Improving System Development Project Success: How Internal Auditors Add Value Through Process Involvement & Measurement Glen L. Gray, California State.

Slides:



Advertisements
Similar presentations
Successful Enterprise Applications Projects Golan Avraham - Tescom USA June 22 nd 2006 Hold System Integrator Accountable Through Independent Quality Assurance.
Advertisements

IT Project Management Greg Dexter City of Los Angeles Cheng Li Cal State Los Angeles.
1 The Antecedents of Internal Auditors Adoption of Continuous Auditing Technology: Exploring UTAUT in an Organizational Context Ray Henrickson CAIT, CACISA.
Program Management Office (PMO) Design
USG INFORMATION SECURITY PROGRAM AUDIT: ACHIEVING SUCCESSFUL AUDIT OUTCOMES Cara King Senior IT Auditor, OIAC.
A Consultative Approach to Auditing
2025 Planning Contacts Meeting November 8, 2012 K-State 2025.
#CPACONGRESS B2 – Public Sector Audit Committees: What is all the fuss about? Jenny Morison FCA Director – Morison Consulting Pty Limited Thursday 20 November.
Evaluating public RTD interventions: A performance audit perspective from the EU European Court of Auditors American Evaluation Society, Portland, 3 November.
By Collin Smith COBIT Introduction By Collin Smith
© 2007 Sequence Advisors. All Rights Reserved. Driving Change With Microsoft EPM Solutions David Luper, MBA, PMP, MCP.
PwC Role of Internal Audit in Corporate Governance September 2010 Tumin Gültekin, Partner.
IT Planning.
Glen Knight, PMP, CSP President How Mature Do You Think Your Are? The Project Management Maturity Model.
Continuous Business Risk Assessment. About BYU Private, Church-sponsored Founded 1875 Three campuses –Provo, Utah (30,000) –Rexburg, Idaho (14,000) –Laie,
Quality evaluation and improvement for Internal Audit
Most Experienced Gold Partner (est. 1994)
© 2008 Prentice Hall11-1 Introduction to Project Management Chapter 11 Managing Project Execution Information Systems Project Management: A Process and.
Project Execution.
HOW TO WRITE A GOOD TERMS OF REFERENCE FOR FOR EVALUATION Programme Management Interest Group 19 October 2010 Pinky Mashigo.
Presentation Management-information ESF by Martin de Vries Coordinator Planning & Control September 19 th :30 – 12:15 h.
Systems Analysis and Design in a Changing World, 6th Edition
S/W Project Management
Multidisplinary Approach.. What are your expectations Write on board.
Developing an IS/IT Strategy
Project Management Donald Hsu, Ph.D. Dominican College
Having an independent Non- Executive Director on your board is essential for growth Bryan Foss Independent Non-Executive Director, Risk & Audit Chair,
Organically evolving CBC opportunities and areas of work INTOSAI Capacity Building Committee - Meeting in Lima, Peru 9-11 September 2014.
Systems Development AIMS 2710 R. Nakatsu. Overview Why do IT projects succeed and fail? Two philosophies of systems development –Systems Development Life.
Discussion of “ Comparing the Attitudes and Activities of Internal Auditors in Australia, Canada, and the United States Regarding Green IT,” by Glen Gray,
Mani Subramanian. What is Project? is a temporary endeavor with a beginning and an end. Delivers Unique Product, Service or result.
Lecture 11 Managing Project Execution. Project Execution The phase of a project in which work towards direct achievement of the project’s objectives and.
– Planning Overview September New Planning Committee established – 2013 New Planning Committee established – 2013 – 6 Pastors, 1 Finance.
The views expressed in this presentation do not necessarily reflect those of the Federal Reserve Bank of New York or the Federal Reserve System Association.
Analysis of 2007 BOD Assessment Checklists Prepared by: Cambria Tidwell.
Corporate Support PPSO Gez Keating, Serco Plc. AGENDA Portfolio Management Role of Corporate PPSO Processes Where to Start Benefits.
Annual Conference The Internal Auditor – value added to both the Audit Committee and Management 7 November 2012.
The Changers Library Part One: A day in the life ExFiles FOLIO Course.
A Relative Cost Framework for Rethinking Assurance of XBRL Filings ISAIS 2011: Rome, Italy Glen L. Gray, California State University, Northridge, USA Michael.
Get Your "Party" Started: Establishing a Successful Third-party Evaluation Martha Thurlow, Ph.D. & Vitaliy Shyyan, Ph.D.—National Center on Educational.
INSIGHT – Delivering Value to Stakeholders San Francisco Chapter of the IIA Tuesday, September 11, 2012 Patricia K. Miller Former IIA Chairman of the Board.
Developed by:.  What is it?  Approaches  Processes  Objectives of PM  Conclusion.
BNL Tier 1 Service Planning & Monitoring Bruce G. Gibbard GDB 5-6 August 2006.
Board Feedback Results Board Meeting Dallas April 2007 Board Feedback Results Governance Committee Report Presented at Los Angeles July 2007.
PUBLIC–PRIVATE PARTNERSHIP (PPP) FRAMEWORK AND GUIDELINES Syed M. Ali Zaidi, P.Eng. PM(Stanford), Ph.D. Director, Strategic Partnerships Alberta Infrastructure.
Managing IT as a Business Managing Organizations in the 21 st Century Organizations must become more agile, transparent, and innovative. There is great.
Needs Assessment: Conducting, Completing and Aligning with the Budget November 9, 2015 Deborah Walker, ESE Worcester Public Schools: Gregg Barres, Manager.
AB 86: Adult Education Consortia Planning Using Your Planning $$$ Wisely Webinar Series
Public Value Review of services for people with learning disabilities Andrew Price & Simon Laker, PLD Commissioning, Adult Social Care February
August 2, Welcome Who is the TSD Continuous Improvement Team ? What is the work of the TSD Continuous Improvement Team? What is.
Louisiana Board of Elementary and Secondary Education Student-Based Budgeting Task Force November 3, 2010 Matt Hill.
Establishing (or Enhancing) PMO Effectiveness Nicolle Goldman, PMP March 28, 2007.
The role of Finance in Agile Application Development
How Project Management Tool Helps Sticking To Basic Project Management Principles  Organizations can consider using project management tool to facilitate.
IS&T Project Reviews September 9, Project Review Overview Facilitative approach that actively engages a number of key project staff and senior IS&T.
WP6 – Monitoring and Evaluation 17th November 2014 Rome.
Key to an Effective Red Book Shop JUAN R PEREZ, CHIEF OF AUDITS COUNTY OF SAN DIEGO MARCH 9, 2016.
Board Roles & Responsibilities
Project Management The Roles and Responsibilities of a Project Manager
Inflectra User Summit May 18, 2017.
What are the common reasons software development projects fail?
Description of Revision
Contents A GENERIC IT BALANCED SCORECARD
Fix it or Forget it? Dealing with Troubled Projects
Utilizing Internal Audit Metrics to Advance Your Department
IS&T Project Reviews September 9, 2004.
Service Development at Aalto University Key Enabler for Aalto's Academic Mission Mari Svahn.
Deloitte & Touche November 2018.
Effective Project Management: Traditional, Agile, Extreme
Presentation transcript:

Improving System Development Project Success: How Internal Auditors Add Value Through Process Involvement & Measurement Glen L. Gray, California State University, Northridge, USA Anna H. Gold, VU University, The Netherlands Christopher G. Jones, California State University, Northridge, USA David W. Miller, California State University, Northridge, USA EAA 2011: Rome, Italy

2 Overview Background –SDP failures and the dismal rate of SDP success –Control issues Research objective –Internal auditor’s role in SDP success Research questions, methods, and summary of findings

3 Many SDP failures… December 2002: McDonald’s abandons major project after two years. Cost: US$170 million November 2004: Sainsbury (UK super- market chain) writes off a £260 million IT investment in its supply chain February 2008: Los Angeles Unified School District’s faulty US$95 million payroll system goes live. For months afterward, thousands are overpaid, underpaid, or not paid at all. November 2010: FBI spent $405 million of the $451 million budgeted for new Sentinel case-management system, but, as of September, it’s two years behind schedule and $100 million over budget

4 Few SDP Successes… Standish Group Standish Group [2009]

5 Costly Conundrum How do failing or challenged projects go undetected? Where were the ‘red flags’? –Missed, dismissed, or ignored all together? Who’s responsible for monitoring the controls and raising these red flags?

6 Research Objective To explore how internal auditors currently do and potentially can provide value-added support to proactively help identify and monitor system development project controls to either:currently –Help get these projects back on track toward success or –Stop projects when the investment in the projects is still relatively low

7 Post-SOX Changes? Pre-SOX: internal auditors usually came into a system development project after the project was completed to evaluate the internal controls—bayoneting the wounded Post SOX: internal auditors are more frequently active members of major system development projects, but— –auditor focuses on controls for the specific processes being automated, not the system development controls Gray [2004, 2007]

8 Research Questions RQ1: When and how should internal auditors become involved in SDPs? RQ2: For which factors critical to system success can internal auditors add the most value? RQ3: What metrics should be used to monitor SDPs?

9 Mixed-mode Research Method 1.Review IS and internal auditing literature CSFs and CFFs 2.Conduct internal auditor focus groups exploring RQ1 – RQ3. Qualitative 3.Develop CSF taxonomy from an internal auditing perspective Qualitative 4.Survey a sample of The IIA membership Quantitative

Critical Success Factors Literately, hundreds of success/failure factors –However, many different ways to say same things From both professional and academic literature Mostly opinions/observations vs. rigors analysis Mostly not stated as measurable factor/metric (e.g., adequate user involvement) Our next task: reduce factors to manageable set. 10

Critical Success Factor Taxonomy OrganizationProject Management Externalities People 11

Critical Success Factors Project Management 1.Systems Development Methodology 2.Quality Assurance 3.Change Management 4.Monitoring SDP Process 5.Financial Management 6.Tools and Infrastructure 7.Agile Optimization Project 8.System Requirements 9.Systems Interoperability People 10.Executive Support 11.Project Personnel 12.Project Management Expertise 13.Conflict Management Organization 14.User Involvement 15.Business Alignment Externalities 16.Vendor Relationship Management 12

Summary of Findings (1) RQ 1 Internal Auditor’s Role –Waiting until post-implementation review is too late. 13 Greenberg & Murphy, 1989

Summary of Findings (2) RQ 1 Internal Auditor’s Role –It’s OK to invite yourself to the party. 14

Summary of Findings (3) RQ 2 Where Internal Auditors Add Value –Some CSFs more critical than others. Criticality transforms. 15 Internal Auditing Adds Value Contributes to Project Success Critical Success FactorRankMeanRankMean Quality assurance (PM) Change management (PM) Monitoring SDP (PM) System requirements (P) Systems development methodology (PM)

Summary of Findings (4) RQ 3 Monitoring SDP Success –Metrics abound but dashboards uncommon. –Conventional wisdom evolving. 16 Old Conventional Wisdom New Conventional Wisdom Internal auditing should primarily focus on application controls Internal auditing should also focus on SDP controls

Internal Auditor Involvement Three basic approaches to the auditor’s involvement in SDPs: –Auditor approach would be the more traditional auditing function by monitoring the SDP on a milestone basis to monitor how the project is progressing on behalf of management and the board. –Consultant approach where the internal auditors are advising the SDP team on an as-needed basis regarding controls. –Embedded approach where internal auditors are integrated in the SDP team functioning as the control experts. 17

Internal Auditor Involvement 18 [Large] Internal Audit Department Size [Small] Embedded Consultant Auditor [Audit] IT Skill Portfolio [IT]

The Final Survey Question Q: What is the one best way for internal auditors to improve the success rate of SDPs? A: “Be included, be involved, and participate regularly in the process from project inception.” 19

Questions? Thank You! Grazie Mille! Glen L. Gray Anna H. Gold Christopher G. Jones David W. Miller ]