Wednesday, June 15, 2011

Continuous Auditing and Monitoring Bootcamp Scheduled in Atlanta

Visual Risk IQ will be leading a one-day workshop in Atlanta, hosted by the Georgia Society of CPA's. The workshop is designed to help you get started on the path to delivering measurable results with continuous monitoring and auditing.

We will discuss overall methodology, detailed design for constructing a CA program, talk about current technology, and demonstrate how to turn “CA” into “CM” to benefit your entire organization.

Outcomes from the class will include a Company-specific roadmap, customized for your business and stakeholders, to target the risks you identify and benefits you want to achieve.

Attendees will receive up to seven hours of NASBA-compliant CPE and accomplish the following learning objectives.

1. Business challenges today, and how early detection mitigates greater risks
2. Working definitions of CCM, CM and CA and supporting technologies
3. How to determine where your organization is on the CA/CM maturity model
4. Hurdles to CM/CA implementation and how to overcome them
5. How to dive deeper to determine specific needs in developing the roadmap for CM/CA implementations
6. Proven methods for engaging other stakeholders

For more information, see the following Registration page, or see our Events webpage to download a more detailed description.

Monday, April 4, 2011

An $8 Million Question: Why do auditors test changes to Vendor Master Files?

One of the early audit tests that I was responsible for was to review who had access to change our vendor master file, and to make sure that all those changes were logged, reviewed, and approved. Our audit objective were validity - making sure that all changes to the master file(s) were properly authorized. But even authorized changes to the master file create risk.

Case in point: Conde Nast's $8 million email scam, as reported in this Forbes Magazine blog posting from William Barrett and Janet Novack.

What seems to have happened in the Conde Nast case is that a fraudster sent in a change of address / change of banking information request on behalf of a legitimate vendor. But the bank information provided was not the actual vendor; rather it was an account set up by a fraudster with a similar name and address as the real vendor. So properly authorized payments totaling nearly $8 million were misdirected. The fraud was detected when the real vendor called to ask "where's our money?"

A variety of preventive and detective controls began to visualize in my head when I read this story. How are changes to address and/or bank information communicated from your suppliers? How are these changes corroborated?

How might data analysis be used to identify mis-matches between supplier names and addresses? Seems like a good time to ask at your organization, even if an AP audit is not on the current quarter's schedule.

Joe Oringel
Visual Risk IQ
Charlotte, NC USA


Monday, February 21, 2011

Book review - a Great Read for Data Analysis Folks

Just finished Malcolm Gladwell's "What the Dog Saw" on a long plane ride this weekend. Like his other books (Tipping Point, Blink, and Outliers), there are great stories and examples for those of us involved in data analysis, including internal auditing and especially continuous auditing.

Gladwell's current book is actually a collection of essays from New Yorker magazine, but they piece together nicely so the essays can be read in sequence or by selecting chapters of interest. If you have time to only read one chapter, I'd point you toward the chapter "Open Secrets. Enron, Intelligence, and the Perils of Too Much Information."

The book points out that Enron's Special Purpose Entities (SPE's) were entirely transparent. To a fault. Because each of the more than 3000 SPE's involved paperwork of an average of 1000 pages of filings. Even an executive summary of an SPE contained 40 single-spaced pages. So the challenge in understanding the financial risks of their SPE's was to understand how to filter an insanely large volume of data into a form that was manageable, comprehensible, and actionable.

As you progress on the Continuous Auditing and Continuous Monitoring Maturity Curve, you'll find that your teams are amassing a similarly overwhelming (though hopefully not as large!) set of source data and anomalies to review. How do you see the source data? How do you see the exceptions? How do you decide which ones to act on?

Most data analysis efforts that we have worked have a goal of identifying individual exceptions, or rows, in database speak. So a AP vendor shares an address or tax ID number with an employee. Or a sales invoice had a discount in excess of a contract maximum. To act, we send an email to someone, maybe with a spreadsheet attached, to research and resolve the exception row.

But let's learn from Enron's SPE's. If we send 3000 emails, how will we manage the follow-up. Can we use color and graphs to measure the magnitude of the exceptions in total? How should we identify transactions that are acceptable one-by-one (example: a $9,500 requisition from a manager with a $10,000 signing authority), but unacceptable as a larger series (say ten, $9,500 requsitions from that same manager, all within the same week)?

Monday, January 31, 2011

How to update the IIA GTAG for what's new in Continuous Auditing?

Today's blog seeks to assimilate some of the things we heard at the IIA International conference last summer in Atlanta, in advance of this week's IIA Working Group discussions regarding the Global Technology Audit Guide (GTAG) on Continuous Auditing #3. The purpose of the Working Group discussions are to identify areas of the GTAG that require updating, so we are pleased to be able to participate with such an esteemed group of colleagues.

I wrote last summer about the IIA International conference, and how Data Analysis and Continuous Auditing were discussed at that three of the more interesting presentations at that conference. Those presenters Dan Kneer, Steve Biskie (ACL Services) and Robert Mainardi, and each presenter spoke on some combination of Data Analysis, Continuous Auditing, and Continuous Monitoring. Though they used many of the same words and terms, their perspective often seemed quite different.

Is Continuous Auditing about audit project selection and Risk Assessment. Yes. So techniques such as regression analysis, ratio analysis, and other analysis of aggregate data should be considered in any GTAG update. But Continuous Auditing is also about more frequent updates of subjective data, like control self-assessment, surveys, and call program activities. Similarly Continuous Auditing can and should include data analysis of transaction details. And greater frequency of data analysis, to include Visual Reporting also aid greatly in Risk and Control Assessment activity. Perhaps text analytics and analysis of unstructured data too.

Looking forward to this week's Working Group, so we can find some distinctive words to distinguish the various types of Continuous Auditing activities for inclusion in any updates to the GTAG.

Since Continuous Auditing can

Joe Oringel
Visual Risk IQ
Charlotte, NC USA

Saturday, November 6, 2010

Highlights of Day 2 Rutgers WCAS

More case studies on Saturday than Friday - presenters have included Hewlett-Packard, Proctor & Gamble, IBM, and Siemens Financial, among others. Highlights from these presentations include:
  • HP presented their use of monthly data extraction and a variety of CAAT-based and ERP query tools to interrogate transactions and logs. They evaluate a mix of configurable controls and transaction analysis to deliver a risk-based heat map that aids the audit team in project selection decisions. They've made excellent progress from prior years, and continue to be a leader in CA / CM, especially among SAP shops.
  • P&G presented about their measurement around the business case for their CA / CM investments, which have focused primarily around order to cash (O2C). Their program's strengths are its workflow, in that audit uses "automated delivery of high quality controls tests results to the business." It's the evolution of having MANAGEMENT evaluate the test results (vs. internal audit) that was most noteworthy.
  • IBM presented about their system that they call Enhanced Auditing with Technology, which is also focuses on O2C. They monitor more than 400 query test attributes (contrast w/ Siemens Financial, who monitors only 45!).
  • Jason Gross of Siemens Financial presented their CCM program with considerable energy and enthusiasm. Jason and I had previously met at an IIA event during 2007, when he had been in Internal Audit. Interesting is that he has left audit and is now a direct report to the CFO at Siemens Financial. This option should be on the career path of most data-focused, audit professionals as it allows Jason and his team to have more responsibility for research and follow-up on CCM exceptions.
As additional slide decks are posted, I expect to update this and other blog posts from the weekend. - UPDATED w/ HP deck.

Best wishes,

Joe Oringel
Visual Risk IQ
Newark NJ

Friday, November 5, 2010

Top 10 Things that Go Wrong in a Continuous Auditing Project

Very nice summary from Patrick Taylor from Oversight Systems of their experiences from CA and CCM implementation. Patrick did a very good job of sharing examples and screen shots of how their tool are being configured to monitor both routine and non-routine transactions.

10. Compliance is the Lead
9. Your eyes are bigger than your stomach (you try to monitor everything)
8. Look through this report please (tedious, there's no bottom to the report)
7. Let's learn a specialized analysis language (instead of SQL)
6. Let's clean up the last two years of exceptions (10000++ exceptions. Yikes!)
5. Continuous Audit instead of Continuous Improvement (i.e. Use Reason Codes)
4. Don't know how to spell Vasarhelee, Vaserheyli, Vasarhellee, Vasarhelyi... (LOL!)
3. Only know how to Audit AP (other apps are
2. Bringing a knife to a gun fight. (re-testing what is already controlled by ERP)
1. Not Using Oversight (LOL x 2)

More from Rutgers WCAS. ACL, XBRL, and Caseware RCM (alphabet soup indeed!)

Excellent presentation by ACL's John Verver on their Data Analytics Capability model. The shout out regarding our similar CA Maturity model was much appreciated. ACL's efforts to chart the path from one-time, retrospective data analysis (i.e. Hindsight) to more frequent, even predictive data analytics (i.e. Foresight) is on-target.

Noteworthy is that their model doesn't necessarily advocate "continuous" as the desired frequency for data analysis, either for Internal Audit or for management-led monitoring efforts. The right frequency depends on the relative risk of the process and data that is being analyzed.

These slides aren't up yet on the Rutgers site (UPDATE - Link provided above), but I'll look to post a link when they're uploaded. Very good content here for building a simple path toward more frequent, data driven auditing and monitoring.

Following John was Eric Cohen from PwC who provided some excellent information on the state of tagging and XBRL as a technique for automated data acquisition. The ability to acquire external data (e.g. competitor financial results) and compare those results to our own results is an excellent management tool, and one that is now beginning to be realized.

Following Eric Cohen was Andrew Simpson. Andrew is the Chief Operating Officer, CaseWare RCM Inc., formerly SymSure Ltd. Andrew's slide on the cycle (aka "yo-yo") of control measurement and how greater frequency yields continuously improving controls. Though CaseWare is a relatively new entrant in the CA / CM space, they seem to have excellent potential. UPDATE - link to Andrew Simpson's slides, which are now posted at WCARS site: