Annual Conference and Global Internal Audit Leadership Summit 2017 (27 Oct)

Managing Cyber Risks. (KPMG) Cybersecurity is one of the top 5 risks as rated by CAEs. Cyberattacks are one of the top 3 man-made risks which can be addressed. In a survey, Asian CEOs aren’t as well prepared as their US counterparts when dealing with cyber risks and cybersecurity. There is a need for cybersecurity risk assessment. Sometimes, insiders can provoke a cyberattack too. Due to the widening of the digital footprint, it can lead to greater cybersecurity threats. External threats like new technology, technology change, regulatory compliance and changing market forces will continue to affect the cyber landscape. The new cybersecurity bill by CSA is slated to be released in Feb 2018. The Bill will affect CIIs from 7 different industries. The cyber risk gap needs to be plugged through the use of specialist reviews and audits. Some of the losses that an organization could face are theft of client information, IP, corporate date, DOS attacks etc. Nowadays, it is quite common for the attacker to attack your service provider (since there are less strict internal controls) and get information from them about your company. Some of the staff from your vendor might not be well screened also. Usually, there is no point trying to figure out who the cyber-attacker is as it is hard to prosecute if it’s not in Singapore jurisdiction. Some of the tactics that cyber-attackers use is ransomware, key loggers, phishing, insider data theft and man in the middle attacks. Do not give away passwords at any cost. Training/education is important, more so that IT tools at times. As auditors, we can audit the data classification in an organization. Cybersecurity is a growing factor and needs to be included as a risk indicator. There needs to be a detailed response plan after being attacked. There is also a need to link the cybersecurity threats to your business. One can read the ISO27000 series, MAS TRM Guidelines, NIST, COBIT and others.

SAP Case Study. (SAP) SAP is a German company. Maintenance costs is a big part of the implementation costs of having such an ERP software. For SAP itself, some of the risks facing the organization are acquisition risks, cloud computing etc. Within the audit team, they use the SAP Audit Management Software, which is automated from the end to end auditing process. One will be able to see clear audit plan overviews and also real time status updates of the plan. There are also resource management tools in place which will help improve the global resource transparency. In addition, there are audit executive dashboards in use. All these lead to better cost savings, user satisfaction and faster audit cycles for the organization. As a result, during quality assessments, the IA function scores better. Analytics helps in audit sampling for auditors.

Internet of Things. (Microsoft) The Internet has shifted from the Internet of content to service to people and now to ‘Things’. Internet is very commonly used nowadays as it is more efficient and has led to increased productivity. It has brought the whole world together through Skype. There is data in chips in our everyday devices and such data can be harnessed for decision making. Some of the benefits of IoT are that it leads to 1) safety, comfort and efficiency; 2) faster decision making; 3) revenue generation. Some of the risks of IoT are 1) privacy, security and legal (types of data collected can be collected and should be collected etc). The major challenges that will be faced are to obtain the business and IT buy-in and also the fact that data magnitude can be huge and complex and hard to interpret. It is important for IA to stay ahead of the changes and understand the risks emanating from IoT. We need to be trusted advisers to the business. CAEs need to determine the skillsets required, like from data scientists, private specialists etc. IA needs to recruit the right people. We need to change our approach to how to audit etc. The process flow is like this: device connection -> data sensing -> communication (access rights) -> data analytics (queries etc) -> data value -> human value

Data Analytics at MAS. (MAS) Data is the new AIR that we breathe. Insight is the new storage of value also. There are a few Vs we need to be aware of: Veracity, Value etc. We have approached the other departments, like banking, insurance and capital markets, to understand what are the pain points of these departments. We have moved from rule based (AML + STR) to machine learning. There is a strong need to enforce data quality and to move from just big data to smart data. Labels must be given for supervised machine learning in order for it to work more efficiently. However, there is also such a thing as unsupervised machine learning etc. For data, there is a need to achieve generalisability. An important question to ask is whether your model can work on future data? Or just past data? Ensure that your data can be interpreted and cleaned before it can be used. The process is as follows: 1) know the question; 2) understand the data; 3) find the right algorithm; 4) be aware of the limitations; 5) be sceptical; 6) automate; 7) experiment. It is important to share insights across the different departments. Machine learning is a programme which automatically improve its performance through learning and experience. Culture is hard to change and in fact, culture is more important than the application of an algorithm.

Cybersecurity Lessons Learned. (SWIFT Asia Pacific) SWIFT is a co-operative that is based out of Belgium. Nowadays, cyberattacks are tailored for a particular institution and that can be really scary. Hackers are now able to perform multi-stage attacks. There is a hacker collaboration space in the dark web. Cross-border banking usually requires the use of SWIFT. Hackers have different motivations for committing crimes and it is difficult to predict. Cyber must be managed from the top-down. One needs to understand that spending money doesn’t make you more secure and there is a need to evaluate cost-benefit analysis. At times, it could be the client servers which have issues. There is a need to dictate how the client runs their programmes in order to secure their environment. There needs to be a cyber-response plan in place to address attacks and to recover. In future, SWIFT would make it compulsory for banks to report on their compliance to SWIFT’s assurance framework. This will certainly help to improve transparency.

Ethics in a Digital World. (Avande) Avanade is a cloud service provider and is a partnership between Accenture and Microsoft. In this digital age, there is a debate between Personalization vs Privacy. Facebook tried to have two bots chats with one another, but they turned racist and eventually had to be put down. Although AI development is swift, it might be necessary to put the guardrails on AI and curb its growth in view of ethical considerations. What is morally acceptable in today’s society? What is lawful? Digital is becoming a way of life and ethical behaviour is vital in this day and age. Is there a need for a framework to manage ethical dilemmas? What are the possibilities of digital tech? Core ethical values are embodied by leadership and there needs to be a good tone from the top.

IA in the Age of Transformation. (Asia Pacific Black Sun, Sofitel Singapore, UOB, NTUC, EDB) What are the elephants in the room? This refers to important issues that are not being addressed by IA. IA needs to keep themselves relevant. 43% of jobs in Singapore can eventually become automated (mechanized, robotized, digitalized) etc. However, there are still many opportunities in the audit space to add value. IA needs to be high tech, high touch (build strong relationships with management), and high trust. IA’s job is to highlight exceptions to management and in order to do so, they need to be loud and courageous in the boardroom and not shirk from difficult conversations. IA needs to avoid getting on the newspaper. IA needs to familiarize themselves in the area of sustainability reporting and professional scepticism. IA needs to constantly update themselves through attending training etc. Industrial domain knowledge is also important and this is usually learnt on-the-job. People retention is important and there could be a risk of knowledge loss without people. There is a need for IA to provide inputs on controls for IT projects right at the start. If there are no audit findings, it is possible for IA to issue a clean audit report. IA should gradually take on a more advisory role for the business.

auditing-service-singapore

Advertisements

Annual Conference and Global Internal Audit Leadership Summit 2017 (26 Oct)

Opening Address by Guest of Honour (Professor Tan Cheng Han). (SGX RegCo) Singapore Exchange Limited (SGX) has moved to a disclosure based regime for markets for regulators. Shareholders are active and can ask questions of the management or try to get rid of a few directors. There is a need to listen to businesses nowadays when trying to propose new regulations. We have moved from a prescriptive to a more principle based form of regulation. Nowadays, we listen to market participants and seek their inputs. We live in an uncertain world. Lawyers should facilitate transactions and not simply keep telling people want they cannot do. They should guide people to be able make decisions within the legal framework. In this way, it is similar to what Internal Audit does. As an auditor, it is important to stand your ground and do the right thing, all the time.

Transforming Internal Audit. (AIG) It is important for IA to be clear of their role. Internal Auditors should read the ‘Common Body of Knowledge’ by IIA and also the ‘Global Trends of 2030’. Our job is to find things and to help management see things that they have not been able to see (i.e. provide assurance). Many companies have evolved over the years, like IBM, GE, Rakuten in order to stay alive. Some might have to abandon their traditional model just to keep afloat. IA can also read ‘The Fourth Industrial Revolution’. Internal auditors should all get the Certified Internal Auditor certificate and show that they belong to a professional body with high standards. We all need to comply with IIA standards. The current IA role is shifting from one of assurance to also one of advice and insight. Some of the more recent trends in internal audit include performing data analytics on the whole population. Combined assurance is also one of the up and coming trends in Internal Audit.

In Conversation with an Audit Committee Chairman. (SIA, DKSH) The IA team in PwC has grown tremendously since its inception. The role of IA is to provide an independent assurance on governance and risk management. Is the level of risk management adequate for the business? IA should also get inputs from management on their performance. One factor to judge the CAE is on whether the audit plan is incomplete and what the status of the plan vs is the execution. One option is to conduct a 360degree feedback exercise. A CAE’s pay package should be established by the remuneration committee and with inputs from the audit committee. The bonus paid is relevant to the company’s profits and individual performance. IA is a business partner and must not be seen as competing/slowing down the business. There is a need for internal auditors to retain a strong ethical and moral compass when discharging their duties. If you feel you are being mistreated by management, do highlight this fact to the Audit Committee. In cases of disagreement with management, it is important to highlight to the AC what is your position. It may be wise for audit partners to resign from the audits where there is serious disagreement with management. Before joining an organization, it is important to try and assess its culture and whether the culture is ethical etc. The CAE must be outgoing and interact seamlessly with other stakeholders. He must demonstrate leadership potential etc. One way to assess that is through conducting reference checks on his background etc. It is not necessary for internal auditors to have accounting backgrounds. However, it is difficult to be a CEO without a finance/accounting background. In general, having a diverse IA team is important. As the chairman of the AC, it is important to do preparatory work and also to meet the IA informally a few times a year. For young auditors, it is important to spend on your own career development and set 3 year career plans on what do you want to achieve etc.

Innovative and Agile Internal Auditing at Google. (Google) In Google, the employees practice moonshot or 10x thinking and they try their best to think differently. Waymo is their project on self-driving cars. They have many interesting projects like on Calico, Capital G, Deepmind, GV, Jigsaw, Nest, Sidewalk Lass, Verlly, Waywo, X etc. Google was incorporated in 1998 by Sergey and Larry. Read the Founders’ letter to get an insight of some of Google’s core values. Also, on their website, there is a hilarious list of ’10 Things we know to be true’. Their IA has also to fit in with the culture at Google and they are moving away from SOX compliance to other forms of combined assurance. An intense level of collaboration is expected at Google. They use many syncs, tools and techniques to get their work. The stakeholders are usually understanding and it is not difficult for IA to receive information. Also, the IA team uses software so that the client can see the IA reports at any time and also there is live QnA that happens every Friday. The software will enable the IA team to view the project status live and also to view audit working papers. Audit findings are tracked using software. As for hiring, Google looks for collaborative people. As for other skills, Google looks out for cognitive abilities, role knowledge, leadership and Googleyness. The top down approach doesn’t always work and Google tends to empower employees instead. Due to the speed of change, the IA team only develops a 6 mth rolling audit plan and revises it accordingly due to changing level of risks.

Auditing Big Data. (New York State Office) In the New York auditors’ office, the IA role has been expanded to include both artificial intelligence and data analytics. Big data makes decision making easier and faster. Avoid rolling out apps when not many have access to the network. The greatest opportunities will come at a risk. You have to get comfortable with being uncomfortable. There is a need for big data and technical skillsets. Big data is large, complex and covers many complex data sets. There is a trend of lower cost of data storage. Despite this, data tags will help in the data retrieval. Big data has really helped the audit team in NY to improve the audit efficiency and effectiveness. There are mainly 4 risks associated with Big Data: 1) program governance; 2) tech availability and performance; 3) security and privacy; 4) data quality, management and reporting. When using big data, it is important to ensure that there is no invasion of privacy and that it is legal to collect and use any particular form of data. It’s a massive leap to fully integrate by data and analytics. The auditors analyze social media like Craig’s list to detect unlicensed car repair workshops etc. The team also builds AI when it is not available.

Geopolitical Risks – What does it mean to Organizations and Internal Audit? (Focus Strategic Group Inc) Internal Auditors need to understand global and regional trends facing them. There are many geopolitical risks in this world and these threats can lead to supply chain disruptions. There is a massive distribution of wealth problem in this world. Some of the major events that have impacted the world are the Israel/Palestine conflict, war in Syria, Greece debt, Brexit, appointment of Trump, Spain/Catalonia separation. There is an increasing trend of protectionism for major economies and these countries are also against immigration. Trump is against the North American Treaty agreements, the TPP etc. In this world, there is only the certainty of uncertainty. People fight over many things, like land, resources, religion, perceived inequalities etc. China is also striving for more economic co-operation and wants to be the next Superpower via their one Belt one Road programme. They are also looking at how to harvest resources in the Arctic Circle. China started the Asian Infrastructure Investment Bank (AIB) and there are currently 57 countries on board with them. This bank can help provide funding for major infrastructure projects. The 3 prominent tech companies in China are Baidu, Alibaba, Tencent etc. In IA, we need to ask ourselves whether our organizations are secure. There is also a frequent need to check asset risks, read up on the latest news and check countries’ sovereign ratings. It is also possible to buy insurance to cover losses arising from geopolitical risks.

Panel Discussion: Transforming Internal Audit. (VISA, GIC, Google, SIA) There is a need for internal auditors to develop a more diverse set of skills especially in this world of digitalization. IA can be the change agent and also shape the company’s culture. For listed companies, IA can check compliance with the listing rules with methodology. The modern IA role is beyond compliance and more towards advisory. There may be a need for IA to revamp its methodology and include the need for analytics. IA needs to be proactive, adaptable and diligent. As auditors, we need good communication and networking skills and have the willingness to do things better. There is a need to use CAATs like Qlikview, SQL, Tableau to improve data analytics skills. There is a need for executive support before a data analytics programme can be rolled out successfully. One should start with the small DA projects with ROIs in order to show to management that it can work. An advanced maturity of data analytics would include things like predictive/behavior analytics and robotic process reengineering/augmented intelligence. Whereever possible, it would be good for IA to be able to automate its processes. IA can perform the prediction and look through the red flags. It is important to have good mentors who will grow and support you in your relationship. Auditors need to be curious and learn continuously. Company culture can be assessed via analytics and by the conducting of employee opinion surveys.

Internal-Audit

audit financial company tax investigation process business accounting

Annual Conference and Global Internal Audit Leadership Summit 2017 (25 Oct)

Audit Committee’s Expectations of the Chief Audit Executive in an Uncertain World. (Singapore Institute of Directors) We live in an uncertain world with plenty of technological advancements and digitalization. The world can be termed as VUCA (volatile, uncertain, complex and ambiguous). The advent of tech companies like Uber, Airbnb have caused the downfall of many traditional businesses. One thing is for sure, technology is here to stay and it will continue to disrupt economies. The Financial Reporting Surveillance Programme by ACRA revealed that there is still work to be done in terms of complying with FRS for listed companies. The surveillance programme also reaches out now not just to companies with qualified audit opinions, but those with unqualified audit opinions. ACRA has stated 8 audit quality indicators which will be important for IAs to follow. The recent enhanced auditor report format requires the key audit matters and other information to be disclosed (notes to FS). In Jan 18, companies will need to comply with the IFRS 9 on Financial Instruments and the IFRS 15 on Revenue. Also, in general, there is a move from SFRS to IFRS convergence in Singapore. In addition, for listed companies, it is mandatory for them to produce sustainability reports. This is an area where auditors need to equip themselves with more knowledge. From the above, it is imperative that one unlearns, relearns etc. In addition to provide better assurance, IA can leverage off other assurance providers and work closely with ISD or consider performing co-sourcing etc. The 5 Ls that Internal Auditors need to possess are Learn (lifelong learning on data analytics and how to audit IT etc); Leverage (other assurance providers for AML, cybersecurity etc); Lead (lead the risk management, lead the combined assurance framework/Governance Risk Control framework etc); Live (treat Internal Audit as a form of meaningful work and be passionate about their work); Love (treat IA as a vocation, continue back to the IIA).

The Cyber Resilience Challenge. (RSM, DHL, Datalogic, CSA) To tackle cyber threats, there needs to be a good governance system in place. RSA has a GRC framework and business driven frameworks to address such risks. In addition to cyber risks, an organization must never forget the operational/financial risks and how the cyber risks linked to such risks. Due to the skill of hackers, it is likely everyone will be hacked and it is just a matter of time before it happens. There is a need to weigh the pros and cons of anti-cyber threat measures. In the audit space, IT auditors have a lot of potential to upscale and re-learn. For complex environments, it must be even necessary to develop a hacker mindset in order to perform vulnerability and threat testing. It is important for an organization to have a good risk culture. It is never wise to be naïve when it comes to cybersecurity. There is a need to consider the single points of failure as this might break the organization (for example: a lack of business continuity planning or the drawing up of DRP). In such cases, it might be better to build some form of redundancy. Ask yourself: if you were the CEO, what is the thing that keeps you awake at night? Do not ignore the threat of cybersecurity breaches in your organization.

Auditing at the Speed of Risk in the Digital Age. (DHL) Due to digitalization, IA needs to keep up to date with the latest market developments and update their risk assessments more frequently. Technology is the biggest game changer. Some of the threats that will be surfaced during a threat assessment would be things like malicious software, hacking attempts, unencrypted information, hacking and data theft. It is important to test the disaster recovery plans (DRPs) and BCPs. Ask yourself what do you fear? One should believe in lifelong learning.

Do one thing every day that scares you. – Eleanor Roosevelt

Maximising Value from the Three Lines of Defence. (DSTA) The first line is the management/ internal controls. The second line is risk management/safety/compliance functions. The third line is internal audit. IA has to move away from traditional assurance to advisory and advocacy work. However, do remember that the core IA work is still in still in assurance. Although advisory work is important, CAE should not take on roles that lead to conflict of interest. CAEs must remember that they do not endorse business decisions. The 3 lines of defence can be linked to the COBIT framework (IT governance). COSO framework also supports the 3 lines of defence model in an organization. Some of the attributes required for a successful 3LoDs are strategy, shared values, system, structure, staff and skills. IA could use dashboards and DA to make their work more efficient. Some are proposing a fourth line of defence for the financial industry (external auditor + MAS banking supervision). Internal Auditors must always fall back on the IPPF. KPIs like competency of procurement staff could be introduced.

The Customer Centric Audit: Learn How to Audit What Customers (and Your CEO) Actually Care About. (Proximity Risk and Assurance) How does one go about auditing the customer experience?  It is important to do so as it concerns the revenue area of the business. One can start by mapping out the customer journey. Identify the brand touchpoints with the customer and also assess the environment. Poor customer experience could have a negative impact on the business, like the United Airlines passenger who was thrown off the plane. IA needs to audit the risk of poor delivery. IA can indeed and should audit the customer experience. Avoid excessive controls as it might stifle the customer experience and affect the quality. Customer experience is something that will keep the CEO awake. IA can sometimes even pretend to be a mystery guest/customer to examine the quality of service. As part of documentation, IA can build up a customer journey matrix and add in the relevant departments responsible for the various sub-processes. Next, IA can test the expected journey vs actual feedback received from customers. If it’s the first audit report on this area, it would be advisable not to grade it. Always remember the importance of good customer experience as it is essential for customer retention.

Panel Discussion: Leading to Make a Difference. (Deloitte, Citi, MOHH, Olam) MOHH IA managed to evolve from a mainly compliance function to now one that fully incorporates DA. It has been a painful process but it has really helped to boost efficiency. IA is now moving beyond compliance. IA needs to adopt a pragmatic approach and look through the lens of the business. It is necessary to get the right strategy. The CAE must be able to engage the senior management well and also explain to them what IA is all about and how we can meet your expectations. In order to be able to influence management’s behavior, IA must have a deep in-depth knowledge of the business. IA should be seen as being impartial, but not be neutral. As the CAE, it is crucial to state one’s opinion and not sit on the fence. Although it may not be a right opinion, an opinion must be based on facts. To be seen as successful, IA needs to be seen as a growth enabler, and not slowing down the various processes. One such way to achieve this is that IA can get involved in the process design stage and give inputs and recommendations on controls. Olam has many e-learning modules to help IA team improve their competencies. Citi has a Chief Auditor for Innovation and they use many tools for analytics in their work. It is now very common for IAs to use data analytics to audit and now 100% sampling is possible. Due to the rigour of MAS’ inspections, banks like Citi needs to step up and comply. This forces the IA team to improve their quality. Instead of simply adding controls, auditors can remove controls to get rid of legacy issues which slow down processes. In order to stay relevant, Internal Auditors need to be passionate about their work and always remember their core job is still assurance.

auditing-service-singapore

IIA Magazine Dec 2016

One potential failure of ERM is that of green-washing, this is when crucial risks are pushed down into the larger collection of more trivial risks. Cybercrime is a current buzz risk. The first line of defence needs to take on better accountability for sound risk management and control.

Investors are pushing for more accountability and transparency behind decision-making. Shareholder activism is playing a big role nowadays.

The EU has released new general data protection regulation (GDPR) which intends to strengthen and unify data protection for individuals within the EU. However, most organizations say that they are not well prepared. Organizations should start preparing for this as it will kick off in May 2018.

Client Feedback. Audit performance can be fine-tuned with the right input from stakeholders. Feedback should aid audit performance. Feedback should be to the point and be specific and timely in order to be effective. Useful feedback can increase audit effectiveness. Feedback can be provided during the opening meeting, during the audit or during the closing meeting. The client should take the opportunity to clarify any concerns that they may have. During the closing meeting, IA needs to present the supporting documents and records. A post-audit questionnaire can be sent to the client after the audit.

Must-have Controls for Small Medium Enterprises. 5 controls can help SMEs protect themselves against cyber breaches. Sometimes, they do not have sufficient resources to deal with threats. Firstly, scan the network quarterly and identify vulnerabilities. Train employees on IT security. Protect sensitive information by inventorizing sensitive business processes and reviewing access to information. Learn to segment the network. Deploy extra protection for endpoints and encrypt the data. Learn to monitor the network, manage service providers, protect smart devices and monitor activity related to sensitive information.

A Holistic Approach to IT Risk. The COBIT framework can help auditors understand and address their organization’s technology risks. IT can be very complex but IA needs to evaluate the full range of IT risks. COBIT is valuable for the whole process, from end to end. The 5 key principles are meeting stakeholder needs, covering the enterprise end-to-end, applying a single integrated framework, enabling a holistic approach, and separating governance from management. Internal auditors can use COBIT to understand the nature of IT risks that are unique to their organization.

A Toxic Culture. A department leader creates a hostile work environment by promoting friends and abusing employees and company assets. When many employees leave, there could be a sign of a toxic culture. There was an inadequate internal control system as no one tracked expenses. Critically review turnover data as this is a big red flag. Exit interview results should be reviewed regularly. Access control over reports should be reviewed and approved.

On The Rise. Learning is the key to do well in IA. Get students involved early and you can volunteer as a guest speaker on internal auditing topics. IA an get involved in many projects and act as change agents for the organization. Projects can allow one to build and develop business relationships with stakeholders. One can use data analytics during audit engagements. IA can add as a trusted advisor and perform consulting work. One can learn SQL, which is a tool for managing data. One could take others under their wing and mentor them so that they can grow. Interaction between auditee and IA must be positive. Spread the good word that your team does. IA should be innovative in addressing solutions. It is helpful to distinguish the different roles of EA and IA too. Communication skills are the key for IA’s success.

Growth through challenge. Current and past emerging leaders discuss the tough assignments that helped propel their careers forward. Challenges faced in your career can propel you to be a better auditor. It is good to share with others what are some of the common mistakes. See auditors as people and go in with a customer first mentality. Be client centric. Be prepared when you go for meetings and interviews. Get a mentor, build relationships, learn from your mistakes and learn to network. It is important to preserve independence and objectivity. Influencing mindsets are tough. Building relationships with auditees can be tough when you are new. It is important to have a good audit methodology. The learning curve can be steep especially if the industry is new for you. Some departments are resistant to let the IA perform audits on operations. Talent auditors are always in demand. Once you are good, you can engage the C-suite management easily and without fear. Young auditors are always eager for more opportunities.

It’s all in the delivery. Sharing difficult messages is an unavoidable part of the job for internal auditors. Some audit observations can be difficult to convey. You should always build the relationship before telling the bad news. Telling the bad news right away is unlikely to work. Using weekly updates once the exceptions are noted is the key. Preparation is the key to accomplishing objectives. It is important to be fair and factual. Focus on the process as well as content. If you can, you can tailor the response to the personality of the recipient. During the discussion, one can seek opportunities, offer to help, make it clear and maintain open body language. ‘If the audit report is the first time a client is seeing something in writing, that is the first and biggest mistake. Verbal updates are great, but periodic written updates go a long way. Auditors might get into trouble over their poor soft skills. Focus on the problem, include some positives, have a face-to-face meeting etc. The key is not to beat around the bush. EQ is important in helping good delivery. The key is to deliver bad news but still build a good relationship with the auditee.

Breaking Through. Women in business are taking on the barriers to advancement, and that’s good news for everyone. Diversity is good for the workplace. More women need to be in leadership positions. However, women might face issues like lack of support, exclusion, apathy. There needs to be sufficient support from male leaders. Men should be interested in achieving gender equality. Be You. Seize the Moment. Integrate Your Life. Earn Respect. Stay Behind Facts. Be realistic and practical. Forget silos. Think context before issue. Rethink reporting. Aim at destination with gratitude. Women may also face the motherhood penalty.

Mapping Assurance. Internal auditors can facilitate efforts to document the organization’s combined assurance activities. There are a variety of assurance providers. CAE can use an assurance map to co-ordinate assurance activities. It can also aid to prevent gaps in coverage. IA is well positioned to provide combined assurance. The plan should start with the organization’s strategic plan and the key risks that are associated with the strategic objectives. There should be 3 tiers of defence to provide assurance. IA need to assess the quality and quantity of assurance received.

A Winning Pair. Governance and automated controls must work in tandem to achieve maximum results. Good governance is the key. IA needs to access the current risk profile, mitigation activities and residual risks. Good behaviour requires time and employees should receive reminders in order to conduct good behaviour. Desired behaviour ultimately stems from the top.

The High-Performance Audit Team. Today’s complex, evolving business environment demands more of internal auditors. The world is changing and stakeholder expectations are increasing. IA can also rotate and fill other operational positions. An integrated internal audit function can boost performance. There is a strong need to invest in training and learning. Verbal, leadership, communication skills are very important. A high performance team can evolve to meet new challenges and reinvent itself. We also welcome constructive feedback from staff.

auditing-service-singapore

IIA Magazine Feb 2017 issue

IIA Feb 2017 Issue

Internal Auditors need to provide maximum return on investment and audit the right things. They need to understand the company’s strategic mission, objectives and KPIs. More auditors need to base their work on the International Standards for the Professional Practice of Internal Auditing.

The 5 emerging threats are (i) global economic uncertainty; (ii) increased regulatory burden; (iii) significant industry changes; (iv) business model disruption; (v) cybersecurity threats. Global economic uncertainty seems to a bigger risk in 2017 as compared to previous years. In the compliance space, with the new US administration, enforcement areas could see some change. Trump could change the legislative, regulatory and executive actions under Obama’s reign.

Although most companies feel that they could detect a sophisticated cyberattack, many of them do not have an adequate communication strategy in the event of a significant attack. Also, some of the BCP might be lacking. The continuous monitoring of cyberattacks is also a challenge.

Data Mining. By leveraging data, internal auditors can address issues beyond the reach of traditional analysis techniques. It involves making use of data which had previously no formulated relationships, patterns. Artificial intelligence, machine learning, statistics and database systems all come into play. Some of the techniques auditors can use are predictive modeling (IF), data segmentation (data clustering), neural networks (artificial intelligence), link analysis (links between records), deviation detection (red flags). The use of email mining can identify red flags in fraud etc. Social network analysis is also possible. IA should continue to look for ways to innovate their audit testing.

Intelligent Assessments. Use cognitive technology to help identify high-risk areas. These are intelligent computer systems that can aid in the performance of risk assessments. For instance, this tool can extract and analyze text from audit reports and analyze trends and high-risk areas. Natural language processing (NLP) has the power to tap into every sentence of every report to churn out more information. The machine will convert text to a certain structure and add meaning to the text and teach the computer to understand audit concepts. Words like ‘fraud’, ‘finding’, ‘auditee’ can be flagged out.

Turning Up the Heat on Fraud. A fraud risk assessment can help auditors take the organization’s ethical temperature. There are many ways to do it, example, through surveys, focus groups, workshops etc. The focus is mainly on fraud risk. It works best in small brainstorming sessions with operational management. Using the ACFE’s Fraud Risk Assessment Tool can be useful as it provides a structured approach. Risk assessment is about identifying where fraud might occur and the potential perpetrators. IA can do surveys to measure the ethical climate and voting can be anonymous. The results of the survey can be discussed with management. If there are high risk areas with fraud risks, IA can pay more attention to them.

The Accidental Discovery. Small or remote locations can be more susceptible to embezzlement, especially when they are not audited regularly. Confront someone after the facts have been reviewed. Look at the big picture. Controls that aren’t operating effectively are as good as them not being there.

Auditing what matters. Add value by selecting audits that contribute to achievement of strategic objectives. Auditors now should start looking at this area. Look at where the company spends the most money, what their main programmes are etc. Find out who is responsible for the strategy and make them IA’s stakeholders. Traditional audit activities can move towards strategy too. IA should use the COSO ERM framework in its entirety. The aim is for IA to a strategic partner to management. Don’t fear failure and find out more from the auditee by talking to them. The trick is to engage with processor owners easy and evaluate control design. IA should do the following: (i) Identify and define the risks; (ii) rate the risks; (iii) address risks in detail. Getting management buy-in is also important. The CAE must convince the AC to highlight the need for a strategic approach. Most IA wants to be a trusted advisor.

Core Principles and the QAIP. The new IPPF in 2015 can be incorporated into the QAIP to show that the IA is aligned with the mandatory IPPF elements. Learn to develop a concept and approach that is easy to understand. Core principles are a mandatory element of the IPPF. IA need to have general conformance with the Code of Ethics and Standards. The 5 steps are (i) establish a maturity framework (ineffective, partially effective, effective, sustainable, world class); (ii) map core principles with the standards and code of ethics; (iii) Define characteristics of maturity in 3 aspects of standards and QAIP characteristics, infrastructure and process characteristics, core principles and specific characteristics; (iv) perform internal and external assessment consistent with requirements of QAIP; (v) Evaluate and report maturity levels for core principles.

Champion of Trust. By modelling high standards of ethical behaviour, IA can help shore up faith in the organizations they serve. How can IA be a trusted advisor that is well respected? One way is via ethical commitment. IA needs to model ethical conduct in everything they do. IA must have the courage to sound off before things get in trouble. Ethical commitment is the key to a well-functioning IA. Ethics should come naturally to all. We also need to build ethical resilience (integrity, courage, honesty, accountability, trustworthiness).

Infusing IT Auditing into Engagements via a three-phase approach. The tech sector is growing at a rapid rate. Internal auditors also need to develop IT-related capabilities. IA needs to think about the future of integrated auditing. For a start, IA can incorporate IT perspectives into current audit engagements. This can involve documenting down what are the IT automated controls. One can also read IT policies or those on change management. One should also identify resources and pinpoint where they are stored (example: servers). Map core IT resources and data to key business objectives. Respond to IT risks and identify audit objectives that can add value. An integrated audit can help in this. In the middle term, IA can build an IT audit team, understand the IT framework like COBIT, perform IT audits and also foster relationships with IT and management. In the long term, IA can leverage on data analytics and obtain professional certifications (like IIA and CISA).

Breaking Down The Standards. With the right strategy, practitioners can divide conformance into bite-size, easily digested portions. The standards consist of attribute standards (series 1000 to 1322) and performance standards (series 2000 to 2600). Some IA may neglect the attribute standards and focus on the performance standards instead. However, both are very important. IA should perform an assessment of how well they are conforming to the Standards. An external assessment must be conducted once every 5 years. The audit work program needs to be reviewed and approved by the CAE before engagement commencement. Ultimately, conforming and understanding the principles behind the Standards are important.

Auditing Organizational Governance. IA has an integral role to play in improving the organization’s strategic performance. This area is becoming increasingly important in recent years. Governance reviews can help prevent governance failures. Less than 1 in 6 IAs conduct reviews for their organization’s strategy. Sometimes, it might be difficult to conduct a separate governance review. Rather, it might be easier to incorporate it as part of routine audits. One can focus on both the governance structures as well as the organizational culture. Some of the soft controls can include management competence/style; mutual trust and openness; strong leadership; high performance and quality expectations; shared values and understanding; high ethical standards. However, for some of these measures, there are no hard data to analyse. Hence, it is important for IA to read the signs. IA can also provide a more advisory role, which is educating board about developments and trends in the industry and governance best practices. In terms of strategic reviews, IA has much to work on. There is a tendency to focus on weaknesses in financial reporting etc.

Good Governance is All About Quality. The 5 quality rules are (i) customer focus; (ii) management leadership; (iii) Teamwork; (iv) Measurement; (v) Total commitment to continuous improvement.

pic_internal_audit_big

 

IIA Magazine April 2017 issue

Business Resiliency is about the organization’s ability to quickly adapt to risk events such as these while maintaining continuous operations and safeguarding its employees, assets, and brand equity.

Malware, Ransomware and man-in-the-middle attacks are common security issues for organizations

Some organizations lack a clear risk management program and that is a problem. Lack of resources, complexity and inability to get started are some of the reasons cited.

  1. Communication errors/ misinformation over company performance through channels other than financial reports; 2. Environment, health and safety is an area which is high risk, but not many IA covers this.

Cyber risks are also a main area where IA needs to be concerned about.

Learn to work smart and not harder. Employers should 1) acknowledge the problem; 2) appreciate the employee; 3) identify the root cause; 4) define the roadblock; 5) Devise a solution (training, resource allocation, process improvements); 6) Circle back. Guiding an employee well will result in an increase in productivity and morale.

The Data Museum. IA can compile organizational data in structured exhibits. Auditors need to use data warehousing principles to clean the data and structure it once that it is ready for analysis. Before storing data, consider the following: relevance, reliability; reusability; rarity. For instance, SQL can be used to extract, transform and load the data. Learn to run SQL statements. As for audit tools, auditors can use data visualization and advanced reporting techniques. Use a relational database and start small. Ensure that there are audit trails and logs.

The Many Facets of Risk. Risk is always multi-faceted. Look at the product and market research life cycle. It is important to do the strategy and competitive analysis like via SWOT, Porters’ 5 forces etc. Financial Management like NPV calculations aid in project-making decisions. Operations Management is about maintaining the optimum amount of inventory, like the EOQ method. Forecasting sales and demand is also a risk. Human resource risks and quality management risks are also possible. IA can act to cross-pollinate risks via mathematical or management methods.

Life of Luxury (Embezzlement). When too much power, accounting and budgeting etc, resides with the head, too much risks exists and there is potential fraud risk. There were too many over budgeted accounts in this case. Also, a person spending excessively or leading a lavish lifestyle will arouse suspicion. There are many lessons that the IA can learn: include riskier businesses in the IA plan; question how beneficial is the whistle-blowing hotline; an audit on payroll can detect payment to ficitious persons/ other people; review the acceptable use policy for all corporate-issued credit cards.

Resilience Through Crisis. Organizations all need to overcome crises and emerge stronger. The BP oil-spill PR was handled badly. IA can audit the crisis management plan. A crisis team should be cross-functional and with each goal clearly defined. IA should also be part of the team to ensure that the team is addressing the appropriate issues. The team should identify potential crises and IA can chip in. Next, a comprehensive crisis plan should be developed. Effective communication is the key and there must be a plan to inform stakeholders quickly. It is also important to have a spokesperson to handle the media etc. General templates can be used for media statements. Experts can be used as well. Crisis simulations should be conducted, like table-top exercises etc. IA should be the observer in all simulations. After the crisis, the crisis management team should evaluate the effectiveness and the performance of the plan.

Hit the Ground Running. The trend is to convert interns in IA into the permanent establishment as they already understand some of the company’s operations. One option is to transfer existing staff to IA. Interns who perform well stand to be converted. Interns are also less costly and can be used during peal-periods. There needs to be a significant investment in developing a good internship programme. There needs to be a plan all along. When you plan, it is important to prepare a job description, program budget, hiring plan and schedule. Provide guidelines for the interns to do work and make the audit project interesting for them. Teach them soft skills in the audit. Give them real assignments. Stretch them and ensure that they can contribute and make their internship meaningful.

Climbing the Scale. Turn to maturity models. Maturity models can rank from 1 to 5. They can be expanded into many business areas nowadays. Maturity models can be more meaningful than a simple pass/fail. Using this can convey a more positive collaborative tone too. Acknowledge what the client is doing already to improve processes and controls. A maturity model also focuses more on processes than people and seems more non-threatening. The models you can use are CMMI, C2M2, COBIT, P3M3, RMM, TMMi etc. Develop a dynamic risk assessment approach. IA should provide both assurance and insight. One can use the ISO standardized frameworks to compare the organization’s maturity level against. At times, the highest level of maturity might not be required as a lot of resources will be required. Maturity models can be very judgemental indeed. To succeed, IA needs to choose the correct model and be flexible when applying it. Build the best model and find a project champion if possible.

From the Same Playbook. IA needs to align its work with the organization’s strategy. There are debates as to whether IA should provide assurance around risks affecting company strategy. It depends on the CAE. However, not all top executives will want to discuss strategy with the CAE. There can be a disconnect as IA usually does not audit the latest transformations and developments in the company. Some IA prefer to audit compliance, which they are more familiar with. Two big risks are not having effective strategy or not executing them properly. CAE should think like CEOs and think through different perspectives and figure out how to maximize shareholder value. IA can perform gross profit margin analysis etc. There needs to be a balance between strategic-level audits and compliance based audits. Have discussions with management and the audit committee on strategy. It is for IA to look into strategy risks and the risks of entering any particular strategy.

Three Lines in Harmony. A Centralized testing model will enable the 3 lines of defence to rely on each others’ work. Front-line management is the first line of defense, risk/compliance functions are the second line of defense, internal audit is the third line of defense. It is important to co-ordinate so as to ensure all areas are covered and there are no duplications. Relying on others can also provide an increase in efficiency. Ensure that there are proper service agreements if there is a centralized testing unit. Automatic testing preferred and desired. There is a need to document the risk framework.

Signature Audits. Auditors should try to identify and respond to emerging risks. Most IA confirm concerns already identified by management. IA can do a mystery shopper role, or perform simulations to test controls. IA now need to be more innovative and curious. Signature Audits refer to thinking out of the box to design appropriate test procedures (example: penetration testing or social engineering). IA can identify best practices or try to circumvent processes rather than test them.

Internal-Audit

Audit Analytics by Sean Elrington

Data analytics is useful for good governance as it provides better assurance as compared to manual sampling. Is the need to hire consultants necessary for straight-forward audit tests? It can help recover unnecessary spending. There may be resistance from the other departments if audit wants to perform 100% checks. There are still auditors which do not use data analytics.

Common Objections to Using Audit Analytics. Some auditors are too busy to learn and to change. The data may not be readily available. In addition, the cost has to be justified. Some are too intimidated by change. You need an understanding of ERP, database structures, views, tables etc. The benefit is that you might save time for data analysis. How will analytics help audit productivity? As it requires less man-hours, analytics can be useful. Although in the short-run, probably more work will be required. If the error is systematic, testing 100% of the population might not be very useful. In such cases, it will be better just to test a few samples and fix the control first. Analytics is here to stay.

Questions that the IT manager will ask you. Why can’t the auditors use Excel? Excel has its limitations on data size. Random sampling is not a good way to detect fraud. Data can be amended easily in excel and it does not have much data security. Sorting can be slow and Excel lacks functions like Benford’s Analysis. Modern audit software have data logs too. It is good to host the data on a server especially when there are multiple users. If you rely on the IT department to generate data for you, there is a risk that the data could be manipulated before being provided to you. There is an issue of how much access that an audit should be given. Data should be obtained from production and not the data warehouse. In the data warehouse, bad data might have been removed already. Application controls rely on passwords and roles to work. Relying on the controls in the ERP system might not be useful when there is collusion. Data might be present from different systems and auditors can’t simply draw the data from one ERP system.

Considerations when choosing audit software. Some of the functions that are heavily used are extract, join, relate, summarize, stratify, classify and age. Continuous monitoring is a lot more expensive and complicated. Is training a big consideration? Do you need to write your own scripts? Or can you buy scripts? What is your required return on investment? Will learning the software help the auditors in their career development? How much technical support is needed? What are the server requirements?

Analytic Software Tools. Picalo is a free tool that can be downloaded online. Some of the other software besides Excel are TopCATTs, Arbutus Software, IDEA, Monarch, Picalo, ACL. ACL usually requires a lot of training before users will know how to use.

Testing for Duplicate Payments. One can test both exact and fuzzy matches. There are multiple reasons why this might occur. First, you have to ensure that there are no duplicate vendors by scrutinizing the vendor’s details. For exact match testing, you can use ‘Substring’; ‘Include’; ‘Exclude’; ‘Alltrim’ formulae to remove dashes, hyphens etc. Testing should be performed on fields like Invoice Number, Vendor Number, PO Number, Date, Amount etc. Deconstruction techniques are used for Fuzzy matches. They use techniques like Soundex, Soundslike, HEX etc. Some of the algorithms are Levenshtein distance, Metaphone etc.

P2P Vendor Analytics. Some of the objectives are 1) vendor master file is correct; 2) employees are not vendors; 3) no duplicate or unused vendors. Match vendor information with employee information. Check out vendor addresses to ensure that they are not mail drop addresses used by delivery services. Sort the number of vendors by payments per year. Use a vendor name fuzzy match. Find vendors with missing fields to check whether the vendor master is well-kept or not.

Purchase Card Analytics. Objectives are 1) only authorized employees are using cards; 2) card purchases are acceptable. Try and detect transactions by authorized card-holders. Find cardholders not in employee master file. List top spenders by department. Find transactions in excess of authorization limits. Identify weekend and holiday purchases.

FCPA analytics. Objectives are 1) test that there are no suspicious payments made to individuals or entities; 2) verify that gifts received are permitted. Identify payments made to high risk countries. Identify cash payments. Identify unusual gifts. Identify credit card spending with unusual Merchant Category Codes. Find unusual vendors, like PEPs etc. Flag out payments with the words ‘facilitate’. Match to watch-lists, world-check etc.

P2P Payment Analytics. Objectives: 1) POs are unique and properly filled; 2) SODs are working; 3) controls to match invoice and PO amounts are accurate. Detect split purchases. Find duplicate payments. Find POs that were raised late. Look out for people who can create and approve their own POs. Look out for unauthorized purchasers. Ensure that there is approval for all POs. Compare a list of payments to prohibited vendor lists.

GL Analytics. Objectives: 1) Only authorized employees are making GL entries; 2) GL entries are acceptable. Detect duplicate GL entries. Look for suspicious wordings like ‘park’; ‘temp’; ‘reverse’; ‘suspense’. Detect GLs made at odd timings. Detect payment voucher and look out for approvals etc. Look out for frequently changed or reversed accounts. Find temporary accounts.

Healthcare Analytics. Objectives: 1) procedures billed to the correct code; 2) appropriate charges are billed to correct account; 3) reasonable timeline of patient activities.

Fraud Facts. Whistle-blower hotlines are a great way to detect fraud. Some level of fraud might be acceptable. It depends on the organizational culture. It is not the auditor’s responsibility to detect fraud. Look out for transactions with fraud symptoms. In general, there are two types of fraud: 1) Fraudulent financial reporting and 2) misappropriation of assets. It is hard to distinguish whether it was an honest mistake or fraudulent. The top from the top must be correct.

Common Business Frauds. You might need the help of a skilful financial auditor to deconstruct fraudulent financial reporting. Financial fraud is a very serious matter. Misappropriation of assets often involve kickbacks. Multiple payees could be an issue. Duplicate payments are a potential source of fraud too. A shell company could be used to deliver fictitious services. Detect maintenance which has been performed too frequently. Physical inspection of works/goods can help. Look out for defective delivery of goods/services by having good IC over the receipting of goods and services. See how often different employees reject or accept goods based on their quality. Inaccurate pricing is one of the type of risks too. Contract rigging means awarding to the lowest bid, but later subsequently changing the product specs so that the contractor will have to deliver more and thus can earn more money. Check contracted projects over their original budgets. Contract rigging is difficult to detect if you are not familiar with the goods. Bid rigging is very difficult to detect. Ensure that there are no phantom employees or contractors. Look out for invalid employees’ wages.

Interesting Fraud Stories. The fraud triangle occurs when there is 1) opportunity; 2) motivation; 3) rationalization. Don’t let non-trained employees do the accounts. Do not let the salespeople collect the cash. Be wary of bribery to win contracts etc.

analytics-hero-5f7a43918471e91c3e0f0d7347d5698b