Transcript
Speaker: Welcome to another episode of Balancing the Future. My name is Chris Mitchell, and I am excited to have Ian Burnett. Ian Burnett is a managing director with Serious Solutions. And you know, this guy is an expert.
Speaker: I call him an expert when it comes to internal audit of compliance and governance, because he's been doing it probably as long as I've been doing it. So Ian, welcome. Thanks for making time for us today. i know i'm not I haven't done your background justice. So please share with the audience some of the unique things that you've done in the past.
Speaker: Yeah, thank you very much, Chris. Great to be here with you. So excited to have time today to talk about all this. So yes, I am a managing director with Serious Solutions, fairly new to that organization, but I have a lot of history in the consulting and advisory space around GRC, especially all things internal audit and Sarbanes-Oxy, which I know we're going to spend a lot of time talking about today. So very excited about that.
Speaker: And importantly, I've been on both sides, meaning most of my career has been in consulting and advisory roles like the one I have now. But I also spent time in industry and had key roles in internal audit at some very large organizations, which allowed me to travel globally and get into some really neat stuff.
Speaker: So, um you know, it's it's been a passion of mine to to talk about these things for for many years, and I'm excited to get into it with you. You know, when you mentioned internal audit and we think about Sorbanes-Oxley and Sorbanes-Oxley arrived back in 2002. That was a long time ago. I was but a pup out there doing the best that I could as relates to internal controls work. And I remember when I was pulled in and someone told me about the the regulatory guidance and what was coming down and we didn't know how to solve for it. I won't tell you what company I was with because I want to give that away. However,
Speaker: um I think the audience needs to understand, you know, the initial intentions of a 404, Sorbanes-Oxley. I know these internal audit professionals are probably shaking their heads, and no, I don't. And some executive leadership saying, no, I don't, because we have been dealing with it now for quite some time. But I think it's interesting to give just a bit of history.
Speaker: What do you know about it? Yeah, no, you're absolutely right, Chris. it It deserves a little bit of time for some context setting. And I would like to say I was a pup too, but actually I parted my career before all of this ah came out. So I was doing internal audit before SOX and I was there for the the genesis of all this. And so to get to the point, you know why did we even have this? Right.
Speaker: And It really came out of the the massive corporate failures of Enron and WorldCom back in 2001. So as you said, over 20 years ago now.
Speaker: and And those were horrible events. And you know a lot of people lost money. you know Investors suffered greatly because of those circumstances. um But I think Congress had sort of a knee-jerk reaction to to some of that. And thus, the Sarbanes-Oxley Act ah was born in 2002, as you said. And well-intended, a good act. I've read it many times and well-intentioned.
Speaker: And really, a lot of positivity is you can tie back to the act and how there is really good awareness of of internal controls and their importance when it comes to financial reporting and all of that.
Speaker: And so that act created the PCAOB, which became the institution that started to oversee the external auditors. And after the act was passed, the PCAOB was formed, and then they wrote up some standards about, okay, how is this going to actually be implemented? And how will external audit firms go about um issuing opinions that the act required them to to do around internal control over financial reporting?
Speaker: So we started with AS2. And ah the way that people interpreted ah the AS2 Act, it really required folks to to dive into a heck of a lot of detail, really documenting everything, right? Going through a lot of detailed walkthroughs, really culminating in massive amounts of walkthrough documentation and control matrices and and all of that. Very, very granular, right?
Speaker: And it's understandable because it was a new thing. People didn't really know, you know, how should we do this? a lot of folks, I was in big four at the time when this came out. So I was there from from the get go and everybody was sort of scrambling to figure out how we going to do this?
Speaker: And, um you know, the the the reaction was, let's just document everything. Right. So that happened. And a few years went by and people kind of thought about it a little bit more and said, is this the right thing to do? Is this, does it make sense? Is this really risk-based in terms of how we're going about doing this work?
Speaker: And so the PCAOB came out with another standard AS5, 2007. And in that document, the the the thinking was, let's take this up a notch. Let's come at this with more of a risk-based approach. Let's think about entity level controls and try to get away from the super granular level of documentation and work that was taking place.
Speaker: And that made sense um in in theory. But I think, Chris, I would say that at the end of the day, it didn't really change things that much. ah External audit firms and companies never really made a full pivot, I would say, away from the details and the intensive granularity of of what they had been doing previously.
Speaker: There was some shifting here and there and so on. But you have to remember that, um and rightly so, external audit firms... um are very aware of managing their own risk.
Speaker: So naturally there's this inclination to to do more rather than less, to kind of manage that risk. And and their expectations of course, ah were pushed on to their clients and internal audit departments, which we'll get into more of that, ended up playing a pretty significant role in the Sarbanes-Oxley implementation process and have continued to do so through the years here.
Speaker: And um I think it kind of brings us to a point where There's always fresh thinking that needs to happen. And we're sort of at that moment now. And I know the Institute of Internal Auditors, which is the global governing body of the internal audit profession, ah has recently written some ah papers on this. So a white paper on modernizing the Sarbanes-Oxley Act and really thinking a little bit more on what really makes sense, especially for internal audit teams that are supporting this effort.
Speaker: You know, when you share it quite a bit, and what I remember about that time, it was absolute chaos. And what I mean it was chaos is that no one could really interpret the standard the right way.
Speaker: And we we tested everything. Okay, the matrices that you mentioned, we were just scattered and trying to do way too much work. I will say this. I believe it someone made a lot of money off of 404 initially.
Speaker: Those initial days, I'm not saying who, but it was just a confusing time. You mentioned something that hits home. You said we inherited that as internal audit professionals.
Speaker: Was that a good thing or a bad thing? I'm trying to figure out how we got stuck with it. And I can say this, how we got stuck with it, because um when you think about what it looks like today,
Speaker: It's completely opposite of what I think we probably considered ourselves experts at. Yeah, we manage risk, but we manage and help. We don't manage anything, but we we review, we you know we draw conclusion on the risk and control framework across a ah broad area of things.
Speaker: And I think we're somewhat isolated with 404. So when I think about You know, how we got it and why we got it and how it's hurting us today.
Speaker: You know, that's the way I see it or interpret it. What do you see? I mean, you you were around as well. But what did you really see when they came and they said, hey, you're doing now a focus on 404, but you still have to run a program up against the framework, yeah a plan up against the framework.
Speaker: It had to be confusing. So I'm interested in what your initial thoughts were. Yeah, it is confusing and and created a lot of confusing ah confusion, like you said, Chris.
Speaker: But it's interesting because internal audit departments are seen as experts in risk and internal controls. And it's an interesting dynamic about the SOX Act itself, if you go back to it, is that nowhere in the Act does it even mention in internal audit.
Speaker: And this is one of the things that's part of the refresh that the IA is looking at now. So it really talks about management. you know Management has internal controls. Management is managing risk associated with internal controls over financial reporting.
Speaker: But somehow the brunt of this fell on the lap of internal audit because they had the expertise maybe that other people didn't have. And there's there's value in what internal audit does, for sure, because they do have that expertise.
Speaker: But it has to be balanced. It should be balanced. And it hasn't always been balanced. And by that, I mean, there are certain organizations out there where almost the entirety of the responsibility for the SOX program kind of fell on internal audit. Now, to your point, internal audit doesn't manage risk. It doesn't own the controls. It never should.
Speaker: But they had availability or seemingly it was thought that they had the availability to take this on maybe in a way that was better than what management could do themselves.
Speaker: So I call it a punt. It was punted to internal audit in in many instances, but there's consequences from that, right? And what does that mean? Well, every organization and has a budget. Internal audits have, ah departments have budgets.
Speaker: And to your point, with the extreme level of effort that is required for SOX, or the way it was sort of interpreted early on with all that detail, something had to give. And a lot of things, you know, got pushed aside because of the massive effort that was required for SOX.
Speaker: So some internal audit departments, you know, took this on and it was... Almost the entire budget in some cases. In some cases, maybe it was 50%, 60%.
Speaker: But all of that time spent doing SOX, and there's value there. Don't get me wrong. There's value. But it meant that other things that internal audit historically might have looked at or other other places where they could add value,
Speaker: ah Just they weren't able to do it. They weren't able to do that. So this is ah sort of an ongoing situation that um it warrants some reflection and stepping back to say, does this make sense?
Speaker: So let me let me talk about the culprit. this material weakness, this disclosure. And I think it kind of overshadowed everything.
Speaker: And we started thinking about what did we find? We do all of this work and then we prioritize certain things. And we've always prioritized IT controls. okay and i started thinking about how that kind of overshadowed you know the overall process in the reporting piece of it what are your thoughts when i say material weakness what comes to mind because i'm going to give you my two cents my two cents is We isolated our focus on IT, ITGC in particular, and it overshadowed and gave purpose in a different way to what we did as it relates to 404 and what was in focus when we had conversations with the executive leadership. What do you think about that? I know we all, I made money at it because I was consultant back then, so I get it.
Speaker: But I think it was a slippery slope for us, and I don't think we've come back from that. So what are your thoughts? Yeah, I don't disagree with that, Chris. um If you look at data around material weaknesses, and and first of all, let's step back and talk about what is a material weakness, right?
Speaker: It's really the probability that there could be a material misstatement in the financials at the end of the day. And so there's ah a size dimension to it. Things have to be over a certain materiality to qualify to to rise to the level of material weakness.
Speaker: And there's a probability element to it. But you have to remember, now that we have SOX and SOX 404 in particular, ah The 404B opinion is a separate opinion from what the financial statement audit opinion is.
Speaker: So companies can fail SOX in the form of having a material weakness and still pass their financial statement audit opinion, meaning it's an unqualified opinion, right? There's no there's no issues um or nothing that is going to make it unqualified.
Speaker: But If you look at the material weaknesses that are often cited, as you said, it it's often ITGCs. And I think the reason is because they're very rules-based, pretty low judgment type of controls.
Speaker: And there's a lot of them. a lot A lot of companies have a lot of different systems. And there's a fairly standard set of ITGCs that get looked at, you know, things around access controls and change management and and so on.
Speaker: And they're often cited as as issues um because they're easy to to spot. you know People might not take someone's access away timely or that sort of thing.
Speaker: And if that's written up as a control, and remember, you know with all the detailed work we did, we wrote down controls. And in a very literal sense, you know what people generally test in the control is what does the control say? And if if the attribute is you've got to remove someone's access within X time period of them terminating the company or leaving their job, then it's ah it's an easy pass fail, right? It's very rules-based.
Speaker: But... um you know, at the end of the day, these aren't typically the things that do drive failed audits and potential real misstatement and financials.
Speaker: And so ive I've called this, I've written about this before, and I've called it the the two opinions conundrum. I've also referred to it as the ITGC paradox. And because I feel like There's a bit of a disconnect between the two opinions, the ICFR opinion for 404B and the financial statement audit opinion.
Speaker: And the data kind of proves this out. I've looked into this um and and cited some other research that other people have put together. Where you know there seems to be a bit of a disconnect, and you very often see these material weaknesses cited in 10K filings related to ITGCs because there was a you know there was enough of ah the failed ITGC controls that they aggregated up to a material weakness.
Speaker: But then you go back to the previous paragraph and look, and you see it was an unqualified financial statement audit opinion. And why is that? Well, very oftentimes, there's other mitigating controls.
Speaker: There's other things that management does to make sure that they don't have any kind of material misstatement in the financials. And I actually think it's pretty rare, and the data that I looked at kind of proved that out, it's pretty rare that an ITGC material weakness would actually drive a material misstatement in your financial reporting.
Speaker: The things that do drive material misstatements are usually things more related to overall governance, entity level controls, the ah capabilities and and quality of the finance and accounting team overall, and more complex um accounting requirements. And a good example of that is revenue recognition. you know We have ASC 606.
Speaker: which has a lot of different criteria around you know how you recognize revenue ah across various types of contracts and industries and so on. And those are the things that really drive material misstatement.
Speaker: And they're very judgment oriented, right? They don't typically, it's not it's not cut and dried. It requires people really applying thinking and judgment and challenge, um which is very different from what people do when they're looking at ITGCs.
Speaker: Ian, you know, you mentioned opinion and you mentioned the parties involved. i know you've got the external, you've got the internal influence with internal audit, but you've also got the board and the various committees and leadership trying to figure out what the heck are we doing?
Speaker: What do you share with leadership in an equation like this? Because they are impacted. And they're trying to figure out, are we leveraging one another the right way? What do you say to that?
Speaker: Just to put any, because I know we've got some chief audit executives well as leadership that are tuning in. What would you share with them in in an instance like that? Well, Chris, I think it definitely demands some coordination and some some conversations to make sure that what everyone is doing to to satisfy this Sarbanes-Oxley compliance regulation makes sense.
Speaker: And to your point, um boards and and audit committees, they want to make sure that their companies are in a good place and they have good, clean financial reporting and unqualified opinions coming out of it.
Speaker: And it does require coordination because the Sarbanes-Oxley Act, we didn't get into this previously, but I talked about 404B, which was the external auditor ah having to make their opinion about internal control over financial reporting.
Speaker: But the other component of the SOX Act was 404A, which was that management has to make an assertion around their internal control effectiveness. And that gets published in a different place in the 10K.
Speaker: So you've got both sides. It does depend on the size of the company. Certain companies, if they're below a certain threshold, um you know they they have to do A, but B doesn't come into play.
Speaker: But for if you're big enough for B, you're certainly big enough for A, and the coordination is required. And everyone's looking to do it in the most efficient way. So the internal audit teams, as I mentioned previously, got tapped on the shoulder to say, hey, you guys need to get involved with this. You have some really good expertise around risk and internal controls and know how to test and so on.
Speaker: And it made sense. And so what we... came to see is that in some cases, depends on the external audit firm, there's this reliance that's placed on work that internal audit does. So the I see it as the goal of internal audit in many ways is to to get out in front of external auditors and make sure or help to make sure the company is going to be in a good place when the external auditors come along and do their piece for 404B.
Speaker: And certain um you know controls may be ah able to be relied upon by the external auditors. And so that work would not get tested twice and you would have the benefit of that coordination.
Speaker: There are probably some opportunities to to do a bit more of that here and there, um but it does depend on the external audit firm and and what they want to do and so on. But back to to what we were talking about earlier, I do think that there is this risk paradox in the sense that a lot of time is spent on the ITGs, like we said.
Speaker: And are we really spending enough time on the things that could potentially move the needle from a ah misstatement standpoint? And I think that's a conversation that executives really should could could have more often, I'll put it that way, and even boards to just really understand is the place where we're spending our time, does it make the most sense given the risk that we have in the organization?
Speaker: And should there be some rebalancing of of how we do these things over time? And does it make sense to define even more explicitly what is internal audits role in all of this? And that was something that the IA did really talk about in their recent ah white paper, which is entitled Modernizing the SOX Act.
Speaker: So it makes a lot of sense. I think after... 20 plus years, this is a good time to take a look at things you know with a fresh set of eyes. And you know we'll probably get into this a bit more, Chris, is the technology we have today has changed.
Speaker: We've got a lot of new tools now. Yes, sir. With AI that um you know came on the scene a few years ago. And it it changes the game in some ways. And it changes some of the things that we can and should be able to do moving forward.
Speaker: So there's a couple of things that I want to touch on. One, I want to talk about how important the relationship is between internal audit and the external auditors, um because I think it is absolutely critical that you guys be, and or we be in lock and step with them to get through that exercise.
Speaker: And that's just my experience. What has been your experience with external audit and having that sound relationship to make sure that things flow the way they should? Yeah, I think you you hit the nail on the head. the The coordination and the coordination is really, really critical.
Speaker: And certainly you don't want internal audit management and external auditors off doing things in silos. There really needs to be a lot of coordination there and combining efforts to look at process, to look at walkthroughs,
Speaker: Getting clear ah indications on where that reliance might happen, where does the external auditor really want reliance, and what are their expectations for that is is also a good thing to get clarity on. How is everything going to be documented? What are what is the form of the final work papers and the results of testing?
Speaker: these are great conversations to have early on to really maximize that coordination and make sure that there's no surprises the last thing you really want is surprises in this process and i've seen it many many times where you kind of come down to the year end and there's some disconnects because the coordination wasn't exactly where it needed to be in fact a few years ago i had a situation where I had a client that ah was looking at the possibility of of some material weaknesses being reported.
Speaker: And they ah they called me in to kind of take a look at that situation. i was able to unpack the circumstances and what had happened. and ah helped them to kind of identify some other things and some mitigating controls that maybe hadn't been fully considered in terms of of the entire picture and uh you know they were very appreciative because at the end of the day they were able to avoid any kind of material weakness being reported in their ah financial statements and it ended up as a a clean 404 opinion
Speaker: and and a financial statement opinion as well. So, you know, would this have happened if with better coordination? I don't think so. I think it's really about, you gotta have those lines of communication open and have a lot of um open and honest discussion about the best way to get through this and how to do it in ah in a way, if I can say this, that's least painful for everybody.
Speaker: You know, one thing I'm thinking about is opportunity. And when I look at internal audit and 404 and trying to figure out what the right approach looks like, and I'd like to take some time to just step through, you know, a good approach and how to go about managing 404. 404 SAP's resources,
Speaker: It saps the the focus of the internal audit team. It overshadows, you know, other areas, high risk areas that we probably should be spending time on. How do I get it right?
Speaker: So if I'm sitting now with my team and I'm sitting now with my leadership, which we get to do often. as the chief audit executives, how do I get it right? How do I have the right conversation? yeah And what is that opportunity? And help me graduate through some logic on that, Ian. So the audience is better equipped when they're having those, um ah how can I put it difficult conversations with leadership.
Speaker: Yeah, and it it touches on what we were talking about earlier, Chris, in, you know, very often you see organizations where internal audit is taking on such a heavy part of this load.
Speaker: And Go back to the Sarbanes-Oxley Act in the beginning. And as I mentioned before, internal audit isn't even mentioned in in the original act in 2002. So I think what's important, it really, it's talking about management.
Speaker: And so I think internal audit definitely has a place in this process. But at the end of the day, and you you said this earlier, Internal audit doesn't own risk management.
Speaker: Management owns risk management. And so I really think an important thing to do is very early on in the SOX process is really get some more clarity around explaining who owns what in this process and making it very clear to people that work in in areas within the organization that potentially could have an impact on financial reporting, be it finance, accounting, and IT t has a role for sure.
Speaker: um making sure that that the stakeholders in those departments in management understand that they are responsible. for internal controls and managing the risk that ultimately could um impact the the financial statements and the reporting.
Speaker: So, and you don't always see that. Sometimes, you know, too much is pushed to internal audit as we've talked about. And it it kind of lets, um and and I'm not saying this is universal, but there are organizations where that ownership is not at the level where it should be.
Speaker: You know, people don't step up and, you know, why don't why don't we put this in job descriptions and say, if you work in finance, if you're a controller, if you're performing reconciliations and so on, make it explicit that, you know, part of that job and part of that responsibility ah is really important.
Speaker: including SOX and making sure that those controls are designed effectively, that they are being performed as expected and so on. And it gets to you know a lot of companies, especially for, we didn't get into this yet, but SOX 302, which is more of a ah quarterly requirement,
Speaker: um Make people assess their own controls and go on record to say, i have i own these controls, I'm performing them, and everything's good. They really need to to take on that responsibility. And if you do that and you really define the roles effectively, and where does audit play and fit in most often and and best use is is independent ah testing of controls, that's when you really can can get a good result there.
Speaker: You know, i also think about the option of outsourcing because sometimes a leadership believes that that is the solution and it's not. And they think it's taken away from my responsibility as a chief audit executive, but it's not.
Speaker: I'm still involved. I'm still woven in. I still have responsibility. Is that what you see or have seen in the past as well? No, absolutely. ah Outsourcing and co-sourcing is a great model because, you know, the people that you can bring in to do that, they can they can provide a lot of that expertise and a lot of that um work that is just so demanding from from a workload standpoint and maybe allow internal audit to to do some other things.
Speaker: But... you can't outsource that responsibility fully. I mean, i a a consulting firm coming in cannot own controls, right?
Speaker: And their primary role in the process is to bring expertise, to be good advisors, to do independent testing of controls. So it is a ah role that's very heavily focused on facilitation of the process. And you can use your external consultants to help with project management ah to do reporting to executive leadership and audit committees and boards as necessary.
Speaker: They're perfectly capable of doing that. They do a really good job with it. And they can share leading practices and things that they see at other clients. And that's important to bring that perspective as well.
Speaker: But at the end of the day, they are there to to advise and assist. They cannot own the process. And I think most chief audit executives recognize that.
Speaker: um But it's a really good, powerful solution in many cases is to to have ah a combined team. You know, I think about um the strength of that team and and coming together and being able to deliver that way. But I also know it doesn't change my focus and my plan. I'm still covering a broad range of risk.
Speaker: Okay. 404 is 404. All right. I still have to run a plan up against the framework. And what I'm saying politely, and I'm trying to get leaders to understand this, don't cut my budget.
Speaker: And i maybe I can say that aloud. Maybe you're you don't want to boldly say that, ian but you can't keep cutting the but the budget in FTE because there's so much more that we need to do as internal audit. What do you think about that? When I share something like that, what are you what are you thinking about?
Speaker: No, I agree with you, Chris, because as we've talked about, the SOX component of what internal audit departments get involved with, ah it's it's a lot. It's often a lot of it in a small company or certainly more than a majority of the internal audit work in in some larger organizations.
Speaker: But ah that leaves a lot of things untouched, to your point. So if you go back to pre-SOX, And the definition of internal audit and really what is the purpose of internal audit, it's to provide that independent assurance around internal controls across all aspects of the organization that are relevant when you think about that organization wanting to achieve its objectives.
Speaker: And SOX, as we've talked about, you know what is that opinion? It's internal control over our financial reporting. And what do we mean, really? It's completeness and accuracy of the financial statements, right? but It doesn't really touch on things like efficiency, as an example, or profitability.
Speaker: So you could have a very inefficient process that has good controls, actually, and can pass SOCs. Or you could be looking at controls that might be associated with ah product lines or a customer relationships that are not profitable products, not not profitable customers,
Speaker: These are the types of things that SOX is just not going to get into. Think about you know supply chain management or or think about um you know there's a lot of things that an organization is trying to achieve objectively that SOX is just not going to necessarily help you get there.
Speaker: um So it is very important to step back and think about what are the risks we're not hitting with SOX. And that gets back to your question is, you know, don't don't cut my budget, right? Because if all I'm doing is SOX related work and maybe a little sliver of some other things, what am I missing?
Speaker: And there's quite a bit that can be missing sometimes. So I am excited about the future. And we i I mentioned briefly technology because I think there's an opportunity there where with new tech, people can maybe get through the SOX component of the work faster with less time, less less less money, and free up budget to do other things, which really gets back to why do we even have internal audit in the first place?
Speaker: you know one One thing i want i want to spend a little bit of time on this, and this is the transformational or the transformation component of it. okay And that's what you are bringing up with AI. But let's start with this because there's been some transformation as it relates to how we operate and how we manage. as internal audit, the advisory piece of it, because the change in the standard has got a different lens on how we go about doing that and still maintaining independence.
Speaker: How does that play a role in this overall exercise? Because I think if we're thinking transformation and we're thinking You know, the plan looks different because I'm working with leadership in a different way to help understand what our risks are. And that's the overall objective. Are we at risk? Are we effective? And we may not be. And I can have a conversation and determine that. So how does the advisory piece get baked into this overall equation? Because I think it has a lot to do with how we're going to manage ourselves as a team, as an internal audit team go forward.
Speaker: Yeah, the advisory piece is very important. and When it comes to SOCs, that's always going to be more assurance related, right? Like let's let's make sure that these controls are in place and effective.
Speaker: But the advisory can component of what internal audit can do is is huge. And the standards allow for this. And this is really about with by still maintaining objectivity,
Speaker: Being that advisor to management and being a partner to them. For example, if there's a new yeah ERP system being implemented, having that seat at the table early on to advise on what is a good, well-controlled, well-managed, well-governed implementation look like, right?
Speaker: And provide that that lens and that insight and so on And it's very valuable and it doesn't compromise. If you do it right, you're not compromising your position in terms of independence.
Speaker: So I think there's a lot of places within an organization where it does make sense to bring internal audit in early and take advantage of their ability to provide that advisory type service and help um you know think through processes, think through risk, think through leading practices for what good controls and good governance should be for for a process to help. Again, at the end of the day, we're trying to help a company achieve its objectives.
Speaker: You know, you've been touching on this already and it's hey i Let's graduate through that in a different way. Just help the audience understand the tools that are available and how this transformational exercise is happening. i do, I still do internal lot of work.
Speaker: And that's I use AI all the time. OK, it just makes me more efficient at what it is that I do, you know, assessing risk and pulling together work papers and rolling up findings and generating audit reports. It just makes it so much easier. It's only because I've been doing it forever, you know, but help the team understand what's available now. Some of those tools that are available that could expedite and speed this process up even more.
Speaker: Yeah. Well, we came out with in 2022, ChatGPT, the first, you know, widespread generative AI tool. And people latched onto to that and found it was very helpful for writing documents and summarizing information and so on. and And that was great. And people started doing that very, very early on, even an audit to maybe take content and summarize it for reporting and so on. So very valuable.
Speaker: But we've had this continuous progression at a pretty amazing clip with AI over the last few years. And now we're at the point where we have these agentic AI tools.
Speaker: And I think there's a tremendous opportunity for these agentic AI tools to get involved in in some of this control testing that we were talking about, especially things like ITGCs, but there are probably other financial financial transactional controls that that could be could could benefit from this as well.
Speaker: And these are anything that's kind of low judgment, rules-based testing, where you might have to select large samples. And if you do all that manually, it can be very time-consuming.
Speaker: Again, back to the budget issue. But the agentic AI, and I've seen demos of of a few tools, and I know some of the firms out there are building their own capabilities in this regard, and there's there's different ways it could be pulled together. But I'm a big fan of this because I think that the agentic AI is ah definitely able to help in this budget situation. And what I mean by that is, let's give the easy stuff, the low judgment, the rules-based stuff to the agentic AI tools.
Speaker: And it can churn through that testing. And these are designed to um markup audit evidence. There's APIs that can pull information from systems. They can build work papers that look perfect in a matter of minutes.
Speaker: And then you know free up the people who historically had done that to look at other things that do require more judgment, Chris. There's a lot of things we talked about ASC 606 and revenue rec.
Speaker: There's other things like that that are definitely more... ah judgmental and in nature where you really need a human to be involved in that. And so there's an opportunity here to take some of that easy stuff and turn it over to agentic AI tools and then repurpose the time that's freed up to look at other more complex controls that maybe in the SOX realm, but also what about all the other efficiency type auditing and other things that we haven't been able to get to because of SOX?
Speaker: Now, we if we're freeing up people's time to do more of that, that could be a huge win for companies and internal audit of departments. You know, when I think about your response and you started um yeah explaining how more how much more efficient the process can be, I started thinking about internal audit. It's all about risk and a risk management and being able to develop a plan based on all of the stuff that's going on within the business to figure out where we should be spending our time.
Speaker: I'll tell you, I used I've been using AI for about a year, but I'm telling you within the last six months, it's changed dramatically and what it can do.
Speaker: And with the assistance of someone who is competent, who understands internal audit and understands risk, it is a valuable tool. So I'm telling any team out there, if you're not using it, you're missing out.
Speaker: because it will absolutely be at the forefront. It can't do all of the work. That's not why it's there, but it can definitely speed up the process. So when you're thinking about this whole internal audit and 404 and you see what Congress is doing, I mean, what are the steps? What are those next steps that are going to make us just even better at this? I know we talked about generically what that formula might look like, but what are those next steps if Congress does what they need to do?
Speaker: OK, and AIA is influential of the way that they are. What is that going to lead to in your the way you see transformation in our business and how we operate?
Speaker: Yeah, I think for well a couple of things, I think we may truly get to more of a risk based approach on this if if these things happen, which is good because that's everything should ultimately come come down to risk. So if we can get there, if we can make it more true to the spirit of what the original Sarbanes-Oxley Act of 2002 was really meant to address.
Speaker: You know, why did Enron fail? Why did WorldCom fail? And there were others where we had situations where there was, you know, weak governance that led to a lot of these things or just not the right challenge to what was happening and so on.
Speaker: Again, Not because somebody didn't turn off an access right after somebody left the company. It wasn't. So we could get back to more the original spirit of of what the SOX Act was supposed to be and have this whole thing be more risk-based, which would be huge.
Speaker: And again, with the technology we have now, we can take some of these more transactional level things that still, we're still being asked to look at that, right? And and and and there's risk there. There's risk there.
Speaker: But because of the nature of the transactions and the type of risk that it is, there's that opportunity that we talked about to leverage tech there. And then really you know let let people start to step back and think about other risks and other audit areas that are more operational in nature and and not necessarily related to SOCs and all that. So I'm excited about you know what's happening here. I'm excited about the white paper.
Speaker: that the IA wrote because ah i think it's going to provide a lot more clarity around all of this. And it will finally help address you know what is internal audits role in this? Where do they fit in?
Speaker: And how do we make sure that all that coordination that we were talking about and the good communication really gets optimized? And just based on some of the conversation we've already had, i can't help but think about the human equation, human capital and internal audit.
Speaker: And I know it doesn't directly align with all of the other things that we talked about, but I think it's critical. I mean, what's happening? what what What's the right fit when I say human capital?
Speaker: um Because I think it's changing. I think it's changing within professional services. I think it's changing within business in general. What is the right human capital, in your opinion, the right human capital equation look like for internal audit today? Yeah, Chris, I think it's important that Internal audit is in ah a very unique spot in a lot of organizations. And the variety that people are exposed to in internal audit work is is tremendous.
Speaker: More than any other function within a corporation, typically in internal audit gets to see different departments, different locations. You get a very, very broad view of what's happening. And there's tremendous value in that.
Speaker: So the best people to bring in to those types of situations are people that are curious, people that like to learn, continuous learners, people that want to really understand how do things really work. And they ask a lot of good questions.
Speaker: And they're continuous learners in the sense that now we have the new tech that we've talked about and doing things the old way. it's going to evolve. It needs to evolve and it will evolve.
Speaker: So people that want to learn new skills, new trades, new ways of doing things and really just want to add value to their organization.
Speaker: And if you're thinking about outsourcing, you know, again, you want to bring in partners that kind of have that same mindset, right? People that that want to help you get there and have good experience and and good exposure.
Speaker: um And as I mentioned before, if you are outsourcing, you get the benefit of ah the perspective of what consultants have seen at other companies as well. So there's there's value in that model from that perspective as well.
Speaker: But I do think that, um you know, making sure you hire the right people that have that curiosity is huge and want to be continuous learners. And really not only you understand things on a technical level, but they have to be good communicators too.
Speaker: And be able to explain to leadership, C-level, ultimately up to boards, the so what, right? Like we're doing this work. Here's what we saw. Here's what we found.
Speaker: what's what's the impact at the end of the day? Why do we care? If that story cannot be told, it kind of falls flat, right? So you need people that really can connect the dots and tell that story across the organization and at various levels, different stakeholders about what they're seeing.
Speaker: So there's a lot of people out there, I think, who would really thrive in that environment. And those are the types of people that internal audit um departments and consulting firms providing that service should be latching onto.
Speaker: You know, this has just been so interesting. and And I'm thinking about if I'm in the audience and I'm listening to all of this and it sounds like a lot and I'm trying to figure it out as a staff, I'm trying i'm listening in as a manager, I'm trying to figure it out as a chief audit executive. What's that one takeaway?
Speaker: I mean, if you had one thing you would share with this audience as it relates to internal audit, 404, transformation that I know we're all evolving, what would that takeaway be?
Speaker: Yeah, i I think the takeaway is there's huge opportunity here to really see internal audit as a group that can add a lot of value and really get focused on things in a smart way, leveraging tech where it can be leveraged and really letting people think through the things that require that human in the loop right around judgment around governance challenge things that you just can't turn over to agents and let me also say i didn't say this earlier
Speaker: even when you're using agents, you never just turn things over to agentic AI. You always need to have people involved because people know what good looks like at the end of the day. They have to be the ultimate owners of what is done.
Speaker: They need to review. They may need to make sure that everything makes sense. But I see a lot of opportunity for internal audit to really up its game, Use that budget that we have to do some different things besides SOX. Of course, we need to make sure that's all good and tight, but let's get back to the original purpose of audit.
Speaker: And remember that internal audit and SOX are, they're not the same thing. They're different things. And there's a role for internal audit and SOX, a big role ah depending on the organization, but it needs to be a little better defined for sure.
Speaker: And also we want to make sure that we're addressing the original spirit of what internal audit is meant to be. And let's help organizations achieve their objectives overall, including operating efficiently, effectively, profitably for the benefit of shareholders.
Speaker: Ian, it's been an absolute pleasure just geeking out and talking about internal audit and kind of how we we do the business. And I think this audience has learned a great deal, but I know you're busy man.
Speaker: I know you're an important role within your current organization, but I do thank you for being a part of this conversation. Well, thank you, Chris. It's been a pleasure to be here and and talk with you about all of this.
Speaker: I enjoyed it. Awesome. Awesome. I'm going to take some time and and just look into the camera and say, internal audits important. The way that we manage and and go through the exercise of assisting management with their ownership of those controls.
Speaker: We go through and we provide a different lens and we help out, but we can't do that effectively if we're focused a lot on 404 and 404 only.
Speaker: There's more to what we deliver and how we can be used within an organization. So I ask. ah Those that are in leadership roles, just understand that there's a lot of value in having us be on your team.
Speaker: We are incredible advisors and 404 can be managed in some different ways. With the introduction of AI, it's moving in a totally different rhythm and cadence. And I think there are some things that can be handled that way.
Speaker: So just, you know, just take some insight, take some perspective from that. And this has been a fantastic fantastic fantastic conversation. And thank you for joining us on this episode of Balancing the Future. And I'm looking forward to future conversations.



