The analytics team was now at three people – so I could build some overlap in our knowledge of the application systems that were we accessing on a regular basis. For example, this meant that I was no longer the only person who understood the financial system. Now we had at least two people for each of the 10-12 systems we were accessing on a regular basis. For all but the inventory system (an IMS database we accessed with ACL for MVS IMS interface) we were getting monthly extracts – either by running the extract jobs ourselves, or as a standard production job.
The first question I had to address in building a team was the level and experience of the people that should be part of the analytics function. A related question was: Should an auditor be taught programming (data extraction and analysis) or should a programmer be taught to conduct audits? Failures in implementing analytics have one thing in common — management did not assign the right person or people to the task. Too often, a junior programmer with limited or no audit experience — addressing only the IT aspects of the job — is assigned to develop the analytics function. Given the nature of the task — dealing with business process owners, system programmers, and review team leaders — the analytics function must be staffed at the appropriate level and with the necessary experience. The biggest hurdle is having the business process knowledge to identify the types of analytics to run. Because of management’s support, I was able to hire people at senior auditor or team leader levels. One was a programmer with IT audit experience, the other a programmer willing to learn about audit.