Continuous monitoring of business process controls: A pilot implementation of a continuous auditing system at Siemens
نویسندگان
چکیده
In this paper we report on the approach we have developed and the lessons we have learned in an implementation of the monitoring and control layer for continuous monitoring of business process controls (CMBPC) in the US internal IT audit department of Siemens Corporation. The architecture developed by us implements a completely independent CMBPC system running on top of Siemens’ own enterprise information system which has read-only interaction with the application tier of the enterprise system. Among our key conclusions is that “formalizability” of audit procedures and audit judgment is grossly underestimated. Additionally, while cost savings and expedience force the implementation to closely follow the existing and approved internal audit program, a certain level of reengineering of audit processes is inevitable due to the necessity to separate formalizable and non-formalizable parts of the program. Our study identifies the management of audit alarms and the prevention of the alarm floods as critical tasks in the CMBPC implementation process. We develop an approach to solving these problems utilizing the hierarchical structure of alarms and the role-based approach to assigning alarm destinations. We also discuss the content of the audit trail of CMBPC. © 2006 Elsevier Inc. All rights reserved.
منابع مشابه
Assuring Homeland Security: Continuous Monitoring, Control & Assurance of Emergency Preparedness
This paper examines the potential relationships of Continuous Auditing and Emergency Preparedness to the design, development, and implementation of Emergency Response Management Information Systems (ERMIS). It develops an argument for the integration of emergency response processes and continuous decision process auditing requirements into the system development life cycle of an organization wi...
متن کاملNovel Design Approach to Build Audit Rule Ontology for Healthcare Decision Support Systems
Continuous Auditing (CA) has been investigated over time and it is, somewhat, in practice within financial and transactional auditing as a part of continuous assurance and monitoring. Enterprise Information Systems that run their activities in the form of processes require continuous auditing of a process that invokes the action(s) specified in the policies and rules in a continuous manner. A s...
متن کاملMonitoring Organizational Transactions in Enterprise Information Systems with Continuous Assurance Requirements
This work focuses on issues typically encountered in organizations whose core business largely depends on ICT: continuous monitoring, continuous auditing, controlling and assessment of transactions risk. Organizations have been making efforts to implement methods and systems which enable them to increase reliability of their business and, simultaneously, to be in accordance with their organizat...
متن کاملApplication of international energy efficiency standards for energy auditing in a University buildings
This study seeks to provide insights on understanding the contemporary problems of energy efficiency in Ukrainian universities by developing a comprehensive energy efficiency management framework that encompasses its participating subjects, objects and key drivers along with suggesting its implementation mechanism and tools. Emphasis should be given that the current situation of inefficient and...
متن کاملA solution for real time monitoring and auditing of organizational transactions
The controlling and auditing of organizational transactions in real time allows to determine the degree of reliability with which they are carried out, mitigating the organizational risk. This paper presents a solution proposal under a new vision for organizational auditing and monitoring in real time since it is focused on the implementation of continuous assurance services in organizational t...
متن کامل