Jim Kaplan's
|
|
||||||
|
|
|||||||
|
AuditNet® Community Sponsor News! The AuditNet® community has grown by leaps and bounds thanks to your continued support. Yes it is hard to imagine but it has been more a decade since this community was created! Support AuditNet® by supporting our sponsors. Without sponsor and affiliate advertising and contributions from the AuditNet® community everyone would have to pay for use of this site.
This month check out IDEA - Data Analysis Software, that is the standard in ease of use for auditors, accountants and financial managers. Visit the site to download the new whitepaper: Data Analysis The Cornerstone of Effective Internal Auditing! Remember! Clicking on sponsored ads and visiting their sites helps support AuditNet®. Getting Started with GAIT By Jack Bess, KnowledgeLeader contributing writer On a February 7, 2007 Institute of Internal Auditors (IIA) web cast, panelists offered practical tips and techniques when using GAIT to scope IT controls for SOX compliance and how to effectively implement GAIT. The Sarbanes-Oxley Act (SOX) of 2002 is clear in its mandate that companies annually assess their internal controls over financial reporting. Companies have found that the precise scope of their assessment is less clear. “You would be surprised how may times this question comes up in audiences: ‘Where can I get a list of the key controls I need to have for IT general controls?’” says Norman Marks, vice president of internal audit at Business Objects, S.A., a software developer based in San Jose, Calif. “But if you follow the approach of ‘Where is the standard list?’ you are not necessarily going to get the right ones.”Marks is part of a core team at The Institute of Internal Auditors (IIA) who have helped develop a methodology and set of principles to help organizations define their scope of control assessments as mandated by Section 404 of SOX. That methodology, the Guide to the Assessment of IT General Controls Scope (GAIT), aims to provide a structured reasoning process companies can use in scoping the controls that ensure the accuracy of their financial statements. Click here for the rest of the story! This article was contributed by Protiviti KnowledgeLeader, an online service providing tools, templates, and other resources for internal audit and risk management. Free trials available at www.knowledgeleader.com. For a limited time KnowledgeLeader memberships are available for the reduced rate of $595 per year. Tell them you heard about it from AuditNet.org. Sage strategies to help every worker succeed Today’s work environment offers none of the stability and
long-term tenure of prior decades. Penelope Trunk, author of “Brazen Careerist: The New Rules for Success Click here for the Q&A! Resume Tune-Ups Dressing it up! by Robbie Miller Kaplan Overall, Dele has done a good job writing his resume. But qualifications alone won’t capture an employer’s interest. With some key changes to the format, Dele will increase his chances of attracting attention. For starters, set the margins at one-inch all around and use a single line space. This will free up space to allow a 10-point font; anything under 10-point is too small. Balance the text with a 12-point font for name and all section headings; centering the headings and using all uppercase, bold, and a different font (such as Book Antiqua or Century Schoolbook) to guide the reader’s eye. Consistency is important so Dele should choose one bullet to use throughout the resume. Round and square bullets have more punch and can be customized under “Bullets and Numbering.” Save additional space by setting the bullets flush with the left margin. Format the second position on page two identical to position one. And follow the rules for numbers; spell out numbers one through ten and use figures for 11 and over. Dele should avoid pronouns and craft a stronger qualifications summary.
Try: “Technical and business savvy professional with an expertise in
leadership, networking and hands-on IS. Solid achievements in delivering
quality client services, consistently meeting diverse needs. Excellent
record of deploying simultaneous, mission-critical equipment and projects,
on time and under budget. Recognized for a team-based management style with
excellent interpersonal and communication skills.” Get a Free Resume Analysis! AuditNet Adds a New Career Feature: The Resume Tune-Up. Nationally recognized resume expert and author of How to Say It In Your Job Search, Robbie Miller Kaplan will select one auditor resume each month and suggest ways to transform the resume from passable to powerful. If you would like your resume to be considered for a tune-up, please e-mail it to Ms. Kaplan. You will be notified by e-mail if your resume is selected. You will need to make yourself available via e-mail to answer a few questions with a tight deadline. Ms. Kaplan will send a critique and suggestions to the individual selected and a summary Resume Tune-Up will appear in the monthly newsletter column. If selected you give AuditNet the right to display your resume for the column. AuditNet® What's New This Month? New Column on Recovery Auditing Rich Lanza, a longtime AuditNet contributor and writer has launched a new Website and has agreed to sharing articles on recovery auditing. Read his column and check out his Web site to see how you can save your company $$. PricewaterhouseCoopers Global Best Practices shared an excellent paper of Building Blocks for Effective Corporate Boards. Make sure you share this with your audit committee! Auditor's Dozen Renewal Offer Have you let your subscription to AuditNet expire? If so then have I got a deal for you! Renew your AuditNet subscription by the end of the month and I will throw in an extra month on your subscription renewal. In other words you will get 13 months for the price of 12 or as I like to call it; the Auditor's Dozen. Process your renewal payment today as this is a limited time offer! AuditNet Server Upgrade AuditNet is moving the Web site to a dedicated server. Please be patient and be sure to report broken links that you encounter. Pay by Phone or FAX AuditNet is now set up to accept credit card payments for subscriptions by phone or fax. If you are interested in this option click here! Writing for AuditNet? AuditNet Editorial Guidelines Based on the number of articles being contributed to AuditNet we have developed editorial guidelines for future submissions. If you are planning to write an article please review the guidelines before submission. We appreciate receiving material from the global audit community in the interest of sharing knowledge. We are also in the process of guidelines for book reviews and other material submitted for inclusion on AuditNet. Get Audit Related Books Free! Interested in developing your writing skills with having access to the latest audit and business related books? AuditNet is looking for auditors that would like to review books for the benefit of the audit community. This is an excellent way to build your professional publication library and provide a valuable service for AuditNet users. A list of available books will be provided on request. For the guidelines click here. New Benefits of Registration AuditNet receives many questions on what kind of audit related information is available on the Internet and where to find it. As a result of my research to find the answers to those questions I discover value added resources that are useful for auditors. In the past these resources would have been added to the AuditNet Links Page (aka KARL). To provide an incentive for auditors to register on AuditNet I will begin loading these links to a special page that is only available to registered users. AuditNet forges new relationships with professional associations and accounting sites to provide auditors with access to audit work programs. Professional Association Access to AuditNet Audit Programs. If you want your professional association (IIA, ISACA, ACFE, ACUA, ACUIA etc) to have transparent access to AuditNet audit programs and other content as a benefit of membership contact your professional association official and ask them to pursue this with AuditNet. Fraud News Feed Go to the AuditNet Fraud Resource Center and check out the fraud news feed to keep up to date with media reported fraud happenings. Audit Programs The audit programs section of AuditNet requires registration in order to access. New audit program contributions are available only to paid subscribers or on a one-for-one exchange basis. However 181 standard management audit programs were added this month to the free content thanks to Professor Andrew Chambers of the UK. There are over 65,000 registered users. A multi-user subscription rate was added to the individual subscription program to the premium content. Organizations that need more than 2 staff members accessing the service will benefit from this new rate. There are new additions to the premium audit programs available as an alternative for those auditors that are unable to contribute material to AuditNet®. Site licenses are also available for organizations with more than 15 users. The best way to find all the resources on the site is by going to the Virtual Library or use the site search. Voice recorders: an effective way to reduce time documenting controlsby Jean-Louis Vergaert Experienced internal auditors know their business. They
foresee the issues, are familiar with the risks and controls specific to the
business processes they audit, have seen best practices in some places, and
weak controls in others. Auditors possess a mental map of how a process must
work to be efficient and well-controlled. Click here for the rest of the article! IIA Technology Audit Guide Series Guide 8: Auditing Application Controls Each year, billions of dollars are spent globally on implementing new or upgrading business application systems. Effective application controls will help your organization to ensure the integrity, accuracy, confidentiality and completeness of your data and systems. It is important for the chief audit executive (CAE) and his or her team to develop and execute audits of application controls on a periodic basis in order to determine whether they are designed appropriately and operating effectively. This IIA's new guidance Auditing Application Control provides internal auditors with the following information. What is application control? Each Global Technology Audit Guide (GTAG) will be written in straightforward business language to address timely issues related to information technology management, control, or security. GTAG will be a ready resource series for chief audit executives to use in the education of members of the board and audit committee, management, process owners, and others regarding technology-associated risks and recommended practices. Previous Guides:
AuditNet® Fraud Auditing Corner |
|||||||
|
After successfully fighting fraud within the UK government, Ros Wright now independently advises, drives new research, and gives her unvarnished opinions as chair of a watchdog group. And people listen. |
This article is from Fraud Magazine, the professional magazine
of the Association of Certified Fraud
Examiners
For the rest of the article from the latest ACFE Fraud Magazine click here.
ACFE FraudInfo Newsletter click here!
AuditNet® Conference & Training News
Want to announce your professional association conference to the global audit community? Send us conference name, date and URL details. (A reciprocal link to AuditNet is required). AuditNet supports co-marketing sponsorship agreements for conferences on a case by case basis.
2007 ACFE Fraud Conferences and Training
2007 IIA Conferences and Training
The 6th Annual Summit on Auditing and Governance December 3-4, 2007, New York, NY Optional Workshop(s): December 2 & 5
Audit, Fraud and Governance Conference, October 23, 23, 2007, Dublin, Ireland
IIA Winnipeg Chapter Governance Conference 2007, October 16, 17, 2007, Winnipeg Canada
Auditing Information Security - Evaluating the Effectiveness of Your Information Security Program - by Dan Swanson and Clint Kreitner 2 hour Webinar September 20, 2007
Current Developments Under Sarbanes-Oxley, the SEC, and the PCAO Conference New York, NY, September 18, 2007
* indicates events where Jim Kaplan is speaking
Need Help in Passing the CCSA Exam? Then check out the CCSA Study System published by Pleier Corporation. Using the "McKeever CCSA Study System" will improve
users' probability of successfully passing the IIA CCSA exam
by teaching users to answer the type of questions typically
presented on the CCSA exam. Additionally, this system helps
users identify CCSA domains that require their additional
study and lists references useful for any additional study. The "McKeever CCSA Study System" is available in 2
versions - a 288-page spiral-bound workbook and CD-ROM (for
those who prefer clicking a mouse to turning pages) - for
details click
here! DISCOUNTS TO AUDITNET READERS |
Exceeding Expectations for Internal Auditors
Registered User Free Tools
AMIGO (Audit Management and Information Guidance Software)
The Perils of Mount Must Read
SOXERM
AuditNet Monographs
Premium User Tools
Sarbanes-Oxley, IT and Management Audit Programs
The Auditor's Guide to Internet Resources 2nd edition
Procedure Guidelines and Controls Documentation
Cobit 4th Edition Domain Quiz
Coming Attractions!
AuditNet is working with professional associations to provide access to the audit program inventory. Stay tuned!
Next month a new article on Automated Techniques for Detecting Procurement Fraud.
The AuditNet Monograph Series provides useful guides for all levels of auditors from juniors right up to audit directors. As soon as I can make some time I will be working on new guides for Sarbanes-Oxley, internal controls and Internet for auditors and other relevant subjects. These guides will be available to registered subscribers. If you are interested in developing a monograph on a contract basis, contact us.
Watch for new articles on Sarbanes-Oxley, Information Security, Software Auditing, CAATTs, DATTA and more from contributors. Reviews are in the works for more audit and SOx books. Watch the newsletter for more products, services and tools for auditors. Have an idea for a column? Contact us.
AuditNet® continues adding new specialized resources for auditors. Watch the newsletter and keep checking the Library page for updates and new resources.
Fraud News
Need to keep up with fraud news and happenings? There are several options available. One is to subscribe to the free ACFE FraudInfo E-newsletter.
Another free resource is the Auditing & Fraud News. Service for research professionals. Constantly updated news and information about Business & Companies. Go to FraudNet and click on the link Click Here for Fraud News.
Please let us know of links that are not working!
Click here for the latest update!

ALTAMONTE SPRINGS, Fla. (July 11, 2007) — In honor of his outstanding contributions to the internal audit profession, James Kaplan, CIA, was awarded by The Institute of Internal Auditors (IIA) with the prestigious Bradford Cadmus Memorial Award during The IIA’s 2007 International Conference, held in Amsterdam this week. Initiated in 1965, the award is named after The IIA’s first managing director and recognizes internal audit practitioners for research, academic involvement, article and book publication, and other thought-leading pursuits.
For the complete press release click here!
AuditNet® CAATTs and Data Analysis
Audit results gleaned from competent data analysis activities by internal audit can shine a light on the issues lying within the organization's data. Therefore, audit leaders must focus on making certain every staff member understands the client systems, and knows how to acquire and analyze the data produced by these systems in order to corroborate or detect failures in the reliability and integrity of the system information.
When properly used by trained staff, data analysis software can be incorporated into audit plans to provide assurance and consulting services related to the organization's information systems and thus becomes the true cornerstone of an effective audit foundation.
Does your audit organization embrace the use of data analysis?
This research report provides an implementation framework for
audit leaders interested in taking their function to the next level.
Visit the site to download the new whitepaper: Data Analysis The Cornerstone of Effective Internal Auditing!
by Mike Blakely
The process of auditing fixed asset records in an enterprise that can be daunting, especially when the number of supporting detail records is in the thousands or tens of thousands, which is not an unusual situation. Two general audit approaches can be used: sampling, or 100% testing of the records using automated procedures. This article describes the latter approach, using three different software tools. For each tool, the steps needed to accomplish each of the audit objectives are described. These tools were selected for the article as they are the most familiar to the author. However, a similar approach can be used with almost any other audit software tool.
For the complete article including the link to the sample data click here!
About the author: Mike Blakley is currently an IT auditor with the State of North Carolina, Department of Health and Human Services. Mike maintains a blog devoted to audit software topics at http://blog.ezrstats.com and his e-mail address is Mike.Blakley@ezrstats.org.
*Data Analysis Tools and Techniques for Auditors

It's no wonder that the audit recovery business is thriving and evolving. Many companies are currently benefiting from the services of a recovery audit firm.
Here are some of the reasons why:
People in companies are always fighting a six-headed hydra, constantly focusing on the dragon head that is currently snapping at them. Therefore, there is little time for improvement, best practices, and the tedium involved in reviewing transactions for recovery.
Companies are constantly downsizing and outsourcing. This creates additional issues due to a "lack of touch" by the people working the process with those who developed the process. This is coupled with the fact that accounts payable departments are constantly understaffed, overworked, and receive a relatively small portion of the budget for technology improvement purchases.
Most accounting systems were built to process transactions and not to provide users access to the data for reporting purposes. Data analysis is critical in obtaining recoveries. Further, recovery auditors are skilled in data analysis and the types of reports that are the most fruitful. Therefore, it is best to learn from them by watching them on a few engagements.
With all of the reasons, see the articles below on how companies can save money.
Richard B. Lanza, CPA/CITP, CFE, PMP
President - Cash Recovery Partners, LLC
Phone: 973-601-3701
Email: rich@richlanza.com
There are a number of reasons many firms remain resistant to recovery auditing, but they can generally be grouped into three main categories:
Morale/Motivation Issues
Business & Procedural Obstacles
Financial Impact
To read the rest of this article click here!
Upcoming Webinars and Events
| September 18, 2007 | Claim recovery "Yachtmanship" - Presented by Health Decisions, Inc. |
| October 23, 2007 | The "Rx" for Rx Claims - Presented by Health Decisions, Inc. |
| November 13, 2007 | Declaring WARR - Presented by Health Decisions, Inc. |
Audit Work Programs Corner
Free Access to the Premium Section for New Audit
Programs Shared!
Access to the free audit program section now requires registration. The following audit programs, ICQs, checklists or working papers were added this month. They are available on a 1 for 1 exchange for an original audit work program not currently in the inventory. If you unable to share audit programs then consider subscribing to the premium content which provides you with access free and premium content 24/7/365. For a limited time AuditNet is offering free access to the premium content section. Contribute an original audit work program not currently in the inventory and receive 2 months free access to the premium content. Contribute 5 programs and receive a subscription for one year. (Offer only available for new programs submitted).
Offer Expires September 30, 2007
E-Book for
Subscribers to the Annual Audit Programs

The following programs are also now available to premium subscribers:
Ten Ways to Identify Accounts Payable Fraud
Part Two
By Christine L. Warner, President of Automated Auditors, LLC
When Sarbanes-Oxley passed in 2002,
it forced many companies to take an in-depth look at internal
Accounts Payable controls. Implementing internal controls takes
time, but may prove to be a very cost- effective measure if any
fraud or leakages are found. The following approaches, requiring
some degree of
data mining and programming capability, are fairly straightforward
and should tighten up your A/P audit.
For Part Two of this article click here!
If you missed Part One of this article click here!
AuditNet® Information Security Corner
Protect Yourself: Beware of Phishing Attempts
by Rey Leclerc
FDIC Consumer Call Centers in Kansas City, Missouri, and Washington, D.C., began receiving a large number of complaints by consumers who received an e-mail that has the appearance of being sent from the FDIC. The e-mail informed the recipient that the Department of Homeland Security Director advised the FDIC to suspend all deposit insurance on the recipient’s bank account due to suspected violations of the USA PATRIOT Act. The e-mail further indicated that deposit insurance will be suspended until personal identity, including bank account information, could be verified.
This e-mail was not sent by the FDIC and is a fraudulent attempt to obtain personal information from consumers.
Click here for tips on securing your information!
Ask the Auditor

Each month I select one question submitted to Ask the Auditor and provide an answer using the same digital tools and techniques that I recommend to all auditors.
Q: Can a fixed assets count be done at different times through the organization or should it be done at the same time to identify any transfers of assets between departments easily.
A: For best practices on inventory counts such as fixed assets I suggest using the following document:
Best Practices in Achieving Consistent, Accurate Physical Counts of Inventory and Related Property which can be found at this link.
Here is an excerpt that mentions when and what to count. In order to count an appropriate amount of the total inventory, management must decide which inventory items to count and how frequently those items should be counted. The most desirable goal would be to count all of the inventory items at least once a year. However, maintaining accurate inventory records by counting items takes time and costs money. Since there are typically limits on these resources, the best way to balance control of the inventory and cost of the count is to focus on the items determined to be more important or of higher risk to the organization. Accordingly, it is not always practical to give the same treatment to each item; it may be desirable to segment the inventory into identifiable classes and assess the risk for each segment or class to determine the frequency of counts.
If you have a question for Ask the Auditor click here!
AuditNet is interested in developing a series of SOx or industry related audit programs for organizations. If anyone is interested in writing audit programs, ICQs, questionnaires, or control matrices on a work for hire basis please contact me. If you may know of anyone who would be interested in this as well please pass along my contact information.
Click here for Building Blocks of Effective Corporate Boards |
AuditNet Construction Corner News
MANAGEMENT AND
AUDIT OF ACQUISITION OF LANDED PROPERTY
[Vacant Land or Buildings]
by Gursharan Singh
Acquisition of landed property either as vacant land or completed building compatible with the needs of the buyer can also be transacted by the private and public sector entities. This article will give emphasis to audit of acquisition of landed property but not to disposal of any existing landed property. However the aspects that are listed and explained are also substantially applicable to disposal of landed property as the owner would have initially gone through the process of acquisition before it can be disposed off. These aspects may not be taken into account by Government and their agencies that generally have their own procedures that may take into account other ‘considerations’ in acquisitions or disposal of landed properties.
For the rest of the story click here!
By Tom Crouch, CPA, CIA, CISA, and Attorney
The first wave of baby boomers were born in 1946 and began entering the job market in about 1965. They were followed by subsequent waves born through 1964. Their numbers were so great that employers were able to become increasingly selective in their hiring. The employers were also able to hire folks who were more qualified than those hired for the same type positions during the 1950s. The employers were able to hire people who were generally better educated, taller, leaner, more articulate, and better looking. As the baby boomers start retiring, the job market for current skilled employees and new skilled worker hires might resemble the 1950s, except there will be far more women and minorities.
For the rest of the story click here!
(Note: this is part 10 of a series of articles written by the author. For links to the previous articles click here)
Watch for more articles on this topic in the coming months!
AuditNet Sarbanes-Oxley News
Low Cost SOX Compliance Readiness Tool
Exclusively for AuditNet
Looking for a low cost ($100) solution for SOX compliance? The Compliance Readiness Tool™ allows organization’s to evaluate the effectiveness of their information technology environment and controls in relation to section 404 of SOX and the Committee of Sponsoring Organizations (COSO) internal control framework.
For more information click here!
There are plenty of articles in the news on the topic of Sarbanes Oxley. Here is a link to a site that does the research and provides you with links to all the relevant stories.
AuditNet Career Center
Auditors Looking for Jobs!
Companies Looking for Auditors!
The Matching Service for Auditors!
Go to the AuditNet® Career Center now for the latest job opportunities and career-related information and tools. 24 hours a day, 7 days a week you have the ability to not only look at available jobs, but you can also post your resume, apply for open jobs, research companies and obtain career advice. If you are in the market for a new job, make AuditNet® your first stop to check out what's available.
If your company has any audit job vacancies that you are looking to fill, have your HR people contact AuditNet® to post the job and search for candidates.
This is just another benefit of using AuditNet® as your one stop shop for all your audit and career resources.
AuditNet® Book Reviews
AuditNet® Software Compliance Audit Corner
|
Monograph on Software Compliance Auditing: Looking for a Career Change? Registered users can read the complete monograph by clicking here! Registered AuditNet users can send for 20 free software compliance articles. Login to your account and click on the link to receive the articles by email. Also the following articles should interest you! Microsoft has started a program recently in UK that has wide reaching implications for smaller and medium sized organizations, that auditors need to be aware of to minimize risk. More details can be seen by clicking here! |
Your Secret Weapon in the War on Fraud
White-Collar Crime Fighter brings you expert strategies and actionable advice from the most prominent experts in the fraud-fighting business. Each month you’ll learn about the latest frauds, scams and schemes... and the newest and most effective fraud-fighting tools, techniques and technologies you can put to work immediately to protect your organization.
Click here for the latest e-newsletter and subscription details.
The AuditNet® Audit Bookstore Corner
Looking for books on auditing related topics? We suggest using the AuditNet® bookstore. The bookstore focuses on Internal Audit but includes other related subjects as well. AuditNet® uses Amazon to power the bookstore so each purchase you make through this link helps support AuditNet®.
How to Say It When You Don't Know What to Say The Right Words for Difficult Times
By Robbie Miller Kaplan
As auditors we constantly interact with diverse stakeholders such as colleagues, managers, employees and others. Frequently we encounter people dealing with challenging and difficult times that may or may not be related to work. Our reaction to these situations is conveyed in our behavior both nonverbal and verbal.
For the rest of the review click here.
AuditNet® Vendor News
Check here for the latest news from our AuditNet® sponsors!
Dan's Internal Audit Corner
Each month Dan Swanson, a senior security and internal audit professional will provide his list of recommended resources for AuditNet readers. You can reach Dan at his website or by clicking here.
Tackling Operational Resiliency: The Next Priority!
Ensuring the organization can recover from a disaster is a basic business requirement that the board should explore regularly with management. Nowadays, leading organizations are taking this requirement and turning it into a strategic advantage, that is, investments in operational resiliency are assisting organizations in being more responsive to client needs as well as improving operational reliability, quality, and efficiency.
For the rest of the story and the links click here!
Also check out the latest IT and Information Security Titles Published by Taylor & Francis!
Revised: September 04, 2007