1 / 9

Continuous Monitoring and Gaining External Audit Reliance

This article explores the opportunity for organizations to establish key groups to govern risk and measure compliance, who, along with the external auditor, form an interdependent compliance community. By moving towards a continuous monitoring approach, organizations can create a better control environment with much less investment and expense than today’s environment. The article outlines a methodology and tools for continuous control monitoring.

Télécharger la présentation

Continuous Monitoring and Gaining External Audit Reliance

An Image/Link below is provided (as is) to download presentation Download Policy: Content on the Website is provided to you AS IS for your information and personal use and may not be sold / licensed / shared on other websites without getting consent from its author. Content is provided to you AS IS for your information and personal use only. Download presentation by click this link. While downloading, if for some reason you are not able to download a presentation, the publisher may have deleted the file from their server. During download, if you can't get a presentation, the file might be deleted by the publisher.

E N D

Presentation Transcript


  1. Continuous Monitoring and Gaining External Audit Reliance

  2. The Opportunity Post SOX organizations are inclined to establish key groups to govern risk and measure compliance across the company, who with the external auditor form an interdependent compliance community: Assess risk Assure internal controls Committed to operational excellence, solid metrics for measuring the process and continuous improvement. We believe that with some additional focus and prioritization, that these organizations can move to a continuous monitoring approach and create a better control environment with much less investment and expense than today’s environment. Continuous Monitoring will allow for far fewer audits and more risk coverage.

  3. The Approach Build toward a common compliance strategy Model and measure in aligned segments Link monitoring activity to assertions and objectives Use audit engagements to determine specifications Collect persuasive detail through the monitoring applications Establish a solid methodology to accompany the metrics to reach a conclusion

  4. Model and Measure in Aligned Segments Compliance Community Continuous Control Monitoring Tools and Methodology IT Operations Risks Application Risks Financial Process Risks GAIT Principles ITIL Processes Transaction Processing • Change Management • Security • Availability • Release & Config Mgt • Identity Management • Incident Management • Configurable Controls • Exception Data Accepted Assurance Frameworks

  5. Link Monitoring Activity to Assertions and Management Objectives Assertion: Completeness Assertion: Existence / Occurrence Assertion: Valuation / Measurement Financial Processes Applications & Databases Operating Systems GAIT Principles Control Objectives ITIL Processes • Accuracy • Authorization • Completeness • Change Management • Security • Operations • Release & Config • Identity • Incident Handling

  6. SAP_ALL Comparison Across Similar Applications (June 2008 – Sept 2008) Investigate

  7. SAP_ALL Comparison Across Similar Applications (June 2008 – Sept 2008) Investigate

  8. SAP_ALL Details for APL – September 2008

More Related