AUDIT COMMITTEE FORUM TM ACF Roundtable IT Governance – what does it mean to you as an audit committee member July 2010 The AUDIT COMMITTEE FORUM TM is.

Slides:



Advertisements
Similar presentations
Organizational Governance
Advertisements

Options appraisal, the business case & procurement
Auditing Governance Functions
Primary Benefit Types Value Discipline Benefits – Operating Excellence Reduce Cost Reduce Risk – Product Leadership Increase Revenue – Customer Intimacy.
Core principles in the ASX CGC document. Which one do you think is the most important and least important? Presented by Casey Chan Ethics Governance &
Introduction to Enterprise Risk Management (ERM)
Project Monitoring Evaluation and Assessment
Executive Insight through Enhanced Enterprise Risk Management Leverage Value From Your Risk Management Investment.
Welcome! Internal Auditing CHAPTER 1. Definition Internal auditing is an independent, objective, assurance and consulting activity designed to add value.
IT Governance Navigating for Value Michael Vitale 6 May 2003 CIO Conference Steering the Enterprise Through Stormy Seas Image source: Access2000.
CISB444 - Strategic Information Systems Planning
Viewpoint Consulting – Committed to your success.
PwC Role of Internal Audit in Corporate Governance September 2010 Tumin Gültekin, Partner.
Aust. AM Collaborative Group (AAMCOG) An introduction to ISO “What to do” guide 20th October 2014.
Moving from money well accounted for to money well spent UK Information Technology Summit May 2005 Helen McDonald A/Chief Information Officer Treasury.
Euseden INTERNAL AUDIT & ASSURANCE SERVICES.
CORPORATE RISK MANAGEMENT & INSURANCE BY R P BLAH D.G.M. INCHARGE THE ORIENTAL INSURANCE COMPANY LIMITED REGIONAL OFFICE BHUBANESWAR.
PAINTING THE FULL PICTURE
How can projects be controlled?
Corporate Governance: Beyond Compliance at a time of Recession Prof. Ashley G. Frank BA(Econ)[Magna Cum Laude], MDPA (Cum Laude], MBA, MCom [Cum Laude],
Internal Auditing and Outsourcing
Project Human Resource Management
© 2010 Plexent – All rights reserved. 1 Change –The addition, modification or removal of approved, supported or baselined CIs Request for Change –Record.
Information Security Governance 25 th June 2007 Gordon Micallef Vice President – ISACA MALTA CHAPTER.
Governance of the Treasury Function CIPFA Scottish Treasury Management Forum Alan George, Regional Director 23rd February 2012.
DPE Shareholder Oversight & Risk Management
Continual Service Improvement Process
ISMMMO, Antalya April Internal Audit, Best Practices Özlem Aykaç, CIA,CCSA CAE Coca-Cola İçecek.
Global Risk Management Solutions Risk Management and the Board of Director: Moving Beyond Concepts to Execution Anton VAN WYK Partner, Global Risk Management.
Chapter 3 Internal Controls.
THE REGIONAL MUNICIPALITY OF YORK Information Technology Strategy & 5 Year Plan.
The Challenge of IT-Business Alignment
Chapter Three IT Risks and Controls.
Logistics and supply chain strategy planning
© 2013 Cengage Learning. All Rights Reserved. 1 Part Four: Implementing Business Ethics in a Global Economy Chapter 9: Managing and Controlling Ethics.
Certificate IV in Project Management Introduction to Project Management Course Number Qualification Code BSB41507.
CSI - Introduction General Understanding. What is ITSM and what is its Value? ITSM is a set of specialized organizational capabilities for providing value.
CERTIFICATION In the Electronics Recycling Industry © 2007 IAER Web Site - -
An Integrated Control Framework & Control Objectives for Information Technology – An IT Governance Framework COSO and COBIT 4.0.
Committee of Sponsoring Organizations of The Treadway Commission Formed in 1985 to sponsor the National Commission on Fraudulent Financial Reporting “Internal.
Private & Confidential1 (SIA) 13 Enterprise Risk Management The Standard should be read in the conjunction with the "Preface to the Standards on Internal.
Holistic Approach to Security
IT Strategic Planning.
Bank Audit. Internal Audit Internal audit is an independent, objective assurance activity and can give valuable insight in providing assurance that major.
Practical Investment Assurance Framework PIAF Copyright © 2009 Group Joy Pty. Ltd. All rights reserved. Recommended for C- Level Executives.
IT GOVERNANCE  Objective : The objective of this area is to ensure that the Certified Information Systems Auditor ( CISA ) candidate understands and can.
Briefing to Portfolio Committee on Public Enterprises On Performance Management of SOE Senior Management 10 November 2009.
Chapter 3 Governance.
Kathy Corbiere Service Delivery and Performance Commission
Corporate Services Restructuring 31 March Introduction  The AG completed the restructuring of Corporate Services in November 2005  The restructuring.
Internal Auditing Effectiveness
12-CRS-0106 REVISED 8 FEB 2013 APO (Align, Plan and Organise)
Driving Value from IT Services using ITIL and COBIT 5 July 24, 2013 Gary Hardy ITWinners.
IT Auditor’s Role in IT Governance Fred C. Roth, CISA MIS Training Institute Session 425.
Organizations of all types and sizes face a range of risks that can affect the achievement of their objectives. Organization's activities Strategic initiatives.
COBIT. The Control Objectives for Information and related Technology (COBIT) A set of best practices (framework) for information technology (IT) management.
1 Balanced Scorecard Philosophy, Basics, Fundamentals, and Functions.
12-CRS-0106 REVISED 8 FEB 2013 EDM (Evaluate, Direct, and Monitor) CDG4I3 / Audit Sistem Informasi Angelina Prima K | Gede Ary W. KK SIDE
JMFIP Financial Management Conference
Priorities for the Success AT Strategic Action Plan: SUMMARY
Asset Management Accountability Framework
IIASA Governance Review
CIGFARO ANNUAL CONFERENCE – 11 OCTOBER 2017
Identify the Risk of Not Doing BA
Audit & Risk Management
Asset Governance – Integrated Strategic Asset Management
Portfolio, Programme and Project
MAZARS’ CONSULTING PRACTICE Helping your Business Venture Further
A COMPETENCY FRAMEWORK FOR GOVERNANCE GOVERNORS’ BRIEFING LANGLEY HALL PRIMARY ACADEMY 14 JULY 2017 Clive Haines & Rebecca Walker.
Operational Risk Management
Presentation transcript:

AUDIT COMMITTEE FORUM TM ACF Roundtable IT Governance – what does it mean to you as an audit committee member July 2010 The AUDIT COMMITTEE FORUM TM is proudly sponsored by KPMG

Current State There have been a number of high-profile instances where processes that govern the integrity of information technology operations (IT governance) are not sufficiently effective to guard companies against serious financial loss. Companies have damaged their operations and negatively impacted revenue recognition, profit, and reputation by compromising the integrity or availability of their information as a result of problems associated with IT system implementations. Good Corporate governance (and King III) outline the role that Audit Committees should play in improving IT Governance. In two recent surveys, 30% of respondents indicated that they were not satisfied with the amount of time that audit committees spend on oversight of IT risk while only 9-11% were “Very satisfied’’ 22

The AUDIT COMMITTEE FORUM TM is proudly sponsored by KPMG Current State (cont.) Many organisations are struggling with: Poor alignment of IT resources against business goals Lack of demonstrative value from IT investments Business and / or technology change Dissatisfaction with IT function and the level of service it provides The implementation of compliance legislation IT projects exceeding time and financial budgets IT risks and control responsibilities poorly defined 33

The AUDIT COMMITTEE FORUM TM is proudly sponsored by KPMG A definition of IT Governance IT governance is a set of business processes that impose management and control disciplines on IT activities to help ensure the integrity and protection of IT operations and the achievement of targeted business goals. It is primarily about achieving three things: Getting the most value from IT, including moving towards strategic goals. Ensuring that stakeholders and management understand key IT risks and manage them accordingly. Establishing the conditions that allow IT management to operate effectively. 44

The AUDIT COMMITTEE FORUM TM is proudly sponsored by KPMG The Key Elements of IT Governance 55 IT Strategy and Planning Board Oversight and Responsibility IT Governance/ Performance Tracking and Reporting Governance Structures IT Governance Framework Risk Assessment IT Investment Analysis Build IT control framework Business Needs and Expectations Outcomes

The AUDIT COMMITTEE FORUM TM is proudly sponsored by KPMG THE KING III PERSPECTIVE 66 IT Strategy and Planning Board Oversight and Responsibility IT Governance/ Performance Tracking and Reporting Governance Structures IT Governance Framework Risk Assessment IT Investment Analysis Build IT control framework Business Needs and Expectations Outcomes Principle 2: Performance and Sustainability 2 2 Principle 3: IT Governance Framework 3 3 Principle 1: Board Responsibility 1 1 Principle 2: Performance and Sustainability 2 2 Principle 6: Information Security 6 6 Principle 4: IT Investments 4 4 Principle 7: Governance Structures 7 7 Principle 5: Risk Management 5 5

The AUDIT COMMITTEE FORUM TM is proudly sponsored by KPMG QUESTIONS THE AUDIT COMMITTEE SHOULD ASK 77

The AUDIT COMMITTEE FORUM TM is proudly sponsored by KPMG IT Strategy and Planning 88. What is it and why is it important? The purpose of IT strategy – the business needs to understand its strategy and document its strategic intent Strikes an optimum balance of information technology opportunities and IT business requirements Accomplishes organisational goals and objectives Critical to aligning business and IT objectives Ensures investments are made optimally Drives a “common language” Sets expectations Considers architecture, delivery and governance Key Questions: Who was involved in developing the IT strategy and what was the process followed? Have you defined a sourcing strategy? Key Questions: Who was involved in developing the IT strategy and what was the process followed? Have you defined a sourcing strategy?

The AUDIT COMMITTEE FORUM TM is proudly sponsored by KPMG IT Governance Framework 99 What is it and why is it important? IT governance at its most basic is the process of making decisions about IT Good IT governance ensures that IT investments are optimised, aligned with business strategy and delivering value within acceptable risk boundaries — taking into account culture, organisational structure, maturity and strategy Articulates the roles of the various management and governance bodies across the business and decision making Assigns clearly defined delegation for effective and efficient decision making and performance monitoring, Encompasses a broad focus on overall IT capability Enhances strategic decision making capacity Key Questions: Have roles and responsibilities been assigned across IT? Is a policy framework and related policies in place? Are we aligned to industry standards, and if so, which ones? Key Questions: Have roles and responsibilities been assigned across IT? Is a policy framework and related policies in place? Are we aligned to industry standards, and if so, which ones?

The AUDIT COMMITTEE FORUM TM is proudly sponsored by KPMG IT Investments  10 IT Investments What is it and why is it important? Organisations must be able to measure business value and also manage and communicate value delivery in order to answer the questions: 1) Are we doing the right things? and 2) are we getting the benefits? Define the relationship between IT and the business Manage portfolio of IT-enabled business investments Maximise the quality of business cases for IT-enabled investments Articulate IT investment decision rights to ensure that they deliver the maximum business value at an acceptable level of risk. Key Questions: Do we have a formal project management methodology / processes? Do we perform a business case prior to significant spend? Do we identify the targeted benefits and track these through the life of the project? Key Questions: Do we have a formal project management methodology / processes? Do we perform a business case prior to significant spend? Do we identify the targeted benefits and track these through the life of the project?

The AUDIT COMMITTEE FORUM TM is proudly sponsored by KPMG IT Risk Assessment  11 Risk Assessment What is it and why is it important? These can range from accidental damage caused by employees with inadequate training to deliberate attempts from outsiders to illegally access data that your business holds Helps identify and form basis for risk mitigation plans Risk areas for consideration - Business Focus, Information Assets, Dependence on IT, Dependence on IT internal staff, Dependence on third parties, Reliability of IT systems, Changes to IT, Legislative and regulatory environment Recognise the risks associated with using IT in a business environment Key Questions: How often do we perform IT risk assessments? Are the necessary resources made available within the business and within the Internal Audit department to conduct IT Audits? What are the key risks in our IT environment? Key Questions: How often do we perform IT risk assessments? Are the necessary resources made available within the business and within the Internal Audit department to conduct IT Audits? What are the key risks in our IT environment?

The AUDIT COMMITTEE FORUM TM is proudly sponsored by KPMG IT Control Framework  12 IT controls are specific activities performed by people or systems designed to ensure that business objectives are met IT Control Framework What is it and why is it important? IT controls are specific activities performed by people or systems designed to ensure that business objectives are met A subset of an enterprise's internal control which relate to the confidentiality, integrity and availability of data and the overall management of the IT function A set of fundamental controls that must be in place to prevent information loss in an organization Control areas for consideration - Management of IT, Continuity of systems (Disaster recovery), Systems development, Change control, Security of information and systems, Physical and logical access controls, Control assurance Key Questions: Have we identified our key IT controls? Do we monitor (and benchmark) these on an ongoing basis? Key Questions: Have we identified our key IT controls? Do we monitor (and benchmark) these on an ongoing basis?

The AUDIT COMMITTEE FORUM TM is proudly sponsored by KPMG Performance Tracking and Reporting  13 Performance tracking and reporting What is it and why is it important? It is critical to measure to outcomes of strategic initiatives Keep the focus on ongoing control Effectively manage the IT function Provide transparent reporting to the business on IT performance Performance reporting should focus not only on financial outcomes but also on the operational, marketing, risk and developmental inputs to the business Key Questions: Have we defined KPI’s and CSF’s for IT? Are these monitored, reported, and followed up on? Key Questions: Have we defined KPI’s and CSF’s for IT? Are these monitored, reported, and followed up on?

The AUDIT COMMITTEE FORUM TM is proudly sponsored by KPMG Summary of key questions  14 IT Strategy and Planning: Who was involved in developing the IT strategy and what was the process followed? Have you defined a sourcing strategy? IT Governance Framework: Have roles and responsibilities been assigned across IT? Is a policy framework and related policies in place? Are we aligned to industry standards, and if so, which ones? IT Investments: Do we perform a business case prior to significant spend? Do we identify the targeted benefits and track these through the life of the project? IT Risk Assessment How often do we perform IT risk assessments? What are the key risks in our IT environment? IT Control Framework Have we identified our key IT controls? Do we monitor (and benchmark) these on an ongoing basis? Performance Tracking and Reporting Have we defined KPI’s and CSF’s for IT? Are these monitored, reported, and followed up on?

The AUDIT COMMITTEE FORUM TM is proudly sponsored by KPMG King III specific responsibilities The audit committee should consider IT as it relates to financial reporting and the going concern of the company What are the key systems responsible for the generation and processing of financial reporting data? How reliant are we on our systems? (how long could we survive without them?) Do we have Disaster Recovery and Business Continuity Plans? Have we tested these? Is our information security sufficient for the business? The audit committee should consider the use of technology to improve audit coverage and efficiency Has our (internal or outsourced) Internal Audit function identified key application controls to test? Do we test the general controls related to those key applications? What internal auditing tools do we utilise (e.g. CAATs, Continuous Auditing)?  15

The AUDIT COMMITTEE FORUM TM is proudly sponsored by KPMG Presenter’s contact details:  16 Cape Town Patrick Ryan KPMG (021) Durban Eugene Pfister KPMG (011) Johannesburg Frank Rizzo KPMG (011)

The AUDIT COMMITTEE FORUM TM is proudly sponsored by KPMG 17 QUESTIONS?