More than 100 people attended our session last week at the Carolina's IIA District Conference, where I joined Matt Cleaver, Head of Internal Audit for RH Donnelley (RHD), to talk about their journey along the Continuous Auditing maturity curve. Since Visual Risk IQ's initial continuous auditing project for them in 2007, RHD has migrated from one-time, retrospective data analysis in the Accounts Payable area to weekly review of potential duplicate payments or overpayments PRIOR to any checks being issued. An important step on the maturity curve for RHD was achieved earlier this year, as the business process owner (not internal audit!) now runs the queries that had been developed to identify the potential duplicates.
As shared at the Conference, several hundred thousands of dollar in errors have been prevented due to this weekly review, and the overpayments actually recovered from our original project have more than funded the entire annual budget of the internal audit department. The return on the project's investment has been outstanding, and the audit team is even more highly valued at the Company during these challenging times affecting media and advertising companies (and most everyone else!).
Special thanks to Matt, who was very candid about the findings that our project helped their audit team uncover, in terms of these overpayments, as well as other internal control improvements that resulted from the data analysis work. For more information on their success, or for a copy of the slide deck, please email me at the contact information below.
Here's wishing that your internal audit projects can help demonstrate the value of data analysis and continuous auditing in such a direct and tangible way.
Joe Oringel
Visual Risk IQ
Charlotte NC, USA
Monday, March 2, 2009
Sunday, March 1, 2009
New acronyms in the Continuous Controls Monitoring space - CCM-T
Those of you who have met Kim Jones and me, either from our PwC days or since we've founded Visual Risk IQ, know that we believe that the IT Research community has not done a great job of defining categories within Governance, Risk and Compliance software. Even the Continuous Controls Monitoring category had everything from Segregation of Duties tools like Virsa (now SAP-GRC) to IT General Control Tools (like TripWire) to more general purpose CCM tools like those from ACL, Apex, Approva, and Oversight.
But now in 2009, the Research community is getting better. Maybe much better. Gartner has published a new report on the segment of the GRC category that we specialize in, and they have named the category "Continuous Controls Monitoring for Transactions, or CCM-T" We believe this segmentation does a MUCH better job of identifying the vendors who are in this cateogory.
The report separates CCM-T from other CCM technologies, like Segregation of Duties tools, Application Controls, and Master Data tools. For a copy of the report, register on ACL's web site and download the Gartner CCM-T Report
Take a look and tell us what you think, either by commenting below, sending an email or seeing us in person. Look for Visual Risk IQ at IIA's GAM conference or at MISTI's SuperStrategies, where we will be a sponsor and speaker on Thursday morning April 16.
Joe Oringel
Visual Risk IQ
Charlotte NC, USA
But now in 2009, the Research community is getting better. Maybe much better. Gartner has published a new report on the segment of the GRC category that we specialize in, and they have named the category "Continuous Controls Monitoring for Transactions, or CCM-T" We believe this segmentation does a MUCH better job of identifying the vendors who are in this cateogory.
The report separates CCM-T from other CCM technologies, like Segregation of Duties tools, Application Controls, and Master Data tools. For a copy of the report, register on ACL's web site and download the Gartner CCM-T Report
Take a look and tell us what you think, either by commenting below, sending an email or seeing us in person. Look for Visual Risk IQ at IIA's GAM conference or at MISTI's SuperStrategies, where we will be a sponsor and speaker on Thursday morning April 16.
Joe Oringel
Visual Risk IQ
Charlotte NC, USA
Wednesday, February 25, 2009
Now Hiring - Continuous Auditing specialists
Many of you know who have heard my partner and I speak at various IIA and MISTI events have heard that we have Google alerts set up on Continuous Auditing and Continuous Monitoring. Most Continuous Monitoring alerts have been related to Medical Devices - glucose monitoring, pacemakers, but it has been rare that we actually get article posts related to Continuous Auditing or what is becoming known as Continuous Controls Monitoring.
But maybe this is changing....
For the past two weeks, I have gotten "hits" on Google Alerts for Continuous Auditing and Continuous Controls Monitoring that relate to data analysis, data mining, and continuous auditing, specifically Job Postings. Yes, despite the challenging economy, there are several Audit Groups that are hiring continuous auditing specialists. Technical skills needed include data analysis, such as working with ACL or IDEA, as well as to more modern tools such as Approva, Oversight Systems or Apex Analytix.
Not surprising, interpersonal skills, including good communication skills and technical writing are also required. You can't write a good continuous auditing test if you don't have good data. And auditors need help from someone to acquire and understand the data.
Kudos to the hiring executives who understand that increasing the depth and especially the frequency of data analysis can increase the value that internal audit brings. Two of the three job postings I've seen are in the Hospitality sector, and the third is in Healthcare. Common threads perhaps are large volumes of disparate data, and opportunities to increase top line revenue through improving data quality.
For more information on these jobs or to compare notes on data analysis and continuous auditing, please reach out via contact information below.
Regards,
Joe Oringel
Visual Risk IQ
Charlotte NC, USA
joe.oringel@visualriskiq.com
But maybe this is changing....
For the past two weeks, I have gotten "hits" on Google Alerts for Continuous Auditing and Continuous Controls Monitoring that relate to data analysis, data mining, and continuous auditing, specifically Job Postings. Yes, despite the challenging economy, there are several Audit Groups that are hiring continuous auditing specialists. Technical skills needed include data analysis, such as working with ACL or IDEA, as well as to more modern tools such as Approva, Oversight Systems or Apex Analytix.
Not surprising, interpersonal skills, including good communication skills and technical writing are also required. You can't write a good continuous auditing test if you don't have good data. And auditors need help from someone to acquire and understand the data.
Kudos to the hiring executives who understand that increasing the depth and especially the frequency of data analysis can increase the value that internal audit brings. Two of the three job postings I've seen are in the Hospitality sector, and the third is in Healthcare. Common threads perhaps are large volumes of disparate data, and opportunities to increase top line revenue through improving data quality.
For more information on these jobs or to compare notes on data analysis and continuous auditing, please reach out via contact information below.
Regards,
Joe Oringel
Visual Risk IQ
Charlotte NC, USA
joe.oringel@visualriskiq.com
Labels:
ACL,
Apex Analytix,
Approva,
Continuous Auditing Jobs
Wednesday, February 11, 2009
What is the cost of non-compliance? How's $579 million sound?
Source: Reuters: Halliburton and KBR agree to Settlement in historic Foreign Corrupt Practices Act (FCPA) case
In the largest FCPA settlement against a US-based company, KBR and its former parent Halliburton agreed to pay $579 million in fines to settle charges that they violated Foreign Corrupt Practices Act (FCPA) as part of a plan to secure large, long-term construction contracts in Nigeria.
According to the DOJ, KBR was part of a four-company joint venture that received the contracts. As part of its plea, KBR admitted to conspiring with those partners to promise and pay bribes. They also admitted to paying tens of millions of dollars in consulting fees to two agents for use in bribing government officials.
In the largest FCPA settlement against a US-based company, KBR and its former parent Halliburton agreed to pay $579 million in fines to settle charges that they violated Foreign Corrupt Practices Act (FCPA) as part of a plan to secure large, long-term construction contracts in Nigeria.
According to the DOJ, KBR was part of a four-company joint venture that received the contracts. As part of its plea, KBR admitted to conspiring with those partners to promise and pay bribes. They also admitted to paying tens of millions of dollars in consulting fees to two agents for use in bribing government officials.
As part of its criminal plea deal, KBR agreed to retain an independent compliance monitor for a three-year period and continue to cooperate with the DOJ's continuing investigation of this matter.
In a related civil complaint by the SEC, Halliburton and KBR jointly agreed to pay $177 million in disgorgement. The SEC had charged KBR with violating the anti-bribery provisions of the Foreign Corrupt Practices Act. It also charged Halliburton and KBR with record-keeping and internal control violations.
"As part of the resolution of the SEC investigation, Halliburton will retain an independent consultant to perform a 60-day initial and, approximately one year later, a 30-day follow-up review and evaluation of Halliburton's anti- bribery and foreign agent internal controls and record-keeping policies and to adopt any necessary improvements," the company said.
----------------------------------
The application for continuous auditing and monitoring in helping organizations monitor internally for potential FCPA violations is particularly positive, because these compliance issues can be assessed concurrent with other operational challenges such as duplicate payment or overpayment.
In a related civil complaint by the SEC, Halliburton and KBR jointly agreed to pay $177 million in disgorgement. The SEC had charged KBR with violating the anti-bribery provisions of the Foreign Corrupt Practices Act. It also charged Halliburton and KBR with record-keeping and internal control violations.
"As part of the resolution of the SEC investigation, Halliburton will retain an independent consultant to perform a 60-day initial and, approximately one year later, a 30-day follow-up review and evaluation of Halliburton's anti- bribery and foreign agent internal controls and record-keeping policies and to adopt any necessary improvements," the company said.
----------------------------------
The application for continuous auditing and monitoring in helping organizations monitor internally for potential FCPA violations is particularly positive, because these compliance issues can be assessed concurrent with other operational challenges such as duplicate payment or overpayment.
Joe Oringel
Visual Risk IQ LLC
Charlotte NC, USA
Visual Risk IQ LLC
Charlotte NC, USA
Thursday, February 5, 2009
Check out "The Fraudies", Oversight's list of top Corporate Fraudsters
The folks at Oversight Systems have announced The Fraudies, a light-hearted collection of some of the bolder attempts to defraud corporations that have been detected or deterred by continuous auditing and monitoring. My personal favorite is the individual who used their company's P-Card to purchase $3,400 worth of advice from the Psychic Hotline. Let's hope the psychic didn't tell the fraudster to join your firm.
Unfortunately, today's challenging economic times are increasing the pressures and the rationalization behind more potential fraudsters. We are working with a number of organizations in different industries, to help increase the likelihood of detection by implementing cost-effective monitoring techniques.
Using these techniques as part of regularly scheduled audits of Accounts Payable, Travel & Entertainment or P-Card audits can help organizations achieve compliance objectives while also returning money to the bottom line by reducing overpayments and re-capturing inappropriate disbursements. Further, like the Fraudies, we hope that by publicizing these instances of fraud, other future fraudsters will be deterred.
Unfortunately, today's challenging economic times are increasing the pressures and the rationalization behind more potential fraudsters. We are working with a number of organizations in different industries, to help increase the likelihood of detection by implementing cost-effective monitoring techniques.
Using these techniques as part of regularly scheduled audits of Accounts Payable, Travel & Entertainment or P-Card audits can help organizations achieve compliance objectives while also returning money to the bottom line by reducing overpayments and re-capturing inappropriate disbursements. Further, like the Fraudies, we hope that by publicizing these instances of fraud, other future fraudsters will be deterred.
Joe Oringel
Visual Risk IQ
Charlotte NC 28277
Sunday, December 28, 2008
Visual Risk IQ to Partner with Vonya Global: Providing Data-Driven Audit Services
Feedback from the Continuous Auditing Life Cycle workshop that we did with Vonya Global in Chicago was very positive; consequently, we have developed a partner relationship with them to market and deliver two services specifically focused at helping audit executives recover costs and increase margins during challenging economic times.
The services analyze historical purchasing and sales transactions looking for overpayment, contract pricing variations, and other operational and compliance issues. Clients benefit from tangible recoveries, while also receiving advice on monitoring controls that can be used to prevent future errors.
On Point Data Analytics(sm), the first service provided by the two firms, is directed primarily toward internal audit and executives responsible for Governance, Risk and Compliance. On Point Data Analyticcs analyzes client's data in the context of an internal audit project, thus providing hands-on audit software training while accomplishing specific audit objectives. The service also includes an assessment of an organization's capabilities and readiness for continuous auditing.
On Point Continuous Controls Monitoring (sm), the second jointly provided service, is designed to help companies understand the value of more in-depth and frequent monitoring solution. The services includes an in-depth analysis of historical transactions using a best-in-class continuous monitoring tool, and identifies operational and compliance issues along with improvements that can prevent future errors.
Click here to read the entire press release
Bookmark this blog to read case studies and client profiles that highlight examples of cost recovery and other savings that have paid for the services many times over.
Friday, December 26, 2008
ERM Resources from NC State
During the last several months, I have been attending the Enterprise Risk Management (ERM) roundtables at NC State University in Raleigh. These ERM roundtables provide thought-provoking Continuing Professional Education (CPE) and networking opportunities for Governance, Risk and Compliance professionals on a regional and national level. Previous presentations are archived on the web at: http://mgt.ncsu.edu/erm/Roundtables.php
The purpose of the ERM program is multi-dimensional. They aspire to provide outreach (through the roundtables), research (through an outstanding web portal), and undergraduate and graduate education.
Speakers this fall included Jim Traut, Director of ERM at H.J. Heinz, and Drew Zavatsky, Office of Financial Management from the State of Washington, and the February roundtable will be in Charlotte NC. Steve Dreyer of Standard & Poors (S&P) will be presenting on their use and evaluation of ERM as part of S&P's ratings process.
Continuous Auditing combines more frequent risk assessment with more frequent and in-depth control assessment. Since ERM represents leading edge practices in risk assessment, we will continue to identify opportunities to link continuous controls monitoring to ERM, to provide more data-driven risk assessment.
Stay tuned for more information in 2009 about these initiatives.
Joe Oringel
Charlotte, NC
Visual Risk IQ
The purpose of the ERM program is multi-dimensional. They aspire to provide outreach (through the roundtables), research (through an outstanding web portal), and undergraduate and graduate education.
Speakers this fall included Jim Traut, Director of ERM at H.J. Heinz, and Drew Zavatsky, Office of Financial Management from the State of Washington, and the February roundtable will be in Charlotte NC. Steve Dreyer of Standard & Poors (S&P) will be presenting on their use and evaluation of ERM as part of S&P's ratings process.
Continuous Auditing combines more frequent risk assessment with more frequent and in-depth control assessment. Since ERM represents leading edge practices in risk assessment, we will continue to identify opportunities to link continuous controls monitoring to ERM, to provide more data-driven risk assessment.
Stay tuned for more information in 2009 about these initiatives.
Joe Oringel
Charlotte, NC
Visual Risk IQ
Subscribe to:
Posts (Atom)