SDLC- Key Areas to Audit in IT Projects ISACA Geek Week 2013 8/21/2013. PwC



Similar documents
Dallas IIA Chapter / ISACA N. Texas Chapter. January 7, 2010

Wilhelmenia Ravenell IT Manager Eli Lilly and Company

Explore the Possibilities

Master data deployment and management in a global ERP implementation

Fixed Scope Offering for Implementation of Sales Cloud & Sales Cloud Integration With GTS Property Extensions

Project Risk and Pre/Post Implementation Reviews

Suggested/Recommended Audit Points in the Software Lifecycle (From thought to sunset)

Information Management CoE A Pragmatic Approach

Contents. Evolving Trends in Core Banking Transformation (CBT) Challenges Faced in Core Banking Transformation (CBT)

Project, Program & Portfolio Management Help Leading Firms Deliver Value

Project Management/Controls and their impact on Auditing and Accounting Issues. October 31, 2012

Business Resiliency Business Continuity Management - January 14, 2014

Domain 1 The Process of Auditing Information Systems

Data Management Maturity Model. Overview

Maryland Health Benefit Exchange: Independent Verification and Validation (IV&V) Services Public Summary

IT Governance. What is it and how to audit it. 21 April 2009

Project Management Office (PMO) Charter

SharePoint as a Business Application, Not Just a Collaboration Tool

The presentation will begin in a few moments

Managing Multiple Vendors: Getting the Most from a Complex Team. November 16, 2012

Assessing the Appropriate Level of Project, Program, and PMO Structure

Auditing the Software Development Lifecycle ISACA Geek Week. Mike Van Stone Sekou Kamara August 2014

SAP Training Are your people adequately trained to maximize your

Fortune 500 Medical Devices Company Addresses Unique Device Identification

Blend Approach of IT Service Management and PMBOK for Application Support Project

@DanSSenter. Business Intelligence Centre of Excellence Manager. +44 (0) dansenter.co.

Assuring success in large business programs Internal audit s role in strategic risk management

Top 10 System Implementation Audit Considerations

SEVEN WAYS TO AVOID ERP IMPLEMENTATION FAILURE SPECIAL REPORT SERIES ERP IN 2014 AND BEYOND

The PMO as a Project Management Integrator, Innovator and Interventionist

Keys to a Successful Outsourcing Transition

SEVEN WAYS THAT BUSINESS PROCESS MANAGEMENT CAN IMPROVE YOUR ERP IMPLEMENTATION SPECIAL REPORT SERIES ERP IN 2014 AND BEYOND

Begin Your BI Journey

NCOE whitepaper Master Data Deployment and Management in a Global ERP Implementation

How To Improve Your Business

PM Services. Transition Program Management

Scale agile throughout the enterprise A PwC point of view

Diagram. Microsoft Dynamics Sure Step Methodology

Implementing a Project Portfolio Management (PPM) Solution. Sean Hansen, PMP

Fixed Scope Offering for. Oracle Taleo EE Saas Implementation

Data Audit Solution. Data quality visibility in 5 days for improving corporate performance. TABLE OF CONTENTS. Purpose of this white paper

Risk management and the transition of projects to business as usual

Finding The PPM Sweet Spot

The ICT Strategic plan execution toolbox

FIXED SCOPE OFFERING FOR ORACLE FUSION TALEO CLOUD

G-Cloud II Services Service Definition Accenture Cloud PaaS Implementation Services AWS Beanstalk

1. Purpose and objectives

TECHNOLOGY SOLUTIONS FOR THE INTERNAL AUDITOR

IT Governance (Worthwhile Exercise?) January 10, 2013 Presented by Chad Murphy, CISA

Template K Implementation Requirements Instructions for RFP Response RFP #

Fixed Scope Offering for Oracle Fusion HCM. Slide 1

IT Governance Overview

KPMG Advisory. Microsoft Dynamics CRM. Advisory, Design & Delivery Services. A KPMG Service for G-Cloud V. April 2014

Blue Fire Thames Court 1 Victoria Street Windsor SL4 1YB enquiries@bluefire-uk.com

State of Tennessee Division of Health Care Finance and Administration. Tennessee Technical Advisory Services (TN TAS)

TD Bank N.A. s Enterprise-Wide PMO Monitors Projects and Maintains Focus on Strategic Goals

EMA Service Catalog Assessment Service

Technical Management Strategic Capabilities Statement. Business Solutions for the Future

Changing the way we Change 2015 MFMER

Conducting a System Implementation Risk Review at Higher Education Institutions

fs viewpoint

Enterprise Risk Management & Information Technology

Project Management Office Best Practices

An RCG White Paper The Data Governance Maturity Model

Consulting. PMOver Transforming the Program Management Office into a Results Management Office

WHY DO I NEED A PROGRAM MANAGEMENT OFFICE (AND HOW DO I GET ONE)?

MNLARS Project Audit Checklist

14 TRUTHS: How To Prepare For, Select, Implement And Optimize Your ERP Solution

Agile project portfolio manageme nt

Risk Management to Contingency Planning. ICD-10 Operational Readiness Keith Hatch, Florida Blue (BCBS of Florida), Senior Manager

Developing a Data Management Strategy Using CMMI Data Maturity Model

The Internal Audit Analytics Conundrum Finding your path through data

Using Your PMO to Drive Successful Organizational Change Management

04 Executive Summary. 08 What is a BI Strategy. 10 BI Strategy Overview. 24 Getting Started. 28 How SAP Can Help. 33 More Information

Mapping COBIT 5 with IT Governance, Risk and Compliance at Ecopetrol S.A. By Alberto León Lozano, CISA, CGEIT, CIA, CRMA

Skatteudvalget (2. samling) SAU Alm.del Bilag 48 Offentligt. Programme, Project & Service Management Analysis

Using SAP Master Data Technologies to Enable Key Business Capabilities in Johnson & Johnson Consumer

IT Change Management Implementation The Journey. Marguerite Vickery Manager, Systems Change and Integration British Columbia Ferry Services Inc.

Practical Approaches to Achieving Sustainable IT Governance

BUSINESS INTELLIGENCE COMPETENCY CENTER (BICC) HELPING ORGANIZATIONS EFFECTIVELY MANAGE ENTERPRISE DATA

Business Analysis Capability Assessment

Enterprise Information Management

iworks healthcare Managed IT services

Implementing an HRMS Where Do You Begin. Dino Nosella, PMP

Auditing Capital Projects and Project Controls. March 2013

Business Service Management Links IT Services to Business Goals

Data Governance Overview

PM Services. Our Corporate Profile and Credentials

TDWI strives to provide course books that are content-rich and that serve as useful reference documents after a class has ended.

Presented By: Leah R. Smith, PMP. Ju ly, 2 011

April Navigating Cloud Management Robust IT management capabilities are critical to success in a cloud delivery model

Managing Complex Transformations Achieving excellence

Information Technology Services Project Management Office Operations Guide

Operational Excellence for Data Quality

Planning an ERP Implementation Small and Medium Enterprises

Enterprise Data Management for SAP. Gaining competitive advantage with holistic enterprise data management across the data lifecycle

TOGAF TOGAF & Major IT Frameworks, Architecting the Family

Solutions. Master Data Governance Model and the Mechanism

Whitepaper: Creating an ECM Advisory Board and Program Charter

For more information, contact:

Transcription:

SDLC- Key Areas to Audit in IT Projects ISACA Geek Week 2013 8/21/2013 1

Introductions and Projects Overview

Presenters Charlie Miller and Andrew Gerndt The Coca-Cola Company Principal IT Auditors Atlanta, GA CISA Mike Shipham PricewaterhouseCoopers LLP Project Assurance Director Chicago, IL CISA and PRINCE2 3

Agenda Topic Timing 1. Introductions and Projects Overview 15 minutes 2. IT projects- the risks 15 minutes 3. Key areas to audit 20 minutes 4

Coca-Cola at a glance 5

Project- sharing a Coke 6

Getting to know you 1. Are you involved in an IT project at your company? 2. How has Internal Audit been involved in this project? a. Mostly in planning b. Mostly in execution c. Doing a post implementation review d. Not at all 7

Getting to know you 1. What has been the greatest challenge with this project? a. Planning b. Execution c. Post implementation d. Other 8

Sound familiar? 9

IT Projects the risks

Are IT projects successful? s 2012 survey indicates that 200 global companies were spending over $4.5 B on projects to deliver changes required to implement their strategy. 20% of ERP implementation projects are not completed. (Gartner) 51% of ERP implementation viewed as a failure (Robbins-Gioia Survey) 71% of ERP projects do not meet the expectations of senior management (CSC Index/AMA Survey) 84% of projects do not meet all criteria for success (Standish Group) 2%: Companies that had 100% of their projects on time, within budget, to scope and delivering the right business benefits. ( Global Survey on State of Project Management) 35%: Number of companies where system projects deliver expected business benefits ( Global Survey on State of Project Management) 11

IT project risks In your experience, what IT project risks have you seen? 12

Reasons for program failures Source: s 3 rd Global Survey on State of Project Management (2012) 13

Key areas of project risk Risks are not isolated to classic project management artifacts, but extend to a broader risk universe. Technology Infrastructure System architecture Networking Security Availability Performance Disaster recovery Data Data Structures Mapping Cleansing Effort Conversion and validation Data governance Backup and recovery BI and reporting strategy Process and Solution Requirements Business processes System Development Life Cycle Data Controls Bolt-ons Interfaces/integrations * * $ $ $ $ Governance Strategic Alignment Senior Management Commitment Sponsorship / Champions Governance and Decision making Synergy identification and tracking Program Management Time schedules Budgets Resources/staffing Vendors Knowledge transfer Issue and Risk management Scope management Organization Business impacts Training Communication Organizational alignment Change management Compliance and controls Business continuity 14

Key areas to audit

PM Maturation Model Maturity Levels 5. Enterprise Standards and Program Management Culture Exists 4. Cross Business Unit Program Management Implemented 3. Programs Managed with a Strategic Enterprise Focus 2. Stable Project Management Processes Characteristics Strategic resource management crosses the enterprise Program value management occurs through project portfolio management, prioritization and interdependency management Change issues address organizational design and culture change Measures of process quality are collected and processes are managed Process performance target zones are established Management processes address multiple projects A PMO is used for efficiency and risk management is proactive Projects and programs assume a strategic focus with status visibility provided to a wider stakeholder audience Work projects are controlled and basic PM capability established Management visibility into project status at predefined checkpoints and milestones and react to problems as they occur Initial use of metrics at the project performance level 1. Unstable Project Performance (Ad Hoc) Processes poorly defined Managers have little visibility into status and processes employed Success achieved through "heroics" 16

Who plays a part in managing program risk? Large transformation projects typically have a number functions supporting risk and quality management. Understanding the respective roles and levels of assurance provides a holistic view of current assurance levels and helps identify the gaps that may need to be addressed. Work stream monitoring activities Examples of Level 1 activities: Program risk function Program PMO Vendor PMO & QA PMO monitoring and assurance activities Examples of Level 2 activities: Operational risk teams Compliance teams Organizational or independent PMO Targeted QA activities (from within the organization but independent of the project) Product vendor provided assurance External vendor and internal audit Examples of Level 3 activities: Internal Audit reviews (part of the annual plan) Health checks and targeted specialist Deep Dive reviews External Audit reviews 17

How can audit add value to a project? 1. Navigate the integration risk landscape Questions How well aligned is internal audit s plan with the critical risks facing the organization? 2. Understand stakeholder perspectives and provide deeper insights Does internal audit provide a point of view to help the business improve its responses to risk? 3. Cut through the clutter How effectively does internal audit communicate with stakeholders? 18

Cost of controls Solution Blueprint Design Build Test Build UAT Implement Go Live How can audit add value? Controls are often overlooked high Post imp. Pre - implementation Cost of controls increases as project progresses low During development start Project life cycle finish 19

Driving Change Delivering Change Managing risk over the program lifecycle Assess Design Construct Implement Operate & Review Is the case for change robust with clear scope, business outcomes and ownership? Will the organization & technical design deliver the benefits? Is the solution being built as designed and robustly tested? Is the business ready to go with detailed go live and support plans in place? Are the benefits being delivered and what could be improved? Project governance and mgt review Planning and mobilization Business case review High level target operating model Organization change strategy Deployment strategy Business process design Data and reporting design Test and data conversion strategies Security & controls People and Org Design Dedicated vendor management Solution testing and remediation Training plans and execution Data conversion Security and control configuration Business continuity planning Benefits management plan Support model design Test and training results Go-live process Data conversion process Transition to business as usual (BAU) planning Stakeholder engagement Go-live readiness assessment 30-90 day support Business adoption Benefits realization Compliance and controls certification * * Is the Change Management approach appropriate and delivering success? Is the organization engaging key stakeholders (including existing vendors/partners) throughout the change? $ $ $ Is the program being effectively governed against guiding principles and managed across all workstreams? Is delivery of business benefits a key focus throughout the lifecycle? $ 20

Further reading and Appendix Slides Internal Audit s Role in Transformational Change Insights and Trends: Current Portfolio, Programme, and Project Management Practices (our 3 rd global survey) Reaching Greater Heights: Are You Prepared for the Journey? 2013 State of the Internal Audit Profession Study (our 9 th annual survey) http://www.pwc.com/en_us/us/risk-assurance-services/publications/internalaudit-transformational-change.jhtml http://www.pwc.com/en_us/us/public-sector/assets/pwc-global-projectmanagement-report-2012.pdf http://www.pwc.com/en_us/us/risk-assurance-services/publications/assets/pwc- 2013-state-of-internal-audit-profession-study.pdf 21

For more information: Contact Charlie Miller The Coca-Cola Company Principal IT Auditor 678-516-8149 cmiller@coca-cola.com Andrew Gerndt The Coca-Cola Company Principal IT Auditor 404-676-4897 agerndt@coca-cola.com Mike Shipham PricewaterhouseCoopers LLP Director 312-298-4188 michael.a.shipham@us.pwc.com 22

Thank you 2013 PricewaterhouseCoopers LLP. All rights reserved. refers to the United States member firm, and may sometimes refer to the network. Each member firm is a separate legal entity. Please see www.pwc.com/structure for further details.

Video 24

Appendix Slides- Examples of control considerations by project phase 25

Top 10 Keys to success Key events that may contribute to a successful Project Audit: 1. Stakeholder buy-in & tone at the top, understanding & acceptance of engagement 2. Staffing, proper technical skills, qualifications and capabilities allowing the team to quickly establish credibility 3. Understanding project needs and expectations, as well as the level of comfort desired 4. Scoping appropriately, leveraging a risk based approach and delivering upon the agreed scope 5. Up-front communication regarding scope of review, extent of review, timing of review and level of details to be provided in reporting 6. Execution and completion of work within defined budget and schedule 7. Change agility, being able to change with the project needs (adjust timeline, etc.) but avoiding scope creep 8. Communication to all parties 9. Relevance, providing actionable useful and timely deliverables (reporting) consider requirements of the audience (i.e. Audit Committee, Sponsor, Project Manager, etc.) 10. Monitoring project progress between checkpoint reviews to minimize ramp-up time required at each checkpoint 26

Project assurance Control considerations Define Design Build & Test Deliver Imp. Support Maintain ITGCs Business Process Interfaces H A clear understanding of Business Processes in Scope. A clear understanding of the current status of controls and the proposed change. A clear understanding of the control risks to be addressed: - Operational - Compliance - Financial Reporting Understanding of the efficiency improvements required Appropriate expertise assigned to deliver appropriate controls Appropriate activities included in project plan to deliver appropriate controls Data Quality 27

Project assurance Control considerations Define Design Build & Test Deliver Imp. Support Maintain ITGCs H Business Process Design appropriate ITGCs based on the risks identified Determine what the key controls are Ensure specifications of ITGCs are produced for input into the next phase. Interfaces Data Quality 28

Project assurance Control considerations Define Design Build & Test Deliver Imp. Support Maintain ITGCs Business Process Interfaces H Ensure there is a clear understanding of current interfaces and interface controls and how these may be changing A high level plan has been developed to show interface development activities, priorities, and contingency plans should desired interfaces be unavailable when needed by business teams. Data Quality 29

Project assurance Control considerations Define Design Build & Test Deliver Imp. Support Maintain ITGCs Business Process H Ensure appropriate business process controls are developed (in line with the specifications from the previous phases) Make sure controls that are developed are tested appropriately Interfaces Data Quality 30

Project assurance Control considerations Define Design Build & Test Deliver Imp. Support Maintain ITGCs Business Process Interfaces Data Quality H Setup of integration test environment should include execution of data conversion procedures to validate completeness and accuracy of conversion procedures. Data conversion reconciliation specifies tests to prove that the converted data is sufficiently clean to be used within the new environment and data inaccuracies have not been introduced during the conversion process 31

Project assurance Control considerations Define Design Build & Test Deliver Imp. Support Maintain ITGCs Business Process Interfaces Data Quality In instances where data has not been converted or migrated (i.e., only summary data is in new system), is the historical data available in a read only environment for reference purposes? H 32