Year 20 – 2007 – Inventory

It was hard to believe, but I had now been at this (data analytics to support audit) for 20 years.  And I still found it interesting, challenging, frustrating, rewarding and aggravating – all at once.

I was constantly being asked to access new systems and perform analysis for different types of audits.  At the same time, I had my regular monthly routine tasks of extracting, downloading and cleansing data we used on a regular basis.  For example, the SAP extract – full year-to-date extracted and download every period – would take most of the day to perform by the time I got to period 8.  I could only download one period at a time because of CPU limitations – so I would start a background extract of period 1 and work on other things.  When it finished, I would extract period 2 and download period 1; and so on until I reached the current period (AX and DirectLink would have made things much simpler).  In addition, I had to extract and download the 12 master tables (vendor, customer, cost centre, GL, etc) that I needed every quarter.

Once all year-to-date extracts had been performed, I had a script that combined the periods and transformed the detailed transaction (BSEG table) and the header (BKPF Table) into a more useful data set where the customer and vendor information was on every line of a document.  The script also produced a snapshot of the controls and summary files (by GL; by Cost Centre; by Vendor; etc.).  Next I would combine data from the previous “X” years to produce multi-year summaries (by GL by year; by Cost Centre by year; etc.).

Continue reading Year 20 – 2007 – Inventory

Year 19 – 2006 – Health Claims

Note: I hope this is like the ACL forum where there are more people reading it, but not posting questions/answers.  While I am enjoying my trip down memory lane – it is a lot of work and it would be a shame if I was the only one reading the posts.  My aim was to encourage discussion and sharing – this is not happening and lessens the value of the blog.  So post a comment, describe your experience, etc.

My early introduction into audit included the concept that audit was an early warning for management (this was before “independent assurance”).  It had the notion of identifying things that were going wrong and making useful recommendations (this was also before the idea of “risk”).  However, my belief was always that audit was there to help; and that the help could and should be offered to all levels of management.  Luckily, I did not see these as incompatible ideals; and to a certain extent so did my managers.

I remember often having discussions over who was audit’s “client”.  We reported to the Board – and they were the main recipients of our reports.  So they were a client.  Senior management also received the reports and responded to the recommendations – so they were a client.  But local management was the group being assessed and had to implement the recommendations – so this made them a client.    The issue was, the three groups had very different motivations and needs.  A high-level report was of little value to the local manager who need to fully understand the “cause” associated with the finding in order to be able to adequately address the issue; whereas senior management and the Board were more concerned with the impact.  Hence the ongoing debate of “who is our client”.

For a number of years, we actually produced three levels of reports.  The local manager detailed report with criteria, condition, cause, impact and recommendations; the management report which focused on the “what does it all mean” (impact and recommendation; and the Board report which presented an overall assessment.  In the end we were spending as much time writing the report(s) as performing the actual audit.

Your thoughts/experience on who is your client and how do you address the needs of your audience?

Auditors are often asked to examine fairly sensitive areas.  This can also mean that you have access to personal information.  Depending on your definition, this could be executive compensation, but in this case (for me) it was health claims.

Continue reading Year 19 – 2006 – Health Claims

Year 18 – 2005 – Quantitative Indicators of Risk – part 2

This is Part2 of an article on developing quantitative indicators of risk to support the annual risk-based audit planning process.

Part1 presented the concept that risk (Probability and Impact) can be measured quantitatively by looking at Complexity and Change (which increase the probability) and Materiality or Volume (which increases the impact).  It also encouraged you to look at more than financial risk.  Part 2 presents examples of indicators of risk and an approach that you can use to develop your own quantitative indicators.

The following are examples of data-driven risk indicators for various risk categories:

  • Financial – an entity that has multiple responsibility centers, a large degree of discretionary spending, and a high number of journal entries and suspense account transactions has a higher level of financial risk than one that has a single responsibility center and primarily non-discretionary spending (e.g. regular salary).
  • Operational – a production plant that has multiple production lines that produce both standard and customized products, requiring changes in the product line, has a higher operational risk than one with a single production line producing a standard product.
  • Legal – an entity that is highly regulated and subject to national, international regulations and has a higher level of ongoing litigation has a higher legal risk that one that is not regulated.
  • Technological – an entity dependent on rapidly changing technology has a higher technological risk that one that has a stable technological environment.
  • Environmental – entity that is highly regulated in an area that is subject to changing environmental regulations, has a lower level of organizational maturity and experience levels of staff, and high costs of non-compliance has a higher environmental risk than one that is not regulated or has minimal non-compliance costs.
  • HR – an entity that spans multiple locations and has full-time, part-time and casual employees – many with very little experience – has a higher level of HR risk than one that operates from a single location and only has full-time employees with many years of experience.

The data-driven indicators are relative – comparing the risk level of an audit entity to other entities (e.g. one activity or region to another).  The result is a data-driven relative risk ranking of each entity on each risk indicator and risk category.   The overall risk for each entity/activity can be assessed by combining the rating for all risk categories.  Thus, audit can identify entities with the highest financial or operational, etc. risk and the entities with the highest overall risk; or assess the effectiveness of risk mitigation efforts on corporate risks.

Data-driven indicators make the risk identification and assessment process easier to update, more responsive to changing levels of risk; and they support an analysis of the source of the risk.  Transactional quantitative indicators of risk can be viewed at any level or slice of the organization.  Auditors can drill down into a corporate risk or risk category to assess and compare every region, plant, division, project, etc.  The risk categories can also determine, for example, what is causing a higher level of legal or strategic risk.  In addition, during the development of the annual risk-based plan or the corporate risk profile, the analysis supports the conduct of more productive interviews with management.  It provides insights that allow auditors to ask questions that focus on the areas of highest risk to the specific audit entity (e.g. “Why do you have twice the number of journal entries and reversals as other financial managers?” or “What are your plans to address both the high existing HR vacancy rate and the large number of employees who are eligible for retirement within two years?”).   This can direct management’s attention to risks that might not have been known previously – making the risk discussion more valuable to both parties.

During the planning phase of an audit, drilling down into the data-driven indicators can focus the audit on specific risk issues (e.g. operational inefficiencies, emerging regulatory changes) or identify best practices.  For example, it is easy to examine the risk indicators for an audit entity to determine the factors causing, for example, HR risk to be high.  This can help shape the audit scope and objectives making the audit more effective and efficient.

Data-driven risk indicators can also be used on an ongoing basis to assess the risk associated with specific corporate initiatives (e.g. a proposed merger or acquisition) on all categories of risk not just financial.   For example, a quick assessment of the HR risk factors could identify emerging HR issues (high turnover and eligibility for retirement rates) in a company where a merger is being proposed.  Data-driven risk indicators can also highlight financial risks related to the proposed merger company’s current financial management control framework including highlighting a different financial management framework which may negatively impact the merger.  In addition, a potential merger’s risk indicators can be compared to previous mergers (successful and unsuccessful) to determine the relative risk and areas of highest concern.  This would better inform management decisions and risk management activities.

To support the risk-based plan, the identification of potential data-driven risk indicators should be considered for each corporate risk and for all risk categories.  Auditors should work with the Chief Risk Officer and subject matter experts to examine the risks; identify drivers that affect the risk; and develop data-driven indicators for each risk driver.   Table 1 is illustrative of the process to identify data-driven risk indicators for HR.  The same process can be used for each risk category (finance, legal and regulatory, etc.).  The first step is to define the sub-categories of risk (e.g. recruitment); then the associated risk drivers (e.g. lack of resources); and finally the data-driven risk indicator (e.g. increasing number of vacant positions).

Table 1 – Development of HR Risk Category Indicators

Risks Risk Driver Data-Driven Risk Indicator
Recruiting – failure to attract people with the right competencies. ·  Lack of resources

·   Lack of skilled employees

•    Vacancies

•    Acting appointments

Resource Allocation – failure to allocate resources in an effective manner to support the achievement of goals and objectives. •   Inappropriate resources for tasks

 

•    Employee type (full-time, part time, seasonal, contractor, etc)

•    Employee classification

•    Employee status

•    Unions

Retention – failure to retain people with the right competencies and match them to the right jobs. •   Demographics

•   Low experience levels

·   High turnover

•    Years of pensionable service

•    Average age

•    Average years in position

Work environment – failure to treat people with value and respect. ·   Unhappy workforce

·   High sick leave

•    Average sick leave/vacations

•    Percentage departures

 Once identified, the data-driven risk indicators should be categorized as indicators of volume, variability/change or complexity.  The same process would be performed on the other risk categories.

Since each risk category (finance, HR, legal, etc.) will have several risk indicators related to each of volume, variability/change and complexity, determining the overall risk for each audit entity will be difficult to do manually.  For example, you could have 7-8 risk categories (finance, HR, operations, legal, technological, etc.); with 5-10 risk indicators for each of volume, variability/change and complexity; and 20-50 audit entities for the annual risk-based audit plan totalling 700 – 4,000 risk measures.  However, the details allow you to look at risk from an overall, a risk category or even a risk factor perspective.  For example, you could easily determine that Entity A has the highest overall risk score, which is due to high risk scores in Finance, Operations and HR.  The HR risk is being driven by high variability (employee turnover and percentage eligible for retirement) and the finance risk is due to the complexity of the financial framework.  This will inform the planning phase of the audit of Entity A.  A similar analysis can determine which audit entities are having the largest impact on corporate risks.

While the details provide information to support the planning and conduct of an audit, the risk-based plan needs a higher level view of risk.  The solution is to develop a single composite data-driven risk score for each entity which includes all risk categories.  This is a multi-step process, the first of which is to develop a single risk factor score for each of volume, variability/change and complexity for each risk category; second, consolidate the risk factor scores into a single risk category score for each risk category (finance, HR, operations, etc.); and third, consolidate the risk category scores into an overall risk rating for each entity.

The data-driven risk ratings can be used to rank entities based on based on their overall risk.  In addition, qualitative and auditor judgment factors can now be included to arrive at a final risk rating. The final results can be sorted by risk ranking and audits assigned based on availability of resources.

The identification and assessment of data-driven key risk indicators can be accomplished easily and with minimal investment.  A data-focused approach will allow internal audit to identify issues, target risks and allocate resources more effectively.  It will support professional auditor judgment and make the annual risk-based audit plan more defensible, easier to update, and backed by quantitative and qualitative factors.  The data-driven risk indicators are useful during the interview process, aid the planning phase of individual audits, and can be used to keep the annual risk-based audit plan current.  The risk indicators can also be used to update corporate risk profiles, and assess the effectiveness of risk mitigation strategies and the risk associated with new strategic initiatives – providing valuable advice to senior management on all categories of risk.  Audit functions that leverage a quantitative, data-driven approach to identifying and assessing risk, are more relevant to the business and can provide more efficient and improved risk coverage to senior management and the Board.

 Examples of HR data-driven risk indicators

Volume / Size

·          Number of employees

·          Total dollars of payroll

Variability/Change

·          Average age

·          average age of senior managers

·          Average years of pensionable service

·          % of employee who can retire in least than 2 years

·          Experience – years in dept / position / classification

·          % fulltime employees

·          % positions affected by org change in last year

·          % employees in acting assignments

·          % new hires (within last year)

·          Total leave taken

·          Average sick leave taken

·          Average vacation leave take

·          Average unpaid leave taken

Complexity

·          # types of employee

·          # classifications of employee

·          # geographic locations

·          # unions

·          % employee with non-standard hours

Other

•       % by Gender (M/F)

•       % First Official Language (Eng/Fr/Sp/etc.)

Examples of financial data-driven risk indicators

Volume

·          Total Expenses

·          Total Revenue

·          Total Assets

Variability/Change

·          Percentage of discretionary spending

·          Percentage of expenditures in Period 12, 13+

·          Total and number of JVs

·          Total and number of suspense account transactions

·          Total and number of Reversal documents

·          Total and number of Losses

·          Percentage of A/P transactions paid late (> 30 days)

·          Percentage of A/R transactions more than 30 days overdue

Complexity

·          Number of Cost centres

·          Number of General Ledger accounts

·          Number of Foreign Currencies,

·          Number of Document types

·          Use of Internal Orders

·          Use of Purchase orders

·          Use of Fund reservations

·          Use of Materiel and Asset numbers

·          Use of Real estate blocks

·          Use of Work Breakdown Structure

·          Number of Employees

·          Number of P-Cards

ACL Commands: TOTAL, STATISTICS, CLASSIFY, EXPRESSIONS, and RELATE.  While the process used scripts to perform all the analysis, the commands were basic – such as Total Age 1 “Number_Emps” and then calculating the average age (Age / Number_Emps).

Lessons-learned: the analysis was extremely useful – particularly when discussing risks with managers.  We have the risk measures for each audit entity and could ask pointed questions of managers of projects or activities or ask senior managers about emerging areas of risk based on a comparison of previous years’ data.

“Built it and they will come” – is sometimes true, but I found that I often had to educate the auditors on how to review the results and drill down into the details to better understand the source of the risk.  To me it seems obvious – because I view a business process or activity from the data perspective – but this was not the case for all the auditors.  They would have a financial, HR or environmental lens and couldn’t see how the data helped.  Fortunately, with assistance, some were able to understand what the data was telling them about the entity/activity/process.

Using data-driven indicators of risk we were able to update the RBAP on a quarterly basis in hours.  This allowed us to ensure that we were dealing with the highest areas of risk and to identify emerging areas of risk early.

Year 18 – 2005 – Quantitative Indicators of Risk – part 1

This was my first attempt at identifying risk to support the development of the annual risk-based audit plan (RBAP).  I have been involved in the development of the RBAP – even responsible for it – over the years and always felt that it was more professional opinion than anything else.  Some people built a spreadsheet with weighting factors 1-5 and fooled themselves into believing that there is a logic and quantitative underpinning to the RBAP, but in the end, the auditors are providing the weighted scores based on professional opinion.

My approach was to use data analytics to support the qualitative aspects of the plan (auditor judgement, interviews with managers, previous audit results, etc.).  This was for two reasons: first, quantitative indicators are easier to update; and second they provide assurance that we were also considering emerging risks.

Below is part 1 of an article I submitted to the IIA magazine.  It was not published because they did not consider it to be “relevant to internal auditors” (????????), despite the fact that the IIA standards call for a continuous risk assessment.  I think that the reviewers didn’t understand the ease and utility of developing the data driven risk indicators.  I hope you find the article useful.

Developing data-driven indicators of risk to support the ongoing assessment of risk – Internal auditors face a daunting task of identifying and assessing risk.  The results of this activity are critical as they serve to ensure that scarce audit resources are being expended on activities that best address the risks identified by senior management.  The initial assessment of risk typically includes reviews of the corporate risk profile, business plans, financial statements, previous audit reports, and interviews with senior managers with question such as “What keeps you awake at night?”. The process can take weeks even months to complete.  Contrast this with the IIA standard #2010 which states that the chief audit executive must review and adjust the plan as necessary, in response to changes in risk, operations, programs, systems and controls and you can see where audit has a problem.

Continue reading Year 18 – 2005 – Quantitative Indicators of Risk – part 1

Year 17 – 2004 – Part 2 – Construction

From time to time I was lucky enough to get to do some consulting work.  These were usually fairly large audits, involving a number of external experts.  As the “data guy” I was often given very little time to perform the required analysis.  On such audit was a review of the costs for a major construction project.  The audit team did not have all of the necessary expertise and had hired experts in project management, construction, and data analysis (me).  It was interesting to work with experts from outside of audit and in an area that I did not have a lot of expertise (construction).

The audit was requested by senior management.  Management was concerned because they knew that the manager responsible for a major, multi-phased, construction project would have a great deal of influence over the contractors.  It was early in the construction project and millions of dollars worth of contracts were still up for grabs.  Management felt that this put the project manager in a position where he could request “favors” from the contractors in exchange for the promise of future contracts.  They also knew that the company did not have a lot of experience in managing construction projects.  For these reasons they requested that audit perform a multi-phased review of the project – starting with the controls over the project management office.

It was not a surprise to anyone when the auditors determined that the project manager had arranged for one of the contractors to do work on his house, and bill the cost to the company.  But, the audit director was curious about how the auditors had found the fraud so quickly.  They had only been at the construction site for three days, and had already uncovered more problems than any other audit team had found in audits lasting months or longer.

Continue reading Year 17 – 2004 – Part 2 – Construction

Year 17 – 2004 – Part 1 – Direct Deposit

This was the year that I re-published my second book “Fraud Detection: A Revealing Look at Fraud (2004).  This dealt with obtaining, verifying and analyzing the data to support fraud prevention, detection and investigation.  However, it was also relevant to regular internal audit analyses.

I thought I would do something a little different this week – so here is a fraud analysis story.  It is based on an actual fraud analysis that I performed.  In telling this story over the years, I have had a number of people tell me that their company had experienced a similar type of fraud.  Which raises the question: “Why do companies so often ignore basic controls like separation of duties?”

Direct Deposit – Bill was not happy when he returned from the quarterly management meeting and Tom wondered why.  Bill explained a fraud that had been discovered – but not by internal audit.

“It went like this,” said Bill, “you know how we employ a lot of casual workers – people who may show up for anywhere from 1 day to 6 months.  Well it seems that an 8-month investigation in the payroll area has determined that the person in charge of keeping the attendance records has been committing fraud.”

“Wait a second’, exclaimed Tom, “we haven’t been conducting an investigation”.

Bill shook his head, “that is part of the reason why I am so upset.  First there was a fraud, and second we weren’t even notified – contrary to what the corporate fraud policy states, I might add.”

The supervisor of the payroll section noticed a weakness in the system.  Even though the casual workers were not around for long, everyone was paid by direct deposit.  This procedure was put into place when a fraud involving payroll checks was discovered a few years back.  The weakness was two-fold – first, the payroll supervisor was responsible for the sign-in sheet.  Every time a casual employee reported to work, they signed in and recorded their hours.  The second weakness was the fact that the same supervisor was responsible for the entry and update of the basic employee data, including the direct deposit number.  Seems that, upon learning that a casual employee was not planning on returning to work, the supervisor would continue to record their attendance, but would change the direct deposit number to a bank account that he controlled.

“Nice scheme”, responded Tom.  “I presume he kept his extra earning down to a minimum amount.”

“Sure,” said Bill.  “He never kept anyone on for more than 20-30 hours, but with so many casuals, he was clearing an extra week’s pay every week.”

The scheme was discovered when a casual worker received his income tax statement and compared it to his paychecks.  He called to talk to the supervisor, who just happened to be off sick that week.  A new employee, eager to impress her boss, researched the problem while the supervisor was off and discovered the fraud.

Now Tom was confused.  “It sounds pretty straightforward to me.  Why did it take eight months to investigate the fraud?”

Bill explained, “She called the police and they pulled all of the attendance sheets and copies of the bank statements.  Then they did a manual review – looking for the same direct deposit number turning up for more than one employee.  Seems that our payroll supervisor was not working alone, his girlfriend also had several checks deposited to her account.”

“Still – eight months?” cried Tom.

Bill laughed, “You’re right.  Since this was a white-collar crime, they only worked on it when there was a lull in other police work.  As a result, we lost even more money, and the payroll supervisor found out about the investigation and had time to make a run for it.”

“Well I guess we lost another one,” lamented Tom as he headed for the door.

“Get back in here – were not done with this yet,” said Bill.  “I want you to verify the police work – make sure they didn’t miss anything.  And I want it today!”

Using data analysis, all pay transactions for the last two years were examined – looking for all instances of the same direct deposit number being used by more than one employee.  While it did identify two cases where the husband and wife both worked for the company, it also identified four accounts that had been used to collect extra pay.

Bill smiled, “that is two more than the police found.”

“And it only took 45 minutes,” said Tom.

But still Bill wasn’t happy – something was nagging at him.  Tom was just about to ask what the problem was when Bill shook his head and exclaimed “Boy, am I a fool”.

Tom bit his tongue and did not reply “Yes, but why do you ask?”

Instead he waited for Bill to continue. “I wasn’t happy when I heard that the police had conducted a manual investigation.  I knew that matching direct deposit number to employee was much easier for a computer.  But there was more to it than that – I just didn’t realize it until now.”

Tom couldn’t wait any longer, “What?” he said.

Bill just looked at him and replied, “Run the analysis for all of our payroll sections across the country.  If it is happening here, I’ll bet my last dollar it happening elsewhere.”

Tom walked into Bill’s office two months later and said, “That clears up our payroll fraud case.”

“What was the final result?” inquired Bill.

“Well, we recovered close to $209,000 and are prosecuting four people – the criminal cases look promising.” replied Tom.  Bill waited.  “Oh ya, and we fixed the control weakness too.”

Finally, Bill was pleased; the data analysis had taken less than two days to complete, was instrumental in proving the case in court, and had been easy to do.  But most of all, the direct deposit fraud had been properly and thoroughly dealt with.

ACL Commands: DUPLICATES and JOIN

 Lessons Learned:  1. The police don’t always place the same priority on a fraud investigation as you might like.  2. Fixing one control weakness may create another – it is important to review all controls when making changes to procedures.  3. Data analysis is often the ideal way to find evidence of fraud.        4. Once you have found a fraud and understand the control weaknesses exploited, look for additional cases of fraud.

Year 16 – 2003 – Recruitment Process

People, even those that perform analytics, often think that data analysis can only be applied to financial-type audits.  I have tried to highlight other types of audits where analytics played a significant role including transportation, inventory, and hazardous materials (environmental).   In that vein, I offer you analysis that was part of an HR recruitment audit.

he organization was an international/national police force.  Like many police forces, it needed a fairly continuous flow of recruits.  The problem with this agency was that the recruitment process – which leads to a six month training program – was overly long. In fact it was 18-22 months from the time a potential recruit entered the process until they were offered begin the training program.  During this time, they were not paid, and, as a result, many suitable recruits exited the recruitment process because they found other jobs.

Working with the HR section, the auditors determined that they were 36 separate steps in the recruitment process.  Some were fair minor – like completing an application form – while other were more time consuming – like the security clearance process.  I was able to obtain the recruitment data for the past 3 years.  The data contained the start and end date for each step for each recruit.  In reviewing the recruitment data I was able to determine that the steps were done in series – not in parallel.  This meant that before a recruit could enter step “n”, step “n-1” had to be completed.  Our first recommendation was to change the process to permit steps to be done in parallel.  For example, rather than waiting for the results of the written test (which could take up to two weeks), recruits could start on the physical test phase.

Continue reading Year 16 – 2003 – Recruitment Process

Year 16 – 2003 – Accounts Receivable

It was beginning to almost become routine – get data, perform analysis, identify significant results, make recommendations and, often, transfer the analysis jobs to management for continuous monitoring.  This doesn’t mean that there were problems: obtaining the data, persuading audit teams to use analysis, and sometimes convincing management to address the control problems.  It was a challenge and it kept the job interesting.

I was also performing consulting from time to time.  This year I was asked to assist an audit team in a retail company with branches across the country.  The company was having cash flow problems and the Vice President of Finance had questions about the efficiency of the accounts receivable department. I explained that an aging of the A/R transactions in ACL would quickly identify all invoices that were past the due date by 30, 60, 90 days, or any cut-off point he chose to specify.  We performed that analysis and confirmed the Vice President’s concerns, but the team leader decided to take the analysis a step further and calculate the average time each account was past due for each branch office.  Again, this was easy to do using the break field on the AGE command. In addition, he calculated the carrying cost associated with borrowing money to finance the shortfall in revenues.

Continue reading Year 16 – 2003 – Accounts Receivable

Year 15 – 2002 – Part 2 – IT Audit

Second part of article on making IT Audits more effective and value-added ….

The next area that will need to be address by CAEs is ensuring that risk-based audit plans are relevant and that selected audits provide maximum value to senior management.  Today’s business environment changes rapidly to adjust to market conditions, evolving legislation and economic forces; and the risk-based audit plan must keep pace with this rapid change if it is to properly identify and assess emerging risks that can impact the achievement of business objectives.

ISACA standards state that appropriate risk assessments approach should be used when developing the overall IS audit plan.  Risk should also guide IT auditors in determining priorities for the allocation of resources to provide assurance regarding the state of the IT control processes.  This means that risk should drive the IT audit plan and the focus of IT audit resources.  IT audit should use a top-down approach that starts with the identification of the business objectives.  The next step should be the identification of the key controls required, in both the application system and the business process, to provide assurance for the business objectives.  Finally, IT audit should identify the applications where the IT controls need to be tested in order to focus IT audit effort where it is needed most.

IT audit plans also need to lay the groundwork for integrating IT audit expertise within non-IT auditor to ensure that the risks associated with the IT systems are considered when assessing the overall risk in a business process.  Conversely, you should also be looking at the risks in the business processes and determining the IT controls that are mitigating these risks.

Continue reading Year 15 – 2002 – Part 2 – IT Audit

Year 15 – 2002 – Part 1 – IT Audit

Many audit shops rely on IT auditors to support their use of data analytics; however, the IT audits typically focus on general and application controls.  Around this time I wrote an article for the EDPACS magazine which encouraged IT auditors to look beyond the black box – to look at how IT supports, drives, and impact business processes.  I have included below.

IT Auditors need to come out of the black box

Are you an IT auditor who takes comfort in your specialized knowledge and feels secure in assessing general and application controls – but does no more?  Then you need to wake-up to today’s business environment and step out of your comfort zone.  You also will probably need to pull the general auditor away from the safety of pure compliance audits.  The notion of the integrated auditor was usually applied to the need for the general auditor to increase his/her knowledge of IT.  Alternatively, general audit teams were encouraged to include an IT auditor to assess the IT controls.  It was a one-way street that added IT expertise to the operational audit program.

Today, we are going through yet another time of economic and organizational upheaval.  IT auditors need to look at how they are contributing to the organization’s flexibility and sustainability.  They need to ensure that information systems supporting business processes are not obstructing the very improvements in operations that they are supposed to achieve.  IT auditors need to better understand the operations of the organization and how IT contributes to their effectiveness and efficiency.

As IT becomes more and more integrated with business operations, the role of IT audit is changing, moving beyond the black box, to a role that is tied directly to the achievement of business objectives.   Business processes rely on automated systems for controls and to support efficient and effective processes.  As a result, IT risks are a part of, not separate from, business risks.  In the current market conditions, marked by rapidly changing risks and tough economic conditions, testing of IT controls by IT auditors and compliance testing by general auditors cannot separately address risks and opportunities resulting from the integration of complex technology into multiple business processes.

Continue reading Year 15 – 2002 – Part 1 – IT Audit