its criminal plea deal, KBR agreed to retain an independent compliance monitor for a three-year period and continue to cooperate with the DOJ's continuing investigation of this matter.

In a related civil complaint by the SEC, Halliburton and KBR jointly agreed to pay $177 million in disgorgement. The SEC had charged KBR with violating the anti-bribery provisions of the Foreign Corrupt Practices Act. It also charged Halliburton and KBR with record-keeping and internal control violations.

"As part of the resolution of the SEC investigation, Halliburton will retain an independent consultant to perform a 60-day initial and, approximately one year later, a 30-day follow-up review and evaluation of Halliburton's anti- bribery and foreign agent internal controls and record-keeping policies and to adopt any necessary improvements," the company said.

----------------------------------

The application for continuous auditing and monitoring in helping organizations monitor internally for potential FCPA violations is particularly positive, because these compliance issues can be assessed concurrent with other operational challenges such as duplicate payment or overpayment.
Joe Oringel
Visual Risk IQ LLC
Charlotte NC, USA

Thursday, February 5, 2009

Check out "The Fraudies", Oversight's list of top Corporate Fraudsters

The folks at Oversight Systems have announced The Fraudies, a light-hearted collection of some of the bolder attempts to defraud corporations that have been detected or deterred by continuous auditing and monitoring. My personal favorite is the individual who used their company's P-Card to purchase $3,400 worth of advice from the Psychic Hotline. Let's hope the psychic didn't tell the fraudster to join your firm.

Unfortunately, today's challenging economic times are increasing the pressures and the rationalization behind more potential fraudsters.  We are working with a number of organizations in different industries, to help increase the likelihood of detection by implementing cost-effective monitoring techniques.

Using these techniques as part of regularly scheduled audits of Accounts Payable, Travel & Entertainment or P-Card audits can help organizations achieve compliance objectives while also returning money to the bottom line by reducing overpayments and re-capturing inappropriate disbursements.  Further, like the Fraudies, we hope that by publicizing these instances of fraud, other future fraudsters will be deterred.   

Joe Oringel
Visual Risk IQ
Charlotte NC 28277

Sunday, December 28, 2008

Visual Risk IQ to Partner with Vonya Global: Providing Data-Driven Audit Services

Feedback from the Continuous Auditing Life Cycle workshop that we did with Vonya Global in Chicago was very positive; consequently, we have developed a partner relationship with them to market and deliver two services specifically focused at helping audit executives recover costs and increase margins during challenging economic times.  

The services analyze historical purchasing and sales transactions looking for overpayment, contract pricing variations, and other operational and compliance issues.  Clients benefit from tangible recoveries, while also receiving advice on monitoring controls that can be used to prevent future errors.  

On Point Data Analytics(sm), the first service provided by the two firms, is directed primarily toward internal audit and executives responsible for Governance, Risk and Compliance.  On Point Data Analyticcs analyzes client's data in the context of an internal audit project, thus providing hands-on audit software training while accomplishing specific audit objectives.  The service also includes an assessment of an organization's capabilities and readiness for continuous auditing.   

On Point Continuous Controls Monitoring (sm), the second jointly provided service, is designed to help companies understand the value of more in-depth and frequent monitoring solution.  The services includes an in-depth analysis of historical transactions using a best-in-class continuous monitoring tool, and identifies operational and compliance issues along with improvements that can prevent future errors.  

Click here to read the entire press release

Bookmark this blog to read case studies and client profiles that highlight examples of cost recovery and other savings that have paid for the services many times over.    
 

Friday, December 26, 2008

ERM Resources from NC State

During the last several months, I have been attending the Enterprise Risk Management (ERM) roundtables at NC State University in Raleigh. These ERM roundtables provide thought-provoking Continuing Professional Education (CPE) and networking opportunities for Governance, Risk and Compliance professionals on a regional and national level. Previous presentations are archived on the web at: http://mgt.ncsu.edu/erm/Roundtables.php

The purpose of the ERM program is multi-dimensional. They aspire to provide outreach (through the roundtables), research (through an outstanding web portal), and undergraduate and graduate education.

Speakers this fall included Jim Traut, Director of ERM at H.J. Heinz, and Drew Zavatsky, Office of Financial Management from the State of Washington, and the February roundtable will be in Charlotte NC. Steve Dreyer of Standard & Poors (S&P) will be presenting on their use and evaluation of ERM as part of S&P's ratings process.

Continuous Auditing combines more frequent risk assessment with more frequent and in-depth control assessment. Since ERM represents leading edge practices in risk assessment, we will continue to identify opportunities to link continuous controls monitoring to ERM, to provide more data-driven risk assessment.

Stay tuned for more information in 2009 about these initiatives.

Joe Oringel
Charlotte, NC
Visual Risk IQ

Wednesday, November 12, 2008

Continuous Auditing Maturity Model presented in Chicago

This past week, we presented an overview of Continuous Auditing and Monitoring to a group of internal audit and compliance executives in Chicago, IL. The session focused on the Continuous Auditing Maturity Model, and provided specific guidance on how to get started with data mining and data analysis, as well as more advanced advice on increasing frequency and progressing toward continuous auditing.

The session was attended by a diverse group of attendees from a variety of industries and functional backgrounds. Experience with data analysis ranged from "not started" to regular use of ACL and IDEA, and each attendee was able to take away practical advice to help them with their specific situation and risk profile.

Visual Risk IQ and Vonya Global, a Chicago-based consulting firm specializing in Internal Audit, co-sponsored the event, and Vonya hosted the event at their offices on N. Michigan Avenue. Feedback from attendees was very positive, and we expect to co-sponsor similar events together in the new year.

To obtain a copy of the slide deck used at the event, please email joe.oringel@visualriskiq.com or call 704-752-6403.

Regards,

Joe Oringel
Visual Risk IQ
Charlotte NC, USA