Failure to adequately control IT changes result in failed audits. Ensure that change management processes are documented and changes have authorized approvals before promotion with emergencies needing post approvals after installation. #changemanagement#audits
Auditors should not generate fear but respect. They should be regarded as corporate team members and be solicited for advice and education, Read "Audit Defense". #audits#auditreadiness#auditeducation
If not done so already why don't corporations assign ex-auditors to educate management on audit process and controls. Pro-active measures could increase revenue flow, tighten controls and improve customer sat before negative effects. Read "Audit Defense" #audits#auditreadiness
Corporations should not only assign IA departments to identify exposures AFTER revenue is delayed/lost due to control weaknesses but should educate management on how to be pro-active in addressing these issues BEFORE losses. Read "Audit Defense"
Most management, current and future, in large corporations will probably be subjected to audits. They need be prepared and audit ready. Managers and MBA students should be educated on audit process and controls. Read textbook "Audit Defense". #audits#management#auditreadiness
@TheIIA We need just not to educate the next generation of internal auditors but also need to educate the next generation of managers to be audit ready. They can't wait for auditors to inform them of exposures but should be pro-active. Corporations will benefit. Ref book "Audit Defense"
Auditors are educated and prepared before audits while most managers are ill-prepared. Management education is trial by fire- not good for corporations. Be proactive and educate management to lock barn doors before horses escape. Read "Audit Defense". #audits#auditreadiness
Management, who have never been audited before, in preparation for an audit, should be pro-active and simulate audits with role playing and mock audits. Read "Audit Defense". #audits#auditreadiness#auditpreparationin
As a prospective audit client, management or staff, it is essential that you know what are some pro-active steps to take in defending yourself against an audit (internal or external). Read "Audit Defense" #audits#auditreadiness#auditpreparation
@rfchambers I realize that internal auditors first responsibility is to their organizations but doesn't this necessitate that they are totally independent including an obligation and responsibility to stockholders, shareholders and other external resources as well?
A failing audit can sometimes be prevented by a pre-audit documented risk assessment and acceptance. Refer to the Risk Management chapter in the textbook titled 'Audit Defense' . #audits#riskassessments
Where is the auditor? Whether documents are sensitive, classified or confidential, controls need be established and effectively executed for access, storage, distribution, and destruction. Read physical control section in "Audit Defense" textbook. #audits#classificationcontrols
In the words of Benjamin Franklin- " by failing to prepare, your are preparing to fail". Audit clients should read "Audit Defense" to: become aware of audit expectations; understand controls and risks: and reduce audit fears. #audits#auditreadiness
See my article, "A Decade of Disruption Continues for Boards," with my colleague, Frank Kurre. It features both a global and U.S. perspective from directors participating in the recent global risk study conducted by @Protiviti and @ERMInitiative https://t.co/3PlSjMhhKh
In modern business, it i snot the crook who is to be feared most, it is the honest man who does not know what he is doing - William Wordsworth. Read "Audit Defense". #auditreadiness#audits
Failed audits are usually due to lack of preparation. Processes and procedures not being documented and/or controls absent or not effectively being executed. Read "Audit Defense" for readiness. #audits#auditreadines
If audited would you have documentation and be able to explain to an auditor what preventive, detective and/or deterrent controls exist and are effective within your process? Read "Audit Defense". #auditreadiness#audits#processcontrols
One of the most rigorous components of audits is a review of change management controls.Frequently this is where many exposures are identified and unfortunately unsatisfactory or failed audits result. Refer to the book "Audit Defense" for more information. #audits#auditeducation
Auditors during an audit of a selected process, will probably sample the most sensitive financial/confidential data and ask for a list of those individuals with access. Only those with valid business needs should have access. Remove others ASAP. Read "Audit Defense" #audits