21/1/2011 European Court of Auditors Chamber IV Techniques for risk-based auditing DG INFSO-02...

50
21/1/2011 European Court of Auditors Chamber IV Techniques for risk-based auditing DG INFSO-02 Freddy Dezeure - Charles Macmillan

Transcript of 21/1/2011 European Court of Auditors Chamber IV Techniques for risk-based auditing DG INFSO-02...

Page 1: 21/1/2011 European Court of Auditors Chamber IV Techniques for risk-based auditing DG INFSO-02 Freddy Dezeure - Charles Macmillan.

21/1/2011 European Court of Auditors Chamber IV

Techniques for risk-based auditingDG INFSO-02 Freddy Dezeure - Charles Macmillan

Page 2: 21/1/2011 European Court of Auditors Chamber IV Techniques for risk-based auditing DG INFSO-02 Freddy Dezeure - Charles Macmillan.

Background DG INFSO

European Commission department

European Digital Agenda

Co-funding of cost of research projects: 1,5 bio€ per year

FP6, FP7, eTEN, CIP: > 7000 beneficiaries, >2000 projects

Financial audits - 200 per year

Page 3: 21/1/2011 European Court of Auditors Chamber IV Techniques for risk-based auditing DG INFSO-02 Freddy Dezeure - Charles Macmillan.

Selection of auditees

Page 4: 21/1/2011 European Court of Auditors Chamber IV Techniques for risk-based auditing DG INFSO-02 Freddy Dezeure - Charles Macmillan.

Assurance audits -> error 4%

Page 5: 21/1/2011 European Court of Auditors Chamber IV Techniques for risk-based auditing DG INFSO-02 Freddy Dezeure - Charles Macmillan.

P1

P1

Major sources of errors

Excessive overheads

Claimed salary cost not actual

Page 6: 21/1/2011 European Court of Auditors Chamber IV Techniques for risk-based auditing DG INFSO-02 Freddy Dezeure - Charles Macmillan.

Representative error rate

Page 7: 21/1/2011 European Court of Auditors Chamber IV Techniques for risk-based auditing DG INFSO-02 Freddy Dezeure - Charles Macmillan.

Risk-based auditing

Risk of intentional inflation of cost

Assessment of the organisation as a whole

Data mining – new tools and methods

Audit programme specific to the risk (ISA240 - ISA315)

Page 8: 21/1/2011 European Court of Auditors Chamber IV Techniques for risk-based auditing DG INFSO-02 Freddy Dezeure - Charles Macmillan.

CM

Page 9: 21/1/2011 European Court of Auditors Chamber IV Techniques for risk-based auditing DG INFSO-02 Freddy Dezeure - Charles Macmillan.

Data gathering

Risk assessment

Define approach

Field work

Assess next steps

Finalise

Page 10: 21/1/2011 European Court of Auditors Chamber IV Techniques for risk-based auditing DG INFSO-02 Freddy Dezeure - Charles Macmillan.

Data gatheringRisk

assessment

Page 11: 21/1/2011 European Court of Auditors Chamber IV Techniques for risk-based auditing DG INFSO-02 Freddy Dezeure - Charles Macmillan.

Data Gathering phase

Scope from risk assessment – continually reassessed

Collect available information from internal and external sources

Check for indicators and inconsistencies

Outcomes define specific audit procedures

Use and find new Indicators

Feed into control systems

Page 12: 21/1/2011 European Court of Auditors Chamber IV Techniques for risk-based auditing DG INFSO-02 Freddy Dezeure - Charles Macmillan.

Internal Sources

Project documents: proposal, description of work, deliverables, reports, reviews, emails, cost claims

Experts Database

Organisations Database

Page 13: 21/1/2011 European Court of Auditors Chamber IV Techniques for risk-based auditing DG INFSO-02 Freddy Dezeure - Charles Macmillan.

Open Sources

People Companies Communications

Google, BingGoogle Scholar, Microsoft AcademicMicrosoft EntityCubeLinkedIn, Zoominfo123People, Yasni, PIPLGoogle Magic Wheel, Timeline

Google, BingCompany registriesGoogle Maps Google Streetview

Google, BingInfobelIxquickUKPhonebookDomaintoolsDomaincrawlerRobtexWayback Machine

Page 14: 21/1/2011 European Court of Auditors Chamber IV Techniques for risk-based auditing DG INFSO-02 Freddy Dezeure - Charles Macmillan.

Find the right person

Find all the relevant information about the person

Avoid noise

Finding people

Page 15: 21/1/2011 European Court of Auditors Chamber IV Techniques for risk-based auditing DG INFSO-02 Freddy Dezeure - Charles Macmillan.
Page 16: 21/1/2011 European Court of Auditors Chamber IV Techniques for risk-based auditing DG INFSO-02 Freddy Dezeure - Charles Macmillan.
Page 17: 21/1/2011 European Court of Auditors Chamber IV Techniques for risk-based auditing DG INFSO-02 Freddy Dezeure - Charles Macmillan.
Page 18: 21/1/2011 European Court of Auditors Chamber IV Techniques for risk-based auditing DG INFSO-02 Freddy Dezeure - Charles Macmillan.
Page 19: 21/1/2011 European Court of Auditors Chamber IV Techniques for risk-based auditing DG INFSO-02 Freddy Dezeure - Charles Macmillan.

“Fake” People - Examples

Non-existent people

Existing, but

not relevant

not employed

not aware of project

People in multiple roles / companies / projects

Page 20: 21/1/2011 European Court of Auditors Chamber IV Techniques for risk-based auditing DG INFSO-02 Freddy Dezeure - Charles Macmillan.

Neuron – partner in BRAIN

Page 21: 21/1/2011 European Court of Auditors Chamber IV Techniques for risk-based auditing DG INFSO-02 Freddy Dezeure - Charles Macmillan.

Neuron: Key staff

• DoW Description

• Computer Science degree

• Experienced ICT researcher

• etc

Page 22: 21/1/2011 European Court of Auditors Chamber IV Techniques for risk-based auditing DG INFSO-02 Freddy Dezeure - Charles Macmillan.

Neuron – Key staff

Page 23: 21/1/2011 European Court of Auditors Chamber IV Techniques for risk-based auditing DG INFSO-02 Freddy Dezeure - Charles Macmillan.

Neuron – Key staff

Page 24: 21/1/2011 European Court of Auditors Chamber IV Techniques for risk-based auditing DG INFSO-02 Freddy Dezeure - Charles Macmillan.

Indicators

Not found on internet

Top management of company

Always the same names

Listed for different companies in different projects

Listed in a different country from the company

CV on LinkedIn contradicts submission

Anonymous email address (gmail, ...)

GSM phone only

Page 25: 21/1/2011 European Court of Auditors Chamber IV Techniques for risk-based auditing DG INFSO-02 Freddy Dezeure - Charles Macmillan.

Finding companies

Find the right company

Find all the relevant information about the company

Avoid noise

Page 26: 21/1/2011 European Court of Auditors Chamber IV Techniques for risk-based auditing DG INFSO-02 Freddy Dezeure - Charles Macmillan.

Even simple tools can help

Page 27: 21/1/2011 European Court of Auditors Chamber IV Techniques for risk-based auditing DG INFSO-02 Freddy Dezeure - Charles Macmillan.

34

Earth Match – partner in SOLARSYS

Page 28: 21/1/2011 European Court of Auditors Chamber IV Techniques for risk-based auditing DG INFSO-02 Freddy Dezeure - Charles Macmillan.

www.emsoft.com

Page 29: 21/1/2011 European Court of Auditors Chamber IV Techniques for risk-based auditing DG INFSO-02 Freddy Dezeure - Charles Macmillan.

34

Earth Match – partner in SOLARSYS

Page 30: 21/1/2011 European Court of Auditors Chamber IV Techniques for risk-based auditing DG INFSO-02 Freddy Dezeure - Charles Macmillan.

www.earthmatch.com.mt

Page 31: 21/1/2011 European Court of Auditors Chamber IV Techniques for risk-based auditing DG INFSO-02 Freddy Dezeure - Charles Macmillan.
Page 32: 21/1/2011 European Court of Auditors Chamber IV Techniques for risk-based auditing DG INFSO-02 Freddy Dezeure - Charles Macmillan.

www.cabbage.com

Page 33: 21/1/2011 European Court of Auditors Chamber IV Techniques for risk-based auditing DG INFSO-02 Freddy Dezeure - Charles Macmillan.

ONION – partner in VEGETABLE

Page 34: 21/1/2011 European Court of Auditors Chamber IV Techniques for risk-based auditing DG INFSO-02 Freddy Dezeure - Charles Macmillan.

32

• Does the website exist?

• Does the project fit the company’s core activities?

• Does the website give contact information - and does it match the official transmission documents?

• Is the website registered by the partner?

32

Company website

Page 35: 21/1/2011 European Court of Auditors Chamber IV Techniques for risk-based auditing DG INFSO-02 Freddy Dezeure - Charles Macmillan.

33

• Company registration websites

http://www.rba.co.uk/sources/registers.htm

• http://www.infobel.com/, http://www.ixquick.com/

– Cross-check the phone number with yellow/white pages

– Reverse search on the phone number

33

Company registry, phone/fax

Page 36: 21/1/2011 European Court of Auditors Chamber IV Techniques for risk-based auditing DG INFSO-02 Freddy Dezeure - Charles Macmillan.

33

• Website registration

http://www.domaintools.com/

http://www.robtex.com/dns/

• Archive

http://www.waybackmachine.org/

http://www.archive.org/web/web.php

33

Company website, history

Page 37: 21/1/2011 European Court of Auditors Chamber IV Techniques for risk-based auditing DG INFSO-02 Freddy Dezeure - Charles Macmillan.

44

• Search for company in Google

– Not reassuring if nothing found

• Translation tools

– http://translate.google.com

– http://babelfish.yahoo.com/

44

Tools - internet search

Page 38: 21/1/2011 European Court of Auditors Chamber IV Techniques for risk-based auditing DG INFSO-02 Freddy Dezeure - Charles Macmillan.

45

Page 39: 21/1/2011 European Court of Auditors Chamber IV Techniques for risk-based auditing DG INFSO-02 Freddy Dezeure - Charles Macmillan.

HOUR – partner in TIME

Page 40: 21/1/2011 European Court of Auditors Chamber IV Techniques for risk-based auditing DG INFSO-02 Freddy Dezeure - Charles Macmillan.

• Email address not <-> company domain

• Phone number = fax number

• Phone number = gsm number

• Website registered by another company

• Website or phone numbers in another country

• Corporate website without contact coordinates, “under construction”

Indicators

Page 41: 21/1/2011 European Court of Auditors Chamber IV Techniques for risk-based auditing DG INFSO-02 Freddy Dezeure - Charles Macmillan.

FD

Page 42: 21/1/2011 European Court of Auditors Chamber IV Techniques for risk-based auditing DG INFSO-02 Freddy Dezeure - Charles Macmillan.

Data Gathering Outcomes

Organisation

Cannot (financially)

Cannot (operationally)

Can do / have not

Staff

Have not done

Have done, cost inflated

Have done, cost ineligible

Page 43: 21/1/2011 European Court of Auditors Chamber IV Techniques for risk-based auditing DG INFSO-02 Freddy Dezeure - Charles Macmillan.

Outcome - Audit Procedures

Cannot (financial)

Find other income source

Check commercial agreements with others...

Cannot (operational)

Find who could have done the work

Verify working agreements / CVs / job descriptions...

Page 44: 21/1/2011 European Court of Auditors Chamber IV Techniques for risk-based auditing DG INFSO-02 Freddy Dezeure - Charles Macmillan.

Risk-based audits -> error 30%

Page 45: 21/1/2011 European Court of Auditors Chamber IV Techniques for risk-based auditing DG INFSO-02 Freddy Dezeure - Charles Macmillan.

Impact on DG INFSO

Huge effort in administrative follow-up

Litigation (EDPS, Ombudsman, TPI, ECJ)

Impossibility to recover funds

Waste of budget - impact on genuine participants

Reputation damage

Page 46: 21/1/2011 European Court of Auditors Chamber IV Techniques for risk-based auditing DG INFSO-02 Freddy Dezeure - Charles Macmillan.

Perception

Page 47: 21/1/2011 European Court of Auditors Chamber IV Techniques for risk-based auditing DG INFSO-02 Freddy Dezeure - Charles Macmillan.

Challenge

Detect problems early in the project life-cycle (PO)

Link data gathering/risk-assessment/audit programme

Manage exceptions well

Page 48: 21/1/2011 European Court of Auditors Chamber IV Techniques for risk-based auditing DG INFSO-02 Freddy Dezeure - Charles Macmillan.

Implementation of audits

Page 49: 21/1/2011 European Court of Auditors Chamber IV Techniques for risk-based auditing DG INFSO-02 Freddy Dezeure - Charles Macmillan.

Residual error

AuditedError = 0

ExtrapolatedError = non-systematic

UntouchedError = representative

Page 50: 21/1/2011 European Court of Auditors Chamber IV Techniques for risk-based auditing DG INFSO-02 Freddy Dezeure - Charles Macmillan.

Selectiveness

FacilitateSimplify

Trust

DetectCorrectPrevent