Custom Search
Showing posts with label Auditing. Show all posts
Showing posts with label Auditing. Show all posts

Getting the Best From an Audit

Getting the Best From an Audit
C J Kelly. Computerworld. Framingham: May 12, 2008. Vol. 42, Iss. 20; pg. 34, 1 pgs

Abstract (Summary)
An independent information security audit can be nerve-wracking, but this time, the author actually enjoyed it. She guesses it's just a matter of perspective. A bigger factor was that this time around, she was prepared. And she's come to see the audit not as a reproach to her work but as a quantitative affirmation of all the things she's been saying they need to do to keep their data safe. Her idea was to ask the auditor to help her develop documentation and processes for the agency that would ensure a formalized system-development life cycle. The new process addresses the security concerns raised by the report. As a result, they now have a suitable framework with which they can begin doing things differently.

Don't fear the audit. Learn from it. The important thing is that systems should be more secure in the end.

AN independent information security audit can be nervewracking, but this time, IJustify Full actually enjoyed it. I guess it's just a matter of perspective.

It might help that I've been an auditor myself, and so I knew what the auditor was looking for and what he would put into his report. But that isn't the whole story.

A bigger factor was that this time around, I was prepared. And I've come to see the audit not as a reproach to my work but as a quantitative affirmation of all the things I've been saying we need to do to keep our data safe.

Of course, even quantitative results can be misleading, misguided or misconstrued, depending on the expertise of the auditor. And quite often, what most people will look at is the executive summary. In our case, that was a few pages, backed up by a 700-page technical report. Guess which one of those the higher-ups in state government are going to look at?

The problem is that this executive summary, like most of them, is filled with charts and graphs that grossly overstate our security problems. Not that we don't have problems. We do, and I'm glad to have them out in the open.

In our report, what those charts and graphs showed were the number of high-, medium- and low-risk vulnerabilities and their levels of exploitability. The sheer volume of potential problems could overwhelm the uninitiated.

I need to formulate a response to this, so that as this audit report goes up through the chain of command, those who read only the executive summary will have my comments to refer to. This will be a tough document to craft, because my purpose is to show how the executive summary exaggerates and distorts the actual situation, but I don't want to sound defensive or oblivious to what are real shortcomings.

MEGO GALORE

As for that 700-page technical report, even I could only scan it before I came down with a serious case of MEGO (my eyes glaze over). What I got out of it was that all of the highrisk vulnerabilities are related to our application development environment. And many of these highrisk vulnerabilities would require very little skill to cause serious harm.

This wasn't a big shock. I knew that application development was a problem. But the report was an opportunity to do something about it.

The basic weakness is that developers and programmers often have unpatched systems or have configured their systems so that the application they are working on will work the way they want it to. They give no thought to security matters, as you might well expect.

My idea was to ask the auditor to help me develop documentation and processes for the agency that would ensure a formalized system-development life cycle. The new process addresses the security concerns raised by the report.

As a result, we now have a suitable framework with which we can begin doing things differently. At the same time, we moved the application development team to a separate network segment, off of the production network. That should make it less alarming if the application development systems aren't completely up to date.


There is more work to do in the aftermath of this audit, but we've made big progress. Best of all, the positive outcome is something I wouldn't have thought of without the audit.

So, here's a bit of advice: If you are a security manager, welcome your next audit with open arms. The burdens of playing bad cop all the time and being ignored will be off your shoulders. Let the audit speak for itself- in all its quantitative glory.

Read More....

Auditing skill

MENTOR: How good are your auditing skills?
Anonymous. Businessline. Chennai: Oct 6, 2008.

Abstract (Summary)
Hence, the company is justified in including the interest component on the cash credit account attributable to such stocks in the valuation of its stocksc) Dividends are to be paid only in cash. The company is not justified in its proposal to pay dividend by giving cloth at cost price to its share holders. Audit considerationsQ3(a) What are the points to be considered by an auditor under Section 227 (1A)? (7 marks) Section 227(1A), applicable to all audits, requires an auditor to examine the following and offer a comment only if it is not complied with: Where the company makes loans and advances against a security, whether such loans and advances are properly secured and whether the terms of such loans are not prejudicial to the interest of the company or its members. Where certain transactions are represented by mere book entries, whether such transactions are not prejudicial to the interest of the company. Where the company, not being an investment company, sells its investments, whether the sale is not below the purchase price and that the terms of sale are not prejudicial to the company. Whether advances and loans are disclosed as deposits. Whether any expenditure of a personal nature has been debited to the profit and loss account. Where it has been mentioned that shares have been allotted for cash, whether the company has actually received cash. b) What is auditor's lien? (3 marks) Auditor lien is a right of the Q4(a) What are the different methods of substantive procedures?

from BUSINESS LINE, October 06, 2008 State whether the following are true or false giving reasons: (2x10 = 20 marks) a) Internal auditor need not send his audit report to the statutory auditor.

b) Tolerable error is the difference in balance sheet acceptable to the auditor.

c) An auditor has no access to a company's non-financial records.

d) Board of directors can appoint the first auditor of any company.

e) Private limited company, which is a subsidiary of a public limited company, is not included in the ceiling of 20 audits.

f) Cost audit cannot be carried out by a chartered accountant.

g) An income-tax officer cannot add taxable income arbitrarily.

h) Propriety audit is audit of proprietary concerns.

i) Test audit is the other name of test check.

j) Deferred revenue expenditure is capital in nature, hence taken to the balance sheet.

Answers: a) True. Confidentiality is applicable to internal auditors also. Statutory auditor is a third party. There is no legal or professional requirement to submit the report.

b) False. It is the error acceptable between the inferences from sampling as compared to the bulk (AAS 15).

c) False. Section 227 of the Companies Act gives him a statutory right of access to any information, which, in his opinion, is necessary for the purposes of the audit.

d) False. They cannot appoint the first auditors of a government company.

Such an appointment can only be done by the C&AG.

e) True. Any private limited company is excluded from the ceiling of 20 audits f) True. Cost audit can be carried out by cost accountants only.

g) True. Assessment is to be done as per the provisions of law.

h) False. It is an audit in to the justification of expenditure incurred by an officer.

i) False. It is another name of supplementary audit. It is carried out by the C and AG. It is a type of audit, whereas test check is an audit technique.

j) False. It is revenue in nature, having benefits extending beyond the accounting period.

Statement analysis Q2: Give your views on the following: a) During the course of the audit, the auditor comes across a fraud committed by the director of a company, who makes good the loss suffered by the company. The auditor does not qualify the report. (6 marks) b) A company dealing in timber holds its stocks for long durations for seasoning.

The company proposes to include the interest component on the cash credit account attributable to such stocks in the valuation of its stocks. (7 marks) c) A textile company proposes to give the cloth manufactured by it to the shareholders at its cost of production by way of dividend. (7 marks) Answers: a) When an auditor finds a fraud, he should bring it to the notice of the higher authorities. If a director commits a fraud, the auditor should bring it to the notice of the shareholders of the company, the fact that he has made good the loss notwithstanding.

An auditor is governed by confidentiality, which prohibits him from divulging information to a third party, unless he is legally or professionally required so to do.

An audit report is a public document. By qualifying his report, the auditor is communicating with persons such as bankers, tax authorities, etc, who are not the shareholders of the company. Therefore, such qualification in the report would be violative of the concept of confidentiality.

Hence he is justified.

b) AS 16 defines a "qualifying asset" as an asset which requires a substantial period of time before it is ready for its intended use. It does not distinguish between fixed assets and current assets.

In the given case, if timber is to be stored for substantially long period of time before it is ready for its intended use, that is, sale, it also becomes a "qualifying asset".

Once it is a "qualifying asset", borrowing costs expended for it can be capitalised.

Hence, the company is justified in including the interest component on the cash credit account attributable to such stocks in the valuation of its stocksc) Dividends are to be paid only in cash. The company is not justified in its proposal to pay dividend by giving cloth at cost price to its share holders. Audit considerationsQ3(a) What are the points to be considered by an auditor under Section 227 (1A)? (7 marks) Section 227(1A), applicable to all audits, requires an auditor to examine the following and offer a comment only if it is not complied with: Where the company makes loans and advances against a security, whether such loans and advances are properly secured and whether the terms of such loans are not prejudicial to the interest of the company or its members. Where certain transactions are represented by mere book entries, whether such transactions are not prejudicial to the interest of the company. Where the company, not being an investment company, sells its investments, whether the sale is not below the purchase price and that the terms of sale are not prejudicial to the company. Whether advances and loans are disclosed as deposits. Whether any expenditure of a personal nature has been debited to the profit and loss account. Where it has been mentioned that shares have been allotted for cash, whether the company has actually received cash. b) What is auditor's lien? (3 marks) Auditor lien is a right of the Q4(a) What are the different methods of substantive procedures? How are they used? (6 marks) b) What are the advantages of an audit plan? (4 marks) Q5(a) What points are to be considered in an examination in depth? (5 marks) b) What are the precautions to be taken while resorting to a test check? (5 marks) Q6(a) What are the drawbacks of an audit of a small company? (6 marks) b)

What are the considerations for audit of income by the C&AG? (4 marks) Short notesQ7: How do you vouch/verify any two of the following? (2x5 = 10 marks) a) Cenvat credit receivable; b) contingencies; c) write off of bad debtsQ8: Write short notes on any two of the following: (2x5 = 10 marks) a) Computer aided audit techniques; b) audit trail; and c) concept of true and fair.

Read More....

Inappropriate P-card Practices

Inappropriate P-card Practices
Courtenay Thompson. The Internal Auditor. Altamonte Springs: Jun 2004. Vol. 61, Iss. 3; pg. 97, 3 pgs

Abstract (Summary)
At a major research university, the internal auditors were tasked with performing routine documentation reviews for the university's procurement card (p-card) program. The lessons to be learned about p-cards from a fictional case study include: 1. Routine audits, although not glamorous, may provide opportunities for internal auditors to identify material control weaknesses in routine processing systems that can have wide ranging impact. 2. The p-card process should have an outlet, by hotline or anonymous e-mail, to allow individuals involved in transaction processing and oversight to report suspected abuse without fear of retribution. 3. Budget pressures may so impact established internal controls that the control is eliminated, resulting in significantly increased risk of fraud.

An understaffed university accounting department gets some much needed help from campus internal auditors and uncovers fraudulent use of procurement cards.

AT A MAJOR RESEARCH UNIversity, the internal auditors were tasked with performing routine documentation reviews for the university's procurement card (p-card) program. Although the audit director was not generally in favor of his department performing routine monitoring, he had agreed to the reviews as a service to the accounting director, whose department recently had been a target of budget cuts.

The accounting department had only one person assigned to review p-card transactions processed through the accounting office. With 1,200 p-cards in staff and faculty hands, the review clerk was responsible for manually reviewing nearly 71,000 transactions totaling more than $11 million from the previous year. The p-card program relied solely on internal control processes in user departments and the monitoring practices of one accounting clerk to ensure the cards were used only for appropriate university expenses.

Previous documentation reviews in other departments had revealed random missing documents, a few instances of card use by someone other than the person to whom the card was assigned, and occasional pyramiding of transactions. (Pyramiding is the use of multiple, or split, transactions - for example, multiple card swipes - in an attempt to break transactions into smaller pieces to circumvent card limits.) These transactions are usually easy to identify with data sorts by vendor and date, or by date, vendor, and accounting transaction number. They are also usually fairly easy to spot by their even-dollar amount and by data extraction that highlights purchase amounts reasonably close to the transaction limit. Despite these occurrences, no evidence of fraud had been identified.

As the current round of documentation reviews was drawing to a close, the internal audit director decided to review one of the university's remote locations that had several p-cards assigned to staff and faculty. His reasoning was that the location had not been visited in recent years by internal auditing, had a history of "creative" accounting related to other transactions, and perhaps was in need of a control-awareness wake-up call.

Using the automated financial system query capabilities, the p-card transactions for the previous year were downloaded, and approximately ioo transactions were selected for document verification. Among those transactions were several suspected instances of pyramiding and unusual descriptions of items purchased.

The audit director scheduled a visit to the remote unit for Tuesday morning. The unit was notified in advance and asked to schedule approximately four hours for documentation verification. Upon arrival, the audit director presented the accounting clerk with a list of transactions to be reviewed and asked the clerk to pull the appropriate documentation. The first receipt document pulled was from a well-known discount store and listed, along with the items that would be used by the university, several children's DVDs and video games. The audit director also noticed several items that were crossed out, with a different description handwritten on the receipt. When queried about the appropriateness of the purchases, the accounting clerk responded that the purchaser had told her the chain's receipt didn't always actually describe the item purchased, and what appeared to be unauthorized purchases were actually different items that were authorized.

The audit director, recognizing that the discount chain's financial success "lived and died" by the accuracy of its inventory control, suspected something was wrong. The director continued reviewing the remaining receipts, identifying an additional 12 questionable purchases, which totaled more than $1,200. he contacted the local chain store manager and verified that "if the receipt says video game, it is a video game," and that the manager could specifically identify each game. After visiting with the manager and identifying all the questionable items, the internal auditor contacted the university police department, as was standard practice, to coordinate a criminal investigation of what was now a suspected p-card fraud.

The auditor identified and downloaded all p-card purchases made by the individual since he had received his card three years earlier and identified multiple suspected unauthorized purchases. The following week, the internal auditor, along with an experienced investigator from the university police department, returned to the unit to review documentation of these transactions and to interview individuals involved. While the auditor reviewed and documented scores of unauthorized purchases, the investigator interviewed staff, and through the senior administrator responsible for the unit, scheduled an interview with the suspect for the following day.

When the accounting clerk was asked whether she had wondered about the appropriateness of the purchases, she became very emotional, commenting that she knew they were wrong, but, "it's a small town and I need my job." After questioning several of the earliest transactions, she had quit doing so. Apparently, management pressured her to ignore the discrepancies because the suspect reported to the dean, and "we don't question what the dean was believed to know about."

The audit director, investigator, and senior administrator arrived for the interview with the suspect the following day armed with the internal auditor's documented evidence of suspected unauthorized transactions dating back three years, just one week after the p-card was issued to the suspected individual. Early in the interview, the suspect admitted purchasing unauthorized items for personal use, but also indicated that many of the purchases were for the university but were being "stored" by him at no cost because the school had limited storage space.

Using a search warrant obtained by the university police department, the audit director and university police removed nearly four van-loads of suspected unauthorized purchases from the suspect's home and personal vehicle. he was terminated immediately.

The total estimated loss from the fraud was more than $60,000, but only $32,000 was considered provable. Many other purchases, though apparently excessive and clearly unnecessary, were not traceable because they could not be individually identified. The suspect was arrested, and the university is currently pursuing the case through the courts.

LESSONS LEARNED

* Routine audits, although not glamorous, may provide opportunities for internal auditors to identify material control weaknesses in routine processing systems that can have wide ranging impact. The p-card process was designed as a pilot program of 30 cards and 15 users and was never truly updated to reflect the growth in the process. As a result, controls that worked for a small program were inadequate for a full-scale program.

* The p-card process should have an outlet, by hotline or anonymous e-mail, to allow individuals involved in transaction processing and oversight to report suspected abuse without fear of retribution. Economic realities often shape actions, and even the most honest people will overlook or ignore fraud if they suspect their job or livelihood will be in jeopardy if they report the suspected abuse. When the tone from the top does not encourage and support ethical actions, fraud can grow rapidly.

* Budget pressures may so impact established internal controls that the control is eliminated, resulting in significantly increased risk of fraud. In the search for efficiency, the first activity to be cut is often the control activity, because practicing good internal controls takes time and doesn't normally contribute to processing efficiency in a budget-conscious environment. This can be a costly decision when control processes become overwhelmed by transaction activity.

* Financial system capabilities must be used to allow detective internal controls to effectively identify and evaluate high-risk transactions. Having one clerk assigned to review all p-card transactions - if the clerk does nothing other than review transactions eight hours a day, five days a week - results in just over one minute per transaction for review. Analysis of buying trends and usage patterns through data extraction and analysis, or periodic system queries, should be implemented to identify potentially fraudulent transactions.

* Individuals responsible for p-card use and monitoring must be continually trained and made aware of fraud risk in card use. Annual refresher courses, including fraud awareness, for all individuals involved in p-card processes should be required. No infraction of p-card rules should be considered minor, and management must be made aware of even seemingly accidental infractions.

* Real consequences for misuse of p-cards need to be formalized and enforced. The tone at the top must clearly convey that fraudulent use of p-cards will be prosecuted. A p-card program without "teeth" to address misuse is a "fraud waiting to happen." Even the best run and most well-controlled p-card program will experience fraud.

* P-card fraud may be indicative of fraud in other areas of purchasing.

P-cards are just one purchasing method. A purchasing card fraud investigation should include review of other purchasing methods available to suspected fraudsters. In this fraud, the suspect was also making unauthorized purchases, totaling many thousands of dollars, through direct-billed purchases and standing (framework) orders, as well as using other individuals' p-cards to which he had access.

Read More....

Practice management tips

Practice management tips from the '03 AAA meeting
Anonymous. Accounting Office Management & Administration Report. New York: Oct 2003. Vol. 03, Iss. 10; pg. 1

Abstract (Summary)
Sessions at the recent Association for Accounting Administration (AAA) national symposium in Montreal focused on current practice management issues of importance to firm administrators and managing partners. For firms that are considering going paperless, an intranet will be key to the process. About one-third of attendees at the intranet session reported that their firms have begun to perform paperless audits. About the same number are using .pdf tax forms and doing as much e-filing as possible. The partner succession issue is critical, since about a decade's worth of younger talent is missing at many firms. One danger in succession planning concerns buyouts. Many firms still follow the traditional approach which involves a percentage of past earnings times years of business. Firms should expect to see a continuing trend of acquisitions by $4-million to $20-million firms of $1-million to $1.5- million firms with two partners who are tired, find it hard to compete, and no longer enjoy their work.

Two sessions at the recent Association for Accounting Administration (AAA) national symposium in Montreal focused on current practice management issues of importance to firm administrators and managing partners.

The first was one of the small-group breakout discussions for which AAA's conferences are well known. AOMAR attended the session for firms with $2 million to $4 million in fees, but the observations we collected apply to any small or midsize firm.

A second session involved audience questions during a breakfast seminar, which were fielded by industry consultant Allan Koltin (www.pdi-global.com), who was able to shed light on a number of partner-specific concerns.

Highlights from the small-group breakout discussion:

* The importance of intranets. Firms are now learning how to use these effectively, those that are just building their intranets as well as those that are expanding them. And, like many technology areas, the set-up and cultural buy-in will take far more time than getting the technology operational. The tools have become quite simple, especially for small firms, which generally use Microsoft Front Page for their intranet software. A benefit to Front Page is its interface with the Microsoft Office programs.

Your firm can use a single in-office computer to operate the intranet and act as the Web server; in fact, small firms probably won't need to devote a separate computer to this function.

For help with intranets: One firm administrator who consults with CPA firms in establishing intranets is Jim Fahey, firm administrator for Brott Mardis & Co. (Akron, Ohio; jim@brottmardis.com). Another resource is AAA's guide to intranets, which is free to members.

* Going "paperless." For firms that are considering going paperless, an intranet will be key to the process. About one-third of attendees at this session reported that their firms have begun to perform paperless audits. About the same number are using .pdf tax forms and doing as much e-filing as possible.

Attendees advise firms that would like to make this change to start with just a few clients to learn how to do it, and then expand the program. And you needn't invest in an expensive program: You can work with Microsoft Internet Explorer to set up your own files. You can also get software from scanner vendors, although you may find that you have little or no need for high-end scanners. More important than the hardware is the interface.

Also key: Implementation strategy and firm culture. Paperless firms need someone to "own" or take responsibility for the project, to see that it proceeds at an acceptable pace, deadlines are met, and that the new file structure is correct.

* Partner accountability. Firm administrators are always concerned about this issue and it is becoming increasingly important among firm owners as well.

Administrators can do only so much to track operations-partners must accept responsibility if things are to get done, agreed several participants in the session. "This is a cultural issue," noted one firm administrator. You need consensus, a strong managing partner, and a written performance plan. Expect any cultural changes to take "more time than you'd think."

* Budgets for staff appreciation/incentive programs. One firm administrator observed how important it is in a merging firm that has separate locations to use one system to encourage a single culture. Most attendees said their firms had incentive programs for getting new clients, hitting performance goals, and recruitment. But they cautioned that bonuses don't always work as incentives, especially if firm members expect them. If your firm uses bonuses, be clear about their purpose.

In addition to monetary rewards, consider recognizing people's achievements at brief staff meetings at which you can also share information about engagements and other firm data, and morale-boosting programs (contests and trivia games were mentioned as examples).

* Sharing financial information with staff. The firm administrators in the session supported an open-books policy: Staff like to know where the firm stands, and who the achievers are. They expect to be informed about what's going on-it makes them feel part of the team and breeds loyalty.

Partner issues. The breakfast session led by Allan Koltin focused on more partner-related issues, which are no less important to practice management. Key topics:

* Partner succession. This issue is critical, since about a decade's worth of "younger" talent is missing at many firms, Koltin noted. "Now we are beginning to pay the price." The issue has many facets besides finding and grooming talented CPAs to become partners.

"A good succession plan begins the day the account comes into the firm," he asserted. The work needs to become the work of the firm over time, not just the work of a particular partner.

One danger in succession planning concerns buyouts. Many firms still follow the traditional approach which involves a percentage of past earnings times years of business. Koltin urges firms to consider instead the age of the retiring partner's clients-old clients will disappear from the firm long before the payout of the retired partner is complete. He believes that tying the payout to the longevity of the client makes sense financially. However, it can encourage partners to cling to their clients instead of sharing them with the firm-the opposite of what is best for the firm.

The real solution, according to Koltin, is funded retirement, but this is a goal that continues to elude many firms. Until they can accomplish this, a capped payment tied to a percentage of retirement fees and the bottom line is probably the best approach.

* Corporate vs. partnership business models. The profession is moving for now to the corporate model. Koltin says the best managing partners run the firm like a business and treat partners as business partners.

Firms that want to embrace the corporate model will have to do away with one partner having one vote, and requiring a 75% majority to make a change. They'll also need to consider having several levels of partners, including equity, non-equity, and director levels.

* Length of term of service for managing partners. Because managing partners rarely hold the position throughout their careers, firms need to consider how to structure the job. Will the managing partner give up some of his or her book of business to perform the administrative duties? If so, the firm should probably help the person rebuild that book of business after completing the term of service. Moreover, it's important for managing partners to hand over the reins fully to their successors.

Consider having a non-CPA "managing principal" run the firm, Koltin suggests. This can work well for the firm, as long as the partners take what this person says seriously. No matter who runs the firm day to day, partners must not become isolated from decisions made about management and client service issues.

* Valuation of mergers and acquisitions. What are CPA firm practices being sold for now? The one-times-gross-fees traditional measure is still around, Koltin noted. Expect to see a continuing trend of acquisitions by $4-million to $20-million firms of $1-million to $1.5- million firms with two partners who are tired, find it hard to compete, and no longer enjoy their work.

* Value and high billing rates. The most profitable firms set high billing rates for their partners-and they get paid. Koltin proposed a multiplier of utilization times realization. Partners need to focus on what they do to deliver value to set their rates, he said.

* Firm association membership. Today, firms need depth and resources and can get them in the strategic "partners" of a firm association. Also, as an association member, you can learn from others about new areas. In fact, not joining an association and using as much as possible from its offerings causes you to under-serve your clients, Koltin claimed. It also puts you at a disadvantage among larger CPA firms, which are marketing ever more services and core business functions to clients now.

Read More....

Automated audits

Automated audits
Tays-Dunphy, Karla. CA Magazine. Toronto: Jun/Jul 1996. Vol. 129, Iss. 5; pg. 36, 3 pgs

Abstract (Summary)
Data transfer is simpler now than it was even a few years ago, and graphical user interfaces have made today's software programs easier to learn and use. Generally, firms first use audit software to automate current tasks, such as the selection of samples from general ledger transactions, accounts receivable outstanding items, inventory items, capital asset additions and payroll. Audit software reduces the time required to select a statistical or systematic sample. Audit software can also be used to help assess valuation and obsolescence. In the receivables area, audit software is used to re-age the accounts receivable outstanding items and compare the results to the client's aging. Audit software is useful not only for large clients of large public practices, but for smaller practices and internal auditors.

IF YOU'VE BEEN DISILLUSIONED WITH AUDIT software in the past, either because data transfer was too difficult or your staff spent hours wrestling with the program, it's time to reconsider. Data transfer is simpler now than it was even a few years ago, and graphical user interfaces have made today's software programs easier to learn and use. More than ever, audit software is a tool that can make your audits more efficient and effective.

For one of our clients (a credit union), we normally spend about two weeks selecting deposit and loan confirmation samples, footing the subledgers and preparing confirmation letters. This year, however, one of our CAs, who had very limited audit software experience, completed it all in one day with audit software -- including transferring the client data to our portable computer.

Doane Raymond decided to use audit software several years ago for a number of reasons: to increase efficiency and productivity; to gain time by automating manual tasks; to perform analysis (such as extensive testing) that would be difficult to do manually; to audit systems for which a traditional paper audit trail was inadequate; to meet the expectations of clients who had invested heavily in technology and wanted their auditors to use it; to provide general audit staff with the most productive tools; and to offer value-added services, such as trends analysis.

Since then, both IDEA and ACL, leading suppliers of microcomputerbased audit software, have introduced Windows-based versions that are easier to learn and use than the former DOSbased programs. In addition, many of our clients now regularly transfer data to their microcomputers from networks and mainframe systems, so data transfer is no longer a problem.

Generally, firms first use audit software to automate current tasks, such as the selection of samples from general ledger transactions, accounts receivable outstanding items, inventory items, capital asset additions and payroll. Audit software reduces the time required to select a statistical or systematic sample - a measurable benefit.

You don't realize how powerful the software really is, however, until you go beyond sampling. In the inventory area, for instance, we use audit software to refoot the inventory file, reperform the extension of quantity times cost, and compare the result to the client's calculation. Previously, a few samples would have been tested manually. Now, with the computer, and in significantly less time, 100% can be confirmed. Audit software can also be used to help assess valuation and obsolescence. Common procedures include extracting all inventory items where cost is more than net realizable value, extracting items that have not been sold in the last 12 months, aging the inventory based on the last sales date, and extracting items with negative costs or quantities. All these procedures would be very time-consuming or impractical to perform manually, especially for large inventory files. For clients whose accounting systems are unable to perform these analyses, we use the audit software to generate reports to help value their inventory. We also use audit software to match inventory test counts to the physical inventory file and then to perpetual inventory. At the same time, we can also check for duplicate inventory tickets.

In the receivables area, audit software is used to re-age the accounts receivable outstanding items and compare the results to the client's aging. We can re-age the entire accounts receivable file, rather than just a few samples. In addition, the software is generally flexible, so that aging periods other than those on the client's standard reports can be used. In instances where a significant number of accounts receivable are selected for confirmation, audit software can be used to select the sample and export the results to a mail-merge file, saving support staff the need to rekey the information.

There are many possible uses for audit software, depending on the type of client. In the case of a charitable organization, for instance, we use audit software to check the continuity of donation receipts and search for duplicate receipt numbers, work orders and bills of lading. For one of our municipality clients, we use such software to generate payroll exception reports, which can include unusually large pays, overtime payments or the largest 20 pays during the year. For financial institutions, we use software to identify loans with unusual interest rates or payment terms, or recompute accrued interest on all outstanding loans -- tasks that used to be restricted to manual test-checks.

In many industries, audit software can be used to extract unusual items (such as repair and maintenance expenses exceeding a certain amount) for further follow-up. The software can also search for all missing sales invoices, based on beginning and ending invoice numbers. It can be used to extract any large debit entries in revenue accounts or to identify related-party transactions; and it can also be used to compare clients' actual balances with budgeted balances, extracting accounts with a large variance for further analysis.

Audit software can be beneficial in non-audit engagements as well. We have used it for analytical procedures, to identify and extract related-party transactions, and to generate reports for clients on inventory obsolescence or other matters. Audit software is also used frequently to import the client's trial balance and then export it into a format supported by our working paper software.

The 1994 CICA Audit Technique Study, Application of Computer Assisted Audit Techniques Using Microcomputers, is a good reference for implementing audit software. (See Appendix A of the study for further examples of audit procedures that can be performed with this software. )

Audit software is useful not only for large clients of large public practices, but for smaller practices and internal auditors. One internal auditor was able to reduce his travel to the branch offices by obtaining branch data in advance and using audit software to look for unusual items and select samples. He then sent this information back to the branch so the supporting documents would be available when he arrived.

Audit software is not just for computer audit specialists, either. At Doane Raymond, all audit staff are trained to use IDEA, the software selected by the firm. Staff learn about the key functions of the software, how to obtain client data, and how to document their work. Such training is necessary to ensure staff learn the most proper and efficient use of the software.

There is a learning curve, especially on the first two or three engagements. Although we are able to obtain net savings in the first year on many of our audits, savings are much more likely in the second and subsequent years. That is because in the first year, it is necessary to spend time rethinking our audit approach. Because of this initial investment, it is imperative that partners be committed to this change. Staff will not use a tool, even one that ultimately makes them more efficient, if they think they'll be blamed for spending too much time in the current year. In such a case, it's much safer for them to do the audit the old way.

With appropriate planning and supervision, however, it's possible to minimize the first-year investment. After providing adequate staff training, you should choose clients who can easily export data from their accounting software (such as ACCPAC Plus). Also, consider selecting smaller clients first, to ensure the task is manageable. And try to target clients who are using the same software or are in the same industry, so you can apply your knowledge from one client to the next.

Consider adding new audit applications each year rather than all at once. If inventory is a high-risk area, for example, start by implementing procedures to assist in checking obsolescence and valuation. Then, the following year, expand procedures to other areas such as receivables or payroll.

It's important to investigate data transfer implications as early as possible. Although the ability to transfer data from a client's system has been a significant barrier to the use of audit software in the past, that barrier has been minimized in recent years. Many of our clients now connect microcomputers to their networks or mainframe systems and download data regularly, in order to manipulate them with spreadsheet software such as Excel and Lotus. The summer season is an ideal time to meet with clients and plan the transfer of their data. (Additional information on downloading and understanding data is provided in appendixes D and F of the study mentioned earlier.)

There are several ways to transfer data between microcomputers: Copy the data to a diskette on the client's microcomputer and then onto the hard drive of your own. For a data file too large to fit on one diskette, use a compression program such as PKZip.

If the data file is larger than 2 MB, you can connect two microcomputers with a parallel or serial cable and then transfer the file. DOS 6 includes a program called Interlnk for such transfers. Other popular programs are LapLink, FileShuttle and Brooklyn Bridge. Or, use Windows 95's Direct Computer Connect to connect two computers. You can also use Windows or DOS backup and restore commands, or a portable tape backup unit.

Small business clients often use accounting software programs on their microcomputers and several of these systems have record definitions included in the audit software. You need to find out the name of the appropriate data file and copy it to your microcomputer.

If the audit software does not contain a record definition for the client's accounting software, determine what export capabilities are available in the accounting software. Most mainstream accounting software can export data in formats such as dBASE, ASCII text or Lotus 1-2-3. If you are using IDEA, the best format is dBASE, since it automatically includes the record definition information in the file.

If the client's software does not have an export capability, it might be capable of printing the desired information in a report format. You may be able to import the report file directly into the audit software or by using a file translation utility such as AutoImport, Monarch or DataImport.

If these methods are not successful, ask the software vendor if he or she can provide the layout of the data files so you can generate a record definition. The vendor may also be willing to develop a program to convert the client's data to a format readable by IDEA.

There are definite benefits to be gained from using audit software in your practice. Not only will it lead to greater efficiency and productivity, but it will enhance your firm's image. Moreover, the software is easier to use than it used to be. If you have ignored audit software for the past few years, it's time to take another look.

Read More....

The Importance of Data Audits

Risky Business: The Importance of Data Audits for Content Security
Sue Marquette Poremba. EContent. Wilton: Oct 2008. Vol. 31, Iss. 8; pg. 32, 5 pgs

Abstract (Summary)
Database security is a serious issue that affects every business or organization, and most IT security personnel state one of the most effective means of database security is good database auditing. There are four key categories to database auditing: server security, database connections, table access control, and restricting database access. The federal government and some industries have begun to realize the severity of database breaches and have begun to institute data privacy regulations. Companies are expected to follow these regulations and are regularly audited to make sure they are properly securing their databases. Despite the regulations and governance councils, companies are slow to respond to the need for better database auditing. Not every data breach is caused by criminal intent, but for every accidental breach, there is a disgruntled employee who is looking for revenge or a crime ring eager to make a few thousand dollars selling the information on the black market.

In early July, a Texas man was arrested for allegedly filing more than 160 false tax returns using the Social Security numbers of University of California-Irvine graduate students. The Social Security numbers were reportedly stolen while the man worked for the Student Resources Department of United HealthCare Services, Inc.

In June, a California man was sentenced to nearly 5 years in prison after he was found guilty of hacking into the protected computer system of his former employer, Council of Community Clinics, multiple times, disabling the backup system and deleting files. (He was angry after receiving a negative performance review.) His actions destroyed personal medical records of patients, putting their lives at risk.

This spring, online mortgage loan marketplace Lending Tree, LLC sent a letter to its customers to inform them of a possible data breach caused by former employees providing passwords and access to personal information to other mortgage lenders.

Even members of the Supreme Court aren't safe from identity theft: Justice Stephen Breyer's personal information was made public when someone in an investment firm used peer-to-peer networking and inadvertently provided a gateway to a database. The breach wasn't discovered for 6 months.

Troubling as they are, these stories are just a few of what seems like a never-ending list of companies experiencing data breaches, which can lead to the theft of information ranging from a customer's Social Security number to a corporation's secret designs for a new product.

A 2007 study of 494 IT security personnel conducted by the Computer Security Institute found that, while the numbers are slowly decreasing, 46% of the respondents said their company experienced a security incident in the past year. Fraud caused, in part, by the loss of customer and proprietary data is the number one reason for financial loss within companies (overtaking computer viruses for the first time).

Database security is a serious issue that affects every business or organization, and most IT security personnel state one of the most effective means of database security is good database auditing. Too often, however, data is left vulnerable, partly because companies are more concerned with protecting the network from the outside and invest in technologies such as firewalls to prevent attacks. What gets overlooked is that information from a database is more likely to be hacked by a current or former employee than from a virus injection.

"Essentially, we are guarding the front door, while the bad guys are walking in the back door," says Rick Kam of ID Experts.

THE DATA TRAIL

In order to ascertain risk, companies must track data usage, which is commonly referred to as database auditing. There are four key categories to database auditing: server security, database connections, table access control, and restricting database access.

Server security limits user access to the database server. Database connection involves knowing who has access to a database and how and when it is accessed, while table access control dictates what the user can do within the database itself. Restricting database access refers to protecting the database from outside sources, such as malware that can manipulate code on an internethoused database.

Perhaps the biggest breakdown in database auditing is the lack of governance over user accounts. Too often, when an employee leaves a company or even transfers from one department to another, the person's account isn't closed or changed.

In fact, user access is the number one IT security concern among healthcare workers, according to a study taken at the Healthcare Information and Management Systems Society (HIMSS) 2008 Annual Conference and Exhibition by Courion Corp. Of the 136 people questioned, 64% cited access as their main security issues, while 60% were concerned about passwords being shared between personnel and 52% admitted that orphaned accounts were not properly disabled.

While providing doctors, nurses, and other caretakers easy access to the data they need improves patient care, Kurt Johnson, vice president of corporate development at Courion, adds, "It also opens a whole new concern in the organization to exactly who has access to this information."

There are three phases to a database audit, according to Robert Grapes, chief technologist with Cloakware's data center. "There's the upfront work, the tactical things to be done day-by-day, and the post-forensic or the real audit of what happened on the system," he explains.

The upfront phase involves password issues and who has access to accounts. "While a lot has been done to address password management from an engineering standpoint, we're finding that very little has been done to correct password issues for human administrators who need access to the database," Grapes continues.

So upfront, the idea is to look at who exactly has access to a database and to regularly do audits to account for everyone who has access to the database.

Automated software functions control the tactical daily audits. This can include closing a person's access to the network or changing the fields an employee should have access to, depending on the job duties. The software also dictates when passwords should be changed.

After applications have been run and the database logs have been recorded for the day, the audit occurs. Software, such as Grapes' Cloakware, can be used to record every time the data had been manipulated or a password changed. This information should then be verified on a regular basis to make sure the people working with the database had the authorization to do so.

Unfortunately, financial issues often drive database auditing best practices. It costs money to manage thousands of passwords, Grapes says, yet password management is the best way to protect data.

"Automating the process can improve the security profile," he says. Software, for example, can produce new passwords but not release the new code until the user is ready to log in.

However, if the funds don't exist for automated auditing software, there is a relatively low-tech way to go to protect database information: Make sure that multiple people have access to the database. Too often, companies will assign control to one person, and there are no checks and balances in place.

"In San Francisco recently, a guy was able to lock out an entire system," Grapes says, "and that scenario is not uncommon. One person has all the privileges, like the fox protecting the hen house, and in this case, the fox is able to set up new accounts. Financial institutions are worried about this."

PRIVACY PLEASE

The federal government and some industries have begun to realize the severity of database breaches and have begun to institute data privacy regulations. They include best practice requirements and industry guidelines regarding usage and access to customer data. Financial institutions are currently regulated by the Gramm-Leach-Bliley Act (GLBA), which requires the protection of nonpublic personal data while in storage and implements a variety of access and security controls. Payment Card Industry Data Security Standard (PCI DSS) requires that merchants who accept credit cards follow certain standards of security protection for consumers. The Sarbanes-Oxley Act of 2002 is a congressional response to the Enron and similar accounting scandals and establishes new and enhanced standards for publicly held companies. Perhaps the bestknown privacy effort is the Health Insurance Portability and Accountability Act (HIPAA), which is meant to further protect patient information as more medical records are shared via electronic means.

In addition, the IBM Data Governance Council was formed to create best practices around risk assessment and data governance. The IBM Data Governance Council is an industry group comprising about 50 members representing financial companies such as American Express, Deutsche Bank, Citibank, MasterCard, and others.

Companies are expected to follow these regulations and are regularly audited to make sure they are properly securing their databases.

"IT security is a strategic part of the company, but business people haven't recognized that yet," explains Steve Adler, chairman of the IBM Data Governance Council. "We think that the current methods used for calculating risk need to be automated and a normal part of business."

He says that every individual in an organization needs to be aware of the security risks, which is not usually the case. "There are many people who work in the IT department who are unaware of the security strategy," he says. "There needs to be more operational awareness." Despite the regulations and governance councils, companies are slow to respond to the need for better database auditing. For example, the PCI DSS had a June 30th deadline requiring that web application security testing be upgraded from a best practice to mandatory compliance, yet IT security firms helping with this transition say that only a handful of firms were prepared to meet the requirement, despite being notified of this requirement in 2006.

Rick Kam blames the inefficient database auditing on the natural disconnect between what the executive teams think they are doing for security and what's really happening in the IT and privacy offices.

"There's a tendency to compartmentalize functions," Kam says, "and this has provided easy opportunities to steal information."

THINK LIKE A THIEF

One thing Kam recommends is for organizations to think like a bad guy when protecting data. "We think very differently from crooks," he says. "We think, 'how would a rational person break into the system,' and we invest heavily to protect where we think the vulnerabilities lie. The problem is, the crooks don't view it the same way and will find other ways to access the information they want."

What the company can do instead, Kam says, is bring in a person who can look at database security from a different perspective, such as an auditor hired to investigate fraud risks.

Good training is another vital step toward database auditing. Too often, Kam explains, a person may detect potential fraud early on, such as improper access to certain information, but then not know what steps to take to stop the breach.

Kam has three tips for putting a database-auditing plan into action:

1. Do an information security assessment.

2. Have an up-to-date instant response plan. "Most companies have information security plans and disaster recovery plans, but when they have to respond to lost or stolen information, they scramble like crazy," Kam says.

3. Have an insurance policy to cover the risk. "You have insurance policies to cover employee accidents or other financial loss," he adds. And with nearly half of all companies experiencing a database violation or theft of information, it makes sense to be prepared to cover the costs involved.

Of course, contrary to popular belief, data theft has been around as long as there has been data to steal, and criminals still use low-tech methods, such as stealing mail with personal checks inside or recording credit card information during a restaurant transaction. Computers and the internet have simply provided the bad guys with access to more information stored in one place.

SEPARATE, NOT EQUAL

For that reason, Yuval Ben-Itzhak, CTO of Finjan, Inc., says it is important to segment the data. For a simple database, multiple users may have access to a database, but for each application, each person will use a specific credential to only access the information that is needed.

"The majority of data breaches happen because most applications provide access to all the information in the database," he says. "But once you segment the data, even if it is compromised, the hacker will have limited access to the information."

Encryption is another important and often overlooked tool, he says. Good encryption tools will make information from a violated database useless to a cyber criminal.

Ben-Itzhak suggests companies be creative when it comes to the way they create their databases too. "There's no reason to have all customer data or medical records in one place that's easy to access," he says. Providing different avenues to access the data will better protect it.

He also disagrees with those who say that the costs of better database auditing prohibit companies from making changes. Instead, he says, these practices should be included as the database is being built, that companies need to plan for better security from the get-go. "You don't need to buy other products," he says. "It's a design issue. The developers aren't educated in how to provide security; their job is to provide functionality. And in ignoring security in the design, it becomes a playground for hackers. "

He also recommends frequently checking the information that is in the database. If a customer's information hasn't changed within a specified period of time, it should be considered outdated and removed. "You can't focus on just one element of database auditing," he adds, "or you will end up with a weak link in your security efforts."

COMMUNICATING THE RISK

Customers understand the risks involved when it comes to database breaches, and reports of a breach affect their relationship with the company. According to a study the Ponemon Institute and issued by ID Experts, nearly one-third of consumers notified of a security breach terminate their relationship with the company.

"We found that most people do care about security breach notifications and are concerned," says Larry Ponemon, founder of the Ponemon Institute. "And their concerns are identity theft, financial losses, and the inconveniences that the breaches cause."

Not every data breach is caused by criminal intent, but for every accidental breach, there is a disgruntled employee who is looking for revenge or a crime ring eager to make a few thousand dollars selling the information on the black market. Smart companies realize their reputations and their financial growth depend on ongoing database security.

Read More....

Auditing desktop applications

Auditing desktop applications ...even if distributed via SOFTGRID
Derek Melber. Internal Auditing. Boston: May/Jun 2007. Vol. 22, Iss. 3; pg. 42, 2 pgs

Abstract (Summary)
Almost every company is up against the wall when it comes to controlling desktop applications -- licensing, auditing, and maintenance. With new technologies like SoftGrid from Microsoft, all of these procedures are made easier, including the auditing of these applications. SoftGrid is designed to run applications virtually, but with that virtualization, delivery, and management comes the ability to track nearly anything regarding the application that is desired. Application auditing is not the most fun task in the world, that is for sure. However, with SoftGrid, the solutions for auditing and controlling software are more plentiful and useful. SoftGrid can ensure that license compliance is met and will trigger a notification if the company is out of compliance.

Almost every company is up against the wall when it comes to controlling desktop applications. The control that I am talking about is the licensing, auditing, and maintenance of these applications. Even though a company needs these applications to generate revenue, it seems like there should be easier methods to control the applications, from deployment through maintenance. With new technologies like SoftGrid from Microsoft, all of these procedures are made easier, including the auditing of these applications. In an ideal world, the audit mechanism should help or cure licensing compliancy, restrict illegal copying of the applications, and provide robust reporting and analysis of each application. SoftGrid provides a mechanism to solve all of these issues and needs.

The state of the union

Most companies today are scrambling every day to ensure that they are in compliance with software licensing and that the software the company owns is not being illegally copied and taken out of the company. Sure, vendors are taking extra precautions to help restrict these actions, but each step the vendor takes to restrict the application from piracy means one more step in the direction of making the application too complex to operate or maintain.

If your company runs a small to medium Windows network today, you are fully aware of the pain that is required to audit the applications that are running on the desktops in the organization. With such a dynamic array of desktop images and installations, every desktop must be touched in some way. The touch might be manual if a very small shop, or with some reporting mechanism such as SMS or Tivoli. Regardless, these tools provide only an overview of the applications that are installed, leaving a lot of analysis to the administrator or auditor.

May I take your order please?

When it comes to applications, licenses, auditing, and the like, there are plenty of ideal situations that we would like to see. However, instead of thinking about the future and what could be if we had a magic wand, what are some auditing and reporting attributes that seem realistic?

First, there needs to be some mechanism in place to report back which applications are installed and have that compared to the licenses that are available today. The result of this should be some report, e-mail, flag, message box, or the like that pinpoints which applications are out of license compliancy.

Second, the applications need to be protected in some fashion so that standard users cannot just copy them to a USB or external hard drive and take them home. This has gotten better, but there are still some applications, many of them very expensive, that allow this behavior.

Third, it would be nice to know which applications are actually being used. If a user has not used an application in two years, chances are good that the application will not be used for another two years. In these cases, where an application is not being utilized but a license is being paid for yearly, it would be nice to recoup that cost of the application by uninstalling it and stopping payment on that license.

Can you be successful today?

If you dissect the three desires above and apply the concepts to your environment today, does your company measure up and provide these capabilities? Even if you say "yes" or "sort of," I encourage you to read on. There are technologies that will make these tasks easier.

With regard to your company's capability to tackle the first issue above, how well do you know which applications have been installed? Not just "we pushed them out through Group Policy" and hope they are installed, but are actually installed by the end user. Then, how well do you compare the install base to the licensing compliance? If a company does well at any point, this is the point that shines most of the time.

With regard to the second point, pirating applications from work to the rest of the world, how do you measure up? This is extremely difficult to manage and monitor, as some applications can just be copied and moved from point to point. If there is a mechanism in place at your company for this, most likely you have already purchased a high-end application to control such acts.

Finally, do you have any metrics on how often the installed applications are utilized today? If so, I know for a fact that you have spent some "bank" to get this capability. This data is not easy to obtain and is even harder to analyze.

SoftGrid to the rescue!

Of course, with a buildup like this, it is no surprise that SoftGrid can do all of these tasks with ease. SoftGrid is designed to run applications virtually, but with that virtualization, delivery, and management comes the ability to track nearly anything regarding the application that is desired.

First, each application is controlled centrally by the SoftGrid server, so all applications are monitored as they are downloaded and installed. The SoftGrid server can monitor the state of the installed application, indicating the percentage of the application that has been downloaded so far. This is key, as some users might begin the download, start to use the application, then have to leave the network before the entire package is complete. Since every application is controlled through the SoftGrid server, it is easy to check the installed applications to the available licenses. If the licenses are surpassed by the installs, the system can be configured to trigger a notification to the administrators that they are out of compliance.

Secondly, each packaged application on the SoftGrid server has an Access Control List (ACL) associated with it. This controls the use of the application, not only denying anyone from using the application if they are not granted access, but certainly denying them from copying the application for use off of the network.

Finally, SoftGrid is constantly gathering information about the use of the application. Reports can be gathered and generated based on each application, each user and the applications being used, and server usage of the applications. If it is specific application metrics that are desired, the SoftGrid reporting can track start and end times, as well as session duration per application and user.

Conclusion

Application auditing is not the most fun task in the world, that is for sure. Part of the problem with application auditing is that there are no great solutions for the tasks that need to be performed. License compliancy is really just a portion of what needs to be evaluated, and it is not all that elaborate with solutions today. However, with SoftGrid, the solutions for auditing and controlling software are more plentiful and useful.

SoftGrid can ensure that license compliance is met and will trigger a notification if the company is out of compliance. Piracy of applications is no longer an issue, as SoftGrid can control who uses the applications, whether on the network or off. SoftGrid also reports on nearly any metric that is desired to control whether the application is being used or not. Unused applications can save a company thousands of dollars, as the license can be cancelled and the application can be uninstalled. With SoftGrid, the entire world of application installation, control, management, and auditing will be turned upside down.

Read More....

The route to compliance

The route to compliance
Arif Mohamed. Computer Weekly. Sutton: Apr 24, 2007. pg. 34, 2 pgs

Abstract (Summary)
"There is no other regulatory or industry compliance requirement that is quite this granular. PCI is unique, but the data you collect in a PCI compliance scan can be useful in meeting many other kinds of audit and assessment requirements - an ISO 27001 certification or a Sarbanes-Oxley audit, for instance," she said.

The security area gets more than its share of red tape. So how do you chart a course that meets regulations without you getting strangled? Arif Mohamed reports

Complying with government and industry regulations is a major concern for IT managers across the board. But few areas of IT get to see as much red tape as security. IT managers are now bound by law to store, backup, encrypt, secure and protect their confidential data, and demonstrate that they are doing this satisfactorily.

Many organisations in the public sector and the regulated industries, such as utilities and legal or financial services, have to demonstrate an information security policy that proves they have a range of steps and measures in place. If these policies are not adhered to, the regulators reserve the right to prosecute.

This happened in February this year, when the Financial Services Authority (FSA) fined Nationwide Building Society £980,000 for failing to have effective systems and controls to manage its information security risks.

The failings came to light following the theft of a laptop from a Nationwide employee's home last year. This urged the FSA to carry out an investigation, during which it found that the building society did not have adequate information security procedures and controls in place, potentially exposing its customers to an increased risk of financial crime.

Margaret Cole, director of enforcement at the FSA, said, "Firms' internal controls are fundamental in ensuring customers' details remain as secure as they can be, and as technology evolves firms must keep their systems and controls up-to-date to prevent lapses in security.

The FSA took swift enforcement action in this case to send a clear, strong message to all firms about the importance of information security."

Afterwards, Nationwide took several measures, including commissioning a comprehensive review of its information security procedures and controls, and increasing security around its accounts.

There are other regulators besides the FSA that require sensitive data to be secured, for example for the pharmaceutical and legal industries, and more recently the retail sector.

The latter has a new security requirement, the PCI Data Security Standard, to ensure that member organisations secure their online transactions and data.

It is based on an initiative by the Payment Card Industry (PCI), driven by MasterCard, Visa and others, to lock down customer data through ensuring that any company that handles credit card payments keeps a tight reign on security.

The PCI requirements look at the fundamentals of IT security, such as making sure that firewalls are only passing traffic on accepted and approved ports, that servers are only running the services that need to be live, or that databases are not configured with supplier defaults, said Diane Kelly, vice-president and service director at Burton Group.

"There is no other regulatory or industry compliance requirement that is quite this granular. PCI is unique, but the data you collect in a PCI compliance scan can be useful in meeting many other kinds of audit and assessment requirements - an ISO 27001 certification or a Sarbanes-Oxley audit, for instance," she said.

"You will be looking at many of the same things. After all, most compliance comes down to things like whether your firewall is correctly configured."

One international standard for security compliance that can be applied across industries is the International Standards Organisation's ISO 17799, known as ISO 27001 in Europe.

This is a formal process that helps an organisation demonstrate that it has a high level of IT security management. It covers 10 major areas, including business continuity planning, physical and environmental security, compliance, personnel security, asset control and security policy.

One organisation that is working towards ISO 27001 is international law firm Norton Rose, which believes that ISO security accreditation will differentiate its from its competitors.

ISO accreditation carries stringent tests for client data and employee security, said Malcolm Todd, head of systems delivery at Norton Rose. He added that the firm is using a range of software products from Attachmate division NetIQ to help achieve ISO security accreditation.

Todd explained that Norton Rose will go through a certification process when it is ready, then face regular audits every six months to a set framework. These checks could cover anything from e-mail tracking to risk analysis, and any staff member can be interviewed about the firm's security policy.

In addition, organisations must adhere to the UK Data Protection Act 1998 if they hold information on members of the public. The act contains eight principles of data protection, including that all data is accurate and, where necessary, kept up to date, that data be kept for no longer than necessary, that it is kept secure, and that it is transferred only to countries that offer adequate data protection.

Then there is the US Sarbanes-Oxley Act of 2002, which affects any UK company that is listed on the US stock exchange. The act requires strict internal controls and independent auditing of financial information to defend proactively against fraud. This carries potentially serious civil and criminal penalties for non-compliance.

As with many of the industry security regulations, software products are available that can help organisations to audit, test and document their security processes.

One supplier that sells a specific on-demand PCI compliance service is Qualys, with Qualysguard PCI. This is a subset of the supplier's Qualysguard on-demand offering that is used by BAA, Novartis and Travelodge to meet compliance requirements.

Another security compliance tool is available from Tier-3, whose Huntsman product carries out enterprisewide threat management and real-time compliance and operational risk management capabilities.

It works by detecting any noncompliant behaviour, establishing an audit trail, reconstructing any security breach event and carrying out forensic analysis. It also has the ability to enforce the security policy.

Other point systems are available from suppliers such as Computer Associates and IBM.

Andy Kellett, senior research analyst at Butler Group, said, "There is an ever growing raft of regulatory rules and hoops to jump through, depending on the business the organisation is in, and some of them cut across the business. For example, if you are in the financial services sector you have to properly comply with the FSA regulations and maybe Basal 2, and if you are a retailer, you may also be responsible for financial data," he said.

"So many security breaches take place, and reality tells us that the average organisation has so many different systems and infrastructures that it needs to protect, that nothing is ever going to be 100% secure."

Kellett said that the starting point for any compliance exercise is to carry out a full audit to understand what information the business holds, what its vulnerabilities are and what elements of the IT systems can be locked down. These include databases, information storage systems and business applications, which could put customers and the business itself at risk.

Following this it is essential to publish a security policy and inform everyone who works in the organisation about what is and is not allowed, said Kellett.

The organisation can automate much of the security activity. So, for example, if the user acts in an insecure way, they could receive an e-mail saying they have been doing something that is not in line with policy, or the system may automatically encrypt a file or lock down the user's file access.

"You tend to end up looking at products that do the monitoring, alerting and protecting of information," Kellett said. This could include managing and locking down the file access rights of individual users, ensuring that particular attachments cannot be sent from e-mails, or even using biometric login systems to secure workers.

At the higher end of the security scale, the organisation could use a military-grade system like Clearswift's Bastion, said Kellett. This can isolate an IT system so that it only interacts with a few other systems that are authorised to do so.

"Clearswift found that the military systems used by the Pentagon were very secure, and that some private firms, financial services and pharmaceutical companies which want to keep their patented medicines properly protected, might benefit from a system where communication could be locked down," said Kellett.

Read More....

A Continuous View of Accounts

A Continuous View of Accounts
David Coderre. The Internal Auditor. Altamonte Springs: Apr 2006. Vol. 63, Iss. 2; pg. 25, 4 pgs

Abstract (Summary)
In fiscal year 2004-2005, The Royal Canadian Mounted Police (RCMP) performed an audit to assess the appropriateness and effectiveness of the control framework in place to support accounts payable (AP) activities. The overall goal of the audit was to provide reasonable assurance that AP policies and procedures comply with central agency policies and regulations, the control framework effectively supports AP activities, and financial transactions are processed in a way that complies with applicable policies, procedures, and regulations. Continuous auditing supported several of the RCMP auditors' objectives, including identifying and assessing risks and control deficiencies in the AP process, examining trends related to performance and efficiency, and searching for anomalies and fraud. In this audit, continuous auditing contributed to improvements in the AP operation; reduced financial errors and potential for fraud, waste, and abuse; and provided a sustainable and cost-effective means to support compliance with policies and procedures and perform risk and control assessments.

Royal Canadian Mounted Police auditors ride to the rescue of a complex accounts payable function.

N FISCAL YEAR 2004-2005, THE ROYAL Canadian Mounted Police (RCMP) performed an audit to assess the appropriateness and effectiveness of the control framework in place to support accounts payable (AP) activities. As a result of regionalization, the law enforcement agency's AP function is performed primarily by seven AP groups and a network of satellite offices located in five regions across Canada. The function processes almost 500,000 payments for goods and services totaling approximately C $1.5 billion (US $1.31 billion) each year.

The overall goal of the audit was to provide reasonable assurance that AP policies and procedures comply with central agency policies and regulations, the control framework effectively supports AP activities, and financial transactions are processed in a way that complies with applicable policies, procedures, and regulations. Given the electronic nature of the data, the wide variety of transactions, and the large number of AP offices, the audit team planned to maximize its use of information technology to identify and assess risks, test key controls, and check for potential areas of fraud, waste, and abuse. These factors made the project a good candidate for using continuous auditing techniques.

Continuous auditing is a unifying structure that brings together risk and control assessment, audit planning, digital analysis, and other audit technologies and techniques. It supports macro-audit issues, such as using risk to prepare the annual audit plan, and micro-audit issues, such as developing the objectives and criteria for an individual audit. Continuous auditing not only measures transactions against a defined threshold, such as a maximum value, as they are being processed, it also compares those transactions to all transactions over time. Auditors also can use it to compare one set of transactions with another set, such as comparing transactions at one office with another office. These abilities allow auditors to test the consistency of a process by measuring the variability of each dimension.

IN SUPPORT OF AUDIT OBJECTIVES

Continuous auditing contributes to individual audits by supporting the identification and assessment of risk and the development of scope and objectives (see "Key Steps to Continuous Auditing" on page 26). Further, it can be used to determine which locations auditors will visit and to identify specific audit criteria.

During the planning phase of the RCMP's AP audit, auditors used data extracted from the financial and human resources systems to review the operations of regional AP offices before traveling to perform the on-site work. AP personnel in the RCMP's regional offices are responsible for processing a wide variety of transactions, including invoices, purchase card (p-card) expenses, interdepartmental settlements, journal vouchers, emergency salary advances, travel expenses, and relocation claims. In addition, they respond to inquiries from vendors and others within the RCMP, resolve payment issues and disputes, categorize expenses to the appropriate general ledger accounts, and keep the master file of suppliers up-to-date.

The quality of the AP process' design and how well the regional offices execute the process impacts two important areas: supplier relationships and cash management. Control design quality is also directly related to the cost of the AP function; appropriately designed controls will ensure that risks are mitigated at an acceptable and cost-effective level.

Continuous auditing supported several of the RCMP auditors' objectives, including identifying and assessing risks and control deficiencies in the AP process, examining trends related to performance and efficiency, and searching for anomalies and fraud.

RISK IDENTIFICATION

The RCMP's auditors included a variety of risk factors - culled from policy reviews, interviews, reviews of previous audit results, and Internet searches - in the initial risk assessment. The audit compared the performance attributes - cost, quality, and time-based performance measures - of each AP office. Labor cost for accounts payable was the primary cost-based measure. Quality-based measures, which assessed how well the organization's products or services met customer needs, included the average number of errors per invoice. Time-based measures, focusing on the efficiency of the AP process, included the average number of days to pay an invoice and late payment charges. Auditors extracted data from the RCMP's ERP system and imported it into audit software to calculate the elapsed days between the receipt and payment of the invoice and the total of late payment charges.

Using continuous auditing for each AP office, the auditors also determined dollar amounts for each type of transaction. The transaction-type analysis gave the audit team a better understanding of the operations of each office, including how many different types of transactions were being processed. This analysis supported the risk assessment, because operations tend to have greater complexity when more transaction types are processed. The audit also compared the number of correcting journal entries and manually produced checks per office, which indicated additional workload that contributed to the overall level of risk. Using the extracted ERP data, a cross tabulation showing the number and dollar value of each type of transaction for each regional AP office was produced.

Finally, the audit used data extracted from the human resources (HR) database to compare the organizational structure of each office, including reporting relationships, number and classification of staff, length of time in job, retention rates, and training received. The combination of the HR data with the transaction types and volumes helped to identify areas of risk, such as understaffing and lack of staff trained to handle complex transaction types.

Auditors considered the risks associated with the transaction types, volumes, and dollar amounts to determine which types of transactions would be included in the audit. They also used the overall risk assessment to select the locations for on-site audit work.

CONTROL ASSESSMENT

The flip side of risk is control. Control deficiencies can increase risk levels, and unmitigated risks are usually the result of control deficiencies. The audit team reviewed the financial software system to identify key control points in the AP module. Next, auditors used the Internet to research the control rules for that module and used audit software to develop analytical tests to ascertain whether or not the controls were working as designed. For example, audit software was used in one test to compare transaction types processed by each AP clerk to verify that ,separation of duties existed. Additional analyses verified that all invoices over C $5,000 referenced a purchase order, validated that only authorized users were creating or modifying vendor records, and determined whether the goods receipt amount equaled the invoice and contract amounts. Auditors created scripts that enabled tests to be run at any time.

PERFORMANCE TRENDS

Trending data identified performance and efficiency concerns. For example, the audit team used continuous auditing to compare the AP offices, looking at the number and job classification of employees involved in the process and the efficiency of operations. Audit software was used to calculate efficiency measures, including the number of invoices processed per user, number of days and average dollar cost to process a payment, percentage of invoices paid late, percentage paid early, percentage of recurring and electronic funds transfer (EFT) payments, percentage of manual checks, and percentage of invoices for less than C $500. Analyzing trends across years also helped to identify both problems and areas where improvements had been made.

ANOMALIES AND FRAUD

To assist the continuous auditing process, the audit team used brainstorming techniques to identify anomalies and areas of potential fraud. For example, the team theorized that an inadequate separation of duties would permit an AP clerk to create a vendor record, enter a purchase order, and process an invoice to make a payment to that vendor, which could pay a kickback to the clerk. Another concern was that satellite AP offices could process duplicate invoices.

For items identified in the brainstorming session, auditors developed specific automated tests to search for possible fraud, waste, and abuse. Auditors tested for duplicate payments and compared current-year payments to previous years to see if operations were improving. They looked for invoices processed against backdated purchase orders and split purchase orders intended to avoid financial limits. The audit also examined the number and dollar value of invoices going to suspense accounts, where funds are stored temporarily until a decision about their allocation is made.

Finally, auditors ran tests to determine if there were cases where:

* Vendors were created and only used by a single AP clerk.

* The entry user was the same as the user who approved payment.

* The payee was the entry or approving user.

* There were duplicates in the vendor table or vendors with names such as C.A.S.H., Mr., and Mrs.

* Vendors had no contact information, such as phone numbers or addresses.

Although auditors did not discover any instances of fraud, they did identify control weaknesses and instances of noncompliance with policies. In particular, weaknesses in the vendor table and poor controls over the entry of invoices resulted in more than C $100,000 in duplicate payments that were recovered by the auditors.

AUDIT RECOMMENDATIONS

The final use of continuous auditing was to follow up on audit recommendations to determine whether or not management had implemented them and whether they were having the desired effect. During the review, auditors identified data-driven indicators for each recommendation. For example, auditors found that most regional offices processed a large number of invoices of less then C $500. Many studies have shown that the use of p-cards can significantly reduce the costs of processing such payments. The auditors recommended promoting p-card usage for low-dollar purchases and training cardholders to use them appropriately. Six months after issuing their report, the auditors measured usage for transactions under $500 and found that the percentage of p-card payments for low-dollar transactions had increased, indicating that this recommendation was implemented effectively.

Additional tests revealed a reduction in the number of duplicates in the supplier master table, a decrease in the number and dollar value of duplicate invoices, and an increase in the number of invoices referencing purchase orders.

A CHANGE OF THINKING

In this audit, continuous auditing contributed to improvements in the AP operation; reduced financial errors and potential for fraud, waste, and abuse; and provided a sustainable and cost-effective means to support compliance with policies and procedures and perform risk and control assessments. Continuous auditing helped the team to better understand the regional offices. The overview analysis determined that AP was decentralized with no standard processes and that different regional offices processed different transaction types. Auditors also identified concerns in efficiency and effectiveness of transaction processing at certain offices.

As the RCMP discovered, implementing continuous auditing places certain demands on internal auditors. In particular, the audit organization must develop and maintain the technical competencies necessary to access and manipulate data in multiple information systems. If the auditors are not already using data analysis techniques to support audit projects, the audit department will need to purchase analysis tools and develop and maintain analysis techniques. To realize its full benefits, all audit staff members need to adopt the continuous auditing concept. The benefits are substantial and can reduce the time needed to perform audit planning, increase risk and control assessment capability, and allow auditors to a widen their scope of audit activities and use existing corporate data cost effectively and efficiently.

Read More....

Survey Benchmarks Internal Audit Direction

Survey Benchmarks Internal Audit Direction
J Whitley. The Internal Auditor. Altamonte Springs: Feb 2006. Vol. 63, Iss. 1; pg. 15, 2 pgs

Abstract (Summary)
Standards and regulatory mandates are among a host of factors impacting internal auditors in Australia and New Zealand, according to the second annual benchmarking survey, Trends in Australia and New Zealand Internal Auditing. Risk-based audit planning has become widespread in the two countries. According to the survey, many organizations are seeking auditors with a variety of experiences and backgrounds, including engineers and strategy consultants. The use of automated audit tools by internal audit departments jumped from 46% in 2004 to 73% in 2005. Survey findings suggest that public companies in Australia and New Zealand are seeking greater assurance of their internal audit activity.
span class="fullpost":>
Reputation Risk Increasing... EU Amends Accounting Laws ... Study Compares IT PCAOB Critical of AS2 Progress ... DOD to Authenticate Electronic Devices ... Diamond Dispute Settled ...

STANDARDS AND REGUlatory mandates are among a host of factors impacting internal auditors in Australia and New , Zealand, according to the second annual benchmarking survey, Trends in Australian and New Zealand Internal Auditing. The new report from IIA-Australia, IIA-New Zealand, and Ernst & Young (E&Y) compiles information about the audit activities of more than 170 organizations to provide a better understanding of how internal audit functions in both the public and private sectors are progressing to meet demands and expectations. The report compares the survey's findings and observations with results of the 2004 survey.

The report's authors say the internal audit profession is at a crossroads in Australia and New Zealand. "Internal auditors have the opportunity to capitalize on the new visibility and sponsorship they enjoy," the report states. "However an inability to live up to these new expectations may see an erosion of their resource base and a loss of credibility and diminishing support from stakeholders."

Risk-based audit planning has become widespread in the two countries. Eighty-four percent of organizations base their annual audit plan on the management principles of AS/NZS 4360:2004 Risk Management, the Australia and New Zealand standard that provides a generic guide for managing risk. In 57 percent of organizations, internal auditing works with other assurance functions to provide a summary of key risks and assurance coverage to management and board committees.

More than three-fourths of internal audit functions report to either the audit committee or the chief executive officer (CEO). Although primary reporting lines are often split, there are generally mechanisms to ensure that internal audit objectivity and independence are preserved. Among private-sector respondents in New Zealand, for example, 76 percent have audit committees that satisfy the requirements specified by the New Zealand Stock Exchange's Corporate Governance Best Practice Code, issued in 2003. The code requires audit committee members to have an accounting or financial background.

According to the survey, many organizations are seeking auditors with a variety of experiences and backgrounds, including engineers and strategy consultants. Respondents report that 54 percent of audit staff have a financial background, down from 66 percent in 2004. On the other hand, the use of automated audit tools by internal audit departments jumped from 46 percent in 2004 to 73 percent in 2005. Seventy-seven percent of respondents say their organization outsources parts of their internal audit activity, largely to obtain needed specialty skills.

Survey findings suggest that public companies in Australia and New Zealand are seeking greater assurance of their internal audit activity. Thirty-two percent of organizations have had an independent review of their internal audit function within the past two years, up from 25 percent last year.

Read More....
Custom Search