You are on page 1of 18

ACL Solutions for Continuous Auditing

and Monitoring

John Verver CA, CISA, CMC


Vice President, Professional Services & Product Strategy
ACL Services Ltd
ACL Services Ltd.

Copyright © 2008 ACL Services Ltd. 2

Continuous Auditing and Monitoring:


Where are we? Where are we going?

• ACL has 11,000+ user organizations globally

• 33-40% of organizations consider they perform some form of


Continuous Auditing

• Chief Audit Executive surveys indicate Continuous Auditing and


Monitoring usage will more than double by 2012
ACL Services Ltd.

Copyright © 2008 ACL Services Ltd. 3

Continuous Auditing – ACL’s Experience

• Wide variation in CA approach and techniques

• CA part of a continuum of analytic usage

• Flexibility is key
ACL Services Ltd.

Copyright © 2008 ACL Services Ltd. 4

Continuum of Audit Analytics

• Automated analyses and • Continual execution of


• One-off analysis and tests automated audit and
testing • Managed and deployed monitoring tests to
from a central identify errors, fraud and
environment anomalies on a timely
basis

24
7
365

ad hoc repetitive continuous


ACL Services Ltd.

Copyright © 2008 ACL Services Ltd. 5

Continuous Auditing: Issues to Address

• Data access and management


• Quality and control
• Sustainability and productivity
• People and process
ACL Services Ltd.

Copyright © 2008 ACL Services Ltd. 6

Enabling the Continuum of Audit Analytics

A MANAGED ANALYTICS PLATFORM for AUDIT


Secure controlled access to data
Configuration, automation and scheduling of tests
Management of tests, documentation, findings, logs, workflow
One common platform

24
7
365

ad hoc repetitive continuous


ACL Services Ltd.

Copyright © 2008 ACL Services Ltd. 7

Query & Analysis


Reporting & • In-depth analysis
• Audit-specific commands & scripting
Presentation • Advanced analytics and predictive modeling
• Centralized logging

Management & Automation


Query & Analysis • Audit repository
• User access & rights, data security
• Centralized tests and processing
• Continuous auditing management
Analytic • Configuration & management
Library
Data Access
• Access, extract, transform, load
Management • Specialized format connectors
& Automation • Audit data repository

Reporting & Presentation


• Templates, charting
• Dashboard integration
Data Access • Report deployment and maintenance

Analytic Library
• Packaged analytics, key business
processes
ACL Services Ltd.

Copyright © 2008 ACL Services Ltd. 8

Audit Analytics Repository


Management & Automation
• User access & • Scheduling • Search
rights • Administration • Security

Data Analytics Findings & Results


• Data sets for each audit • Test library • Results management
area • Test documentation • Specific findings
• Data dictionaries • “Best Practices” • Logs & other documentation
• Data management & refresh documentation
ACL Services Ltd.

Copyright © 2008 ACL Services Ltd. 9

Populating and Refreshing the Audit Data Repository

• INFORMATICA for ACL AuditExchange


o Industry leading technology for ETL (Extract Transform Load)
o Connectors for any enterprise data
 PowerCenter:
 Flat files, delimited text, XML, Access, Oracle, Sybase, Teradata, ODBC, Informix, SQL
Server, dBase
 B2B Complex Data Exchange:
 PDF, XML, XBRL, Excel
 PowerExchange
 Specialized data formats – HIPPAA etc

• ACL Data Access, including Direct Link for SAP


ACL Services Ltd.

Copyright © 2008 ACL Services Ltd. 10

ACL: Continuous Auditing and Continuous Monitoring

• ACL AuditExchange
o Enables Best Practices in Audit Analytics
o Provides a secure, controlled, well-managed and sustainable environment for the
continuum of Audit Analytics – Ad Hoc through Continuous Auditing
o Provides benefits of Audit Analytics to the entire audit team, according to roles
o A reliable environment for Continuous Auditing

• ACL Continuous Controls Monitoring


o Provides management and audit with insight into control effectiveness
o Monitors all transactions throughout business process cycles
o Tests against suites of control rules
o Identifies and quantifies exceptions on a timely basis
o Supports exception resolution and control remediation
o Configuration and management of the monitoring process
ACL Services Ltd.

Copyright © 2008 ACL Services Ltd. 11

ACL Continuous Controls Monitoring Technology


Framework
ACL Services Ltd.

Copyright © 2008 ACL Services Ltd. 12

ACL CCM Product Suite

• Continuous testing of transactions in core business process


areas against sets of internal control rules

Purchase to Pay Procurement Card


Travel & Entertainment Payroll
Order To Cash General Ledger
ACL Services Ltd.

Copyright © 2008 ACL Services Ltd. 13

ACL CCM Product Suite

• Browser-based interface:
o Manage Continuous Monitoring process
o Security and Administration
o Manage test parameters
o View, report and manage exceptions
ACL Services Ltd.

Copyright © 2008 ACL Services Ltd. 14

ACL CCM Product Suite – Large Enterprise Version

• Advanced capabilities for complex large scale enterprise monitoring


• For 10+ control entities:
o Enhanced multi-entity configuration
o Enhanced multi-entity parameter management
o Enhanced workflow and remediation
ACL Services Ltd.

Copyright © 2008 ACL Services Ltd. 15

ACL Enterprise Continuous Monitoring at

• ACL audit analytics used for many years in Siemens entity


internal audit organizations
• Siemens Power Generation one of first organizations to
implement ACL CCM Purchase to Pay 2004
• 2008 implementation of ACL Continuous Monitoring – Large
Enterprise Version for Purchase to Pay systems across entire
Siemens enterprise
• Believed to be largest purchase-payment transaction monitoring
project in the world
ACL Services Ltd.

Copyright © 2008 ACL Services Ltd. 16

Enterprise Controls Monitoring at Siemens

Scale
• All corporate entities (currently 900+)
• All Purchase to Pay transactions
• Daily with 90 days running history
• 27 control tests
• 275 different data sources & applications
• Average 5GB of source data analyzed per entity
• Primary integration environment: analysis of 200GB data for
~400 entities
ACL Services Ltd.

Copyright © 2008 ACL Services Ltd. 17

Enterprise Controls Monitoring at Siemens

Exceptions: workflow process


• Process managed by entity business owners
o review all exceptions
o assign appropriate category
• Unresolved exceptions automatically escalated through multiple
CFO levels
ACL Services Ltd.

Copyright © 2008 ACL Services Ltd. 18

Questions?

Contact: john_verver@acl.com

You might also like