Continuous Controls Monitoring ISACA, Houston Chapter. August 17, 2006



Similar documents
CONTINUOUS CONTROLS MONITORING

Continuous Controls Monitoring. Virginia ISACA January Meeting 19 January 2010

Application Control Effectiveness for SAP. December 2007

Integration Time, expense, cost, billing and work process data collected and approved in Tenrox software can be exchanged with:

IT Audit Perspective on Continuous Auditing/ Continuous Monitoring KPMG LLP

Manage and Control Access Risk and Assess Its Financial Impact

PwC The Path Forward for Data Analysis and Continuous Auditing May 2011

San Francisco Chapter. Jonathan Shipman, Ernst & Young David Morgan, Ernst & Young

Leveraging Continuous Auditing / Continuous Monitoring in internal audit April 10, 2012

Understanding ERP Architectures, Security and Risk Brandon Sprankle PwC Partner March 2015

Process Control Optimisation with SAP

Minimize Access Risk and Prevent Fraud With SAP Access Control

The Power of Risk, Compliance & Security Management in SAP S/4HANA

An Auditor s Guide to Data Analytics

EDUCATION, LEARNING AND TEACHING. I have never let my schooling interfere with my education. Mark Twain ( ) American writer.

Advisory Services Oracle Alliance Case Study

IT audit updates. Current hot topics and key considerations. IT risk assessment leading practices

Agenda 3/7/ ERM Symposium March 14 16, Continuous Controls Monitoring. I. Changes In Corporate Environment

Risk Management in Role-based Applications Segregation of Duties in Oracle

Reduce Audit Time Using Automation, By Example. Jay Gohil Senior Manager

ACL WHITEPAPER. Automating Fraud Detection: The Essential Guide. John Verver, CA, CISA, CMC, Vice President, Product Strategy & Alliances

Continuous Auditing / Continuous Monitoring

<Insert Picture Here> Looking to Reduce Operating Costs? Automate Your Expense Processing with PeopleSoft Travel and Expenses 9.1

Sarbanes-Oxley Control Transformation Through Automation

Application controls testing in an integrated audit

Building an Audit Trail in an Oracle EBS Environment. Presented by: Jeffrey T. Hare, CPA CISA CIA

Using data analytics and continuous auditing for effective risk management

Feature. Multiagent Model for System User Access Rights Audit

XBRL & GRC Future opportunities?

Data Analytics: Applying Data Analytics to a Continuous Controls Auditing / Monitoring Solution

OVERVIEW OF THE ISSUE

Great Expectations : How to Detect and Prevent Fraud using Data Analysis

Sarbanes-Oxley (SOX) The Migration from Project to Process. Practical Actions for Getting Started. Jim DeLoach, Managing Director.

Whitepaper. GL Consolidation. Published on: August 2011 Author: Sivasankar. Hexaware Technologies. All rights reserved.

Dynamic Enterprise Performance Management

S24 - Governance, Risk, and Compliance (GRC) Automation Siamak Razmazma

Financial Systems Integration

Data Analytics in Internal Audit. Elizabeth Dunkerley

An Introduction to Continuous Controls Monitoring

IDS for SAP. Application Based IDS Reporting in the ERP system SAP R/3

Data Analytics For the Restaurant Industry

Continuous Auditing: Implications for Assurance, Monitoring, and Risk Assessment

ERP Systems: Audit and Control Risks

Optimize procure-to-pay processes for profitability, efficiency, and compliance

Governance, Risk & Compliance for Public Sector

How to leverage SAP NetWeaver Identity Management and SAP Access Control combined solutions

Data Analytics: Applying Data Analytics to a Continuous Controls Auditing / Monitoring Solution

Demonstrating the ROI for SIEM: Tales from the Trenches

Electronic Audit Evidence (EAE) and Application Controls. Tulsa ISACA Chapter December 11, 2014

AUDITING AND ITS ROLE IN CORPORATE GOVERNANCE

GUIDE TO THE SARBANES-OXLEY ACT: MANAGING APPLICATION RISKS AND CONTROLS. Frequently Asked Questions

The Information Systems Audit

Transportation Solutions Built on Oracle Transportation Management. Enterprise Solutions

DEMONSTRATING THE ROI FOR SIEM

Compliance Management, made easy

GSK Vaccines: Easing Compliance with SAP Process Control

Information Technology Auditing for Non-IT Specialist

Risk-Based Assessment of User Access Controls and Segregation of Duties for Companies Running Oracle Applications

Losing Control: Controls, Risks, Governance, and Stewardship of Enterprise Data

Managing JDE security Compliance in World Automate your audit with SOXLock

The Differentiator A Great Internal Auditor. The Institute of Internal Auditors of Thailand

Technical Management Strategic Capabilities Statement. Business Solutions for the Future

Continuous Monitoring: Match Your Business Needs with the Right Technique

Internal Audit Practice Guide

Driving business performance Using data analytics

Ellipse The Enterprise Asset Management (EAM) solution for asset intensive industries

What Should IS Majors Know About Regulatory Compliance?

JD Edwards EnterpriseOne: Governance, Risk, and Compliance

Information overload: How to make data analytics work for the internal audit function

1. FPO. Guide to the Sarbanes-Oxley Act: IT Risks and Controls. Second Edition

ORACLE ENTERPRISE GOVERNANCE, RISK, AND COMPLIANCE MANAGER FUSION EDITION

Cisco Intelligent Automation for SAP

DocSavi. Expert Solution for Accounts Payable Invoice Automation. Accounts Payable Automation and ROI

Citi Integrated Freight Processing. Optimize Working Capital Achieve Supply Chain Efficiency

Sarbanes-Oxley Compliance for Cloud Applications

SAP Workflow SWAT (WF-SWAT) Accelerated Automation.

Our Service Offering to SASOL

The presentation will begin in a few moments

How To Ensure Financial Compliance

2015 Travel and Expense Management Report

Automating Sarbanes-Oxley Compliance Testing for SAP Applications. A Guide to Cost and Time Efficiencies for Annual SOX Compliance Initiatives

Performing Audit Procedures in Response to Assessed Risks and Evaluating the Audit Evidence Obtained

ORACLE HYPERION PUBLIC SECTOR PLANNING AND BUDGETING

WHITEPAPER PROACTIVE SECURITY INTELLIGENCE RETURN ON INVESTMENT

[ COREY PEARSON. Driving Process Efficiency through SAP Business Workflow at Stanley John Hoover, Stanley Works Rajkishore Una, GyanSys Inc.

Logging and Auditing in a Healthcare Environment

Infosys: Treating Governance and Compliance Strategically with SAP Access Control

Accounts Payable Automation Benefits

How To Manage Risk

Transcription:

Continuous Controls Monitoring ISACA, Houston Chapter August 17, 2006

Purpose of Discussion Understand impact of Continuous Controls Monitoring (CCM) on the Information Systems Audit community To perform this analysis, we need to explore: What is driving growth of the CCM market? What services can existing CCM tools provide? How does CCM impact audits and SOX reviews? Where is the CCM market heading/evolving? From there, we can discuss how to prepare: What opportunities exist due to the CCM growth? What education should the audit community be focused on? 2

Defining Continuous Controls Monitoring (CCM) The use of a combination of monitoring software and defined business rules to detect, prevent and monitor the operating effectiveness of internal controls Key attributes of effective CCM programs include: Effective Control Automation, including IT General Controls Continuous access control and segregation of duties management and monitoring (Role Management and Monitoring) Ability to monitor ERP configuration settings (Configuration) Real-time notification of anomalies from expected outcomes based on established business rules (Transaction) 3

Why is CCM an Important Topic Today? Pre SOX, many public companies had limited awareness and understanding of their control environment. IT General Controls Access Administration Change Control Application Controls Configuration Process IT-Dependent Manual Controls Manual Controls Pre SOX, many public accounting firms placed little or no emphasis on controls and operational audits 4

Cost of SOX (Year 1) Rule-of-thumb budget guideline for SOX compliance was $1M in expenditure* for every $1B in annual revenue. * (including cost of internal and external auditors) Average Company Sales (US $) 0 250 Million 250 500 Million 500 750 Million 750 1 Billion 1 2 Billion 2 7 Billion 7-10 Billion Average Cost of Section 404 Compliance 1.56 million 1.71 million 1.78 million 2.03 million 2.4 million Insufficient data 10 million Analysis Greater than estimations Greater than estimations Greater than estimations Greater than estimations Greater than estimations Insufficient data Greater than estimations (Sarbanes-Oxley Implementation Costs: What companies are reporting in their SEC filings Feb 2005, A.R.C. Morgan) 5

Value of Utilizing Application Controls Manual Controls Cost of Control Testing Application Controls Company Size and Complexity (IT Control Objectives For Sarbanes-Oxley, 2 nd Edition - April 30, 2000, IT Governance Institute) 6

Audit-based vs. CCM Approach High Audit Business Risk Audit Audit Cost of Control Continuous Monitoring Cost of Control Audit Based Reactive Limited Business Value Costly Investor concerns CCM Based Continuous & Proactive Comprehensive Integrated Business Impact Cost Effective Low Time 7

CCM Benefits There are substantial benefits to implementing Continuous Controls Monitoring tools. Economic Benefits Performance Benefits Assurance Benefits Lower transaction costs Reduced risk of fraud Lower SOX costs Increased shareholder confidence Real-time identification and resolution of transaction issues Improve business processes and operational efficiencies Continuous monitoring of 100% of transactions Sarbanes-Oxley compliance On-going evaluation of control effectiveness Increased Focus on Profitability and Growth 8

How has increased interest in Continuous Controls impacted the CCM industry? 9

CCM Tools Today Pre-SOX Focused on a single ERP Post-SOX Perform test of controls on all major ERPs (SAP, PeopleSoft, Oracle) with ability to expand to other products (Hyperion, JDE, Great Plains) Analyzed Segregation of Duties and Sensitive Access Perform complex access, process and configuration control analysis Perform data and transactional analysis for fraud detection Perform cross-application analysis Perform User Administration and What-if analysis Marketed tools to companies that had implemented or were planning to implement the ERP Marketing tools to both the audit firms (point-in-time) and companies that have implemented or are planning to implement ERP/Legacy applications 10

Growth of CCM Market Control Intelligence Control Assurance Customer Maturity Control Documentation Control Automation 2003 2004 2005 2006 2007 2008 Technology Application Rate (Continuous Control Monitoring & Audit, Approva Corporation, 2006) 11

Growth of CCM Market (cont.) Control Documentation Document the control environment Develop an understanding of the key controls and their impact on the business Control Automation Implement and increase reliance on application controls Automate the monitoring and management of processes & controls Implement processes to perform real-time resolution of issues 12

Growth of CCM Market (cont.) Control Assurance Allow companies to focus on improving business performance by performing continuous monitoring of financial and operational controls, creating an independent and auditable compliance process Provide confidence regarding the quality of information processed and produced by IT systems Control Intelligence Allow for companies to realize net gains to bottom-line results by proactively identifying opportunities to reduce operational costs, minimize profit erosion, and mitigate the risk of fraud, while driving down the cost of compliance. 13

CCM Implementation: Keys to Success 14

Implementing CCM: Keys to Success Understanding differences between CCM tools CCM tools have different strengths, weaknesses and capabilities that need to be assessed prior to selection. Business processes (P2P, O2C, FSCP, Payroll, T&E) Test of controls (Access & SOD, Configuration, Transactional) Cross-application analysis (multi-erp/financial applications) Assessing CCM tools based on Use Case Various issues may arise based on company's ERPfinancial application environment and use case scenario Connectivity to financial applications Business rules limitations Restrictions to extract company data for detailed analysis Cross application analysis 15

Implementing CCM: Keys to Success Development of Business Rules CCM default business rules do not directly map to the company s controls environment, thereby: Increasing risk of false positives Impacting ability to establish and maintain SOX compliance and reliance Reducing ability to test for fraud Standardizing Company s Controls Environment Implementing standard key application controls will: Improve quality of monitoring and reporting Reduce false positives Improve ability to perform maintenance of the business rules as the company s controls environment changes 16

IT Audit Opportunities 17

Opportunities for IT Auditors Category Product Assessment and Selection Implementation of CCM Tool Service Identify Client/Company Requirements Identify and Present Software Options Assist in Resolution of Implementation Issues Perform Functionality Testing Design and Implementation of Control Structure Monitor Controls Understand Control Environment Develop Test of Control Structure Implement Control Structure Develop Procedures for Monitoring and Reporting Control Violations Perform Review of Controls and Report Results Perform Fraud Analysis 18

Opportunities for IT Auditors (cont.) Because current CCM tools are focused on SOX-related business processes, other areas key to operations and profitability are not supported Customer Relationship Management Supply Chain Management Protection of intellectual property Safeguarding non-financial information 19

How to Prepare for Upcoming Changes Education CCM Tools Improve understanding of existing tools Business Processes Improve understanding of key financial and operational business processes ERP Training Understand ERP controls environment and capabilities Market Development Business Development ROI Process Improvements Reduce Inefficiencies and Fraud 20

Thoughts for the Road How prepared are you to meet the changing market? Knowledge of business processes Awareness of CCM tools capabilities Understanding of ERP controls capabilities How prepared is your organization to provide services? What development is required to prepare your organization? 21

Management Consulting Business & IT Strategy SOX Compliance Due Diligence M & A Support Supply Chain Management IT Governance Project Management Business Optimization Business Technology Enterprise Solutions Application Development Business Intelligence System Integration Managed Services Executive IT Services Infrastructure Outsourcing www.auxis.com 22

Appendix 23

Virsa ComplianceOne TM Multi-platform: ERPs and Legacy Business Processes: Procure-To-Pay Order-to-Cash Reconcile-to-Report IT Controls Access Control Suite: Addresses access administration and SoD Performs Critical Transaction Monitoring Supports Enterprise role definition, change control Process Control Suite Deploys configurable automated controls for key business processes and manages the compliance process for custom controls 24

ACL CCM Solutions Multi-platform: ERPs and Legacy Business Processes: General Ledger Order-to-Cash Payroll Purchasing Cards Purchase-to-Payment Cycle Travel & Entertainment For each module, ACL CCM: Analyzes User Authorization & SoD Performs Critical Transaction Monitoring Provide detailed analytics, identify transactional exposures Perform proactive SoD analysis 25

Approva Bizrights Multi-platform: ERPs and Legacy Business Processes: Procure-To-Pay Order-to-Cash Financial Close Payroll IT Controls Application Control Suite: Addresses access administration and SoD Performs Critical Transaction Monitoring Performs enterprise role definition, change control Process Control Suite Analyzes configurable automated controls for business processes and manages the compliance process for custom controls 26