Module 6
Analytics, XBRL, IC, IS, Fraud
A. Big Data and Data Analytics
As technology advances at an alarming rate, there is much more data that could be
captured than ever before. In addition, storage of this large amount of data becomes more
feasible as the cost of data storage decreases. This trend is projected to continue
exponentially into the future. Business leaders increasingly understand the power of this
technology and recognize the value that data can have in an increasingly competitive
global marketplace. During this technological era, Big Data and Data Analytics are
having transformational effects on businesses. You’ll often hear the term Big Data,
especially when you’re talking about data analytics. We define Big Data as datasets that
are too large and complex for businesses’ existing systems to handle utilizing their
traditional capabilities to capture, store, manage, and analyze these datasets.
Volume is the sheer amount of data, regardless of its source. It might come from
corporate systems, clickstream data from social media (e.g., Facebook, Instagram, blogs,
etc.), from the government (e.g., census records), from Internet search engines (e.g.,
Google, Yahoo!), or just from the Internet in general. Variety is the form of the data.
Structured data is highly organized. It fits neatly in a table or in a database. The best
example of structured accounting data is a balance sheet or income statement, which
comes in tabular format and would be considered structured. Unstructured data is data
without internal organization (or structure or outline). Blogs and social media and
pictures posted in Instagram would be examples of unstructured data. Some estimates
suggest that 80 percent of enterprise data (things like emails, blogs, social media posts,
PDFs, and other documents) is unstructured!1 In between those two extremes would be
semi-structured data with elements of both structured and unstructured data.
We define Data Analytics as the science of examining raw data (now often
described as Big Data), removing excess noise from the dataset, and organizing the data
with the purpose of drawing conclusions for decision making. Data Analytics is useful for
a business to examine patterns and trends in large datasets. That is, the process of Data
Analytics aims at transforming raw data into valuable information. Data Analytics plays a
vital role in today’s business world by examining the data to generate models for
predictions of patterns and trends. If the data couldn’t be analyzed to provide meaningful
insight, the Big Data would not be nearly as valuable. Effective Data Analytics provides a
way to search through large and unstructured data to identify unknown patterns or
relationships.2 Then, this data is organized in a meaningful structure to be extracted in
order to provide useful information. Data Analytics often involves the technologies,
systems, practices, methodologies, databases, and applications used to analyze diverse
business data to help organizations make sound and timely business decisions.
B. The Benefits and Costs of the Use of Data Analytics on Business and Accounting
What differentiates Big Data from other types of data is determined “by whether
these data push the limit of capabilities of information systems that work with these
data.”4 Companies generally face two important limiting factors in their business systems
when dealing with Big Data: storage and processing. Depending on the size and resources
of the company, the amount of data the company can feasibly store varies greatly. Many
companies choose to use a cloud platform to lower the cost of data storage (e.g., AWS by
Amazon, Azure by Microsoft). In terms of processing Big Data, the processing power
required to obtain information valuable to the company could be enormous or even
impossible.
The data itself might have a cost to acquire (such as the cost to acquire weather
pattern data, Twitter data, economic data, etc). Another cost is that raw data must be
scrubbed from extraneous data and noise to become useful. This is generally referred to
as the extract, transform, and load (ETL) process. Reformatting, cleaning, and
consolidating large volumes of data from multiple sources and platforms can be
especially time consuming. In fact, Data Analytics professionals estimate that they spend
between 50 percent and 90 percent of their time cleaning data so it can be analyzed.5
This, too, has an explicit cost that includes the salaries of the Data Analytics scientists
and the cost of the technology to prepare and analyze the data that needs to be included in
the cost of performing Data Analytics.
Many companies address the likely possibility that the data their organizations
hold is, in fact, influencing their market value. A study from McKinsey Global Institute
estimates that Big Data could generate up to $3 trillion in value per year in just a subset
of industries impacted.6 Big Data and Data Analytics could very much transform the
manner in which companies run their businesses in the near future. According to a study
produced by CapGemini and EMC, it is clear that Big Data is a disruptive force and must
be addressed.7 That is, the real value of data comes from Data Analytics. With a wealth
of data on their hands, companies are empowered by using Data Analytics to discover
various patterns, investigate anomalies, forecast future behavior, etc. For example, with
insight provided through Data Analytics, companies could do more directed marketing
campaigns based on patterns observed in their data, giving them a competitive advantage
over companies that do not use this information to improve their marketing strategies.
Patterns discovered from historical data enable businesses to identify future opportunities
and risks. In addition to producing more value externally, studies show that Data
Analytics affects internal processes, improving productivity, utilization, and growth.
According to the results of the 18th Annual Global CEO Survey conducted by
PricewaterhouseCoopers (PwC), many CEOs indicate that they put a high value on Data
Analytics, and 80 percent of them place data mining and analysis as the second-most
important strategic technology for CEOs. In fact, per PwC’s 6th Annual Digital IQ
survey of more than 1,400 leaders from digital businesses, the area of investment that
tops CEOs’ list of priorities is business analytics.10 In its survey of executives, 82
percent believe that “organizations are increasingly using data to drive critical and
automated decisionmaking, at unprecedented scale.”
C. The Impact of Data Analytics On Accounting
We refer to financial reporting as the responsibility internal to the firm of issuing
financial statements and financial reports; an effort generally led by the chief financial
officer (CFO) and controller. Financial reporting includes a number of estimates and
valuations that might be better evaluated through use of Data Analytics. Both internal and
external data could be used to address many of the questions that face financial reporting.
ne way to answer these questions may include the possibility of using Data Analytics to
scan the environment—that is, scanning social media to identify potential risks and
opportunities to the firm. For example, in a business intelligence sense, it may allow a
firm to monitor its competitors and its customers to better understand opportunities and
threats around them.
For example, are their competitors, customers, or suppliers facing financial
difficulties (and so forth) that might affect their interactions with them? Data Analytics
may also allow an accountant or auditor to assess the probability of a goodwill write-
down, warranty claims, or the collectability of bad debts based on what customers,
investors, and other stakeholders are saying about the company in blogs and in social
media. This information might help the firm determine both its optimal response to the
situation and the appropriate adjustment to its financial reporting.
Data Analytics plays a very critical role in the future of audit. “As the business
landscape for most organizations becomes increasingly complex and fast-paced, there is a
movement toward leveraging advanced business analytic techniques to refine the focus
on risk and derive deeper insights into an organization.”12 In fact, in PwC’s 18th Annual
Global CEO Survey, 86 percent of CEOs say they find it important to champion digital
technologies and emphasize a clear vision of using technology for a competitive
advantage, while 85Ipercent say they put a high value on Data Analytics. This sentiment
has been reverberating through industry circles for several years now and has triggered
many public accounting firms to invest in technology and personnel to capture, organize,
and analyze this data to provide expanded services and added value to their clients. As a
result, Data Analytics is expected to be the next innovation in the evolution of the audit
and professional accounting industry.
Given the fact that operational data abounds and is easier to collect and manage,
combined with CEOs’ desires to utilize this data, accounting firms will be approaching
their engagements with a different mindset. No longer will they be simply checking for
material misstatements, fraud, and risk in financial statements or merely reporting their
findings at the end of the engagement. Now, audit professionals will be collecting and
analyzing the company’s data similar to how an internal cost accountant or business
analyst would in order to help management make better business decisions. This means
that external auditors will stay engaged with clients beyond the audit. This is a significant
paradigm shift. The audit process will be changed from a traditional process toward a
more automated one, which will allow audit professionals to focus more on the logic and
rationale behind data queries, and less on the gathering of the actual data.13 As a result,
audits will not only yield important findings from a financial perspective, but also
information that can help companies refine processes, improve efficiency, and anticipate
future problems.
It is clear that Data Analytics will transform the audit profession in several ways.
Both internal and external auditors can benefit significantly through the use of Data
Analytics. By using Data Analytics, auditors are able to spend less time looking for
evidence, which will allow more time for presenting their findings and making
judgments. This will help eliminate some of the mundane tasks involved with audits and
will lead to a more interesting and challenging experience for auditors. Data Analytics
will also allow auditors to vastly expand sampling beyond current traditional sample sizes
and, in many cases, be able to test the full population of transactions. With Data
Analytics, auditors will also be able to work from anywhere at any time, given the data
will be at the ready, and there will no longer be a need to pull data at the client site.
Another aspect of the audit profession that will change as a result of Data
Analytics is the clients’ expectations. Clients will begin to expect deeper and broader
insights, faster and more efficient delivery, as well as innovative thinking from their
auditors.16 Overall, the use of Data Analytics brings forth significant and exciting
changes to the audit profession. Auditors who adapt early to these changes will have a
significant advantage over slow movers because the harnessing of Data Analytics will
provide notable benefits in the upcoming years.
D. The Amps Model
Recall the analytics mindset proposed by EY (from the opening chapter vignette)
that all of their accounting professionals will ultimately need. Closely related to the
analytics mindset, in what we consider to be an effective approach to thinking about the
data analytics, is the use of a framework that explains the steps involved in the data
analytics process. Specifically, we recommend the AMPS model be used as a framework
for the data analytics process.
After completing all stages of the AMPS model, oftentimes the decision maker is
now more knowledgeable and better able to ask another deeper, more refined question,
which suggests the AMPS model should best be viewed as recursive in nature. Data
analytics might be viewed as successively peeling the layer of an onion. By peeling the
first layer of the onion, you now are able to see the next layer and evaluate it and remove
it to get to the third layer, etc. The best way to develop critical thinking skills is to ask
questions, which is the first step in the analytics mindset. Given that analyzing data
strengthens critical thinking (and vice versa), students should ask questions, which they
can often solve using data and data analytics.
Generally the more succinct the question, the better. For example, it is hard to
think about a question like “How does Walmart grow net income?” but easier to
potentially address a question like “How do we sell more bicycles at Walmart in
Fayetteville, Arkansas, store 359?” Narrowing the scope of the question helps enhance
the focus on a specific question. In data analysis, the axiom “your data won’t speak
unless you ask it the right data analysis questions”19 really speaks to the expertise the
accountant can offer by asking questions that are answerable by the data. Given
accountants’ knowledge of business processes, how information flows through the
organization (from customer to order desk to shipping dock to customer), and how and
when transactions hit the income statement, accountants can help management create
specific questions to address the heart of the problem, opportunity, or challenge at hand.
Moreover, accountants should have a thorough knowledge of an organization’s data to
determine what internal data can potentially answer the question and what additional
(external) information should be gathered.
External auditors (like Grant Thornton, PwC, Deloitte, Bob’s Accounting Firm,
etc.) require clients to share their data that is to be audited. If both the audit client and its
external auditor agreed on the same data standards to share their data, this cost of
cleaning and formatting the data could be alleviated. For this reason, the American
Institute of Certified Public Accountants (AICPA) worked to develop Audit Data
Standards (ADS). ADS is a set of standards for data files and fields typically needed to
support an external audit in a given financial business process area. These standards also
include questionnaires that may need to be considered to ensure that the data to be
accessed is a complete and valid population. While the AICPA’s most immediate goal is
to support the financial statement audit process, in practice there may be very similar data
requirements for external audit, internal audit, and compliance testing.
To evaluate the status and collectability of accounts receivable, companies
analyze how long the receivables have been outstanding. Knowing the current status of
accounts receivable helps us understand the potential to ultimately collect the receivables.
How does that help? The longer the receivables go unpaid, the less likely they will ever
be repaid. Aging receivables helps the company accountant and internal and external
auditors assess the right amount of the Allowance for Doubtful Accounts account.
E. Common Elements of Performing and Sharing Data Analysis
Data visualizations are graphical representations that present information to
decision makers. Data visualizations are one way we share the story. In Chapter 1, we
discussed the information value chain (Figure 1.2) from the Institute of Management
Accountants Statements on Management Accounting. The information value chain
collects data based on business needs and business events. Those data are turned into
information to create knowledge for decision makers and support decisions. Preparing
relevant, effective data visualizations requires an analytics mindset as discussed in
Chapter 10. Data visualization is the process of presenting information graphically that
consists of three basic activities.
There are several widely used tools for data visualization including Excel,
Tableau, and Power BI described later in this chapter. Each data analytics software
product includes its own data visualization tool. The visualization must focus the decision
maker’s attention and avoid information overload. Information overload occurs when the
level of information is greater than the decision maker’s information processing
capability.
In every case, you need to get data from a file, database, online service, or web
location. Often that data is in Excel or text (e.g., csv) format or can be downloaded in one
of those formats, such as online banking transaction data. As described in the data
visualization concepts section, you need to understand and clean the data for use.
Through careful analysis, select the attributes/ fields that support the story/purpose of the
visualization. In some cases, this requires calculation of new fields based on the available
data.
F. Using Excel, Tableau, and Power Bi for Data Analysis
This section introduces the use of Excel to perform data analytics. The example
employs a dataset that is available to students via Connect, and we encourage students to
replicate our analysis process. For consistency in describing the steps in Excel, we
describe tab, section, and item selection as X > Y > Z, where X represents the Excel tab,
Y is the section of the ribbon bar, and Z is the specific icon on the ribbon bar. The data
consists of three worksheets: Customers, Orders, and Stores in an Excel spreadsheet as
shown in Figure 11.1. In this example, the data already resides in Excel, but Excel can
interface with a variety of data sources. Select Data > Get & Transform Data to get data
from other spreadsheets, text files, databases, or online sources.
The first step to prepare the Excel data is to convert the raw data to tables (Excel
Table). Click on any cell within the data. Select Insert > Tables > Table as shown in
Figure 11.2. A Create Table pop-up will appear to specify where the data for the table is
and whether the table has headers. If there are no blank rows or columns in the data,
Excel will correctly identify the extent of the data for the table. Check the box to specify
that the table has headers. Select OK to create the table. Excel will apply a default design
to the Table that creates a style for the header row, adds filters to each column, and bands
the rows with alternating colors as shown in Figure 11.3. To apply a different style, select
Design > Table Styles and choose a new style from the available options. Excel by
default names tables Table1, Table2, etc. Select Design > Properties > Table Name to
rename the table. For this example, we create three tables and rename the customers data
as Customers, orders data as Orders, and stores data as Stores, as shown in Figure 11.4, to
facilitate connections among tables and further analysis in a pivot table.
The next step is to create relationships among the three tables shown in Figure
11.1. After reviewing the tables, we see that customer number, the primary key for the
Customers table, is included in the Orders table (a foreign key). Similarly, store
identifier, the primary key for the Stores table, is included in the Orders table as a foreign
key. So, we want to connect the Orders table to Customers table using customer number
and connect Orders to Stores with store identifier. Select Data > Data Tools >
Relationships as shown in Figure 11.5 to create the relationships. That displays the
Manage Relationships screen. Select the New button as shown in Figure 11.6. First,
select the table with the foreign keys (the Orders table) and specify customer number as
the foreign key. Then, select the table with the primary key (the Customers table) and
specify customer number as the primary key as shown in Figures 11.7 and 11.8. This
connects Orders to Customers. Repeat the process for Orders to Stores as shown in
Figure 11.8 and then close the Manage Relationships screen.
Before selecting attributes for Excel visualizations, we need to create a pivot table
using the database structure we just established. Click within the Customers table and
select Design > Tools > Summarize with PivotTable to activate the Create PivotTable
dialog box shown in Figure 11.9. Click the radio button to use the workbook’s data
model. Chapter 11 Data Analytics in Accounting: Tools and Practice 303 Otherwise, only
the Customers data will be selected for the pivot table. After clicking the OK button on
the dialog box, the box will close and the initial pivot table worksheet will display as
shown in Figure 11.10. The area on the left is where the pivot table will appear. The area
on the top right shows the available pivot table fields. In this case, available fields are
shown for all three tables.
Next, we format the pivot table. Click on the sum of sale amount field in the ∑
Values box to display a menu as shown in Figure 11.13. Select Value Field Settings.I.I. to
display the dialog box shown in Figure 11.14. Click on the Number Format button and
format the sum of sale amount field as currency per Figure 11.15. Click the OK button to
return to the Value Field Settings dialog box and change the Custom Name to Store
Sales.
Finally, we use the pivot table to create a pivot chart showing relative store sales.
First, we add a slicer to filter the pivot table and the pivot chart that we will create (note
that you can add the slicer at any time). Select Analyze > Filter > Insert Slicer. We are
interested in examining specific flower sales by store, so we select flower name for our
slicer. After creating the slicer, select Options > Buttons > Columns to change the default
(one column) to three columns. On the Options tab, you can also change slicer styles and
slicer caption. Slicers are interactive controls that allow easy filtering of the data
displayed in pivot tables and related pivot charts.
Tableau desktop is to perform data analytics. We use the same data employed for
Excel and follow the same general steps. Before reviewing this section, we encourage
students to visit the Tableau website to view some of the informative training videos.
Again, the data consists of three worksheets: Customers, Orders, and Stores in an Excel
spreadsheet. Note that Tableau currently offers free licenses to students. See the Tableau
website for further information. To start, open Tableau desktop.
The first step is to connect to the Excel data. From the opening screen in Tableau,
select Connect > To a File > Microsoft Excel per Figure 11.23. Tableau will also connect
to data in a host of other file formats. After loading the data, Tableau displays the Data
Source page. The next step is to create relationships among the three tables shown in
Figure 11.24. As before, customer number, the primary key for the Customers table, is
included in the Orders table (a foreign key). Similarly, store identifier, the primary key
for the Stores table, is included in the Orders table as a foreign key. So, we want to
connect the Orders table to the Customers table using customer number and connect
Orders to Stores with store identifier. Drag and drop each of the three sheets onto the
canvas (Drag Sheets Here). We recommend dragging Orders out first (the sheet with
foreign keys) and then adding Customers and Stores (the sheets with primary keys to link
to the foreign keys). Tableau attempts to set relationships as shown in Figure 11.25. The
overlapping circles indicate that type of join. The default is to only show records where
there are matching values in both tables (an inner join). For this data, that is the correct
join, but it is easy to change the join properties by clicking on the overlapping circles
icon and selecting the correct join.
Before we select attributes/fields for the first visualization, let’s review the layout
of the Tableau worksheet shown in Figure 11.27. The fields in the three tables are listed
in the left panel divided between Dimensions (1) and Measures (2). Dimensions are
categorical fields, such as store location, sale date, and zip code. Measures are numeric
fields that can be summarized, such as quantity sold, sale amount, sale price. Marks (3)
allow modification of the visualization by changing colors, size, etc. Sheet 1 (4) is the
area in which you will create the visualization. Show Me (5) helps you select the
appropriate visualization for the data you want to present. To create a simple chart, drag
Store Location to the Rows shelf and Sale Amount to the Columns shelf as shown in
Figure 11.28. Tableau automatically creates the horizontal bar chart.
Tableau can create many kinds of visualizations. Its Show Me tool allows easy
selection of appropriate visualization options. Select Show Me and then select one or
more of the fields of interest while holding the CTRL key down. The best options for
visualizing the selected data will be highlighted as shown in Figure 11.29 (other chart
options will be dimmed). Select the icon for any of the suggested charts to see what it
looks like with the selected data. Once your chart is selected, you can modify the
visualization using the Marks options. Figure 11.30 shows Color options. You can
change the color, opacity (transparency), and border effects of your chart.
After creating multiple visualizations, you can combine them on a Tableau
dashboard. Select Dashboard > New Dashboard. The sheets available for the dashboard
are listed on the left and hovering over each sheet gives a preview. To include any sheet
on the dashboard, drag the sheet onto the dashboard canvas as shown in Figure 11.32,
dropping each sheet in its desired position. Tableau also provides a Story feature where
multiple sheets and dashboards can be combined to walk the viewer through a story
designed to explain the results of the analysis. Select Store > New Story, then add sheets
and dashboards as story points. Tableau allows easy modifications to titles and display
options.
Power BI desktop is to perform data analytics. We use the same data employed
for Excel and follow the same general steps. Before reviewing this section, we encourage
students to visit Microsoft’s Power BI website to view some of the informative training
videos. Again, the data consists of three worksheets: Customers, Orders, and Stores in an
Excel spreadsheet. Note that Power BI desktop is currently a free download and only
works on Windows-based systems. See Microsoft’s Power BI website for further
information. To start, open Power BI desktop and sign in as appropriate.
The first step is to connect to the Excel data. From the Report View screen shown
in Figure 11.33, select Home > Get Data and pick Excel from the dropdown menu as
shown in Figure 11.34. Browse to the location of the Excel worksheet and open it. Figure
11.35 shows the three tables in the Excel spreadsheet. Select the check boxes next to each
table and click on the Load button. Move to Relationships View to set connections
between the tables. Power BI attempts to identify appropriate relationships between
tables and in this case successfully linked Orders to Customers and Stores (as well as
Stores to Customers by store identifier) as shown in Figure 11.37. You can modify or
delete relationships by double-clicking on the line between tables. We changed the
relationship between Stores and Customers to make it inactive and make the relationship
between Stores and Orders active. Inactive relationships are shown by the dashed line.
Moving to Data View as shown in Figure 11.38, you can edit the existing data,
format fields, and calculate new fields. To format a field, select Modeling > Formatting.
We change the format of sale amount to currency by first clicking on the $ icon and then
setting the decimal points to 2 as shown in Figure 11.39. To add a new column, select
Home > Calculations > New Column. This adds the new column and allows you to create
an expression for your new variable as shown in Figures 11.40, 11.41, and 11.42. To
create the expression, start entering the field name after the equal sign and select the
appropriate field as shown in Figure 11.41. Complete the expression and then change
Column to an appropriate name for the field as shown in Figure 11.42. In this case, we
create a new field, named Test Amount, to test whether the sale amount values are
accurate. After confirming the accuracy, we delete the Test Amount field.
Moving to Report View as shown in Figure 11.43, we are ready to create
visualizations. First, we add a simple table to the page. We click on the Table icon
(second icon in the last row of Visualizations). Then we select the store location field in
Stores and sale amount field in Orders. Power BI automatically sums the sale amount by
location and provides a grand total. To create a horizontal bar chart (as we did with both
Excel and Tableau), we simply click the bar chart icon (third in the top row) as shown in
Figure 11.44. Drag store location to Axis and sale amount to Value. To format the chart,
select the Paint Roller icon directly below the Visualizations area. This displays the
various formatting options as shown in Figure 11.45. You can modify the title, colors,
size, axis options, etc. The updated bar chart is shown in Figure 11.46. Finally, like
Tableau and Excel, Power BI provides various analytic tools as shown in Figure 11.47.
Selecting the Analytics icon (next to the Paint Roller), you can add trend lines.
G. Data Warehouses and Data Marts
Earlier chapters in this textbook demonstrated how information is gathered and
accumulated in a database. We are now interested in the reporting of that information to
both internal and external users. We introduce the overall concept of a data warehouse
and then specifically explain how data warehouses may be used in business intelligence
settings. We also discuss how dashboards are used to manage a company’s operations.
Finally, we explore the use of XBRL to share financial and nonfinancial information with
external users like the Securities and Exchange Commission, the Internal Revenue
Service, financial analysts, lenders, and current or potential investors.
Our discussion thus far in this book has been about operational systems primarily
designed and optimized to capture business transactions, such as sales and purchases. In
contrast, a data warehouse is essentially a new (often independent) repository designed to
be optimized for speed and efficiency in data analysis. More specifically, a data
warehouse is a collection of information gathered from an assortment of external and
operational (i.e., internal) databases to facilitate reporting for decision making and
business analysis. Data warehouses often serve as the main repository of the firm’s
historical data (or, in other words, its corporate memory) and will often serve as an
archive of past firm performance.
The best way to illustrate a data warehouse is by using a figure. Figure 9.1 shows
operational and external databases that are used as inputs into the data warehouse. The
operational databases may all come from within the company’s enterprise system or
various systems throughout the firm. The external databases may come from a variety of
places, including purchased data from the Gartner Group, the Federal Reserve, industry
organizations, and so forth. The opening vignette suggests Starbucks continues to use a
data warehouse and data marts within its organization. Figure 9.2 provides an example of
a potential data warehouse design for Starbucks. The figure highlights four types of data
marts (although the potential number of data marts is unlimited) that may be useful to
Starbucks: business intelligence, inventory, marketing, and sales and human resources.
H. Business Intelligence
Business intelligence is a computer-based technique for accumulating and
analyzing data from databases and data warehouses to support managerial decision
making. The term business intelligence is often used interchangeably with competitive
intelligence. Imagine Tesla using business intelligence to find indicators of quality issues
to pinpoint machinery failures in its assembly plants after collecting and analyzing data
on its processes. Sorting through the data may help Tesla predict and prevent failures.
Imagine Delta Airlines trying to decide how to price its flights from New York to
Atlanta. It can use business intelligence to track its competitor’s prices over different
times, days of the week, and so on. It can also use business intelligence to decide the right
mix of first-class, business, and economy passengers to maximize revenue. It can also use
business intelligence to decide the costs of canceling a flight based on its mix of first-
class and economy-class customers.
Data mining is one technique used to analyze data for business intelligence
purposes. Data mining is the process of using sophisticated statistical techniques to
extract and analyze data from large databases to discern patterns and trends that were not
previously known. Data mining is often used to find patterns in stock prices to assist
technical financial stock market analysts, or in commodities or currency trading. The
main caveat about data mining is making sure the results are reasonable (or even
plausible). While data mining may find a statistical correlation or relationship between
two data items, it may or may not have a plausible relationship in the real world. There is
a classic example that ice cream sales are correlated with drownings, suggesting that as
ice cream sales increase, the number of drownings also increases. That does not mean
that ice cream sales cause drownings or that drownings cause more ice cream sales, but
rather that warm weather caused both. So it is clear that professional judgment must be
used when using data mining techniques.
Your car has a dashboard that is easy to read and contains information that is
critical to the driver (e.g., engine status, engine heat, rpms, speedometer, odometer, fuel
levels, etc.). The original automobile dashboard designers carefully considered the most
important metrics of the automobile’s performance and conveniently put them in the best
place for the driver to see. Figure 9.3 illustrates an automobile dashboard.
In accounting information systems (AISs), a digital dashboard is designed to track
a firm’s process or its performance indicators or metrics to monitor critical performance.
Examples of the metrics that might be continuously tracked include month-to-date orders,
days that receivables are outstanding, budget variances, and days without an accident on
the assembly line. While the data on the main dashboard may monitor high-level
processes, lower-level data can be quickly accessed by clicking through the links. This
high-level summary with the lower-level detail allows executives not only to see the
summary, but also to drill down deeper as questions arise.
I. Financial Reporting and XBRL
XBRL stands for eXtensible Business Reporting Language and is based on the
XML language (Extensible Markup Language), a standard for Internet communication
among businesses. XBRL is specifically designed to electronically communicate business
information and is used to facilitate business reporting of financial and nonfinancial data.
One of the advantages of XBRL is that it greatly enhances the speed and accuracy of
business reporting. XBRL International has developed a taxonomy to describe and tag
thousands of financial statement items. XBRL provides major benefits in the preparation,
analysis, and communication of business information. Instead of treating financial
information as just a block of text that has to be manually reentered into a computer (or
digitized) to give it meaning, XBRL gives each financial statement item (both text and
numbers) its own unique tag that is computer readable and searchable. Total assets, for
example, has its own unique tag telling the database exactly what it is. Accounts
receivable has its own tag, and inventory has yet a third tag.
In February 2009, the U.S. Securities and Exchange Commission (SEC) passed a
new rule titled “Interactive Data to Improve Financial Reporting,” which required all
large domestic and foreign accelerated filers to begin formatting their financial
statements using XBRL. The new rule also requires these same public companies to
format their financial statements using XBRL on their corporate websites. XBRL US, a
division of XBRL International, was chosen to develop a single taxonomy for SEC
financial reporting.
The data start in the accounting information system (AIS). XBRL tags are then
assigned to each financial and nonfinancial item either automatically by the enterprise
system or manually by a member of the accounting department or its designee. The
XBRL tags are available for various uses, including reporting on the firm’s website,
filing to regulators (SEC, IRS, etc.), and providing information to other interested parties
(such as financial analysts, loan officers, and investors). Each interested XBRL user can
either access standard reports (i.e., 10-K going to the SEC or the corporate tax return
going to the IRS) or specialized reports (i.e., only specific data) using what is called an
XBRL style sheet (discussed in more detail later). The power of XBRL allows interested
parties to either access standardized financial statements and reports or access only the
information that is needed most for their own use.
The XBRL taxonomy defines and describes each key data element (e.g., total
assets, accounts, payable, net income). Because each national jurisdiction may have
different accounting rules and regulations, each country may have its own taxonomy for
financial reporting. That is why there are different taxonomies for each country: XBRL-
Australia, XBRL-Canada, XBRL-Germany, XBRL IASB, XBRL-Japan, XBRL-
Netherlands, and XBRL-UK. Taxonomies continue to be developed to enable filings to
regulators (such as banks), tax authorities (such as the IRS), and other governmental
entities. For example, U.S. banks are required to submit their quarterly report “Report of
Condition and Income” or their Call Report to the Federal Deposit Insurance Corporation
(FDIC) using XBRL. The Federal Financial Institutions Examination Council (FFIEC) is
responsible for creating XBRL Call Report taxonomy to facilitate filing call reports.
While the XBRL taxonomy describes the data elements, XBRL instance
documents contain the actual dollar amounts or the details of each of the elements within
the firm’s XBRL database. Thus, XBRL instance documents are a collection of data in a
computer-readable format. It is not until the style sheet is applied that the financial
statement information is finally readable by people. XBRL style sheets take the instance
documents and add presentation elements to make them readable by people. The data
may be presented in a number of formats, including HTML, PDF, Microsoft Word, and
Microsoft Excel (among others). The style sheet is made in conformance with a
standardized language called Extensible Stylesheet Language (XSL). The official XSL
specification for the XSL language is XSLT. This language is not governed by XBRL but
is a standard means for taking data from XBRL or XML and presenting computer
readable data in a way that is readable to humans. As discussed in Figure 9.4, different
users will have different style sheets to access the exact data they are interested in. While
the SEC may be interested in a standardized style sheet to retrieve a standardized report, a
bank loan officer or financial analyst may be interested in developing his or her own to
facilitate analysis.
Before the SEC mandated XBRL submissions, assurance on any voluntary XBRL
filings generally followed guidance from the Public Company Accounting Oversight
Board (PCAOB), which relied on the auditor comparing a paper output of the XBRL-
related documents to the information in the official EDGAR (Electronic Data Gathering,
Analysis and Retrieval) filing to note any possible differences. Now that the use of
XBRL is mandated by the SEC, assuring those XBRL documents is not required. It is
expected that investors and other financial statement users will ultimately demand some
assurance from an auditor or external party on a firm’s use of XBRL.
XBRL allows highly disaggregated data, so not only is it possible to know the
level of sales, but it is possible to know sales revenue in much more detail. For example,
it is possible for firms to apply XBRL tagging to sales by state or by country, by product
line, by store or by office, and so on. While the extent of disaggregated data that a
company will provide is still in question, the possibility allows opportunities for firms to
provide this potentially helpful data to external parties. As firms begin to use XBRL to
disclose disaggregated data, assurance will be needed on items that have never before
been disclosed to investors. It will be especially critical for these items to receive
assurance as mentioned under item 2 to ensure that the underlying financial and
nonfinancial data used in XBRL tagging are reliable.
Thus far, we have focused on XBRL for financial reporting. That type of XBRL is
meant to facilitate efficient communication between firms and external parties (e.g.,
shareholders, regulatory bodies like the SEC and IRS, and the like). In contrast, XBRL
GL (also known as XBRL Global Ledger Taxonomy) serves as a means to facilitate
efficient communication within a firm. XBRL GL allows the representation of anything
that is found in a chart of accounts, journal entries, or historical transactions—financial
and nonfinancial. The ability to tag using XBRL is generally supported by enterprise
systems (ERPs) such as SAP, Oracle, and Microsoft.
J. Ethics, the Sarbanes-Oxley Act of 2002, and Corporate Governance
Ethics, internal controls, and information security are three closely related areas
critical to corporate governance. Safeguarding the assets of a firm has always been the
responsibility of its management. Given the swift advancements in computing technology
and the pervasive use of IT in all aspects of business operations, managers and
accountants have to reexamine how to establish and monitor internal controls. For
internal and external auditors, it is important to assess the effectiveness of internal
controls to meet the mandate of the Sarbanes-Oxley Act.
Ethical principles are derived from cultural values, societal traditions, and
personal attitudes on issues of right and wrong. Integrity and individual ethics are formed
through a person’s life experience. Ethics play a critical role when people make choices
and decisions. Although individuals have their own values and may behave differently
from one another, firms often choose to establish a formal expectation, through a code of
ethics, on what is considered to be ethical within the group in order to promote ethical
behavior. Ethical behavior prompted by a code of ethics can be considered a form of
internal control. Given today’s diversified and globalized business environment, a firm
will have to rely on the ethics of its employees to operate efficiently and effectively. In
addition, the importance of a code of ethics should be emphasized because employees
with different culture backgrounds are likely to have different values.
The impact of public policy on the accounting profession through the enactment
of laws and regulations has been well-documented and can be traced back to the 1930s.1
Among those policies enforced, the Sarbanes-Oxley Act of 2002 (SOX) has probably had
the most far-reaching effect on public companies and accounting firms. This bill was a
response to business scandals such as Enron, WorldCom, and Tyco International. SOX
requires public companies registered with the SEC and their auditors to annually assess
and report on the design and effectiveness of internal control over financial reporting.
SOX also established the Public Company Accounting Oversight Board
(PCAOB) to provide independent oversight of public accounting firms. The PCAOB
issues auditing standards and oversees quality controls of public accounting firms.
PCAOB Auditing Standard No. 5 (AS No. 5) encourages auditors to use a risk-based,
top-down approach to identify the key controls. That is, auditors should start at the
financial statement level when analyzing controls, focusing on entity-level controls2
followed by reviewing significant accounts, disclosures, and management assertions.
K. Control and Governance Frameworks
Internal control involves the processes that an organization implements to
safeguard assets, provide accurate and reliable information, promote operational
efficiency, enforce prescribed managerial policies, and comply with applicable laws and
regulations. Appropriate internal controls support organizations’ objectives through
accountability and transparency for good corporate governance. According to SOX, the
establishment and maintenance of internal controls is a management responsibility.
Firms use internal controls as a means of preventing errors and deterring fraud.
The three main functions of internal control are prevention, detection, and correction.
Preventive controls deter problems before they arise. Preventive controls require
compliance with preferred procedures and thus stop undesirable events from happening.
For example, a transaction should be authorized to ensure its validity. Hence, a signed
source document should be required before recording a transaction. Detective controls
find problems when they arise. These controls are procedures and techniques designed to
identify undesirable events after they have already occurred. For example, bank
reconciliations and monthly trial balances are prepared to catch mistakes. Corrective
controls fix problems that have been identified, such as using backup files to recover
corrupted data. Detective controls are often linked to accompanying corrective controls to
remediate any issues that are discovered.
In a computerized environment, internal controls can also be categorized as
general controls and application controls. General controls pertain to enterprisewide
issues such as controls over accessing the network, developing and maintaining
applications, documenting changes of programs, and so on. Application controls are
specific to a subsystem or an application to ensure the validity, completeness, and
accuracy of the transactions. For example, when entering a sales transaction, use an input
control to ensure the customer account number is entered accurately. Given SOX, the
SEC requires management to evaluate internal controls based on a recognized control
framework such as the frameworks developed by the Committee of Sponsoring
Organizations (COSO) of the Treadway Commission.
COSO is composed of five nonprofit organizations: American Accounting
Association (AAA), American Institute of Certified Public Accountants (AICPA),
Financial Executives International (FEI), Institute of Internal Auditors (IIA), and Institute
of Management Accountants (IMA). COSO is a voluntary initiative to improve corporate
governance and performance through effective internal controls, enterprise risk
management, and fraud deterrence. COSO examines the causal factors that lead to
fraudulent financial reporting and develops recommendations for public companies,
independent auditors, the SEC and other regulators, and educational institutions to
improve the quality of financial reporting through internal controls and corporate
governance.4 COSO developed two frameworks to improve the quality of financial
reporting through accountability, effective controls, risk management, and corporate
governance. The Committee issued the “Internal Control—Integrated Framework” in
1992 and an updated version in 2013, and the “Enterprise Risk Management—Integrated
Framework” in 2004 and an updated version in 2017. The COSO internal control
framework is one of the most widely accepted authorities on internal control, providing a
baseline for evaluating, reporting, and improving internal control. COSO 2013 internal
control framework provides the principles for effective internal controls to address
changes in the business and operating environments, and to respond to expectations from
stakeholders.
The control objectives for information and related technology (COBIT)
framework is an internationally accepted set of best IT security and control practices for
IT management released by the IT Governance Institute (ITGI). It is a control framework
for the governance and management of enterprise IT. COBIT provides management with
an understanding of risks associated with IT and bridges the gap among risks, control
needs, and technical issues. The Information Technology Infrastructure Library (ITIL) is
a set of concepts and practices for IT service management. COBIT defines the overall IT
control framework, and ITIL provides the details for IT service management. ITIL is
released by the UK Office of Government Commerce (OGC) and is the most widely
accepted model for IT service management. ITIL adopts a life-cycle approach to IT
services, focusing on practices for service strategy, service design, service transition,
service operation, and continual service improvement. The International Organization for
Standardization (ISO) 27000 series is designed to address information security issues.
The ISO 27000 series—particularly, ISO 27001 and ISO 27002—have become the most
recognized and generally accepted sets of information security framework and guidelines.
As we know, COSO 2013 provides a general internal control framework that can
be applied to all firms on various systems. COBIT 2019 is a comprehensive framework
for IT governance and management and provides management and auditors with five
domains, 40 objectives, risk and value drivers, best practices regarding information
security, and a capability/maturity model for performance measurement to maximize the
benefits from IT. ITIL is a framework focusing on IT infrastructure and IT service
management. The ISO 27000 series is a framework for information security management.
COBIT 2019 provides the biggest advantages because it includes other widely accepted
standards, frameworks, and guidance for building effective IT governance and practices,
a firm can implement a wide range of desirable IT processes and controls, as well as
achieve its business objectives regarding IT security and service management.
L. Information Security and Systems Integrity
Rapid development in digital technologies has been a driving factor of consumer
demand, employee training, and efficient use of firms’ resources. As a result of the
maturing digital economy, firms across different industries will continue to be reshaped
through the application of information technology. In this chapter, we present a
discussion of one of the most critical impacts of technology on firms’ operations—
information security. We first introduce concepts and risks regarding information security
and then provide examples of computer fraud and how AIS can be misused in achieving
personal gains. We then explain common vulnerabilities and how to manage and assess
those vulnerabilities.
The AICPA conducts a survey each year to identify the top 10 technology issues
for certified public accountants (CPAs). The purpose of the survey is to indicate the
CPAs’ unique perspectives on how much each technology will affect financial
management and the fulfillment of responsibilities such as safeguarding assets,
overseeing business performance, and compliance with laws and regulations. For many
years, information security management has been ranked as the top technology issue for
CPAs. According to AICPA, “the primary focus of information security is the balanced
protection of the confidentiality, integrity, and availability of data while maintaining
efficient policy implementation and without disrupting organizational productivity.”
Encryption is a preventive control providing confidentiality and privacy for data
transmission and storage. It refers to algorithmic schemes that encode plaintext into
nonreadable form or cyphertext. The receiver of the encrypted text uses a “key” to
decrypt the message, returning it to its original plaintext form. The key is the trigger
mechanism to the cryptographic algorithm. The main factors of encryption are key
length, encryption algorithm, and key management. Longer key length provides for
stronger encryption. In general, a key length of 56 bits or less is insufficient for sensitive
data; 128-bit and longer key lengths are more than sufficient for secure data transmission.
In addition, using a strong encryption algorithm and establishing a strong policy on key
management are essential for information security.
Symmetric-key encryption is fast and suitable for encrypting large data sets or
messages. However, key distribution and key management are problematic because both
the sender and the receiver use the same key to encrypt and decrypt messages. If a firm
has many employees and trading partners at different geographical locations, it is very
difficult to always distribute keys in a secured way. In addition, managing one key for
each pair of users, which results in exponential growth of the number of keys for each
additional party, is not cost-effective given the large number of users among the firms.
Conversely, asymmetric-key encryption is slow and is not appropriate for
encrypting large data sets. However, because each user has a pair of two keys—the public
key and the private key—asymmetric-key encryption solves problems in key distribution
and key management. The two keys are created as one pair and you use one to encrypt
and the other to decrypt the data or document. The public keys are widely distributed and
available to authorized users. The private key is kept secret and known only to the owner
of the key. Hence, to transmit confidential information, the sender uses the receiver’s
public key to encrypt the message; the receiver uses his or her own private key for
decryption upon receiving the message. Refer to Figure 14.2 regarding the process of
how to use the asymmetric-key method to transmit data/documents in maintaining
confidentiality. Two common names for asymmetric-key encryption are public-key
encryption and two-key encryption.
Authentication is a process that establishes the origin of information or
determines the identity of a user, process, or device. It is critical in e-business because it
can prevent repudiation while conducting transactions online. Using asymmetric-key
encryption, authentication can be achieved for electronic transactions. For example, in
Figure 14.3, to authenticate the receiver (B), the sender (A) emails a challenge message
to B. B will use his or her private key to encrypt the challenge message and send it to A.
If A is able to use B’s public key to decrypt and get the plaintext of the challenge
message, A has authenticated B successfully. Please notice that only the pair of one
user’s two keys is used for encryption and decryption. In this example, B used his or her
private key to encrypt the message, and A used B’s public key to decrypt the message.
Keys from different users cannot be mismatched for encryption and decryption purposes.
Please note that this process would need to be repeated in reverse to authenticate both
parties involved in the transaction.
A digital signature is a message digest (MD) of a document (or data file) that is
encrypted using the document creator’s private key. An MD is a short code (256 bits or
32 characters) that is generated through a process called hashing, where the original
document passes through an algorithm (a series of steps) to generate the MD. Because
popular algorithms such as SHA-256 use every bit in the file to calculate the MD, the
change of a single character would result in a completely different hash. Therefore,
digital signatures can ensure data integrity. In addition, to create a digital signature, the
document creator must use his or her own private key to encrypt the MD, so the digital
signature also authenticates the document creator and serves the purpose of assuring
nonrepudiation.
The AICPA believes cybersecurity is an important part of risk management. A
company’s cybersecurity is an essential consideration for investors when deciding
whether or not to invest in a company. Public accounting firms may provide attestation
and advisory services to clients to enhance the reliability of a company’s cybersecurity
representations. Public accounting firms and their clients’ management have similar
obligations regarding cybersecurity as they do for financial audits. Management is
responsible for describing and asserting the effectiveness of its cybersecurity. The
accounting firm is responsible for providing an opinion regarding its client’s
cybersecurity. The AICPA created Reporting on an Entity’s Cybersecurity Risk
Management Program and Controls: Attestation Guide in 2017. This framework provides
CPAs guidance on performing cybersecurity examinations for clients.
M. Computer Fraud and Abuse
The International Professional Practices Framework4 (IPPF) of the Institute of
Internal Auditors (IIA) defines fraud as any intended illegal act characterized by deceit,
concealment, or violation of trust. “Frauds are perpetrated by parties and organizations to
obtain money, property, or services; to avoid payment or loss of services; or to secure
personal or business advantage.”5 It is important to understand that intent is a key
component defining and differentiating fraud from other acts and behaviors. In addition,
the Statement of Auditing Standards (SAS) No. 99, “Consideration of Fraud in a
Financial Statement Audit” states that an entity’s management has primary responsibility
for establishing and monitoring all aspects of the entity’s fraud risk-assessment and
prevention activities and has both the responsibility and the means to implement
measures to reduce the incidence of fraud.
Some of the most valuable items desired by individuals committing computer
fraud are the digital assets maintained by the firm. Most firms gather, create, utilize,
store, and discard data that have value to others outside the firm. Such data can be in the
form of employee or customer personal information such as governmentissued
identification numbers, bank account numbers, credit card numbers, other personal
information, confidential company information, and/or trade secrets. Whether the
perpetrator is an individual with authorized access to the data or a hacker, these data can
be sold to others or used for personal gain for crimes such as identity theft, unauthorized
purchases on stolen credit cards, or stealing or diverting money from a bank account.
Insiders, having legitimate access to their firms’ data, systems, and networks,
pose a significant risk to their firms. Employees experiencing financial problems may
tend to use the systems they access at work to commit fraud such as stealing confidential
data, proprietary information, or intellectual property from their employers. According to
the fraud triangle (see Figure 14.5), three conditions exist for a fraud to be perpetrated.
First, there is an incentive or pressure that provides a reason to commit fraud. Second,
there is an opportunity for fraud to be perpetrated (e.g., absence of controls, ineffective
controls, or the ability of management to override controls.) Third, the individuals
committing the fraud possess an attitude that enables them to rationalize the fraud.
Because research indicates that more than half of the malicious incidents in IT security
are caused by insider abuse and misuse, firms should implement a sound system of
internal controls to prevent and detect computer frauds perpetrated by insiders. However,
the reality seems to be that threats from inside have been overlooked by many firms. We
address this gap by introducing computer fraud risks, typical fraud schemes, and
strategies/techniques to prevent and detect computer frauds.
A fraud prevention program starts with a fraud risk assessment across the entire
firm, taking into consideration the firm’s critical business divisions, processes, and
accounts and is performed by management. Management is responsible for fraud risk
assessments, while the audit committee typically has an oversight role in this process.17
The audit committee often works with the internal audit group to ensure that the fraud
prevention and detection program remains an ongoing effort. The audit committee also
interacts with the firm’s external auditor to ensure that fraud assessment results are
properly communicated.
N. Vulnerability Assessment and Management
The Information Systems Audit and Control Association (ISACA) defines
vulnerability as “the characteristics of IT resources that can be exploited by a threat to
cause harm.”19 The GTAG considers vulnerabilities as weaknesses or exposures in IT
assets or processes that may lead to a business risk, compliance risk, or security risk.20
Vulnerability management and risk management have the same objective: Reduce the
probability of the occurrence of detrimental events. The subtle difference between risk
management and vulnerability management is that risk management is often a more
complex and strategic process that may take many months or years and is mostly
conducted using a top-down, risk-based approach, whereas vulnerability management is
often a tactical and short-term effort that may take weeks or a few months and is
frequently conducted using an IT asset-based approach. The purpose of an asset-based
approach is to categorize and prioritize further investigation efforts on each asset and to
identify appropriate control measures based on meaningful criteria, such as a monetary
value of assets and significance of the corresponding risks. To use this approach, it is
important to properly maintain asset inventory on an ongoing basis.
There are two prerequisites for vulnerability management. First, a firm should
determine the main objectives of its vulnerability management because the firm’s
resource for managing vulnerabilities is limited. In some cases, a primary purpose of
vulnerability management could be to comply with applicable laws, regulations, and
standards—in which case, the firm should determine which laws, regulations, and
standards it should comply with. Second, a firm should assign roles and responsibilities
for vulnerability management. Management may designate a team (i.e., internal audit
group, risk management committee, etc.) to be responsible for developing and
implementing the vulnerability management program. When assigning roles and
responsibilities (i.e., assigning an owner of each IT asset and/or process, implementing a
control self-assessment program, etc.), it is important to note that management’s
commitment and support, as well as the integration of vulnerability management efforts
within all levels of the firm, are critical success factors.
A key component of IT service delivery and support is making sure the data are
available at all times or, at a minimum, in the moment the data are needed. Even a short
period of system downtime on an e-commerce application can result in a loss of e-
commerce sales and, potentially, a loss of trust in the provider. Firms continue to monitor
system availability. Backups are used to alleviate problems of file or database
corruptions. An uninterruptible power supply is a device using battery power to enable a
system to operate long enough to back up critical data and shut down properly during the
loss of power. Fault tolerance uses redundant units to provide a system with the ability to
continue functioning when part of the system fails. Many firms implement a redundant
array of independent drives (RAID) so that if one disk drive fails, important data can still
be accessed from another disk.
Recently, cloud computing has become a popular model for business operations.
In general, cloud computing refers to a service model in which a third-party service
provider offers computing resources, including hardware and software applications, to
cloud users over the internet, and the service provider charges on a per-user basis. A
cloud user company often shares the computing resources with other user companies, and
a cloud provider bears the responsibility for managing and maintaining the resources. A
survey result showed that 43 percent of 2,014 IT leaders in 50 countries indicated that
their companies were projected to have most of their IT efforts running in the cloud by
2015.22 However, a user company must evaluate a cloud provider’s credibility, controls,
and security of the systems and networks and its financial viability carefully before using
the cloud provider. It is important that a cloud user company obtains and reviews a
service organization control (SOC) report from the cloud provider prior to signing an
agreement for the service (could be a SOC 1 report). If the business operations are critical
to the cloud service user company (such as storing its confidential data and hosting
critical applications), the user company should consider requiring an SOC 2 or SOC 3
report. The SOC 1 report focuses on the impact of the cloud provider’s controls on the
user company’s financial statements. On the other hand, SOC 2 and SOC 3 reports
provide the evaluations on a broader set of controls relevant to security, availability,
processing integrity, confidentiality, or privacy implemented by the service provider.
O. Disaster Recovery Planning and Business Continuity Management
Adverse events happen in every daily business environment. For any firm, it is
essential to establish and maintain a proper plan to recover from a disaster or any
disruptive event and to continue its business operations. In recent years, the severe
experience of natural disasters (such as the tsunami in Japan and the tornados in the
United States) reinforced the importance of disaster recovery planning and business
continuity management. Disaster recovery planning (DRP) is a process that identifies
significant events that may threaten a firm’s operations and outlines the procedures to
ensure that the firm will resume operations if such events occur. DRP must include a
clearly defined and documented plan that covers key personnel; resources, including IT
infrastructure and applications; and actions required to be carried out in order to continue
or resume the systems for critical business functions within planned levels of disruption.
A disaster recovery plan should be reviewed and tested periodically to analyze
weaknesses and explore possible ways to improve the plan.
While DRP is the process of rebuilding the operations and/or infrastructure after a
disaster has occurred, business continuity management (BCM) refers to the activities
required to keep a firm running during a period of displacement or interruption of normal
operations. DRP and BCM are the most critical corrective controls, and DRP is a key
component of BCM.23 BCM is broader than DRP and is concerned with the entire
business process, rather than particular assets such as IT infrastructure and applications.
To achieve business objectives, a firm must continue to perform its critical business
processes, as well as IT functions that support the business processes.
International Organization for Standardization (ISO) 22301 is the commonly
accepted standard for BCM. It establishes the process, principles, and terminology of
continuity management for business and its IT functions. ISO 22301 provides a
framework to plan, establish, implement, operate, monitor, review, maintain and
continually improve a business continuity management system (BCMS). It is expected to
help organizations protect against, prepare for, respond to, and recover when disruptive
incidents arise.24 As shown in Figure 14.12, BCM often includes the following
components: (1) understanding the firm and identifying risks; (2) analyzing business
impact of the risks; (3) determining BCM strategy and developing plans for the BCM;
and (4) testing, maintaining, and improving the firm’s BCM practices.