23.11.2014 Views

Protiviti Pitch Deck Template - The Institute of Internal Auditors

Protiviti Pitch Deck Template - The Institute of Internal Auditors

Protiviti Pitch Deck Template - The Institute of Internal Auditors

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Leveraging Data for Audit Planning, Execution<br />

and Mitigating Risk on a Continuous Basis<br />

Miron Marcotte and Brad Rachmiel<br />

March 14, 2005<br />

© 2005 <strong>Protiviti</strong> Inc. EOE


Agenda<br />

• Introductions<br />

• Objectives <strong>of</strong> Today’s Session<br />

• <strong>The</strong> Evolution <strong>of</strong> Continuous Auditing<br />

• Overview <strong>of</strong> Selected Tools<br />

• Case-Study --- Tool Demonstration<br />

• Summary<br />

• Q&A


Introductions<br />

• <strong>The</strong> purpose <strong>of</strong> this exercise is to allow us<br />

to learn a little about each <strong>of</strong> you so that<br />

we can tailor our presentation accordingly<br />

• Please take out a blank piece <strong>of</strong> paper<br />

• Please draw a PIG<br />

• Don’t talk to your neighbor<br />

• Don’t look at your neighbor’s paper<br />

• You have 2 minutes


Objective <strong>of</strong> Today’s Session<br />

• To present the key drivers behind the Age <strong>of</strong><br />

Continuous Auditing along with the response<br />

from the <strong>Internal</strong> Audit community<br />

• To create some awareness around a variety <strong>of</strong><br />

tools that Leverage Data for Continuous<br />

Monitoring and other Audit purposes<br />

• To discuss the concept <strong>of</strong> Financial Leakage,<br />

and present some alternatives for identifying this<br />

leakage<br />

• To provide a detailed walk-through <strong>of</strong> a<br />

Continuous Monitoring tool


Survey<br />

• Throughout our presentation, we will ask you to<br />

answer a number <strong>of</strong> questions related to<br />

today’s session.<br />

• We would like you to turn in the survey at the<br />

end <strong>of</strong> the session.<br />

• You may either:<br />

• Keep it anonymous<br />

• Put you name on it (or attach your business<br />

card) -- we will compile the results <strong>of</strong> the<br />

survey and email a copy <strong>of</strong> the results to you


<strong>Protiviti</strong> – Our Firm<br />

• Leading global firm focused on<br />

Risk Consulting and <strong>Internal</strong><br />

Audit (1800 pr<strong>of</strong>essionals, 37<br />

<strong>of</strong>fices, 9 countries)<br />

• In addition to <strong>Internal</strong> Audit<br />

and Governance (SOX), there<br />

are 25 service lines that help<br />

our clients address various<br />

Business and Technology<br />

Risks


Spend Risk Solutions -- Our Practice<br />

• Focus on the Purchase-to-Payment (Spend) process<br />

•Utilizeproprietary tools and deep functional expertise to:<br />

• Identify both <strong>Internal</strong> Control and Operational Risks<br />

associated with a company’s Spend<br />

• Identify, recover and prevent Financial Leakage<br />

• Identify Spend Optimization opportunities


History <strong>of</strong> <strong>Internal</strong> Audit<br />

Ancient<br />

History<br />

1940’s 1992 Today Future<br />

Age <strong>of</strong><br />

Inspection &<br />

Re-<br />

Performance<br />

Age <strong>of</strong> Control<br />

Focused<br />

Auditing<br />

Age <strong>of</strong> Risk<br />

Based<br />

Auditing<br />

?<br />

• Very substantive<br />

• Focus on:<br />

• Recounting<br />

• Re-performance<br />

• Inspection<br />

• Assisted external<br />

auditors with<br />

clerical tests and<br />

tasks<br />

• Victor Brink’s book<br />

• Modern <strong>Internal</strong><br />

Auditing – 1942<br />

• IIA Established<br />

• Began “service to<br />

management”<br />

• Began Operational<br />

Auditing<br />

• Began to focus on<br />

adherence to<br />

controls & policies<br />

• Publication <strong>of</strong><br />

COSO <strong>Internal</strong><br />

Control - Integrated<br />

Framework<br />

• Broader definition<br />

<strong>of</strong> risk than just<br />

Financial Reporting<br />

• Focus on risk<br />

mitigation by proper<br />

design/operation <strong>of</strong><br />

entity & process<br />

level controls


Forces Affecting <strong>Internal</strong> <strong>Auditors</strong><br />

SOX - Rapid &<br />

Robust Reporting<br />

Financial Info &<br />

Control Issues<br />

Rapid<br />

Pace <strong>of</strong><br />

Business<br />

Change<br />

New<br />

Factors<br />

Affecting<br />

<strong>Internal</strong><br />

<strong>Auditors</strong><br />

Increased<br />

Pressure to<br />

Detect/Prevent<br />

Fraud<br />

Increased<br />

Complexity <strong>of</strong><br />

Technology


How <strong>Internal</strong> <strong>Auditors</strong> are Responding<br />

Need for Rapid &<br />

Robust Reporting<br />

<strong>of</strong> Financial Info<br />

& Control Issues<br />

Increased<br />

Pressure to<br />

Detect & Prevent<br />

Fraud<br />

Rapid<br />

Pace <strong>of</strong> Business<br />

Change<br />

Increased<br />

Complexity <strong>of</strong><br />

Technology<br />

• Developing risk control specialists to assist with SOX<br />

• Developing processes for more rapid & robust reporting <strong>of</strong><br />

control issues (i.e. – continuous monitoring)<br />

• Increased contact with external auditors, audit comm., etc.<br />

• Performing explicit fraud risk assessments<br />

• Monitoring “Whistleblower” hotlines<br />

• Increasing the use <strong>of</strong> self-assessments to improve the chance<br />

<strong>of</strong> someone identifying and reporting a fraud risk<br />

• Focusing on IA roles in Enterprise Risk Management<br />

• Consolidation <strong>of</strong> risk assessment initiatives (ERM, SOX, BCP, etc.)<br />

• Some becoming Chief Risk Officers<br />

• Increased use <strong>of</strong> outside IT specialists<br />

• Increased investment in IT audit tools and techniques<br />

• Increased development <strong>of</strong> automated monitoring tools


<strong>The</strong> 4 th Age -- Continuous Auditing<br />

“<strong>The</strong> value <strong>of</strong> continuously monitoring and auditing<br />

controls has been discussed and experimented with<br />

for a considerable time but two factors are now<br />

helping it to become standard practice.<br />

Specifically, enhanced computer technologies and<br />

the impact <strong>of</strong> legislative changes such as the<br />

Sarbanes-Oxley Act, are serving to facilitate and<br />

accelerate the use <strong>of</strong> continuous auditing<br />

approaches.”<br />

---<strong>The</strong> Honorable David M. Walker, Comptroller<br />

General <strong>of</strong> the United States


<strong>The</strong> <strong>Internal</strong> Auditor <strong>of</strong> the Future<br />

• Annual risk assessments will be viewed as<br />

untimely and obsolete<br />

• IA will have to develop and implement systems that<br />

provide continuous risk assessments and<br />

updates to audit plans<br />

• Significant risks will need to be monitored<br />

continually by management, and internal auditors<br />

will need to be able to test management’s<br />

monitoring process on a continuous basis<br />

• Audit committees and stockholders will expect<br />

breakdowns in significant controls to be detected<br />

and reported almost immediately


In the Age <strong>of</strong> Continuous Auditing<br />

Technology will enable a more robust leveraging <strong>of</strong> data<br />

to facilitate decision making throughout the enterprise<br />

Audit Planning<br />

& Execution<br />

Leveraging<br />

Data<br />

Risks<br />

Continuous<br />

Monitoring


Survey Question # 1<br />

X<br />

• How big was the size <strong>of</strong> your Pig’s tail????<br />

Today<br />

Next 1-2 yrs<br />

• What % <strong>of</strong> your audit testing is<br />

performed on a sample set <strong>of</strong> data<br />

(vs. auditing 100% <strong>of</strong> the data)


Survey Question # 2<br />

Audit Planning<br />

and Execution<br />

Continuous<br />

Monitoring<br />

• Today, do you primarily<br />

leverage your data for Audit<br />

Planning and Execution or<br />

Continuous Monitoring?


Examples <strong>of</strong> Technology Enablers<br />

Application-Focused Tools:<br />

Process-Focused Tools:


Application-Focused Tools<br />

Features<br />

Tools<br />

jabIT Assure<br />

Solutions<br />

www.jabitsolutions.com<br />

Applimation<br />

Integra<br />

www. applimation.com<br />

<strong>Internal</strong> Contols<br />

Enforcer<br />

www.peoples<strong>of</strong>t.com<br />

ERP<br />

Application<br />

SAP Oracle PeopleS<strong>of</strong>t<br />

Security<br />

Controls<br />

Configuration<br />

Controls<br />

Data Diagnostic<br />

Testing<br />

Bolt-on<br />

Application<br />

No Yes Yes


Example -<br />

Risk Configurable Controls Not Operating Effectively<br />

Benefit Automates Testing and Prioritization <strong>of</strong> Risks Identified<br />

Source: jabIT as used by <strong>Protiviti</strong>


Example -<br />

Risk Accounts Activated for Inactive Users & Policy Nonconformance<br />

Benefit Automates Testing and Identification <strong>of</strong> Security Issues<br />

User Login & Password Change Analysis Report<br />

Metric Analysis<br />

Result<br />

Analysis<br />

Total Number <strong>of</strong> User Accounts 17,677<br />

Total Number <strong>of</strong> Active User Accounts (As <strong>of</strong> xxx) 15,454 87.4% <strong>of</strong> total user<br />

accounts<br />

Total Number <strong>of</strong> Active User Accounts - Have Ever Logged In 12,456 80.6% <strong>of</strong> active user<br />

accounts<br />

Total Number <strong>of</strong> Active User Accounts - Have Logged In During<br />

Calendar Year (As <strong>of</strong> xxx)<br />

Total Number <strong>of</strong> Active User Accounts - Have not Logged In<br />

During Calendar Year (As <strong>of</strong> xxx)<br />

11,591 75.0% <strong>of</strong> active user<br />

accounts<br />

865 5.6% <strong>of</strong> active user<br />

accounts<br />

Total Number <strong>of</strong> Active User Accounts - Have NEVER Logged In 2,998 19.4% <strong>of</strong> active user<br />

accounts<br />

Total Number <strong>of</strong> Active User Accounts - PWD Change Policy NOT<br />

SET<br />

Total Number <strong>of</strong> Active User Accounts - PWD Change Policy Set<br />

to 90 Days or Less<br />

Total Number <strong>of</strong> Active User Accounts - PWD Change Policy Set<br />

to 91 Days or More<br />

413 2.7% <strong>of</strong> active user<br />

accounts<br />

15,041 97.3% <strong>of</strong> active user<br />

accounts<br />

- 0.0% <strong>of</strong> active user<br />

accounts<br />

Source: Applimation as used by <strong>Protiviti</strong>


Example -<br />

Risk<br />

User Access – Segregation <strong>of</strong> Duty Issues<br />

Benefit Automates Testing on a Continuous Basis<br />

<strong>The</strong> Diagnostic Manager allows you to<br />

compare access to a process ID (e.g. VMF)<br />

at multiple points in time.<br />

<strong>The</strong> Diagnostic Report will display the<br />

status <strong>of</strong> all users who have access to the<br />

process ID at each point in time.<br />

1<br />

2<br />

<strong>The</strong> Diagnostics Comparison will compare<br />

the user’s access at each point in time so<br />

that changes in access can be<br />

continuously monitored on command.<br />

Source: PeopleS<strong>of</strong>t


Process-Focused Tools (External)<br />

(WWW.ANGOSS.COM)<br />

• KnowledgeSTUDIO analyzes and models data and aids in the<br />

identification <strong>of</strong> business trends and risks that lie ahead<br />

through data mining and quick visualization <strong>of</strong> data via charts<br />

and graphs<br />

(WWW.ACL.COM)<br />

• ACL enables data inquiry, analysis and reporting by uploading<br />

data from almost any data source (database, ERP system, etc.)<br />

and permits users to analyze data interactively


Process-Focused Tools (<strong>Internal</strong>)<br />

(WWW.PROTIVITI.COM)<br />

• Provides an engine to create and conduct assessments by<br />

surveying end users and creating a repository for best<br />

practices and key controls<br />

(WWW.PROTIVITI.COM)<br />

• Assesses risks associated with an organization’s<br />

purchase-to-payment (P2P) process including<br />

quantification <strong>of</strong> possible financial leakage, evaluation <strong>of</strong><br />

the internal control environment and helps identify<br />

methods to enhance processes and technologies<br />

associated with spend


Example -<br />

Risk Paying Fraudulent Insurance Claims<br />

Benefit Reduces the Likelihood <strong>of</strong> Fraud through Modeling<br />

Identify a set <strong>of</strong> “rules” to better<br />

predict the occurrence <strong>of</strong> fraud<br />

Source: KnowledgeSTUDIO as used by <strong>Protiviti</strong>


Example -<br />

Risk Payment Errors<br />

Benefit Identify Transaction Anomalies at any Point in Time<br />

Source: ACL


Example -<br />

Risk<br />

Unable to Interview all Parties in a Timely, Cost Efficient Manner<br />

Benefit Allows Organizations to Monitor and Rate Control Risks on a<br />

Real-Time Basis<br />

Source: <strong>Protiviti</strong>


Example -<br />

Risk Controls are not Operating Effectively Resulting in Financial Leakage<br />

Benefit Detect and Prevent Financial Leakage BEFORE It Occurs<br />

Source: <strong>Protiviti</strong>


Survey Question #3<br />

• How many different Continuous<br />

Monitoring tools do you utilize?<br />

• Application-focused<br />

• Process-focused<br />

Today<br />

Next 1-2 yrs<br />

• Please list the tools in place today.


Tool<br />

Demonstration


Benefits <strong>of</strong> Continuous Monitoring Tools<br />

• Improve Corporate Governance<br />

• Immediate Issue Notification to Management<br />

• Increase External Auditor Assurance<br />

• Leverage Data to Help Identify Risks and<br />

Opportunities<br />

• Add Value to your Organization<br />

• Transform data into pr<strong>of</strong>itable information<br />

that can increase revenues and reduce<br />

costs<br />

• Audit BETTER, CHEAPER, and FASTER<br />

• Bring the audit to you<br />

• Audit 100% <strong>of</strong> Transactions<br />

• Automated vs. Manual<br />

Risks


Closing Thoughts<br />

“In the absence <strong>of</strong> a continuous monitoring<br />

process, organizations may be further exposed<br />

to fraud, error and abuse – representing a<br />

significant cost as well as pr<strong>of</strong>it erosion<br />

through revenue leakage.<br />

--- J. Don Warren, Director <strong>of</strong> the Center for<br />

Continuous Auditing


Survey Question #4<br />

X<br />

• How big was the size <strong>of</strong> your Pig’s tail????<br />

Yes<br />

No<br />

• Did we meet your expectations<br />

during today’s presentation?


Any Questions?


Contacts:<br />

Miron Marcotte (312) 476-6424<br />

Miron.Marcotte@protiviti.com<br />

Brad Rachmiel (312) 476-6425<br />

Brad.Rachmiel@protiviti.com<br />

John Maddente (414) 390-1715<br />

John.Maddente@protiviti.com

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!