Guest Blog by Michael Rasmussen, Research Analyst at GRC 20/20 Research
Business today is changing minute-by-minute and second-by-second. Processes and technology and their configurations are changing. Employees and their access into systems are changing as they are hired, change roles, inherit rights, and ultimately leave the organization. Transactions and vendors are changing. The pace of change in business today requires new approaches to control automation.
Control monitoring and testing in the past involved random sampling, an approach that is dated and out of step for the dynamic nature of business today. Random sampling and monitoring of controls only cover a small fraction of the configurations, master data, segregation of duties/access rights, and transaction controls in an organization’s environment. Manual processes for control monitoring that focus on random sampling leaves the organization with a false sense of control where, in reality, there can be significant control issues that expose the organization to malicious and inadvertent issues and events.
Random sampling of controls results in:
Dynamic business today requires 360° awareness and insight into controls. Manual processes focused on random sampling are a thing of the past and leave the organization to exposure and a false sense of control. It is time for organizations to consider full control automation across configuration, master data, transactions, and access in their systems. This allows for:
Don’t miss the upcoming Webinar How to Achieve an Integrated & Continuous Approach to Managing Controls on March 4th. Click here for more information and to register.
Share
There is no escaping risk in today’s multi-application la...
The Securities and Exchange Commission's (SEC) new rules on...
The global shortage of skilled accountants has been making ...
Esteemed Colleagues in Internal Audit and Risk Management: ...