Vonya Global is surveying a cross-section of Executives and Internal Auditors from both public and private organizations in a variety of industries to evaluate their opinions regarding the strategic role of internal audit. This is a follow up study to one conducted in 2008. The results of the 2008 study revealed a expectation gap in the strategic role internal auditors play in their organizations. This follow up study will compare how expectations may have changed in light of continued risks of fraud, financial statement errors, environmental risks, security breaches, and privacy concerns.
One executive from the previous study stated the following: "Internal Audit could improve its capabilities in evaluating the effects of strategic and business risk on the overall risk profile of the Company. This would also enhance the primary mission of internal audit to look for potential financial issues.” This statement, along with many others, reveal the importance of internal audit becoming more than a financial compliance function. The results of this new study will highlight whether or not internal audit has taken steps in this direction.
To participate in the study, please visit the Vonya Global website: http://www.vonyaglobal.com
Vonya Global is an international consulting firm specialized in internal audit and enhancing corporate governance. (www.vonyaglobal.com)
We would love to get your feedback on this blog. You may also submit topics for us to consider or submit articles for us to post. We would be delighted to hear from you!
Wednesday, June 2, 2010
Wednesday, May 12, 2010
Social Media - is it Friend or Foe?
Social media is rapidly becoming a critical tool for communication not only bringing benefits, but also risks. For many organizations, social media is a vital channel for communication to customers, partners and stakeholders. However, some organizations see it as a distraction to their employees and a potential security threat and reputation risks. The key, of course, is to maximize the opportunities it presents and minimize the risks.
As an alternative to simply banning or limiting employees from using social media, organizations should understand the role that these innovative services have in today’s world. With the appropriate amount of governance, organizations can leverage social media to help reach their objectives.
In order to develop, implement, monitor and improve social media activities within an organization, an effective governance framework is imperative. A social media strategy and policy should be established followed by a risk assessment. Based on the outcome of the risk assessment, embed key controls, including an acceptable use agreement, corporate image rules and branding guidelines. Implementation of operational best practice guidelines should cover blogging and usage of popular sites such as LinkedIn, Twitter, Facebook, and YouTube.
Finally, ensure that roles and responsibilities are defined, metrics and monitoring procedures are established, and training and communication organization-wide takes place to help provide awareness and conformity.
Whether your objectives are to generate exposure for your business, increase traffic to your site, build new business partnerships or bring in new, qualified leads, benefits from social media can be realized as long as there is an effective governance structure in place to mitigate the associated risks.
As an alternative to simply banning or limiting employees from using social media, organizations should understand the role that these innovative services have in today’s world. With the appropriate amount of governance, organizations can leverage social media to help reach their objectives.
In order to develop, implement, monitor and improve social media activities within an organization, an effective governance framework is imperative. A social media strategy and policy should be established followed by a risk assessment. Based on the outcome of the risk assessment, embed key controls, including an acceptable use agreement, corporate image rules and branding guidelines. Implementation of operational best practice guidelines should cover blogging and usage of popular sites such as LinkedIn, Twitter, Facebook, and YouTube.
Finally, ensure that roles and responsibilities are defined, metrics and monitoring procedures are established, and training and communication organization-wide takes place to help provide awareness and conformity.
Whether your objectives are to generate exposure for your business, increase traffic to your site, build new business partnerships or bring in new, qualified leads, benefits from social media can be realized as long as there is an effective governance structure in place to mitigate the associated risks.
Labels:
control,
facebook,
linkedin,
Risk,
social media,
threat,
twitter,
vonya global,
youtube
Tuesday, May 4, 2010
Vonya Global is Lowering the Cost of a SAS 70 Assessment
Statement on Auditing Standards Number 70 (SAS 70) issued by the AICPA requires service organizations to obtain an external opinion assessing internal controls. Issued in 1993, the SAS 70 is not a new requirement but it has increased in relative importance since the enactment of the Sarbanes-Oxley Act of 2002 (SOX, Sarbox), Gramm-Leach-Bliley Act (GLBA), and other new regulatory requirements. Any service organization holding third party data must provide assurance that the data is protected. The certification process can be quite costly for all service organizations, and disproportionally so for smaller companies.
Vonya Global has a history of working with companies on SAS 70 readiness. The work completed by Vonya Global helps companies streamline their internal processes and controls making it easier for the certifying agent to complete the assessment. The easier it is to certify, the lower the cost of certification. As the SAS 70 is an annual requirement, the cost savings are realized each year.
For a limited time, Vonya Global is offering its SAS 70 readiness services at a discounted price. For more information please contact a representative of the firm.
Vonya Global has a history of working with companies on SAS 70 readiness. The work completed by Vonya Global helps companies streamline their internal processes and controls making it easier for the certifying agent to complete the assessment. The easier it is to certify, the lower the cost of certification. As the SAS 70 is an annual requirement, the cost savings are realized each year.
For a limited time, Vonya Global is offering its SAS 70 readiness services at a discounted price. For more information please contact a representative of the firm.
Labels:
GLBA,
Gramm-Leach-Bliley,
Sarbanes-Oxley,
sarbox,
SAS 70,
SOX,
vonya global
Monday, April 12, 2010
The New SEC Proxy Disclosure Rules and the Relationship Between the Board and Management
The way to effectively hold a company accountable for their actions is through transparency. On December 16, 2009, the U.S. Securities and Exchange Commission (SEC) approved new rules requiring public companies to increase their transparency around proxy disclosure, specifically:
• Board risk oversight practice and philosophy
• Executive compensation practices and policies
• Board leadership structure
• Board diversity
• Director qualifications and their “value add”
SEC Commentary on the rule states “Disclosure of the board’s oversight of the risk management process should provide important information to investors about how a company perceives the role of its board and the relationship between the board and senior management in managing the material risks facing the company.”
The relationship between the board and management has become of greater importance and will need to continue to strengthen.
Management is responsible for identifying, monitoring, managing, and communicating the risks to the board. As management it is important to use the time with the board and the committees to help them understand the real objective and risk exposure is in relation to the risk culture of the company. The board continually needs to access management’s understanding of risks, attitude towards risk, and their performance. Furthermore, the board must ensure that only well informed decisions are made.
Management manages risk and the board oversees management, therefore the continuous communication between the two, including the committees, is vital for success. The new proxy disclosure rules itself and any additional changes in corporate governance are going to push for continued improvement in this relationship.
• Board risk oversight practice and philosophy
• Executive compensation practices and policies
• Board leadership structure
• Board diversity
• Director qualifications and their “value add”
SEC Commentary on the rule states “Disclosure of the board’s oversight of the risk management process should provide important information to investors about how a company perceives the role of its board and the relationship between the board and senior management in managing the material risks facing the company.”
The relationship between the board and management has become of greater importance and will need to continue to strengthen.
Management is responsible for identifying, monitoring, managing, and communicating the risks to the board. As management it is important to use the time with the board and the committees to help them understand the real objective and risk exposure is in relation to the risk culture of the company. The board continually needs to access management’s understanding of risks, attitude towards risk, and their performance. Furthermore, the board must ensure that only well informed decisions are made.
Management manages risk and the board oversees management, therefore the continuous communication between the two, including the committees, is vital for success. The new proxy disclosure rules itself and any additional changes in corporate governance are going to push for continued improvement in this relationship.
Tuesday, March 16, 2010
Responding to Fraud Risk: the CAE’s Role
Background: The Association of Certified Fraud Examiners (ACFE) conducts a bi-annual study on fraud investigations, the results of which get summarized in the ACFE Report to the Nation. The most recent report was issued in 2008 and revealed the following:
- U.S. organizations lose 7% of their annual revenues to fraud
- There is approximately $994 billion in fraud losses each year
- Fraud schemes typically last for at least 2 years before they are caught
- Corruption was the #1 scheme at 27% of all reported fraud cases
- False Billing was the #2 scheme at 24% of all reported fraud cases
- Frauds are most likely to be uncovered by a “tip” rather than any other method, including audit
- Roughly 38% of Frauds happened at small companies (>100 employees)
- Roughly 42% of Frauds happened at large companies (1,000+ employees)
- Roughly 39% of Frauds happened at Private Companies
- Roughly 28% of Frauds happened at Public Companies
- There is approximately $994 billion in fraud losses each year
- Fraud schemes typically last for at least 2 years before they are caught
- Corruption was the #1 scheme at 27% of all reported fraud cases
- False Billing was the #2 scheme at 24% of all reported fraud cases
- Frauds are most likely to be uncovered by a “tip” rather than any other method, including audit
- Roughly 38% of Frauds happened at small companies (>100 employees)
- Roughly 42% of Frauds happened at large companies (1,000+ employees)
- Roughly 39% of Frauds happened at Private Companies
- Roughly 28% of Frauds happened at Public Companies
What these statistics prove is while fraud may not happen at every company; no company is immune to fraud risk. As an inherent risk to business, fraud should be included in Enterprise Risk Management (ERM). Methods for managing and controlling the risk of fraud should include strategies for fraud prevention, fraud detection, and fraud deterrence.The Chief Audit Executive (CAE) must be involved in the organizational anti-Fraud strategy. As with other business risks the CAE should be assessing Fraud Risk and evaluating the effectiveness of the anti-Fraud strategies. Here is a sample list of strategies:
Fraud Prevention
- Anti-Fraud Tone at the Top
- Strong Corporate Governance and Internal Control Environment
- Policies and Procedures to reflect mindset and actions
- Hire ethical employees (Background checks, signed forms, etc.)
- Code of Conduct – signed by every employee
- Conflict of Interest Statement (employees and business partners)
- Strong Corporate Governance and Internal Control Environment
- Policies and Procedures to reflect mindset and actions
- Hire ethical employees (Background checks, signed forms, etc.)
- Code of Conduct – signed by every employee
- Conflict of Interest Statement (employees and business partners)
Fraud Detection
- Establish a Hotline
- Fraud Risk Assessment
- Fraud Penetration Study based on Schemes and Concealment Strategies
- Incorporate Fraud in every phase of an audit (SAS 99)
- Create/utilize a Red Flags Database
- Implement effective SOX Fraud Controls
- Data mine instead of sample testing
- Create a Toolkit including a resource roster of experts (Fraud expert, Investigator, Data mining, etc.)
- Continuously Monitor Transactions for possible Fraud
- Fraud Risk Assessment
- Fraud Penetration Study based on Schemes and Concealment Strategies
- Incorporate Fraud in every phase of an audit (SAS 99)
- Create/utilize a Red Flags Database
- Implement effective SOX Fraud Controls
- Data mine instead of sample testing
- Create a Toolkit including a resource roster of experts (Fraud expert, Investigator, Data mining, etc.)
- Continuously Monitor Transactions for possible Fraud
Fraud Deterrence
- Create an Internal Audit department
- Publicize Ethics Hotline
- Publicize Internal Fraud Cases and Punishment
- Publicize Continuous Monitoring Program
- Publicize Ethics Hotline
- Publicize Internal Fraud Cases and Punishment
- Publicize Continuous Monitoring Program
Vonya Global and the ACFE are not affiliated. Information in the opening paragraph is sourced from the ACFE 2008 Report to the Nation, which can be downloaded at the ACFE website.
Wednesday, January 6, 2010
NACD Directorship names its Top 50 Companies
The National Association of Corporate Directors magazine, "Directorship", has recently released its list of the top 50 "Best Performing, Best Governed Companies in the Fortune 500." Vonya Global applauds the publications effort to recognize the companies which place an emphasis on Corporate Governance, Ethics, Integrity, and Citizenship. There are hundreds of lists that rank companies based on revenue, profit margin, growth potential, and many other financial and non-financial metrics, but this is the first (and only that we know of) that includes these other, arguably more important metrics to the evaluation equation.
The top rated company in the "Nifty Fifty" was Goldman Sachs and their CEO, Lloyd Blankfein, was named the "Directorship" CEO of the Year. Our heartfelt congratulations goes out to Mr. Blankfien and all the other companies which made it on the list.
The article stated: "A great employer posts poor earnings or a great profit maker is not a terrific corporate citizen. These facts suggested that something should be done to recognize companies that are both far sighted in terms of corporate governance and producing returns for their shareholders."
The top rated company in the "Nifty Fifty" was Goldman Sachs and their CEO, Lloyd Blankfein, was named the "Directorship" CEO of the Year. Our heartfelt congratulations goes out to Mr. Blankfien and all the other companies which made it on the list.
Vonya Global and the NACD are not related organizations
Labels:
citizenship,
corporate governance,
ethics,
integrity,
NACD,
vonya global
Tuesday, December 29, 2009
The 2009 Ponzi Collapse
The great recession of 2009 brought with it 4 times the annual average of Ponzi scheme collapses (according to an AP report). Headlined by Bernie Madoff's $50 Billion blowout, there were over 150 Ponzi's revealed in 2009 compared to around 40 in 2008.
Was the Ponzi collapse a result of better governance or stricter enforcement? No. The economic situation created conditions which made it impossible for the schemes to continue. We still need better corporate governance, enhanced enforcement, and improved detection.
Was the Ponzi collapse a result of better governance or stricter enforcement? No. The economic situation created conditions which made it impossible for the schemes to continue. We still need better corporate governance, enhanced enforcement, and improved detection.
Subscribe to:
Posts (Atom)