Friday, August 26, 2011

A Walk to the Pub... An Internal Auditor's Commitment to find a Cure

The following article was written and contributed by a dear friend and Internal Audit Colleague. As he is nearing a milestone birthday, he is making a personal commitment to help those who suffer from ovarian cancer. Here is his story, please help him if you can:


September 2nd will be my forty-tenth birthday, so I've decided to take a walk to the pub for a pint of beer. Let me tell you why.....


Amanda heard the silent killer but didn't understand what it was saying. Trouble was, nor did some of her doctors.

My wife learnt that she had ovarian cancer in the spring of 2002. Abdominal pains; swollen stomach; unexplained infertility; this was what Amanda had heard from her body. "Gluten intolerence...irritable bowel syndrome...take these drugs" was what she heard in response from the medical community, until an investigative operation revealed the killer. But "silent"?

After a recurrence of the disease in 2004, an appearance on BBC TV's Breakfast Time show - bloated and bald from the effects of chemotherapy - to raise awareness of ovarian cancer, three major operations, twelve cycles of chemotherapy and countless hospital visits, appointments with specialists, scans, tests and other general disruptions to a normal way of life, Amanda's consultant declared her "cured" last summer, eight years after she was first diagnosed.

Her cure wasn't just about conventional medicine though. Complementary therapies, nutritional and dietary change, and a lifestyle re-evaluation all played a role in her recovery alongside the clinical care overseen by her enlightened oncologist. (Thank you, Dr. Harper!)

Amanda was lucky to be diagnosed early. The UK has one of the worst ovarian cancer survival rates in the developed world.

So I've decided to raise money for Ovarian Cancer Action (and celebrate my 50th birthday!) by going for a pint of beer.....in Britain's most remote pub!

The Old Forge at Inverie on the Knoydart peninsula is accessible by boat from Mallaig, at the end of the road and railway line west from Fort William. But I’m not going by boat. On September 1st, my last-ever day as a forty-something, I will set out alone on foot from Glenfinnan to trek across 28 miles of some of the wildest and most remote terrain in the Western Highlands of Scotland. By the end of the day I aim to reach a remote bothy (a basic stone shelter), 12 miles to the north, where I shall spend the night. The following morning, as a 50-year old(!), I will head west to cover the remaining 16 miles to Inverie where I shall enjoy my birthday pint (or pints!) of beer in The Old Forge. And then collapse in the Bunkhouse!!!

Don't expect a running commentary from me en route though. There's no mobile phone coverage where I'm going. As one account of the route puts it: "If you break a leg, you crawl to a stream (for water), wrap up warm, and wait."

I'm doing this because of Amanda, not for her. I want to help Ovarian Cancer Action fund critical research and raise awareness that the "silent" killer can be heard. I'm doing this for your wife, mother, sister, daughter, grand-daughter.....so that hopefully they can choose to go on journeys that will have happy endings (like a pint of beer!), rather than be forced by the silent killer onto a journey that more often than not, won't.

I'm looking forward to my pint of beer in The Old Forge. And it's your round. Please spare the price of a pint (or several!) for Ovarian Cancer Action.

Thanks for taking the time to visit my JustGiving page.

Donating through JustGiving is simple, fast and totally secure. Your details are safe with JustGiving - they'll never sell them on or send unwanted emails. Once you donate, they'll send your money directly to the charity and make sure Gift Aid is reclaimed on every eligible donation by a UK taxpayer. (Non-UK taxpayers can also donate with JustGiving.) So it's the most efficient way to donate - I raise more, whilst saving time and cutting costs for the charity.

So please dig deep and donate now.




This blog post was written by Peter Seyderhelm. Peter is an Internal Audit, Risk, Compliance and Corporate Governance professional in London, UK. If you would to contact Peter, you may reach him through this blog or his LinkedIn Profile.

Friday, August 19, 2011

In Business We Must "Jiggle the Gate" - Lessons From the Air and Water Show and the Home


Today, as the jets are flying over Chicago (and my office – how cool is that?) practicing their maneuvers for the annual Chicago Air and Water Show this weekend, I am reminded of two things:

1 – The importance of effective internal control systems

2 – The importance of monitoring those internal control systems


It doesn’t take an aerospace engineer to understand that while flying in tight formation a pilot must be constantly aware of his position relative to the other aircraft in the formation. One false move by any of the pilots would spell disaster for everyone. Fortunately they have computer systems in the cockpit that continuously calculate time, space, distance (i.e. internal control system) and a built in warning system alerting them when things are going wrong (i.e. monitoring). However, it is up to the pilot to react to these indicators to avoid disaster. It is pretty amazing to me that all of this works, considering they are flying at speeds over 500 mph and at a distance of 18 inches apart from each other. Heck, I find it difficult jogging next to someone who is only 18 inches away from me – I can almost guarantee we’d bump into each other – but not these pilots. Amazing!

Well, effective internal controls systems and monitoring the internal control systems is important in other places too. Parents of toddlers know all about internal control systems (gates around staircases, plastic covers over door knobs, protective covers over electric outlets…) and monitoring systems (you can’t leave a toddler alone, right? and when you do there is technology for to help - it is called a baby “monitor” after all!). How about pet owners? Do you think they know a little about internal control systems and monitoring? Absolutely.

My business is helping organizations evaluate their systems of internal controls and also the effectiveness of the internal control monitoring. It is as important in a corporation as it is in an airplane and as it is in the home. Can you think of an example of when there have been breakdowns in either the internal controls or the monitoring of those controls in business? You probably don’t have to think too hard. It has happened all too often and unfortunately it continues today. Sometimes it is a fundamental breakdown in internal control, sometimes it is someone circumventing internal control, and other times it is a failure to monitor the control. When done purposely or with malicious intent it is usually for a perceived short term gain (meeting quarterly earnings, making a bonus) at the expense of the long term.

The examples in the corporate world have been discussed and evaluated over and over and over. It cost many their jobs and many more their life savings. But business is not alone in this. If you happen to be a college sports fan, the recent examples of Ohio State (my alma mater) and this week the University of Miami (FL) are shining examples of failure to monitor internal controls systems, ignoring warning indicators, and/or circumventing internal controls systems… all for short term gain at the expense of long term success.

Why have internal controls and effective monitoring systems? Well, besides all the obvious reasons, it is simply the right thing to do. It is important to protect our pilots, protect our children, protect our pets, protect our investments, protect our reputations, and protect our chances at long-term success. However, it is not enough to simply design and implement a good system of internal control. You have to TEST it! Imagine installing a baby gate at the top of a staircase. When finished installing the natural instinct is to jiggle it to make sure it is stable, right? Who would install a baby gate and not test it? And, for good measure you would test it regularly. You could do a great job in creating the control (installing the gate), a great job in monitoring the control (checking regularly to make sure it is still there), but if you don’t test it (jiggle the gate) you could fail as a parent with catastrophic consequences.

When enacted in 2002, the Sarbanes-Oxley Act created the requirement for publicly traded companies to design, monitor, and test systems of internal controls. However, most private companies and private institutions are not held to such standards. While “it is the right thing to do” many private companies ignore the need for internal controls and many more fail to test. If you are reading this and work for a private organization (heck, any organization) think about how often your organization “jiggles the gate” when it comes to the financial reporting processes, information technology, security, privacy, policy and procedures, and operations. If you really think about it, you might not like the answer. A small investment each year to design controls, monitor controls, and “jiggle the gate” will go a long way to protect your opportunity for long-term success.

Effective systems of internal controls are critical to all of us in every walk of life. It is important in the cockpit, at home, in the classroom, and yes, in the workplace. So, do yourself a favor and go “jiggle the gate!”

For those of you in Chicago, I hope you enjoy the Air and Water Show this weekend!



This blog post was written by Steven Randall. Steve is a Managing Partner with Vonya Global, a premier provider of internal audit consulting services. If you would like more information about Vonya Global or if you have a questions for Steve, you may him through this blog, the company website, twitter, or his LinkedIn Profile.

Friday, July 15, 2011

Information Risk Management Topics and Trends for Internal Auditors and Audit Committees - a Vonya Global Web Seminar


As the old adage goes, “Information is Power.” It is undeniable that the company with the best information has an advantage. Access to information impacts every decision a company makes from long-term strategic planning, to which suppliers to use, to which markets to serve, to which employees to hire or promote, all the way down which paperclips to order.

On the flip side, losing information can do more damage than having it in the first place. Competitive advantages can be lost, privacy can be violated, security can be threatened, and reputations can be ruined. It is critical to understand and manage the risks to information and unfortunately it is getting harder each day.

On August 18, Vonya Global will be hosting a one hour web-based seminar on Information Risk Management and the latest trends that have Chief Information Risk Officer’s concerned. The presentation is geared towards the Internal Audit and Audit Committee communities and will cover:
  • Consumerization of IT
  • Cloud Computing
  • Mobile Security
  • Social Media
To capture the potential these new technologies offer, companies need to embrace the opportunity while balancing solid risk management. We invite you to learn about these technologies and what they mean from an Information Risk Management perspective. If you are in the Internal Audit profession or seated on an Audit Committee, you should attend this session.



To register please visit http://www.vonyaglobal.com/ and follow the link to the session.


Tuesday, July 12, 2011

Board Director and Audit Committee Member Independence

Audit Committee Member independence as it relates to SOX section 301 definitions and SEC Rule10A-3 (specifically the definitions of “affiliate” and “affiliated person”) proves to be an area clouded by many shades of gray. In short, a clear and explicit definition of an “affiliated person” or “affiliate” is not defined. Rather, what is provided is a safe harbor definition suggesting that an individual is not an “affiliated person” if that person:
  • is not an executive officer and,
  • does not own more than 10% of the company stock.
Although this specific definition applies to ownership of securities, determining if a Director is an “affiliated person” appears to require more than that initial look.

What the rules are as of now.
Under SEC Rule 10A-3, all issuers must be in compliance with SOX Section 301 in order to be listed on any securities exchange. Specifically, they require each member of the Audit Committee of the issuer must be independent. The requirements establish two criteria and allow for each exchange to make more strict rules of their own:
  • Audit committee members are barred from accepting any consulting, advisory or compensatory fee from the issuer or any subsidiary thereof, other than in the member’s capacity as a member of the board and any board committee.
  • An Audit Committee Member of an issuer that is not an investment company must not be an affiliated person (see definition of “affiliate” below) of the issuer or any subsidiary apart from the member’s capacity as a member of the board or any board committee.
To answer the question about an “affiliated person”, the definition of an affiliated person by the SEC is “a person that directly, or indirectly through one or more intermediaries, controls or is controlled by, or is under common control with, [the issuer]”. The SEC defines control as “the possession, direct or indirect, of the power to direct or cause the direction of the management and policies of a person, whether through ownership of voting securities, by contract or otherwise”. Finally, as part of the definitions by the SEC, they have provided a baseline determination for what may or may not be an affiliate by providing a safe harbor under which a person who is not an executive officer and is not a greater than 10% stockholder is not deemed to control the issuer, therefore not an “affiliated person”.

Based on many discussions and information, other than the safe harbor definition, clear or explicit requirements for who is defined as an “affiliate” are not provided. Rather, the determination of whether a person falls within the category of an “affiliate” requires a factual determination based on a consideration of all relevant facts and circumstances on a case by case basis by the Board. These facts and circumstances would look deeper into the relationship to determine if control or influence exists or whether interference with judgment may occur.

Given the impossibility of defining all the relationships with a company that may arise for Directors and Director candidates, we believe it is advisable that Boards retain discretion to decide independence on a case by case basis rather than use rigid standards.

However, if a company is looking to define or add more explicit language for the definition of an affiliated person, you can look beyond the SEC rules and Sarbanes Oxley to rules established by the national exchanges and other professional associations (e.g. NYSE, NASDAQ and NACD) where more strict independence requirements. These requirements although not explicitly defining “affiliate” look deeper into the relationships of the Board Directors and Audit Committee Members, including:
  • NYSE – “No material relationship.” Under the NYSE listings, no director qualifies as independent unless the board of directors affirmatively determines that the director has “no material relationship” with the listed company, either directly or as a partner, shareholder or officer of an organization that has a relationship with the company.
  • NASDAQ – “No interference with independent judgment.” The rules provide that an independent director is a person other than an officer or employee of the company or its subsidiaries or any other individual having a relationship that, in the opinion of the company’s board of directors, would interfere with the exercise of independent judgment in carrying out their responsibilities of a director.
  • NACD – “The strictest definition of the term is a director whose only connection to the company is the receipt of director fees.”
If an organization is looking to define independence in the strictest sense, then the NACD definition would fit best; however, based on our experience and knowledge, most Boards follow listing standards of the national exchange for which they belong. In addition to the exchange definitions, they also allow their Boards the discretion to make judgment on member independence on a case by case basis.


This post was contributed by Sargon Youmara, a Partner with Vonya Global. If you would like to contact or connect with Sargon directly you can find his profile on LinkedIn: http://www.linkedin.com/in/syoumara.

Wednesday, June 1, 2011

The GRC Approach - for Small Internal Audit Departments

Governance, Risk and Compliance (Part 2)

First identify all of the functions and/or groups that interact with the area subject to assessment. Then through interviews and evaluation determine the following:
  • Governance: the goal, mission and objective of the program.
  • Risk: the risks that are being managed by each of the functions and groups involved.
  • Compliance: the rules, regulations, internal policies, the operating procedures that influence the operating activities. In this space it is also necessary to identify all of the tools, people, and resources available in support of the compliance efforts.
Once determined, you can assess whether the various functions are aligned as to the Governance mission and objective, you can determine if they are operating against a common set of Risk factors and you can evaluate whether the Compliance efforts are operating cohesively across all groups and whether resources are being deployed to effectively address each of the compliance requirements.

This evaluation is then used as the springboard to development of a high level summary regarding the cohesiveness of the company’s GRC activities across the multiple disciplines subject to review.


This post was contributed by Brad Zolkoske. Brad is the Director of Internal Audit at International Coal Group. He is responsible for the design, development, coordination and communication of auditing services throughout the company. Brad’s number one goal at International Coal is to establish a professional internal audit function that actively supports the company’s growth and culture initiatives.

During the course of his 20 year internal audit career Brad has worked in internal audit management for several publicly traded manufacturing companies. He is an expert at getting exceptional performance out of small audit departments. Brad can be contacted through this blog or through his LinkedIn profile.

Tuesday, May 24, 2011

When does GRC Fit within a Small Audit Shop?

Governance, Risk and Compliance (Part 1)

Governance, Risk and Compliance (GRC) is the latest and greatest hot topic being thrown at Internal Audit functions. But what really is the place for GRC in the profession today? Having been bombarded with Risk Management literature and programs for many years and those programs appearing to still be in their embryonic state, what confidence is there to be had in the GRC initiative?

As it turns out, there is a practical application for GRC in the world of Internal Audit. Certain cross-functional audit projects can greatly benefit from a GRC perspective. When faced with a large project across multiple disciplines, divisions, regions or operating groups the GRC model can provide a structure for evaluating the control environment in a manner and perspective that should appeal to senior management’s vision of the organization.

Stay tuned for Pat 2 of the GRC for Small Internal Audit Departments.


This post was contributed by Brad Zolkoske. Brad is the Director of Internal Audit at International Coal Group. He is responsible for the design, development, coordination and communication of auditing services throughout the company. Brad’s number one goal at International Coal is to establish a professional internal audit function that actively supports the company’s growth and culture initiatives.

During the course of his 20 year internal audit career Brad has worked in internal audit management for several publicly traded manufacturing companies. He is an expert at getting exceptional performance out of small audit departments. Brad can be contacted through this blog or through his LinkedIn profile.

Wednesday, May 18, 2011

Internal Audit Departments and Building a Definition of Risk

Internal Audit Departments today are constantly told to be "risk based" and to assist their companies in the management of risk. While this sounds great in concept, the execution is a different manner as many companies today do not have a formal risk management program with which to align. When tasked with developing such programs Internal Audit should not fall into the trap of developing a population of risks before first arriving at a common definition of risk.

Understanding how your company views risk is a good place to start. Is risk viewed as good or bad? Remember, risk is not just a negative; the presence of risk presents the possibility of reward as well as loss. In looking at risk as both a positive and negative, Internal Audit Departments will better align their risk activities with the thoughts and strategies of management.

This definition, once developed, can then allow Internal Audit Departments to evaluate risks and risk management activities to determine if the potential for success warrants the risk being taken; to assess whether the risks being taken are aligned with corporate values, goals, objectives, policies and management capabilities; and to determine whether the culture of your organization is strong enough to allow for a legitimate discussion about risk events that haven’t yet happened.


This post was contributed by Brad Zolkoske. Brad is the Director of Internal Audit at International Coal Group. He is responsible for the design, development, coordination and communication of auditing services throughout the company. Brad’s number one goal at International Coal is to establish a professional internal audit function that actively supports the company’s growth and culture initiatives.

During the course of his 20 year internal audit career Brad has worked in internal audit management for several publicly traded manufacturing companies. He is an expert at getting exceptional performance out of small audit departments. Brad can be contacted through this blog or through his LinkedIn profile.