The Death of Continuous Auditing – part 2

I purposely made the title of my first article more dramatic than needed to make people understand that Continuous Auditing needs to be looked at from a different perspective. In fact, it is the original perspective – Risk and Controls – the needs to be adopted. Unfortunately, the concept of Continuous Auditing transformed into “data analysis” which often resulted in auditors simply reporting errors and exceptions and not tying these back to the Control weakness and the Risk. For those of you who did not fall into this trap: congratulations – no need to change anything; except to continually improve.

Also, as previously mentioned, Continuous Auditing was seen as a negative by clients who misunderstood the term to mean that auditor would continuously be looking at their operations (and reporting errors and exceptions). Thus my suggestion: rename Continuous Auditing to Risk-Responsive and Agile (RRA) audit.

Risk-Responsive should be seen as a positive attribute of internal audit. Senior management would understand the important of a continual monitoring of risk levels to identify changes or emerging risks that would negatively impact operations. (Note: ‘continual’ does not mean all the time. The frequency of the monitoring should be based on the level of the risk.) In addition, using data-driven risk indicators would mean that audit is not negatively impacting operations. The analysis can be a non-intrusive assessment of operational data, key risk indicators, and key performance indicators. This would eliminate some of the “we don’t want audit bothering us (again)” attitude.

This brings me to another issue that goes hand-in hand with being risk-responsive: having the correct audit objective. In a previous article “Getting the Most out of your Compliance Audits”, I stressed the importance of having the right audit objective. If your objective is: To ensure compliance with “A.”; and the criteria is: Client should do “A.”, then when you find that (Condition): Client is not doing “A.”, too often the Recommendation is: Do “A.” Not only does this not add any value, but it also doesn’t address the root cause: Why are they not doing “A”?

Audit should be able to conclude on the objective and, when developing recommendations, ensure that the root cause is being addressed. This means that audit objectives should be carefully defined and understood. When developing the audit objectives ask the question: “Will I be able to conclude on the audit?”.  You can’t conclude on “To ensure compliance with A”. I try to respond with a Yes or No to determine if the audit objective is correctly defined. I can’t answer Yes or No to “To ensure compliance with A”. Instead of “To ensure compliance with A” the audit objective should focus on the controls that are mitigating the initial risk (why the controls were put in place). Thus, the objective would be more like, “the controls to support compliance with are adequate and effective”.  

The next step is to ensure that you have appropriate criteria to support your ability to conclude on the objective. Which controls were put in place to reduce the risk of non-compliance? Determining this will focus your analysis on testing the relevant controls (not the data) and, if you find the controls are not working, the recommendation will address the control weaknesses: not simply “Do A”.

Taking an accounts payable example, RRA audit would first define the audit objective, such as: “The accounts payable controls support the timely and accurate payment of approved invoices.” The next step is to define the data required by the business process, such as Invoice number, date and amount, vendor, payment terms, etc.  Then, identify the risks associated with the business process; and the mitigating controls such as paying early, fictitious vendors, etc.. Next, determine the analysis that will test the controls and the data required to perform the analysis. Once these steps have been completed, you are able to perform the analysis and the review and interpret the results. But you are not done yet. The most important step, assuming everything else was done correctly, is to link the results of the analysis back to why you were performing the analysis – to test the controls – and link the controls back to the risk. This will allow you to conclude on the objective.

A/P Example worksheet to identify risk – controls – analytics – data and results:

Using this approach, you will have audit objectives that are supported by analytics; and your analytics will be designed to examine risks by testing the mitigating controls. Further, it is easy to see how the results are related to the mitigating controls and risks. This will focus your analysis and lead to recommendations that directly address the control weaknesses. It also means that the analysis can be re-performed to determine if the recommended action taken by management has addressed the control weaknesses and impact the risk levels.

RRA steps:

This approach will ensure that audit is both risk-responsive and agile in the performance of audits.

Dave Coderre, CAATS (www.caats.ca); and River Analytics and Automation (River AA)


 

Jennifer Gargiulo AMA-CPM

Director of Compliance Testing, First Vice President at Dime Community Bank

6 年
Angela Kroboth

Answering Questions with Data

6 年

Wise words. From a different perspective, I feel like this advice also applies to my children. I want the solution to be “Do A” but it appears I need to preform some additional, helpful assessments to figure out how to offer better advice.

回复
Raven Catlin

Authority speaker, trainer, & facilitator in risk, controls, and audit. "Engaging, energetic, expert trainer" Keynote speaker Pioneer & Author of Agile Auditing CEO, Raven Global Training

6 年

Thank you for including the business / process objective in your RCM. Too many #internalaudit shops ignore the business objective when identifying risks

回复
Jerry Chen

Sr. IT Auditor & Audit Data Analyst

6 年

Great article.? We often do data analytics for data analytics sack, not looking at big picture of why we need it in the first place!??

Amr Riad, CIA

Risk Advisory | Internal Audit | Governance | Compliance | Process Reenginering

6 年

Very useful articel ???? Thanks Mr David for sharing such a valuable approach. It will be helpful for updating our RCM (Risk and control matrix) to gain the deep understanding thrugh the business processes to identify control weaknesses appropriately.

要查看或添加评论,请登录

David Coderre的更多文章

  • Analytics Maturity

    Analytics Maturity

    Study after study has shown that data analytics is effective and efficient at detecting risk and identifying control…

  • Duplicates Invoices – Root Cause Analysis

    Duplicates Invoices – Root Cause Analysis

    Cost recovery firms make millions of dollars identifying and recovering duplicate payments. They often have well…

    2 条评论
  • COVID and Internal Audit

    COVID and Internal Audit

    I don’t understand why some Chief Audit Executives and internal auditors think that this is the time for audit to stop…

    22 条评论
  • Analytics support for annual Risk-Based Audit Planning (RBAP)

    Analytics support for annual Risk-Based Audit Planning (RBAP)

    The Risk-Base Audit Plan (RBAP) is an important output of Internal Audit. Not only is it a requirement of the IIA…

    6 条评论
  • See Visualizations

    See Visualizations

    Seeing Visualization I have been performing analytics for more than 30 years and I am not sure if it was simply a case…

  • The Death of Continuous Auditing

    The Death of Continuous Auditing

    David Coderre, www.caats.

    23 条评论
  • Identifying Duplicates Effectively

    Identifying Duplicates Effectively

    The concept of identifying duplicates is fairly simple: do two records have the same values? If yes, then they are…

    12 条评论
  • Blush - the game

    Blush - the game

    Helping Parents with their Children’s Sex Education For years I have written about data analysis to identify and assess…

    3 条评论
  • CEOs Need to Wake up to the Strategic Importance of GRC

    CEOs Need to Wake up to the Strategic Importance of GRC

    GRC: Governance, Risk and Compliance (or, in my view, Controls) is critical to companies that want to remain viable. A…

  • Integrating ERM and Performance Measurement: Part 2

    Integrating ERM and Performance Measurement: Part 2

    A proposed integrative model Dave Coderre, CAATS, www.caats.

社区洞察

其他会员也浏览了