Friday, September 21, 2012

Insights from ISACA's EuroCACS ISRM Conference

1 comments
Munich is always a popular place as October approaches, but I missed the wonders of the 'biergartens' in full flourish. Last week I joined a large gathering of IS Audit, Risk and Controls specialists at ISACA’s annual EuroCACS and ISRM conference at the Hilton by the Englischer Garten in the city.


Thursday, August 16, 2012

Six Strings to GRC Success . . .

0 comments
I am just about to go into 'silent running' mode as I depart to build another guitar on the wonderful Balearic/Piteuse island of Formentera . . . So you won't hear much from me for a few weeks unless you follow my 'Guitarra - Part Deux' blog.

BUT, thinking of my impending trip did provide some inspiration for a little treatise on performance, risk and compliance from the perspective of a guitar maker of average skill. Since most business processes are performed by people with average levels of skill and experience, I thought this might be an interesting parallel, and, as I thought about it more, it stimulated some interesting thoughts. Well, at least, they interested me!

Thursday, July 5, 2012

Risk Awareness & The Bear

0 comments
Take a look at the awareness test here, before you read the rest of this post.

Have you looked at this?

OK . . .  you get the point . . .

This is an interesting phenomenon . . . .

Friday, June 1, 2012

STOP! The Controls Madness . . . Part deux!

1 comments
In Part 1 of this post I talked about the fact that the relationship between better risk management and more control is not intuitive or even direct. We discussed the shortcomings of the traffic light system as a control. We also touched on the issues in financial control with the false sense of security created by automated controls, such as those for purchase limits for example. You can read Part I here . . .

The same challenge exists for the classic accounting control,

Thursday, May 31, 2012

STOP! The Controls Madness . . . Part I

1 comments
I saw this headline recently and it got me thinking . . . .

Many organisations have been encouraged, and in some cases required, to focus their financial risk efforts on controls, developing an internal control system, regularly assessing the efficacy of controls and reporting against that for audit and compliance purposes.

Any good internal control system is risk based, but the excesses

Sunday, May 6, 2012

The 'Great Potato Fraud of 2012'

0 comments
I wrote a few weeks ago of the pride and complacency of the middle management fraudster and the 'smartest guys in the room'

On a recent ski trip I had met a guy on a chairlift

Are we all better than average at risk management?

0 comments
Who's fooling who?

CFO magazine recently published a fascinating article that is another example where executives all think their organizations are above average. The article observes that experts estimate that internal fraud costs companies 3% to 5%

Thursday, April 19, 2012

Perception, Risk and Safeguards

0 comments
I gave a talk today at the Enterprise Risk Management (ERM) Symposium in Washington D.C. We divided the time 60/40 between my presentation and a group discussion on implications, especially for the Insurance industry. We had a lively discussion with CROs and risk professionals

Tuesday, April 17, 2012

Fraud, 'Smart Guys' and 'Better Than Average'

0 comments
I was skiing the weekend before last in the Swiss Alps and as luck would have it, a rather interesting conversation developed on a chair lift. A pretty long lift as it happened . . .

The only other person on the chair was a guy who introduced himself

Tuesday, April 3, 2012

Accounting Regulation Reducing Fraud, Really?

2 comments
An article in CFO magazine today announced the opinion that the US 'Jumpstart Our Business Startups' (JOBS) Act, whilst easing the Sarbanes-Oxley (SOX, Sarbox) standards, might pave the way for fraud. You can read