Current Campaign


Latest Archives

  1. August 23, 2010 Getting Serious about Risk Monitoring Posted in: Daily News with: 0 comments

  2. August 17, 2010 Y211? And other Risks . . . Posted in: Daily News with: 0 comments

  3. August 10, 2010 Video Spills on Government Fraud Posted in: Daily News with: 0 comments

  4. August 5, 2010 Re-Inventing the Internal Auditor? Posted in: Daily News with: 0 comments

  5. August 3, 2010 The Guidance Gauntlet Posted in: Daily News with: 0 comments

  6. July 30, 2010 Stopping the Spreadsheet Scourge Posted in: Daily News with: 1 comment

  7. July 21, 2010 Robbing Risk Management to Pay Receivables Posted in: Daily News with: 0 comments

  8. July 15, 2010 Trailblazing Uncle Sam Posted in: Daily News with: 0 comments

  9. July 13, 2010 CCM Momentum Posted in: Daily News with: 0 comments

  10. July 8, 2010 Introducing Approva One On Demand Posted in: Daily News with: 0 comments

Recent Articles

The Four Tiers of a Successful Compliance Protocol

Posted on January 8th, 2008 by Steve Elliott »Permalink

We at Approva like to talk about how important it is to have cross-functional, cross-application controls monitoring solutions – how crucial it is to ensure that risks are monitored and addressed across disparate job functions and varied ERPs.

In order to illustrate exactly how this works, I thought it might be useful to outline the tiers of software within an ideal compliance system – the risks monitored, the stakeholders alerted, and the impacts on business processes beyond compliance.

Ideally, a comprehensive compliance environment consists of four tiers – enterprise risk dashboarding, risk policy and procedure management, controls collection/correlation, and automated controls testing and monitoring. When organizations are able to implement these effectively, and ensure that each tier works with the others, you can be confident that risks are being assessed, detected, monitored and mitigated – and that overall business effectiveness is positively impacted.

The top tier is dashboarding to different personas – the CFO, controller, internal audit manager, or IT managers who need visibility into controls. This tier takes low level information being tested and correlates it across multiple systems to identify gaps large enough to merit CXO awareness and involvement.

The second tier is risk policy and procedure management – essentially, where the rules of the game are documented. In this tier, the organizational structure is defined, along with what is being analyzed and by whom. This tier enables stakeholders to assess risk by region, business unit, or other variables – and enables them to make sense of risk. This tier also incorporates documentation policies and defines responses to everything from loss event investigation to hotlines for whistle-blowers to risk analytics.

The third tier controls collection and correlation. This tier orchestrates the testing scheduling and normalizes results across the landscape for consumption by the risk and controls repository.

The final layer of software compliance environment is automated controls testing and monitoring. This tier enables continuous automated testing of application, process and system controls within the ERP, as well as other layers of the IT stack like database, OS, network, email and spreadsheets. As far as the business world has come in recent years, the fact is that good deal of businesses to this day manage important business functions in uncontrolled tools like Excel, which leaves considerable room for error. Automated application testing helps companies to address this kinds of risks.

If an organization can bring these four tiers to work together, you can be confident that you’ve done a thorough job managing disparate risks across an enterprise. No software solution is perfect, and an organization is only as compliant as its people – but this is heck of a start.

— Steve Elliott, Chief Technology Officer

Tags: , ,

Bookmark and Share

3 Responses

Leave a Reply