c c c c In this session, we will address some findings of our recent audit.
Always starting off positively, we have, in most cases, mitigated the
majority of the previous year's findings. However, this year there are
still some reoccurring issues and one new unresolved. The utilization
of Shadow IT. To specify, active usage of unapproved and
unauthorized cashless payments at several of our locations and office
within PB. Payment services at PB range from the concierge desk to
contactless payment. It is important to remember that revenue of all
types improperly maintained or recorded possess financial and
security risks and could lead to tax evasion are actively taking
measures to include a cease and desist. We want to ensure that all
financial information reported is within our account information
system and abides by GAAS standards (astatebystate accounting
guide, 2021).
The issue with Shadow IT:
Compliance: the utilization of technology or application poses a
threat of many kinds, including compliance with standard use and
security, and goes against our policies at PB as well.
Security - if the technology is not approved or not to standards, our
location could be compromised. This would be a very costly event to
mitigate, going over budget in overtime to find exactly how or what
the breach was and how to fix it. Also, or equipment is equipped
with everything that any anyone location should need.
Records of Sales- when using an authorized method at the point-of-
sale risk of false reporting.
Vulnerability – using unapproved payment staff increases the risk
factor that already exists and creates an unknown vulnerability (C-
CORPORATE COMPLIANCE INSIGHTS, 2019).
Ways to prevent noncompliance:
Third-Party Compliance- Be able to verify that the vendor has been
approved and ensure that the vendor are within the standard of
conditions of policies and regulation for the operation of PCI DSS
Ensuring End 2 -To-End Encryption with the POS is secured on
every level to safeguard financial transactions and records
Implement a financial information system- This allows for a company
to store, organize and analyze the information as a stand-alone
functional application.
Updates- allowing for regular updates of systems, patching, and
keeping in the now to policy changes and updates to avoid costly
penalties.
The security risk of mobile devices such as mobile devices and
wearable devices that were not originally purposed for payment has
to meet PDIS standards with the exception of some devices stated in
category three scenario two. The location of which audits findings
reflect noncompliance will be penalized should the cease and desist
not immediately be effective and implemented throughout the
location.
Works Cited
astatebystate accounting guide. (2021, November 5). Retrieved from
AccountingEdu.org: https://www.accountingedu.org/public-
accounting-jobs-what-is-public-accounting-accountant-salaries-and-
degrees/
C-CORPORATE COMPLIANCE INSIGHTS. (2019, September 9).
Retrieved from The Challenges of Managing PCI DSS Compliance:
https://www.corporatecomplianceinsights.com/challenges-pci-dss-
compliance/