Detecting Compliance Failures in Unmanaged Processes
نویسنده
چکیده
The importance and the challenges of detecting compliance failures in unmanaged business processes is discussed and the process of creating and verifying internal controls as a requirement of enterprise risk management framework is explained. The effect of using automated auditing tools to detect compliance failures against internal control points in unmanaged business processes is investigated. Risk exposure of a business process due to compliance failures is analyzed and the factors that affect the risk exposure of a business process are evaluated. INTRODUCTION Detecting compliance failures help organizations better control their operations and remain competitive. The quality of product and services can not be ensured in a business if the processes do not conform to design goals and comply with the rules and regulations. Moreover, organizations may be subject to serious financial penalty as well as civil and penal consequences if they failed to comply with established guidelines, rules and regulations. Hence, the impact of non-compliance may have severe consequences that need to be managed either by reducing or eliminating the associated risk. Companies invest significantly on detecting compliance failures to ensure governance and manage risk. The cost of reducing the risk of being non-compliant could run into millions of dollars [ 1]. AMR Research survey reveals that the spending of companies on governance and risk management and compliance expected to grow to $29.8 billion in 2010, up nearly %4 over the $28.7 billion spent in 2009 [ 2]. Compliance can be managed relatively easy when the set of interrelated and interacting activities to achieve business goals are coordinated by business process management systems. This is the case where processes are well structured and documented. When the activities in a business process are structured enough, the transitions from one activity to another are automated by software systems. In a fully automated structured business process real time information about the status of various activities can be collected by business activity monitoring software [ 3]. Hence, compliance of processes against rules and regulations can be checked automatically. In such automated environments, the trace of the business operations is completely visible and it possible to know who did what and when. In reality, business activities span multiple systems and organizations across modern enterprises, integrating legacy and newly developed software applications. There exists no single system or organization that controls the process end to end. Operations often depend on activities that rely heavily on human interaction without predefined control structures. Human actors decide what to do to achieve business goals. Since the transitions between human activities can not be fully automated or monitored by software systems, the visibility of end to end business operations is reduced. The processes that consist of such activities are called unmanaged processes. In the absence of business process management software with business activity monitoring that registers various aspects of the business operations, compliance check is usually performed manually by auditors, hence it is costly, time consuming.
منابع مشابه
Effect of Using Automated Auditing Tools on Detecting Compliance Failures in Unmanaged Processes
The effect of using automated auditing tools to detect compliance failures in unmanaged business processes is investigated. In the absence of a process execution engine, compliance of an unmanaged business process is tracked by using an auditing tool developed based on business provenance technology or employing auditors. Since budget constraints limit employing auditors to evaluate all process...
متن کاملA Monitoring Framework for Guidance and Risk Control Assistance of Environmental Compliance Officers
It is the ultimate goal of environmental compliance management to assure corporate compliance with given regulations. The work processes that are required to fulfill and maintain compliance are usually complex and long running processes that are composed of many interdependent human lead activities. Errors of human work activities and also material and equipment defects can lead to non-complian...
متن کاملChecking Security Policy Compliance
Ensuring compliance of organizations to federal regulations is a growing concern. This paper presents a framework and methods to verify whether an implemented low-level security policy is compliant to a high-level security policy. Our compliance checking framework is based on organizational and security metadata to support refinement of high-level concepts to implementation specific instances. ...
متن کاملModeling and Reconfigurating critical Business Processes for the purpose of a Business Continuity Management respecting Security, Risk and Compliance requirements at Credit Suisse using Algebraic Graph Transformation: Long Version
Critical business processes can fail. A Business Continuity Management System is a special management system that will define how to recover from such failures and specifies temporary work-arounds to make sure a company is not going out of business in the worst case. However, because today’s implementations are primarily organizational best-practice solutions, their security, risk and complianc...
متن کاملFailure Recognition and Fault Tolerance of an Autonomous Robot
The purpose of this paper is twofold The rst purpose is to present important issues in designing fault tolerant systems for autonomous robots The second is to present the fault tolerance capabilities we implemented on our autonomous robot Our approach is characterized by a distributed network of concurrently running processes To tolerate hardware failures a set of fault tolerance processes are ...
متن کامل