Standardizing Your Compliance Activities to Implement Data Analytics - - PowerPoint PPT Presentation

standardizing your compliance activities to implement
SMART_READER_LITE
LIVE PREVIEW

Standardizing Your Compliance Activities to Implement Data Analytics - - PowerPoint PPT Presentation

Standardizing Your Compliance Activities to Implement Data Analytics and RPA #AuditBoardWebinars Jason Sechrist Director of Audit and Compliance Solutions AuditBoard Former Head IT Compliance and Internal Audit Volunteer Board/Audit


slide-1
SLIDE 1

#AuditBoardWebinars

Standardizing Your Compliance Activities to Implement Data Analytics and RPA

slide-2
SLIDE 2

Director of Audit and Compliance Solutions AuditBoard

Jason Sechrist

Former Head IT Compliance and Internal Audit

Volunteer Board/Audit Committee Member

16 years of IT Security Experience

PwC / IT Risk Assurance / IT Consulting

USAF Weather Systems

slide-3
SLIDE 3

3

Learning Objectives

▪ Define and differentiate data analytics, robotic process automation, and AI ▪ Discuss best practices to standardize compliance activities in preparation for implementing RPA ▪ Understand how to leverage Data Analytics & RPA in IT Compliance to eliminate manual, redundant compliance activities, and improve

  • verall efficiency and quality for control

activities

slide-4
SLIDE 4

Define and Differentiate Data Analytics, Robotic Process Automation, and Artificial Intelligence

slide-5
SLIDE 5

5

Leveraging digital capabilities is a popular topic for internal audit teams, but many struggle to identify the right capability to use.

slide-6
SLIDE 6

6

There are several key considerations when selecting what controls are eligible for analytics or automation.

slide-7
SLIDE 7

7

With increased demand on the IA function, RPA and analytics present great opportunities to create efficiencies and drive value but often fall short of providing the anticipated value.

slide-8
SLIDE 8

8

Companies are realizing significant value from adopting innovative technologies and insight tools.

slide-9
SLIDE 9

9

A challenge for many organizations is the lack of resources and skill sets to drive a digital transformation journey forward

slide-10
SLIDE 10

Data Analytics

slide-11
SLIDE 11

11

Where to Start: Define what questions you want to answer using Data Analytics

Sample Questions IT Audit/Compliance leaders should ask:

  • Where should your team be spending resources,

personnel, and time?

  • What assets and what processes should I be

prioritizing in my audit plan?

  • Could I use analytics to assess the effectiveness
  • f controls?
  • Do I have a broad scope of things to assess (i.e.

millions of transactions you need to sample from) where RPA could point out outliers and anomalies where you might find meaningful findings

slide-12
SLIDE 12

12

Where to Start: Gathering Your Resources

  • Is there a data governance committee at your
  • rganization you can work with?
  • Can they help you identify what data you have,

where it’s stored, and how it’s formatted?

  • Is there standardization around sources?
  • What technology is being used in different systems

(will depend on the data and where it’s coming from)

  • Can I extract the data myself, or do I need a system

administrator to get the data from the system?

slide-13
SLIDE 13

13

Types of data sources that are helpful for doing data analytics in an IT Compliance context:

Understanding the environment:

  • Where does the data reside?
  • Do you know path from source to data warehouse?

Pull information from systems into a data analytics platform:

  • About assets (physical and data assets) from an inventory
  • Policy info from a content management tool
  • Controls/risks from GRC platforms and Jira
  • HR/Personnel data from TriNet or Workday
slide-14
SLIDE 14

14

Where to Start: Data Completeness & Accuracy

Data analytics will not be successful without a good data warehouse

  • GIGO: The data you work with is
  • nly as good as the source
  • Agreement on source of truth
  • Dealing with post-acquisition
slide-15
SLIDE 15

15

Data Analytics Uses in IT Compliance Example:

slide-16
SLIDE 16

16

Data Analytics Uses in IT Compliance Example:

slide-17
SLIDE 17

Robotic Process Automation

slide-18
SLIDE 18

18

Benefits of RPA

Accurate Consistent Available 24/7 Instantly Scalable

More time for creative, insightful, value-add activity

slide-19
SLIDE 19

19

Challenges: Top reasons RPA fails during first implementation

Weak or no executive sponsorship 1 Inadequate data completeness and accuracy 3 Underestimate change management 2 Introduced too early within the transformation process 4

slide-20
SLIDE 20

20

Challenges: Top reasons RPA fails during first implementation

Weak or no executive sponsorship

  • Executive sponsorship enables the program to

– Solicit support from leadership within other departments – Navigate a politically sensitive environment – Effectively escalate when encountering resistance

Challenge 1

slide-21
SLIDE 21

21

Challenges: Top reasons RPA fails during first implementation

Weak or no executive sponsorship

  • Executive sponsorship enables the program to

– Solicit support from leadership within other departments – Navigate a politically sensitive environment – Effectively escalate when encountering resistance

Challenge 1 Change Management

  • Regardless the intentions of the program (FTE reduction, operational efficiency, etc), those impacted by RPA

technology often react with anxiety upon first hearing of the tool.

Challenge 2

slide-22
SLIDE 22

22

Challenges: Top reasons RPA fails during first implementation

Inadequate Data Completeness and Accuracy

  • RPA is only as good as your data!

Challenge 3 Change Management

  • Regardless the intentions of the program (FTE reduction, operational efficiency, etc), those impacted by RPA

technology often react with anxiety upon first hearing of the tool.

Challenge 2

slide-23
SLIDE 23

23

Challenges: Top reasons RPA fails during first implementation

Inadequate Data Completeness and Accuracy

  • RPA is only as good as your data!

Challenge 3 Introduced too early within the transformation process

  • Unfortunately, many companies try implementing RPA when they still have disparate, complex processes,

yielding little to no ROI.

  • Therefore, RPA should be introduced once processes have been optimized.

Challenge 4

slide-24
SLIDE 24

24

When should you implement RPA? At the Tail End of Transformation

E

Eliminate

S

Standardize

O

Optimize

A

Automate

R

Robotize

slide-25
SLIDE 25

25

The ESOAR methodology is a systematic framework used to enable transformation

E S O

Eliminate all unnecessary activities that impact time, cost, and effort. Addressing and eliminating the cause of waste and barriers to services shifts the focus to more value-added activities in your business operations, such as analysis. Standardize similar routine processes in the same repetitive manner by using standard templates to run transactions with less time and effort. Standardization is a way to avoid the cost of ERP customization and drive best practices Optimize using all the functions of existing tools to the maximum effect, including ERPs, processes, and workflows. Organizations often have the right tools, but don’t know to use them effectively.

slide-26
SLIDE 26

26

The ESOAR methodology is a systematic framework used to enable transformation

Automate standardized manual processes – oftentimes possible with existing technology. Automation reduces or eliminates manual work, while delivering increased transparency and control over the process, with extremely high levels of accuracy. Robotize to drive efficiency in any remaining manual, repetitive, rule-based activities by simulating the activities of a human operator.

A R

Through a structured review of operations ESOAR allows us to understand current process drivers and enables next level of growth through transformation

slide-27
SLIDE 27

27

RPA Uses in IT Compliance

slide-28
SLIDE 28

Final Thoughts

slide-29
SLIDE 29

29

Organizations should start their digital transformation journey by defining specific objectives, measurable goals, and metrics that can be used to track against those items

slide-30
SLIDE 30

Thank You!

Contact: jsechrist@auditboard.com