Implementing Continuous Auditing in a Global Real Time Economy Miklos A. Vasarhelyi KPMG Professor of AIS Rutgers University Technology Consultant AT&T.

Slides:



Advertisements
Similar presentations
AUDITING : AN OVERVIEW. Auditing defined It is a critical and systematic examination or review of accounting reports, documents, records, procedures and.
Advertisements

Internal Control–Integrated Framework
8/2/2006Prelimary – do not quote1 Transaction Objects, Control Objects, Control tags and Tags Dynamics Miklos A. Vasarhelyi Rutgers University.
Chapter 15: Packaged Software and Enterprise Resource Planning
International Federation of Accountants International Education Standards for Professional Accountants Mark Allison, Executive Director Institute of Chartered.
Learning Objectives LO1 Explain the importance of auditing. LO2 Distinguish auditing from accounting. LO3 Explain the role of auditing in information risk.
Audit Guidance Using the Federal Information System Controls Audit Manual (FISCAM) to Achieve Audit Objectives in Financial and Performance Audits Mickie.
1 Continuous Auditing Implications: Rethinking the Roles of Systems of Internal Controls Presented by Rob Nehmer Berry College at the Fifth Continuous.
Principles of Analytic Monitoring Miklos A. Vasarhelyi Michael Alles Alexandr Kogan Rutgers Business School.
1. Research Topics for Continuous Auditing Mike Groomer Professor of Accounting and Information Systems Kelley School of Business Indiana University.
The Acceptance and Adoption of Continuous Auditing by Internal Auditors: A Micro Analysis Miklos A. Vasarhelyi Micheal Alles Siripan Kuenkaikaew James.
Miklos A. Vasarhelyi Siripan Kuenkaikaew Silvia Romero
Continuous Auditing Technology Adoption in Leading Internal Audit Organizations Miklos A. Vasarhelyi Siripan Kuenkaikaew.
Operational Auditing--Fall Operational Auditing Fall 2010 Professor Bill O’Brien.
Operational Auditing--Fall Operational Auditing Fall 2009 Professor Bill O’Brien.
MIS350 Accounting Information Systems Course Context.
Evolution of the Siemens Experience in its Effort to Test IT Controls on a Continuous Basis Rolf Haardörfer IT Audit Professional Siemens Corporation Tenth.
Advanced Accounting Information Systems
Quality evaluation and improvement for Internal Audit
Principles of Information Systems, Sixth Edition 1 Systems Investigation and Analysis Chapter 12.
The Information Systems Audit Process
MSIS 110: Introduction to Computers; Instructor: S. Mathiyalakan1 Systems Investigation and Analysis Chapter 12.
© Siemens Product Lifecycle Management Software Inc. All rights reserved Siemens PLM Software A protocol for continuous monitoring and assurance.
Audit Automation as the Foundation of Continuous Auditing Michael Alles Alexander Kogan Miklos A. Vasarhelyi J. Donald Warren, Jr.
Purpose of the Standards
Principles and Problems of Audit Automation as a Precursor to Continuous Auditing Michael Alles Alexander Kogan Miklos A. Vasarhelyi.
Basel Accord IITRANSITIONSERVICES Business Integration Support FCM Management Limited Paris New York Toronto.
Internal Auditing and Outsourcing
An Introduction to AlarmInsight
D-1 McGraw-Hill/Irwin ©2005 by the McGraw-Hill Companies, Inc. All rights reserved. Module D Internal, Governmental, and Fraud Audits “I predict that audit.
Five axioms and the future of tagging Miklos A. Vasarhelyi KPMG Professor of AIS Rutgers Business School Senior Technology Consultant AT&T Laboratories.
Copyright 2002 Prentice-Hall, Inc. Chapter 1 The Systems Development Environment 1.1 Modern Systems Analysis and Design.
MANIFESTO FOR RESPONSIBLE EUROPEAN MANAGEMENT EUROCADRES’ Conference Nov 2003 Dirk Ameel.
© Grant Thornton | | | | | Guidance on Monitoring Internal Control Systems COSO Monitoring Project Update FEI - CFIT Meeting September 25, 2008.
Overview:  Different controls in an organization  Relationship between IT controls & financial controls  The Mega Process Leads  Application of COBIT.
© 2013 Cengage Learning. All Rights Reserved. 1 Part Four: Implementing Business Ethics in a Global Economy Chapter 9: Managing and Controlling Ethics.
Chapter 1: Accounting Information Systems and the Accountant
Presented By Tay Un Soo Senior VP, Bank of Commerce President of ISACA - Malaysia Chapter 1999 National Accountants Conference THRIVING IN THE DIGITAL.
Implementing Continuous Auditing in a Global Real Time Economy Miklos A. Vasarhelyi KPMG Professor of AIS Rutgers University Technology Consultant AT&T.
Risk Management. IT Controls Risk management process Risk management process IT controls IT controls IT Governance Frameworks IT Governance Frameworks.
Bank Audit. Internal Audit Internal audit is an independent, objective assurance activity and can give valuable insight in providing assurance that major.
1 Chapter Nine Conducting the IT Audit Lecture Outline Audit Standards IT Audit Life Cycle Four Main Types of IT Audits Using COBIT to Perform an Audit.
Continuous Auditing at Unibanco Washington Lopes
Continuous Auditing Continuous Monitoring Of Business Controls Discussant’s Comments Presented by: Clyde Rogers – October, 2005.
Principles of Information Systems, Sixth Edition Systems Investigation and Analysis Chapter 12.
Copyright © 2013 by The McGraw-Hill Companies, Inc. All rights reserved.McGraw-Hill/Irwin.
CHAPTER 1 An Overview of Auditing. What does an auditor do?
Chapter 11 Managing Application Development. Agenda Application management framework Application management issues Criteria for development approach Development.
Principles of Information Systems, Sixth Edition Systems Investigation and Analysis Chapter 12.
Industry Outlook November Manufacturing Matters in Canada  A $620 billion industry  12% of GDP (18% in 2004)  1.7.
1 Emerging CARLAB work Miklos A. Vasarhelyi. 2 Outline Continuous Control Monitoring Simulating Continuous Auditing Control Tags.
© 2009 IBM Corporation Smarter Decisions for Optimized Performance IBM Global Executive Forum Panel Discussion Business Analytics and Optimization Fred.
Foundations of Information Systems in Business. System ® System  A system is an interrelated set of business procedures used within one business unit.
Project Management May 30th, Team Members Name Project Role Gint of Communications Sai
Thomas L. Gilchrist Testing Basics Set 3: Testing Strategies By Tom Gilchrist Jan 2009.
Continuous Auditing ISACA London Chapter Technical Presentation Thursday, June 27th 2002 Charles Mansour, CISA ©Charles Mansour.
Copyright © 2015 McGraw-Hill Education. All rights reserved. No reproduction or distribution without the prior written consent of McGraw-Hill Education.
Continuous audit: today and tomorrow Miklos A. Vasarhelyi KPMG Professor – Rutgers University Senior Consultant- AT&T Laboratories.
Current risk and compliance priorities for law firms PETER SCOTT CONSULTING.
Talent Acquisition, Staffing, Recruitment, Executive Search.
Announcing the 2014 National Digital Stewardship Agenda.
Government Internal Audit Career
Chapter 1 An Introduction to Assurance and Financial Statement Auditing.
Attention CFOs How to tighten your belt and still survive May 18, 2017.
Audit Automation as the Foundation of Continuous Auditing
Service Organization Control (SOC)
Miklos A. Vasarhelyi Rutgers University
Transaction Objects, Control Objects, Control tags and Tags Dynamics
43 World Continuous Audit Symposium
Transaction Objects, Control Objects, Control tags and Tags Dynamics
Presentation transcript:

Implementing Continuous Auditing in a Global Real Time Economy Miklos A. Vasarhelyi KPMG Professor of AIS Rutgers University Technology Consultant AT&T Laboratories

Continuous Audit and Reporting Laboratory 2 Outline The real time economy Going Global Measuring Business Assurance in the Global Real Time Economy Implementing Continuous Audit Opportunities and Challenges

The Real Time Economy

Continuous Audit and Reporting Laboratory 4 The real time economy The objective –Reduction of latency Inter-Process Latency Intra-Process Latency The facilitators –Sensors – measuring transactions automatically –ERPs –Process Automation –Dashboards –Reengineering, Outsourcing, System Integration

Continuous Audit and Reporting Laboratory 5 RTE Processes that are supported by real-time systems Processes which are monitored on a close to continuous basis Processes that are highly time dependent Processes where timely decisions give competitive advantage

Continuous Audit and Reporting Laboratory 6

Going global

Continuous Audit and Reporting Laboratory 8 Going global - Preamble Over the last 50 years technology has enabled major motion towards a global economy. Consequently it has set into motion social change, economic rebalancing, and an unprecedented degree of across-country cooperation. However this phenomenon of ubiquitous consequence has created a wave of challenges to the socio-technical structure of business and corporate policy making.

Continuous Audit and Reporting Laboratory 9 Going Global - Friedman 11/09/1989 (Berlin Wall) 08/09/95 (Netscape went Public) Three billion new people joining the fray Work flow software Open sourcing Outsourcing, offshoring, In-forming Hardware & software multifuctionality Tools of cooperation

Measuring Business

Continuous Audit and Reporting Laboratory 11

Continuous Audit and Reporting Laboratory 12 RTEBIS Very rapid business cycles Instant need of resolution of certain business needs (for example monthly billing may not be acceptable) Service agreements that specify certain degree of data reliability Rapid change in the terms of agreements contingent on dynamic parameters Utilization of Service Oriented Architectures that allow for dynamic servicing of clients and dynamic acquisition of suppliers and service providers

Continuous Audit and Reporting Laboratory 13

Assurance in the Global Real Time Economy

Continuous Audit and Reporting Laboratory 15 What is Continuous Auditing? o No consensus on what constitutes a continuous audit o Enhanced auditor skill set o Differences from traditional audit o New audit risk model o Continuous reporting and impact on auditor’s report o Senior management support

Continuous Audit and Reporting Laboratory 16 A Distinction between Continuous Auditing and Continuous Monitoring Continuous auditing does not necessarily have to generate a report; it is a process that tests transactions based upon prescribed criteria, identifies anomalies, and is the responsibility of the auditor. Continuous monitoring, on the other hand, is the responsibility of management, best defined in terms of the COSO Study control framework. Continuous monitoring, when employed by auditors, focuses on the control environment and not transactions.

Continuous Audit and Reporting Laboratory 17 An evolving continuous audit framework Automation Sensoring ERP E-Commerce Continuous Audit Continuous Control Monitoring Continuous Audit Data CA = CCM+ C(D)A CA -> Continuous Audit CCM -> Continuous Control Monitoring C(D)A -> Continuous Data Assurance

Continuous Audit and Reporting Laboratory 18 Unibanco – Advances to Clients Monitoring

Overview of CaR-Lab examples

Continuous Audit and Reporting Laboratory 20 CAR-Lab Experiences Control monitoring at Siemens Transaction monitoring at Unibanco Continuous (data) assurance at HCA Other –Conceptual developments –Simulating Liberty –EBR work –KPMG projects

Implementing Continuous Audit

Continuous Audit and Reporting Laboratory 22 Background –While technologies of continuous audit have been extensively discussed and are progressively emerging the more mundane issues of their implementation in a socio- technical environment have been neglected – features /feature-2/

Continuous Audit and Reporting Laboratory Rule 5. Follow-up 1.Priority Areas 6. Action and Reaction 4. Parameterization 3. Frequency Audit Control Panel Six steps of process implementation

Opportunities and Challenges

Continuous Audit and Reporting Laboratory 25 Opportunities for business and research (1) Control system measurement –We are in a pre-paradigmatic stage of control documentation and measurement –We do not know how to monitor controls in large ERPs –We do not know how to provide a really supportable opinion on controls –We do not know how to rate combinations of controls Business Process Monitoring and Alarming –Auditors have to carve a position on the new monitoring and control environment –Auditors can collect exception “alarms” as trusted parties and incorporate these into evidentiary matter –Auditors can be “trusted”

Continuous Audit and Reporting Laboratory 26 Opportunities (2) Automatic Confirmation Tools –Confirmations will have an increased evidentiary role with eventual elimination of population and integrity worries –Intelligent confirmatory tags can do much –Database to database hand-shaking will be medium –Business opportunity for auditors Audit bots (agents) –Many of the basic audit functions can be emulated by software –These must be eventually developed by the profession to work hand-in- hand with human auditors in the new audit world –These agents will work on all areas including: 1) audit planning, 2) analytical reviews, 4) confirmations, and )5 evergreen opinions

Continuous Audit and Reporting Laboratory 27 Opportunities (3) Collecting forensic trails –Auditor “black” box Publishing real-time authenticated reports for different compliance masters Publishing FD independent compliance reports

Continuous Audit and Reporting Laboratory 28 Challenges Standards are needed for CA –Audit monitoring needs to be defined –Types of evidence are to change and must be reconsidered –Independence needs to be re-defined The billing model has to be restructured to bill on function not hours Audit firms must put improved knowledge collection and management processes to feed their audit analytic toolkit Audit firms have to engage in auditor automation and pro-actively promote corporate data collection during-the-process Value added must be justified in terms of data quality